LA MOITIE DU LOG OLT
OTL logfile created on: 22/03/2011 19:59:01 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Lorenz du web\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free
5,00 Gb Paging File | 4,00 Gb Available in Paging File | 81,00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,04 Gb Total Space | 71,72 Gb Free Space | 49,79% Space Free | Partition Type: NTFS
Drive D: | 144,04 Gb Total Space | 80,94 Gb Free Space | 56,19% Space Free | Partition Type: NTFS
Computer Name: CRAZYLO | User Name: Lorenz du web | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/03/22 19:14:01 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Lorenz du web\Desktop\OTL.exe
PRC - [2011/03/18 18:58:47 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/08/27 14:22:00 | 002,356,848 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Online Armor\oaui.exe
PRC - [2010/08/27 14:21:58 | 003,638,240 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Online Armor\oasrv.exe
PRC - [2010/08/27 14:21:58 | 000,969,944 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Online Armor\OAhlp.exe
PRC - [2010/08/27 14:21:58 | 000,432,344 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Online Armor\OAreg.exe
PRC - [2010/08/27 14:21:56 | 000,380,272 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Online Armor\OAcat.exe
PRC - [2009/12/23 22:34:20 | 000,370,688 | ---- | M] (StarWind Software) -- C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
PRC - [2009/12/10 23:03:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/11/08 23:18:00 | 000,065,216 | ---- | M] (WordWeb Software) -- C:\Program Files\WordWeb\wweb32.exe
PRC - [2009/07/13 22:18:12 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2009/04/01 14:46:04 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\
AntiVir Desktop\sched.exe
PRC - [2009/03/03 03:38:13 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iashost.exe
PRC - [2009/03/02 12:09:54 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\
AntiVir Desktop\avguard.exe
PRC - [2009/03/02 12:08:11 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\
AntiVir Desktop\avgnt.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/10/29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/06/30 16:56:32 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2008/05/20 11:06:00 | 006,144,000 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007/11/06 21:58:20 | 000,294,912 | ---- | M] () -- C:\Program Files\HomePlayer\HomePlayer.exe
PRC - [2007/05/31 08:21:28 | 000,648,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdcBase.exe
========== Modules (SafeList) ========== MOD - [2011/03/22 19:14:01 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Lorenz du web\Desktop\OTL.exe
MOD - [2010/09/20 10:25:01 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msshsq.dll
MOD - [2010/08/31 16:39:57 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll
MOD - [2010/08/27 14:22:02 | 001,087,400 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Online Armor\OAwatch.dll
MOD - [2008/11/13 16:23:00 | 000,612,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll
MOD - [2008/01/21 03:25:01 | 000,183,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\duser.dll
MOD - [2008/01/21 03:25:01 | 000,097,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\powrprof.dll
MOD - [2008/01/21 03:24:47 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winnsi.dll
MOD - [2008/01/21 03:24:46 | 000,026,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wtsapi32.dll
MOD - [2008/01/21 03:24:35 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IPHLPAPI.DLL
MOD - [2008/01/21 03:24:02 | 000,128,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll
MOD - [2008/01/21 03:23:45 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wsock32.dll
MOD - [2006/11/02 13:34:33 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IconCodecService.dll
========== Win32 Services (SafeList) ========== SRV - [2010/08/27 14:21:58 | 003,638,240 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files\Online Armor\oasrv.exe -- (SvcOnlineArmor)
SRV - [2010/08/27 14:21:56 | 000,380,272 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files\Online Armor\OAcat.exe -- (OAcat)
SRV - [2009/12/23 22:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2009/12/10 23:03:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/07/13 22:18:12 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU)
SRV - [2009/04/01 14:46:04 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\
AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009/03/02 12:09:54 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\
AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/01/21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2007/05/31 08:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 08:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ========== DRV - [2010/08/27 14:22:36 | 000,038,856 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\oahlp32.sys -- (oahlpXX)
DRV - [2010/08/27 14:22:16 | 000,029,120 | ---- | M] (Emsisoft) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OAnet.sys -- (OAnet)
DRV - [2010/08/27 14:22:16 | 000,025,000 | ---- | M] (Emsisoft) [Kernel | System | Running] -- C:\Windows\System32\drivers\OAmon.sys -- (OAmon)
DRV - [2010/08/27 14:22:14 | 000,201,168 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\OADriver.sys -- (OADevice)
