Hi Super Dave,
I can't find anythig related to WildTangent in my programs so I didn't remove anything.
I ran Combo fix and GMER as instructed. Here are the logs:
ComboFix 11-01-15.01 - jocey 01/18/2011 21:52:04.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.534 [GMT -6:00]
Running from: c:\documents and settings\jocey\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jocey\Desktop\CFScript.txt
AV: Norton Internet Security Netbook Edition *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security Netbook Edition *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
FILE ::
"C:\found.000"
.
((((((((((((((((((((((((( Files Created from 2010-12-19 to 2011-01-19 )))))))))))))))))))))))))))))))
.
2011-01-16 22:02 . 2001-08-17 19:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-01-16 22:02 . 2001-08-17 19:48 12160 ----a-w- c:\windows\system32\dllcache\mouhid.sys
2011-01-16 22:02 . 2008-04-14 06:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2011-01-16 22:02 . 2008-04-14 06:15 10368 ----a-w- c:\windows\system32\dllcache\hidusb.sys
2011-01-15 22:45 . 2011-01-15 22:45 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-01-15 20:56 . 2011-01-15 22:17 -------- d-----w- c:\windows\ie8updates
2011-01-15 20:50 . 2011-01-15 20:50 -------- d-----w- c:\program files\Trend Micro
2011-01-14 12:05 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2011-01-14 12:05 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2011-01-14 12:04 . 2010-09-18 06:53 954368 ----a-w- c:\windows\system32\mfc40.dll
2011-01-14 12:04 . 2010-09-18 06:53 954368 ------w- c:\windows\system32\dllcache\mfc40.dll
2011-01-14 12:04 . 2010-09-18 06:53 953856 ----a-w- c:\windows\system32\mfc40u.dll
2011-01-14 12:04 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2011-01-14 12:04 . 2010-09-18 06:53 974848 ----a-w- c:\windows\system32\mfc42.dll
2011-01-14 12:04 . 2010-09-18 06:53 974848 ------w- c:\windows\system32\dllcache\mfc42.dll
2011-01-14 12:04 . 2008-08-14 10:04 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-01-14 12:04 . 2008-08-14 10:04 138496 ------w- c:\windows\system32\dllcache\afd.sys
2011-01-14 12:04 . 2010-08-23 16:12 617472 ----a-w- c:\windows\system32\comctl32.dll
2011-01-14 12:04 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2011-01-14 11:59 . 2009-06-21 21:44 153088 ----a-w- c:\program files\Common Files\Microsoft Shared\Triedit\triedit.dll
2011-01-14 11:59 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2011-01-14 11:54 . 2009-12-09 05:53 726528 ----a-w- c:\windows\system32\dllcache\jscript.dll
2011-01-14 11:52 . 2010-02-24 13:11 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-01-14 11:52 . 2010-02-24 13:11 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2011-01-13 03:22 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2011-01-13 02:29 . 2010-11-06 00:26 5959168 ----a-w- c:\windows\system32\dllcache\mshtml.dll
2011-01-13 02:29 . 2010-11-06 00:26 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-01-13 02:29 . 2010-11-06 00:26 11080704 ------w- c:\windows\system32\dllcache\ieframe.dll
2011-01-13 02:29 . 2010-11-02 15:17 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2011-01-13 02:29 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-01-13 02:27 . 2010-04-27 13:59 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-01-13 02:27 . 2010-04-27 13:59 2146304 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-01-13 02:27 . 2010-04-28 02:25 2189952 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-01-13 02:27 . 2010-04-27 13:05 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-01-13 02:27 . 2010-04-27 13:05 2024448 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-01-13 02:27 . 2010-04-27 13:05 2066816 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-01-13 02:25 . 2008-05-08 14:02 203136 ----a-w- c:\windows\system32\drivers\rmcast.sys
2011-01-13 02:25 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2011-01-13 02:25 . 2008-05-01 14:33 331776 ----a-w- c:\program files\Common Files\System\msadc\msadce.dll
