Here is the gmer log file:
GMER 1.0.15.15087 -
http://www.gmer.netRootkit scan 2009-09-15 22:17:51
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Ian\LOCALS~1\Temp\pxtdqpod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0xB68A8F4A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0xB68A8454]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0xB68A8AEE]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0xB68A8132]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSection [0xB68AA1D6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateSymbolicLinkObject [0xB68AA4AE]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateThread [0xB68A7CF8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteKey [0xB68A9130]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDeleteValueKey [0xB68A92E0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwDuplicateObject [0xB68A7A5A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwLoadDriver [0xB68A9E58]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0xB68A86D8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenFile [0xB68A8D32]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenProcess [0xB68A778A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenSection [0xB68A8968]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwOpenThread [0xB68A7902]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRenameKey [0xB68A988C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0xB68A8250]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0xB68A9BF4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0xB68AA006]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetValueKey [0xB68A968C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0xB68A8672]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSystemDebugControl [0xB68A885C]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateProcess [0xB68A7FFC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0xB68A7ECA]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwCreateKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FEC] ZwCreateKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwOpenKey [0x804D7FF1]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FF1] ZwOpenKey [0x804D7FF1]
INT 0x03 \WINDOWS\system32\ntkrnlpa.exe[unknown section] 804D7FFB
INT 0x06 \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) B5ACB16D
INT 0x0E \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) B5ACAFC2
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[2220] ntdll.dll!NtFlushVirtualMemory 7C90D35E 5 Bytes JMP 02526DCE C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] ntdll.dll!NtMapViewOfSection 7C90D51E 5 Bytes JMP 025272BA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 02525BBB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] ntdll.dll!NtUnmapViewOfSection 7C90DF0E 5 Bytes JMP 0252737D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 0252724D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!ReadFile 7C80180E 7 Bytes JMP 02525AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 025273E3 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!CreateFileMappingW 7C8093AA 5 Bytes JMP 02526C79 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!CloseHandle 7C809B57 5 Bytes JMP 0252595F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetDriveTypeW 7C80B2E0 5 Bytes JMP 025261DA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetFileAttributesW 7C80B75C 5 Bytes JMP 025265B6 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!DuplicateHandle 7C80DE0E 7 Bytes JMP 02526AEA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!FindFirstFileExW 7C80EA8D 5 Bytes JMP 0252633F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!FindClose 7C80EDE7 7 Bytes JMP 02526261 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!FindNextFileW 7C80EF4A 7 Bytes JMP 025262BB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 02526035 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetFileSizeEx 7C810A19 5 Bytes JMP 025266AD C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetFileInformationByHandle 7C810C7D 5 Bytes JMP 02526A54 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!WriteFile 7C810D97 7 Bytes JMP 025259B9 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetFileAttributesExW 7C811105 5 Bytes JMP 025264E4 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetLongPathNameW 7C813363 5 Bytes JMP 02526EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetShortPathNameW 7C81F27E 5 Bytes JMP 02526F53 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!MoveFileWithProgressW 7C81F73E 5 Bytes JMP 02526725 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!SetFilePointerEx 7C821067 5 Bytes JMP 02527202 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!CopyFileExW 7C827B42 7 Bytes JMP 02525C61 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!ReadFileEx 7C82BD0B 5 Bytes JMP 02525BDA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!WriteFileGather 7C82DDB5 7 Bytes JMP 0252718A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!ReadFileScatter 7C82DE61 7 Bytes JMP 02526BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!SetFileAttributesW 7C8314F5 5 Bytes JMP 0252644C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetOverlappedResult 7C8315E4 5 Bytes JMP 025269D0 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!DeleteFileW 7C831F7B 5 Bytes JMP 02526135 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!SetEndOfFile 7C83208E 5 Bytes JMP 02527001 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!FlushViewOfFile 7C8359B9 5 Bytes JMP 02526D63 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!RemoveDirectoryW 7C836FA3 5 Bytes JMP 02525E5A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!BackupRead 7C856F6F 5 Bytes JMP 02526E31 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!CreateDirectoryExW 7C85A782 5 Bytes JMP 02525F4C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!WriteFileEx 7C85C891 5 Bytes JMP 02525A83 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!GetCompressedFileSizeW 7C85D501 5 Bytes JMP 02527108 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] kernel32.dll!CreateHardLinkW 7C86B65C 7 Bytes JMP 02527236 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\Explorer.EXE[2220] USER32.dll!ExitWindowsEx 7E45A045 5 Bytes JMP 025271E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] ntdll.dll!NtFlushVirtualMemory 7C90D35E 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] ntdll.dll!NtMapViewOfSection 7C90D51E 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] ntdll.dll!NtUnmapViewOfSection 7C90DF0E 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!ReadFile 7C80180E 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!CreateFileMappingW 7C8093AA 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!CloseHandle 7C809B57 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetDriveTypeW 7C80B2E0 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetFileAttributesW 7C80B75C 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!DuplicateHandle 7C80DE0E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!FindFirstFileExW 7C80EA8D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!FindClose 7C80EDE7 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!FindNextFileW 7C80EF4A 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetFileSizeEx 7C810A19 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetFileInformationByHandle 7C810C7D 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!WriteFile 