Hi,
Need assistance to remove "Incredibar" please.
Logs:
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.11.03
Windows XP Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: IBM-4E642AA635C [administrator]
2/11/2012 10:55:47 PM
mbam-log-2012-02-11 (22-55-47).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 186124
Time elapsed: 11 minute(s), 23 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Documents and Settings\Administrator\Desktop\DownloadSetup.exe (Affiliate.Downloader) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-13 15:30:32
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HTS548040M9AT00 rev.MG2OA5BA
Running: 2drordz9.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uwxiikob.sys
---- System - GMER 1.0.15 ----
SSDT F8BB9114 ZwClose
SSDT F8BB90CE ZwCreateKey
SSDT F8BB911E ZwCreateSection
SSDT F8BB90C4 ZwCreateThread
SSDT F8BB90D3 ZwDeleteKey
SSDT F8BB90DD ZwDeleteValueKey
SSDT F8BB910F ZwDuplicateObject
SSDT F8BB90E2 ZwLoadKey
SSDT F8BB90B0 ZwOpenProcess
SSDT F8BB90B5 ZwOpenThread
SSDT F8BB90EC ZwReplaceKey
SSDT F8BB90E7 ZwRestoreKey
SSDT F8BB9123 ZwSetContextThread
SSDT F8BB90D8 ZwSetValueKey
SSDT F8BB90BF ZwTerminateProcess
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegCreateKeyExA] [00408A00] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [004078D0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [00408A00] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [004078D0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [004078D0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenUserClassesRoot] [004086A0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [004078D0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Administrator at 15:36:23 on 2012-02-13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.147 [GMT 11:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Cisco Systems\Aironet Client Monitor\ACUMon.Exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: BFlix Class: {0c9f4179-6ce2-4c6a-a3e5-67ff3592a12e} - c:\program files\bflix\BFlix.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Incredibar.com Helper Object: {6e13dde1-2b6e-46ce-8b66-dc8bf36f6b99} - c:\program files\incredibar.com\incredibar\1.5.3.27\bh\incredibar.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Incredibar Toolbar: {f9639e4a-801b-4843-aee3-03d9da199e77} - c:\program files\incredibar.com\incredibar\1.5.3.27\incredibarTlbr.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe" -NoStart
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [PRONoMgr.exe] c:\program files\intel\ncs\proset\PRONoMgr.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ACUMon] "c:\program files\cisco systems\aironet client monitor\ACUMon.Exe" -a
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE
mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor
mRun: [BLOG] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Nero MediaHome 4] "c:\program files\nero\nero mediahome 4\NeroMediaHome.exe" /AUTORUN
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\documents and settings\administrator\desktop\PartyPoker.lnk
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.fujifilmimagine.com/imagine/ax/ImageUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1299310973505
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{4365D515-1E78-4F11-ABA8-11120F730D3F} : DhcpNameServer = 192.168.2.1
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-3-17 11608]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2008-8-21 16384]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-3-17 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-3-17 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-3-17 66616]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2010-6-1 367456]
S3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family Driver;c:\windows\system32\drivers\cben5.sys [2006-11-30 46108]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-12-6 18432]
S3 PCX504;Cisco Systems Wireless LAN Adapter Driver;c:\windows\system32\drivers\PCX504.sys [2006-12-8 119296]
.
=============== Created Last 30 ================
.
