dear dave
everything went a bit different from the description, i wasn't asked whether i wanted to perform any scan, so i just checked whether the boxes were all checked/unchecked and then started the scan, which seemed to have finished but again i didn't receive any notice.
here is the log:
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-07-16 15:01:42
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Elisa\AppData\Local\Temp\uglcapoc.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAllocateVirtualMemory [0xA82F5752]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAlpcConnectPort [0xA82F5388]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAssignProcessToJobObject [0xA82F5440]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwConnectPort [0xA82F5482]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateFile [0xA82F5530]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateProcess [0xA82F5DD8]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateProcessEx [0xA82F5E64]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateThread [0xA82F5EF4]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwDebugActiveProcess [0xA82F5580]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwDuplicateObject [0xA82F55C2]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwLoadDriver [0xA82F5606]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenKey [0xA82F5648]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenSection [0xA82F568A]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenThread [0xA82F56CC]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwProtectVirtualMemory [0xA82F579A]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwRequestWaitReplyPort [0xA82F570E]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwRestoreKey [0xA82F57DC]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwResumeThread [0xA82F5824]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSecureConnectPort [0xA82F58B4]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSetValueKey [0xA82F5866]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSuspendProcess [0xA82F5958]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSystemDebugControl [0xA82F599A]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwTerminateProcess [0xA82F59DC]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwWriteVirtualMemory [0xA82F5A2A]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateThreadEx [0xA82F5F96]
SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateUserProcess [0xA82F5D68]
INT 0x62 ? 854F6BF8
INT 0x72 ? 854F6BF8
INT 0x72 ? 854F6BF8
INT 0x72 ? 854F6BF8
INT 0x82 ? 854F6BF8
INT 0x82 ? 854F6BF8
INT 0x82 ? 854F6BF8
INT 0x82 ? 854F6BF8
INT 0xA2 ? 84606BF8
INT 0xB2 ? 84606BF8
INT 0xB2 ? 84606BF8
INT 0xB2 ? 84606BF8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 131 81AEE894 4 Bytes [52, 57, 2F, A8]
.text ntkrnlpa.exe!KeSetEvent + 13D 81AEE8A0 4 Bytes [88, 53, 2F, A8]
.text ntkrnlpa.exe!KeSetEvent + 191 81AEE8F4 4 Bytes [40, 54, 2F, A8]
.text ntkrnlpa.exe!KeSetEvent + 1C1 81AEE924 4 Bytes [82, 54, 2F, A8]
.text ntkrnlpa.exe!KeSetEvent + 1D9 81AEE93C 4 Bytes [30, 55, 2F, A8]
.text ...
? System32\Drivers\spxo.sys The system cannot find the path specified. !
.text USBPORT.SYS!DllUnload 8C5A341B 5 Bytes JMP 854F61D8
.text au8ydgj3.SYS 8BA35000 22 Bytes [82, 63, A1, 81, 6C, 62, A1, ...]
.text au8ydgj3.SYS 8BA35017 181 Bytes [00, 32, B7, 79, 80, 3D, B5, ...]
.text au8ydgj3.SYS 8BA350CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, ...]
.text au8ydgj3.SYS 8BA350DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...]
.text au8ydgj3.SYS 8BA350E7 714 Bytes [00, F0, 0E, 00, 00, 00, 00, ...]
.text ...
