Virus home search assistant et about blank

bonjour,
Je viens sur ce forum car apres plusieurs jours de recherches a propos de mon prbleme je n'ai toujours pas trouvé de solutions.
En effet, je pense etre infecte par Home search assistant.
Pour que vous puissiez lus facilement m'aider je vous envoie le log que hijack this a trouvé.

Logfile of HijackThis v1.98.2
Scan saved at 20:05:39, on 03/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Propriétaire\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http//www.wanadoo.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http//wanadoo.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [RegSvr32] C:\Program Files\messenger\msmsgs.exe
O4 - HKLM\..\Run: [exitlicenseshimwait] C:\Documents and Settings\All Users\Application Data\prochopeexitlicense\Bleh Face.exe
O4 - HKLM\..\Run: [winmt.exe] C:\WINDOWS\system32\winmt.exe
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKLM\..\Run: [syscd32.exe] C:\WINDOWS\system32\syscd32.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [addmq32.exe] C:\WINDOWS\addmq32.exe
O4 - HKLM\..\Run: [ipwj.exe] C:\WINDOWS\ipwj.exe
O4 - HKLM\..\RunOnce: [d3ea.exe] C:\WINDOWS\d3ea.exe
O4 - HKLM\..\RunOnce: [appte32.exe] C:\WINDOWS\appte32.exe
O4 - HKLM\..\RunOnce: [javats32.exe] C:\WINDOWS\javats32.exe
O4 - HKLM\..\RunOnce: [apppp.exe] C:\WINDOWS\system32\apppp.exe
O4 - HKLM\..\RunOnce: [crjt32.exe] C:\WINDOWS\system32\crjt32.exe
O4 - HKLM\..\RunOnce: [iexd32.exe] C:\WINDOWS\system32\iexd32.exe
O4 - HKLM\..\RunOnce: [ipat.exe] C:\WINDOWS\system32\ipat.exe
O4 - HKLM\..\RunOnce: [winah32.exe] C:\WINDOWS\winah32.exe
O4 - HKLM\..\RunOnce: [mssn32.exe] C:\WINDOWS\system32\mssn32.exe
O4 - HKLM\..\RunOnce: [mshi32.exe] C:\WINDOWS\system32\mshi32.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [TitleCash] C:\DOCUME~1\PROPRI~1\APPLIC~1\DRVLOA~1\Love Kind Soap.exe
O4 - HKCU\..\Run: [MessengerPlus3] "\" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll

voila j'ai essayé la procédure su site echu.org mais ca n'a rien changé.
J'espere que quelqu'un pourra me venir en aide assez rapidement.
Merci d'avance, j'attends vos suggestions.
Configuration: compaq presario
intel pentium4
2.6 ghz
256ddr
120 go disque dur
ati radeon 9200 se
128 mo de memoire video
windows xp familiale 
service pack2

14 réponses

  1. salut
    tu as la mauvaise version hijack this
    , télécharge HijackThis ici:
    http://www.hijackthis.de/downloads/hijackthis_199.zip

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (merci à balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    Bon courage

