Hi JSntgRvr, thanks for the quick reply. I've been reading the work you've done for other people. Ok, I'vve done all the scans and I'll post the logs below. Just one question... would it be possible for you to explain why I'm performing each step? Like what is a rootkit and what information are you looking for in the logs. I just like to understand so I'll know for the future. Teach a man to fish and all that...
edit: wow these are bit long... I'll attatch them as .txt at the bottom too...
GMER 1.0.12.12011 -
http://www.gmer.net
Rootkit scan 2007-03-25 09:23:31
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
---- Kernel code sections - GMER 1.0.12 ----
.text USBPORT.SYS!DllUnload BA90762C 5 Bytes JMP 8A16D1B8
---- User code sections - GMER 1.0.12 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[584] kernel32.dll!MultiByteToWideChar 7C809CAD 5 Bytes JMP 1002FF60 C:\WINDOWS\system32\ddcya.dll
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 8A19D1D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 8A19D1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 8A16C1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 8A20F1D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 8A20F1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 8A16C1D8
Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 8A16C1D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CREATE 8A1401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CLOSE 8A1401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 8A1401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A1401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_POWER 8A1401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 8A1401D8
Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_PNP 8A1401D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 8A19F1D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 8A0F61D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 8A0F61D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 8A19F1D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 8A19F1D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 8A0F61D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 8A0F61D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CREATE 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CLOSE 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_DEVICE_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_INTERNAL_DEVICE_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_POWER 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SYSTEM_CONTROL 8A19E1D8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_PNP 8A19E1D8
Device \Driver\NetBT \Device\NetBT_Tcpip_{789F4325-0086-43F7-8413-77F688EDEBBA} IRP_MJ_CREATE 89CA9648
Device \Driver\NetBT \Device\NetBT_Tcpip_{789F4325-0086-43F7-8413-77F688EDEBBA} IRP_MJ_CLOSE 89CA9648
Device \Driver\NetBT \Device\NetBT_Tcpip_{789F4325-0086-43F7-8413-77F688EDEBBA} IRP_MJ_DEVICE_CONTROL 89CA9648
Device \Driver\NetBT \Device\NetBT_Tcpip_{789F4325-0086-43F7-8413-77F688EDEBBA} IRP_MJ_INTERNAL_DEVICE_CONTROL 89CA9648
Device \Driver\NetBT \Device\NetBT_Tcpip_{789F4325-0086-43F7-8413-77F688EDEBBA} IRP_MJ_CLEANUP 89CA9648
Device \Driver\NetBT \Device\NetBT_Tcpip_{789F4325-0086-43F7-8413-77F688EDEBBA} IRP_MJ_PNP 89CA9648
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 89CA9648
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 89CA9648
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 89CA9648
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 89CA9648
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 89CA9648
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP