StartupList report, 03/09/2008, 10:24:14
StartupList version: 1.52.2
Started from : C:Documents and SettingsGERALDINE CUPIFBureausniffle.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16705)
* Using default options
==================================================
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesWindows DefenderMsMpEng.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesFichiers communsAppleMobile Device SupportinAppleMobileDeviceService.exe
C:Program FilesFichiers communsInterVideoDeviceServiceDevSvc.exe
C:WINDOWSSystem32FTRTSVC.exe
C:Program FilesFichiers communsLightScribeLSSrvc.exe
C:Program FilesControle Parentalinoptproxy.exe
C:WINDOWSsystem32HPZipm12.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSExplorer.EXE
C:PROGRA~1CONTRO~1inoptgui.exe
C:Program FilesWindows DefenderMSASCui.exe
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:WINDOWSsystem32ctfmon.exe
C:PROGRA~1WanadooTaskBarIcon.exe
C:AcerEmpowering TechnologyeRecoveryMonitor.exe
C:Program FilesHPDigital Imaginginhpqtra08.exe
C:Program FilesFichiers communsNikonMonitorNkMonitor.exe
C:PROGRA~1WanadooGestionnaireInternet.exe
C:PROGRA~1WanadooComComp.exe
C:PROGRA~1WanadooToaster.exe
C:PROGRA~1WanadooInactivity.exe
C:PROGRA~1WanadooPollingModule.exe
C:WINDOWSSystem32ALERTM~1ALERTM~1.EXE
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:Program FilesHPDigital ImaginginhpqSTE08.exe
C:PROGRA~1WanadooWatch.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Documents and SettingsGERALDINE CUPIFBureausniffle.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[C:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrage]
HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imaginginhpqtra08.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogon]
UserInit = C:WINDOWSsystem32userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
PHIME2002ASync = C:WINDOWSsystem32IMETINTLGNTTINTSETP.EXE /SYNC
OPTENET_GUI = C:PROGRA~1CONTRO~1inoptgui.exe
LaunchApp = Alaunch
Windows Defender = "C:Program FilesWindows DefenderMSASCui.exe" -hide
(Default) =
avast! = C:PROGRA~1ALWILS~1Avast4ashDisp.exe
PHIME2002A = C:WINDOWSsystem32IMETINTLGNTTINTSETP.EXE /IMEName
WOOTASKBARICON = C:PROGRA~1WanadooGestMaj.exe TaskBarIcon.exe
Adobe Reader Speed Launcher = "C:Program FilesAdobeReader 9.0ReaderReader_sl.exe"
--------------------------------------------------
Autorun entries from Registry:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
WOOKIT = C:PROGRA~1WanadooShell.exe appLaunchClientZone.shl|PARAM= cnx
ctfmon.exe = C:WINDOWSsystem32ctfmon.exe
Uniblue RegistryBooster 2009 = C:Program FilesUniblueRegistryBoosterRegistryBooster.exe /S
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
[OptionalComponents]
=
--------------------------------------------------
Load/Run keys from C:WINDOWSWIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM..Windows NTCurrentVersionWinLogon: load=*Registry value not found*
HKLM..Windows NTCurrentVersionWinLogon: run=*Registry value not found*
HKLM..WindowsCurrentVersionWinLogon: load=*Registry key not found*
HKLM..WindowsCurrentVersionWinLogon: run=*Registry key not found*
HKCU..Windows NTCurrentVersionWinLogon: load=*Registry value not found*
HKCU..Windows NTCurrentVersionWinLogon: run=*Registry value not found*
HKCU..WindowsCurrentVersionWinLogon: load=*Registry key not found*
HKCU..WindowsCurrentVersionWinLogon: run=*Registry key not found*
HKCU..Windows NTCurrentVersionWindows: load=
HKCU..Windows NTCurrentVersionWindows: run=*Registry value not found*
HKLM..Windows NTCurrentVersionWindows: load=*Registry value not found*
HKLM..Windows NTCurrentVersionWindows: run=*Registry value not found*
HKLM..Windows NTCurrentVersionWindows: AppInit_DLLs=C:PROGRA~1GoogleGOOGLE~3GOEC62~1.DLL
--------------------------------------------------
Shell & screensaver key from C:WINDOWSSYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:WINDOWSsystem32INOOK-~1.SCR
