After formatting I installed Microsoft Security Essentials, which immediately found 1 threat: Trojan:DOS/Alureon.E
MSE offers, but fails, to remove the threat.
Any help getting rid of this infection would be greatly appreciated. I have the win7 and driver install dvd's handy, so don't worry about saving any files or setups. Below are the OTL.txt and Extras.txt contents.
OTL.txt:
OTL logfile created on: 19-12-2011 18:44:11 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jon\Desktop
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
7,98 Gb Total Physical Memory | 6,43 Gb Available Physical Memory | 80,59% Memory free
15,95 Gb Paging File | 14,25 Gb Available in Paging File | 89,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 907,21 Gb Free Space | 97,40% Space Free | Partition Type: NTFS
Drive D: | 100,00 Mb Total Space | 70,36 Mb Free Space | 70,36% Space Free | Partition Type: NTFS
Drive F: | 1397,26 Gb Total Space | 580,39 Gb Free Space | 41,54% Space Free | Partition Type: NTFS
Computer Name: PERLEN | User Name: Jon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-12-19 18:42:39 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Jon\Desktop\OTL.exe
PRC - [2011-11-21 05:19:36 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011-02-15 12:20:22 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
PRC - [2010-04-27 03:09:52 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2009-10-26 13:16:00 | 000,223,464 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2009-10-26 13:15:56 | 000,375,000 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
========== Modules (No Company Name) ==========
MOD - [2011-11-21 05:19:36 | 001,989,592 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011-02-15 12:20:22 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
MOD - [2011-02-15 12:20:08 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
MOD - [2011-02-15 12:20:02 | 000,278,528 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
MOD - [2011-02-15 12:19:44 | 000,229,376 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTCore.dll
MOD - [2011-02-15 12:19:30 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTUI.dll
MOD - [2011-02-15 12:19:20 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTFC.dll
MOD - [2010-07-27 05:37:16 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTTSH.dll
MOD - [2009-06-27 10:11:12 | 000,503,202 | ---- | M] () -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011-11-25 15:00:10 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011-04-27 17:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2011-04-27 17:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010-10-27 16:18:52 | 000,052,896 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2009-10-26 13:16:00 | 000,223,464 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011-11-25 16:06:28 | 010,497,024 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011-11-25 14:23:04 | 000,326,656 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011-06-06 23:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011-04-27 15:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2010-10-27 15:50:28 | 000,301,680 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2010-10-27 15:50:28 | 000,279,152 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2010-10-27 15:50:28 | 000,203,624 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2010-10-27 15:50:28 | 000,156,520 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2010-10-27 15:50:28 | 000,058,992 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2010-10-27 15:50:28 | 000,055,336 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AthDfu.sys -- (ATHDFU)
DRV:64bit: - [2010-10-27 15:50:28 | 000,038,248 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2010-10-27 15:50:28 | 000,031,080 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2010-10-26 04:08:08 | 000,406,632 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010-10-19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010-09-30 06:00:06 | 000,180,736 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010-09-30 06:00:06 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010-08-27 18:53:22 | 000,297,000 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv91xx.sys -- (mv91xx)
DRV:64bit: - [2009-07-14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009-07-14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2010-05-27 01:43:00 | 000,014,648 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-12-19 17:14:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011-12-19 17:19:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jon\AppData\Roaming\Mozilla\Extensions
