Hi,
I did already today a windows update and installed spywareblaster.
there were 2 updates that i diden't do Sql server express and Genuine advantage.
Here is the OTL.log
OTL logfile created on: 26/05/2011 17:35:39 - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Patrick\Bureaublad
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000813 | Country: België | Language: NLB | Date Format: d/MM/yyyy
1023,39 Mb Total Physical Memory | 507,96 Mb Available Physical Memory | 49,64% Memory free
2,40 Gb Paging File | 2,11 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 1535 2096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55,78 Gb Total Space | 24,34 Gb Free Space | 43,64% Space Free | Partition Type: NTFS
Computer Name: LAPTOP_DELL | User Name: Patrick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Patrick\Bureaublad\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe (International Business Machines Corporation)
PRC - C:\Program Files\IBM\SQLLIB\BIN\db2mgmtsvc.exe (International Business Machines Corporation)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe ()
PRC - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe (The Firebird Project)
PRC - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe (The Firebird Project)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\1XConfig.exe (Intel)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\BAsfIpM.exe (Broadcom Corp.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
PRC - C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
PRC - C:\Program Files\Microsoft Office\Office\1043\OLFSNT40.EXE (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Patrick\Bureaublad\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) -- File not found
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (DB2NTSECSERVER_DB2COPY1) DB2 Security Server (DB2COPY1) -- C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe (International Business Machines Corporation)
SRV - (DB2MGMTSVC_DB2COPY1) DB2 Management Service (DB2COPY1) -- C:\Program Files\IBM\SQLLIB\BIN\db2mgmtsvc.exe (International Business Machines Corporation)
SRV - (msvsmon80) -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (FirebirdServerDefaultInstance) -- C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe (The Firebird Project)
SRV - (FirebirdGuardianDefaultInstance) -- C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe (The Firebird Project)
SRV - (WLANKEEPER) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (BAsfIpM) -- C:\WINDOWS\system32\BAsfIpM.exe (Broadcom Corp.)
========== Driver Services (SafeList) ==========
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (tmcomm) -- C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (STAC97) -- C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (w29n51) Stuurprogramma voor Intel(R) -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (APPDRV) -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (IWCA) -- C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (HSFHWICH) -- C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (GTIPCI21) -- C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
DRV - (omci) -- C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (BASFND) -- C:\WINDOWS\system32\drivers\BASFND.sys (Broadcom Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.euro.dell.com/
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://www.euro.dell.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.euro.dell.com/
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://www.euro.dell.com/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.be/
IE - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/01 13:45:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/10 21:17:16 | 000,000,000 | ---D | M]
[2009/04/09 22:07:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Patrick\Application Data\Mozilla\Extensions
[2011/02/21 20:48:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gsdxxua1.default\extensions
[2010/10/11 21:00:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gsdxxua1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2005/03/13 07:07:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/25 18:05:05 | 000,001,892 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bolcom-nl.xml
[2010/11/25 18:05:05 | 000,004,558 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\marktplaats-nl.xml
[2010/11/25 18:05:05 | 000,001,111 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\vandale-nl.xml
[2010/11/25 18:05:05 | 000,001,049 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-nl.xml
[2010/11/25 18:05:05 | 000,001,106 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-nl.xml
O1 HOSTS File: ([2011/05/26 07:55:41 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - File not found
O3 - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
O4 - HKU\.DEFAULT..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe (Adobe Systems, Inc.)
O4 - HKU\S-1-5-18..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10b.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\Poort voor Symantec Fax Starter Edition.lnk = C:\Program Files\Microsoft Office\Office\1043\OLFSNT40.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-464677283-1223472582-1953054680-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB}
http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IntelWireless: DllName - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop Components:0 (Mijn huidige introductiepagina) - About:Home
O29 - HKLM SecurityProviders - (zwebauth.dll) - C:\WINDOWS\System32\ZWebAuth.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/09/13 15:06:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/26 12:49:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programma's\SpywareBlaster
[2011/05/26 12:09:44 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/05/26 07:57:10 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/05/26 07:55:40 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/05/26 07:54:28 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Patrick\Bureaublad\OTL.exe
[2011/05/26 07:41:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Patrick\Bureaublad\Nieuwe map
[2011/05/26 00:01:37 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/05/25 22:57:46 | 000,000,000 | ---D | C] -- C:\mY_stuff
[2011/05/25 17:41:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/05/25 10:24:49 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Documents and Settings\Patrick\Bureaublad\ATF-Cleaner.exe
[2011/05/24 21:52:35 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/05/22 10:05:00 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/22 10:05:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programma's\Malwarebytes' Anti-Malware
[2011/05/22 10:04:56 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/22 10:04:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/22 10:02:51 | 007,734,240 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Patrick\Bureaublad\mbam-setup.exe
[2011/05/21 11:44:24 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/05/21 11:40:17 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/05/21 11:40:16 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/05/21 11:40:16 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/05/21 11:40:16 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/05/21 11:40:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/05/21 11:39:44 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/05/20 18:15:05 | 000,953,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/05/20 18:14:49 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/05/20 18:14:21 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/05/20 18:09:53 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2011/05/20 18:08:33 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2011/05/19 08:02:57 | 001,407,280 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Patrick\Bureaublad\TDSSKiller.exe
[2011/05/14 11:55:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Patrick\Mijn documenten\14-05-2011
[2011/05/14 11:42:42 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2011/05/14 11:42:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programma's\ERUNT
[2011/05/14 11:39:33 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Patrick\Bureaublad\erunt-setup.exe
[2011/05/10 22:50:23 | 000,589,632 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Patrick\Bureaublad\aswMBR.exe
[2011/05/01 14:29:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2011/05/01 14:17:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programma's\CCleaner
[2011/05/01 14:17:33 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[1999/05/24 01:17:58 | 000,099,840 | ---- | C] (Symantec Corp.) -- C:\Program Files\Common Files\IRAABOUT.DLL
[1998/12/09 04:53:54 | 000,186,368 | ---- | C] (Symantec Corp., Peter Norton Computing Group) -- C:\Program Files\Common Files\IRAREG.DLL
[1998/12/09 04:53:54 | 000,070,144 | ---- | C] (Symantec Corp., Peter Norton Computing Group) -- C:\Program Files\Common Files\IRAMDMTR.DLL
[1998/12/09 04:53:54 | 000,048,640 | ---- | C] (Symantec Corp., Peter Norton Computing Group) -- C:\Program Files\Common Files\IRALPTTR.DLL
[1998/12/09 04:53:54 | 000,031,744 | ---- | C] (Symantec Corp., Peter Norton Computing Group) -- C:\Program Files\Common Files\IRAWEBTR.DLL
[1998/12/09 04:53:54 | 000,017,920 | ---- | C] (Symantec Corp.) -- C:\Program Files\Common Files\IRASRIAL.DLL
========== Files - Modified Within 30 Days ==========
[2011/05/26 17:32:00 | 000,001,046 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/26 12:49:43 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\SpywareBlaster.lnk
[2011/05/26 12:30:18 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/05/26 12:29:34 | 000,001,042 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/26 12:29:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/26 12:29:00 | 000,255,064 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/26 12:26:02 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/05/26 12:13:48 | 000,559,088 | ---- | M] () -- C:\WINDOWS\System32\perfh013.dat
[2011/05/26 12:13:48 | 000,490,570 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/05/26 12:13:48 | 000,110,604 | ---- | M] () -- C:\WINDOWS\System32\perfc013.dat
[2011/05/26 12:13:48 | 000,090,578 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/05/26 07:55:41 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/05/26 07:54:32 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Patrick\Bureaublad\OTL.exe
[2011/05/26 07:37:20 | 000,513,320 | ---- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\erunt.zip
[2011/05/25 10:24:50 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\Patrick\Bureaublad\ATF-Cleaner.exe
[2011/05/23 18:49:13 | 004,353,829 | R--- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\ComboFix.exe
[2011/05/23 18:42:29 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/22 10:05:00 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Bureaublad\Malwarebytes' Anti-Malware.lnk
[2011/05/22 10:02:51 | 007,734,240 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Patrick\Bureaublad\mbam-setup.exe
[2011/05/21 11:44:30 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011/05/21 11:39:00 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\MBR.dat
[2011/05/19 08:02:37 | 001,280,208 | ---- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\tdsskiller.zip
[2011/05/18 08:48:28 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\Defogger.exe
[2011/05/17 20:39:40 | 000,589,632 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Patrick\Bureaublad\aswMBR.exe
[2011/05/17 20:38:38 | 000,000,135 | ---- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\Regfix.reg
[2011/05/14 23:45:16 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/14 11:50:25 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\ERUNT.lnk
[2011/05/14 11:40:28 | 000,625,664 | ---- | M] () -- C:\Documents and Settings\Patrick\Bureaublad\dds.scr
[2011/05/14 11:39:36 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Patrick\Bureaublad\erunt-setup.exe
[2011/05/13 13:21:28 | 001,407,280 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Patrick\Bureaublad\TDSSKiller.exe
[2011/05/10 22:14:04 | 000,434,142 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110514-120905.backup
[2011/05/01 21:48:42 | 000,433,442 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110510-221404.backup
[2011/05/01 21:33:10 | 000,000,326 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011/05/01 14:17:34 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Bureaublad\CCleaner.lnk
========== Files Created - No Company Name ==========
[2011/05/26 12:49:43 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\SpywareBlaster.lnk
[2011/05/26 07:37:16 | 000,513,320 | ---- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\erunt.zip
[2011/05/23 18:47:40 | 004,353,829 | R--- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\ComboFix.exe
[2011/05/22 10:05:00 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Bureaublad\Malwarebytes' Anti-Malware.lnk
[2011/05/21 11:44:30 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/05/21 11:44:27 | 000,261,936 | RHS- | C] () -- C:\cmldr
[2011/05/21 11:40:17 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/05/21 11:40:17 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/05/21 11:40:16 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/05/21 11:40:16 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/05/21 11:40:16 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/05/19 08:02:33 | 001,280,208 | ---- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\tdsskiller.zip
[2011/05/18 08:48:28 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\Defogger.exe
[2011/05/17 20:40:44 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\MBR.dat
[2011/05/17 20:38:38 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\Regfix.reg
[2011/05/14 11:50:25 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\ERUNT.lnk
[2011/05/14 11:40:24 | 000,625,664 | ---- | C] () -- C:\Documents and Settings\Patrick\Bureaublad\dds.scr
[2011/05/01 14:17:34 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Bureaublad\CCleaner.lnk
[2010/08/22 21:09:07 | 000,015,880 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2010/08/21 17:27:29 | 000,000,326 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/02/05 00:03:00 | 000,046,856 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2008/03/29 21:59:36 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/02/21 21:24:46 | 000,162,304 | ---- | C] () -- C:\Program Files\UNWISE.EXE
[2007/11/12 19:34:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PowerReg.dat
[2007/08/26 20:16:58 | 000,000,120 | ---- | C] () -- C:\WINDOWS\imagedit.ini
[2007/01/15 20:59:25 | 000,000,018 | ---- | C] () -- C:\WINDOWS\paswoord.INI
[2006/11/04 19:24:55 | 000,001,168 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/11/04 16:16:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/10/28 20:44:56 | 000,001,753 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/05/21 00:05:04 | 000,006,656 | ---- | C] () -- C:\Documents and Settings\Patrick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/17 14:53:42 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\ArmAccess.dll
[2005/11/08 20:56:26 | 000,016,973 | ---- | C] () -- C:\WINDOWS\System32\ZWebAuth.dll
[2005/09/11 10:31:43 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2005/08/21 17:30:54 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2005/07/13 19:57:11 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\WebOffer.exe
[2005/07/13 19:57:10 | 000,716,800 | ---- | C] () -- C:\WINDOWS\System32\WebOffer.dll
[2005/06/20 22:48:45 | 000,000,763 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/06/20 22:48:45 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2005/06/20 22:48:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2005/06/20 22:09:43 | 000,000,424 | ---- | C] () -- C:\WINDOWS\ChssBase.ini
[2005/06/20 19:46:19 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Patrick\Local Settings\Application Data\fusioncache.dat
[2005/06/16 18:26:12 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/06/16 18:23:59 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2005/06/16 18:21:30 | 000,028,779 | ---- | C] () -- C:\WINDOWS\System32\javaw.exe
[2005/06/16 18:21:30 | 000,024,681 | ---- | C] () -- C:\WINDOWS\System32\java.exe
[2005/06/16 18:07:40 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
[2005/06/16 18:07:26 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2005/06/16 18:06:56 | 000,000,423 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/09/13 15:11:34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/09/13 15:04:15 | 000,021,748 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/09/13 15:03:33 | 000,003,717 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/09/13 14:59:34 | 000,004,774 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/09/13 14:58:52 | 000,255,064 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/09/13 14:52:55 | 000,559,088 | ---- | C] () -- C:\WINDOWS\System32\perfh013.dat
[2004/09/13 14:52:55 | 000,318,670 | ---- | C] () -- C:\WINDOWS\System32\perfi013.dat
[2004/09/13 14:52:55 | 000,110,604 | ---- | C] () -- C:\WINDOWS\System32\perfc013.dat
[2004/09/13 14:52:55 | 000,039,178 | ---- | C] () -- C:\WINDOWS\System32\perfd013.dat
[2004/09/13 14:52:42 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/09/13 14:52:40 | 000,490,570 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/09/13 14:52:40 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/09/13 14:52:40 | 000,090,578 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/09/13 14:52:40 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/09/13 14:52:39 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/09/13 14:52:38 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/09/13 14:52:37 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/09/13 14:52:32 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/09/13 14:52:32 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/09/13 14:52:24 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/09/13 14:52:17 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/12 09:44:10 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\iwca.dll
[2002/06/28 16:20:54 | 000,005,025 | ---- | C] () -- C:\WINDOWS\System32\patterns.dat
[1999/01/22 20:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2008/04/10 20:44:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IBM
[2006/02/10 22:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2011/05/26 17:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/22 20:19:16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/21 17:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greetje\Application Data\Imomx
[2009/08/16 10:43:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Patrick\Application Data\ChessBase
[2005/12/27 21:18:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Patrick\Application Data\HK-Software
[2008/05/27 20:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Patrick\Application Data\IBM
[2006/05/12 15:53:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Patrick\Application Data\RSC_Antwerpen
[2008/07/08 21:34:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Patrick\Application Data\Toad Data Modeler Freeware
[2005/06/23 08:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Patrick\Application Data\Van Dyke Technologies
[2010/06/21 19:08:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Patrick\Application Data\Widyo
[2011/05/26 12:30:18 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >