ComboFix 08-11-29.03 - Jacques 2008-11-30 13:40:32.1 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.512 [GMT 1:00]
Lancé depuis: d:\documents and settings\Jacques\Bureau\ComboFix.exe
Commutateurs utilisés :: d:\documents and settings\Jacques\Bureau\CFscript.doc
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
d:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
d:\documents and settings\Jacques\Application Data\inst.exe
d:\documents and settings\Jacques\Local Settings\TempNER50C13CD5.EXE
d:\windows\sysdat.dll
d:\windows\system32\awowobes.ini
d:\windows\system32\byXOighI.dll
d:\windows\system32\idatonus.ini
d:\windows\system32\IlSCdccf.ini
d:\windows\system32\lukazuwi.dll
d:\windows\system32\peluloge.dll
d:\windows\system32\rabasasa.dll
d:\windows\system32\ranodenu.dll
d:\windows\system32\sebowowa.dll
d:\windows\system32\setup.ini
d:\windows\system32\sunotadi.dll
d:\windows\system32\taskmgr.com
d:\windows\system32\vijyyqcs.ini
d:\windows\system32\vohetufa.dll
d:\windows\Tasks\yljihsyx.job
d:\windows\winhelp.ini
----- BITS: Il y a peut-être des sites infectés -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-28 au 2008-11-30 ))))))))))))))))))))))))))))))))))))
.
2008-11-29 18:22 . 2008-11-29 18:22 <REP> d-------- D:\rsit
2008-11-29 18:22 . 2008-11-29 18:22 <REP> d-------- d:\program files\trend micro
2008-11-26 10:58 . 2008-11-26 10:58 297,697 --a------ d:\windows\system32\SpywareRemover.exe
2008-11-24 23:37 . 2008-11-24 23:37 <REP> d-------- d:\program files\Photo DVD Maker Professional
2008-11-24 17:04 . 2008-11-24 17:04 <REP> d-------- d:\program files\7-Zip
2008-11-20 18:28 . 2008-11-20 18:28 <REP> d-------- d:\windows\system32\Adobe
2008-11-19 19:40 . 2008-11-19 19:40 <REP> d-------- d:\program files\Free Video Converter
2008-11-19 19:32 . 2008-11-19 19:32 <REP> d-------- d:\program files\Fichiers communs\DVDVideoSoft
2008-11-18 21:50 . 2008-03-05 15:56 3,786,760 --a------ d:\windows\system32\D3DX9_37.dll
2008-11-18 21:49 . 2008-11-18 21:49 <REP> d-------- d:\windows\Logs
2008-11-18 21:49 . 2007-04-24 16:30 60,273 --a------ d:\windows\system32\pthreadGC2.dll
2008-11-18 21:49 . 2008-03-04 12:33 7,680 --a------ d:\windows\system32\ff_vfw.dll
2008-11-18 21:49 . 2007-07-10 17:10 547 --a------ d:\windows\system32\ff_vfw.dll.manifest
2008-11-18 21:48 . 2008-11-18 21:48 <REP> d--h----- d:\documents and settings\All Users\Application Data\{727691AA-C0CE-4AB4-8D16-F6558DFF5408}
2008-11-18 21:40 . 2008-11-18 21:40 <REP> d-------- d:\program files\Utherverse Digital Inc
2008-11-18 10:30 . 2008-11-18 10:30 <REP> d-------- d:\documents and settings\Jacques\iWizz
2008-11-18 10:29 . 2008-11-18 10:29 <REP> d-------- d:\program files\iWizz
2008-11-18 10:29 . 2008-11-18 10:29 <REP> d-------- d:\documents and settings\Jacques\.bitrock
2008-11-17 10:26 . 2008-11-17 10:26 <REP> d-------- d:\documents and settings\Jacques\.VirtualBox
2008-11-17 10:19 . 2008-11-17 10:19 <REP> d-------- d:\program files\Sun
2008-11-17 10:19 . 2008-10-23 22:39 96,016 --a------ d:\windows\system32\drivers\VBoxDrv.sys
2008-11-17 10:19 . 2008-10-23 22:39 41,744 --a------ d:\windows\system32\drivers\VBoxUSBMon.sys
2008-11-15 19:54 . 2008-11-15 19:54 <REP> d-------- D:\MySlideshow
2008-11-15 18:14 . 2008-11-15 18:14 323,584 --a------ d:\windows\system32\swt-win32-3232.dll
2008-11-15 15:28 . 2007-05-23 18:28 5,627,904 --a------ d:\windows\system32\RLVirDev.ocx
2008-11-15 15:28 . 2006-05-16 11:58 73,728 --a------ d:\windows\system32\ISUSPM.cpl
2008-11-12 09:00 . 2008-09-04 18:16 1,106,944 --------- d:\windows\system32\dllcache\msxml3.dll
2008-11-12 09:00 . 2008-10-24 12:21 455,296 --------- d:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 17:46 . 2008-11-11 17:46 <REP> d-------- D:\DVD-Slideshow
2008-11-11 00:21 . 2008-11-11 00:21 47,360 --a------ d:\documents and settings\Jacques\Application Data\pcouffin.sys
2008-11-11 00:20 . 2008-11-11 00:21 <REP> d-------- d:\documents and settings\Jacques\Application Data\Vso