DRV - [2009/11/12 12:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009/11/12 05:14:28 | 000,066,664 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2009/11/11 15:11:30 | 000,181,792 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/09/05 13:25:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/08/04 17:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2009/06/29 00:36:36 | 000,017,920 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2009/06/17 09:56:18 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009/06/17 09:56:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009/03/30 09:32:47 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2009/03/24 15:07:58 | 000,055,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009/02/13 11:49:30 | 000,028,376 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009/02/13 11:34:33 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\
AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/01/14 17:46:04 | 000,077,824 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2008/12/10 15:56:26 | 000,017,792 | ---- | M] (Avnex) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vcsvad.sys -- (VCSVADHWSer) Avnex Virtual Audio Device (WDM)
DRV - [2008/11/13 16:23:00 | 007,580,192 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/05/30 12:44:42 | 000,146,944 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atswpdrv.sys -- (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2008/05/26 14:13:00 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2008/03/27 08:06:59 | 000,542,976 | ---- | M] (LiteOn) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Ltn_stk7070P.sys -- (Ltn_stk7070P)
DRV - [2007/12/16 16:57:20 | 000,075,776 | ---- | M] (Wasay) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSVD.sys -- (WSVD)
DRV - [2007/12/13 20:13:02 | 000,017,264 | ---- | M] (FSPro Labs) [Kernel | Boot | Running] -- C:\Windows\SYSTEM32\DRIVERS\MPRIFL.SYS -- (MPRIFL)
DRV - [2007/03/28 06:51:40 | 000,043,008 | ---- | M] (Winbond Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\winbondcir.sys -- (winbondcir)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.acer.com/rdr.aspx?b=ACA ... pire_7530gIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://fr.fr.acer.yahoo.com IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.acer.com/rdr.aspx?b=ACA ... pire_7530gIE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://global.acer.com [binary data]
IE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://global.acer.com [binary data]
IE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/IE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore =
http://homepage.acer.com/rdr.aspx?b=ACA ... pire_7530gIE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-160463765-1735941628-721991443-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..browser.search.defaulturl: "http://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.fr/firefox"
FF - prefs.js..extensions.enabledItems:
gazopa@hitachi.com:0.13
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.7.4
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems:
savesession@noasobi.net:1.3.1.6
FF - prefs.js..extensions.enabledItems:
tineye@ideeinc.com:1.1
FF - prefs.js..extensions.enabledItems:
foxyproxy@eric.h.jung:2.22.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "http://search.sweetim.com/search.asp?src=2&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "chrome://browser-region/locale/region.properties"
FF - prefs.js..browser.startup.homepage: "resource:/browserconfig.properties"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/22 19:05:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/22 19:05:42 | 000,000,000 | ---D | M]
[2008/11/05 17:50:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Extensions
[2011/03/21 00:48:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions
[2011/03/12 03:29:39 | 000,000,000 | ---D | M] (Session Manager) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2010/08/27 19:04:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/30 15:06:07 | 000,000,000 | ---D | M] (Linkification) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2011/03/12 03:29:35 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/03/12 03:29:35 | 000,000,000 | ---D | M] (Easy Youtube Video Downloader) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
[2011/03/12 03:29:41 | 000,000,000 | ---D | M] ("Flash Video Downloader (Youtube Downloader)") -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\artur.dubovoy@gmail.com
[2011/03/12 16:12:21 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\foxyproxy@eric.h.jung
[2011/02/01 22:49:41 | 000,000,000 | ---D | M] (GazoPa Similar Image Search) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\gazopa@hitachi.com
[2011/03/12 03:29:40 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\personas@christopher.beard
[2010/01/17 04:39:16 | 000,000,000 | ---D | M] (Save Session) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\savesession@noasobi.net
[2011/03/12 03:29:39 | 000,000,000 | ---D | M] (SkipScreen) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\SkipScreen@SkipScreen
[2011/03/12 03:29:35 | 000,000,000 | ---D | M] (TinEye Reverse Image Search) -- C:\Users\Lorenz du web\AppData\Roaming\mozilla\Firefox\Profiles\2hl3ezz5.default\extensions\tineye@ideeinc.com
[2011/01/01 20:50:16 | 000,001,992 | ---- | M] () -- C:\Users\Lorenz du web\AppData\Roaming\Mozilla\Firefox\Profiles\2hl3ezz5.default\searchplugins\hotfilesearch.xml