2012-02-11 11:53:19 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes
2012-02-11 11:52:20 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-02-11 11:52:14 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-11 11:52:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-10 10:20:41 -------- d-----w- c:\documents and settings\administrator\application data\Incredibar.com
2012-02-10 10:19:58 -------- d-----w- c:\program files\BFlix
2012-02-10 10:19:23 -------- d-----w- c:\program files\Incredibar.com
2012-02-10 10:17:04 -------- d-----w- c:\documents and settings\all users\application data\100
2012-02-10 10:17:02 -------- d-----w- c:\documents and settings\all users\application data\InstallMate
2012-02-05 09:18:15 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Nero
2012-02-05 09:13:06 -------- d-----w- c:\program files\Nero
2012-02-05 09:12:46 -------- d-----w- c:\documents and settings\all users\application data\Nero
2012-01-19 06:24:17 -------- d-----w- C:\a6cf2f781aae66c5528c7397822a18
2012-01-19 06:00:22 -------- d-----w- c:\windows\system32\XPSViewer
2012-01-19 05:58:50 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2012-01-19 05:58:18 14048 ------w- c:\windows\system32\spmsg2.dll
2012-01-19 05:55:37 -------- d-----w- c:\program files\Navman
.
==================== Find3M ====================
.
.
============= FINISH: 15:37:35.55 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 11/30/2006 10:15:25 AM
System Uptime: 2/13/2012 1:10:50 PM (2 hours ago)
.
Motherboard: IBM | | 23747FM
Processor: Intel(R) Pentium(R) M processor 1600MHz | None | 1594/400mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 37 GiB total, 8.674 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP66: 11/23/2011 2:29:39 PM - System Checkpoint
RP67: 11/28/2011 6:14:33 PM - System Checkpoint
RP68: 12/1/2011 4:57:57 PM - System Checkpoint
RP69: 12/2/2011 7:58:46 PM - System Checkpoint
RP70: 12/4/2011 2:08:44 PM - System Checkpoint
RP71: 12/5/2011 5:06:14 PM - System Checkpoint
RP72: 12/6/2011 5:21:50 PM - Removed Apple Application Support
RP73: 12/6/2011 5:23:57 PM - Removed Apple Mobile Device Support
RP74: 12/10/2011 10:49:41 AM - System Checkpoint
RP75: 12/13/2011 9:29:45 AM - System Checkpoint
RP76: 12/14/2011 6:59:51 PM - System Checkpoint
RP77: 12/15/2011 11:22:09 AM - Software Distribution Service 3.0
RP78: 12/16/2011 11:33:56 AM - System Checkpoint
RP79: 12/17/2011 4:28:15 PM - Installed Windows XP Wdf01009.
RP80: 12/18/2011 4:03:45 PM - Software Distribution Service 3.0
RP81: 12/21/2011 2:03:18 PM - System Checkpoint
RP82: 12/28/2011 10:38:22 AM - Installed Java(TM) 6 Update 30
RP83: 12/29/2011 7:48:52 PM - System Checkpoint
RP84: 1/5/2012 3:36:48 PM - System Checkpoint
RP85: 1/8/2012 8:09:14 AM - System Checkpoint
RP86: 1/10/2012 10:48:36 AM - System Checkpoint
RP87: 1/13/2012 3:15:22 PM - System Checkpoint
RP88: 1/13/2012 8:51:50 PM - Removed Adobe Reader 9.4.7.
RP89: 1/17/2012 9:47:17 PM - System Checkpoint
RP90: 1/19/2012 4:53:55 PM - Installed NavDesk 2009
RP91: 1/19/2012 4:55:57 PM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
RP92: 1/19/2012 4:57:38 PM - Installed Windows XP WIC.
RP93: 1/19/2012 4:58:18 PM - Installed %1 %2.
RP94: 1/19/2012 4:58:30 PM - Printer Driver Microsoft XPS Document Writer Installed
RP95: 1/19/2012 5:26:09 PM - Installed Windows KB954550-v5.
RP96: 1/19/2012 5:28:21 PM - Printer Driver Microsoft XPS Document Writer Installed
RP97: 1/26/2012 8:40:37 AM - Printer Driver Microsoft XPS Document Writer Installed
RP98: 1/31/2012 12:11:14 PM - System Checkpoint
RP99: 2/5/2012 8:11:02 PM - Installed Nero MediaHome 4 Essentials 4.4.8.1
RP100: 2/10/2012 7:17:11 PM - System Checkpoint
RP101: 2/12/2012 9:17:50 AM - System Checkpoint
RP102: 2/13/2012 3:26:25 PM - System Checkpoint
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.5.0
Advertising Center
Agere Systems AC'97 Modem
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
Avira AntiVir Personal - Free Antivirus
BFlix
Bonjour
Cisco Aironet Installation Wizard
DivX Setup
e-tax 2011
FrostWire 4.21.7
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB981793)
IBM ThinkPad Battery MaxiMiser and Power Management Features
Incredibar Toolbar on IE and Chrome
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet
Intel(R) Sebring API
iPod To Computer Transfer 6.6
iTunes
Java Auto Updater
Java(TM) 6 Update 30
Malwarebytes Anti-Malware version 1.60.1.1000
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB925673)
Nero ControlCenter
Nero Installer
Nero MediaHome 4
Nero MediaHome 4 Essentials
Nero MediaHome 4 Help
Nero Online Upgrade
OLYMPUS Master 2
PartyPoker
PMB
PowerDVD
QuickTime
Realtek AC'97 Audio
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Spybot - Search & Destroy
ThinkPad Power Management Driver
ThinkPad Wireless LAN Adapters Software (11a/b, 11b/g, 11a/b/g)
Ultimate Mahjongg 5
Unwired
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB898461)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.6195
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
XML Paper Specification Shared Components Pack 1.0
.
==== Event Viewer Messages From Past Week ========
.
2/9/2012 11:40:20 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service.
2/13/2012 2:38:10 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
2/11/2012 9:47:17 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Nero MediaHome 4 Service service to connect.
2/11/2012 9:47:17 PM, error: Service Control Manager [7000] - The Nero MediaHome 4 Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/11/2012 11:12:06 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
2/11/2012 10:28:44 PM, error: PSched [14103] - QoS [Adapter {4365D515-1E78-4F11-ABA8-11120F730D3F}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.
.
==== End Of File ===========================
Need assistance to remove "Incredibar" please.
Logs:
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.11.03
Windows XP Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: IBM-4E642AA635C [administrator]
2/11/2012 10:55:47 PM
mbam-log-2012-02-11 (22-55-47).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 186124
Time elapsed: 11 minute(s), 23 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Documents and Settings\Administrator\Desktop\DownloadSetup.exe (Affiliate.Downloader) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-13 15:30:32
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HTS548040M9AT00 rev.MG2OA5BA
Running: 2drordz9.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uwxiikob.sys
---- System - GMER 1.0.15 ----
SSDT F8BB9114 ZwClose
SSDT F8BB90CE ZwCreateKey
SSDT F8BB911E ZwCreateSection
SSDT F8BB90C4 ZwCreateThread
SSDT F8BB90D3 ZwDeleteKey
SSDT F8BB90DD ZwDeleteValueKey
SSDT F8BB910F ZwDuplicateObject
SSDT F8BB90E2 ZwLoadKey
SSDT F8BB90B0 ZwOpenProcess
SSDT F8BB90B5 ZwOpenThread
SSDT F8BB90EC ZwReplaceKey
SSDT F8BB90E7 ZwRestoreKey
SSDT F8BB9123 ZwSetContextThread
SSDT F8BB90D8 ZwSetValueKey
SSDT F8BB90BF ZwTerminateProcess
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegCreateKeyExA] [00408A00] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [004078D0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [00408A00] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [004078D0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00407760] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [004078D0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegOpenUserClassesRoot] [004086A0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExA] [00408D70] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegCreateKeyExW] [00408BF0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegCloseKey] [00408900] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!RegOpenKeyExW] [00408F20] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [00407960] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [004078D0] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
IAT C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe[472] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [00407980] C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe (Nero MediaHome/Nero AG)
