SERIEUX PROBLEME !! AIDEZ MOI SVP

Fermé
Bonjour, Je fait appelle a vous car hier en demarrant mon pc avast ma indiquer qui y'avai
beaucoup de virus (cheval de troie trojan..ect) alors que la veille tout marchait bien !j'ai tenter alors le scan au redemarage (programmer pour supprimer les fichier infectés avant qu'il soit actif) mais après le scan avast me dit encore que ces mêmes fichier son sur mon pc enfaite sa les supprime pas .Spybot n'y fait rien aussi ! malware bite trouve plus de 65 fichier infecter mais quant je fait supprimer les memes fichier reviennent toujours en plus maintenant sa m'ouvre des pages internet explorer pour rien alors que mon navigateur par default est Mozilla !!! J'AIS BESOIN D'AIDE

rapports en dessous!
Configuration: Windows XP
Firefox 3.0.7

7 réponses

  1. Contributeur sécurité
    salut,

    le rapport est pas là!
    0
    1. Contributeur sécurité
      Salut, chimay8

      Je te laisse poursuivre.

      Une info que j'ai déjà eu à traiter :
      C:\WINDOWS\system32\reader_s.exe --> Virut.
      https://www.broadcom.com/

      Bon courage.
      Je vais suivre la discussion pour autant.
      0
    2. Contributeur sécurité
      @verni29Salut

      oui c'est exact
      reader_s.exe: c'est du virut

      je l'ai également eu sous le même ".exe"

      0
  2. Contributeur sécurité
    Bonsoir,

    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre le sur ton Bureau.
    http://images.malwareremoval.com/random/RSIT.exe

    Double-clique sur " RSIT.exe " pour le lancer .
    dans la fenêtre qui va s’ouvrir choisis 2 months pour l'option "List files/folders created ..." ,
    cliques ensuite sur " Continue " pour lancer l'analyse ...

    Si la dernière version de HijackThis n'est pas trouvée sur ton PC, RSIT la téléchargera et te demandera d'accepter la licence.

    Attends jusqu’à la fin de l’analyse.
    deux rapports vont être generés.

    Poste uniquement le contenu de " log.txt ", et garde " info.txt " ( dans la barre des tâches), pour analyse, si je te le demande.

    Si tu ne les trouves pas,les rapports sont sauvegardés dans le dossier C:\rsit.

    A+
    0
    1. Malwarebytes' Anti-Malware 1.34
      Version de la base de données: 1813
      Windows 5.1.2600 Service Pack 2

      24/03/2009 19:35:18
      mbam-log-2009-03-24 (19-35-14).txt

      Type de recherche: Examen rapide
      Eléments examinés: 90631
      Temps écoulé: 41 minute(s), 32 second(s)

      Processus mémoire infecté(s): 6
      Module(s) mémoire infecté(s): 7
      Clé(s) du Registre infectée(s): 56
      Valeur(s) du Registre infectée(s): 8
      Elément(s) de données du Registre infecté(s): 6
      Dossier(s) infecté(s): 3
      Fichier(s) infecté(s): 55

      Processus mémoire infecté(s):
      C:\Program Files\Fichiers communs\rfqo\rfqom.exe (Trojan.Downloader) -> No action taken.
      C:\Program Files\Fichiers communs\rfqo\rfqoa.exe (Trojan.Downloader) -> No action taken.
      C:\Program Files\VnrPack\VnrPack29.exe (Adware.Agent) -> No action taken.
      C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
      C:\Documents and Settings\NNB\reader_s.exe (Trojan.Agent) -> No action taken.
      C:\Documents and Settings\All Users\Application Data\Microsoft\svchost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.

      Module(s) mémoire infecté(s):
      C:\WINDOWS\system32\ruvlweij.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\yayxxwus.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\ssqOHbxY.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\ddcBsRHy.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\fmardmop.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\sgkvvl.dll (Trojan.Vundo.H) -> No action taken.
      C:\Program Files\Fichiers communs\rfqo\rfqod\rfqoc.dll (Adware.TargetServer) -> No action taken.