? \ArcName\multi(0)disk(0)rdisk(0)partition(1)\Windows\system32\drivers\PctWfpFilter.sys The system cannot find the path specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 00414A50 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] USER32.dll!InSendMessageEx + 3B1 76FAE6B0 6 Bytes JMP 0044C7F0 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] WS2_32.dll!getaddrinfo 77A2418A 5 Bytes JMP 71640022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] WS2_32.dll!gethostbyname 77A362D4 5 Bytes JMP 71670022
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] ntdll.dll!LdrLoadDll 77819390 5 Bytes JMP 00B013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 02187B40 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] kernel32.dll!SetUnhandledExceptionFilter 76E4A84F 6 Bytes PUSH 71510022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!DdeInitializeW 76FA7921 6 Bytes PUSH 714E0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!RegisterClassExW 76FADA30 6 Bytes PUSH 716E0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!GetMessageW 76FBFEF7 6 Bytes PUSH 71480022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!TranslateMessage 76FC01AD 6 Bytes PUSH 71410022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!GetClipboardData 76FE715A 6 Bytes PUSH 714B0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[3200] GDI32.dll!BitBlt 76F070A6 6 Bytes PUSH 71540022; RET
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 00438CE0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] WS2_32.dll!getaddrinfo 77A2418A 5 Bytes JMP 71670022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] WS2_32.dll!gethostbyname 77A362D4 5 Bytes JMP 716E0022
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3848] kernel32.dll!CreateThread + 1A 76E6C928 4 Bytes CALL 0044B8D9 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806916D6] \SystemRoot\System32\Drivers\spxo.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80691042] \SystemRoot\System32\Drivers\spxo.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [80691800] \SystemRoot\System32\Drivers\spxo.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806910C0] \SystemRoot\System32\Drivers\spxo.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069113E] \SystemRoot\System32\Drivers\spxo.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A0E9C] \SystemRoot\System32\Drivers\spxo.sys
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortNotification] CC358B04
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortUchar] 838BA5AF
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortUlong] 458B38C6
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetPhysicalAddress] A5A5A514
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 100D8BA5
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5F8BA580
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortUchar] 30810889
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortStallExecution] 54771129
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetParentBusType] 10C25D5E
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortRequestCallback] 8B55CC00
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 084D8BEC
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0CF0918B
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortCompleteRequest] 458B0000
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortMoveMemory] 8B108910
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 000CF491
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 04508900
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 053C7980
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortUshort] 560C558B
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortBufferUshort] C6127557
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortInitialize] B18D0502
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetDeviceBase] 00000CF8
IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortDeviceStateChange] A508788D
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 71670000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\GDI32.dll [USER32.dll!GetWindowRect] 71450000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ole32.dll [USER32.dll!GetWindowRect] 71450000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowRect] 71450000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WININET.dll [USER32.dll!GetWindowRect] 71450000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3848] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3848] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8460C1F8
Device \Driver\volmgr \Device\VolMgrControl 846081F8
Device \Driver\usbuhci \Device\USBPDO-0 854F31F8
Device \Driver\sptd \Device\1136032336 spxo.sys
Device \Driver\usbuhci \Device\USBPDO-1 854F31F8
Device \Driver\usbehci \Device\USBPDO-2 854E41F8
Device \Driver\usbuhci \Device\USBPDO-3 854F31F8
Device \Driver\usbuhci \Device\USBPDO-4 854F31F8
AttachedDevice \Driver\tdx \Device\Tcp pctgntdi.sys
Device \Driver\usbuhci \Device\USBPDO-5 854F31F8
Device \Driver\usbehci \Device\USBPDO-6 854E41F8
Device \Driver\volmgr \Device\HarddiskVolume1 846081F8
Device \Driver\PCI_PNP0319 \Device\00000058 spxo.sys
Device \Driver\volmgr \Device\HarddiskVolume2 846081F8
Device \Driver\cdrom \Device\CdRom0 8551E1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8460A1F8
Device \Driver\atapi \Device\Ide\IdePort0 8460A1F8
Device \Driver\atapi \Device\Ide\IdePort1 8460A1F8
Device \Driver\atapi \Device\Ide\IdePort2 8460A1F8
Device \Driver\msahci \Device\Ide\PciIde1Channel0 8460B1F8
Device \Driver\msahci \Device\Ide\PciIde1Channel2 8460B1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 8460A1F8
Device \Driver\cdrom \Device\CdRom1 8551E1F8
Device \Driver\netbt \Device\NetBT_Tcpip_{D1957ABD-6FAC-430A-98F1-B0F3C259C5C7} 85B68500
Device \Driver\netbt \Device\NetBt_Wins_Export 85B68500
Device \Driver\Smb \Device\NetbiosSmb 85C3F1F8
Device \Driver\iScsiPrt \Device\RaidPort0 855771F8
Device \Driver\usbuhci \Device\USBFDO-0 854F31F8
Device \Driver\usbuhci \Device\USBFDO-1 854F31F8
Device \Driver\netbt \Device\NetBT_Tcpip_{0C10FA32-146C-4B41-A940-8A06AA1733CB} 85B68500
Device \Driver\usbehci \Device\USBFDO-2 854E41F8
Device \Driver\usbuhci \Device\USBFDO-3 854F31F8
Device \Driver\usbuhci \Device\USBFDO-4 854F31F8
Device \Driver\usbuhci \Device\USBFDO-5 854F31F8
Device \Driver\usbehci \Device\USBFDO-6 854E41F8
Device \Driver\au8ydgj3 \Device\Scsi\au8ydgj31Port4Path0Target0Lun0 855621F8
Device \Driver\au8ydgj3 \Device\Scsi\au8ydgj31 855621F8
Device \FileSystem\cdfs \Cdfs 855111F8
---- EOF - GMER 1.0.15 ----
many thanks!