
voilà le Combofix :
ComboFix 08-01-21.4 - MR PREAU 2008-01-29 14:07:46.8 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.0.1252.1.1036.18.611 [GMT 1:00]
Endroit: C:\Documents and Settings\MR PREAU\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\MR PREAU\Bureau\CFScript.txt
AVERTISSEMENT - CETTE MACHINE N'A PAS LA CONSOLE DE RÉTABLISSEMENT INSTALLÉE !!
FILE
C:\WINDOWS\System32\clusap.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\System32\clusap.dll . . . . Echec de suppression
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\poof
-------\poof
((((((((((((((((((((((((((((( Fichiers créés 2007-12-28 to 2008-01-29 ))))))))))))))))))))))))))))))))))))
.
2008-01-27 21:43 . 2008-01-27 21:43 3,767,229 --a------ C:\upload_moi_MR-6AIZY9QD1LAR.tar.gz
2008-01-23 18:00 . 2008-01-23 18:00 <REP> d-------- C:\Deckard
2008-01-22 16:39 . 2008-01-22 16:39 <REP> d-------- C:\Program Files\Avira
2008-01-22 09:45 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-21 21:56 . 2008-01-21 21:56 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-21 17:27 . 2008-01-21 22:42 <REP> d-------- C:\Program Files\Navilog1
2008-01-21 11:12 . 2007-08-14 13:04 9,216 --a------ C:\WINDOWS\system32\ffnd.exe
2008-01-21 11:02 . 2008-01-21 11:02 <REP> d-------- C:\Program Files\Enigma Software Group
2008-01-21 10:22 . 2008-01-21 10:22 <REP> d-------- C:\Program Files\FreeFixer
2008-01-21 00:43 . 19,584 C:\WINDOWS\system32\drivers\vnbkqahq.dat
2008-01-21 00:42 . 2001-09-28 18:19 84,480 --a------ C:\WINDOWS\system32\clusap.dll
2008-01-09 22:06 . 2008-01-09 22:09 <REP> d-------- C:\Program Files\TallStick
2008-01-01 14:21 . 2008-01-21 00:21 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-01 14:21 . 2008-01-01 14:21 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 12:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-01-21 13:05 --------- d-----w C:\Program Files\a-squared Free
2007-12-12 10:55 --------- d-----w C:\Program Files\Fichiers communs\PCSuite
2007-12-12 10:55 --------- d-----w C:\Program Files\Fichiers communs\Nokia
2007-12-12 10:54 --------- d-----w C:\Program Files\Nokia
2007-12-10 21:17 --------- d-----w C:\Program Files\Fichiers communs\Nikon
2007-12-07 09:34 --------- d-----w C:\Program Files\Nikon
2007-12-06 20:38 --------- d-----w C:\Program Files\QuickTime
2007-12-06 20:37 --------- d-----w C:\Program Files\Apple Software Update
2005-04-27 08:25 60,619 --sh--w C:\WINDOWS\repair\cfmdmc.bak1
2005-05-22 11:30 503,869 --sh--w C:\WINDOWS\repair\cfmdmc.bak2
.
((((((((((((((((((((((((((((( snapshot@2008-01-22_ 9.48.45,57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-22 08:45:42 10,903,552 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\ntuser.dat
+ 2008-01-29 13:07:27 10,903,552 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\ntuser.dat
- 2008-01-22 08:45:43 159,744 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-29 13:07:27 159,744 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-01-22 08:45:55 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2008-01-29 13:07:38 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2007-08-09 12:04:11 40,768 ----a-w C:\WINDOWS\system32\drivers\avgntdd.sys
+ 2007-07-18 13:22:19 21,312 ----a-w C:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2008-01-22 15:43:16 61,632 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-03-01 09:34:36 28,352 ----a-w C:\WINDOWS\system32\drivers\ssmdrv.sys
- 2007-12-27 06:28:01 138,848 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-01-24 15:11:12 137,256 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{102499AA-A382-44C8-A4EB-22018739DB6E}]
2001-09-28 18:19 84480 --a------ C:\WINDOWS\System32\clusap.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{200B4767-4E46-4A4F-B2A0-D23A0E30B592}"= C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll [2005-11-14 21:18 2465792]
[HKEY_CLASSES_ROOT\clsid\{200b4767-4e46-4a4f-b2a0-d23a0e30b592}]
[HKEY_CLASSES_ROOT\PixVue.ExplorerBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{066EFA48-AC3A-4B5A-BDCE-434BA4C203C3}]
[HKEY_CLASSES_ROOT\PixVue.ExplorerBar]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\PixVue EXIF]
@={3E57A8B6-849B-476E-A3E9-CFCE49E3662A}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\PixVue EXIF & IPTC]
@={E3F36090-0540-418f-8136-074D5B255B59}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\PixVue EXIF & XMP]
@={E1C1BE26-35A8-4999-A3A6-235CB7BD558B}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\PixVue EXIF & XMP & IPTC]
@={2E9BD3CA-A57F-450b-B1BA-A6A58C0C1D51}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\PixVue IPTC]
@={BCA5FB3A-9FC1-4465-ACE3-8C2072449164}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\PixVue XMP]
@={F0C13C81-FB8D-464e-873F-F8FF999E3EEC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\PixVue XMP & IPTC]
@={0117FFFB-91FD-414E-AC34-A00531032006}
[HKEY_CLASSES_ROOT\CLSID\{3E57A8B6-849B-476E-A3E9-CFCE49E3662A}]
2005-11-14 21:18 2465792 --a------ C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
