Here is DDS Log:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.5.1
Run by Ace Ducey at 20:23:47 on 2012-07-24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2246 [GMT -7:00]
.
AV: Panda Cloud Antivirus *Enabled/Updated* {5AD27692-540A-464E-B625-78275FA38393}
.
============== Running Processes ===============
.
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
F:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\system32\devldr32.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
F:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://isearch.avg.com/?cid={FCD82787-2558-4015-8507-585D13950717}&mid=82ad155a80a447d08851d145b71e0489-e2dd74a8a5f86ed4734d82507fa9f649d27771e8&lang=en&ds=gm011&pr=sa&d=2012-04-24 23:10:49&v=11.0.0.9&sap=hp
uInternet Settings,ProxyOverride = *.local
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [Steam] "f:\program files\steam\steam.exe" -silent
mRun: [USRpdA] c:\windows\system32\usrmlnka.exe runservices \device\3cpipe-USRpdA
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [PSUNMain] "f:\program files\panda security\panda cloud antivirus\PSUNMain.exe" /Traybar
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
IE: Free YouTube Download - c:\documents and settings\ace ducey\application data\dvdvideosoftiehelpers\freeyoutubedownload.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\ace ducey\application data\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1302597116812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{5AD40C12-AB1F-4132-AF3C-C02795098365} : DhcpNameServer = 75.75.75.75 75.75.76.76
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\ace ducey\application data\mozilla\firefox\profiles\skwwuu8z.default-1342677914089\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - plugin: f:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: f:\program files\real alternative\browser\plugins\nppl3260.dll
FF - plugin: f:\program files\real alternative\browser\plugins\nprpjplug.dll
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-5-2 218688]
R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [2011-11-23 130312]
R2 NanoServiceMain;Panda Cloud Antivirus Service;f:\program files\panda security\panda cloud antivirus\PSANHost.exe [2011-4-28 140608]
R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [2012-1-5 144008]
R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [2011-4-28 97096]
R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [2011-4-28 111688]
R2 PSINProt;PSINProt;c:\windows\system32\drivers\PSINProt.sys [2011-11-30 112648]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-20 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-20 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-6-7 113120]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [2011-5-3 223128]
.
=============== Created Last 30 ================
.
2012-07-25 02:59:53 -------- d-----w- c:\documents and settings\ace ducey\local settings\application data\Sun
2012-07-24 15:55:33 2106216 ----a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2012-07-24 15:55:33 18912 ----a-w- c:\program files\mozilla firefox\AccessibleMarshal.dll
2012-07-24 15:55:33 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2012-07-24 15:55:32 117728 ----a-w- c:\program files\mozilla firefox\crashreporter.exe
2012-07-24 03:21:28 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-07-23 22:44:09 -------- d-sha-r- C:\cmdcons
2012-07-23 22:41:28 98816 ----a-w- c:\windows\sed.exe
2012-07-23 22:41:28 518144 ----a-w- c:\windows\SWREG.exe
2012-07-23 22:41:28 256000 ----a-w- c:\windows\PEV.exe
2012-07-23 22:41:28 208896 ----a-w- c:\windows\MBR.exe
2012-07-23 22:36:52 -------- d-----w- c:\windows\system32\appmgmt
2012-07-19 05:55:55 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-07-19 05:55:55 -------- d-----w- c:\windows\system32\wbem\Repository
2012-07-19 05:41:50 -------- d-----w- c:\program files\Oracle
.
==================== Find3M ====================
.
2012-07-16 20:31:53 2011424 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSUNConsole.dll
2012-07-16 18:53:06 3387680 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSUNPnlConfig.dll
2012-07-16 18:29:29 101928 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\system32\drivers\vista_w7\PSINReg.sys
2012-07-16 18:29:23 112680 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\system64\drivers\vista_w7\PSINReg.sys
2012-07-16 18:29:18 102824 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\system32\drivers\xp\PSINReg.sys
2012-07-13 22:38:49 45856 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskalloc.dll
2012-07-13 20:07:14 174880 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSUASysTray.dll
2012-07-13 14:16:26 63776 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSUATranslator.dll
2012-07-13 14:16:26 55584 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSUAUtils.dll
2012-07-13 14:16:26 54560 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSUAWatchdog.dll
2012-07-13 14:16:25 102176 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSUASystrayObject.dll
2012-07-13 14:16:21 237856 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\x64\PSUAShell.dll
2012-07-13 14:16:17 98592 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\x86\PSUAShell.dll
2012-07-13 14:07:06 85792 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSNCGP64.dll
2012-07-13 14:07:06 80672 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\x64\PSNCSysAction.exe
2012-07-13 14:07:06 189216 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSNCIPC64.dll
2012-07-13 14:07:01 18720 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\x86\PSNCSysAction.exe
2012-07-13 14:03:57 336160 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSANCU.exe
2012-07-13 14:03:43 79648 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSANUpgSI.dll
2012-07-13 14:01:51 120872 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\system32\drivers\vista\PSINProt.sys
2012-07-13 14:00:58 46880 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSNEvts.dll
2012-07-13 13:59:55 167200 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSINEnAg.dll
2012-07-13 13:58:56 108832 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\psendecs.dll
2012-07-13 13:57:43 386848 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSANModAV.dll
2012-07-13 13:56:43 204064 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\NdkApi.dll
2012-07-13 13:56:42 238368 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\NdkApi.Configuration.dll
2012-07-13 13:56:42 207648 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\NdkApi.Communication.dll