2011-01-13 02:25 . 2008-05-01 14:33 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2011-01-13 02:22 . 2011-01-16 22:21 -------- d-----w- c:\windows\system32\drivers\NIS\1107000.00C
2011-01-13 02:21 . 2010-03-10 06:15 420352 ----a-w- c:\windows\system32\vbscript.dll
2011-01-13 02:21 . 2010-03-10 06:15 420352 ----a-w- c:\windows\system32\dllcache\vbscript.dll
2011-01-13 02:19 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2011-01-13 02:18 . 2010-10-11 14:59 45568 ----a-w- c:\program files\Outlook Express\wab.exe
2011-01-13 02:18 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-01-13 02:18 . 2010-08-16 08:45 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2011-01-13 02:18 . 2010-08-16 08:45 590848 ------w- c:\windows\system32\dllcache\rpcrt4.dll
2011-01-12 01:32 . 2011-01-12 01:32 -------- d-----w- C:\found.000
2011-01-12 01:03 . 2011-01-16 15:04 -------- d--h--w- c:\windows\$hf_mig$
2011-01-11 23:16 . 2010-06-18 13:36 3558912 ----a-w- c:\program files\Movie Maker\moviemk.exe
2011-01-11 23:16 . 2010-06-18 13:36 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2011-01-11 21:40 . 2010-12-21 00:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-11 21:40 . 2011-01-11 21:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-11 21:39 . 2011-01-11 21:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-11 21:39 . 2010-12-21 00:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-11 20:20 . 2011-01-11 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-01-11 20:19 . 2011-01-11 20:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-01-11 19:54 . 2011-01-11 19:54 -------- d-----w- c:\program files\CCleaner
2011-01-11 19:47 . 2011-01-11 23:17 -------- d-----w- c:\documents and settings\All Users\Application Data\OnlineArmor
2011-01-11 19:47 . 2010-11-03 21:57 38856 ----a-w- c:\windows\system32\drivers\oahlp32.sys
2011-01-11 19:47 . 2010-11-03 21:55 25000 ----a-w- c:\windows\system32\drivers\OAmon.sys
2011-01-11 19:47 . 2010-11-03 21:55 29272 ----a-w- c:\windows\system32\drivers\OAnet.sys
2011-01-11 19:47 . 2010-11-03 21:52 202064 ----a-w- c:\windows\system32\drivers\OADriver.sys
2011-01-11 19:47 . 2011-01-19 03:40 -------- d-----w- c:\program files\Online Armor
2010-12-26 22:57 . 2010-12-26 23:06 -------- d-----w- c:\documents and settings\Administrator
2010-12-26 22:03 . 2010-12-26 22:32 -------- d-----w- c:\program files\PC Tools Security
2010-12-26 22:03 . 2010-12-26 22:32 -------- d-----w- c:\program files\Common Files\PC Tools
2010-12-26 21:54 . 2010-12-26 22:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-12-26 21:44 . 2010-12-26 22:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-12-26 20:32 . 2010-12-26 20:32 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-12-26 20:32 . 2010-12-26 21:13 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-12-26 20:32 . 2010-12-26 20:32 -------- d-----w- c:\program files\Symantec
2010-12-26 20:32 . 2010-12-26 20:32 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-12-25 23:01 . 2001-08-18 04:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-12-25 23:01 . 2008-04-14 11:42 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-12-25 23:01 . 2008-04-14 06:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-12-25 23:01 . 2008-04-14 06:15 15104 ----a-w- c:\windows\system32\dllcache\usbscan.sys
2010-12-25 23:00 . 2011-01-11 21:30 -------- d-----w- c:\documents and settings\All Users\Application Data\fPhCc06305
2010-12-25 23:00 . 2010-12-25 23:00 -------- d-----w- c:\windows\Sun
2010-12-25 22:14 . 2010-02-04 20:32 259584 ----a-w- c:\windows\system32\bcdedit.exe
2010-12-25 22:14 . 2010-12-25 22:14 -------- d-----w- C:\Boot
2010-12-25 22:13 . 2008-04-15 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-12-25 22:13 . 2010-12-25 22:13 -------- d-----w- C:\WildTangent
2010-12-25 22:13 . 2010-12-25 22:13 -------- d-----w- C:\Users
2010-12-25 22:13 . 2010-12-25 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Skyhook Wireless
2010-12-25 22:13 . 2010-12-25 22:13 -------- d-----w- c:\program files\DIFX
2010-12-25 22:13 . 2010-02-17 07:11 13568 ----a-w- c:\windows\system32\drivers\wpsnuio.sys
