Hoi Abraham,
Er is maar een van de twee kladblok-vensters geopend en dat is OTL.txt. Het andere kladblok-venster heb ik maar een keer gezien en dat was toen ik het programma OTL voor de eerste keer gebruikte. Nu was het er weer niet.
Hier is de log met de naam OTL.txt
OTL logfile created on: 10-3-2012 22:08:12 - Run 6
OTL by OldTimer - Version 3.2.36.2 Folder = C:\Documents and Settings\Eigenaar\Bureaublad
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
2,00 Gb Total Physical Memory | 1,51 Gb Available Physical Memory | 75,40% Memory free
2,60 Gb Paging File | 2,28 Gb Available in Paging File | 87,54% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,45 Gb Total Space | 25,40 Gb Free Space | 34,12% Space Free | Partition Type: NTFS
Computer Name: LAKKIE | User Name: Eigenaar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012-03-10 21:25:37 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eigenaar\Bureaublad\OTL.com
PRC - [2012-01-23 08:13:14 | 000,522,848 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Internetbeveiliging\FWES\program\fsdfwd.exe
PRC - [2012-01-23 07:30:15 | 001,008,296 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Internetbeveiliging\Anti-Virus\fssm32.exe
PRC - [2012-01-23 07:30:13 | 000,512,680 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Internetbeveiliging\Anti-Virus\fsgk32.exe
PRC - [2010-03-18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009-08-05 16:58:52 | 000,186,976 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Internetbeveiliging\Common\FSMA32.EXE
PRC - [2009-08-05 16:58:50 | 000,076,384 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Internetbeveiliging\Common\FSLAUNCH.EXE
PRC - [2009-08-05 16:56:10 | 000,215,648 | ---- | M] (F-Secure Corporation) -- C:\Program Files\Internetbeveiliging\Anti-Virus\fsgk32st.exe
PRC - [2008-04-14 18:02:58 | 001,037,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== MOD - [2012-01-23 07:31:12 | 000,030,888 | ---- | M] () -- C:\Program Files\Internetbeveiliging\Anti-Virus\minifilter\hashlib_x86.dll
MOD - [2012-01-23 07:30:13 | 000,768,712 | ---- | M] () -- C:\Program Files\Internetbeveiliging\Anti-Virus\fm4av.dll
MOD - [2009-08-05 16:59:08 | 000,199,264 | ---- | M] () -- C:\Program Files\Internetbeveiliging\Spam Control\fsas.dll
MOD - [2009-08-05 16:58:30 | 000,330,336 | ---- | M] () -- \\?\c:\program files\internetbeveiliging\hips\fshook32.dll
MOD - [2009-08-05 16:58:30 | 000,236,128 | ---- | M] () -- \\?\c:\program files\internetbeveiliging\hips\fsumi.dll
MOD - [2009-02-27 18:13:06 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.NLD
MOD - [2005-10-07 15:05:32 | 000,125,440 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (Planner voor Automatische LiveUpdate)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (getPlusHelper) getPlus(R)
SRV - File not found [Disabled | Stopped] -- -- (AppMgmt)
SRV - File not found [Disabled | Stopped] -- -- (aawservice)
SRV - [2012-01-23 08:13:14 | 000,522,848 | ---- | M] (F-Secure Corporation) [On_Demand | Stopped] -- C:\Program Files\Internetbeveiliging\FWES\Program\fsdfwd.exe -- (FSDFWD)
SRV - [2012-01-23 07:33:03 | 000,061,088 | ---- | M] (F-Secure Corporation) [On_Demand | Stopped] -- C:\Program Files\Internetbeveiliging\ORSP Client\fsorsp.exe -- (FSORSPClient)
SRV - [2010-03-18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009-08-05 16:58:52 | 000,186,976 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files\Internetbeveiliging\Common\FSMA32.EXE -- (FSMA)
SRV - [2009-08-05 16:56:10 | 000,215,648 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files\Internetbeveiliging\Anti-Virus\fsgk32st.exe -- (F-Secure Gatekeeper Handler Starter)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (xpsec)
DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install)
DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (TVICHW32)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (SDTHOOK)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [File_System | Boot | Stopped] -- -- (pavboot)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (catchme)
DRV - [2012-01-23 08:19:01 | 000,082,120 | ---- | M] (F-Secure Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\fsdfw.sys -- (FSFW)
DRV - [2012-01-23 07:35:14 | 000,042,672 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\Drivers\fsbts.sys -- (fsbts)
DRV - [2012-01-23 07:31:25 | 000,148,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\Internetbeveiliging\Anti-Virus\minifilter\fsgk.sys -- (F-Secure Gatekeeper)
DRV - [2009-08-05 16:58:30 | 000,068,064 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- C:\Program Files\Internetbeveiliging\HIPS\drivers\fshs.sys -- (F-Secure HIPS)
DRV - [2006-11-10 15:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2006-07-31 21:44:00 | 000,580,992 | ---- | M] (Omnivision Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FilmScan.sys -- (APL531)
DRV - [2005-08-10 15:06:28 | 000,019,968 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2005-08-10 13:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005-05-16 14:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2002-08-15 14:27:04 | 000,011,721 | ---- | M] (SMaL Camera Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smallogi.sys -- (SMALUSB)