drivers=*Registry value not found*
Policies Shell key:
HKCU..Policies: Shell=*Registry value not found*
HKLM..Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:Program FilesYahoo!CompanionInstallscpnyt.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
AcroIEHelperStub - C:Program FilesFichiers communsAdobeAcrobatActiveXAcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
(no name) - C:PROGRA~1FICHIE~1fluxDVDDOWNLO~1XEBDLH~1.DLL - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8}
(no name) - C:Program FilesJavajre1.6.0_03inssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045}
(no name) - C:Program FilesFichiers communsMicrosoft SharedWindows LiveWindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - c:program filesgooglegoogletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:Program FilesGoogleGoogleToolbarNotifier2.1.615.5858swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
(no name) - C:Program FilesWindows Live Toolbarmsntb.dll - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Maintenance en 1 clic.job
MP Scheduled Scan.job
Norton Security Scan.job
RegCure Program Check.job
RegCure.job
Vérifier les mises à jour de Windows Live Toolbar.job
--------------------------------------------------
Enumerating Download Program Files:
[Microsoft Office Template and Media Control]
InProcServer32 = C:WINDOWSDownloaded Program FilesIEAWSDC.DLL
CODEBASE =
http://office.microsoft.com/templates/ieawsdc.cab
[Shockwave ActiveX Control]
InProcServer32 = C:WINDOWSsystem32AdobeDirectorSwDir.dll
CODEBASE =
http://download.macromedia.com/pub/shoc ... tor/sw.cab
[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:WINDOWSsystem32legitcheckcontrol.dll
CODEBASE =
http://go.microsoft.com/fwlink/?linkid=39204
[Shockwave ActiveX Control]
InProcServer32 = C:WINDOWSsystem32AdobeDirectorSwDir.dll
CODEBASE =
http://fpdownload.macromedia.com/get/sh ... tor/sw.cab
[ActiveScan 2.0 Installer Class]
InProcServer32 = C:WINDOWSDownloaded Program Filesas2stubie.dll
CODEBASE =
http://acs.pandasoftware.com/activescan ... stubie.cab
[YInstStarter Class]
InProcServer32 = C:PROGRA~1YAHOO!COMMONyinsthelper.dll
CODEBASE = C:Program FilesYahoo!Commonyinsthelper.dll
[Windows Live Safety Center Base Module]
InProcServer32 = C:WINDOWSDownloaded Program FileswlscBase.dll
CODEBASE =
http://cdn.scan.onecare.live.com/resour ... se8300.cab
[Symantec RuFSI Utility Class]
InProcServer32 = C:WINDOWSDownloaded Program Files
ufsi.dll
CODEBASE =
http://security.symantec.com/sscv6/Shar ... /cabsa.cab
[MMSPlayerX Class]
InProcServer32 = C:WINDOWSDownloaded Program FilesSMILInetCtrl.dll
CODEBASE =
http://62.201.137.56/mmawap/jsp/compose ... Player.cab
[AdVerifierADPCtrl Class]
InProcServer32 = C:WINDOWSDOWNLO~1ADVERI~1.DLL
CODEBASE =
https://static.impots.gouv.fr/tdir/stat ... DP-1.1.cab
[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE =
http://fpdownload.macromedia.com/get/fl ... rashim.cab
[Oberon Flash Game Host]
InProcServer32 = C:WINDOWSDownloaded Program FilesOberonGameHost.dll
CODEBASE =
http://jeuxenligne.orange.fr/Gameshell/ ... meHost.cab
[Shockwave Flash Object]
InProcServer32 = C:WINDOWSsystem32MacromedFlashFlash9f.ocx
CODEBASE =
http://fpdownload2.macromedia.com/get/s ... wflash.cab
--------------------------------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:WINDOWSsystem32wuauclt.exe.wusetup.249953.bak||C:WINDOWSsystem32wuaueng.dll.wusetup.250734.bak
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:WINDOWSsystem32SHELL32.dll
CDBurn: C:WINDOWSsystem32SHELL32.dll
WebCheck: C:WINDOWSsystem32webcheck.dll
SysTray: C:WINDOWSsystem32stobject.dll
WPDShServiceObj: C:WINDOWSsystem32WPDShServiceObj.dll
--------------------------------------------------
End of report, 10 466 bytes
Report generated in 0,063 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only