Please see log below....Please know I still can not access the internet from the infected unit; so I will need to use the flash drive to transfer what ever is required to remove the virus...
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-12-2012
Ran by SYSTEM at 20-12-2012 15:10:17
Running from F:\
Windows 7 Starter (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-10-13] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [9292392 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [SuiteTray] "C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-05-26] (Egis Technology Inc.)
HKLM\...\Run: [EgisUpdate] "C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d [201584 2010-03-10] (Egis Technology Inc.)
HKLM\...\Run: [EgisTecPMMUpdate] "C:\Program Files\EgisTec IPS\PmmUpdate.exe" [407920 2010-03-10] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-26] (Egis Technology Inc.)
HKLM\...\Run: [Norton Online Backup] C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe [966488 2010-06-01] (Symantec Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated)
HKLM\...\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe [968272 2010-06-21] (Dritek System Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1692968 2010-02-05] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715296 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [404568 2012-03-27] (LG Electronics)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2011-12-07] (Apple Inc.)
HKLM\...\Run: [PSUAMain] "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe" /LaunchSysTray [32032 2012-11-14] (Panda Security, S.L.)
HKU\angelgirldebra@yahoo\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-07-06] (Google Inc.)
HKU\angelgirldebra@yahoo\...\Run: [Facebook Update] "C:\Users\angelgirldebra@yahoo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
HKU\angelgirldebra@yahoo\...\Run: [pcdfsvc] C:\ProgramData\pcdfdata\wgsdgsdgdsgsd.exe /min [79808 2012-12-18] (Microsoft Corporation)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-14] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-14] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Services (Whitelisted) ===================
2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [735776 2010-06-11] (Acer Incorporated)
3 GameConsoleService; "C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe" [246520 2010-04-03] (WildTangent, Inc.)
2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
3 MWLService; C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-26] (Egis Technology Inc.)
2 NanoServiceMain; "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe" [140064 2012-11-12] (Panda Security, S.L.)
2 NOBU; "C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2057560 2010-06-01] (Symantec Corporation)
2 PSUAService; "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAService.exe" [36640 2012-11-14] (Panda Security, S.L.)
2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated)
2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-28] (Acer Group)
2 McAfee SiteAdvisor Service; c:\PROGRA~1\mcafee\SITEAD~1\McSACore.exe [x]
==================== Drivers (Whitelisted) ====================
3 Andbus; C:\Windows\System32\DRIVERS\lgandbus.sys [14336 2010-12-07] (LG Electronics Inc.)
3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag.sys [20736 2010-12-07] (LG Electronics Inc.)
3 AndGps; C:\Windows\System32\DRIVERS\lgandgps.sys [20096 2010-12-07] (LG Electronics Inc.)
3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem.sys [25088 2010-12-07] (LG Electronics Inc.)
3 EUCR; C:\Windows\System32\DRIVERS\EUCR6SK.SYS [82768 2010-06-16] (ENE Technology Inc.)
1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-02] (Egis Technology Inc.)
1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-02] (Egis Technology Inc.)
1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-02] (Egis Technology Inc.)
1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [119208 2012-11-09] (Panda Security, S.L.)
1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [139176 2012-11-09] (Panda Security, S.L.)
1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [163112 2012-11-09] (Panda Security, S.L.)
1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [29224 2012-10-22] (Panda Security, S.L.)
1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [133544 2012-11-09] (Panda Security, S.L.)
4 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [74792 2012-11-09] (Panda Security, S.L.)
1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125480 2012-11-09] (Panda Security, S.L.)
1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [370216 2012-11-09] (Panda Security, S.L.)
1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [191528 2012-11-09] (Panda Security, S.L.)
1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [128040 2012-11-09] (Panda Security, S.L.)
1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [276520 2012-11-09] (Panda Security, S.L.)
1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [133928 2012-11-09] (Panda Security, S.L.)
2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [149544 2012-11-09] (Panda Security, S.L.)