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqohbxy (Trojan.Vundo.H) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9b3039f6-f197-4b4a-ba48-2a27a949cf06} (Trojan.Vundo.H) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{9b3039f6-f197-4b4a-ba48-2a27a949cf06} (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bbe9e0d1-c3e0-44fc-a77b-688038822e3e} (Trojan.Vundo.H) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{bbe9e0d1-c3e0-44fc-a77b-688038822e3e} (Trojan.Vundo.H) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
      HKEY_CLASSES_ROOT\bho_cpv.workhorse (Trojan.Agent) -> No action taken.
      HKEY_CLASSES_ROOT\TypeLib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.Agent) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.Agent) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.Agent) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15421b84-3488-49a7-ad18-cbf84a3efaf6} (Trojan.Agent) -> No action taken.
      HKEY_CLASSES_ROOT\bho_cpv.workhorse.1 (Trojan.Agent) -> No action taken.
      HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> No action taken.
      HKEY_CLASSES_ROOT\TypeLib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> No action taken.
      HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> No action taken.
      HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> No action taken.
      HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\VnrPack (Adware.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netsik (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\netsik (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\netsik (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netsik (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\glaide32 (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\glaide32 (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\restore (Rootkit.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fci (Rootkit.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TSA (Adware.TargetSaver) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fcf (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\fcf (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\fcf (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fcf (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\fci (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\fci (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\fci (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\icf (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\icf (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\icf (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\icf (Rootkit.ADS) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\restore (Rootkit.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\restore (Rootkit.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\restore (Rootkit.Agent) -> No action taken.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\2c1f8034 (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rfqo (Trojan.Downloader) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12zfg94-f641-2sf-k31p-5n1er6h6l2 (Trojan.Agent) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vnrpack29 (Adware.Agent) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12cfg515-k641-55sf-n66p (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.Agent) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.Agent) -> No action taken.

      Elément(s) de données du Registre infecté(s):
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\yayxxwus -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\yayxxwus -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Heuristics.Reserved.Word.Exploit) -> Data: c:\documents and settings\all users\application data\microsoft\svchost.exe -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe "C:\Documents and Settings\All Users\Application Data\Microsoft\svchost.exe") Good: (Explorer.exe) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.

      Dossier(s) infecté(s):
      C:\Program Files\InetGet2 (Trojan.Downloader) -> No action taken.
      C:\Program Files\iCheck (Trojan.Agent) -> No action taken.
      C:\Program Files\VnrPack (Adware.Agent) -> No action taken.

