so I've been infected like a lot of people here...
The community seems quite knowledgeable and any help would be appreciated.
Thank you in advance,
Here is my FRST log
Scan result of Farbar Recovery Scan Tool Version: 04-07-2012 01
Ran by SYSTEM at 04-07-2012 20:39:31
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11075176 2010-07-22] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2392360 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4156 2010-04-16] ()
HKLM\...\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe [92968 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [THXCfg64] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] ()
HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3058304 2011-07-01] (ASUS)
HKLM-x32\...\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r [905216 2010-09-07] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-10] (Creative Technology Ltd.)
HKLM-x32\...\Run: [FLxHCIm] "C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe" [37888 2010-11-19] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [Arctosa] "C:\Program Files (x86)\Razer\Arctosa\razerhid.exe" [147456 2008-10-06] (Razer USA Ltd.)
HKLM-x32\...\Run: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe [248320 2011-03-21] ()
HKLM-x32\...\Run: [LWS] J:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKU\Ozzy\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [9728 2009-07-13] (Microsoft Corporation)
HKU\Ozzy\...\CurrentVersion\Windows: [Load] C:\Users\Ozzy\AppData\Local\Temp\{33570~1.EXE
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ======
2 ASLDRService; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-15] (ASUS)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-09-16] ()
2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [107832 2011-09-16] ()
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2655768 2010-10-05] (Intel Corporation)
3 Microsoft SharePoint Workspace Audit Service; "C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE" /auditservice [x]
========================== Drivers (Whitelisted) =============
2 ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS)
2 atksgt; C:\Windows\System32\Drivers\atksgt.sys [314016 2011-12-24] ()
1 ATKWMIACPIIO; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17024 2010-07-26] (ASUS)
3 FLxHCIc; C:\Windows\System32\Drivers\FLxHCIc.sys [210944 2010-11-19] (Fresco Logic)
3 FLxHCIh; C:\Windows\System32\Drivers\FLxHCIh.sys [49664 2010-11-19] (Fresco Logic)
3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )
2 lirsgt; C:\Windows\System32\Drivers\lirsgt.sys [43680 2011-12-24] ()
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
2 TurboB; C:\Windows\System32\Drivers\TurboB.sys [13832 2010-04-16] ()
3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-04 16:20 - 2012-07-04 16:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE94D7B4FE353C49
2012-07-04 16:16 - 2012-07-04 16:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71FA9751F85A74E0
2012-07-04 16:16 - 2012-07-04 16:16 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\plgguzma.sys
2012-07-04 16:11 - 2012-07-04 16:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72FE4B3470147A4A
2012-07-04 16:08 - 2012-07-04 16:08 - 00110032 ____A C:\Users\Ozzy\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-04 15:40 - 2012-07-04 15:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17A426A707800924
2012-07-04 15:24 - 2012-07-04 15:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBCFFD2806C13F95
2012-07-04 15:06 - 2012-07-04 15:24 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-07-04 15:05 - 2012-07-04 15:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F5B3401E0E744DD
2012-07-04 14:53 - 2012-07-04 14:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10E799337F78E2D4
2012-07-04 14:45 - 2012-07-04 14:45 - 00000036 ____A C:\Users\Ozzy\AppData\Local\housecall.guid.cache
2012-07-04 14:34 - 2012-07-04 14:34 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-04 14:34 - 2012-07-04 14:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-04 14:34 - 2012-04-04 11:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-04 14:31 - 2012-07-04 14:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.264201A5A6E2590D
2012-07-04 14:12 - 2012-07-04 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.164F4B65B9261376
2012-07-04 14:08 - 2012-07-04 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EFA891B89DED3576
2012-07-04 14:05 - 2012-07-04 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1E68D7F4D785755
2012-07-04 14:00 - 2012-07-04 14:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F89510AC694BC18C
2012-07-04 13:57 - 2012-07-04 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.093FCF70F273B514
2012-07-04 13:51 - 2012-07-04 13:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.212AFFABC178B24E
2012-07-04 13:47 - 2012-07-04 13:47 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-04 13:47 - 2012-07-04 13:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-04 13:06 - 2012-07-04 13:06 - 00000000 ____D C:\Users\Ozzy\AppData\Local\Macromedia
2012-07-04 11:38 - 2012-07-04 11:38 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-04 11:34 - 2012-07-04 14:13 - 00009728 ____H C:\Users\Ozzy\AppData\Roaming\desktop.ini
2012-07-03 20:05 - 2012-05-15 02:48 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-07-03 20:05 - 2012-05-15 02:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-07-03 20:05 - 2012-04-18 09:08 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
2012-07-03 20:05 - 2012-04-18 09:08 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
2012-07-03 15:44 - 2012-07-03 15:44 - 00000700 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-07-03 15:44 - 2012-07-03 15:44 - 00000000 ____D C:\Users\Ozzy\AppData\Local\Funcom
2012-07-03 15:12 - 2012-07-03 15:12 - 00000000 ____D C:\Users\All Users\Funcom
2012-07-02 17:22 - 2012-07-02 17:22 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-07-02 17:22 - 2012-07-02 17:22 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-07-02 17:22 - 2012-07-02 17:22 - 00000000 ____D C:\Program Files (x86)\Oracle
