I seem to have some kind of malware. Gmer reports:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-01-17 11:05:21
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 WDC_WD1600BB-00DWA0 rev.15.05R15
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\pgldrkob.sys


---- Disk sectors - GMER 1.0.15 ----

Disk \Device\Harddisk0\DR0 sector 08: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;

---- Devices - GMER 1.0.15 ----

Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 82F4139B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 82F4139B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 82F4139B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 82F4139B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T1L0-1b 82F4139B
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-13 82F4139B
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskWDC_WD1600BB-00DWA0_____________________15.05R15#4457572d414d4b45383235323332_030_0_0_0_0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

---- EOF - GMER 1.0.15 ----


I have run malwarebytes, superantispyware, antivirus software... nothing helps. I get the whitesmoke toolbar and IE popups. HELPPPPPP!

Dani AI

Generated

— GMER flagging "rootkit-like behavior" together with persistent toolbars and IE popups suggests a low-level or deeply persistent component, but the GMER output alone does not prove the exact cause. Further evidence is needed to distinguish an MBR/boot-sector or file-system/driver rootkit from a more common PUP/browser-hijack that has persistent helpers.

Triage first: isolate the machine from sensitive networks if credentials are at risk, and make a full disk image before making changes so the drive can be analyzed or restored if needed. Avoid deleting unknown .sys or driver files from Temp or system folders until the infection is confirmed and a backup/image exists.

Collect these artifacts (post as plain text so responders can search them): OTL log (OTL.txt plus Extras.txt — run from Safe Mode if a rootkit is suspected), DDS.txt (DDS tool), the full GMER scan log, the Malwarebytes scan log, and an Autoruns export. Suspicious driver files can be uploaded to VirusTotal for a quick multi‑engine check (VirusTotal). Useful utilities: Autoruns for persistence enumeration (Autoruns — Sysinternals) and Malwarebytes for malware/anti‑rootkit checks (Malwarebytes).

Next-step options commonly used: run vetted anti-rootkit tools (Kaspersky TDSSKiller or vendor rescue media) and perform an offline rescue-disk scan to catch self-protecting components. Do not run ComboFix without expert instruction, and do not attempt MBR fixes or reinstalls until imaging/backups are done — if the MBR is infected, a clean reinstall or MBR restore from a known-good image is often the safest recovery. As requested, post the Read-Me requested logs so helpers can provide targeted removal steps.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.