2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [104488 2012-11-09] (Panda Security, S.L.)
1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [174632 2012-11-09] (Panda Security, S.L.)
2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [114216 2012-11-09] (Panda Security, S.L.)
2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [123944 2012-11-09] (Panda Security, S.L.)
3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [46672 2012-11-07] (Panda Security, S.L.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2012-12-20 15:10 - 2012-12-20 15:10 - 00000000 ____D C:\FRST
2012-12-20 07:22 - 2012-11-07 06:00 - 00046672 ____A (Panda Security, S.L.) C:\Windows\System32\Drivers\PSKMAD.sys
2012-12-18 15:23 - 2012-12-18 17:17 - 00006080 ____A C:\Users\All Users\NanoRepository.bin
2012-12-18 15:23 - 2012-12-18 15:23 - 00006080 ____A C:\Users\All Users\NanoRepository.bin.bak
2012-12-18 09:30 - 2012-12-18 09:30 - 00001667 ____A C:\Users\Public\Desktop\Win7 Defender.lnk
2012-12-18 09:19 - 2012-12-18 16:07 - 00000000 ____D C:\Users\All Users\pcdfdata
2012-12-13 11:13 - 2012-11-13 18:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-12-13 11:13 - 2012-11-13 18:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-12-13 11:13 - 2012-11-13 18:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-12-13 11:13 - 2012-11-13 17:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-12-13 11:13 - 2012-11-13 17:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-12-13 11:13 - 2012-11-13 17:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-12-13 11:13 - 2012-11-13 17:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-12-13 11:13 - 2012-11-13 17:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-12-13 11:13 - 2012-11-13 17:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-12-13 11:13 - 2012-11-13 17:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-12-13 11:13 - 2012-11-13 17:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-12-13 11:13 - 2012-11-13 17:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-12-13 11:13 - 2012-11-13 17:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-12-13 11:13 - 2012-11-13 17:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-12-13 11:13 - 2012-11-13 17:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-12-13 11:13 - 2012-11-13 17:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-12-13 03:18 - 2012-11-21 23:43 - 02344960 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-12-13 03:17 - 2012-10-04 08:53 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2012-12-13 03:17 - 2012-10-04 08:49 - 00868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2012-12-13 03:17 - 2012-10-04 08:49 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 07:00 - 00271360 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2012-12-13 03:17 - 2012-10-04 06:44 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 06:44 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 06:44 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 06:44 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2012-12-13 03:15 - 2012-11-01 20:48 - 00376832 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
2012-12-13 03:07 - 2012-11-05 06:03 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-13 03:07 - 2012-11-05 06:03 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-13 03:07 - 2012-09-06 08:48 - 00245616 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys
2012-12-13 03:06 - 2012-11-08 20:49 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-12-11 03:32 - 2012-12-11 03:32 - 00003288 ____N C:\bootsqm.dat
2012-12-05 16:29 - 2012-12-05 16:30 - 00999888 ____A (Solid State Networks) C:\Users\angelgirldebra@yahoo\Downloads\install_flashplayer11x32axau_gtbp_chra_aih.exe