2012-07-02 17:22 - 2012-05-04 15:29 - 00772504 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-07-02 17:22 - 2012-05-04 15:29 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-06-22 23:09 - 2012-06-22 23:09 - 00000000 ____D C:\Users\Ozzy\AppData\Roaming\Warner Bros. Interactive Entertainment
2012-06-20 18:56 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-20 18:56 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-20 18:56 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-20 18:56 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-20 18:56 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-20 18:56 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-20 18:56 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-20 18:56 - 2012-06-02 11:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-20 18:56 - 2012-06-02 11:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-15 22:07 - 2012-06-15 22:07 - 00000000 ____D C:\Users\Ozzy\AppData\Local\Focus Home Interactive
2012-06-12 23:00 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 23:00 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 23:00 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-12 23:00 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 23:00 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 23:00 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-12 23:00 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 23:00 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 23:00 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 23:00 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-12 23:00 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 23:00 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 23:00 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 23:00 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 23:00 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 23:00 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 23:00 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-12 23:00 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 23:00 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-12 23:00 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 23:00 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 23:00 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 23:00 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 23:00 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-12 23:00 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 23:00 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 23:00 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 23:00 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 13:54 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 13:54 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 13:54 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 13:54 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 13:54 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 13:54 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 13:54 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 13:54 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 13:54 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 13:54 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 13:54 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 13:54 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 13:54 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 13:54 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 13:54 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 13:54 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 13:54 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-08 12:31 - 2012-06-08 12:31 - 00000000 ____D C:\Users\Ozzy\AppData\Roaming\LoneSurvivor
============ 3 Months Modified Files ========================
2012-07-04 16:20 - 2012-07-04 16:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE94D7B4FE353C49
2012-07-04 16:19 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-04 16:19 - 2009-07-13 20:51 - 00096170 ____A C:\Windows\setupact.log
2012-07-04 16:18 - 2011-07-01 22:12 - 00045056 ____A C:\Windows\System32\acovcnt.exe
2012-07-04 16:16 - 2012-07-04 16:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71FA9751F85A74E0
2012-07-04 16:16 - 2012-07-04 16:16 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\plgguzma.sys
2012-07-04 16:11 - 2012-07-04 16:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72FE4B3470147A4A
2012-07-04 16:08 - 2012-07-04 16:08 - 00110032 ____A C:\Users\Ozzy\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-04 16:08 - 2011-07-01 21:52 - 00038222 ____A C:\Windows\PFRO.log
2012-07-04 15:55 - 2009-07-13 21:13 - 00782528 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-04 15:40 - 2012-07-04 15:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17A426A707800924
2012-07-04 15:24 - 2012-07-04 15:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBCFFD2806C13F95
2012-07-04 15:11 - 2011-07-01 21:24 - 01684549 ____A C:\Windows\WindowsUpdate.log
2012-07-04 15:05 - 2012-07-04 15:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F5B3401E0E744DD
2012-07-04 14:53 - 2012-07-04 14:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10E799337F78E2D4
2012-07-04 14:45 - 2012-07-04 14:45 - 00000036 ____A C:\Users\Ozzy\AppData\Local\housecall.guid.cache
2012-07-04 14:34 - 2012-07-04 14:34 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-04 14:31 - 2012-07-04 14:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.264201A5A6E2590D
2012-07-04 14:13 - 2012-07-04 11:34 - 00009728 ____H C:\Users\Ozzy\AppData\Roaming\desktop.ini
2012-07-04 14:12 - 2012-07-04 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.164F4B65B9261376
2012-07-04 14:08 - 2012-07-04 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EFA891B89DED3576
2012-07-04 14:05 - 2012-07-04 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1E68D7F4D785755
2012-07-04 14:00 - 2012-07-04 14:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F89510AC694BC18C
2012-07-04 13:57 - 2012-07-04 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.093FCF70F273B514