2012-07-13 13:56:42 130336 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\NdkApi.Common.dll
2012-07-13 13:56:41 215328 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\NdkApi.Analysis.dll
2012-07-12 23:17:45 173344 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknact.dll
2012-07-12 18:18:56 219688 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\system64\drivers\NNSStrm.sys
2012-07-12 18:18:32 206632 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\system32\drivers\NNSStrm.sys
2012-07-10 15:36:18 847976 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\Setup.exe
2012-07-06 05:07:08 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-07-06 05:06:20 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-03 20:46:44 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-27 22:05:14 91936 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pkndtr.dll
2012-06-27 22:04:21 24352 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknDTLT.dll
2012-06-27 22:03:39 23840 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknMDT.dll
2012-06-27 22:02:57 24864 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknheu.dll
2012-06-27 22:02:15 87840 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pkndtl.dll
2012-06-27 21:57:41 83744 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknsysmw.dll
2012-06-27 21:56:48 98080 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknreg.dll
2012-06-27 21:55:37 93984 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknproc.dll
2012-06-27 21:52:50 27936 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknrbt.dll
2012-06-27 21:51:44 146208 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknQrt.dll
2012-06-27 21:50:29 95008 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pkndisk.dll
2012-06-27 21:49:16 132384 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pkncmp.dll
2012-06-27 21:48:13 95520 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknmime.dll
2012-06-27 21:47:26 110368 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknbufae.dll
2012-06-27 21:46:28 29472 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknboot.dll
2012-06-27 21:45:41 29472 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknfile.dll
2012-06-27 21:44:45 37152 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknaccess.dll
2012-06-27 21:43:57 196896 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknComCtrl.dll
2012-06-27 21:42:05 36128 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PKNComms.dll
2012-06-27 21:41:18 91424 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pkncomiexm.dll
2012-06-27 21:40:04 179488 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknplg.dll
2012-06-27 21:36:31 15648 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskisig.dll
2012-06-27 21:29:33 72480 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskcoord.dll
2012-06-27 21:28:36 21280 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\psksrf.dll
2012-06-27 21:28:01 48416 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskras.dll
2012-06-27 21:27:00 85792 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskglk.dll
2012-06-27 21:25:39 32544 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskxs.dll
2012-06-27 21:24:57 49952 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\psksys.dll
2012-06-27 21:24:11 11552 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskstr.dll
2012-06-27 21:23:38 460576 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSKSQLT.dll
2012-06-27 21:20:08 140576 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskutil.dll
2012-06-27 21:17:52 526112 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskxml.dll
2012-06-27 21:16:45 49440 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskfcmp.dll
2012-06-27 21:16:00 21792 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskcrypt.dll
2012-06-27 21:15:23 67360 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pskcrt.dll
2012-06-04 17:07:27 85280 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\pknedt.dll
2012-06-02 22:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 22:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 22:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 22:19:34 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 22:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-05-31 20:52:50 428136 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\dg\PAVSMCL.dll
2012-05-31 20:52:45 150120 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\dg\PAV2WSC.dll
2012-05-31 20:52:39 131688 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\dg\DGNano.dll
2012-05-31 20:52:33 308840 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\dg\SMCLPav.dll
2012-05-31 20:52:27 207464 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\dg\PGUse.exe
2012-05-31 20:52:21 213096 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\dg\SMCLpav.exe
2012-05-31 13:22:09 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-31 02:15:45 2726352 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\tools\PandaSecurityTb.exe
2012-05-29 23:55:04 342632 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\program files\panda security\panda cloud antivirus\PSINanoRun.exe
2012-05-16 15:08:26 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 13:20:33 1863168 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 14:42:33 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42:33 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:02 385024 ----a-w- c:\windows\system32\html.iec
2012-05-04 13:12:30 2192640 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32:19 2069120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-03 16:11:36 112456 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\Launcher.exe
2012-05-03 15:54:15 4988744 ----a-w- c:\windows\system32\grouppolicy\machine\scripts\shutdown\pan8.tmp\SetupUI.dll
2012-05-02 13:46:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3160815A rev.3.AAC -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A26C4B1]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a27393c]; MOV EAX, [0x8a273ab0]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x8ACB7AB8]
3 CLASSPNP[0xF7637FD7] -> nt!IofCallDriver[0x804E37D5] -> [0x8A7C4240]
\Driver\atapi[0x8AC2CCA8] -> IRP_MJ_CREATE -> 0x8A26C4B1
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A26C2E2
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 20:24:45.09 ===============
Thank you in advance!


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top