[2011-12-19 17:14:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011-11-21 05:19:37 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011-11-21 02:56:15 | 000,001,525 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-co-uk.xml
[2011-11-21 02:08:07 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011-11-21 02:56:15 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-da.xml
O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB7D8D79-1BFA-4F71-BA1A-C918566A176F}: DhcpNameServer = 192.168.1.254
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-01-21 03:43:28 | 000,000,000 | RH-D | M] - F:\autorun -- [ NTFS ]
O32 - AutoRun File - [2002-10-17 03:56:50 | 000,000,036 | RH-- | M] () - F:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011-12-20 02:04:16 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2011-12-20 02:04:03 | 000,000,000 | -HSD | C] -- C:\Boot
[2011-12-19 18:42:36 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Jon\Desktop\OTL.exe
[2011-12-19 18:07:29 | 000,000,000 | R--D | C] -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2011-12-19 17:55:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2011-12-19 17:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011-12-19 17:43:41 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\DeviceVM
[2011-12-19 17:43:27 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Atheros
[2011-12-19 17:43:26 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Local\BMExplorer
[2011-12-19 17:40:18 | 000,000,000 | ---D | C] -- C:\Users\Jon\Documents\Bluetooth Folder
[2011-12-19 17:40:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Atheros
[2011-12-19 17:39:43 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
[2011-12-19 17:39:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bluetooth Suite
[2011-12-19 17:37:07 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Marvell
[2011-12-19 17:37:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Marvell
[2011-12-19 17:36:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
[2011-12-19 17:36:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Renesas Electronics
[2011-12-19 17:34:57 | 000,406,632 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2011-12-19 17:32:28 | 000,000,000 | ---D | C] -- C:\Windows\AsusInstAll
[2011-12-19 17:32:06 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2011-12-19 17:32:06 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2011-12-19 17:31:53 | 002,580,824 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
[2011-12-19 17:31:52 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2011-12-19 17:31:52 | 000,220,496 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFNHK64.dll
[2011-12-19 17:31:52 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2011-12-19 17:31:52 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2011-12-19 17:31:52 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2011-12-19 17:31:52 | 000,081,232 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFCOM64.dll
[2011-12-19 17:31:52 | 000,078,160 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFAPO64.dll
[2011-12-19 17:31:52 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
[2011-12-19 17:31:51 | 000,372,936 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2011-12-19 17:31:51 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2011-12-19 17:31:51 | 000,307,920 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2011-12-19 17:31:51 | 000,201,928 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2011-12-19 17:31:51 | 000,099,016 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2011-12-19 17:31:51 | 000,076,488 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2011-12-19 17:31:50 | 001,716,368 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEP64A.dll
[2011-12-19 17:31:50 | 000,419,472 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EED64A.dll
[2011-12-19 17:31:50 | 000,125,584 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEL64A.dll
[2011-12-19 17:31:50 | 000,072,336 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEG64A.dll
[2011-12-19 17:31:49 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
[2011-12-19 17:31:49 | 001,770,328 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek.dll
[2011-12-19 17:31:49 | 000,341,336 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO30.dll
[2011-12-19 17:31:49 | 000,334,680 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2011-12-19 17:31:49 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2011-12-19 17:31:49 | 000,106,640 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEA64A.dll
