From ntbtlog.txt (xp boot log file), I found out there is a driver file changed its name everytime I reboot.
Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
Loaded driver \SystemRoot\System32\Drivers\a5mzjxub.SYS
Loaded driver \SystemRoot\system32\DRIVERS\cfosspeed.sys
However, when I login xp, I can't find the suspect file.
This possible virus also appears in registry (HLKM/System/CurrentControlSet/Services/), and also changes its name when I reboot.
But no real filename is recorded in that registry item.
I have used NOD32 4RC and antivir (with updated virus code) to scan the hardrive in safe mode, but no luck.
When the computer is turned off, I think the virus write back its real name to registry so that xp know to run it when I boot up.
Is there a registry editor that can edit registry on another hard drive?