[HKEY_CLASSES_ROOT\CLSID\{E3F36090-0540-418f-8136-074D5B255B59}]
2005-11-14 21:18 2465792 --a------ C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
[HKEY_CLASSES_ROOT\CLSID\{E1C1BE26-35A8-4999-A3A6-235CB7BD558B}]
2005-11-14 21:18 2465792 --a------ C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
[HKEY_CLASSES_ROOT\CLSID\{2E9BD3CA-A57F-450b-B1BA-A6A58C0C1D51}]
2005-11-14 21:18 2465792 --a------ C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
[HKEY_CLASSES_ROOT\CLSID\{BCA5FB3A-9FC1-4465-ACE3-8C2072449164}]
2005-11-14 21:18 2465792 --a------ C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
[HKEY_CLASSES_ROOT\CLSID\{F0C13C81-FB8D-464e-873F-F8FF999E3EEC}]
2005-11-14 21:18 2465792 --a------ C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
[HKEY_CLASSES_ROOT\CLSID\{0117FFFB-91FD-414E-AC34-A00531032006}]
2005-11-14 21:18 2465792 --a------ C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll" [2003-07-28 14:19 852038 C:\WINDOWS\system32\nview.dll]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-03 17:51 68856]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GSICONEXE"="GSICON.EXE" []
"DSLAGENTEXE"="DSLAGENT.exe" []
"GsiFinal"="gspndll.dll" [2001-09-10 10:56 98304 C:\WINDOWS\system32\gspnDll.dll]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-07-28 14:19 4841472]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-07-12 13:31 180269]
"QuickTime Task"="C:\QTTask.exe" [2007-06-29 06:24 286720]
"nwiz"="nwiz.exe" [2003-07-28 14:19 323584 C:\WINDOWS\system32\nwiz.exe]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36 229376]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-22 16:43 249896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cmdmfc]
C:\WINDOWS\repair\cmdmfc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PixVue]
C:\Program Files\PixVue.Com\PixVue\bin\WinLogon.DLL 2005-09-22 23:07 45056 C:\Program Files\PixVue.Com\PixVue\bin\WinLogon.dll
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\DRIVERS\avgntmgr.sys [2007-07-18 14:22]
R0 Defrag32b;Defrag32Boot;C:\WINDOWS\System32\drivers\Defrag32b.sys [2004-10-23 08:01]
R0 hgvdajpc;hgvdajpc;C:\WINDOWS\System32\drivers\vnbkqahq.dat []
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2007-08-09 13:04]
R3 NeroCd2k;NeroCd2k;C:\WINDOWS\System32\drivers\NeroCd2k.sys [2001-04-16 11:54]
S0 ElbyVCD;ElbyVCD;C:\WINDOWS\System32\DRIVERS\ElbyVCD.sys []
S2 Defrag32;Defrag32;C:\WINDOWS\System32\drivers\Defrag32.sys [2004-10-23 08:01]
S2 OIPUWGDV;OIPUWGDV;C:\WINDOWS\System32\oipuwgdv.etp []
S2 PDSched;PDScheduler;C:\Program Files\Raxco\PerfectDisk\PDSched.exe [2005-01-04 14:59]
S2 PixVue;PixVue;"C:\Program Files\PixVue.Com\PixVue\bin\Daemon.exe" [2005-11-14 21:19]
S3 C-Dilla;C-Dilla;C:\WINDOWS\System32\drivers\CDANT.SYS [2003-04-01 11:23]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\System32\DRIVERS\fbxusb32.sys [2004-10-20 16:23]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-01-19 19:05:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 14:19:24
Windows 5.1.2600 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2600.0000]
-> C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_libxml_.dll
-> C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_Magick++_.dll
-> C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_lcms_.dll
-> C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_xlib_.dll
.
Temps d'accomplissement: 2008-01-29 14:20:55 - machine was rebooted [MR PREAU]
ComboFix-quarantined-files.txt 2008-01-29 13:20:45
ComboFix2.txt 2008-01-23 13:34:06
ComboFix3.txt 2008-01-22 08:49:24
-----------------------------
Et le Hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:24:28, on 29/01/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.photim.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {102499AA-A382-44C8-A4EB-22018739DB6E} - C:\WINDOWS\System32\clusap.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &PixVue - {B28B4479-D9C2-41D1-B74D-74A1827037CD} - C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] DSLAGENT.EXE USB
O4 - HKLM\..\Run: [GsiFinal] rundll32 gspndll.dll,postInstall final
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr [...] nicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.co [...] 8696128186
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} - http://www.photoservice.com/au [...] oader4.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/7/840 [...] scan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://acs.pandasoftware.com/a [...] asinst.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} - http://www.extrafilm.fr/NET/Im [...] oader3.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.co [...] wflash.cab
O20 - Winlogon Notify: cmdmfc - C:\WINDOWS\repair\cmdmfc.dll (file missing)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: PixVue - PixVue.Com - C:\Program Files\PixVue.Com\PixVue\bin\Daemon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/MRPREA~1/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg
--
End of file - 6309 bytes