2008-11-11 00:20 . 2004-05-04 11:53 1,645,320 --a------ d:\windows\gdiplus.dll
2008-11-11 00:20 . 2006-05-20 16:16 1,184,984 --a------ d:\windows\system32\wvc1dmod.dll
2008-11-11 00:20 . 2006-05-11 19:21 626,688 --a------ d:\windows\system32\vp7vfw.dll
2008-11-11 00:20 . 2006-09-29 12:24 217,127 --a------ d:\windows\system32\drv43260.dll
2008-11-11 00:20 . 2006-09-29 12:25 208,935 --a------ d:\windows\system32\drv33260.dll
2008-11-11 00:20 . 2006-09-29 12:26 176,165 --a------ d:\windows\system32\drv23260.dll
2008-11-11 00:20 . 2002-12-10 02:20 102,439 --a------ d:\windows\system32\sipr3260.dll
2008-11-11 00:20 . 2007-03-18 20:37 65,602 --a------ d:\windows\system32\cook3260.dll
2008-11-10 23:35 . 2008-11-10 23:35 <REP> d-------- d:\program files\EasyPhotoTools
2008-11-10 13:15 . 2008-11-10 13:15 <REP> d-------- d:\program files\Slideshow pro
2008-11-10 13:15 . 2008-11-10 13:15 <REP> d-------- d:\program files\mresreg
2008-11-10 11:04 . 2008-11-10 11:04 56 --ah----- d:\windows\system32\ezsidmv.dat
2008-11-10 11:03 . 2008-11-10 11:03 <REP> d-------- d:\program files\Fichiers communs\Skype
2008-11-07 19:49 . 2008-11-07 19:49 <REP> d-------- d:\documents and settings\Jacques\Application Data\Search Settings
2008-11-07 13:22 . 2008-11-07 13:22 <REP> d-------- d:\program files\Search Settings
2008-11-07 13:22 . 2008-11-07 13:22 <REP> d-------- d:\program files\Dealio
2008-11-07 13:21 . 2008-11-07 13:21 <REP> d-------- d:\program files\Free Easy Burner
2008-11-07 13:21 . 2008-11-07 13:21 <REP> d-------- d:\documents and settings\Jacques\Application Data\Dealio
2008-11-07 13:21 . 2006-11-18 11:38 200,704 --a------ d:\windows\system32\vbalExpBar6.ocx
2008-11-07 13:21 . 2003-04-18 15:29 44,544 --a------ d:\windows\system32\msxml4a.dll
2008-11-07 13:21 . 2003-01-26 12:41 40,960 --a------ d:\windows\system32\SSubTmr6.dll
2008-11-01 00:50 . 2008-11-01 00:50 <REP> d--hs---- D:\FOUND.010
2008-10-24 08:12 . 2008-10-15 18:35 337,408 --------- d:\windows\system32\dllcache\netapi32.dll
2008-10-20 00:32 . 2008-10-20 00:39 42 --a------ d:\windows\IniFile1.ini
2008-10-17 08:16 . 2008-10-17 08:16 <REP> d-------- d:\program files\Fichiers communs\xing shared
2008-10-16 23:25 . 2008-10-16 23:25 <REP> d-------- d:\program files\iTunes
2008-10-16 23:25 . 2008-10-16 23:25 <REP> d-------- d:\program files\iPod
2008-10-16 23:25 . 2008-10-16 23:25 <REP> d-------- d:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-16 23:14 . 2008-10-16 23:14 <REP> d-------- d:\program files\Bonjour
2008-10-15 08:10 . 2008-08-14 15:23 2,191,232 --------- d:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 08:10 . 2008-08-14 15:23 2,147,328 --------- d:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 08:10 . 2008-08-14 15:23 2,068,096 --------- d:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 08:10 . 2008-08-14 15:23 2,025,984 --------- d:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 08:10 . 2008-09-15 17:26 1,846,528 --------- d:\windows\system32\dllcache\win32k.sys
2008-10-15 08:10 . 2008-09-08 12:41 333,824 --------- d:\windows\system32\dllcache\srv.sys
2008-10-14 19:57 . 2008-10-14 19:57 <REP> d-------- d:\program files\FriendFinder
2008-10-11 00:25 . 2008-10-11 00:25 <REP> d-------- d:\program files\Micro Application
2008-10-01 17:42 . 2008-10-01 17:42 30,796 --ah----- d:\windows\system32\mlfcache.dat
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-28 23:29 44,944 ------w d:\windows\system32\drivers\pxhelp20.sys
2008-11-10 23:21 47,360 ----a-w d:\windows\system32\drivers\Pcouffin.sys
2008-10-27 09:04 70,992 ----a-w d:\windows\system32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w d:\windows\system32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w d:\windows\system32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w d:\windows\system32\X3DAudio1_5.dll
2008-10-24 11:21 455,296 ----a-w d:\windows\system32\drivers\mrxsmb.sys
2008-10-22 15:10 38,496 ----a-w d:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 15:10 15,504 ----a-w d:\windows\system32\drivers\mbam.sys