[2011-12-19 17:31:47 | 001,937,312 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2011-12-19 17:31:47 | 001,327,208 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2011-12-19 17:31:47 | 001,179,752 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2011-12-19 17:31:47 | 001,111,656 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBoostDLL64.dll
[2011-12-19 17:31:47 | 000,504,936 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2011-12-19 17:31:47 | 000,491,112 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2011-12-19 17:31:47 | 000,475,752 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2011-12-19 17:31:47 | 000,317,032 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2011-12-19 17:31:47 | 000,269,928 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLimiterDLL64.dll
[2011-12-19 17:31:47 | 000,266,856 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2011-12-19 17:31:47 | 000,126,056 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLFXAPO64.dll
[2011-12-19 17:31:47 | 000,125,544 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPO64.dll
[2011-12-19 17:31:47 | 000,125,032 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPONS64.dll
[2011-12-19 17:31:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2011-12-19 17:31:46 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2011-12-19 17:31:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2011-12-19 17:31:36 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2011-12-19 17:31:36 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Roaming\InstallShield
[2011-12-19 17:31:04 | 000,053,248 | R--- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\SysWow64\CSVer.dll
[2011-12-19 17:31:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2011-12-19 17:31:00 | 000,000,000 | ---D | C] -- C:\Intel
[2011-12-19 17:24:09 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
[2011-12-19 17:24:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSI Afterburner
[2011-12-19 17:20:21 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Local\Diagnostics
[2011-12-19 17:19:48 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Roaming\Mozilla
[2011-12-19 17:19:48 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Local\Mozilla
[2011-12-19 17:18:18 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Roaming\ATI
[2011-12-19 17:18:18 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Local\ATI
[2011-12-19 17:18:18 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011-12-19 17:16:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2011-12-19 17:16:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2011-12-19 17:16:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011-12-19 17:16:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2011-12-19 17:15:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2011-12-19 17:15:30 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2011-12-19 17:15:29 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2011-12-19 17:15:17 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2011-12-19 17:14:39 | 000,000,000 | ---D | C] -- C:\AMD
[2011-12-19 17:14:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011-12-19 17:12:23 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2011-12-19 17:12:01 | 000,000,000 | R--D | C] -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011-12-19 17:12:01 | 000,000,000 | R--D | C] -- C:\Users\Jon\Searches
[2011-12-19 17:12:01 | 000,000,000 | R--D | C] -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011-12-19 17:12:01 | 000,000,000 | -H-D | C] -- C:\Users\Jon\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011-12-19 17:11:54 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Roaming\Identities
[2011-12-19 17:11:52 | 000,000,000 | R--D | C] -- C:\Users\Jon\Contacts
[2011-12-19 17:11:51 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Local\VirtualStore
[2011-12-19 17:11:45 | 000,000,000 | --SD | C] -- C:\Users\Jon\AppData\Roaming\Microsoft
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Videos
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Saved Games
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Pictures
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Music
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Links
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Favorites
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Downloads
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Documents
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\Desktop
[2011-12-19 17:11:45 | 000,000,000 | R--D | C] -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\AppData\Local\Temporary Internet Files