2010-12-25 22:12 . 2010-12-25 22:12 -------- d-----w- c:\program files\Skyhook Wireless
2010-12-25 22:11 . 2010-12-25 22:11 -------- d-----w- c:\program files\HP Webcam
2010-12-25 22:11 . 2010-03-10 03:17 217088 ----a-w- c:\windows\system32\ACamPropertyPage.dll
2010-12-25 22:11 . 2010-03-03 20:39 363904 ----a-w- c:\windows\system32\drivers\cam3820a.sys
2010-12-25 22:11 . 2010-03-02 21:51 212992 ----a-w- c:\windows\system32\cocam3820.dll
2010-12-25 22:11 . 2010-03-02 21:51 110592 ----a-w- c:\windows\system32\cam3820n.ax
2010-12-25 22:11 . 2010-03-01 15:54 1323296 ----a-w- c:\windows\system32\drivers\rt2860.sys
2010-12-25 22:11 . 2010-03-01 15:50 238880 ----a-w- c:\windows\system32\RaCoInst.dll
2010-12-25 22:11 . 2010-12-25 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Ralink Driver
2010-12-25 22:10 . 2011-01-13 03:22 -------- d-----w- c:\documents and settings\jocey
2010-12-25 22:08 . 2010-08-27 02:34 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-12-25 22:08 . 2010-08-27 04:54 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-12-25 22:08 . 2010-08-27 03:57 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2010-12-25 22:08 . 2010-08-27 02:34 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2010-12-25 22:08 . 2010-08-27 01:37 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\ApplicationHistory
2010-12-25 18:35 . 2008-04-14 06:15 26368 ----a-w- c:\windows\system32\dllcache\usbstor.sys
2010-12-25 18:19 . 2010-12-25 18:19 -------- d-----w- c:\documents and settings\LocalService\Application Data\Apple Computer
2010-12-25 17:59 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-12-25 17:59 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-12-25 17:57 . 2010-12-25 17:57 -------- d-----w- c:\program files\iPod
2010-12-25 17:56 . 2010-12-25 17:59 -------- d-----w- c:\program files\iTunes
2010-12-25 17:56 . 2010-12-25 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-12-25 17:55 . 2010-12-25 17:55 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2010-12-25 17:55 . 2010-12-25 17:55 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2010-12-25 17:55 . 2010-12-25 17:55 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2010-12-25 17:55 . 2010-12-25 17:55 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2010-12-25 17:55 . 2010-12-25 17:55 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2010-12-25 17:55 . 2010-12-25 17:55 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2010-12-25 17:55 . 2010-12-25 17:55 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2010-12-25 17:52 . 2010-12-25 17:55 -------- d-----w- c:\program files\QuickTime
2010-12-25 17:51 . 2010-12-25 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-12-25 17:51 . 2010-12-25 17:51 -------- d-----w- c:\program files\Apple Software Update
2010-12-25 17:50 . 2010-09-28 21:44 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-12-25 17:50 . 2010-09-28 21:44 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-12-25 17:49 . 2010-12-25 17:49 -------- d-----w- c:\program files\Bonjour
2010-12-25 17:48 . 2010-12-25 18:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-12-25 17:48 . 2010-12-25 17:57 -------- d-----w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 23:38 . 2010-11-29 23:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 23:38 . 2010-11-29 23:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:12 . 2010-11-18 18:12 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2010-11-09 14:52 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-10-28 13:13 . 2010-10-28 13:13 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2010-10-26 13:25 1853312 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-01-16_15.54.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-19 04:10 . 2011-01-19 04:10 16384 c:\windows\temp\Perflib_Perfdata_700.dat
- 2008-04-15 12:00 . 2008-04-15 12:00 75776 c:\windows\system32\strmfilt.dll
+ 2009-10-21 05:38 . 2009-10-21 05:38 75776 c:\windows\system32\strmfilt.dll
+ 2010-08-27 05:57 . 2010-08-27 05:57 99840 c:\windows\system32\srvsvc.dll
+ 2009-04-11 02:06 . 2011-01-19 04:12 69172 c:\windows\system32\perfc009.dat
