Rapport OTL :
OTL logfile created on: 26/11/2011 11:02:27 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Sandrine\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy
3,75 Gb Total Physical Memory | 2,37 Gb Available Physical Memory | 63,36% Memory
free7,49 Gb Paging File | 5,86 Gb Available in Paging File | 78,20% Paging File
freePaging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451,66 Gb Total Space | 352,61 Gb
Free Space | 78,07% Space
Free | Partition Type: NTFS
Computer Name: SANDRINE-PC | User Name: Sandrine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/11/26 10:32:03 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sandrine\Desktop\OTL.exe
PRC - [2011/09/07 23:58:13 | 000,357,808 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
PRC - [2011/08/31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/08/07 12:03:52 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\
AntiVir Desktop\avguard.exe
PRC - [2011/04/21 06:53:48 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\
AntiVir Desktop\sched.exe
PRC - [2011/04/21 06:53:33 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\
AntiVir Desktop\avgnt.exe
PRC - [2010/04/06 19:31:32 | 004,866,120 | ---- | M] () -- C:\Program Files (x86)\Video Web Camera\VideoWebCamera.exe
PRC - [2010/03/09 00:58:24 | 000,250,368 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
PRC - [2010/03/09 00:56:08 | 000,258,560 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe
PRC - [2010/03/03 14:21:16 | 001,300,560 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2010/03/03 14:21:16 | 000,325,200 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2010/03/03 14:21:16 | 000,297,040 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
PRC - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
PRC - [2009/10/09 04:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
PRC - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
========== Modules (No Company Name) ========== MOD - [2010/04/06 19:31:32 | 004,866,120 | ---- | M] () -- C:\Program Files (x86)\Video Web Camera\VideoWebCamera.exe
MOD - [2010/03/09 01:18:10 | 000,465,576 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\sqlite3.dll
MOD - [2009/12/22 08:52:20 | 007,581,696 | ---- | M] () -- c:\Program Files (x86)\Adobe\Reader 9.0\Reader\RdLang32.FRA
MOD - [2009/10/03 10:48:05 | 000,106,496 | ---- | M] () -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\plug_ins\EScript.fra
MOD - [2009/10/03 10:44:48 | 000,012,288 | ---- | M] () -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\plug_ins\updater.FRA
MOD - [2009/05/20 07:02:04 | 000,072,200 | ---- | M] () -- C:\Program Files (x86)\Launch Manager\CdDirIo.dll
MOD - [2009/02/28 00:39:14 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\plug_ins\Weblink.FRA
MOD - [2009/02/28 00:33:36 | 001,708,032 | ---- | M] () -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\plug_ins\Annots.FRA
MOD - [2009/02/27 20:52:56 | 000,258,048 | ---- | M] () -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\sqlite.dll
MOD - [2009/01/18 23:50:02 | 000,417,792 | ---- | M] () -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AdobeXMP.dll
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:
64bit: - [2010/03/29 01:41:36 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2010/03/17 09:56:12 | 000,866,336 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe -- (ePowerSvc)
SRV:
64bit: - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service)
SRV:
64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/08/07 12:03:52 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\
AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/04/21 06:53:48 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\
AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/05/15 10:26:04 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/09 00:58:24 | 000,250,368 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2010/03/03 14:21:16 | 000,325,200 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2010/01/15 22:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/10/10 03:59:08 | 000,238,328 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/10/09 04:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:
64bit: - [2011/08/07 12:03:52 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:
64bit: - [2011/08/07 12:03:52 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:
64bit: - [2011/03/11 07:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 07:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010/08/09 04:36:42 | 000,048,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:
64bit: - [2010/04/07 03:04:22 | 002,216,960 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:
64bit: - [2010/03/29 01:51:38 | 006,405,632 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
DRV:
64bit: - [2010/03/29 00:46:28 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:
64bit: - [2010/03/20 19:59:08 | 000,321,064 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:
64bit: - [2010/02/08 14:57:22 | 000,239,136 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:
64bit: - [2009/12/22 01:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:
64bit: - [2009/12/10 12:25:10 | 000,301,104 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:
64bit: - [2009/12/02 08:01:24 | 000,213,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:
64bit: - [2009/08/23 10:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:
64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/05/06 00:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:
64bit: - [2009/05/06 00:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:
64bit: - [2008/06/16 02:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.packardbell.com/rdr.asp ... 5f4542d218IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.packardbell.com/rdr.asp ... 5f4542d218IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.packardbell.com/rdr.asp ... 5f4542d218IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.pucuy.com/IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-318668031-1002096723-1531166652-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.packardbell.com/rdr.asp ... 5f4542d218IE - HKU\S-1-5-21-318668031-1002096723-1531166652-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/IE - HKU\S-1-5-21-318668031-1002096723-1531166652-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010/08/17 17:28:52 | 000,000,000 | ---D | M]
[2010/08/19 12:58:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sandrine\AppData\Roaming\mozilla\Extensions
[2010/08/19 12:58:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sandrine\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:
64bit: - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files (x86)\Shareaza\RazaWebHook64.dll (Shareaza Development Team)
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files (x86)\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O2 - BHO: (EOBHO Class) - {C10DC1F4-CCDF-4224-A24D-B23AFC3573C8} - C:\Program Files (x86)\EoRezo\EoRezoBHO.dll File not found
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-318668031-1002096723-1531166652-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-318668031-1002096723-1531166652-1000\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O4:
64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\
AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Sandrine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:
64bit: - Extra context menu item: Google Sidewiki... -
res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki... -
res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4}
http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC0B0743-4936-4D14-829A-51AB56B29EFF}: DhcpNameServer = 212.27.40.241 212.27.40.240
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:
64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ========== [2011/11/26 10:48:02 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/11/26 10:47:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/11/26 10:47:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2011/11/26 10:43:29 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Roaming\Malwarebytes
[2011/11/26 10:40:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/26 10:40:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/26 10:40:26 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/11/26 10:40:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/26 10:39:19 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Sandrine\Desktop\erunt-setup.exe
[2011/11/26 10:37:50 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Sandrine\Desktop\mbam-setup-1.51.2.1300.exe
[2011/11/26 10:36:16 | 000,000,000 | ---D | C] -- C:\Windows\fr
[2011/11/26 10:32:01 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Sandrine\Desktop\OTL.exe
[2011/11/26 10:20:57 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\Desktop\backups
[2011/11/26 09:59:48 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{407CA1D6-8DDA-4E64-A84A-BEEF863AAC75}
[2011/11/25 07:44:58 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{76A8AAAF-F7DE-43A7-8D1D-2F6232AFB9D5}
[2011/11/24 17:48:14 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{DAD05923-FA74-4C61-B3F2-44057A4E400D}
[2011/11/24 07:40:38 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{E93683E8-0DD1-4ECE-9267-1C447226C067}
[2011/11/23 20:09:34 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{C3BC13DB-4C7D-4F7C-82CA-7A7C7A4CDA22}
[2011/11/23 17:52:42 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{22F2A57B-B03C-4C5A-8417-8CE3417B16F1}
[2011/11/21 19:08:56 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{EB6AC6EB-6C4C-41EB-B0BE-F27C4C51042A}
[2011/11/21 12:26:09 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{59F49E64-9B63-456A-B3A9-FC90F56D548E}
[2011/11/21 08:00:35 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{19D99F74-E289-48F4-B384-CC856DDE2F5D}
[2011/11/20 22:39:05 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{256A609B-9212-478A-8BC8-5ECC50DED226}
[2011/11/20 18:08:49 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{DD65D7A2-5AAC-4409-A66E-CE5CB31B8459}
[2011/11/20 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{D5B143DF-19B7-479B-8B71-8DE369293772}
[2011/11/18 12:20:43 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{E938B3F5-BE99-450C-8671-01DA06ED1889}
[2011/11/18 07:04:24 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{DCED6393-3E21-4EF6-89AC-42EC090D3CA5}
[2011/11/17 17:56:14 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{8C5488CE-D15C-4797-B58E-CF1C3FED8C4E}
[2011/11/16 07:22:42 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{7DE3F737-2E0E-4BF7-AEA1-92B379DB7436}
[2011/11/15 20:46:03 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{CD58A776-2F66-473A-9F50-27885E5BF09B}
[2011/11/15 19:39:37 | 001,837,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2011/11/15 19:39:37 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2011/11/15 19:39:37 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2011/11/15 19:39:36 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2011/11/15 19:39:35 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2011/11/15 19:39:35 | 000,265,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/11/15 19:39:35 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2011/11/15 19:39:35 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2011/11/15 19:39:34 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2011/11/15 19:23:35 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{A76002A4-09F0-478A-B9C1-379485B921B6}
[2011/11/15 12:18:13 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{60C31C3D-BD15-46D6-BF04-6827DF9BCF6C}
[2011/11/15 07:54:50 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{A68F7EB0-4457-44C5-92F2-3BF0C7D81EF9}
[2011/11/14 17:47:46 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{CCD537FB-B47A-4FA0-AC52-16D955D43700}
[2011/11/14 12:41:41 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{DDCE54A9-AC01-4E92-81C6-91DA87A1D6E3}
[2011/11/12 18:20:34 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{77DFFA05-054E-4882-8544-59FB7E4C2CA7}
[2011/11/12 11:57:47 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{F6868823-101D-4CB7-B668-9F454DF7A6FA}
[2011/11/10 19:20:12 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{AEBBADCE-AAB3-4946-A10F-41FBED0438D6}
[2011/11/10 12:16:32 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{34592FC6-E014-4D2D-85DF-8DE049EBAAAF}
[2011/11/09 17:47:23 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{658F37F4-62B8-49A1-BF60-1900B6AF3E78}
[2011/11/09 12:18:51 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{4559D93E-DF91-430D-A817-91BD28ED036A}
[2011/11/08 18:10:41 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{217F48B2-D8B9-49AB-B7EB-BE0CCF0E81F5}
[2011/11/08 07:56:36 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{F369AFE2-FE1E-411B-97AF-95A7DA52F1CD}
[2011/11/07 20:43:16 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{85CA106D-AB4B-407F-AC8F-8970BFAD963C}
[2011/11/07 20:40:46 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{E621A930-7A48-4562-A166-00FC120541AA}
[2011/11/07 20:39:24 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{4D3629EF-C104-476C-A741-EB193FC0C389}
[2011/11/07 20:37:50 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{49F952A6-63FF-4736-A650-95EE5CC539F9}
[2011/11/07 20:35:16 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{68227B5E-77DA-426F-A534-3C44CE03BA06}
[2011/11/07 20:34:03 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{BB8E2F08-5F37-4DB0-A9CE-DD74B97503DD}
[2011/11/07 20:32:55 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{5178020D-F5B8-44F2-A21F-4C7716BF1C9D}
[2011/11/07 20:27:35 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{4EEFA487-468B-49D8-81B3-25A255E976C1}
[2011/11/07 20:22:38 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{22D4D574-9226-4F20-8D29-ED7478C50550}
[2011/11/07 20:21:29 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{D0534E26-D1F8-43B3-9AC8-BEA80529548F}
[2011/11/07 20:19:36 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{8699A6D8-8166-471B-9302-49F94115FBCF}
[2011/11/07 20:18:02 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{6F7CF785-82C6-4912-A730-1D7BFF005B3E}
[2011/11/07 20:14:59 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{06808986-647C-404C-B7A7-682C3525E567}
[2011/11/07 20:07:21 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{47E1A71E-59BF-4E7C-A947-FA32EA5BF0A7}
[2011/11/07 20:03:15 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{30834C12-FD76-4B4C-8008-67702BC15911}
[2011/11/07 19:57:06 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{AC34A7AB-9E27-4B51-A092-A81881DC2545}
[2011/11/07 19:36:14 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{DE19122D-540B-4B8E-86A3-E3BF70B6976C}
[2011/11/07 19:22:52 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{D6CF7DDB-FB33-4004-AA75-EEC88E4CAE5B}
[2011/11/07 19:17:46 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{92846806-7CBB-40E9-BD98-6327D363CAA5}
[2011/11/07 19:13:27 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{1CD73DC1-85BE-4367-A493-301A94B41DEC}
[2011/11/07 19:04:03 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{469FF32A-43A5-4DF6-B0C6-AE0A56F77F30}
[2011/11/07 19:02:05 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{E0215323-027A-482B-8359-D16022573BC6}
[2011/11/07 19:00:38 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{11FFA7AB-148A-4B7F-B2F9-FE5752369A82}
[2011/11/07 18:35:06 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{11D1181E-DEE2-4268-B4B3-9AEDDE5A8841}
[2011/11/07 18:31:07 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{C5CC46A9-EABC-4749-80A8-6C46B3408B1D}
[2011/11/07 18:07:44 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{6D47D6D4-7095-4C73-A288-3A3BBEA3D3B5}
[2011/11/07 17:48:33 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{7622419D-06B6-444F-9878-A254DE9E6F2E}
[2011/11/07 13:00:05 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{F19B3286-9FDE-46E9-9A23-E3E27024D852}
[2011/11/07 12:23:19 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{38851182-DF7F-418B-8BA7-CCD019CEE904}
[2011/11/06 23:16:43 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{652F18B7-CCDF-4C87-AB13-3554D3047E8C}
[2011/11/04 17:20:05 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{AC4A16CD-7BBE-4278-9A30-6F71247E0D50}
[2011/11/03 19:50:01 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{392CF37B-814B-4B8C-9AB2-8CE83DFCD8B5}
[2011/11/03 07:46:04 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{3B0C54DB-4FB1-49CA-BF6E-185FCE4067B1}
[2011/11/02 21:30:51 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{CF4B5F6D-5C9A-496C-8D8B-AD659C8D1002}
[2011/11/02 17:49:20 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{4CB32A7A-7548-4691-AFD0-75337E84586D}
[2011/11/02 07:45:54 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{0B98FE0D-B698-4516-9A1F-DEE3E3FBE926}
[2011/11/01 20:18:23 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{1BE5B710-E130-4042-BF2A-95EFD0D28590}
[2011/11/01 16:30:09 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{7E8C43EA-B156-43E0-AA5B-BD81EE69B631}
[2011/10/31 20:14:05 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{11BC6C0A-46F3-4B5D-9B3E-0C920E94B702}
[2011/10/29 17:54:10 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{43CFCD28-2B21-4033-99E2-77C92D59A22B}
[2011/10/29 16:54:51 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{342C81E0-808D-48EC-B53A-FFB74DFE804D}
[2011/10/29 08:16:21 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{4BBAB4DD-D86F-4734-BACD-94658239E5AB}
[2011/10/28 12:01:29 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{2594C72B-6467-4B54-8917-5E289293FA75}
[2011/10/28 11:55:43 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{8258CAE3-33E4-4DE0-B0A0-6F7A714DE865}
[2011/10/28 06:42:11 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{5B16A3A6-9C69-48CF-BAD7-2C285E0EB161}
[2011/10/27 11:22:29 | 000,000,000 | ---D | C] -- C:\Users\Sandrine\AppData\Local\{77A817AE-D10D-437D-B875-E426ACAB3450}
========== Files - Modified Within 30 Days ========== [2011/11/26 11:04:13 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011/11/26 10:54:43 | 000,198,449 | ---- | M] () -- C:\Users\Sandrine\Desktop\00-PAD-nickW.pdf
[2011/11/26 10:54:13 | 000,001,070 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/26 10:47:39 | 000,001,116 | ---- | M] () -- C:\Users\Sandrine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/11/26 10:47:34 | 000,000,936 | ---- | M] () -- C:\Users\Sandrine\Desktop\NTREGOPT.lnk
[2011/11/26 10:47:34 | 000,000,917 | ---- | M] () -- C:\Users\Sandrine\Desktop\ERUNT.lnk
[2011/11/26 10:40:34 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/26 10:39:36 | 000,005,024 | ---- | M] () -- C:\Users\Sandrine\Desktop\erunt-loc_fr.zip
[2011/11/26 10:39:27 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Sandrine\Desktop\erunt-setup.exe
[2011/11/26 10:37:56 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Sandrine\Desktop\mbam-setup-1.51.2.1300.exe
[2011/11/26 10:32:03 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sandrine\Desktop\OTL.exe
[2011/11/26 10:05:16 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/26 10:05:16 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/26 09:53:14 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/26 09:51:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/26 09:51:38 | 3015,884,800 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/23 19:59:28 | 496,508,595 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/11/15 19:58:14 | 000,364,680 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/07 18:10:29 | 001,524,562 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/07 18:10:29 | 000,695,004 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2011/11/07 18:10:29 | 000,607,190 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/07 18:10:29 | 000,127,684 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2011/11/07 18:10:29 | 000,103,568 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
<End>