      Fichier(s) infecté(s):
      C:\WINDOWS\system32\ssqOHbxY.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\sgkvvl.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\yayxxwus.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\suwxxyay.ini (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\suwxxyay.ini2 (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\ruvlweij.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\jiewlvur.ini (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\ddcBsRHy.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\fmardmop.dll (Trojan.Vundo.H) -> No action taken.
      C:\Program Files\Fichiers communs\rfqo\rfqom.exe (Trojan.Downloader) -> No action taken.
      C:\Program Files\Fichiers communs\rfqo\rfqoa.exe (Trojan.Downloader) -> No action taken.
      C:\Program Files\Fichiers communs\rfqo\rfqod\rfqoc.dll (Adware.TargetServer) -> No action taken.
      C:\RECYCLER\S-1-5-21-8162064167-8498976116-960435484-7326\service.exe (Trojan.Agent) -> No action taken.
      C:\Program Files\WWShow\WWShow.dll (Trojan.Agent) -> No action taken.
      C:\Program Files\Jcore\Jcore2.dll (Trojan.BHO) -> No action taken.
      C:\WINDOWS\system32\awtqrsPh.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\ddcYpNDV.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\jkkKDsqO.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\mlJYpqoM.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\qoMEtUmJ.dll (Trojan.Vundo) -> No action taken.
      C:\WINDOWS\system32\ssqqOigd.dl_ (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\tsuninst.exe (Spyware.TargetSaver) -> No action taken.
      C:\WINDOWS\system32\yayywUlj.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\yayyXnKD.dll (Trojan.Vundo.H) -> No action taken.
      C:\mbackyt.exe (Trojan.TinyDownloader705) -> No action taken.
      C:\rfjcpx.exe (Trojan.TinyDownloader705) -> No action taken.
      C:\Documents and Settings\NNB\Local Settings\Temp\rip10.exe (Trojan.Agent) -> No action taken.
      C:\Documents and Settings\NNB\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe (Trojan.Downloader) -> No action taken.
      C:\Documents and Settings\NNB\Local Settings\Temp\tsupdate_4_0_4_1_b3.exe (Trojan.Downloader) -> No action taken.
      C:\Documents and Settings\NNB\Local Settings\Temp\__E.tmp (Trojan.Dropper) -> No action taken.
      C:\Documents and Settings\Eliezer\Local Settings\Temporary Internet Files\Content.IE5\OS2CM5XY\152[1].net (Trojan.Downloader) -> No action taken.
      C:\Documents and Settings\Eliezer\Local Settings\Temporary Internet Files\Content.IE5\T94SPGTK\155[1].net (Trojan.Downloader) -> No action taken.
      C:\Documents and Settings\NNB\Local Settings\Temporary Internet Files\Content.IE5\9MOA5K7G\apstpldr.dll[1].htm (Trojan.Vundo) -> No action taken.
      C:\Program Files\iCheck\Uninstall.exe (Trojan.Agent) -> No action taken.
      C:\Program Files\VnrPack\dicts.gz (Adware.Agent) -> No action taken.
      C:\Program Files\VnrPack\trgts.gz (Adware.Agent) -> No action taken.
      C:\Program Files\VnrPack\VnrPack29.exe (Adware.Agent) -> No action taken.
      C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556\pqlmq.exe (Trojan.Agent) -> No action taken.
      C:\WINDOWS\system32\drivers\netsik.sys (Trojan.Agent) -> No action taken.
      C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
      C:\WINDOWS\system32\drivers\glaide32.sys (Trojan.Agent) -> No action taken.
      C:\Documents and Settings\Eliezer\reader_s.exe (Trojan.Agent) -> No action taken.
      C:\Documents and Settings\NNB\reader_s.exe (Trojan.Agent) -> No action taken.
      C:\Documents and Settings\Eliezer\Application Data\Twain\Twain.exe (Trojan.Agent) -> No action taken.
      C:\WINDOWS\Temp\BN1.tmp (Trojan.Agent) -> No action taken.
      C:\WINDOWS\Temp\BN2.tmp (Trojan.Agent) -> No action taken.
      C:\lsass.exe (Trojan.Agent) -> No action taken.
      C:\WINDOWS\Prefetch\SVCHOST.EXE (Trojan.Agent) -> No action taken.
      C:\Documents and Settings\NNB\Local Settings\Temp\BN7E.tmp (Trojan.Agent) -> No action taken.
      C:\Documents and Settings\NNB\Local Settings\Temp\BN8B.tmp (Trojan.Agent) -> No action taken.
      C:\WINDOWS\Temp\BN23.tmp (Trojan.Agent) -> No action taken.
      C:\WINDOWS\system32\svchost.exe:exe.exe (Rootkit.ADS) -> No action taken.
      C:\WINDOWS\system32\svchost.exe:ext.exe (Rootkit.ADS) -> No action taken.
      C:\Documents and Settings\All Users\Application Data\Microsoft\svchost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
      C:\WINDOWS\system32\drivers\restore.sys (Rootkit.Agent) -> No action taken.

      RAPORT HIJACK THIS

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:40:43, on 24/03/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Safe mode with network support

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\DOCUME~1\NNB\LOCALS~1\Temp\stzkf3qhka.exe
      C:\DOCUME~1\NNB\LOCALS~1\Temp\mas1.tmp
      C:\WINDOWS\system32\svchost.exe
      C:\DOCUME~1\NNB\LOCALS~1\Temp\stzkf3qhka.exe
      C:\DOCUME~1\NNB\LOCALS~1\Temp\3768558054.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.fr/?gws_rd=ssl
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.files-ftp.com/~unicorni/phpBB2/index.php
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [wrna3ls] C:\Program Files\rnamfler\naomf.exe
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
      O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
      O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
      O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
      O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [12908] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29109] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4133] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23554] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21967] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4392] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23813] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3728] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28964] C:\pxtohk.exe
      O4 - HKLM\..\Run: [1347] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32383] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22341] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14809] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8994] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9917] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14145] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6613] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29339] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21807] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26034] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18503] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22730] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15198] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7666] C:\pxtohk.exe
      O4 - HKLM\..\Run: [134] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4362] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29598] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1058] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13741] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6209] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10437] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13871] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30781] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17434] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21662] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14130] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18358] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16770] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9239] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14390] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17030] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9498] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13726] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17066] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14890] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9075] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9998] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25322] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15653] C:\pxtohk.exe
      O4 - HKLM\..\Run: [21393] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24483] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25017] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19546] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31580] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7817] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14081] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6664] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16487] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32329] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12558] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24447] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25476] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15853] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8541] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7328] C:\pxtohk.exe
      O4 - HKLM\..\Run: [29374] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2301] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2096] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29049] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20724] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19136] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11604] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15832] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26798] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2485] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3409] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11864] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24547] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17015] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27227] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26888] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24103] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12863] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24737] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6369] C:\pxtohk.exe
      O4 - HKLM\..\Run: [7681] C:\pxtohk.exe
      O4 - HKLM\..\Run: [539] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4103] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8590] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28270] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13336] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17824] C:\pxtohk.exe
      O4 - HKLM\..\Run: [27872] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18448] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12359] C:\pxtohk.exe
      O4 - HKLM\..\Run: [339] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14954] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2515] C:\pxtohk.exe
      O4 - HKLM\..\Run: [264] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24378] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10517] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22057] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11320] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26514] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8925] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9054] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16611] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17534] C:\pxtohk.exe
      O4 - HKLM\..\Run: [21098] C:\pxtohk.exe
      O4 - HKLM\..\Run: [7751] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18717] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8674] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23868] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28096] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20564] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24791] C:\pxtohk.exe
      O4 - HKLM\..\Run: [29019] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25715] C:\pxtohk.exe
      O4 - HKLM\..\Run: [29942] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26638] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17519] C:\pxtohk.exe
      O4 - HKLM\..\Run: [21747] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2455] C:\pxtohk.exe
      O4 - HKLM\..\Run: [31919] C:\pxtohk.exe
      O4 - HKLM\..\Run: [31125] c:\pxtohk.exe
      O4 - HKLM\..\Run: [74] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25310] C:\pxtohk.exe
      O4 - HKLM\..\Run: [19495] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6149] C:\pxtohk.exe
      O4 - HKLM\..\Run: [29798] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5485] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10636] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4821] C:\pxtohk.exe
      O4 - HKLM\..\Run: [21732] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12612] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2570] C:\pxtohk.exe
      O4 - HKLM\..\Run: [27806] C:\pxtohk.exe
      O4 - HKLM\..\Run: [32034] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24502] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28729] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6927] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11155] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15383] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7851] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16306] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8774] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13002] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23968] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28195] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20663] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24891] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14848] C:\pxtohk.exe
      O4 - HKLM\..\Run: [7317] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11544] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4012] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26738] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16695] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9163] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13391] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24357] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28585] C:\pxtohk.exe
      O4 - HKLM\..\Run: [44] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25280] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15238] C:\pxtohk.exe
      O4 - HKLM\..\Run: [7706] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11933] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4402] C:\pxtohk.exe
      O4 - HKLM\..\Run: [27127] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19595] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23823] C:\pxtohk.exe
      O4 - HKLM\..\Run: [32278] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24746] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28974] C:\pxtohk.exe
      O4 - HKLM\..\Run: [21442] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25670] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24082] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16550] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20778] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13246] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3204] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7431] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32667] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4127] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15093] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23548] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16016] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20244] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24472] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2670] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6897] C:\pxtohk.exe