- 2009-04-11 02:06 . 2011-01-15 22:33 69172 c:\windows\system32\perfc009.dat
+ 2009-10-21 05:38 . 2009-10-21 05:38 25088 c:\windows\system32\httpapi.dll
+ 2009-10-21 05:38 . 2009-10-21 05:38 75776 c:\windows\system32\dllcache\strmfilt.dll
+ 2010-08-27 05:57 . 2010-08-27 05:57 99840 c:\windows\system32\dllcache\srvsvc.dll
+ 2009-10-21 05:38 . 2009-10-21 05:38 25088 c:\windows\system32\dllcache\httpapi.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\46ef15b88ef577de4882c519329fc5d2\System.Windows.Presentation.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\70ee6267f7bad40e8707d402277770c3\System.Web.DynamicData.Design.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\5e5176efbfeb803b7f217525beec6844\Microsoft.Vsa.ni.dll
- 2011-01-13 02:18 . 2010-08-13 12:53 5120 c:\windows\system32\xpsp4res.dll
+ 2010-08-26 12:52 . 2010-08-26 12:52 5120 c:\windows\system32\xpsp4res.dll
+ 2009-08-25 09:17 . 2009-08-25 09:17 354816 c:\windows\system32\winhttp.dll
- 2009-04-11 02:06 . 2011-01-15 22:33 434966 c:\windows\system32\perfh009.dat
+ 2009-04-11 02:06 . 2011-01-19 04:12 434966 c:\windows\system32\perfh009.dat
+ 2010-06-09 07:43 . 2010-06-09 07:43 692736 c:\windows\system32\inetcomm.dll
+ 2010-08-26 13:39 . 2010-08-26 13:39 357248 c:\windows\system32\drivers\srv.sys
+ 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\drivers\http.sys
+ 2009-08-25 09:17 . 2009-08-25 09:17 354816 c:\windows\system32\dllcache\winhttp.dll
+ 2010-08-26 13:39 . 2010-08-26 13:39 357248 c:\windows\system32\dllcache\srv.sys
+ 2010-06-09 07:43 . 2010-06-09 07:43 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys
+ 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\Driver Cache\i386\http.sys
+ 2011-01-16 16:20 . 2011-01-16 16:20 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\ff53d5b5249a2841ee196294429f51cf\System.Xml.Linq.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\7f9a1ae146571025fd49914b5c71a39b\System.Web.Routing.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\b1646e54b708b9824f4193f87eb00c0e\System.Web.Extensions.Design.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\504a93e73da77c502ecf98bfdfc1485e\System.Web.Entity.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f22334fbd9497d79448fffef515ae0cc\System.Web.Entity.Design.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\af5452305588da228a74e30324681d20\System.Web.DynamicData.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\9d9bca1a8993c427984aa1bc9c165a33\System.Web.Abstractions.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\2a080994f308f347b0497bb8804861cf\System.Net.ni.dll
+ 2011-01-16 16:20 . 2011-01-16 16:20 593408 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\97bd2a5d946aa3a824e4cfe5b6ef95aa\System.Messaging.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\bc1cf48ba7dc00f45d0e949c49ab677a\System.Management.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\904fda53006680a67f917ab638be0305\System.Management.Instrumentation.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\849e98c9f428a12cb581320a23f69dbd\System.DirectoryServices.AccountManagement.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\ad95820d2e29e8d55c0d8a838214c6e5\System.Data.Services.Design.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\617acb0d900bdde947ec79f7b5ccc183\System.Data.Services.Client.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\165bd290e518b9397ca55192985fdee3\System.Data.Entity.Design.ni.dll
+ 2011-01-16 16:20 . 2011-01-16 16:20 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\bec60fe2e934a6284224ab45b0e981e2\System.WorkflowServices.ni.dll
+ 2011-01-16 16:20 . 2011-01-16 16:20 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\09da139c48e2f5e76994a5c0f2e5b19e\System.Workflow.Runtime.ni.dll
+ 2011-01-16 16:20 . 2011-01-16 16:20 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\6809417da74ff937e18b3034f1eac2f2\System.Workflow.ComponentModel.ni.dll
+ 2011-01-16 16:20 . 2011-01-16 16:20 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\6c91ee82035d30efa8893e7b0396bbb0\System.Workflow.Activities.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4200f716e9a41cb91d17516ba864e586\System.Web.Mobile.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\da367bc2ecf2c9c5b4f858b6dba9e2ea\System.Web.Extensions.ni.dll
+ 2011-01-16 16:19 . 2011-01-16 16:19 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\8e34e273d036b7468fc4e951a1fde437\System.ServiceModel.Web.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\b8c9267d87b7358e1a5f00bf1572c313\System.Data.Services.ni.dll
+ 2011-01-16 16:17 . 2011-01-16 16:18 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6ce886492d9b6a34555be3f328682ec2\System.Data.Entity.ni.dll
+ 2011-01-16 16:18 . 2011-01-16 16:18 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\16ff33f07efdb9da2a18e27585c604be\Microsoft.JScript.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00Zecter]
@="{D25B32FE-CB96-491A-98FF-AD59DA382D69}"
[HKEY_CLASSES_ROOT\CLSID\{D25B32FE-CB96-491A-98FF-AD59DA382D69}]
2010-03-28 22:22 718848 ----a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\01Zecter]
@="{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}"
[HKEY_CLASSES_ROOT\CLSID\{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}]
2010-03-28 22:22 718848 ----a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\02Zecter]
@="{B3C78E40-6B64-47C3-AE34-60B770881EB8}"
[HKEY_CLASSES_ROOT\CLSID\{B3C78E40-6B64-47C3-AE34-60B770881EB8}]
2010-03-28 22:22 718848 ----a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\03Zecter]
@="{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}"
[HKEY_CLASSES_ROOT\CLSID\{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}]
2010-03-28 22:22 718848 ----a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\04Zecter]
@="{855156F0-2A0F-11DE-8C30-0800200C9A66}"
[HKEY_CLASSES_ROOT\CLSID\{855156F0-2A0F-11DE-8C30-0800200C9A66}]
2010-03-28 22:22 718848 ----a-w- c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe" [2010-04-05 8192]
"ZumoDrive"="c:\program files\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk" [2010-12-25 1733]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Skyhook Wireless XPS Service"="c:\program files\Skyhook Wireless\XPS\xpscontrolpanel.exe" [2010-04-02 632136]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-11-17 141336]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0369.0\mswinext.exe" [2009-11-30 240472]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-11-17 141336]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-11-17 173592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"@OnlineArmor GUI"="c:\program files\Online Armor\oaui.exe" [2010-11-03 2345000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Media Suite.lnk - c:\program files\Hewlett-Packard\HP Media Suite\Home\ArcStart.exe [2010-4-1 91648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2010-11-03 353992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Hewlett-Packard\\HP CloudDrive\\zumodrive.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:UDP"= 5353:UDP:Java(TM) Platform SE binary
"8182:TCP"= 8182:TCP:Java(TM) Platform SE binary
R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [8/26/2010 10:26 PM 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [8/26/2010 10:26 PM 15856]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1107000.00C\symds.sys [1/12/2011 8:22 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1107000.00C\symefa.sys [1/12/2011 8:22 PM 173104]
R0 SysCow;SysCow;c:\windows\system32\drivers\syscow32x.sys [12/28/2009 12:17 AM 106096]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20101123.003\BHDrvx86.sys [11/23/2010 3:34 AM 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1107000.00C\cchpx86.sys [1/12/2011 8:22 PM 501888]
R1 DVMIO;DeviceVM IO Service;c:\windows\system32\drivers\dvmio.sys [11/11/2009 2:09 PM 18136]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [1/11/2011 1:47 PM 202064]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [1/11/2011 1:47 PM 38856]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [1/11/2011 1:47 PM 25000]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [1/11/2011 1:47 PM 29272]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [8/26/2010 10:26 PM 25584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1107000.00C\ironx86.sys [1/12/2011 8:22 PM 116784]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 8:05 PM 457200]