2008-10-17 07:15 499,712 ----a-w d:\windows\system32\msvcp71.dll
2008-10-15 22:43 599,570 ----a-w d:\windows\system32\x264vfw.dll
2008-10-10 03:52 452,440 ----a-w d:\windows\system32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w d:\windows\system32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w d:\windows\system32\D3DCompiler_40.dll
2008-10-03 18:12 6,066,176 ------w d:\windows\system32\dllcache\ieframe.dll
2008-09-30 15:43 1,286,152 ----a-w d:\windows\system32\msxml4.dll
2008-09-16 01:11 161,096 ----a-w d:\windows\system32\DivXCodecVersionChecker.exe
2008-09-15 16:26 1,846,528 ----a-w d:\windows\system32\win32k.sys
2008-09-10 01:15 1,307,648 ----a-w d:\windows\system32\msxml6.dll
2008-09-10 01:15 1,307,648 ------w d:\windows\system32\dllcache\msxml6.dll
2008-09-04 17:16 1,106,944 ----a-w d:\windows\system32\msxml3.dll
2008-08-29 09:18 87,336 ----a-w d:\windows\system32\dns-sd.exe
2008-08-29 08:53 61,440 ----a-w d:\windows\system32\dnssd.dll
2008-08-28 08:47 74,752 ----a-w d:\windows\system32\msw3prt.dll
2008-08-28 08:47 74,752 ------w d:\windows\system32\dllcache\msw3prt.dll
2008-08-28 08:47 105,472 ----a-w d:\windows\system32\win32spl.dll
2008-08-28 08:47 105,472 ------w d:\windows\system32\dllcache\win32spl.dll
2008-08-27 10:11 3,593,216 ----a-w d:\windows\system32\dllcache\mshtml.dll
2008-08-25 09:39 70,656 ------w d:\windows\system32\dllcache\ie4uinit.exe
2008-08-25 09:38 13,824 ------w d:\windows\system32\dllcache\ieudinit.exe
2008-08-23 06:56 635,848 ------w d:\windows\system32\dllcache\iexplore.exe
2008-08-23 06:54 161,792 ----a-w d:\windows\system32\dllcache\ieakui.dll
2008-08-14 14:23 2,191,232 ----a-w d:\windows\system32\ntoskrnl.exe
2008-08-14 14:23 2,068,096 ----a-w d:\windows\system32\ntkrnlpa.exe
2008-08-14 11:04 138,496 ------w d:\windows\system32\dllcache\afd.sys
2008-04-18 22:15 698 ----a-w d:\program files\cwviewer.ini
2008-04-18 22:15 520 ----a-w d:\program files\SurveyLens.ini
2008-04-18 22:15 0 ----a-w d:\program files\SL_jpapietCAM.ini
2008-04-07 23:12 32 ----a-w d:\documents and settings\All Users\Application Data\ezsid.dat
2007-01-04 10:54 119 ----a-w d:\program files\satsukidecodersettings.ini
2007-01-04 10:53 680 ----a-w d:\program files\mpc2.reg
2007-01-04 10:53 558 ----a-w d:\program files\mpc1.reg
2007-01-04 10:53 236 ----a-w d:\program files\mpc4.reg
2007-01-04 10:53 2,626 ----a-w d:\program files\mpc7.reg
2007-01-04 10:53 2,598 ----a-w d:\program files\mpc3.reg
2007-01-04 10:53 16,174 ----a-w d:\program files\mpc5.reg
2007-01-04 10:53 13,412 ----a-w d:\program files\mpc6.reg
2006-10-09 15:53 200,704 ----a-w d:\program files\Uninstall.exe
2006-10-09 15:53 1,200 ----a-w d:\program files\Uninstall.dat
2004-12-24 23:00 1,785,856 ----a-w d:\program files\cwviewer.exe
2004-11-28 23:00 1,171,456 ----a-w d:\program files\cwvs.exe
2004-02-28 23:00 79 ----a-w d:\program files\ttitrace.ini
1998-08-24 11:09 10,000 ----a-w d:\windows\inf\unregpn.exe
2007-05-14 08:43 10,646 --sha-w d:\windows\system32\KGyGaAvL.sys
2005-10-21 00:01 8 --sh--r d:\windows\system32\D5F73DD769.sys
2005-09-26 14:21 104 --sh--r d:\windows\system32\A95EF9BD22.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RamBoostXp"="d:\program files\RamBoost XP\rambxpfr.exe" [2004-03-09 1542144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vade Retro Outlook Express"="d:\progra~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe" [2006-02-16 295936]
"avgnt"="d:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"SpywareCleaner"="d:\windows\system32\SpywareRemover.exe" [2008-11-26 297697]
"TkBellExe"="d:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-10-17 185872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="d:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="d:\windows\system32\tscupgrd.exe" [2004-08-19 44544]
d:\documents and settings\Jacques\Menu D‚marrer\Programmes\D‚marrage\