2012-07-04 13:54 - 2012-02-12 11:49 - 00000924 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1988046844-1190682726-1738477624-1001UA.job
2012-07-04 13:52 - 2009-07-13 20:45 - 00019520 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-04 13:52 - 2009-07-13 20:45 - 00019520 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-04 13:51 - 2012-07-04 13:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.212AFFABC178B24E
2012-07-04 13:47 - 2012-03-07 12:23 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-04 13:47 - 2011-07-07 00:00 - 00788374 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-04 10:54 - 2012-02-12 11:49 - 00000902 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1988046844-1190682726-1738477624-1001Core.job
2012-07-03 15:44 - 2012-07-03 15:44 - 00000700 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-07-02 17:22 - 2012-07-02 17:22 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-07-02 17:22 - 2012-07-02 17:22 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-21 00:57 - 2011-07-01 22:02 - 00215651 ____A C:\Windows\DirectX.log
2012-06-18 08:56 - 2009-07-13 21:08 - 00032566 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-13 09:11 - 2009-07-13 20:45 - 00417488 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-12 23:03 - 2012-04-27 22:35 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-09 11:55 - 2012-03-11 23:39 - 00000000 ____A C:\Windows\System32\Drivers\lvuvc.hs
2012-06-09 11:55 - 2012-03-11 23:37 - 00025752 ____A C:\Windows\System32\lvcoinst.log
2012-06-02 14:19 - 2012-06-20 18:56 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 18:56 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 18:56 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 18:56 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 18:56 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-20 18:56 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-20 18:56 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-20 18:56 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-20 18:56 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-23 00:36 - 2012-05-23 00:36 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-05-17 18:47 - 2012-06-12 23:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-12 23:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-12 23:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-12 23:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-12 23:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-12 23:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-12 23:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-12 23:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-12 23:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-12 23:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-12 23:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-12 23:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-12 23:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-12 23:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-12 23:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-12 23:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-12 23:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-12 23:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-12 23:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-12 23:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-12 23:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-12 23:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-12 23:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-12 23:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-12 23:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-12 23:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-12 23:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-12 23:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:48 - 2012-07-03 20:05 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-05-15 02:48 - 2011-10-30 20:31 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2012-05-15 02:48 - 2011-10-30 20:31 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2012-05-15 02:48 - 2011-10-30 20:31 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
2012-05-15 02:48 - 2011-10-30 20:31 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
2012-05-15 02:48 - 2011-07-01 21:50 - 00014324 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 01:29 - 2010-10-29 00:38 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2012-05-15 01:29 - 2010-10-29 00:38 - 02561856 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2012-05-15 01:29 - 2010-10-29 00:38 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:29 - 2010-10-29 00:38 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:29 - 2010-10-29 00:38 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:28 - 2010-10-29 00:38 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-14 22:21 - 2012-05-14 22:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
2012-05-14 17:32 - 2012-06-12 13:54 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-04 15:29 - 2012-07-02 17:22 - 00772504 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-05-04 15:29 - 2012-07-02 17:22 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-05-04 15:29 - 2011-07-16 19:31 - 00687504 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-05-04 03:06 - 2012-06-12 13:54 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 13:54 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 13:54 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-12 13:54 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 22:40 - 2009-07-13 18:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2012-04-27 22:40 - 2009-07-13 18:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2012-04-27 19:55 - 2012-06-12 13:54 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 13:54 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 13:54 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 13:54 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 13:54 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 13:54 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 13:54 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 13:54 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 13:54 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 13:54 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 09:08 - 2012-07-03 20:05 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