2012-12-05 16:29 - 2012-12-05 16:30 - 00999888 ____A (Solid State Networks) C:\Users\angelgirldebra@yahoo\Downloads\install_flashplayer11x32axau_gtbp_chra_aih (1).exe
2012-11-28 09:16 - 2012-05-31 09:25 - 00237072 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-11-22 04:44 - 2012-11-22 04:44 - 00000000 ____D C:\Users\angelgirldebra@yahoo\AppData\Roaming\Panda Security
2012-11-22 04:38 - 2012-11-22 04:38 - 00000000 ____A C:\Users\All Users\0x0304A000.sfl
2012-11-22 04:32 - 2012-11-22 04:32 - 00000000 ____D C:\Users\All Users\Panda Security
2012-11-22 04:32 - 2012-11-22 04:32 - 00000000 ____D C:\Program Files\Panda Security
2012-11-22 04:20 - 2012-11-22 04:20 - 00808224 ____A C:\Users\angelgirldebra@yahoo\Downloads\PandaCloudAntivirus (1).exe
2012-11-22 04:18 - 2012-11-22 04:18 - 00808224 ____A C:\Users\angelgirldebra@yahoo\Downloads\PandaCloudAntivirus.exe
==================== One Month Modified Files and Folders ========
2012-12-20 11:48 - 2010-09-26 07:11 - 01059475 ____A C:\Windows\WindowsUpdate.log
2012-12-20 11:48 - 2009-07-13 20:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-12-20 11:48 - 2009-07-13 20:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-12-20 11:39 - 2011-05-09 18:03 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-12-20 11:39 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-12-20 11:39 - 2009-07-13 20:39 - 00092171 ____A C:\Windows\setupact.log
2012-12-18 17:17 - 2012-12-18 15:23 - 00006080 ____A C:\Users\All Users\NanoRepository.bin
2012-12-18 17:10 - 2011-05-09 18:03 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-12-18 17:08 - 2009-07-13 20:53 - 00032622 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-12-18 16:07 - 2012-12-18 09:19 - 00000000 ____D C:\Users\All Users\pcdfdata
2012-12-18 16:07 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2012-12-18 16:07 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\DriverStore
2012-12-18 16:07 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2012-12-18 15:23 - 2012-12-18 15:23 - 00006080 ____A C:\Users\All Users\NanoRepository.bin.bak
2012-12-18 15:23 - 2012-06-06 02:04 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-12-18 13:08 - 2011-05-06 09:28 - 00000000 ____D C:\users\angelgirldebra@yahoo
2012-12-18 09:30 - 2012-12-18 09:30 - 00001667 ____A C:\Users\Public\Desktop\Win7 Defender.lnk
2012-12-18 02:59 - 2011-09-16 14:37 - 00002413 ____A C:\Windows\System32\lgAxconfig.ini
2012-12-17 12:34 - 2010-07-06 06:27 - 00727182 ____A C:\Windows\System32\PerfStringBackup.INI
2012-12-16 14:47 - 2011-09-05 07:20 - 00000000 ____D C:\Users\angelgirldebra@yahoo\AppData\Roaming\SoftGrid Client
2012-12-13 11:26 - 2009-07-13 20:33 - 00298088 ____A C:\Windows\System32\FNTCACHE.DAT
2012-12-11 15:45 - 2010-09-26 07:08 - 00034250 ____A C:\Windows\PFRO.log
2012-12-11 11:33 - 2012-06-06 02:04 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-12-11 11:33 - 2011-09-19 14:34 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-12-11 03:32 - 2012-12-11 03:32 - 00003288 ____N C:\bootsqm.dat
2012-12-07 15:06 - 2011-05-06 09:28 - 00058400 ____A C:\Users\angelgirldebra@yahoo\AppData\Local\GDIPFONTCACHEV1.DAT
2012-12-06 18:18 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\GroupPolicy
2012-12-05 16:30 - 2012-12-05 16:29 - 00999888 ____A (Solid State Networks) C:\Users\angelgirldebra@yahoo\Downloads\install_flashplayer11x32axau_gtbp_chra_aih.exe
2012-12-05 16:30 - 2012-12-05 16:29 - 00999888 ____A (Solid State Networks) C:\Users\angelgirldebra@yahoo\Downloads\install_flashplayer11x32axau_gtbp_chra_aih (1).exe
2012-12-04 06:40 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2012-11-28 12:06 - 2010-07-06 07:20 - 00000000 ____D C:\Users\All Users\McAfee
2012-11-28 12:06 - 2010-07-06 07:20 - 00000000 ____D C:\Program Files\McAfee
2012-11-28 11:22 - 2010-07-06 07:20 - 00000000 ____D C:\Program Files\Common Files\mcafee
2012-11-28 08:56 - 2009-07-13 18:37 - 00000000 ___RD C:\users\Public
2012-11-28 02:45 - 2011-10-15 05:19 - 00001988 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-11-22 04:44 - 2012-11-22 04:44 - 00000000 ____D C:\Users\angelgirldebra@yahoo\AppData\Roaming\Panda Security
2012-11-22 04:38 - 2012-11-22 04:38 - 00000000 ____A C:\Users\All Users\0x0304A000.sfl
2012-11-22 04:32 - 2012-11-22 04:32 - 00000000 ____D C:\Users\All Users\Panda Security
2012-11-22 04:32 - 2012-11-22 04:32 - 00000000 ____D C:\Program Files\Panda Security
2012-11-22 04:20 - 2012-11-22 04:20 - 00808224 ____A C:\Users\angelgirldebra@yahoo\Downloads\PandaCloudAntivirus (1).exe
2012-11-22 04:18 - 2012-11-22 04:18 - 00808224 ____A C:\Users\angelgirldebra@yahoo\Downloads\PandaCloudAntivirus.exe
2012-11-21 23:43 - 2012-12-13 03:18 - 02344960 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
ZeroAccess:
C:\Users\angelgirldebra@yahoo\AppData\Local\{d28b2dd4-9a70-d43c-1397-e9e518f5aacf}
C:\Users\angelgirldebra@yahoo\AppData\Local\{d28b2dd4-9a70-d43c-1397-e9e518f5aacf}\@
C:\Users\angelgirldebra@yahoo\AppData\Local\{d28b2dd4-9a70-d43c-1397-e9e518f5aacf}\L
C:\Users\angelgirldebra@yahoo\AppData\Local\{d28b2dd4-9a70-d43c-1397-e9e518f5aacf}\U
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2012-12-13 03:07] - [2012-09-06 08:48] - 0245616 ____A (Microsoft Corporation) 59F06B4968E58BC83DFC56CA4517960E
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-11-16 09:02:27
Restore point made on: 2012-11-28 06:08:16
Restore point made on: 2012-12-04 06:29:32
Restore point made on: 2012-12-07 14:39:33
Restore point made on: 2012-12-11 03:14:35
Restore point made on: 2012-12-13 11:12:08
Restore point made on: 2012-12-18 09:59:14
Restore point made on: 2012-12-20 11:47:08
==================== Memory info ===========================
Percentage of memory in use: 48%
Total physical RAM: 1013.09 MB
Available physical RAM: 524.35 MB
Total Pagefile: 1013.09 MB
Available Pagefile: 520.51 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.7 MB
==================== Partitions =============================
1 Drive c: (Acer) (Fixed) (Total:135.95 GB) (Free:100.85 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:13 GB) (Free:3.16 GB) NTFS
3 Drive f: () (Removable) (Total:3.73 GB) (Free:3.68 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 3819 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 13 GB 1024 KB
Partition 2 Primary 100 MB 13 GB
Partition 3 Primary 135 GB 13 GB
=========================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E PQSERVICE NTFS Partition 13 GB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SYSTEM RESE NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Acer NTFS Partition 135 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3818 MB 16 KB
=========================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 3818 MB Healthy
=========================================================
Last Boot: 2012-12-07 15:35
==================== End Of Log ============================
Farbar Recovery Scan Tool (x86) Version: 18-12-2012
Ran by SYSTEM at 2012-12-20 15:12:23
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
=== End Of Search ===
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-12-2012
Ran by SYSTEM at 20-12-2012 15:10:17
Running from F:\
Windows 7 Starter (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-10-13] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [9292392 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [SuiteTray] "C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [337264 2010-05-26] (Egis Technology Inc.)
HKLM\...\Run: [EgisUpdate] "C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d [201584 2010-03-10] (Egis Technology Inc.)