7C810D97 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetFileAttributesExW 7C811105 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetLongPathNameW 7C813363 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetShortPathNameW 7C81F27E 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!MoveFileWithProgressW 7C81F73E 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!SetFilePointerEx 7C821067 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!CopyFileExW 7C827B42 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!ReadFileEx 7C82BD0B 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!WriteFileGather 7C82DDB5 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!ReadFileScatter 7C82DE61 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!SetFileAttributesW 7C8314F5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetOverlappedResult 7C8315E4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!DeleteFileW 7C831F7B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!SetEndOfFile 7C83208E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!FlushViewOfFile 7C8359B9 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!RemoveDirectoryW 7C836FA3 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!BackupRead 7C856F6F 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!CreateDirectoryExW 7C85A782 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!WriteFileEx 7C85C891 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!GetCompressedFileSizeW 7C85D501 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] kernel32.dll!CreateHardLinkW 7C86B65C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\Ian\Desktop\gmer.exe[2752] USER32.dll!ExitWindowsEx 7E45A045 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] ntdll.dll!NtFlushVirtualMemory 7C90D35E 5 Bytes JMP 00336DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] ntdll.dll!NtMapViewOfSection 7C90D51E 5 Bytes JMP 003372BA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 00335BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] ntdll.dll!NtUnmapViewOfSection 7C90DF0E 5 Bytes JMP 0033737D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 0033724D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!ReadFile 7C80180E 7 Bytes JMP 00335AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 003373E3 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!CreateFileMappingW 7C8093AA 5 Bytes JMP 00336C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!CloseHandle 7C809B57 5 Bytes JMP 0033595F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetDriveTypeW 7C80B2E0 5 Bytes JMP 003361DA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetFileAttributesW 7C80B75C 5 Bytes JMP 003365B6 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!DuplicateHandle 7C80DE0E 7 Bytes JMP 00336AEA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!FindFirstFileExW 7C80EA8D 5 Bytes JMP 0033633F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!FindClose 7C80EDE7 7 Bytes JMP 00336261 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!FindNextFileW 7C80EF4A 7 Bytes JMP 003362BB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00336035 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetFileSizeEx 7C810A19 5 Bytes JMP 003366AD C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetFileInformationByHandle 7C810C7D 5 Bytes JMP 00336A54 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!WriteFile 7C810D97 7 Bytes JMP 003359B9 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetFileAttributesExW 7C811105 5 Bytes JMP 003364E4 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetLongPathNameW 7C813363 5 Bytes JMP 00336EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetShortPathNameW 7C81F27E 5 Bytes JMP 00336F53 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!MoveFileWithProgressW 7C81F73E 5 Bytes JMP 00336725 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!SetFilePointerEx 7C821067 5 Bytes JMP 00337202 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!CopyFileExW 7C827B42 7 Bytes JMP 00335C61 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!ReadFileEx 7C82BD0B 5 Bytes JMP 00335BDA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!WriteFileGather 7C82DDB5 7 Bytes JMP 0033718A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!ReadFileScatter 7C82DE61 7 Bytes JMP 00336BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!SetFileAttributesW 7C8314F5 5 Bytes JMP 0033644C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetOverlappedResult 7C8315E4 5 Bytes JMP 003369D0 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!DeleteFileW 7C831F7B 5 Bytes JMP 00336135 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!SetEndOfFile 7C83208E 5 Bytes JMP 00337001 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!FlushViewOfFile 7C8359B9 5 Bytes JMP 00336D63 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!RemoveDirectoryW 7C836FA3 5 Bytes JMP 00335E5A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!BackupRead 7C856F6F 5 Bytes JMP 00336E31 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!CreateDirectoryExW 7C85A782 5 Bytes JMP 00335F4C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!WriteFileEx 7C85C891 5 Bytes JMP 00335A83 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!GetCompressedFileSizeW 7C85D501 5 Bytes JMP 00337108 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] kernel32.dll!CreateHardLinkW 7C86B65C 7 Bytes JMP 00337236 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe[2760] USER32.dll!ExitWindowsEx 7E45A045 5 Bytes JMP 003371E7 C:\WINDOWS\system32\wxvault.dll
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E12780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\VMNetSrv.sys[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E12780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E12780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E12780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [B9E12780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E12780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E12780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [B9E12740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [B9E12780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [B9E126E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [B9E127B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
Device \Driver\Disk \Device\Harddisk0\DR0 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
Device \Driver\Disk \Device\Harddisk1\DR2 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+3 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F4A3901F5451D574FA396AAD2001DF25\Usage@CXOne 992981572
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs wxvault.dll C:\WINDOWS\system32\guard32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
---- Files - GMER 1.0.15 ----
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\A0043529.dll 59904 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\A0043529.dll.info 230 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\A0045281.exe 1536 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\A0045281.exe.info 264 bytes
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\zip.exe 135168 bytes executable
File C:\Program Files\COMODO\COMODO Internet Security\Quarantine\zip.exe.info 116 bytes
ADS C:\System Volume Information\_restore{A514C1CC-499A-484A-B67E-3584577FFCF7}\RP134\A0045252.sys:1 8704 bytes executable
---- EOF - GMER 1.0.15 ----