That was the entire log this time, much shorter than the first one and I doublechecked to make sure of settings.
Have to leave now for a bit but here is textr so far from gmer
GMER 1.0.12.12244 -
http://www.gmer.netRootkit scan 2007-04-29 15:47:22
Windows 5.1.2600 Service Pack 2
---- Kernel code sections - GMER 1.0.12 ----
.text ntoskrnl.exe!CcCopyWrite + 4 804F320B 2 Bytes [ 02, 4F ]
PAGE ntoskrnl.exe!NtCreateSection + 4 8056461F 2 Bytes [ 02, 4E ]
PAGE ntoskrnl.exe!NtReadFile + 4 805700DC 1 Byte [ 02 ]
PAGE ntoskrnl.exe!NtQueryInformationFile + 4 80571482 1 Byte [ 02 ]
PAGE ntoskrnl.exe!CcCopyRead + 4 8057189F 2 Bytes [ 02, 4F ]
PAGE ntoskrnl.exe!NtMapViewOfSection + 4 80572370 2 Bytes [ 02, 4F ]
PAGE Ntfs.sys F86D6B89 1 Byte [ 00 ]
? C:\WINDOWS\system32\DRIVERS\update.sys
---- User code sections - GMER 1.0.12 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[2212] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 009CF205 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2212] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 00B5FEBF C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2212] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 00B5FE40 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2212] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 00B5FE84 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2212] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 00B5FDCC C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2212] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 00B5FE06 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2212] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 00B5FEFA C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2212] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 009F15DA C:\WINDOWS\system32\IEFRAME.dll
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE EEADFC8A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE EEADC7C8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ EEAD860A
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE EEAD8AED
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION EEAE3958
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION EEAE6821
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA EEAEF38A
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA EEAEED49
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS EEAE8BBE
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION EEAE9331
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION EEAF74F4
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL EEADFB37
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL EEADB948
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL EEAE546B
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN EEAF679D
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL EEAF5C4A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP EEADC2FD
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP EEAF61DB
Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible EEAF11F9
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EF8D0701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EF8D0701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EF8D0701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EF8D0701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [EF8D0701] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [EF8D089D] tfsnifs.sys
---- Threads - GMER 1.0.12 ----
Thread 4:2340 82BF2338
---- Files - GMER 1.0.12 ----
ADS C:\Documents and Settings\Brent\Favorites\eBay :favicon
ADS C:\Documents and Settings\Brent\Favorites\eBay :favicon
ADS C:\Documents and Settings\Brent\Favorites\Metacafe :favicon
ADS C:\Documents and Settings\Brent\Favorites\Welcome to Webkinz:favicon