2012-04-18 09:08 - 2012-07-03 20:05 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
2012-04-18 09:08 - 2012-03-07 20:47 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll
2012-04-07 15:14 - 2011-12-31 08:07 - 00000023 ____A C:\Windows\BlendSettings.ini
2012-04-07 04:31 - 2012-06-12 13:54 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 13:54 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
ZeroAccess:
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\@
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\L
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U\00000001.@
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U\80000000.@
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U\800000cb.@
ZeroAccess:
C:\Users\Ozzy\AppData\Local\{408ce75b-fa51-7e98-ae24-bc1addbbee96}
C:\Users\Ozzy\AppData\Local\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\@
C:\Users\Ozzy\AppData\Local\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\L
C:\Users\Ozzy\AppData\Local\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 8169.17 MB
Available physical RAM: 7309.55 MB
Total Pagefile: 8167.32 MB
Available Pagefile: 7311.08 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:59.62 GB) (Free:14.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: () (Fixed) (Total:444.27 GB) (Free:17.18 GB) NTFS
3 Drive e: (WIN_EN_DVD) (CDROM) (Total:3.02 GB) (Free:0 GB) UDF
4 Drive f: () (Removable) (Total:0.49 GB) (Free:0.49 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 59 GB 0 B
Disk 1 Online 465 GB 2048 KB *
Disk 2 Online 500 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 59 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NTFS Partition 59 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Dynamic Data 465 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 42
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 RECOVERY FAT32 Simple 21 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 500 MB 32 KB
==================================================================================
Disk: 2
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F FAT Removable 500 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 09:47
======================= End Of Log ==========================
And here is my services.exe log
Farbar Recovery Scan Tool Version: 04-07-2012 01
Ran by SYSTEM at 2012-07-04 20:40:58
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======
Again, thank you very much in advance for the help.
The community seems quite knowledgeable and any help would be appreciated.
Thank you in advance,
Here is my FRST log
Scan result of Farbar Recovery Scan Tool Version: 04-07-2012 01
Ran by SYSTEM at 04-07-2012 20:39:31
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet002
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11075176 2010-07-22] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2392360 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4156 2010-04-16] ()
HKLM\...\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe [92968 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [THXCfg64] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] ()
HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3058304 2011-07-01] (ASUS)
HKLM-x32\...\Run: [THX TruStudio NB Settings] "C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" /r [905216 2010-09-07] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-10] (Creative Technology Ltd.)
HKLM-x32\...\Run: [FLxHCIm] "C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe" [37888 2010-11-19] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [Arctosa] "C:\Program Files (x86)\Razer\Arctosa\razerhid.exe" [147456 2008-10-06] (Razer USA Ltd.)
HKLM-x32\...\Run: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe [248320 2011-03-21] ()
HKLM-x32\...\Run: [LWS] J:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKU\Ozzy\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [9728 2009-07-13] (Microsoft Corporation)
HKU\Ozzy\...\CurrentVersion\Windows: [Load] C:\Users\Ozzy\AppData\Local\Temp\{33570~1.EXE
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Services (Whitelisted) ======
2 ASLDRService; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-15] (ASUS)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [124240 2010-03-18] (Microsoft Corporation)
2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-09-16] ()
2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [107832 2011-09-16] ()
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2655768 2010-10-05] (Intel Corporation)
3 Microsoft SharePoint Workspace Audit Service; "C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE" /auditservice [x]
========================== Drivers (Whitelisted) =============
2 ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS)
2 atksgt; C:\Windows\System32\Drivers\atksgt.sys [314016 2011-12-24] ()
1 ATKWMIACPIIO; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17024 2010-07-26] (ASUS)
3 FLxHCIc; C:\Windows\System32\Drivers\FLxHCIc.sys [210944 2010-11-19] (Fresco Logic)
3 FLxHCIh; C:\Windows\System32\Drivers\FLxHCIh.sys [49664 2010-11-19] (Fresco Logic)
3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )
2 lirsgt; C:\Windows\System32\Drivers\lirsgt.sys [43680 2011-12-24] ()
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
2 TurboB; C:\Windows\System32\Drivers\TurboB.sys [13832 2010-04-16] ()
3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-04 16:20 - 2012-07-04 16:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE94D7B4FE353C49
2012-07-04 16:16 - 2012-07-04 16:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71FA9751F85A74E0
2012-07-04 16:16 - 2012-07-04 16:16 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\plgguzma.sys
2012-07-04 16:11 - 2012-07-04 16:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72FE4B3470147A4A