    A+

    PS:Home search assistant <----detecter par spybot?
    0
    1. Logfile of HijackThis v1.99.1
      Scan saved at 22:49:49, on 09/09/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
      C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
      C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
      C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
      C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\crpp32.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\hidjackthis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xlbov.dll/sp.html#37049
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xlbov.dll/sp.html#37049
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\xlbov.dll/sp.html#37049
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xlbov.dll/sp.html#37049
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xlbov.dll/sp.html#37049
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xlbov.dll/sp.html#37049
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xlbov.dll/sp.html#37049
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - Default URLSearchHook is missing
      O2 - BHO: Class - {3D1E8A6D-0FB0-0E2E-D985-66A3F50B7CDB} - C:\WINDOWS\system32\d3qc.dll
      O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
      O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
      O2 - BHO: Class - {E5BA8ACF-C2BF-8C35-2A93-0CAF53F6A229} - C:\WINDOWS\sdkef32.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [RegSvr32] C:\Program Files\messenger\msmsgs.exe
      O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
      O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
      O4 - HKLM\..\Run: [SpySpotter] C:\Program Files\SpySpotter3\SpySpotter.exe -startup
      O4 - HKLM\..\Run: [crpp32.exe] C:\WINDOWS\system32\crpp32.exe
      O4 - HKLM\..\RunOnce: [d3ea.exe] C:\WINDOWS\d3ea.exe
      O4 - HKLM\..\RunOnce: [atloo.exe] C:\WINDOWS\atloo.exe
      O4 - HKLM\..\RunOnce: [apimr32.exe] C:\WINDOWS\apimr32.exe
      O4 - HKLM\..\RunOnce: [mfcwp32.exe] C:\WINDOWS\system32\mfcwp32.exe
      O4 - HKLM\..\RunOnce: [crke.exe] C:\WINDOWS\system32\crke.exe
      O4 - HKLM\..\RunOnce: [mfclj.exe] C:\WINDOWS\mfclj.exe
      O4 - HKLM\..\RunOnce: [atlze32.exe] C:\WINDOWS\system32\atlze32.exe
      O4 - HKLM\..\RunOnce: [addsl.exe] C:\WINDOWS\system32\addsl.exe
      O4 - HKLM\..\RunOnce: [ipnu.exe] C:\WINDOWS\ipnu.exe
      O4 - HKLM\..\RunOnce: [apirw.exe] C:\WINDOWS\system32\apirw.exe
      O4 - HKLM\..\RunOnce: [d3vl32.exe] C:\WINDOWS\d3vl32.exe
      O4 - HKLM\..\RunOnce: [sysio.exe] C:\WINDOWS\sysio.exe
      O4 - HKLM\..\RunOnce: [netru32.exe] C:\WINDOWS\netru32.exe
      O4 - HKLM\..\RunOnce: [ntou32.exe] C:\WINDOWS\ntou32.exe
      O4 - HKLM\..\RunOnce: [addzb.exe] C:\WINDOWS\addzb.exe
      O4 - HKLM\..\RunOnce: [crdz32.exe] C:\WINDOWS\crdz32.exe
      O4 - HKLM\..\RunOnce: [netit32.exe] C:\WINDOWS\netit32.exe
      O4 - HKLM\..\RunOnce: [ntrt.exe] C:\WINDOWS\ntrt.exe
      O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
      O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [MessengerPlus3] "\" /WinStart
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
      O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
      O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
      O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
      O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
      O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
      O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
      O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\d3ea.exe" /s (file missing)
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
      O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      0
      1. Bonjour Fred,

        Méthode à suivre dans l'ordre...
        ----------------------------------------------------------------------------
        ¤Télécharge ces logiciels mais que tu n‘utilises pas tout de suite:

        1/Spybot S&D 1.4 <<nouvelle version
        http://www.safer-networking.org/fr/index.html

        Démo d’utilisation (merci à Balltrap34 pour cette réalisation)
        http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

        2/Ad-Aware SE 1.06 <<nouvelle version
        http://www.lavasoftusa.com/software/adaware/
        -Une aide:
        http://www.tutopat.com/viewtopic.php?t=1191
        - installe le patch français, tu pourras le trouver ici:
        http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
        et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation)
        http://pageperso.aol.fr/balltrap34/adawrevid.asf

        3/Clean Up 40:
        http://pageperso.aol.fr/balltrap34/CleanUp40.exe
        -aide en image:(merci à Balltrap34)
        http://pageperso.aol.fr/balltrap34/democleanup.htm

        8/about buster:
        http://www.majorgeeks.com/download4289.html

        Clique "Check for updates".
        Télécharge les mises à jour
        referme le
        on l‘utilisera plus tard.
        ----------------------------------------------------------------------------
        ¤Démarre en mode sans échec :
        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
        (Si F8 ne marche pas utilise la touche F5)

        ----------------------------------------------------------------------------
        ¤Affiche tous les fichiers et dossiers :
        Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

        Coche « afficher les fichiers et dossiers cachés »

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décoche « masquer les extensions dont le type est connu »
        Puis fais «Ok» pour valider les changements.