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Templates
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Start Menu
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\SendTo
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Recent
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\PrintHood
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\NetHood
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Documents\My Videos
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Documents\My Pictures
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Documents\My Music
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\My Documents
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Local Settings
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\AppData\Local\History
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Cookies
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\Application Data
[2011-12-19 17:11:45 | 000,000,000 | -HSD | C] -- C:\Users\Jon\AppData\Local\Application Data
[2011-12-19 17:11:45 | 000,000,000 | -H-D | C] -- C:\Users\Jon\AppData
[2011-12-19 17:11:45 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Local\Temp
[2011-12-19 17:11:45 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Local\Microsoft
[2011-12-19 17:11:45 | 000,000,000 | ---D | C] -- C:\Users\Jon\AppData\Roaming\Media Center Programs
[2011-12-19 17:11:39 | 000,000,000 | -HSD | C] -- C:\Recovery
[2011-12-19 17:05:13 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2011-12-19 17:04:43 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011-11-25 15:00:42 | 000,517,120 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2011-11-25 15:00:10 | 000,204,288 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2011-11-25 14:59:10 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2011-11-25 14:58:34 | 000,021,504 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2011-11-25 14:30:06 | 000,058,880 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst.dll
[2011-11-25 09:20:44 | 000,051,200 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011-11-25 09:20:38 | 000,044,032 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
========== Files - Modified Within 30 Days ==========
[2011-12-20 02:04:04 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2011-12-19 18:42:39 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Jon\Desktop\OTL.exe
[2011-12-19 18:12:02 | 000,717,260 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011-12-19 18:12:02 | 000,609,092 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011-12-19 18:12:02 | 000,104,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011-12-19 18:07:24 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2011-12-19 18:07:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011-12-19 18:07:02 | 2129,309,695 | -HS- | M] () -- C:\hiberfil.sys
[2011-12-19 18:06:08 | 000,013,728 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011-12-19 18:06:07 | 000,013,728 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011-12-19 17:55:29 | 000,002,154 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011-12-19 17:55:08 | 000,722,382 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011-12-19 17:43:46 | 000,038,208 | ---- | M] () -- C:\Windows\Ascd_log.ini
[2011-12-19 17:41:08 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2011-12-19 17:40:19 | 000,246,804 | ---- | M] () -- C:\Windows\SysNative\drivers\AtherosBt.bin
[2011-12-19 17:29:24 | 000,025,177 | ---- | M] () -- C:\Windows\Ascd_tmp.ini
[2011-12-19 17:29:17 | 000,001,769 | ---- | M] () -- C:\Windows\Language_trs.ini
[2011-12-19 17:24:09 | 000,001,086 | ---- | M] () -- C:\Users\Jon\Desktop\MSI Afterburner.lnk
[2011-12-19 17:17:55 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2011-12-19 17:14:07 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011-12-19 17:08:41 | 000,266,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011-12-19 17:07:48 | 000,042,049 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2011-12-19 17:07:48 | 000,042,049 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2011-11-25 15:05:10 | 000,207,792 | ---- | M] () -- C:\Windows\SysWow64\atiapfxx.blb
[2011-11-25 15:05:10 | 000,207,792 | ---- | M] () -- C:\Windows\SysNative\atiapfxx.blb
[2011-11-25 15:00:42 | 000,517,120 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2011-11-25 15:00:10 | 000,204,288 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2011-11-25 14:59:10 | 000,120,320 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2011-11-25 14:58:34 | 000,021,504 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2011-11-25 14:45:56 | 001,987,040 | ---- | M] () -- C:\Windows\SysNative\atiumd6a.cap
[2011-11-25 14:45:56 | 000,204,952 | ---- | M] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011-11-25 14:45:56 | 000,204,952 | ---- | M] () -- C:\Windows\SysNative\ativvsvl.dat
[2011-11-25 14:45:56 | 000,157,144 | ---- | M] () -- C:\Windows\SysWow64\ativvsva.dat
[2011-11-25 14:45:56 | 000,157,144 | ---- | M] () -- C:\Windows\SysNative\ativvsva.dat
[2011-11-25 14:38:30 | 001,988,768 | ---- | M] () -- C:\Windows\SysWow64\atiumdva.cap
[2011-11-25 14:30:06 | 000,058,880 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst.dll
[2011-11-25 09:22:48 | 000,066,560 | ---- | M] () -- C:\Windows\SysNative\OpenVideo64.dll
[2011-11-25 09:22:42 | 000,056,832 | ---- | M] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011-11-25 09:22:34 | 000,066,560 | ---- | M] () -- C:\Windows\SysNative\OVDecoder64.dll
[2011-11-25 09:22:26 | 000,056,832 | ---- | M] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011-11-25 09:20:44 | 000,051,200 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011-11-25 09:20:38 | 000,044,032 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
========== Files Created - No Company Name ==========
[2011-12-20 02:04:04 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2011-12-20 02:04:03 | 000,383,562 | RHS- | C] () -- C:\bootmgr
[2011-12-19 17:55:29 | 000,002,154 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011-12-19 17:55:08 | 000,722,382 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011-12-19 17:54:59 | 000,001,897 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011-12-19 17:43:57 | 000,001,238 | ---- | C] () -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Social Games.lnk
[2011-12-19 17:43:15 | 000,000,035 | ---- | C] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2011-12-19 17:41:08 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_btath_hcrp_01009.Wdf
[2011-12-19 17:34:56 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll
[2011-12-19 17:31:42 | 000,008,192 | ---- | C] () -- C:\Windows\SysNative\drivers\IntelMEFWVer.dll
[2011-12-19 17:30:36 | 000,038,208 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2011-12-19 17:29:14 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011-12-19 17:29:12 | 000,025,177 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011-12-19 17:24:10 | 000,110,592 | ---- | C] () -- C:\Windows\SysNative\rtvcvfw32.dll
[2011-12-19 17:24:09 | 000,001,086 | ---- | C] () -- C:\Users\Jon\Desktop\MSI Afterburner.lnk
[2011-12-19 17:17:55 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011-12-19 17:14:07 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011-12-19 17:14:07 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011-12-19 17:12:06 | 000,001,409 | ---- | C] () -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011-12-19 17:12:03 | 000,001,443 | ---- | C] () -- C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011-12-19 17:11:45 | 000,000,290 | ---- | C] () -- C:\Users\Jon\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011-12-19 17:11:45 | 000,000,272 | ---- | C] () -- C:\Users\Jon\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011-12-19 17:07:41 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011-12-19 17:07:33 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011-12-19 17:04:43 | 2129,309,695 | -HS- | C] () -- C:\hiberfil.sys
[2011-11-25 15:05:10 | 000,207,792 | ---- | C] () -- C:\Windows\SysWow64\atiapfxx.blb
[2011-11-25 15:05:10 | 000,207,792 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2011-11-25 14:45:56 | 001,987,040 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2011-11-25 14:45:56 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011-11-25 14:45:56 | 000,204,952 | ---- | C] () -- C:\Windows\SysNative\ativvsvl.dat
[2011-11-25 14:45:56 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011-11-25 14:45:56 | 000,157,144 | ---- | C] () -- C:\Windows\SysNative\ativvsva.dat
[2011-11-25 14:38:30 | 001,988,768 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2011-11-25 09:22:48 | 000,066,560 | ---- | C] () -- C:\Windows\SysNative\OpenVideo64.dll
[2011-11-25 09:22:42 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011-11-25 09:22:34 | 000,066,560 | ---- | C] () -- C:\Windows\SysNative\OVDecoder64.dll
[2011-11-25 09:22:26 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011-09-13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009-07-14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009-07-14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009-07-14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009-07-14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009-07-14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009-06-10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009-04-02 13:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
========== LOP Check ==========
[2009-07-14 06:08:49 | 000,002,350 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
Extras.txt:
OTL Extras logfile created on: 19-12-2011 18:44:11 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jon\Desktop
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000406 | Country: Danmark | Language: DAN | Date Format: dd-MM-yyyy
7,98 Gb Total Physical Memory | 6,43 Gb Available Physical Memory | 80,59% Memory free
15,95 Gb Paging File | 14,25 Gb Available in Paging File | 89,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 907,21 Gb Free Space | 97,40% Space Free | Partition Type: NTFS
Drive D: | 100,00 Mb Total Space | 70,36 Mb Free Space | 70,36% Space Free | Partition Type: NTFS
Drive F: | 1397,26 Gb Total Space | 580,39 Gb Free Space | 41,54% Space Free | Partition Type: NTFS
Computer Name: PERLEN | User Name: Jon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FB4FEB-B994-169A-507C-369048DCDACB}" = ccc-utility64
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{24BDC332-32A7-33F7-2599-1903E743B62B}" = AMD AVIVO64 Codecs
"{2BA9D1BC-C450-C22B-66A2-872783B310BC}" = AMD Drag and Drop Transcoding
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{56CB02B0-7DA3-143A-29F3-F0924CC43207}" = AMD Catalyst Install Manager
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DC911ADF-7B60-40F2-A112-FB1EB6402D07}" = Microsoft Security Client DA-DK Language Pack
"{DD3E185B-5215-EE9F-5B01-C493193168C7}" = AMD Media Foundation Decoders
"{F27D5AAD-758E-460F-964D-6F2E65964C08}" = Microsoft Antimalware Service DA-DK Language Pack
"Microsoft Security Client" = Microsoft Security Essentials
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{013A19BF-EE27-9FB9-5445-C7F13E4BB1B2}" = Catalyst Control Center InstallProxy
"{08CF0904-5AF2-1D20-1A38-BD4CB609DF28}" = CCC Help Chinese Traditional
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1DF55DEA-D893-A4AD-E68E-43A84FFCE0DF}" = HydraVision
"{2ECA81CA-D932-4AD3-AD59-BF5CCF099C83}" = Catalyst Control Center - Branding
"{2F00F52A-FAF3-6842-AE51-336F36E4E34E}" = CCC Help Spanish
"{4284721C-3665-CD39-6E3A-001EF89A76FB}" = CCC Help French
"{47D1C256-08A2-3301-5747-575216650518}" = CCC Help Danish
"{4C39374A-C16A-BDF0-1901-8C2441CCB66D}" = CCC Help English
"{4C408BF5-4997-6318-BB80-5A4B55938F06}" = CCC Help Swedish
"{4C6747D9-F8A1-2E5C-3B72-559549133186}" = CCC Help Polish
"{4F7D5A6B-7C9F-8240-C39E-E8B6D702AF8B}" = Catalyst Control Center Localization All
"{50AEEB69-5A01-5626-0543-AE4E93020D4D}" = Catalyst Control Center Graphics Previews Common
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{5CC355C0-18A5-3144-FB67-76F0DE9464CA}" = CCC Help Greek
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{670BF2B2-7E12-5EBB-187F-1E8B9261FC33}" = CCC Help Norwegian
"{72A3AA90-D847-C373-C970-3A78B5EDB395}" = CCC Help Portuguese
"{7DCF39B0-FB5E-5C0A-47EA-3C6940FB1383}" = CCC Help Russian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8DC09A32-340D-5B07-A5C6-41510E712C45}" = Catalyst Control Center
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A226D7D7-9E4A-6FBF-893E-131FA12643E8}" = CCC Help Italian
"{ABB1E211-9867-CADB-4531-5BE1692D34AE}" = CCC Help Korean
"{B52B3FFA-C6F4-A40E-0C83-43CC6E9971C1}" = CCC Help Finnish
"{C08AA6B3-DA88-EC19-F957-FD0C1F8787A9}" = CCC Help Japanese
"{C4D3AE8B-1E8C-5B43-A7DB-D6A557AC4C80}" = CCC Help Thai
"{C7495A52-2235-A33A-D534-FE61FF3C9EEC}" = CCC Help German
"{CA5DBDEB-B90C-E0D7-92A1-84C41420994D}" = CCC Help Chinese Standard
"{CB0F7ACD-5E8F-63D6-A4BE-F157BF771BE2}" = CCC Help Czech
"{D793423B-FF18-4A54-B9C9-75B3396BAAC4}" = Browser Configuration Utility
"{D7B6CCEE-331F-1876-2C53-5D4EDD0E7D2E}" = CCC Help Hungarian
"{DD6BFA76-7442-81D6-26B8-A436A4DCF86D}" = CCC Help Dutch
"{EA3EE26E-13A1-0734-D71F-233F5AA5DEFA}" = CCC Help Turkish
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Afterburner" = MSI Afterburner 2.1.0
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"MagniDriver" = marvell 91xx console driver
"Mozilla Firefox 8.0.1 (x86 da)" = Mozilla Firefox 8.0.1 (x86 da)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 19-12-2011 12:11:39 | Computer Name = Perlen | Source = Software Protection Platform Service | ID = 1017
Description = Installation of the Proof of Purchase failed. 0xC004F050 Partial Pkey=BBBBB
ACID=?
Detailed
Error[?]
[ System Events ]
Error - 19-12-2011 13:07:28 | Computer Name = Perlen | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 19-12-2011 13:07:28 | Computer Name = Perlen | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 19-12-2011 13:07:30 | Computer Name = Perlen | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 19-12-2011 13:07:31 | Computer Name = Perlen | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 19-12-2011 13:07:33 | Computer Name = Perlen | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 19-12-2011 13:08:10 | Computer Name = Perlen | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft....atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\Device\HarddiskVolume3;boot:_\Device\HarddiskVolume3\
Detection
Origin: %%845 Detection Type: %%822 Detection Source: %%818 User: Perlen\Jon Process
Name: C:\Windows\System32\svchost.exe Action: %%808 Action Status: To finish removing
malware and other potentially unwanted software, restart the computer. To see how
to finish removing malware and other potentially unwanted software, see the support
article on the Microsoft Security website. Error Code: 0x800704ec Error description:
This program is blocked by group policy. For more information, contact your system
administrator. Signature Version: AV: 1.117.1361.0, AS: 1.117.1361.0, NIS: 10.7.0.0
Engine
Version: AM: 1.1.7903.0, NIS: 2.0.7707.0
Error - 19-12-2011 13:08:10 | Computer Name = Perlen | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft....atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\Device\HarddiskVolume3;boot:_\Device\HarddiskVolume3\
Detection
Origin: %%845 Detection Type: %%822 Detection Source: %%818 User: Perlen\Jon Process
Name: C:\Windows\System32\svchost.exe Action: %%809 Action Status: To finish removing
malware and other potentially unwanted software, restart the computer. To see how
to finish removing malware and other potentially unwanted software, see the support
article on the Microsoft Security website. Error Code: 0x80070032 Error description:
The request is not supported. Signature Version: AV: 1.117.1361.0, AS: 1.117.1361.0,
NIS: 10.7.0.0 Engine Version: AM: 1.1.7903.0, NIS: 2.0.7707.0
Error - 19-12-2011 13:08:38 | Computer Name = Perlen | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft....atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition2
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
Perlen\Jon Process Name: Unknown Action: %%808 Action Status: To finish removing
malware and other potentially unwanted software, restart the computer. To see how
to finish removing malware and other potentially unwanted software, see the support
article on the Microsoft Security website. Error Code: 0x800704ec Error description:
This program is blocked by group policy. For more information, contact your system
administrator. Signature Version: AV: 1.117.1361.0, AS: 1.117.1361.0, NIS: 10.7.0.0
Engine
Version: AM: 1.1.7903.0, NIS: 2.0.7707.0
Error - 19-12-2011 13:08:38 | Computer Name = Perlen | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft....atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\\.\PHYSICALDRIVE0\Partition2
(Type 17) Detection Origin: %%845 Detection Type: %%822 Detection Source: %%820 User:
Perlen\Jon Process Name: Unknown Action: %%809 Action Status: To finish removing
malware and other potentially unwanted software, restart the computer. To see how
to finish removing malware and other potentially unwanted software, see the support
article on the Microsoft Security website. Error Code: 0x80070032 Error description:
The request is not supported. Signature Version: AV: 1.117.1361.0, AS: 1.117.1361.0,
NIS: 10.7.0.0 Engine Version: AM: 1.1.7903.0, NIS: 2.0.7707.0
Error - 19-12-2011 13:38:02 | Computer Name = Perlen | Source = Microsoft Antimalware | ID = 1119
Description = %%860 has encountered a critical error when taking action on malware
or other potentially unwanted software. For more information please see the following:
http://go.microsoft....atid=2147650952
Name:
Trojan:DOS/Alureon.E ID: 2147650952 Severity: Severe Category: Trojan Path: boot:_\Device\HarddiskVolume3;boot:_\Device\HarddiskVolume3\
Detection
Origin: %%845 Detection Type: %%822 Detection Source: %%818 User: NT AUTHORITY\SYSTEM
Process
Name: System Action: %%808 Action Status: To finish removing malware and other potentially
unwanted software, restart the computer. To see how to finish removing malware
and other potentially unwanted software, see the support article on the Microsoft
Security website. Error Code: 0x800704ec Error description: This program is blocked
by group policy. For more information, contact your system administrator. Signature
Version: AV: 1.117.1361.0, AS: 1.117.1361.0, NIS: 10.7.0.0 Engine Version: AM: 1.1.7903.0,
NIS: 2.0.7707.0
< End of report >
Edited by jonarni, 19 December 2011 - 02:02 PM.