      O4 - HKLM\..\Run: [32133] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3593] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26318] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18786] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23014] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15482] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5440] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28165] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20633] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24861] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3059] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28295] C:\pxtohk.exe
      O4 - HKLM\..\Run: [32523] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22480] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14948] C:\pxtohk.exe
      O4 - HKLM\..\Run: [19176] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11644] C:\pxtohk.exe
      O4 - HKLM\..\Run: [1601] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26837] C:\pxtohk.exe
      O4 - HKLM\..\Run: [31065] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2525] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13491] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17718] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10186] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14414] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4372] C:\pxtohk.exe
      O4 - HKLM\..\Run: [29608] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1067] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26303] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30531] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22999] C:\pxtohk.exe
      O4 - HKLM\..\Run: [31454] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23922] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28150] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10576] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23259] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24182] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16650] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25105] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17573] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26029] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18497] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22725] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15193] C:\pxtohk.exe
      O4 - HKLM\..\Run: [19420] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23648] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16116] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20344] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12812] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17039] C:\pxtohk.exe
      O4 - HKLM\..\Run: [21267] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13735] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17963] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10431] C:\pxtohk.exe
      O4 - HKLM\..\Run: [388] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4616] C:\pxtohk.exe
      O4 - HKLM\..\Run: [29852] C:\pxtohk.exe
      O4 - HKLM\..\Run: [1312] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26548] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30775] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23244] C:\pxtohk.exe
      O4 - HKLM\..\Run: [27471] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31699] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24167] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28395] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6224] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28415] C:\pxtohk.exe
      O4 - HKLM\..\Run: [1378] C:\pxtohk.exe
      O4 - HKLM\..\Run: [31949] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5506] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12878] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22286] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5756] C:\pxtohk.exe
      O4 - HKLM\..\Run: [1821] C:\pxtohk.exe
      O4 - HKLM\..\Run: [21363] C:\pxtohk.exe
      O4 - HKLM\..\Run: [1278] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28750] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5970] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13297] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14220] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12174] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18343] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10901] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14610] C:\pxtohk.exe
      O4 - HKLM\..\Run: [89] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26379] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14085] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6553] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8791] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15008] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11704] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3345] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12627] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17425] C:\pxtohk.exe
      O4 - HKLM\..\Run: [27987] C:\pxtohk.exe
      O4 - HKLM\..\Run: [204] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5355] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9468] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21228] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22251] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12208] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4676] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8904] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14205] C:\pxtohk.exe
      O4 - HKLM\..\Run: [19870] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9827] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10751] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3219] C:\pxtohk.exe
      O4 - HKLM\..\Run: [30172] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2555] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17748] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17085] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13780] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9553] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14704] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15373] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11399] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24876] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15757] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15937] C:\pxtohk.exe
      O4 - HKLM\..\Run: [30950] C:\pxtohk.exe
      O4 - HKLM\..\Run: [29363] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26059] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26982] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25395] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24731] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24991] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15872] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24327] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15208] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14544] C:\pxtohk.exe
      O4 - HKLM\..\Run: [19695] C:\pxtohk.exe
      O4 - HKLM\..\Run: [30661] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11499] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31110] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10042] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12682] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9378] C:\pxtohk.exe
      O4 - HKLM\..\Run: [30576] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22061] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14529] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10835] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25495] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29722] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26418] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8354] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6779] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6918] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11275] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9528] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25775] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24173] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6728] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24562] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18083] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5790] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26264] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9743] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18828] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24773] C:\pxtohk.exe
      O4 - HKLM\..\Run: [1872] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3804] C:\pxtohk.exe
      O4 - HKLM\..\Run: [21653] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22486] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15473] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16251] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17130] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3119] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6683] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20289] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9583] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17374] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25166] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14459] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3753] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5859] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18931] C:\pxtohk.exe
      O4 - HKLM\..\Run: [19191] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5425] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21671] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16765] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10286] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2220] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31020] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13761] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16686] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8864] C:\pxtohk.exe
      O4 - HKLM\..\Run: [5964] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3913] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2715] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29004] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14815] C:\pxtohk.exe
      O4 - HKLM\..\Run: [13406] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24372] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11025] C:\pxtohk.exe
      O4 - HKLM\..\Run: [22965] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26478] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3089] C:\pxtohk.exe
      O4 - HKLM\..\Run: [11414] C:\pxtohk.exe
      O4 - HKLM\..\Run: [3883] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9697] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15368] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17359] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12597] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8759] C:\pxtohk.exe
      O4 - HKLM\..\Run: [28714] C:\pxtohk.exe
      O4 - HKLM\..\Run: [7042] C:\pxtohk.exe
      O4 - HKLM\..\Run: [7965] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12193] C:\pxtohk.exe
      O4 - HKLM\..\Run: [30561] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8225] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13506] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14121] C:\pxtohk.exe
      O4 - HKLM\..\Run: [31610] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18527] C:\pxtohk.exe
      O4 - HKLM\..\Run: [30546] c:\pxtohk.exe
      O4 - HKLM\..\Run: [953] C:\pxtohk.exe
      O4 - HKLM\..\Run: [12582] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9278] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2799] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13361] C:\pxtohk.exe
      O4 - HKLM\..\Run: [10057] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18512] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12278] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9927] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2395] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6623] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17589] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21816] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26044] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8469] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17848] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18771] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8729] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1197] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26433] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6203] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31439] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32363] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19016] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8973] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1441] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6593] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10820] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3288] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7516] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11744] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22709] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15178] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5135] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27861] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20329] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14514] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6982] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11209] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22175] c:\pxtohk.exe
      O4 - HKLM\..\Run: [373] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4601] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29837] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1297] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24022] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16490] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20718] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13186] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17414] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14109] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18337] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8294] C:\pxtohk.exe
      O4 - HKLM\..\Run: [19260] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23488] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15956] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20184] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12652] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16880] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21107] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13575] C:\pxtohk.exe
      O4 - HKLM\..\Run: [17803] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10271] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14499] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18726] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11194] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15422] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7890] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12118] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8814] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13041] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17269] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9737] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13965] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6433] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10660] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14888] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7356] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11584] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4052] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8279] c:\pxtohk.exe
      O4 - HKLM\..\Run: [748] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4975] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9203] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1671] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5899] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31135] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2594] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6822] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32058] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3518] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21592] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14235] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19951] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5680] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30413] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16676] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26454] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22670] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26898] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5096] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9323] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9193] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23095] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10726] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30811] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3798] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8415] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2066] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26948] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30476] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4567] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20693] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8146] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2331] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27567] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31795] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4178] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8405] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25811] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22516] C:\pxtohk.exe
      O4 - HKLM\..\Run: [623] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3978] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12184] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14440] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25950] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14265] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29948] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20823] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9244] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26689] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12093] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14734] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8789] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1257] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3898] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17504] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32697] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20624] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7217] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7721] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22914] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29399] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31849] C:\pxtohk.exe
      O4 - HKLM\..\Run: [449] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23174] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29927] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1387] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7162] c:\pxtohk.exe
      O4 - HKLM\..\Run: [578] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21717] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15902] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26868] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24097] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3478] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18672] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22899] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14540] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19700] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10476] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4661] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15138] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7561] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21831] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30287] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16970] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21812] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17585] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28017] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11655] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11918] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27661] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31889] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17745] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24522] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4917] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29688] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10077] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13167] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23578] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16291] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27242] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4223] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32408] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13895] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19206] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19061] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23289] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30027] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14155] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20893] c:\pxtohk.exe