        Et appliquer !
        ----------------------------------------------------------------------------
        ¤Vide tes fichiers temps et tempory internet file:
        utilise ceci pour le faire (tu as téléchargé avant)
        http://pageperso.aol.fr/balltrap34/CleanUp40.exe
        ----------------------------------------------------------------------------
        ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xlbov.dll/sp.html#37049

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xlbov.dll/sp.html#37049

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\xlbov.dll/sp.html#37049

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xlbov.dll/sp.html#37049

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xlbov.dll/sp.html#37049

        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xlbov.dll/sp.html#37049

        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xlbov.dll/sp.html#37049

        R3 - Default URLSearchHook is missing

        O2 - BHO: Class - {3D1E8A6D-0FB0-0E2E-D985-66A3F50B7CDB} - C:\WINDOWS\system32\d3qc.dll

        O2 - BHO: Class - {E5BA8ACF-C2BF-8C35-2A93-0CAF53F6A229} - C:\WINDOWS\sdkef32.dll

        O4 - HKLM\..\Run: [RegSvr32] C:\Program Files\messenger\msmsgs.exe

        O4 - HKLM\..\Run: [crpp32.exe] C:\WINDOWS\system32\crpp32.exe
        O4 - HKLM\..\RunOnce: [d3ea.exe] C:\WINDOWS\d3ea.exe
        O4 - HKLM\..\RunOnce: [atloo.exe] C:\WINDOWS\atloo.exe
        O4 - HKLM\..\RunOnce: [apimr32.exe] C:\WINDOWS\apimr32.exe
        O4 - HKLM\..\RunOnce: [mfcwp32.exe] C:\WINDOWS\system32\mfcwp32.exe
        O4 - HKLM\..\RunOnce: [crke.exe] C:\WINDOWS\system32\crke.exe
        O4 - HKLM\..\RunOnce: [mfclj.exe] C:\WINDOWS\mfclj.exe
        O4 - HKLM\..\RunOnce: [atlze32.exe] C:\WINDOWS\system32\atlze32.exe
        O4 - HKLM\..\RunOnce: [addsl.exe] C:\WINDOWS\system32\addsl.exe
        O4 - HKLM\..\RunOnce: [ipnu.exe] C:\WINDOWS\ipnu.exe
        O4 - HKLM\..\RunOnce: [apirw.exe] C:\WINDOWS\system32\apirw.exe
        O4 - HKLM\..\RunOnce: [d3vl32.exe] C:\WINDOWS\d3vl32.exe
        O4 - HKLM\..\RunOnce: [sysio.exe] C:\WINDOWS\sysio.exe
        O4 - HKLM\..\RunOnce: [netru32.exe] C:\WINDOWS\netru32.exe
        O4 - HKLM\..\RunOnce: [ntou32.exe] C:\WINDOWS\ntou32.exe
        O4 - HKLM\..\RunOnce: [addzb.exe] C:\WINDOWS\addzb.exe
        O4 - HKLM\..\RunOnce: [crdz32.exe] C:\WINDOWS\crdz32.exe
        O4 - HKLM\..\RunOnce: [netit32.exe] C:\WINDOWS\netit32.exe
        O4 - HKLM\..\RunOnce: [ntrt.exe] C:\WINDOWS\ntrt.exe

        O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab

        O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab

        O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab

        O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab

        O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll

        O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\d3ea.exe" /s (file missing)

        ----------------------------------------------------------------------------
        ¤Recherche et supprime ceci:
        attention seulement les fichiers (si présents)

        C:\Program Files\messenger\
        C:\WINDOWS\system32\crpp32.exe
        C:\WINDOWS\d3ea.exe
        C:\WINDOWS\atloo.exe
        C:\WINDOWS\apimr32.exe
        C:\WINDOWS\system32\mfcwp32.exe
        C:\WINDOWS\system32\crke.exe
        C:\WINDOWS\mfclj.exe
        C:\WINDOWS\system32\atlze32.exe
        C:\WINDOWS\system32\addsl.exe
        C:\WINDOWS\ipnu.exe
        C:\WINDOWS\system32\apirw.exe
        C:\WINDOWS\d3vl32.exe
        C:\WINDOWS\sysio.exe
        C:\WINDOWS\netru32.exe
        C:\WINDOWS\ntou32.exe
        C:\WINDOWS\addzb.exe
        C:\WINDOWS\crdz32.exe
        C:\WINDOWS\netit32.exe
        C:\WINDOWS\ntrt.exe
        c:\eied_s7.cab
        c:\ex.cab
        C:\WINDOWS\d3ea.exe

        ----------------------------------------------------------------------------
        ¤Arrête ces services :

