thanks for your patience....
Here is an interim report from gmer. It is still running but has not added a new entry in a while....
GMER 1.0.15.15077 [9hxt8ng4.exe] -
http://www.gmer.net
Rootkit scan 2009-09-04 07:00:03
Windows 5.1.2600 Service Pack 3
---- Kernel code sections - GMER 1.0.15 ----
? win32k.sys:1 The system cannot find the file specified. !
? win32k.sys:2 The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\windows\system32\svchost.exe[2040] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\windows\system32\svchost.exe[2040] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\windows\system32\svchost.exe[2040] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\windows\Explorer.EXE[2816] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\windows\Explorer.EXE[2816] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\windows\Explorer.EXE[2816] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\Program Files\iTunes\iTunesHelper.exe[3620] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\Program Files\iTunes\iTunesHelper.exe[3620] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\Program Files\iTunes\iTunesHelper.exe[3620] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A93C080 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A93C0E0 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A93C110 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A93BFE0 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A93C0E0 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A93BFC0 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A93C020 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A93C000 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A93BFA0 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A93C160 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A93C170 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A93C191 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A93C260 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A93C230 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A93C1A0 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A93BEB0 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A93BE50 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A93C0E0 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A93BE10 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\palmOne\Hotsync.exe[3832] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A93BE90 C:\Program Files\palmOne\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Eudora\Eudora.exe[4424] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\Eudora\Eudora.exe[4424] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\Eudora\Eudora.exe[4424] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] USER32.DLL!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
.text C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\system32\svchost.exe[2040] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\windows\system32\svchost.exe[2040] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\windows\Explorer.EXE[2816] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\windows\Explorer.EXE[2816] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\Program Files\iTunes\iTunesHelper.exe[3620] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\Program Files\iTunes\iTunesHelper.exe[3620] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\Eudora\Eudora.exe[4424] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\Eudora\Eudora.exe[4424] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\CD125F8E.x86.dll
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\ole32.dll [USER32.dll!CreateWindowExA] [004171AA] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\ole32.dll [USER32.dll!CreateWindowExW] [00417224] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\ole32.dll [USER32.dll!ShowWindow] [0041729E] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\WININET.dll [USER32.dll!SetWindowPos] [00417350] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\WININET.dll [USER32.dll!CreateWindowExW] [00417224] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!CreateWindowExA] [004171AA] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!CreateWindowExW] [00417224] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [00417350] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!ShowWindow] [0041729E] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\shell32.dll [USER32.dll!CreateWindowExW] [00417224] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\shell32.dll [USER32.dll!ShowWindow] [0041729E] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
IAT C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe[4452] @ C:\windows\system32\shell32.dll [USER32.dll!SetWindowPos] [00417350] C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [264] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponder.exe [312] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jqs.exe [444] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [612] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\windows\system32\svchost.exe [1396] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\windows\System32\svchost.exe [1436] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\windows\system32\svchost.exe [1596] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\windows\system32\svchost.exe [1636] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\windows\system32\spoolsv.exe [1884] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\windows\system32\svchost.exe [2040] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\windows\System32\alg.exe [2088] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\windows\Explorer.EXE [2816] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [3472] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\Program Files\iTunes\iTunesHelper.exe [3620] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\Eudora\Eudora.exe [4424] 0x35670000
Library \\?\globalroot\Device\__max++>\CD125F8E.x86.dll (*** hidden *** ) @ C:\DOCUME~1\mmauk\LOCALS~1\Temp\a.exe [4452]