Club Internet.lnk - d:\program files\Club-Internet\Lanceur\lanceur.exe [2007-12-26 5484544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 15:13 49152 d:\progra~1\FICHIE~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3iv0"= d:\progra~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv1"= d:\progra~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv2"= d:\progra~1\K-LITE~1\codecs\3IVXVF~1.DLL
"vidc.3ivd"= d:\progra~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.div3"= DivXc32.dll
"vidc.div4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"vidc.vp31"= d:\progra~1\K-LITE~1\codecs\vp31vfw.dll
"VIDC.VDOM"= vdowave.drv
"VIDC.JPEG"= jpegCode.dll
"vidc.MJ2C"= M3JP2K32.dll
"msacm.dvacm"= d:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"VIDC.VP70"= d:\progra~1\K-LITE~1\codecs\vp7vfw.dll
"msacm.l3fhg"= d:\progra~1\K-LITE~1\codecs\l3codecp.acm
"VIDC.PIM1"= pclepim1.dll
"vidc.X264"= x264vfw.dll
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
backup=d:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Color Calibration.lnk]
path=d:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Color Calibration.lnk
backup=d:\windows\pss\Color Calibration.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
backup=d:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=d:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=d:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^LE COMPAGNON CLUB.lnk]
backup=d:\windows\pss\LE COMPAGNON CLUB.lnkCommon Startup
path=d:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\LE COMPAGNON CLUB.lnk
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MagicTune 3.6.lnk]
path=d:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\MagicTune 3.6.lnk
backup=d:\windows\pss\MagicTune 3.6.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NaturalColorLoad.lnk]
path=d:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\NaturalColorLoad.lnk
backup=d:\windows\pss\NaturalColorLoad.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=d:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=d:\windows\pss\Outil de mise à jour Google.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^Jacques^Menu Démarrer^Programmes^Démarrage^Datecracker.exe.lnk]
backup=d:\windows\pss\Datecracker.exe.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^Jacques^Menu Démarrer^Programmes^Démarrage^MS Office - Démarrage accéléré.lnk]
backup=d:\windows\pss\MS Office - Démarrage accéléré.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gafoh
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
d:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
d:\windows\system32\dumprep 0 -u [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\viva
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-23 20:33 57344 d:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 d:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-10-01 12:57 111936 d:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]
--a------ 2007-05-22 11:04 521128 d:\program files\Ray Adams\ATI Tray Tools\atitray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreativeMixer]
--a------ 1999-11-18 06:01 20480 d:\program files\Creative\Audio2K\Program\Ctmix32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 04:34 15360 d:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EoEngine]
--a------ 2008-01-08 15:18 561152 d:\program files\eoRezo\EoEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-08-14 08:22 1838592 d:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-11-21 03:12 3297280 d:\program files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 2004-03-24 11:41 1294446 d:\program files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
--a------ 2008-07-16 09:16 1166216 d:\program files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ItsTV]
--a------ 2007-04-26 16:19 2908160 d:\program files\eoRezo\EoTraduction\ItsTV.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 18:57 289576 d:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
--a------ 2006-04-21 15:41 438359 d:\progra~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnappau]