R2 BOTService;BOTService;c:\program files\Roxio\BackOnTrack\Instant Restore\BOTService.exe [2/4/2010 3:00 PM 211440]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\swsetup\QuickWeb\QW.SYS\config\DVMExportService.exe [4/12/2010 8:37 PM 338168]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [4/5/2010 12:12 PM 103992]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe [1/12/2011 8:22 PM 126392]
R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [1/11/2011 1:47 PM 380784]
R2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [1/11/2011 1:47 PM 3652696]
R2 xpssvc;Skyhook Wireless XPS Service;c:\program files\Skyhook Wireless\XPS\xpssvc.exe [4/1/2010 8:04 PM 699720]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [8/26/2010 9:06 PM 113664]
R3 Cam3820;Cam3820 PC Camera Driver;c:\windows\system32\drivers\cam3820a.sys [12/25/2010 4:11 PM 363904]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/26/2010 9:10 PM 227896]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [1/12/2011 8:24 PM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20110114.002\IDSXpx86.sys [1/15/2011 2:57 PM 341944]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\drivers\RtsPStor.sys [8/26/2010 9:08 PM 230944]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [12/25/2010 4:11 PM 1323296]
R3 XPSVCOM;XPSVCOM;c:\windows\system32\drivers\XPSVCOM.sys [2/4/2010 12:07 AM 12416]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4FB2AA7C-C8E4-BBC8-BB1C-FAAB2EF5914B}]
2010-03-26 23:27 200769 ----a-w- c:\program files\Hewlett-Packard\HP Media Suite\Home\QuickLaunch.exe
.
Contents of the 'Scheduled Tasks' folder
2010-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 17:50]
2011-01-19 c:\windows\Tasks\BackOnTrack Instant Restore Idle.job
- c:\program files\Roxio\BackOnTrack\Instant Restore\RstIdle.exe [2010-02-04 21:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-18 22:11
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\SEP2.tmp 0 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.7.0.12\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(492)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2128)
c:\windows\system32\WININET.dll
c:\program files\Hewlett-Packard\HP CloudDrive\ShellExt.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\idt\wdm\STacSV.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\system32\wscntfy.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Online Armor\OAhlp.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
.
**************************************************************************
.
Completion time: 2011-01-18 22:24:21 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-19 04:24
ComboFix2.txt 2011-01-16 16:04
Pre-Run: 138,545,422,336 bytes free
Post-Run: 138,634,129,408 bytes free
- - End Of File - - CE4854CFD9A22F34F22F584A53EAA59C
GMER 1.0.15.15530 -
http://www.gmer.netRootkit scan 2011-01-19 06:13:29
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST916031 rev.0001
Running: gmer.exe; Driver: C:\DOCUME~1\jocey\LOCALS~1\Temp\pxlcypow.sys
---- System - GMER 1.0.15 ----
SSDT 857EDB30 ZwAlertResumeThread
SSDT 85E8DA78 ZwAlertThread
SSDT 85821738 ZwAllocateVirtualMemory
SSDT 8619DE40 ZwAssignProcessToJobObject
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwConnectPort [0x9E6FB64C]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateFile [0x9E7021F8]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA2FC9210]
SSDT 851987B8 ZwCreateMutant
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreatePort [0x9E6FB46A]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcess [0x9E6FCDE4]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcessEx [0x9E6F9978]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateSection [0x9E6F94F2]
SSDT 8520A9B8 ZwCreateSymbolicLinkObject
