Hi! Since last night I've been getting this message from my Nod32 saying that the services.exe file is infected with Win64/Patched.a.Gen. It pops up every 5 to 10 minutes and I just don't know what to do with it! Here's the Farbar log. Do I need to post anything else? Thanks in advance!!
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by Bellsmorte at 25-07-2012 19:54:02
Running from C:\Users\Bellsmorte\Downloads
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-25 19:38 - 2012-07-25 19:38 - 00000000 ____D C:\Users\Bellsmorte\AppData\Local\ESET
2012-07-25 19:35 - 2012-07-25 19:54 - 00000000 ____D C:\FRST
2012-07-25 19:23 - 2012-07-25 19:23 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Bellsmorte\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-25 19:11 - 2012-07-25 19:12 - 00607260 ____A (Swearware) C:\Users\Bellsmorte\Downloads\dds.scr
2012-07-25 19:11 - 2012-07-25 19:11 - 00302592 ____A C:\Users\Bellsmorte\Downloads\zsrqg8tr.exe
2012-07-25 18:57 - 2012-07-25 18:58 - 01438391 ____A (Farbar) C:\Users\Bellsmorte\Downloads\FRST64.exe
2012-07-25 17:51 - 2012-07-25 18:00 - 00292864 __ASH C:\Users\Bellsmorte\Downloads\Thumbs.db
2012-07-25 17:31 - 2012-07-25 17:31 - 00002002 ____A C:\Windows\PFRO.log
2012-07-25 17:21 - 2012-07-25 17:21 - 00000000 ____D C:\Users\All Users\ESET
2012-07-25 17:21 - 2012-07-25 17:21 - 00000000 ____D C:\Program Files\ESET
2012-07-25 17:16 - 2012-07-25 17:16 - 00143212 ____A C:\Users\Bellsmorte\Downloads\pure.rar
2012-07-25 17:03 - 2012-07-25 17:03 - 01378744 ____A (ESET) C:\Users\Bellsmorte\Downloads\eset_nod32_antivirus_live_installer.exe
2012-07-25 15:49 - 2012-07-25 16:55 - 00000000 ____D C:\Program Files (x86)\RegCleaner
2012-07-25 15:40 - 2012-07-25 15:40 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\BlueSprig
2012-07-25 15:40 - 2012-07-25 15:40 - 00000000 ____D C:\Program Files (x86)\BlueSprig
2012-07-25 01:19 - 2012-07-25 01:19 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2012-07-25 00:30 - 2012-07-25 16:55 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-07-25 00:30 - 2012-07-25 16:55 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2012-07-24 19:43 - 2012-07-24 19:43 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\Daedalic Entertainment
2012-07-21 01:08 - 2012-07-21 01:08 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\Elephant Games
2012-07-21 01:08 - 2012-07-21 01:08 - 00000000 ____D C:\Users\All Users\Elephant Games
2012-07-20 15:40 - 2012-07-20 15:40 - 00002214 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-07-19 12:41 - 2012-07-19 12:41 - 00404640 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-16 23:24 - 2012-07-16 23:24 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\PlayPond
2012-07-14 15:51 - 2012-07-14 15:51 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\Anarchy
2012-07-13 18:05 - 2012-07-13 18:05 - 00000219 ____A C:\Users\Bellsmorte\Desktop\Left 4 Dead 2.url
2012-07-11 23:42 - 2012-07-11 23:42 - 00000748 ____A C:\Users\Bellsmorte\Desktop\GoldWave.lnk
2012-07-11 23:42 - 2012-07-11 23:42 - 00000000 ____D C:\Program Files (x86)\GoldWave
2012-07-11 23:37 - 2012-07-11 23:37 - 00000000 ____D C:\tmp
