I have two computers (both with XP SP3 & updates), which I'll simply call "older" and "newer."

About 10 days ago the older machine started acting strangely. All three keyboard status LED's would blink on, then off... sometimes on and then off a second time. Thereafter, the "typematic" or "keyboard repeat" rate became very slow. Holding down one key, to create a line of characters the width of the page, would take 7 or 8 seconds, instead of less than 2 seconds. Rebooting would eliminate the symptoms, but they would come back, anywhere from 5 minutes to 90 minutes after the reboot. Because of the keyboard & LED symptoms, I suspected a keylogger. I scanned with AVG, Ad-Aware, and 2 or 3 rootkit scanners; all came up negative. I downloaded SSnD and it reported VirtuMonde, also reported removing it. The next scan after reboot was clean, but eventually the symptoms came back. I decided to quit running the older machine, and try another approach.

I fired up the newer machine, upgraded to AVG 8 free, downloaded a fresh copy of SSnD. I unplugged the C:\ drive from the older machine, connected it to an ATA/USB adapter, and plugged it into the newer machine's USB port, while holding down {left shift} to prevent autorun/autoplay.

I started SSnD from the user interface, and told it to scan the E:\ drive (which was actually the older machine's boot drive, via the USB adapter). That scan did not find Virtumonde, but found a different infection this time (sorry, I have misplaced my notes with the name). Again, SSnD reported successful cleaning, and a new scan after reboot came up clean.

At that point, I was tempted to copy a few data files from the older boot drive to the newer machine. I opened My Computer, and verified seeing the E:\ drive there (again, the older boot drive via the USB adapter).

Just on a whim, I right clicked the drive, then selected "Scan with SSnD". A small window opened up in the middle of the screen, showed a big list of files, and started scanning. That was last Sunday, 6 days ago. As I write this, it is still scanning! The status bar shows 6 black rectangles, and it appears that the scan is roughly 1/3 complete. I would guess the complete scan of this 20 GB drive will take about three weeks!!!

I just checked, and it took nearly 90 seconds to scan one file, watv02nt.sys.

I can't believe the scan is this slow... are there any comments?

Also, the present slow scan has shown a few hits so far, as follows:

YOUR-machinename.ldb = Smitfraud-c.
regsvr32.exe = AdDestination
SpOrder.dll = webHancer
syssetup.inf = TinyBar.C

I've googled the descriptions of the above malware, and none if it matches the older machine's earlier symptoms. Any chance those are false positives?

Any comments or suggestions would be greatly appreciated!

THANKS IN ADVANCE!