HKLM\...\Run: [EgisTecPMMUpdate] "C:\Program Files\EgisTec IPS\PmmUpdate.exe" [407920 2010-03-10] (Egis Technology Inc.)
HKLM\...\Run: [mwlDaemon] C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-26] (Egis Technology Inc.)
HKLM\...\Run: [Norton Online Backup] C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe [966488 2010-06-01] (Symantec Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated)
HKLM\...\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe [968272 2010-06-21] (Dritek System Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1692968 2010-02-05] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715296 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM\...\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [404568 2012-03-27] (LG Electronics)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2011-12-07] (Apple Inc.)
HKLM\...\Run: [PSUAMain] "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe" /LaunchSysTray [32032 2012-11-14] (Panda Security, S.L.)
HKU\angelgirldebra@yahoo\...\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-07-06] (Google Inc.)
HKU\angelgirldebra@yahoo\...\Run: [Facebook Update] "C:\Users\angelgirldebra@yahoo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-11] (Facebook Inc.)
HKU\angelgirldebra@yahoo\...\Run: [pcdfsvc] C:\ProgramData\pcdfdata\wgsdgsdgdsgsd.exe /min [79808 2012-12-18] (Microsoft Corporation)
HKU\Default\...\RunOnce: [ScrSav] C:\Program Files\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-14] ()
HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-14] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Services (Whitelisted) ===================
2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [735776 2010-06-11] (Acer Incorporated)
3 GameConsoleService; "C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe" [246520 2010-04-03] (WildTangent, Inc.)
2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
3 MWLService; C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-26] (Egis Technology Inc.)
2 NanoServiceMain; "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe" [140064 2012-11-12] (Panda Security, S.L.)
2 NOBU; "C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2057560 2010-06-01] (Symantec Corporation)
2 PSUAService; "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUAService.exe" [36640 2012-11-14] (Panda Security, S.L.)
2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated)
2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232 2010-01-28] (Acer Group)
2 McAfee SiteAdvisor Service; c:\PROGRA~1\mcafee\SITEAD~1\McSACore.exe [x]
==================== Drivers (Whitelisted) ====================
3 Andbus; C:\Windows\System32\DRIVERS\lgandbus.sys [14336 2010-12-07] (LG Electronics Inc.)
3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag.sys [20736 2010-12-07] (LG Electronics Inc.)
3 AndGps; C:\Windows\System32\DRIVERS\lgandgps.sys [20096 2010-12-07] (LG Electronics Inc.)
3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem.sys [25088 2010-12-07] (LG Electronics Inc.)
3 EUCR; C:\Windows\System32\DRIVERS\EUCR6SK.SYS [82768 2010-06-16] (ENE Technology Inc.)
1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-02] (Egis Technology Inc.)
1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-02] (Egis Technology Inc.)
1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-02] (Egis Technology Inc.)
1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [119208 2012-11-09] (Panda Security, S.L.)
1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [139176 2012-11-09] (Panda Security, S.L.)
1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [163112 2012-11-09] (Panda Security, S.L.)
1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [29224 2012-10-22] (Panda Security, S.L.)
1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [133544 2012-11-09] (Panda Security, S.L.)
4 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [74792 2012-11-09] (Panda Security, S.L.)
1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125480 2012-11-09] (Panda Security, S.L.)
1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [370216 2012-11-09] (Panda Security, S.L.)
1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [191528 2012-11-09] (Panda Security, S.L.)
1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [128040 2012-11-09] (Panda Security, S.L.)
1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [276520 2012-11-09] (Panda Security, S.L.)
1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [133928 2012-11-09] (Panda Security, S.L.)
2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [149544 2012-11-09] (Panda Security, S.L.)
2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [104488 2012-11-09] (Panda Security, S.L.)
1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [174632 2012-11-09] (Panda Security, S.L.)
2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [114216 2012-11-09] (Panda Security, S.L.)
2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [123944 2012-11-09] (Panda Security, S.L.)