        Clique sur Démarrer->exécuter->tape: services.msc

        Double-clique: Service: Remote Procedure Call (RPC) Helper

        Règle-le sur "Arrêté" et "Désactivé".
        ---------------------------------------------------------------------------
        Passe about buster autant de fois qu il trouve qqchose (5/10/15 fois au besoin)
        ----------------------------------------------------------------------------
        ¤ Passe Ad-Aware et vire tout ce qu’il trouve
        ----------------------------------------------------------------------------
        ¤ Passe Spybot et vire tout ce qu’il trouve
        ----------------------------------------------------------------------------
        > Tu vides ta poubelle et tu redémarres en mode normal et refait un HijackThis

        Précise tes soucis s’il en reste....

        Tiens-moi au courant

        a+
        0
        1. Le problème n'est toujours pas résolu.
          Je renvoie le log :

          Logfile of HijackThis v1.99.1
          Scan saved at 04:19:08, on 13/09/2005
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
          C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
          C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
          C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\wscntfy.exe
          C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
          C:\WINDOWS\system32\sysrz.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\SpySpotter3\Defender.exe
          C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\MSN Messenger\msnmsgr.exe
          C:\hidjackthis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - Default URLSearchHook is missing
          O2 - BHO: Class - {324C7B28-F8EB-05C3-47CF-680DDABE2D8D} - C:\WINDOWS\ipdn.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O2 - BHO: Class - {5D29CB91-A959-E2C1-4346-FA68E60B26EB} - C:\WINDOWS\ippy.dll
          O2 - BHO: Class - {7D7C699F-514A-9930-EB7D-2543267B7CDC} - C:\WINDOWS\appzl.dll
          O2 - BHO: Class - {A8955C5E-7D09-18F5-1D0E-99FB9B61BC16} - C:\WINDOWS\system32\addsr32.dll
          O2 - BHO: Class - {BFBFA424-9910-08B0-2FBF-CC5180D847C2} - C:\WINDOWS\system32\sysrz.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
          O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
          O4 - HKLM\..\Run: [SpySpotter] C:\Program Files\SpySpotter3\SpySpotter.exe -startup
          O4 - HKLM\..\Run: [sysrz.exe] C:\WINDOWS\system32\sysrz.exe
          O4 - HKLM\..\RunOnce: [mfcmp32.exe] C:\WINDOWS\system32\mfcmp32.exe
          O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
          O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
          O4 - HKCU\..\Run: [MessengerPlus3] "\" /WinStart
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
          O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
          O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
          O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
          O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
          0
          1. ok......
            alors deja arrete de visiter des sites .... et apres spy neeker 2005
            0
            1. pourquoi arrete de visiter des sites?
              Et c'est quoi spy neeker 2005?
              0
              1. salut fred
                ton log que tu m as remis n est pas complet
                recommence stp

                PS: y a de l amelioration mais il en reste pas mal...

                Et aussi ajoute le rapport de ceci
                telecharge ceci
                http://siri.urz.free.fr/Fix/SmitfraudFix.zip
                choisit l option1 , copie/colle le rapport