[2011/03/22 19:05:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2011/03/17 17:56:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) --
[2011/03/18 18:58:47 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/17 17:56:29 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2011/02/28 17:00:12 | 000,002,226 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,001,822 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
[2010/01/01 09:00:00 | 000,001,154 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2010/01/01 09:00:00 | 000,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2010/01/01 09:00:00 | 000,000,956 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml
O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
O3 - HKU\S-1-5-21-160463765-1735941628-721991443-1002\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-160463765-1735941628-721991443-1002\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKU\S-1-5-21-160463765-1735941628-721991443-1002\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O3 - HKU\S-1-5-21-160463765-1735941628-721991443-1002\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\
AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe (Acer Incorporated)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [Google Web Services] File not found
O4 - HKU\S-1-5-18..\Run: [Google Web Services] File not found
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-160463765-1735941628-721991443-1002..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKU\S-1-5-21-160463765-1735941628-721991443-1002..\Run: [WordWeb] C:\Program Files\WordWeb\wweb32.exe (WordWeb Software)
O4 - Startup: C:\Users\Lorenz du web\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-160463765-1735941628-721991443-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O9 - Extra Button: Envoyer
à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Envoyer
à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/ms ... b56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/Messenger ... E_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Me ... b56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.240 212.27.40.241
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AWinNotifyVitaKey MC3000: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Users\Lorenz du web\AppData\Roaming\Microsoft\Windows Photo Gallery\Papier peint de la Galerie de photos Windows.jpg
O24 - Desktop BackupWallPaper: C:\Users\Lorenz du web\AppData\Roaming\Microsoft\Windows Photo Gallery\Papier peint de la Galerie de photos Windows.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\PROGRA~1\Online Armor\oaevent.dll (Emsi Software GmbH)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{43625bb8-9e26-11dd-a134-001e68e237e8}\Shell - "" = AutoRun
O33 - MountPoints2\{43625bb8-9e26-11dd-a134-001e68e237e8}\Shell\AutoRun\command - "" = F:\cdstart.exe
O33 - MountPoints2\{962943b4-3d75-11de-a7b9-001e68e237e8}\Shell\AutoRun\command - "" = cb.exe
O33 - MountPoints2\{962943b4-3d75-11de-a7b9-001e68e237e8}\Shell\open\Command - "" = cb.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ========== [2011/03/22 19:23:00 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/03/22 19:21:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/03/22 19:21:43 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2011/03/22 19:20:46 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Lorenz du web\Desktop\erunt-setup.exe
[2011/03/22 19:17:39 | 007,734,240 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Lorenz du web\Desktop\mbam-setup.exe
[2011/03/22 19:15:56 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW
[2011/03/22 19:14:00 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Lorenz du web\Desktop\OTL.exe
[2011/03/22 19:05:00 | 012,660,544 | ---- | C] (Mozilla) -- C:\Users\Lorenz du web\Desktop\Firefox Setup 4.0.exe
[2011/03/22 12:15:14 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/03/21 00:26:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/03/20 13:42:36 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\Desktop\freeboxV6_valid.pl_fichiers
[2011/03/17 20:50:34 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\Desktop\OpenOffice.org 3.1 (fr) Installation Files
[2011/03/17 17:56:45 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/03/17 17:56:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/03/17 17:56:45 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/03/17 17:52:51 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\Desktop\OpenOffice.org 3.3 (fr) Installation Files
[2011/03/17 17:45:28 | 011,338,008 | ---- | C] (Tracker Software Products Ltd.) -- C:\Users\Lorenz du web\Desktop\PDFXCview.exe
[2011/03/17 17:21:08 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\Desktop\backups
[2011/03/17 17:03:40 | 001,377,112 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Lorenz du web\Desktop\TDSSKiller.exe
[2011/03/14 12:20:38 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2011/03/14 01:28:23 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\Desktop\banque postale
[2011/03/14 01:25:55 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\Desktop\divers
[2011/03/12 01:29:30 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
[2011/03/12 01:28:00 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrsmgr.dll