3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [46672 2012-11-07] (Panda Security, S.L.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2012-12-20 15:10 - 2012-12-20 15:10 - 00000000 ____D C:\FRST
2012-12-20 07:22 - 2012-11-07 06:00 - 00046672 ____A (Panda Security, S.L.) C:\Windows\System32\Drivers\PSKMAD.sys
2012-12-18 15:23 - 2012-12-18 17:17 - 00006080 ____A C:\Users\All Users\NanoRepository.bin
2012-12-18 15:23 - 2012-12-18 15:23 - 00006080 ____A C:\Users\All Users\NanoRepository.bin.bak
2012-12-18 09:30 - 2012-12-18 09:30 - 00001667 ____A C:\Users\Public\Desktop\Win7 Defender.lnk
2012-12-18 09:19 - 2012-12-18 16:07 - 00000000 ____D C:\Users\All Users\pcdfdata
2012-12-13 11:13 - 2012-11-13 18:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-12-13 11:13 - 2012-11-13 18:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-12-13 11:13 - 2012-11-13 18:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-12-13 11:13 - 2012-11-13 17:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-12-13 11:13 - 2012-11-13 17:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-12-13 11:13 - 2012-11-13 17:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-12-13 11:13 - 2012-11-13 17:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-12-13 11:13 - 2012-11-13 17:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-12-13 11:13 - 2012-11-13 17:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-12-13 11:13 - 2012-11-13 17:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-12-13 11:13 - 2012-11-13 17:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-12-13 11:13 - 2012-11-13 17:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-12-13 11:13 - 2012-11-13 17:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-12-13 11:13 - 2012-11-13 17:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-12-13 11:13 - 2012-11-13 17:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-12-13 11:13 - 2012-11-13 17:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-12-13 03:18 - 2012-11-21 23:43 - 02344960 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-12-13 03:17 - 2012-10-04 08:53 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2012-12-13 03:17 - 2012-10-04 08:49 - 00868352 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2012-12-13 03:17 - 2012-10-04 08:49 - 00293376 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00005120 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 07:00 - 00271360 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2012-12-13 03:17 - 2012-10-04 06:44 - 00006144 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 06:44 - 00004608 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 06:44 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2012-12-13 03:17 - 2012-10-04 06:44 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2012-12-13 03:15 - 2012-11-01 20:48 - 00376832 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll
2012-12-13 03:07 - 2012-11-05 06:03 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
2012-12-13 03:07 - 2012-11-05 06:03 - 00034304 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
2012-12-13 03:07 - 2012-09-06 08:48 - 00245616 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\volsnap.sys
2012-12-13 03:06 - 2012-11-08 20:49 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2012-12-11 03:32 - 2012-12-11 03:32 - 00003288 ____N C:\bootsqm.dat
2012-12-05 16:29 - 2012-12-05 16:30 - 00999888 ____A (Solid State Networks) C:\Users\angelgirldebra@yahoo\Downloads\install_flashplayer11x32axau_gtbp_chra_aih.exe
2012-12-05 16:29 - 2012-12-05 16:30 - 00999888 ____A (Solid State Networks) C:\Users\angelgirldebra@yahoo\Downloads\install_flashplayer11x32axau_gtbp_chra_aih (1).exe
2012-11-28 09:16 - 2012-05-31 09:25 - 00237072 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-11-22 04:44 - 2012-11-22 04:44 - 00000000 ____D C:\Users\angelgirldebra@yahoo\AppData\Roaming\Panda Security
2012-11-22 04:38 - 2012-11-22 04:38 - 00000000 ____A C:\Users\All Users\0x0304A000.sfl
2012-11-22 04:32 - 2012-11-22 04:32 - 00000000 ____D C:\Users\All Users\Panda Security
2012-11-22 04:32 - 2012-11-22 04:32 - 00000000 ____D C:\Program Files\Panda Security
2012-11-22 04:20 - 2012-11-22 04:20 - 00808224 ____A C:\Users\angelgirldebra@yahoo\Downloads\PandaCloudAntivirus (1).exe
2012-11-22 04:18 - 2012-11-22 04:18 - 00808224 ____A C:\Users\angelgirldebra@yahoo\Downloads\PandaCloudAntivirus.exe
==================== One Month Modified Files and Folders ========
2012-12-20 11:48 - 2010-09-26 07:11 - 01059475 ____A C:\Windows\WindowsUpdate.log
2012-12-20 11:48 - 2009-07-13 20:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-12-20 11:48 - 2009-07-13 20:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-12-20 11:39 - 2011-05-09 18:03 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-12-20 11:39 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-12-20 11:39 - 2009-07-13 20:39 - 00092171 ____A C:\Windows\setupact.log
2012-12-18 17:17 - 2012-12-18 15:23 - 00006080 ____A C:\Users\All Users\NanoRepository.bin
2012-12-18 17:10 - 2011-05-09 18:03 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-12-18 17:08 - 2009-07-13 20:53 - 00032622 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-12-18 16:07 - 2012-12-18 09:19 - 00000000 ____D C:\Users\All Users\pcdfdata
2012-12-18 16:07 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2012-12-18 16:07 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\DriverStore
2012-12-18 16:07 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2012-12-18 15:23 - 2012-12-18 15:23 - 00006080 ____A C:\Users\All Users\NanoRepository.bin.bak
2012-12-18 15:23 - 2012-06-06 02:04 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-12-18 13:08 - 2011-05-06 09:28 - 00000000 ____D C:\users\angelgirldebra@yahoo
2012-12-18 09:30 - 2012-12-18 09:30 - 00001667 ____A C:\Users\Public\Desktop\Win7 Defender.lnk
2012-12-18 02:59 - 2011-09-16 14:37 - 00002413 ____A C:\Windows\System32\lgAxconfig.ini
2012-12-17 12:34 - 2010-07-06 06:27 - 00727182 ____A C:\Windows\System32\PerfStringBackup.INI
2012-12-16 14:47 - 2011-09-05 07:20 - 00000000 ____D C:\Users\angelgirldebra@yahoo\AppData\Roaming\SoftGrid Client
2012-12-13 11:26 - 2009-07-13 20:33 - 00298088 ____A C:\Windows\System32\FNTCACHE.DAT
2012-12-11 15:45 - 2010-09-26 07:08 - 00034250 ____A C:\Windows\PFRO.log
2012-12-11 11:33 - 2012-06-06 02:04 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-12-11 11:33 - 2011-09-19 14:34 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-12-11 03:32 - 2012-12-11 03:32 - 00003288 ____N C:\bootsqm.dat
2012-12-07 15:06 - 2011-05-06 09:28 - 00058400 ____A C:\Users\angelgirldebra@yahoo\AppData\Local\GDIPFONTCACHEV1.DAT
2012-12-06 18:18 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\GroupPolicy
2012-12-05 16:30 - 2012-12-05 16:29 - 00999888 ____A (Solid State Networks) C:\Users\angelgirldebra@yahoo\Downloads\install_flashplayer11x32axau_gtbp_chra_aih.exe
2012-12-05 16:30 - 2012-12-05 16:29 - 00999888 ____A (Solid State Networks) C:\Users\angelgirldebra@yahoo\Downloads\install_flashplayer11x32axau_gtbp_chra_aih (1).exe
2012-12-04 06:40 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2012-11-28 12:06 - 2010-07-06 07:20 - 00000000 ____D C:\Users\All Users\McAfee
2012-11-28 12:06 - 2010-07-06 07:20 - 00000000 ____D C:\Program Files\McAfee
2012-11-28 11:22 - 2010-07-06 07:20 - 00000000 ____D C:\Program Files\Common Files\mcafee
2012-11-28 08:56 - 2009-07-13 18:37 - 00000000 ___RD C:\users\Public
2012-11-28 02:45 - 2011-10-15 05:19 - 00001988 ____A C:\Users\Public\Desktop\Adobe Reader 9.lnk
2012-11-22 04:44 - 2012-11-22 04:44 - 00000000 ____D C:\Users\angelgirldebra@yahoo\AppData\Roaming\Panda Security
2012-11-22 04:38 - 2012-11-22 04:38 - 00000000 ____A C:\Users\All Users\0x0304A000.sfl
2012-11-22 04:32 - 2012-11-22 04:32 - 00000000 ____D C:\Users\All Users\Panda Security
2012-11-22 04:32 - 2012-11-22 04:32 - 00000000 ____D C:\Program Files\Panda Security
2012-11-22 04:20 - 2012-11-22 04:20 - 00808224 ____A C:\Users\angelgirldebra@yahoo\Downloads\PandaCloudAntivirus (1).exe
2012-11-22 04:18 - 2012-11-22 04:18 - 00808224 ____A C:\Users\angelgirldebra@yahoo\Downloads\PandaCloudAntivirus.exe
2012-11-21 23:43 - 2012-12-13 03:18 - 02344960 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
ZeroAccess:
C:\Users\angelgirldebra@yahoo\AppData\Local\{d28b2dd4-9a70-d43c-1397-e9e518f5aacf}
C:\Users\angelgirldebra@yahoo\AppData\Local\{d28b2dd4-9a70-d43c-1397-e9e518f5aacf}\@
C:\Users\angelgirldebra@yahoo\AppData\Local\{d28b2dd4-9a70-d43c-1397-e9e518f5aacf}\L
C:\Users\angelgirldebra@yahoo\AppData\Local\{d28b2dd4-9a70-d43c-1397-e9e518f5aacf}\U
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2012-12-13 03:07] - [2012-09-06 08:48] - 0245616 ____A (Microsoft Corporation) 59F06B4968E58BC83DFC56CA4517960E
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-11-16 09:02:27
Restore point made on: 2012-11-28 06:08:16
Restore point made on: 2012-12-04 06:29:32
Restore point made on: 2012-12-07 14:39:33
Restore point made on: 2012-12-11 03:14:35
Restore point made on: 2012-12-13 11:12:08
Restore point made on: 2012-12-18 09:59:14
Restore point made on: 2012-12-20 11:47:08
==================== Memory info ===========================
Percentage of memory in use: 48%
Total physical RAM: 1013.09 MB
Available physical RAM: 524.35 MB
Total Pagefile: 1013.09 MB
Available Pagefile: 520.51 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.7 MB
==================== Partitions =============================
1 Drive c: (Acer) (Fixed) (Total:135.95 GB) (Free:100.85 GB) NTFS
2 Drive e: (PQSERVICE) (Fixed) (Total:13 GB) (Free:3.16 GB) NTFS
3 Drive f: () (Removable) (Total:3.73 GB) (Free:3.68 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B
Disk 1 Online 3819 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Recovery 13 GB 1024 KB
Partition 2 Primary 100 MB 13 GB
Partition 3 Primary 135 GB 13 GB
=========================================================
Disk: 0
Partition 1
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E PQSERVICE NTFS Partition 13 GB Healthy Hidden
=========================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SYSTEM RESE NTFS Partition 100 MB Healthy
=========================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Acer NTFS Partition 135 GB Healthy
=========================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3818 MB 16 KB
=========================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT32 Removable 3818 MB Healthy
=========================================================
Last Boot: 2012-12-07 15:35
==================== End Of Log ============================
Farbar Recovery Scan Tool (x86) Version: 18-12-2012
Ran by SYSTEM at 2012-12-20 15:12:23
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\System32\services.exe
[2009-07-13 15:11] - [2009-07-13 17:14] - 0259072 ____A (Microsoft Corporation) 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
=== End Of Search ===