--a------ 2004-08-13 17:41 86016 d:\program files\MSN Apps\Updater\[u]0/u1.03.0000.1005\fr\msnappau.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 d:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCLEPCI]
--a------ 2002-06-25 15:35 32768 d:\progra~1\Pinnacle\PPE\PPE.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2008-08-21 03:18 443968 d:\program files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
--a------ 2004-03-10 16:26 406016 d:\windows\system32\PSDrvCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 d:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RamBoostXp]
--a------ 2004-03-09 22:48 1542144 d:\program files\RamBoost XP\RAMBXPFR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2003-10-31 19:42 32768 d:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
--a------ 2008-06-12 16:57 991584 d:\program files\Search Settings\SearchSettings.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2007-06-13 08:16 528384 d:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--------- 2008-09-16 12:16 1833296 d:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 d:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sunkist2k]
--a------ 2005-10-07 16:42 139264 d:\program files\Multimedia Card Reader\shwicon2k.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-17 00:34 68856 d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-17 08:15 185872 d:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
--a------ 2008-09-26 15:50 206184 d:\program files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVAgent WiFi]
--------- 2006-05-23 19:24 897024 d:\club-internet\Wizard\Agent_wifi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ub4TrayApp]
--a------ 2004-10-10 12:03 1381888 d:\program files\Astase\UltraBackup\4.0\bin\ubTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vaderetro Outlook]
--a------ 2006-07-22 11:59 44544 d:\progra~1\GOTOSO~1\VADERE~1\VrMoRegister.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray]
--a------ 2007-08-21 19:56 55856 d:\program files\VMware\VMware Player\hqtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 d:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray2k]
--a------ 2001-11-01 00:52 57344 d:\windows\system32\MMTray2k.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2004-07-27 17:01 68096 d:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Program Files\\NetMeeting\\conf.exe"=
"d:\\Program Files\\Shareaza\\Shareaza.exe"=
"d:\\Program Files\\BitComet\\BitComet.exe"=
"d:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"d:\\Program Files\\Ratajik Software\\StationRipper\\StationRipperConsole.exe"=
"d:\\Program Files\\Movie Collection\\MovieCollection.exe"=
"d:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"d:\\Sun\\AppServer\\lib\\appserv.exe"=
"e:\\jeux\\MotoGP2\\motogp2.exe"=
"d:\\WINDOWS\\System32\\dplaysvr.exe"=
"e:\\JEUX\\Microsoft Games\\Combat Flight Simulator\\COMBATFS.EXE"=
"d:\\Program Files\\eMule\\emule.exe"=
"e:\\JEUX\\Infogrames\\Grand Prix 4\\GP4.exe"=
"e:\\jeux\\Virtual Skipper 4 Demo\\Vsk4Demo.exe"=
"d:\\Program Files\\uTorrent\\utorrent.exe"=
"e:\\jeux\\skipper\\Vsk3Demo\\Vsk3Demo.exe"=
"e:\\jeux\\TrackMania Sunrise Extreme Demo\\TmSunriseExtremeDemo.exe"=
"d:\\Program Files\\Azureus\\Azureus.exe"=
"d:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2007.SP1\\sandra.exe"=
"d:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2007.SP1\\RpcSandraSrv.exe"=
"d:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2007.SP1\\Win32\\RpcDataSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Allocam Multi Visio\\allocam.exe"=
"d:\\PROGRA~1\\ALLOCA~1\\allocam.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"d:\\Program Files\\SecondLife\\SLVoice.exe"=
"d:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe"=
"d:\\Program Files\\AIM6\\aim6.exe"=
"d:\\WINDOWS\\System32\\rtcshare.exe"=
"d:\\Program Files\\RedlightCenter\\RedLightCenter\\Redlightcenter.exe"=
"d:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
"d:\\Program Files\\adslTV\\adsltv.exe"=
"d:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro_Downloader.exe"=
"d:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Reallusion\\CrazyTalk for Skype\\CT4Skype.exe"=
"d:\\Program Files\\Sun\\xVM VirtualBox\\vboxwebsrv.exe"=
"d:\\Program Files\\Sun\\xVM VirtualBox\\VirtualBox.exe"=
"d:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\infocard.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9147:TCP"= 9147:TCP:BitComet 9147 TCP
"9147:UDP"= 9147:UDP:BitComet 9147 UDP
"6667:UDP"= 6667:UDP:TOTOCAM UDP
"6666:TCP"= 6666:TCP:TOTOCAM TCP
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 aliidex;aliidex;d:\windows\system32\drivers\aliidex.sys [2005-08-12 7040]
R0 aliperf;aliperf;d:\windows\system32\drivers\aliperf.sys [2005-08-12 7168]
R0 m5289;m5289;d:\windows\system32\DRIVERS\m5289.sys [2007-06-21 51840]
R0 pavboot;pavboot;d:\windows\system32\drivers\pavboot.sys [2008-07-18 28544]
R0 PQV2i;PQV2i;d:\windows\system32\drivers\PQV2i.sys [2003-06-03 123957]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);d:\windows\system32\drivers\sfsync03.sys [2005-12-06 35328]
R0 uliagpkx;ULi AGP Bus Filter Driver;d:\windows\system32\DRIVERS\agpkx.sys [2005-08-12 44928]
R1 atitray;atitray;\??\d:\program files\Ray Adams\ATI Tray Tools\atitray.sys [2007-05-22 18088]
R1 DCxxMJPG;Pinnacle DC10plus, Motion-JPEG VideoIO Board;d:\windows\system32\drivers\DCxxMJPG.sys [2005-09-03 132940]
R1 PQIMount;PQIMount;d:\windows\system32\drivers\PQIMount.sys [2003-06-03 46900]
R1 VBoxDrv;VirtualBox Service;d:\windows\system32\DRIVERS\VBoxDrv.sys [2008-11-17 96016]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;d:\windows\system32\DRIVERS\VBoxUSBMon.sys [2008-11-17 41744]
R3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);d:\windows\system32\DRIVERS\webc3vid.sys [2007-07-20 166504]
R3 PctvVirtualNdis;Pinnacle Virtual Miniport;d:\windows\system32\DRIVERS\PctvVirtualNdis.sys [2008-04-12 13696]
R3 ULI5261;ULi Based Ethernet NT Driver;d:\windows\system32\DRIVERS\ULILAN.SYS [2005-08-12 29696]
S0 ElbyVCD;ElbyVCD;d:\windows\system32\DRIVERS\ElbyVCD.sys []
S2 CoachCap;Firstline FDC 2000 USB Video Capture V1.00;d:\windows\system32\drivers\CoachCap.sys [2002-03-03 93068]
S2 oaa4aeyyeruo;Canon BJ Memory Card Manager;d:\windows\system32\gamuj.exe []
S3 ASPI;Advanced SCSI Programming Interface Driver;\??\d:\windows\System32\DRIVERS\ASPI32.sys [2005-02-10 16512]
S3 ATE_PROCMON;ATE_PROCMON;\??\d:\program files\Anti Trojan Elite\ATEPMon.sys []
S3 CallerIP;Visualware CallerIP;d:\program files\CallerIP\cip-nt.exe [2005-12-09 21394]
S3 Ltn_stk7070P;PCTV based TV tuner device;d:\windows\system32\DRIVERS\Ltn_stk7070P.sys [2008-04-11 466048]
S3 Ltn_stkrc;PCTV Infrared Receiver;d:\windows\system32\DRIVERS\Ltn_stkrc.sys [2008-04-11 13440]
S3 Penet;PlaceEngine NDIS Protocol Driver;d:\windows\system32\DRIVERS\penet.sys [2007-10-23 21376]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);d:\windows\system32\DRIVERS\s125bus.sys [2008-05-26 83336]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;d:\windows\system32\DRIVERS\s125mdfl.sys [2008-05-26 15112]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;d:\windows\system32\DRIVERS\s125mdm.sys [2008-05-26 108680]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);d:\windows\system32\DRIVERS\s125mgmt.sys [2008-05-26 100488]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;d:\windows\system32\DRIVERS\s125obex.sys [2008-05-26 98696]
S4 hpt3xx;hpt3xx; []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02da6cf7-59f2-11d9-97a3-806d6172696f}]
\Shell\AutoRun\command - G:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aceb8c6f-cdbb-11dc-9a84-005056c00008}]
\Shell\AutoRun\command - G:\Begin.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc7a9db4-e5db-11db-84ee-00c0a8da3ecc}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0c254ad-1ccf-11dd-9b08-005056c00008}]
\Shell\AutoRun\command - K:\InstallTomTomHOME.exe
.