[2011/03/12 01:27:43 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrs.exe
[2011/03/12 01:27:43 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrshost.exe
[2011/03/12 01:27:43 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsmprovhost.exe
[2011/03/12 01:27:42 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsmplpxy.dll
[2011/03/12 01:27:42 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrssrv.dll
[2011/03/12 01:27:40 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtfwd.dll
[2011/03/12 01:27:40 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecutil.exe
[2011/03/12 01:27:40 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecapi.dll
[2011/03/12 01:27:39 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmRes.dll
[2011/03/12 01:27:39 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pwrshplugin.dll
[2011/03/12 01:27:36 | 000,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManMigrationPlugin.dll
[2011/03/12 01:27:36 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManHTTPConfig.exe
[2011/03/12 01:27:36 | 000,241,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrscmd.dll
[2011/03/12 01:27:36 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmWmiPl.dll
[2011/03/12 01:27:36 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmAuto.dll
[2011/03/12 01:26:24 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011/03/12 01:26:24 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011/03/12 01:26:24 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011/03/12 01:26:24 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011/03/12 01:26:24 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/03/12 01:26:24 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011/03/12 01:26:23 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011/03/12 01:26:23 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011/03/12 01:26:22 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011/03/12 01:26:21 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/03/12 01:26:20 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011/03/12 01:26:20 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011/03/12 01:26:19 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2011/03/12 01:26:19 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011/03/12 01:26:19 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/03/12 01:26:18 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011/03/12 01:26:18 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011/03/12 01:26:05 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/03/12 01:26:05 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2011/03/12 01:26:05 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2011/03/12 01:26:05 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbeio.dll
[2011/03/12 01:26:01 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2011/03/12 01:26:00 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2011/03/12 01:25:58 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskschd.dll
[2011/03/12 01:25:58 | 000,345,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmicmiplugin.dll
[2011/03/12 01:25:58 | 000,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskcomp.dll
[2011/03/12 01:25:55 | 003,602,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011/03/12 01:25:55 | 003,550,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011/03/12 01:25:48 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2011/03/12 01:25:46 | 001,169,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sdclt.exe
[2011/03/12 01:25:45 | 000,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbc32.dll
[2011/03/12 01:25:42 | 002,038,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011/03/12 01:25:38 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2011/03/12 01:24:41 | 000,292,352 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2011/03/12 01:24:41 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2011/03/12 01:24:41 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2011/03/11 22:06:53 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\Desktop\thr
[2011/03/09 01:04:44 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Users\Lorenz du web\Desktop\HiJackThis.exe
[2011/03/03 00:00:08 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\Desktop\nouvelles preuves
[2011/02/28 17:00:28 | 000,000,000 | ---D | C] -- C:\Program Files\Babylon
[2011/02/28 17:00:10 | 000,000,000 | ---D | C] -- C:\Users\Lorenz du web\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JMHL Loader
[2011/02/28 17:00:09 | 000,000,000 | ---D | C] -- C:\Program Files\JMHL Loader
[2011/02/28 00:43:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Celestia
[2011/02/28 00:43:05 | 000,000,000 | ---D | C] -- C:\Program Files\Celestia
[2011/02/22 19:35:01 | 000,000,000 | ---D | C] -- C:\Package
[2008/07/22 09:01:25 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/03/22 19:56:23 | 000,126,339 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/03/22 19:52:49 | 000,126,339 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011/03/22 19:51:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At14.job
[2011/03/22 19:50:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At44.job
[2011/03/22 19:50:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At13.job
[2011/03/22 19:45:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At47.job
[2011/03/22 19:44:51 | 026,809,322 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2011/03/22 19:44:50 | 009,307,074 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2011/03/22 19:44:49 | 008,789,462 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/03/22 19:44:49 | 007,977,902 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/03/22 19:38:14 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/22 19:38:14 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/22 19:38:09 | 000,067,584 | ---- | M] () -- C:\Windows\bootstat.dat
[2011/03/22 19:23:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At6.job
[2011/03/22 19:23:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At4.job
[2011/03/22 19:22:36 | 000,000,917 | ---- | M] () -- C:\Users\Lorenz du web\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/03/22 19:21:44 | 000,000,737 | ---- | M] () -- C:\Users\Lorenz du web\Desktop\NTREGOPT.lnk
[2011/03/22 19:21:44 | 000,000,718 | ---- | M] () -- C:\Users\Lorenz du web\Desktop\ERUNT.lnk
[2011/03/22 19:19:50 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Lorenz du web\Desktop\erunt-setup.exe
[2011/03/22 19:17:31 | 007,734,240 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Lorenz du web\Desktop\mbam-setup.exe
[2011/03/22 19:14:38 | 000,000,395 | ---- | M] () -- C:\Users\Lorenz du web\Desktop\scan.zip
[2011/03/22 19:14:01 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Lorenz du web\Desktop\OTL.exe
[2011/03/22 19:14:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At18.job
[2011/03/22 19:13:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At17.job
[2011/03/22 19:12:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At38.job
[2011/03/22 19:09:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At40.job
[2011/03/22 19:05:45 | 000,000,874 | ---- | M] () -- C:\Users\Lorenz du web\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/22 19:05:44 | 000,000,850 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/03/22 19:04:20 | 012,660,544 | ---- | M] (Mozilla) -- C:\Users\Lorenz du web\Desktop\Firefox Setup 4.0.exe
[2011/03/22 19:04:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At78.job
[2011/03/20 13:42:37 | 000,020,285 | ---- | M] () -- C:\Users\Lorenz du web\Desktop\freeboxV6_valid.pl.htm
[2011/03/17 21:07:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At32.job
[2011/03/17 21:07:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At31.job
[2011/03/17 20:49:40 | 135,328,296 | ---- | M] () -- C:\Users\Lorenz du web\Desktop\openoffice-org_openoffice.org_3.1.0_francais_10677.exe
[2011/03/17 18:21:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At71.job
[2011/03/17 18:15:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At49.job
[2011/03/17 18:15:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At46.job
[2011/03/17 18:08:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At83.job
[2011/03/17 17:56:28 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/03/17 17:56:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/03/17 17:56:28 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/03/17 17:56:27 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011/03/17 17:48:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At51.job
[2011/03/17 17:08:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At26.job
[2011/03/17 17:08:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At25.job
[2011/03/17 16:17:59 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At8.job
[2011/03/17 15:59:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At34.job
[2011/03/17 12:13:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At36.job
[2011/03/17 12:13:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At3.job
[2011/03/17 12:10:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At70.job
[2011/03/17 12:05:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At43.job
[2011/03/17 12:03:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At16.job
[2011/03/17 12:03:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At15.job
[2011/03/17 11:52:03 | 000,000,376 | ---- | M] () -- C:\Windows\tasks\At2.job
[2011/03/17 02:22:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At1.job
[2011/03/17 02:20:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At39.job
[2011/03/17 01:06:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At57.job
[2011/03/17 00:53:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At68.job
[2011/03/17 00:49:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At87.job
[2011/03/17 00:41:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At86.job
[2011/03/17 00:13:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At91.job
[2011/03/17 00:13:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At85.job
[2011/03/17 00:10:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At90.job
[2011/03/16 23:57:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At65.job
[2011/03/16 23:49:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At84.job
[2011/03/16 23:49:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At61.job
[2011/03/16 23:46:01 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At76.job
[2011/03/15 21:57:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At50.job
[2011/03/15 21:57:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At42.job
[2011/03/15 21:48:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At72.job
[2011/03/15 21:43:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At64.job