2012-07-04 16:08 - 2012-07-04 16:08 - 00110032 ____A C:\Users\Ozzy\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-04 15:40 - 2012-07-04 15:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17A426A707800924
2012-07-04 15:24 - 2012-07-04 15:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBCFFD2806C13F95
2012-07-04 15:06 - 2012-07-04 15:24 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-07-04 15:05 - 2012-07-04 15:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F5B3401E0E744DD
2012-07-04 14:53 - 2012-07-04 14:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10E799337F78E2D4
2012-07-04 14:45 - 2012-07-04 14:45 - 00000036 ____A C:\Users\Ozzy\AppData\Local\housecall.guid.cache
2012-07-04 14:34 - 2012-07-04 14:34 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-04 14:34 - 2012-07-04 14:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-04 14:34 - 2012-04-04 11:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-04 14:31 - 2012-07-04 14:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.264201A5A6E2590D
2012-07-04 14:12 - 2012-07-04 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.164F4B65B9261376
2012-07-04 14:08 - 2012-07-04 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EFA891B89DED3576
2012-07-04 14:05 - 2012-07-04 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1E68D7F4D785755
2012-07-04 14:00 - 2012-07-04 14:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F89510AC694BC18C
2012-07-04 13:57 - 2012-07-04 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.093FCF70F273B514
2012-07-04 13:51 - 2012-07-04 13:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.212AFFABC178B24E
2012-07-04 13:47 - 2012-07-04 13:47 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-04 13:47 - 2012-07-04 13:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-04 13:06 - 2012-07-04 13:06 - 00000000 ____D C:\Users\Ozzy\AppData\Local\Macromedia
2012-07-04 11:38 - 2012-07-04 11:38 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-04 11:34 - 2012-07-04 14:13 - 00009728 ____H C:\Users\Ozzy\AppData\Roaming\desktop.ini
2012-07-03 20:05 - 2012-05-15 02:48 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-07-03 20:05 - 2012-05-15 02:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-07-03 20:05 - 2012-05-15 02:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-07-03 20:05 - 2012-04-18 09:08 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
2012-07-03 20:05 - 2012-04-18 09:08 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
2012-07-03 15:44 - 2012-07-03 15:44 - 00000700 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-07-03 15:44 - 2012-07-03 15:44 - 00000000 ____D C:\Users\Ozzy\AppData\Local\Funcom
2012-07-03 15:12 - 2012-07-03 15:12 - 00000000 ____D C:\Users\All Users\Funcom
2012-07-02 17:22 - 2012-07-02 17:22 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-07-02 17:22 - 2012-07-02 17:22 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-07-02 17:22 - 2012-07-02 17:22 - 00000000 ____D C:\Program Files (x86)\Oracle
2012-07-02 17:22 - 2012-05-04 15:29 - 00772504 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-07-02 17:22 - 2012-05-04 15:29 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-06-22 23:09 - 2012-06-22 23:09 - 00000000 ____D C:\Users\Ozzy\AppData\Roaming\Warner Bros. Interactive Entertainment
2012-06-20 18:56 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-20 18:56 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-20 18:56 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-20 18:56 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-20 18:56 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-20 18:56 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-20 18:56 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-20 18:56 - 2012-06-02 11:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-20 18:56 - 2012-06-02 11:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-15 22:07 - 2012-06-15 22:07 - 00000000 ____D C:\Users\Ozzy\AppData\Local\Focus Home Interactive
2012-06-12 23:00 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-12 23:00 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-12 23:00 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-12 23:00 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-12 23:00 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-12 23:00 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-12 23:00 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-12 23:00 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-12 23:00 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-12 23:00 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-12 23:00 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-12 23:00 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-12 23:00 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-12 23:00 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-12 23:00 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-12 23:00 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-12 23:00 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-12 23:00 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-12 23:00 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-12 23:00 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-12 23:00 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-12 23:00 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-12 23:00 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-12 23:00 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-12 23:00 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-12 23:00 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-12 23:00 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-12 23:00 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 13:54 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 13:54 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 13:54 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 13:54 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 13:54 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 13:54 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 13:54 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 13:54 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 13:54 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 13:54 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 13:54 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 13:54 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 13:54 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 13:54 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 13:54 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 13:54 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 13:54 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-08 12:31 - 2012-06-08 12:31 - 00000000 ____D C:\Users\Ozzy\AppData\Roaming\LoneSurvivor