Contenu du dossier 'Tâches planifiées'
2008-11-30 d:\windows\Tasks\MP Scheduled Scan.job
- d:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2008-11-13 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-11-28 d:\windows\Tasks\Maintenance en 1 clic.job
- d:\program files\TuneUp Utilities 2006\SystemOptimizer.exe []
2008-11-29 d:\windows\Tasks\User_Feed_Synchronization-{9E510C6E-0EDC-43C6-A4E1-3E43417E7DA0}.job
- d:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
2008-11-21 d:\windows\Tasks\Norton Security Scan.job
- d:\program files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
BHO-{49F68B91-3571-4883-9CEA-181E40A6857E} - d:\windows\system32\fccdCSlI.dll
BHO-{54D14726-66BC-4235-87B3-1B4797E5B9B8} - d:\windows\system32\jkkLBrrQ.dll
BHO-{87ca771e-9fba-4c5c-9cee-d24d01aa5df0} - d:\windows\system32\peluloge.dll
Toolbar-{ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
WebBrowser-{ECDEE021-0D17-467F-A1FF-C7A115230949} - (no file)
MSConfigStartUp-Anti Trojan Elite - d:\program files\Anti Trojan Elite\TJEnder.exe
MSConfigStartUp-DownloadAccelerator - d:\program files\DAP\DAP.EXE
MSConfigStartUp-IMC - d:\program files\FriendFinder\FriendFinder Messenger 40\imc.exe
MSConfigStartUp-PMCLoader - d:\program files\Pinnacle\TVCenter Pro\PMCLoader.exe
MSConfigStartUp-RegistryBooster 2 d’Uniblue - d:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
MSConfigStartUp-TE_RegProtect - d:\program files\Anti Trojan Elite\TERegPct.exe
MSConfigStartUp-Framework Windows - frmwrk32.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-30 13:49:28
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1632)
d:\windows\system32\Ati2evxx.dll
d:\progra~1\FICHIE~1\Stardock\mcpstub.dll
.
------------------------ Autres processus actifs ------------------------
.
d:\windows\SYSTEM32\ATI2EVXX.EXE
d:\program files\WINDOWS DEFENDER\MSMPENG.EXE
d:\program files\AHEAD\INCD\INCDSRV.EXE
d:\program files\FICHIERS COMMUNS\STARDOCK\SDMCP.EXE
d:\program files\LAVASOFT\AD-AWARE\AAWSERVICE.EXE
d:\windows\SYSTEM32\ATI2EVXX.EXE
d:\program files\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE
d:\program files\GOTO SOFTWARE\VADE RETRO\VADERETRO_OE.EXE
d:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
d:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\program files\Bonjour\mDNSResponder.exe
d:\windows\system32\drivers\CDAC11BA.EXE
d:\windows\system32\CTSvcCDA.exe
d:\program files\EPSON\ESM2\eEBSVC.exe
d:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
d:\program files\UPHClean\uphclean.exe
d:\program files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
d:\program files\Fichiers communs\VMware\VMware Virtual Image Editing\vmount2.exe
d:\windows\system32\vmnat.exe
d:\windows\system32\vmnetdhcp.exe
d:\program files\VMware\VMware Player\vmware-authd.exe
.
**************************************************************************
.
Heure de fin: 2008-11-30 13:53:57 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-30 12:53:56
Avant-CF: 11 277 737 984 octets libres
Après-CF: 11,216,158,720 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[Boot Loader]
timeout=2
Default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptOut
C:\="Microsoft Windows 98"
486 --- E O F --- 2008-11-28 16:16:18
rsit
Logfile of random's system information tool 1.04 (written by random/random)
Run by Jacques at 2008-11-30 13:57:46
Microsoft Windows XP Édition familiale Service Pack 3
System drive D: has 11 GB (29%) free of 38 GB
Total RAM: 1023 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:57:58, on 30/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Ahead\InCD\InCDsrv.exe
D:\PROGRA~1\FICHIE~1\Stardock\SDMCP.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
D:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\RamBoost XP\rambxpfr.exe
D:\Program Files\Club-Internet\Lanceur\lanceur.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\drivers\CDAC11BA.EXE
D:\WINDOWS\system32\CTSvcCDA.exe
D:\Program Files\EPSON\ESM2\eEBSVC.exe
D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\UPHClean\uphclean.exe
D:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
D:\Program Files\Fichiers communs\VMware\VMware Virtual Image Editing\vmount2.exe
D:\WINDOWS\system32\vmnat.exe
D:\WINDOWS\system32\vmnetdhcp.exe
D:\Program Files\VMware\VMware Player\vmware-authd.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\notepad.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Documents and Settings\Jacques\Bureau\infection\RSIT.exe
D:\Program Files\trend micro\Jacques.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.club-internet.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
R3 - URLSearchHook: (no name) - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - D:\Program Files\Dealio\kb127\Dealio.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - D:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - D:\Program Files\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: (no name) - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - (no file)
O4 - HKLM\..\Run: [Vade Retro Outlook Express] "D:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpywareCleaner] D:\WINDOWS\system32\SpywareRemover.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RamBoostXp] D:\Program Files\RamBoost XP\rambxpfr.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "D:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: Club Internet.lnk = D:\Program Files\Club-Internet\Lanceur\lanceur.exe
O8 - Extra context menu item: Compare Prices with &Dealio - D:\Documents and Settings\Jacques\Application Data\Dealio\kb127\res\DealioSearch.html
O8 - Extra context menu item: Post Image to Blog - res://D:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: S'abonner avec l'agrégateur par défaut - D:\Documents and Settings\Jacques\Application Data\RssBandit\iecontext_subscribefeed.htm
O8 - Extra context menu item: Tag This Image - res://D:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://D:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://D:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://D:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - D:\PROGRA~1\ALLOCA~1\allocam.exe
O9 - Extra 'Tools' menuitem: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - D:\PROGRA~1\ALLOCA~1\allocam.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - D:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - D:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/...
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/fr/4,0,0,84/mcinsctl.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {63DF43C2-469A-41F3-B119-17B1ACE8BB50} (Sony SNC-CS3 Image Viewer) - http://82.127.17.206/home/SonySncCs3View.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://www.tele2mail.com/static/apps/utils/AccountHelper.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://camera1.mairie-brest.fr/activex/AxisCamControl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/fr/1,0,0,21/mcgdmgr.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - D:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Visualware CallerIP (CallerIP) - Unknown owner - D:\Program Files\CallerIP\cip-nt.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTSvcCDA.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - D:\Program Files\EPSON\ESM2\eEBSVC.exe
O23 - Service: GoogleDesktopManager - Google - D:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - D:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Canon BJ Memory Card Manager (oaa4aeyyeruo) - Unknown owner - D:\WINDOWS\system32\gamuj.exe (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - D:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - D:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: V2i Protector - PowerQuest Corporation - D:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - D:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - D:\Program Files\Fichiers communs\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - D:\WINDOWS\system32\vmnat.exe
End of file - 15064 bytes
======Scheduled tasks folder======
D:\WINDOWS\tasks\MP Scheduled Scan.job
D:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\WINDOWS\tasks\Maintenance en 1 clic.job
D:\WINDOWS\tasks\User_Feed_Synchronization-{9E510C6E-0EDC-43C6-A4E1-3E43417E7DA0}.job
D:\WINDOWS\tasks\Norton Security Scan.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-10-17 308832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A87B991-A31F-4130-AE72-6D0C294BF082}]
DealioBHO Class - D:\Program Files\Dealio\kb127\Dealio.dll [2008-05-26 3170144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
ST - D:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll [2004-08-13 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - D:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-08 652784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - D:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll [2006-10-26 440384]
{6932D140-ABC4-4073-A44C-D4A541665E35} - ImageShack Toolbar - D:\Program Files\ImageShackToolbar\ImageShackToolbar.dll [2008-01-29 626688]
{40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Vade Retro Outlook Express"=D:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe [2006-02-16 295936]
"avgnt"=D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"QuickTime Task"=D:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"SpywareCleaner"=D:\WINDOWS\system32\SpywareRemover.exe [2008-11-26 297697]
"TkBellExe"=D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2008-10-17 185872]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"RamBoostXp"=D:\Program Files\RamBoost XP\rambxpfr.exe [2004-03-09 1542144]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
D:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe [2005-06-23 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
D:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-10-01 111936]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]
D:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe [2007-05-22 521128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreativeMixer]
D:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE [1999-11-18 20480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
D:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EoEngine]
D:\Program Files\eoRezo\EoEngine.exe [2008-01-08 561152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
D:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2007-08-14 1838592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
D:\Program Files\Google\Google Talk\googletalk.exe [2007-11-21 3297280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
D:\Program Files\Ahead\InCD\InCD.exe [2004-03-24 1294446]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
D:\Program Files\Spyware Doctor\pctsTray.exe [2008-07-16 1166216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ItsTV]
D:\Program Files\eoRezo\EoTraduction\ItsTV.exe [2007-04-26 2908160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
D:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
D:\WINDOWS\system32\dumprep 0 -k []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray2k]
D:\WINDOWS\system32\MMTray2k.exe [2001-11-01 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
D:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe [2006-04-21 438359]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnappau]
D:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe [2004-08-13 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
D:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCLEPCI]
D:\PROGRA~1\PINNACLE\PPE\ppe.exe [2002-06-25 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
D:\Program Files\Picasa2\PicasaMediaDetector.exe [2008-08-21 443968]
[HKEY_LOCAL_MACHINE\software\microsoft