[2011/03/15 21:38:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At41.job
[2011/03/15 21:28:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At24.job
[2011/03/15 21:28:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At23.job
[2011/03/15 21:25:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At79.job
[2011/03/15 11:58:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At22.job
[2011/03/15 11:57:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At21.job
[2011/03/15 11:52:02 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At82.job
[2011/03/15 11:52:01 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At69.job
[2011/03/14 23:35:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At56.job
[2011/03/14 23:25:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At75.job
[2011/03/14 23:21:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At59.job
[2011/03/14 23:19:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At55.job
[2011/03/14 23:01:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At7.job
[2011/03/14 23:01:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At5.job
[2011/03/14 22:56:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At73.job
[2011/03/14 22:47:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At81.job
[2011/03/14 22:45:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At48.job
[2011/03/14 22:44:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At80.job
[2011/03/14 22:20:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At28.job
[2011/03/14 22:19:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At67.job
[2011/03/14 22:19:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At27.job
[2011/03/14 22:13:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At20.job
[2011/03/14 22:12:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At19.job
[2011/03/14 12:22:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At45.job
[2011/03/13 15:57:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At33.job
[2011/03/13 14:54:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At54.job
[2011/03/13 14:43:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At77.job
[2011/03/13 14:39:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At12.job
[2011/03/13 14:38:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At53.job
[2011/03/13 14:38:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At11.job
[2011/03/13 14:32:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At60.job
[2011/03/13 14:28:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At89.job
[2011/03/13 14:20:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At58.job
[2011/03/13 14:14:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At66.job
[2011/03/13 13:46:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At88.job
[2011/03/13 13:29:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At63.job
[2011/03/13 13:29:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At52.job
[2011/03/13 12:58:00 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At74.job
[2011/03/12 18:46:08 | 000,014,140 | ---- | M] () -- C:\Users\Lorenz du web\.recently-used.xbel
[2011/03/12 14:18:22 | 000,296,128 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/03/11 16:56:28 | 004,285,785 | ---- | M] () -- C:\Users\Lorenz du web\Desktop\ComboFix.exe
[2011/03/10 12:27:50 | 001,377,112 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Lorenz du web\Desktop\TDSSKiller.exe
[2011/03/09 01:04:46 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Users\Lorenz du web\Desktop\HiJackThis.exe
[2011/03/05 01:27:58 | 000,103,837 | ---- | M] () -- C:\Users\Lorenz du web\a786a84826cad0f158139584feb29f25.flv
[2011/03/04 11:47:07 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At30.job
[2011/03/04 11:47:07 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At29.job
[2011/03/02 13:08:45 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At62.job
[2011/03/02 11:36:06 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At9.job
[2011/03/02 11:36:06 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At10.job
[2011/03/02 10:38:08 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At35.job
[2011/02/26 15:06:36 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml
[2011/02/23 14:30:31 | 000,108,736 | RHS- | M] () -- C:\Users\Lorenz du web\AppData\Roaming\netsvcss.exe
[2011/02/22 20:45:09 | 000,000,255 | ---- | M] () -- C:\Users\Lorenz du web\Documents\ax_files.xml
[2011/02/22 20:18:52 | 000,244,224 | ---- | M] () -- C:\Users\Lorenz du web\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/21 12:32:18 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\At37.job
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/03/22 19:22:36 | 000,000,917 | ---- | C] () -- C:\Users\Lorenz du web\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/03/22 19:21:44 | 000,000,737 | ---- | C] () -- C:\Users\Lorenz du web\Desktop\NTREGOPT.lnk
[2011/03/22 19:21:44 | 000,000,718 | ---- | C] () -- C:\Users\Lorenz du web\Desktop\ERUNT.lnk
[2011/03/22 19:14:38 | 000,000,395 | ---- | C] () -- C:\Users\Lorenz du web\Desktop\scan.zip
[2011/03/22 19:05:44 | 000,000,862 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/03/20 13:42:36 | 000,020,285 | ---- | C] () -- C:\Users\Lorenz du web\Desktop\freeboxV6_valid.pl.htm
[2011/03/17 20:48:14 | 135,328,296 | ---- | C] () -- C:\Users\Lorenz du web\Desktop\openoffice-org_openoffice.org_3.1.0_francais_10677.exe