SSDT 850B81A8 ZwCreateThread
SSDT 86168E40 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA2FC9490]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA2FC99F0]
SSDT 85821910 ZwDuplicateObject
SSDT 857E5DB8 ZwFreeVirtualMemory
SSDT 851B1628 ZwImpersonateAnonymousToken
SSDT 85F771B8 ZwImpersonateThread
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwLoadDriver [0x9E6FC24C]
SSDT 8582E450 ZwMapViewOfSection
SSDT 851C7628 ZwOpenEvent
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenFile [0x9E702554]
SSDT 852438B0 ZwOpenProcess
SSDT 85189630 ZwOpenProcessToken
SSDT 85242628 ZwOpenSection
SSDT 852437A0 ZwOpenThread
SSDT 8520E9B8 ZwProtectVirtualMemory
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwQueueApcThread [0x9E6FC940]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRequestPort [0x9E6FBCB0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRequestWaitReplyPort [0x9E6FBF14]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRestoreKey [0x9E701FF0]
SSDT 85E85C70 ZwResumeThread
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSecureConnectPort [0x9E6FB86E]
SSDT 851E0630 ZwSetContextThread
SSDT 8582E238 ZwSetInformationProcess
SSDT 857A6C30 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA2FC9C40]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwShutdownSystem [0x9E6FC186]
SSDT 8521F628 ZwSuspendProcess
SSDT 85240630 ZwSuspendThread
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSystemDebugControl [0x9E6FAE40]
SSDT 85180630 ZwTerminateProcess
SSDT 851E8630 ZwTerminateThread
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwUnloadDriver [0x9E6FC414]
SSDT 851BF630 ZwUnmapViewOfSection
SSDT 85062DC0 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2C9C 80504538 12 Bytes [6A, B4, 6F, 9E, E4, CD, 6F, ...] {PUSH -0x4c; OUTSD ; SAHF ; IN AL, 0xcd; OUTSD ; SAHF ; JS 0xffffffffffffffa3; OUTSD ; SAHF }
.text ntkrnlpa.exe!ZwCallbackReturn + 2E08 805046A4 4 Bytes JMP 683CCBC9
.text ntkrnlpa.exe!ZwCallbackReturn + 2FD8 80504874 12 Bytes [28, F6, 21, 85, 30, 06, 24, ...] {SUB DH, DH; AND [EBP-0x7adbf9d0], EAX; INC EAX; SCASB ; OUTSD ; SAHF }
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
? C:\ComboFix\catchme.sys The system cannot find the path specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] ntdll.dll!NtCreateSymbolicLinkObject 7C90D19E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] ntdll.dll!NtCreateSymbolicLinkObject + 4 7C90D1A2 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] ntdll.dll!NtOpenFile 7C90D59E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] ntdll.dll!NtOpenFile + 4 7C90D5A2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AA0001
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] KERNEL32.dll!LoadLibraryA 7C801D7B 6 Bytes JMP 71720F5A
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] KERNEL32.dll!CreateProcessW 7C802336 6 Bytes JMP 71A20F5A
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] KERNEL32.dll!CreateProcessA 7C80236B 6 Bytes JMP 71A50F5A
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] KERNEL32.dll!CloseHandle 7C809BE7 6 Bytes JMP 71960F5A
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] KERNEL32.dll!LoadLibraryW 7C80AEEB 6 Bytes JMP 716F0F5A
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] KERNEL32.dll!CreateFileW 7C810800 6 Bytes JMP 71990F5A
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] user32.dll!RegisterHotKey 7E41EBB3 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] user32.dll!RegisterHotKey + 4 7E41EBB7 2 Bytes [89, 71]
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] user32.dll!ExitWindowsEx 7E45A275 6 Bytes JMP 719F0F5A
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] user32.dll!DdeClientTransaction 7E46A6A2 6 Bytes JMP 718D0F5A
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] user32.dll!RegisterRawInputDevices 7E46CE0E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] user32.dll!RegisterRawInputDevices + 4 7E46CE12 2 Bytes [86, 71]
.text C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe[2288] GDI32.dll!DeleteDC 77F16E5F 6 Bytes JMP 717E0F5A
.tex