      O4 - HKLM\..\Run: [808] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7546] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16925] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16261] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12163] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2940] C:\pxtohk.exe
      O4 - HKLM\..\Run: [9912] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3952] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2380] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10690] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11255] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3159] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25884] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24846] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23129] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12537] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19275] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29318] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1701] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12667] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16895] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11080] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22046] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15433] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28784] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18741] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27067] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6478] C:\pxtohk.exe
      O4 - HKLM\..\Run: [6852] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21122] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6188] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28914] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21382] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22305] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26533] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8958] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31684] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9882] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25075] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17543] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21771] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32737] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28509] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18467] c:\pxtohk.exe
      O4 - HKLM\..\Run: [892] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5120] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1816] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11858] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8554] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31279] C:\pxtohk.exe
      O4 - HKLM\..\Run: [23748] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1945] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6173] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28899] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21367] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25594] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18062] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22290] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14758] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18986] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28884] c:\pxtohk.exe
      O4 - HKLM\..\Run: [343] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4571] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29807] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1267] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26503] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3429] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27742] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17344] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28665] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30267] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11324] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4716] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19909] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23343] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14224] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27531] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16810] C:\pxtohk.exe
      O4 - HKLM\..\Run: [8819] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22350] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21023] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19655] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8454] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23663] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16131] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30362] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23319] c:\pxtohk.exe
      O4 - HKLM\..\Run: [983] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24946] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4860] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30097] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8424] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18222] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1282] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29158] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13301] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24282] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31005] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17139] c:\pxtohk.exe
      O4 - HKLM\..\Run: [913] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22884] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24013] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13765] C:\pxtohk.exe
      O4 - HKLM\..\Run: [25784] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17274] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12039] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24457] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2859] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21822] C:\pxtohk.exe
      O4 - HKLM\..\Run: [16466] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14674] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3164] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17649] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18108] c:\pxtohk.exe
      O4 - HKLM\..\Run: [533] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22830] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10561] C:\pxtohk.exe
      O4 - HKLM\..\Run: [27341] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7241] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10316] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29957] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8155] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30881] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27042] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12178] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15841] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14689] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25250] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15612] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3538] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26179] C:\pxtohk.exe
      O4 - HKLM\..\Run: [26014] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32269] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24197] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27851] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3418] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4341] C:\pxtohk.exe
      O4 - HKLM\..\Run: [2090] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17399] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9867] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4067] C:\pxtohk.exe
      O4 - HKLM\..\Run: [20833] c:\pxtohk.exe
      O4 - HKLM\..\Run: [763] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25999] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4326] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1022] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8439] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3149] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29952] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25060] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9902] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15941] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17619] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18452] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21512] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15147] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24007] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13446] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4387] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27073] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4242] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23618] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7821] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10925] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28120] C:\pxtohk.exe
      O4 - HKLM\..\Run: [24801] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16940] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19450] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5240] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16176] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22081] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17190] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24936] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29089] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27492] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24761] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7187] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16596] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26563] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3294] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22160] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29538] C:\pxtohk.exe
