well the that new user account has come back but it still is running a lil slow and hangs on the boot screen longer then it used to heres the scan
GMER 1.0.10.10122 -
http://www.gmer.netRootkit 2006-07-18 23:45:03
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.10 ----
SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT \SystemRoot\System32\vsdatant.sys ZwMapViewOfSection
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile
SSDT sptd.sys ZwOpenKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile
SSDT \SystemRoot\System32\vsdatant.sys ZwSetSystemInformation
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwTerminateProcess
---- Devices - GMER 1.0.10 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82390B78
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 8217A680
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSEIRP_MJ_READ [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT [BAE79A80] vsdatant.sys
Device \Driver\00000051 \Device\00000044 IRP_MJ_SYSTEM_CONTROL [F8451F68] sptd.sys
Device \Driver\00000051 \Device\00000044 IRP_MJ_DEVICE_CHANGE [F8466A70] sptd.sys
Device \Driver\00000051 \Device\00000044 IRP_MJ_PNP_POWER [F845F728] sptd.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSEIRP_MJ_READ [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT [BAE79A80] vsdatant.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 823DB4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 823DB4F0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82096EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSEIRP_MJ_READ 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 8210D0E8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_PNP 8210D0E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 82096EB0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 820929D0
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 820929D0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSEIRP_MJ_READ [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT [BAE79A80] vsdatant.sys
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 82390E30
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSEIRP_MJ_READ [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT [BAE79A80] vsdatant.sys
Device \Driver\Disk \Device\Harddisk1\DR1 IRP_MJ_CREATE 82390E30
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSEIRP_MJ_READ 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP_POWER 821BFA20
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSEIRP_MJ_READ [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN [BAE79A80] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT [BAE79A80] vsdatant.sys
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSEIRP_MJ_READ 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 821BFA20
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP_POWER 821BFA20
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 8205F410
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 8205F410
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSEIRP_MJ_READ 8205F410
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 8205F410
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 8205F410
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 8205F410
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_EA 8205F410
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 823DB4F0
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 820E9EB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{E72EDB5B-47FE-4021-8437-4123CD1A525B} IRP_MJ_CREATE 820929D0
Device \Driver\viamraid \Device\Scsi\viamraid1 IRP_MJ_CREATE 823900E8
Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE 82045E10
Device \Driver\dtscsi \Device\Scsi\dtscsi1Port3Path0Target0Lun0 IRP_MJ_CREATE 82045E10
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 8217A680
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 8157BAF0
---- Files - GMER 1.0.10 ----
File C:\System Volume Information\MountPointManagerRemoteDatabase
File C:\System Volume Information\tracking.log
File C:\System Volume Information\_restore{CFD8312E-EC25-4251-909E-FE783D689F74}
---- EOF - GMER 1.0.10 ----