============ 3 Months Modified Files ========================
2012-07-04 16:20 - 2012-07-04 16:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE94D7B4FE353C49
2012-07-04 16:19 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-04 16:19 - 2009-07-13 20:51 - 00096170 ____A C:\Windows\setupact.log
2012-07-04 16:18 - 2011-07-01 22:12 - 00045056 ____A C:\Windows\System32\acovcnt.exe
2012-07-04 16:16 - 2012-07-04 16:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71FA9751F85A74E0
2012-07-04 16:16 - 2012-07-04 16:16 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\plgguzma.sys
2012-07-04 16:11 - 2012-07-04 16:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72FE4B3470147A4A
2012-07-04 16:08 - 2012-07-04 16:08 - 00110032 ____A C:\Users\Ozzy\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-04 16:08 - 2011-07-01 21:52 - 00038222 ____A C:\Windows\PFRO.log
2012-07-04 15:55 - 2009-07-13 21:13 - 00782528 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-04 15:40 - 2012-07-04 15:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.17A426A707800924
2012-07-04 15:24 - 2012-07-04 15:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBCFFD2806C13F95
2012-07-04 15:11 - 2011-07-01 21:24 - 01684549 ____A C:\Windows\WindowsUpdate.log
2012-07-04 15:05 - 2012-07-04 15:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1F5B3401E0E744DD
2012-07-04 14:53 - 2012-07-04 14:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10E799337F78E2D4
2012-07-04 14:45 - 2012-07-04 14:45 - 00000036 ____A C:\Users\Ozzy\AppData\Local\housecall.guid.cache
2012-07-04 14:34 - 2012-07-04 14:34 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-04 14:31 - 2012-07-04 14:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.264201A5A6E2590D
2012-07-04 14:13 - 2012-07-04 11:34 - 00009728 ____H C:\Users\Ozzy\AppData\Roaming\desktop.ini
2012-07-04 14:12 - 2012-07-04 14:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.164F4B65B9261376
2012-07-04 14:08 - 2012-07-04 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EFA891B89DED3576
2012-07-04 14:05 - 2012-07-04 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1E68D7F4D785755
2012-07-04 14:00 - 2012-07-04 14:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F89510AC694BC18C
2012-07-04 13:57 - 2012-07-04 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.093FCF70F273B514
2012-07-04 13:54 - 2012-02-12 11:49 - 00000924 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1988046844-1190682726-1738477624-1001UA.job
2012-07-04 13:52 - 2009-07-13 20:45 - 00019520 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-04 13:52 - 2009-07-13 20:45 - 00019520 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-04 13:51 - 2012-07-04 13:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.212AFFABC178B24E
2012-07-04 13:47 - 2012-03-07 12:23 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-04 13:47 - 2011-07-07 00:00 - 00788374 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-04 10:54 - 2012-02-12 11:49 - 00000902 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1988046844-1190682726-1738477624-1001Core.job
2012-07-03 15:44 - 2012-07-03 15:44 - 00000700 ____A C:\Users\Public\Desktop\The Secret World.lnk
2012-07-02 17:22 - 2012-07-02 17:22 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-07-02 17:22 - 2012-07-02 17:22 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-21 00:57 - 2011-07-01 22:02 - 00215651 ____A C:\Windows\DirectX.log
2012-06-18 08:56 - 2009-07-13 21:08 - 00032566 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-13 09:11 - 2009-07-13 20:45 - 00417488 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-12 23:03 - 2012-04-27 22:35 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-09 11:55 - 2012-03-11 23:39 - 00000000 ____A C:\Windows\System32\Drivers\lvuvc.hs
2012-06-09 11:55 - 2012-03-11 23:37 - 00025752 ____A C:\Windows\System32\lvcoinst.log
2012-06-02 14:19 - 2012-06-20 18:56 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-20 18:56 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-20 18:56 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-20 18:56 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-20 18:56 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-20 18:56 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-20 18:56 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-20 18:56 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-20 18:56 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-23 00:36 - 2012-05-23 00:36 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-05-17 18:47 - 2012-06-12 23:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-12 23:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-12 23:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-12 23:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-12 23:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-12 23:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-12 23:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-12 23:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-12 23:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-12 23:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-12 23:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-12 23:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-12 23:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-12 23:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-12 23:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-12 23:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-12 23:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-12 23:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-12 23:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-12 23:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-12 23:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-12 23:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-12 23:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-12 23:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-12 23:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-12 23:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-12 23:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-12 23:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:48 - 2012-07-03 20:05 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-05-15 02:48 - 2012-07-03 20:05 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 02:48 - 2012-03-07 20:47 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-05-15 02:48 - 2011-10-30 20:31 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2012-05-15 02:48 - 2011-10-30 20:31 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2012-05-15 02:48 - 2011-10-30 20:31 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
2012-05-15 02:48 - 2011-10-30 20:31 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
2012-05-15 02:48 - 2011-07-01 21:50 - 00014324 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 01:29 - 2010-10-29 00:38 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2012-05-15 01:29 - 2010-10-29 00:38 - 02561856 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvcr.dll
2012-05-15 01:29 - 2010-10-29 00:38 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:29 - 2010-10-29 00:38 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:29 - 2010-10-29 00:38 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:28 - 2010-10-29 00:38 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-14 22:21 - 2012-05-14 22:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
2012-05-14 17:32 - 2012-06-12 13:54 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-04 15:29 - 2012-07-02 17:22 - 00772504 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-05-04 15:29 - 2012-07-02 17:22 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-05-04 15:29 - 2011-07-16 19:31 - 00687504 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-05-04 03:06 - 2012-06-12 13:54 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 13:54 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 13:54 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-12 13:54 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 22:40 - 2009-07-13 18:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2012-04-27 22:40 - 2009-07-13 18:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2012-04-27 19:55 - 2012-06-12 13:54 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 13:54 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 13:54 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 13:54 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 13:54 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 13:54 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 13:54 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 13:54 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 13:54 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 13:54 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-18 09:08 - 2012-07-03 20:05 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
2012-04-18 09:08 - 2012-07-03 20:05 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
2012-04-18 09:08 - 2012-03-07 20:47 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll
2012-04-07 15:14 - 2011-12-31 08:07 - 00000023 ____A C:\Windows\BlendSettings.ini
2012-04-07 04:31 - 2012-06-12 13:54 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 13:54 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
ZeroAccess:
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\@
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\L
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U\00000001.@
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U\80000000.@
C:\Windows\Installer\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U\800000cb.@
ZeroAccess:
C:\Users\Ozzy\AppData\Local\{408ce75b-fa51-7e98-ae24-bc1addbbee96}
C:\Users\Ozzy\AppData\Local\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\@
C:\Users\Ozzy\AppData\Local\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\L
C:\Users\Ozzy\AppData\Local\{408ce75b-fa51-7e98-ae24-bc1addbbee96}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 8169.17 MB
Available physical RAM: 7309.55 MB
Total Pagefile: 8167.32 MB
Available Pagefile: 7311.08 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:59.62 GB) (Free:14.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: () (Fixed) (Total:444.27 GB) (Free:17.18 GB) NTFS
3 Drive e: (WIN_EN_DVD) (CDROM) (Total:3.02 GB) (Free:0 GB) UDF
4 Drive f: () (Removable) (Total:0.49 GB) (Free:0.49 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 59 GB 0 B
Disk 1 Online 465 GB 2048 KB *
Disk 2 Online 500 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 59 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NTFS Partition 59 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Dynamic Data 465 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 42
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 RECOVERY FAT32 Simple 21 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 500 MB 32 KB
==================================================================================
Disk: 2
Partition 1
Type : 06
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F FAT Removable 500 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-28 09:47
======================= End Of Log ==========================
And here is my services.exe log
Farbar Recovery Scan Tool Version: 04-07-2012 01
Ran by SYSTEM at 2012-07-04 20:40:58
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
====== End Of Search ======
Again, thank you very much in advance for the help.