Part 3 of log.txt
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“ATIModeChange”=C:\WINDOWS\system32\Ati2mdxx.exe [2002-08-15 28672]
“CARPService”=C:\WINDOWS\system32\carpserv.exe [2003-05-21 4608]
“ATIPTA”=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2002-08-14 290816]
“PreloadApp”=c:\hp\drivers\printers\photosmart\hphprld.exe [2001-12-12 36864]
“srmclean”=C:\Cpqs\Scom\srmclean.exe [2001-07-24 36864]
“Display Settings”=C:\Program Files\HPQ\Notebook Utilities\hptasks.exe [2002-08-15 45056]
“QT4HPOT”=C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE [2002-10-14 98304]
“SynTPLpr”=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2002-09-09 126976]
“SynTPEnh”=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2002-09-09 557056]
“Cpqset”=C:\Program Files\HPQ\Default Settings\cpqset.exe [2002-10-23 176197]
“RoxioEngineUtility”=C:\Program Files\Fichiers communs\Roxio Shared\System\EngUtil.exe [2003-05-01 65536]
“RoxioDragToDisc”=C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe [2003-10-21 868352]
“V0250Mon.exe”=C:\WINDOWS\V0250Mon.exe [2006-06-07 32768]
“AVFX Engine”=C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe [2006-10-09 20480]
“AppleSyncNotifier”=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-07-22 116040]
“QuickTime Task”=C:\Program Files\QuickTime\qttask.exe [2008-05-27 413696]
“iTunesHelper”=C:\Program Files\iTunes\iTunesHelper.exe [2008-07-30 289064]
“Adobe Reader Speed Launcher”=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
“SunJavaUpdateSched”=C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-20 136600]
“avast!”=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-18 81000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
“MoneyAgent”=C:\Program Files\Microsoft Money\System\mnyexpr.exe [2003-06-18 204800]
“MsnMsgr”=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
“Creative Live! Cam Manager”=C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe [2006-05-31 143360]
“Skype”=C:\Program Files\Skype\Phone\Skype.exe [2008-08-11 21741864]
“swg”=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-10-20 68856]
“H/PC Connection Agent”=C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE [2004-02-24 401491]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
Belkin Wireless Utility.lnk - C:\Program Files\Belkin\F5D7001v2000\Belkinwcui.exe
ImageFox.lnk - C:\WINDOWS\Installer{92E64C51-5096-442F-9A44-61CB2941391D}\NewShortcut1.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDriveTypeAutoRun”=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000”
“C:\PVSW\Bin\w3dbsmgr.exe”=“C:\PVSW\Bin\w3dbsmgr.exe::Enabled:Database Service Manager"
“C:\Program Files\Microsoft ActiveSync\wcescomm.exe”="C:\Program Files\Microsoft ActiveSync\wcescomm.exe::Enabled:ActiveSync Connection Manager”
“C:\Program Files\Microsoft ActiveSync\WcesMgr.exe”=“C:\Program Files\Microsoft ActiveSync\WcesMgr.exe::Enabled:ActiveSync Application"
“C:\Program Files\NetMeeting\conf.exe”="C:\Program Files\NetMeeting\conf.exe::Enabled:Windows® NetMeeting®”
“C:\Program Files\Messenger\msmsgs.exe”=“C:\Program Files\Messenger\msmsgs.exe::Enabled:Windows Messenger"
“C:\Program Files\SightSpeed\SightSpeed.exe”="C:\Program Files\SightSpeed\SightSpeed.exe::Enabled:SightSpeed”
“C:\Program Files\Bonjour\mDNSResponder.exe”=“C:\Program Files\Bonjour\mDNSResponder.exe::Enabled:Bonjour"
“C:\Program Files\iTunes\iTunes.exe”="C:\Program Files\iTunes\iTunes.exe::Enabled:iTunes”
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger"
“C:\Program Files\Windows Live\Messenger\livecall.exe”="C:\Program Files\Windows Live\Messenger\livecall.exe::Enabled:Windows Live Messenger (Phone)”
“C:\Program Files\Skype\Phone\Skype.exe”="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
“%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“%windir%\Network Diagnostic\xpnetdiag.exe”="%windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000”
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe::Enabled:Windows Live Messenger"
“C:\Program Files\Windows Live\Messenger\livecall.exe”="C:\Program Files\Windows Live\Messenger\livecall.exe::Enabled:Windows Live Messenger (Phone)”
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{051d70b2-c401-11dc-abeb-00173f864771}]
shell\Auto\command - MicrosoftPowerPoint.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{28c04252-bb7a-11dc-abce-000bcd883d84}]
shell\Auto\command - Cn911.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{297187e0-20dd-11dc-aa40-00028a7adc95}]
shell\AutoRun\command - E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{5824c410-74ce-11dc-aaf4-000bcd883d84}]
shell\AutoRun\command - RavMon.exe
shell\open\command - RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{96c34348-7b5e-11dc-ab01-000bcd883d84}]
shell\Auto\command - Cn911.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{fcd67d10-991b-11dd-adb3-00173f864771}]
shell\AutoRun\command - E:\ev60a2.cmd
shell\explore\command - E:\ev60a2.cmd
shell\open\command - E:\ev60a2.cmd