2012-07-11 23:18 - 2012-07-25 16:55 - 00000000 ____D C:\MP3Toolkit
2012-07-11 23:18 - 2012-07-11 23:18 - 00000604 ____A C:\Users\Public\Desktop\MP3 Toolkit.lnk
2012-07-11 23:17 - 2012-07-11 23:17 - 11011319 ____A (MP3Toolkit.com ) C:\Users\Bellsmorte\Desktop\mp3toolkit.exe
2012-07-07 20:46 - 2012-07-07 20:46 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\DVDFab
2012-07-07 20:43 - 2012-07-07 20:43 - 00000000 ____D C:\Users\All Users\dvdfab
2012-07-07 20:41 - 2012-07-07 20:49 - 00000000 ____D C:\Users\Bellsmorte\Documents\DVDFab
2012-07-07 20:41 - 2012-07-07 20:42 - 00000000 ____D C:\Program Files (x86)\DVDFab 8 Qt
2012-07-07 20:41 - 2012-07-07 20:41 - 00001059 ____A C:\Users\Bellsmorte\Desktop\DVDFab Profile Editor.lnk
2012-07-07 20:41 - 2012-07-07 20:41 - 00001022 ____A C:\Users\Bellsmorte\Desktop\DVDFab 8 Qt.lnk
2012-07-07 20:41 - 2012-07-07 20:41 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\NVIDIA
2012-07-07 20:40 - 2011-03-14 09:25 - 00000232 ____A C:\Users\Bellsmorte\Desktop\Información.txt
2012-07-07 20:23 - 2012-07-25 16:55 - 00000000 ____D C:\Program Files (x86)\AnvSoft
2012-07-07 20:23 - 2012-07-07 20:28 - 00000000 ____D C:\Users\Bellsmorte\Documents\Any Video Converter
2012-07-07 20:23 - 2012-07-07 20:23 - 00001242 ____A C:\Users\Bellsmorte\Desktop\Any Video Converter.lnk
2012-07-07 20:23 - 2012-07-07 20:23 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\AnvSoft
2012-07-06 16:59 - 2012-07-06 16:59 - 00000006 ____A C:\Users\Bellsmorte\Documents\jnljin.txt
2012-06-29 23:41 - 2012-06-29 23:41 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
============ 3 Months Modified Files ========================
2012-07-25 19:37 - 2012-03-26 15:27 - 00001044 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-25 19:29 - 2012-02-12 00:14 - 00001066 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3934109233-4140102264-3726521436-1001UA.job
2012-07-25 19:23 - 2012-07-25 19:23 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Bellsmorte\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-25 19:12 - 2012-07-25 19:11 - 00607260 ____A (Swearware) C:\Users\Bellsmorte\Downloads\dds.scr
2012-07-25 19:11 - 2012-07-25 19:11 - 00302592 ____A C:\Users\Bellsmorte\Downloads\zsrqg8tr.exe
2012-07-25 18:58 - 2012-07-25 18:57 - 01438391 ____A (Farbar) C:\Users\Bellsmorte\Downloads\FRST64.exe
2012-07-25 18:34 - 2011-12-04 10:51 - 01819194 ____A C:\Windows\WindowsUpdate.log
2012-07-25 18:34 - 2009-07-14 01:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-25 18:34 - 2009-07-14 01:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-25 18:00 - 2012-07-25 17:51 - 00292864 __ASH C:\Users\Bellsmorte\Downloads\Thumbs.db
2012-07-25 17:49 - 2012-06-04 19:03 - 00003406 ____A C:\Windows\setupact.log
2012-07-25 17:49 - 2012-03-26 15:27 - 00001040 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-25 17:49 - 2009-07-14 02:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-25 17:32 - 2011-12-04 11:27 - 00045056 ____A C:\Windows\System32\acovcnt.exe
2012-07-25 17:32 - 2011-12-04 11:14 - 00002326 ____A C:\Windows\System32\AutoRunFilter.ini
2012-07-25 17:32 - 2011-12-04 11:14 - 00001375 ____A C:\Windows\System32\ServiceFilter.ini
2012-07-25 17:31 - 2012-07-25 17:31 - 00002002 ____A C:\Windows\PFRO.log
2012-07-25 17:16 - 2012-07-25 17:16 - 00143212 ____A C:\Users\Bellsmorte\Downloads\pure.rar
2012-07-25 17:03 - 2012-07-25 17:03 - 01378744 ____A (ESET) C:\Users\Bellsmorte\Downloads\eset_nod32_antivirus_live_installer.exe
2012-07-25 16:58 - 2012-02-12 12:34 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2012-07-21 21:29 - 2012-02-12 00:14 - 00001014 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3934109233-4140102264-3726521436-1001Core.job
2012-07-20 15:40 - 2012-07-20 15:40 - 00002214 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-07-19 12:41 - 2012-07-19 12:41 - 00404640 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-18 19:52 - 2012-02-12 19:29 - 00000949 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-07-13 18:05 - 2012-07-13 18:05 - 00000219 ____A C:\Users\Bellsmorte\Desktop\Left 4 Dead 2.url
2012-07-11 23:42 - 2012-07-11 23:42 - 00000748 ____A C:\Users\Bellsmorte\Desktop\GoldWave.lnk
2012-07-11 23:18 - 2012-07-11 23:18 - 00000604 ____A C:\Users\Public\Desktop\MP3 Toolkit.lnk
2012-07-11 23:17 - 2012-07-11 23:17 - 11011319 ____A (MP3Toolkit.com ) C:\Users\Bellsmorte\Desktop\mp3toolkit.exe
2012-07-07 20:41 - 2012-07-07 20:41 - 00001059 ____A C:\Users\Bellsmorte\Desktop\DVDFab Profile Editor.lnk
2012-07-07 20:41 - 2012-07-07 20:41 - 00001022 ____A C:\Users\Bellsmorte\Desktop\DVDFab 8 Qt.lnk
2012-07-07 20:25 - 2009-07-14 02:13 - 00798302 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-07 20:23 - 2012-07-07 20:23 - 00001242 ____A C:\Users\Bellsmorte\Desktop\Any Video Converter.lnk
2012-07-06 16:59 - 2012-07-06 16:59 - 00000006 ____A C:\Users\Bellsmorte\Documents\jnljin.txt
2012-06-29 23:41 - 2012-06-29 23:41 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
2012-06-25 17:07 - 2012-02-24 00:35 - 00001041 ____A C:\Users\Bellsmorte\Desktop\Dropbox.lnk
2012-06-10 04:06 - 2012-06-09 02:20 - 00017888 ____A C:\Users\Bellsmorte\Documents\cufa2.txt
2012-06-04 19:03 - 2012-06-04 19:03 - 00000000 ____A C:\Windows\setuperr.log
2012-06-01 15:04 - 2012-06-01 15:04 - 00000919 ____A C:\Users\Public\Desktop\Steam.lnk
2012-05-30 18:20 - 2012-05-30 18:20 - 00000115 ____A C:\Users\Bellsmorte\Documents\caldera.txt
2012-05-26 19:25 - 2012-05-26 19:25 - 00001871 ____A C:\Users\Public\Desktop\ImgBurn.lnk
2012-05-24 16:39 - 2012-05-27 15:16 - 892016782 ____A C:\Users\Bellsmorte\Documents\laced.haywire.dvd9.Title1.avi
2012-05-23 21:13 - 2012-05-23 21:13 - 00002014 ____A C:\Users\Bellsmorte\Desktop\DOSBox 0.72.lnk
2012-05-15 15:23 - 2009-07-14 02:08 - 00032616 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-15 15:23 - 2009-07-14 02:08 - 00032616 ____A C:\Windows\Tasks\SCHEDLGU(35).TXT
2012-05-14 00:22 - 2012-05-14 00:22 - 00010115 ____A C:\Users\Bellsmorte\Documents\NOIRE.xlsx
2012-05-10 01:24 - 2012-05-10 01:24 - 00249856 ____N (Microsoft Corporation) C:\Windows\Setup1.exe
2012-05-10 01:24 - 2012-05-10 01:24 - 00073216 ____A (Microsoft Corporation) C:\Windows\ST6UNST.EXE
2012-05-10 00:26 - 2012-05-10 00:26 - 00000156 ____A C:\Users\Bellsmorte\Documents\ballads2.txt
2012-05-10 00:10 - 2012-05-09 23:48 - 00012292 ____A C:\Users\Bellsmorte\Documents\ballads.txt
2012-05-09 00:27 - 2012-05-09 00:27 - 00006076 ____A C:\Users\Bellsmorte\Documents\cufa.txt
2012-05-06 01:16 - 2012-04-24 01:10 - 00028476 ____A C:\Users\Bellsmorte\Documents\deusex.xlsx
2012-05-04 21:03 - 2012-03-30 16:03 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
ZeroAccess:
C:\Windows\Installer\{7fd9681f-20bf-56bc-3453-ea3cd472b4ef}
C:\Windows\Installer\{7fd9681f-20bf-56bc-3453-ea3cd472b4ef}\L
C:\Windows\Installer\{7fd9681f-20bf-56bc-3453-ea3cd472b4ef}\U
C:\Windows\Installer\{7fd9681f-20bf-56bc-3453-ea3cd472b4ef}\L\00000008.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 20:19] - [2009-07-13 22:39] - 0329216 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\System32\services.exe IS INFECTED. <===== ATTENTION!
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 52%
Total physical RAM: 4001.06 MB
Available physical RAM: 1887.92 MB
Total Pagefile: 8000.32 MB
Available Pagefile: 5700.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.87 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:250.05 GB) (Free:166.48 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (Data) (Fixed) (Total:321.12 GB) (Free:133.74 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 25 GB 1024 KB
Partition 2 Primary 250 GB 25 GB
Partition 3 Primary 321 GB 275 GB
==================================================================================
Disk: 0
Partition 1
Type : 1C
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 250 GB Healthy System (partition with boot components)
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Data NTFS Partition 321 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 00:00
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by Bellsmorte at 25-07-2012 19:54:02
Running from C:\Users\Bellsmorte\Downloads
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-25 19:38 - 2012-07-25 19:38 - 00000000 ____D C:\Users\Bellsmorte\AppData\Local\ESET
2012-07-25 19:35 - 2012-07-25 19:54 - 00000000 ____D C:\FRST
2012-07-25 19:23 - 2012-07-25 19:23 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Bellsmorte\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-25 19:11 - 2012-07-25 19:12 - 00607260 ____A (Swearware) C:\Users\Bellsmorte\Downloads\dds.scr
2012-07-25 19:11 - 2012-07-25 19:11 - 00302592 ____A C:\Users\Bellsmorte\Downloads\zsrqg8tr.exe
2012-07-25 18:57 - 2012-07-25 18:58 - 01438391 ____A (Farbar) C:\Users\Bellsmorte\Downloads\FRST64.exe
2012-07-25 17:51 - 2012-07-25 18:00 - 00292864 __ASH C:\Users\Bellsmorte\Downloads\Thumbs.db
2012-07-25 17:31 - 2012-07-25 17:31 - 00002002 ____A C:\Windows\PFRO.log
2012-07-25 17:21 - 2012-07-25 17:21 - 00000000 ____D C:\Users\All Users\ESET
2012-07-25 17:21 - 2012-07-25 17:21 - 00000000 ____D C:\Program Files\ESET
2012-07-25 17:16 - 2012-07-25 17:16 - 00143212 ____A C:\Users\Bellsmorte\Downloads\pure.rar
2012-07-25 17:03 - 2012-07-25 17:03 - 01378744 ____A (ESET) C:\Users\Bellsmorte\Downloads\eset_nod32_antivirus_live_installer.exe
2012-07-25 15:49 - 2012-07-25 16:55 - 00000000 ____D C:\Program Files (x86)\RegCleaner
2012-07-25 15:40 - 2012-07-25 15:40 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\BlueSprig
2012-07-25 15:40 - 2012-07-25 15:40 - 00000000 ____D C:\Program Files (x86)\BlueSprig
2012-07-25 01:19 - 2012-07-25 01:19 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2012-07-25 00:30 - 2012-07-25 16:55 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-07-25 00:30 - 2012-07-25 16:55 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2012-07-24 19:43 - 2012-07-24 19:43 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\Daedalic Entertainment
2012-07-21 01:08 - 2012-07-21 01:08 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\Elephant Games
2012-07-21 01:08 - 2012-07-21 01:08 - 00000000 ____D C:\Users\All Users\Elephant Games
2012-07-20 15:40 - 2012-07-20 15:40 - 00002214 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-07-19 12:41 - 2012-07-19 12:41 - 00404640 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-16 23:24 - 2012-07-16 23:24 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\PlayPond
2012-07-14 15:51 - 2012-07-14 15:51 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\Anarchy
2012-07-13 18:05 - 2012-07-13 18:05 - 00000219 ____A C:\Users\Bellsmorte\Desktop\Left 4 Dead 2.url
2012-07-11 23:42 - 2012-07-11 23:42 - 00000748 ____A C:\Users\Bellsmorte\Desktop\GoldWave.lnk
2012-07-11 23:42 - 2012-07-11 23:42 - 00000000 ____D C:\Program Files (x86)\GoldWave
2012-07-11 23:37 - 2012-07-11 23:37 - 00000000 ____D C:\tmp
2012-07-11 23:18 - 2012-07-25 16:55 - 00000000 ____D C:\MP3Toolkit
2012-07-11 23:18 - 2012-07-11 23:18 - 00000604 ____A C:\Users\Public\Desktop\MP3 Toolkit.lnk
2012-07-11 23:17 - 2012-07-11 23:17 - 11011319 ____A (MP3Toolkit.com ) C:\Users\Bellsmorte\Desktop\mp3toolkit.exe
2012-07-07 20:46 - 2012-07-07 20:46 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\DVDFab
2012-07-07 20:43 - 2012-07-07 20:43 - 00000000 ____D C:\Users\All Users\dvdfab
2012-07-07 20:41 - 2012-07-07 20:49 - 00000000 ____D C:\Users\Bellsmorte\Documents\DVDFab
2012-07-07 20:41 - 2012-07-07 20:42 - 00000000 ____D C:\Program Files (x86)\DVDFab 8 Qt
2012-07-07 20:41 - 2012-07-07 20:41 - 00001059 ____A C:\Users\Bellsmorte\Desktop\DVDFab Profile Editor.lnk
2012-07-07 20:41 - 2012-07-07 20:41 - 00001022 ____A C:\Users\Bellsmorte\Desktop\DVDFab 8 Qt.lnk
2012-07-07 20:41 - 2012-07-07 20:41 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\NVIDIA
2012-07-07 20:40 - 2011-03-14 09:25 - 00000232 ____A C:\Users\Bellsmorte\Desktop\Información.txt
2012-07-07 20:23 - 2012-07-25 16:55 - 00000000 ____D C:\Program Files (x86)\AnvSoft
2012-07-07 20:23 - 2012-07-07 20:28 - 00000000 ____D C:\Users\Bellsmorte\Documents\Any Video Converter
2012-07-07 20:23 - 2012-07-07 20:23 - 00001242 ____A C:\Users\Bellsmorte\Desktop\Any Video Converter.lnk
2012-07-07 20:23 - 2012-07-07 20:23 - 00000000 ____D C:\Users\Bellsmorte\AppData\Roaming\AnvSoft
2012-07-06 16:59 - 2012-07-06 16:59 - 00000006 ____A C:\Users\Bellsmorte\Documents\jnljin.txt
2012-06-29 23:41 - 2012-06-29 23:41 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
============ 3 Months Modified Files ========================
2012-07-25 19:37 - 2012-03-26 15:27 - 00001044 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-25 19:29 - 2012-02-12 00:14 - 00001066 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3934109233-4140102264-3726521436-1001UA.job
2012-07-25 19:23 - 2012-07-25 19:23 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Bellsmorte\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-25 19:12 - 2012-07-25 19:11 - 00607260 ____A (Swearware) C:\Users\Bellsmorte\Downloads\dds.scr
2012-07-25 19:11 - 2012-07-25 19:11 - 00302592 ____A C:\Users\Bellsmorte\Downloads\zsrqg8tr.exe
2012-07-25 18:58 - 2012-07-25 18:57 - 01438391 ____A (Farbar) C:\Users\Bellsmorte\Downloads\FRST64.exe
2012-07-25 18:34 - 2011-12-04 10:51 - 01819194 ____A C:\Windows\WindowsUpdate.log
2012-07-25 18:34 - 2009-07-14 01:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-25 18:34 - 2009-07-14 01:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-25 18:00 - 2012-07-25 17:51 - 00292864 __ASH C:\Users\Bellsmorte\Downloads\Thumbs.db
2012-07-25 17:49 - 2012-06-04 19:03 - 00003406 ____A C:\Windows\setupact.log
2012-07-25 17:49 - 2012-03-26 15:27 - 00001040 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-25 17:49 - 2009-07-14 02:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-25 17:32 - 2011-12-04 11:27 - 00045056 ____A C:\Windows\System32\acovcnt.exe
2012-07-25 17:32 - 2011-12-04 11:14 - 00002326 ____A C:\Windows\System32\AutoRunFilter.ini
2012-07-25 17:32 - 2011-12-04 11:14 - 00001375 ____A C:\Windows\System32\ServiceFilter.ini
2012-07-25 17:31 - 2012-07-25 17:31 - 00002002 ____A C:\Windows\PFRO.log
2012-07-25 17:16 - 2012-07-25 17:16 - 00143212 ____A C:\Users\Bellsmorte\Downloads\pure.rar
2012-07-25 17:03 - 2012-07-25 17:03 - 01378744 ____A (ESET) C:\Users\Bellsmorte\Downloads\eset_nod32_antivirus_live_installer.exe
2012-07-25 16:58 - 2012-02-12 12:34 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2012-07-21 21:29 - 2012-02-12 00:14 - 00001014 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3934109233-4140102264-3726521436-1001Core.job
2012-07-20 15:40 - 2012-07-20 15:40 - 00002214 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-07-19 12:41 - 2012-07-19 12:41 - 00404640 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-18 19:52 - 2012-02-12 19:29 - 00000949 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-07-13 18:05 - 2012-07-13 18:05 - 00000219 ____A C:\Users\Bellsmorte\Desktop\Left 4 Dead 2.url
2012-07-11 23:42 - 2012-07-11 23:42 - 00000748 ____A C:\Users\Bellsmorte\Desktop\GoldWave.lnk
2012-07-11 23:18 - 2012-07-11 23:18 - 00000604 ____A C:\Users\Public\Desktop\MP3 Toolkit.lnk
2012-07-11 23:17 - 2012-07-11 23:17 - 11011319 ____A (MP3Toolkit.com ) C:\Users\Bellsmorte\Desktop\mp3toolkit.exe
2012-07-07 20:41 - 2012-07-07 20:41 - 00001059 ____A C:\Users\Bellsmorte\Desktop\DVDFab Profile Editor.lnk
2012-07-07 20:41 - 2012-07-07 20:41 - 00001022 ____A C:\Users\Bellsmorte\Desktop\DVDFab 8 Qt.lnk
2012-07-07 20:25 - 2009-07-14 02:13 - 00798302 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-07 20:23 - 2012-07-07 20:23 - 00001242 ____A C:\Users\Bellsmorte\Desktop\Any Video Converter.lnk
2012-07-06 16:59 - 2012-07-06 16:59 - 00000006 ____A C:\Users\Bellsmorte\Documents\jnljin.txt
2012-06-29 23:41 - 2012-06-29 23:41 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
2012-06-25 17:07 - 2012-02-24 00:35 - 00001041 ____A C:\Users\Bellsmorte\Desktop\Dropbox.lnk
2012-06-10 04:06 - 2012-06-09 02:20 - 00017888 ____A C:\Users\Bellsmorte\Documents\cufa2.txt
2012-06-04 19:03 - 2012-06-04 19:03 - 00000000 ____A C:\Windows\setuperr.log
2012-06-01 15:04 - 2012-06-01 15:04 - 00000919 ____A C:\Users\Public\Desktop\Steam.lnk
2012-05-30 18:20 - 2012-05-30 18:20 - 00000115 ____A C:\Users\Bellsmorte\Documents\caldera.txt
2012-05-26 19:25 - 2012-05-26 19:25 - 00001871 ____A C:\Users\Public\Desktop\ImgBurn.lnk
2012-05-24 16:39 - 2012-05-27 15:16 - 892016782 ____A C:\Users\Bellsmorte\Documents\laced.haywire.dvd9.Title1.avi
2012-05-23 21:13 - 2012-05-23 21:13 - 00002014 ____A C:\Users\Bellsmorte\Desktop\DOSBox 0.72.lnk
2012-05-15 15:23 - 2009-07-14 02:08 - 00032616 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-15 15:23 - 2009-07-14 02:08 - 00032616 ____A C:\Windows\Tasks\SCHEDLGU(35).TXT
2012-05-14 00:22 - 2012-05-14 00:22 - 00010115 ____A C:\Users\Bellsmorte\Documents\NOIRE.xlsx
2012-05-10 01:24 - 2012-05-10 01:24 - 00249856 ____N (Microsoft Corporation) C:\Windows\Setup1.exe
2012-05-10 01:24 - 2012-05-10 01:24 - 00073216 ____A (Microsoft Corporation) C:\Windows\ST6UNST.EXE
2012-05-10 00:26 - 2012-05-10 00:26 - 00000156 ____A C:\Users\Bellsmorte\Documents\ballads2.txt
2012-05-10 00:10 - 2012-05-09 23:48 - 00012292 ____A C:\Users\Bellsmorte\Documents\ballads.txt
2012-05-09 00:27 - 2012-05-09 00:27 - 00006076 ____A C:\Users\Bellsmorte\Documents\cufa.txt
2012-05-06 01:16 - 2012-04-24 01:10 - 00028476 ____A C:\Users\Bellsmorte\Documents\deusex.xlsx
2012-05-04 21:03 - 2012-03-30 16:03 - 08744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
ZeroAccess:
C:\Windows\Installer\{7fd9681f-20bf-56bc-3453-ea3cd472b4ef}
C:\Windows\Installer\{7fd9681f-20bf-56bc-3453-ea3cd472b4ef}\L
C:\Windows\Installer\{7fd9681f-20bf-56bc-3453-ea3cd472b4ef}\U
C:\Windows\Installer\{7fd9681f-20bf-56bc-3453-ea3cd472b4ef}\L\00000008.@
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 20:19] - [2009-07-13 22:39] - 0329216 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\System32\services.exe IS INFECTED. <===== ATTENTION!
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 52%
Total physical RAM: 4001.06 MB
Available physical RAM: 1887.92 MB
Total Pagefile: 8000.32 MB
Available Pagefile: 5700.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.87 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:250.05 GB) (Free:166.48 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (Data) (Fixed) (Total:321.12 GB) (Free:133.74 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 596 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 25 GB 1024 KB
Partition 2 Primary 250 GB 25 GB
Partition 3 Primary 321 GB 275 GB
==================================================================================
Disk: 0
Partition 1
Type : 1C
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 250 GB Healthy System (partition with boot components)
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D Data NTFS Partition 321 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-18 00:00
======================= End Of Log ==========================