      O4 - HKLM\..\Run: [18237] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1951] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8584] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13782] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31011] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1791] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16436] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22839] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20060] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8080] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20030] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16520] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6348] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2984] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32577] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25045] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9188] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10111] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12752] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5220] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26358] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13011] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23977] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22390] c:\pxtohk.exe
      O4 - HKLM\..\Run: [588] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21726] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14194] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8379] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9302] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17758] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18681] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22909] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28060] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32287] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28983] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27396] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19864] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4007] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29243] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1626] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14309] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23687] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7830] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8753] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9677] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6372] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19055] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15751] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9143] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10196] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23802] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2000] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1336] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5564] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4900] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8059] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17438] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21666] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14134] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19285] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23512] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28664] c:\pxtohk.exe
      O4 - HKLM\..\Run: [123] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25359] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9502] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1970] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18881] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29846] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13989] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6457] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14912] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15836] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20063] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25214] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29442] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1825] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6976] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11204] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3672] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20582] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13051] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7236] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22429] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14897] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31808] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24276] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8419] c:\pxtohk.exe
      O4 - HKLM\..\Run: [887] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5114] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22025] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14493] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8678] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9602] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2070] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4710] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29946] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14089] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6557] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27372] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31394] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4471] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2250] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13481] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28615] C:\pxtohk.exe
      O4 - HKLM\..\Run: [14788] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4172] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9393] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11460] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2425] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31844] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6752] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15283] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13461] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3373] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29273] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21741] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22794] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13675] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16315] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12088] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5609] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25030] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23443] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23458] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31370] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24366] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16834] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21062] c:\pxtohk.exe
      O4 - HKLM\..\Run: [3617] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20398] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16171] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25549] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29777] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15636] c:\pxtohk.exe
      O4 - HKLM\..\Run: [32547] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19200] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23428] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7570] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31264] c:\pxtohk.exe
      O4 - HKLM\..\Run: [39] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16949] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25275] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17873] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28968] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12981] c:\pxtohk.exe
      O4 - HKLM\..\Run: [24077] c:\pxtohk.exe
      O4 - HKLM\..\Run: [687] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17468] c:\pxtohk.exe
      O4 - HKLM\..\Run: [1611] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12577] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16804] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27900] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31464] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18781] c:\pxtohk.exe
      O4 - HKLM\..\Run: [23008] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22345] c:\pxtohk.exe
      O4 - HKLM\..\Run: [672] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8120] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4236] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30136] c:\pxtohk.exe
      O4 - HKLM\..\Run: [16774] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21002] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7151] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13470] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30381] c:\pxtohk.exe
      O4 - HKLM\..\Run: [6991] c:\pxtohk.exe
      O4 - HKLM\..\Run: [12468] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31304] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20598] c:\pxtohk.exe
      O4 - HKLM\..\Run: [7915] c:\pxtohk.exe
      O4 - HKLM\..\Run: [15706] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27411] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5534] c:\pxtohk.exe
      O4 - HKLM\..\Run: [25085] c:\pxtohk.exe
      O4 - HKLM\..\Run: [27845] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17553] c:\pxtohk.exe
      O4 - HKLM\..\Run: [19704] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28519] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4845] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22040] c:\pxtohk.exe
      O4 - HKLM\..\Run: [26268] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30495] c:\pxtohk.exe
      O4 - HKLM\..\Run: [22963] c:\pxtohk.exe
      O4 - HKLM\..\Run: [2878] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8029] c:\pxtohk.exe
      O4 - HKLM\..\Run: [28114] c:\pxtohk.exe
      O4 - HKLM\..\Run: [21636] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8953] c:\pxtohk.exe
      O4 - HKLM\..\Run: [5778] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10799] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13440] c:\pxtohk.exe
      O4 - HKLM\..\Run: [9212] c:\pxtohk.exe
      O4 - HKLM\..\Run: [20178] c:\pxtohk.exe
      O4 - HKLM\..\Run: [18591] c:\pxtohk.exe
      O4 - HKLM\..\Run: [11059] c:\pxtohk.exe
      O4 - HKLM\..\Run: [31533] c:\pxtohk.exe
      O4 - HKLM\..\Run: [13036] c:\pxtohk.exe
      O4 - HKLM\..\Run: [4046] c:\pxtohk.exe
      O4 - HKLM\..\Run: [10784] c:\pxtohk.exe
      O4 - HKLM\..\Run: [742] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29737] c:\pxtohk.exe
      O4 - HKLM\..\Run: [29043] c:\pxtohk.exe
      O4 - HKLM\..\Run: [30072] C:\pxtohk.exe
      O4 - HKLM\..\Run: [1073] c:\pxtohk.exe
      O4 - HKLM\..\Run: [17778] c:\pxtohk.exe
      O4 - HKLM\..\Run: [8195] c:\pxtohk.exe
      O4 - HKLM\..\Run: [14489] C:\pxtohk.exe
      O4 - HKLM\..\Run: [4432] C:\pxtohk.exe
      O4 - HKLM\..\Run: [30796] C:\pxtohk.exe
      O4 - HKLM\..\Run: [15682] c:\pxtohk.ex
      0
      1. Contributeur sécurité
        bah,c'est du zlob!
        0
        1. j'arrive pa a faire marcher ton logiciel a tu lu les rapports ?
          0