DRV - [2001-08-22 07:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-343818398-57989841-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.startpagina.nl/IE - HKU\S-1-5-21-343818398-57989841-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://nl.msn.com/?ocid=iehpIE - HKU\S-1-5-21-343818398-57989841-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl
IE - HKU\S-1-5-21-343818398-57989841-725345543-1003\..\SearchScopes,DefaultScope = {91216286-0DA8-4836-8C4F-FBFE3C1C9AED}
IE - HKU\S-1-5-21-343818398-57989841-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-343818398-57989841-725345543-1003\..\SearchScopes\{91216286-0DA8-4836-8C4F-FBFE3C1C9AED}: "URL" =
http://www.bing.com/search?q={searchTerms}&form=IE8SRC&src=IE-SearchBox
IE - HKU\S-1-5-21-343818398-57989841-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Oracle)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.4: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\litmus-ff@f-secure.com: C:\Program Files\Internetbeveiliging\NRS\litmus-ff@f-secure.com [2012-03-09 07:56:38 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2012-03-09 12:30:57 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\Internetbeveiliging\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\Internetbeveiliging\FSGUI\TNBUtil.exe (F-Secure Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-343818398-57989841-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-343818398-57989841-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-343818398-57989841-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-343818398-57989841-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-343818398-57989841-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-343818398-57989841-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Internetbeveiliging\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Internetbeveiliging\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Internetbeveiliging\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Internetbeveiliging\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183}
https://www.p3.postbank.nl/sesam/CAX.cab (CryptoRSA Control)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C}
http://messenger.zone.msn.com/binary/ms ... b27571.cab (Checkers Class)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B}
http://support.dell.com/systemprofiler/SysPro.CAB (Reg Error: Value error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E}
http://www.systemrequirementslab.com/sr ... ab_srl.cab (System Requirements Lab Class)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B}
http://messenger.zone.msn.com/binary/Mi ... b27571.cab (Minesweeper Flags Class)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}
http://acs.pandasoftware.com/activescan ... stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.microsoft.com/officeupdat ... t/opuc.cab (Office Update Installation Engine)
O16 - DPF: {3E90FFF5-1347-45B9-91F6-DA47926E9697}
http://www.ziggo.nl/f-secure/systemchec ... ysInfo.cab (PlaNet SysInfo Class)
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345}
https://www-secure.symantec.com/techsup ... gctlsi.cab (Symantec SmartIssue)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345}
https://www-secure.symantec.com/techsup ... gctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
http://support.euro.dell.com/systemprof ... ProExe.CAB (WMI Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://spaces.msn.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftup ... 6935634843 (MUWebControl Class)
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE}
http://housecall65.trendmicro.com/house ... hcImpl.cab (Housecall ActiveX 6.5)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61}
http://a840.g.akamai.net/7/840/537/2005 ... scan53.cab (HouseCall Besturing)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103}
http://www3.ca.com/securityadvisor/viru ... ebscan.cab (WScanCtl Class)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
http://messenger.zone.msn.com/binary/Me ... b27571.cab (MessengerStatsClient Class)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/C ... 3327546296 (Reg Error: Key error.)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9}
http://www.windowsecurity.com/trojanscan/axscan.cab (ASquaredScanForm Element)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/get/fl ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941}
http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BF771E44-3B3E-4EE2-B699-6376B42C7C8C}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Dell.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Dell.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004-04-04 14:55:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2012-03-10 21:27:51 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Eigenaar\Onlangs geopend
[2012-03-10 21:25:37 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Eigenaar\Bureaublad\OTL.com
[2012-03-10 19:47:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012-03-10 19:25:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012-03-10 16:55:36 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012-03-09 12:01:49 | 000,000,000 | ---D | C] -- C:\_OTL
[2012-03-08 20:31:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eigenaar\Application Data\Gena01
[2012-03-02 13:04:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012-02-11 12:38:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eigenaar\Mijn documenten\Doorlooptijden
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012-03-10 22:01:00 | 000,000,460 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{6A197408-3705-4F11-B57C-177D2AD69752}.job
[2012-03-10 21:25:37 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eigenaar\Bureaublad\OTL.com
[2012-03-10 20:16:42 | 000,000,667 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Bureaublad\Internet.lnk
[2012-03-10 20:03:36 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-03-10 20:02:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-03-10 12:04:09 | 000,002,523 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Bureaublad\Word.lnk
[2012-03-10 07:00:58 | 000,000,522 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled scanning task.job
[2012-03-09 12:58:43 | 000,000,587 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Bureaublad\Hotmail.url
[2012-03-09 12:30:57 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2012-03-06 20:55:22 | 000,046,273 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Mijn documenten\arma37 de centuriontank in nederlandse dienst.pdf
[2012-03-06 16:07:44 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120309-071321.backup
[2012-03-01 20:56:43 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120302-073217.backup
[2012-02-17 07:57:45 | 000,440,549 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120224-074908.backup
[2012-02-16 18:43:43 | 000,288,184 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012-02-16 18:24:47 | 000,535,422 | ---- | M] () -- C:\WINDOWS\System32\perfh013.dat
[2012-02-16 18:24:47 | 000,467,584 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012-02-16 18:24:47 | 000,102,892 | ---- | M] () -- C:\WINDOWS\System32\perfc013.dat
[2012-02-16 18:24:47 | 000,083,164 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012-02-12 09:25:20 | 000,000,202 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012-02-10 08:52:08 | 000,440,549 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120217-075745.backup
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2012-03-09 13:18:46 | 000,772,998 | ---- | C] () -- C:\Documents and Settings\Eigenaar\Mijn documenten\tramps cd.jpg
[2012-03-06 20:55:22 | 000,046,273 | ---- | C] () -- C:\Documents and Settings\Eigenaar\Mijn documenten\arma37 de centuriontank in nederlandse dienst.pdf
[2012-02-16 16:29:50 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012-02-16 16:29:50 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012-01-23 07:25:08 | 000,042,672 | ---- | C] () -- C:\WINDOWS\System32\drivers\fsbts.sys
[2011-08-09 19:33:18 | 000,653,176 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2011-08-09 19:33:18 | 000,003,411 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall-dBpoweramp Shorten Codec.dat
[2010-12-30 14:49:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\UniFish3.exe
[2010-05-13 11:32:42 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2010-05-13 11:32:42 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
========== LOP Check ========== [2012-01-23 07:23:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\f-secure
[2012-01-23 07:20:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fssg
[2004-04-11 16:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2011-07-03 15:03:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2006-01-23 18:32:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{9E3A8735-9ABB-468A-A982-A50862FC9AB3}
[2012-03-02 09:48:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Belastingdienst
[2012-03-05 21:16:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\BitTorrent
[2008-05-09 12:39:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\BitTorrent DNA
[2006-08-05 09:51:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\BPFTP
[2010-07-30 12:25:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\com.bigfatsimulations.airportmadness3.3A85083A650345D1ADAB4572C5816AD2DC9802A3.1
[2009-03-14 13:16:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\CoSoSys
[2008-01-18 18:29:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\dBpoweramp
[2009-12-04 18:02:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\DNA
[2012-01-29 14:44:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\ElevatedDiagnostics
[2009-12-01 16:10:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\F-Secure
[2010-05-14 11:56:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Gearbox Software
[2012-03-08 20:31:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Gena01
[2004-04-07 15:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Leadertech
[2010-04-30 16:39:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\PowerMp3WmaConverter
[2007-04-25 13:31:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Serif
[2006-01-23 18:29:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Seven Zip
[2008-05-20 16:10:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Uniblue
[2008-09-15 11:48:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\uTorrent
[2012-03-10 07:00:58 | 000,000,522 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled scanning task.job
[2012-03-10 22:01:00 | 000,000,460 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{6A197408-3705-4F11-B57C-177D2AD69752}.job
========== Purity Check ========== < End of report >