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Administrator at 15:36:23 on 2012-02-13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.147 [GMT 11:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Cisco Systems\Aironet Client Monitor\ACUMon.Exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: BFlix Class: {0c9f4179-6ce2-4c6a-a3e5-67ff3592a12e} - c:\program files\bflix\BFlix.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Incredibar.com Helper Object: {6e13dde1-2b6e-46ce-8b66-dc8bf36f6b99} - c:\program files\incredibar.com\incredibar\1.5.3.27\bh\incredibar.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Incredibar Toolbar: {f9639e4a-801b-4843-aee3-03d9da199e77} - c:\program files\incredibar.com\incredibar\1.5.3.27\incredibarTlbr.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe" -NoStart
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [PRONoMgr.exe] c:\program files\intel\ncs\proset\PRONoMgr.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ACUMon] "c:\program files\cisco systems\aironet client monitor\ACUMon.Exe" -a
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE
mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor
mRun: [BLOG] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Nero MediaHome 4] "c:\program files\nero\nero mediahome 4\NeroMediaHome.exe" /AUTORUN
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\documents and settings\administrator\desktop\PartyPoker.lnk
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.fujifilmimagine.com/imagine/ax/ImageUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1299310973505
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{4365D515-1E78-4F11-ABA8-11120F730D3F} : DhcpNameServer = 192.168.2.1
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-3-17 11608]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2008-8-21 16384]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-3-17 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-3-17 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-3-17 66616]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2010-6-1 367456]
S3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family Driver;c:\windows\system32\drivers\cben5.sys [2006-11-30 46108]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-12-6 18432]
S3 PCX504;Cisco Systems Wireless LAN Adapter Driver;c:\windows\system32\drivers\PCX504.sys [2006-12-8 119296]
.
=============== Created Last 30 ================
.
2012-02-11 11:53:19 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes
2012-02-11 11:52:20 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-02-11 11:52:14 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-11 11:52:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-10 10:20:41 -------- d-----w- c:\documents and settings\administrator\application data\Incredibar.com
2012-02-10 10:19:58 -------- d-----w- c:\program files\BFlix
2012-02-10 10:19:23 -------- d-----w- c:\program files\Incredibar.com
2012-02-10 10:17:04 -------- d-----w- c:\documents and settings\all users\application data\100
2012-02-10 10:17:02 -------- d-----w- c:\documents and settings\all users\application data\InstallMate
2012-02-05 09:18:15 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Nero
2012-02-05 09:13:06 -------- d-----w- c:\program files\Nero
2012-02-05 09:12:46 -------- d-----w- c:\documents and settings\all users\application data\Nero
2012-01-19 06:24:17 -------- d-----w- C:\a6cf2f781aae66c5528c7397822a18
2012-01-19 06:00:22 -------- d-----w- c:\windows\system32\XPSViewer
2012-01-19 05:58:50 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2012-01-19 05:58:18 14048 ------w- c:\windows\system32\spmsg2.dll
2012-01-19 05:55:37 -------- d-----w- c:\program files\Navman
.
==================== Find3M ====================
.
.
============= FINISH: 15:37:35.55 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 11/30/2006 10:15:25 AM
System Uptime: 2/13/2012 1:10:50 PM (2 hours ago)
.
Motherboard: IBM | | 23747FM
Processor: Intel(R) Pentium(R) M processor 1600MHz | None | 1594/400mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 37 GiB total, 8.674 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP66: 11/23/2011 2:29:39 PM - System Checkpoint
RP67: 11/28/2011 6:14:33 PM - System Checkpoint
RP68: 12/1/2011 4:57:57 PM - System Checkpoint
RP69: 12/2/2011 7:58:46 PM - System Checkpoint
RP70: 12/4/2011 2:08:44 PM - System Checkpoint
RP71: 12/5/2011 5:06:14 PM - System Checkpoint
RP72: 12/6/2011 5:21:50 PM - Removed Apple Application Support
RP73: 12/6/2011 5:23:57 PM - Removed Apple Mobile Device Support
RP74: 12/10/2011 10:49:41 AM - System Checkpoint
RP75: 12/13/2011 9:29:45 AM - System Checkpoint
RP76: 12/14/2011 6:59:51 PM - System Checkpoint
RP77: 12/15/2011 11:22:09 AM - Software Distribution Service 3.0
RP78: 12/16/2011 11:33:56 AM - System Checkpoint
RP79: 12/17/2011 4:28:15 PM - Installed Windows XP Wdf01009.
RP80: 12/18/2011 4:03:45 PM - Software Distribution Service 3.0
RP81: 12/21/2011 2:03:18 PM - System Checkpoint
RP82: 12/28/2011 10:38:22 AM - Installed Java(TM) 6 Update 30
RP83: 12/29/2011 7:48:52 PM - System Checkpoint
RP84: 1/5/2012 3:36:48 PM - System Checkpoint
RP85: 1/8/2012 8:09:14 AM - System Checkpoint
RP86: 1/10/2012 10:48:36 AM - System Checkpoint
RP87: 1/13/2012 3:15:22 PM - System Checkpoint
RP88: 1/13/2012 8:51:50 PM - Removed Adobe Reader 9.4.7.
RP89: 1/17/2012 9:47:17 PM - System Checkpoint
RP90: 1/19/2012 4:53:55 PM - Installed NavDesk 2009
RP91: 1/19/2012 4:55:57 PM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
RP92: 1/19/2012 4:57:38 PM - Installed Windows XP WIC.
RP93: 1/19/2012 4:58:18 PM - Installed %1 %2.
RP94: 1/19/2012 4:58:30 PM - Printer Driver Microsoft XPS Document Writer Installed
RP95: 1/19/2012 5:26:09 PM - Installed Windows KB954550-v5.
RP96: 1/19/2012 5:28:21 PM - Printer Driver Microsoft XPS Document Writer Installed
RP97: 1/26/2012 8:40:37 AM - Printer Driver Microsoft XPS Document Writer Installed
RP98: 1/31/2012 12:11:14 PM - System Checkpoint
RP99: 2/5/2012 8:11:02 PM - Installed Nero MediaHome 4 Essentials 4.4.8.1
RP100: 2/10/2012 7:17:11 PM - System Checkpoint
RP101: 2/12/2012 9:17:50 AM - System Checkpoint
RP102: 2/13/2012 3:26:25 PM - System Checkpoint
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.5.0
Advertising Center
Agere Systems AC'97 Modem
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
Avira AntiVir Personal - Free Antivirus
BFlix
Bonjour
Cisco Aironet Installation Wizard
DivX Setup
e-tax 2011
FrostWire 4.21.7
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB981793)
IBM ThinkPad Battery MaxiMiser and Power Management Features
Incredibar Toolbar on IE and Chrome
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet
Intel(R) Sebring API
iPod To Computer Transfer 6.6
iTunes
Java Auto Updater
Java(TM) 6 Update 30
Malwarebytes Anti-Malware version 1.60.1.1000
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB925673)
Nero ControlCenter
Nero Installer
Nero MediaHome 4
Nero MediaHome 4 Essentials
Nero MediaHome 4 Help
Nero Online Upgrade
OLYMPUS Master 2
PartyPoker
PMB
PowerDVD
QuickTime
Realtek AC'97 Audio
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Spybot - Search & Destroy
ThinkPad Power Management Driver
ThinkPad Wireless LAN Adapters Software (11a/b, 11b/g, 11a/b/g)
Ultimate Mahjongg 5
Unwired
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB898461)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.6195
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
XML Paper Specification Shared Components Pack 1.0
.
==== Event Viewer Messages From Past Week ========
.
2/9/2012 11:40:20 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service.
2/13/2012 2:38:10 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
2/11/2012 9:47:17 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Nero MediaHome 4 Service service to connect.
2/11/2012 9:47:17 PM, error: Service Control Manager [7000] - The Nero MediaHome 4 Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/11/2012 11:12:06 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
2/11/2012 10:28:44 PM, error: PSched [14103] - QoS [Adapter {4365D515-1E78-4F11-ABA8-11120F730D3F}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.
.
==== End Of File ===========================