                Ainsi tu me met le rapport hijack this en entier + smitfraug fix

                a+
                0
                1. LOG HIJACKTHIS :
                  Logfile of HijackThis v1.99.1
                  Scan saved at 01:21:54, on 18/09/2005
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                  C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                  C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
                  C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                  C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
                  C:\WINDOWS\system32\sysrz.exe
                  C:\Program Files\SpySpotter3\Defender.exe
                  C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
                  C:\WINDOWS\system32\wisptis.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\WINDOWS\system32\mfcmp32.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\hidjackthis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\acams.dll/sp.html#37049
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\acams.dll/sp.html#37049
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\acams.dll/sp.html#37049
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\acams.dll/sp.html#37049
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\acams.dll/sp.html#37049
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\acams.dll/sp.html#37049
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\acams.dll/sp.html#37049
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - Default URLSearchHook is missing
                  O2 - BHO: Class - {BFBFA424-9910-08B0-2FBF-CC5180D847C2} - C:\WINDOWS\system32\sysrz.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
                  O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
                  O4 - HKLM\..\Run: [sysrz.exe] C:\WINDOWS\system32\sysrz.exe
                  O4 - HKLM\..\RunOnce: [mfcmp32.exe] C:\WINDOWS\system32\mfcmp32.exe
                  O4 - HKLM\..\RunOnce: [msfu.exe] C:\WINDOWS\msfu.exe
                  O4 - HKLM\..\RunOnce: [sysuq32.exe] C:\WINDOWS\sysuq32.exe
                  O4 - HKLM\..\RunOnce: [addvu32.exe] C:\WINDOWS\system32\addvu32.exe
                  O4 - HKLM\..\RunOnce: [d3aw.exe] C:\WINDOWS\system32\d3aw.exe
                  O4 - HKLM\..\RunOnce: [javaxt.exe] C:\WINDOWS\system32\javaxt.exe
                  O4 - HKLM\..\RunOnce: [mfcdn.exe] C:\WINDOWS\system32\mfcdn.exe
                  O4 - HKLM\..\RunOnce: [appmo32.exe] C:\WINDOWS\system32\appmo32.exe
                  O4 - HKLM\..\RunOnce: [d3sq.exe] C:\WINDOWS\system32\d3sq.exe
                  O4 - HKLM\..\RunOnce: [mfcmb.exe] C:\WINDOWS\mfcmb.exe
                  O4 - HKLM\..\RunOnce: [ierw32.exe] C:\WINDOWS\ierw32.exe
                  O4 - HKLM\..\RunOnce: [apppd32.exe] C:\WINDOWS\system32\apppd32.exe
                  O4 - HKLM\..\RunOnce: [ntpf32.exe] C:\WINDOWS\system32\ntpf32.exe
                  O4 - HKLM\..\RunOnce: [ntfy32.exe] C:\WINDOWS\ntfy32.exe
                  O4 - HKLM\..\RunOnce: [appls.exe] C:\WINDOWS\appls.exe
                  O4 - HKLM\..\RunOnce: [javacw32.exe] C:\WINDOWS\system32\javacw32.exe
                  O4 - HKLM\..\RunOnce: [ntmw.exe] C:\WINDOWS\system32\ntmw.exe
                  O4 - HKLM\..\RunOnce: [sdkst.exe] C:\WINDOWS\system32\sdkst.exe
                  O4 - HKLM\..\RunOnce: [appfy.exe] C:\WINDOWS\appfy.exe
                  O4 - HKLM\..\RunOnce: [sdkaj.exe] C:\WINDOWS\system32\sdkaj.exe
                  O4 - HKLM\..\RunOnce: [ippq.exe] C:\WINDOWS\system32\ippq.exe
                  O4 - HKLM\..\RunOnce: [appzj32.exe] C:\WINDOWS\appzj32.exe
                  O4 - HKLM\..\RunOnce: [atllc.exe] C:\WINDOWS\atllc.exe
                  O4 - HKLM\..\RunOnce: [appmw32.exe] C:\WINDOWS\appmw32.exe
                  O4 - HKLM\..\RunOnce: [winkr.exe] C:\WINDOWS\winkr.exe
                  O4 - HKLM\..\RunOnce: [javabz32.exe] C:\WINDOWS\javabz32.exe
                  O4 - HKLM\..\RunOnce: [addpo.exe] C:\WINDOWS\system32\addpo.exe
                  O4 - HKLM\..\RunOnce: [atlov.exe] C:\WINDOWS\atlov.exe
                  O4 - HKLM\..\RunOnce: [netzw.exe] C:\WINDOWS\system32\netzw.exe
                  O4 - HKLM\..\RunOnce: [winyw32.exe] C:\WINDOWS\system32\winyw32.exe
                  O4 - HKLM\..\RunOnce: [appsn32.exe] C:\WINDOWS\appsn32.exe
                  O4 - HKLM\..\RunOnce: [addgk.exe] C:\WINDOWS\system32\addgk.exe
                  O4 - HKLM\..\RunOnce: [appmg.exe] C:\WINDOWS\system32\appmg.exe
                  O4 - HKLM\..\RunOnce: [crsd.exe] C:\WINDOWS\system32\crsd.exe
                  O4 - HKLM\..\RunOnce: [atlmo.exe] C:\WINDOWS\system32\atlmo.exe
                  O4 - HKLM\..\RunOnce: [winbe.exe] C:\WINDOWS\system32\winbe.exe
                  O4 - HKLM\..\RunOnce: [crmw32.exe] C:\WINDOWS\crmw32.exe
                  O4 - HKLM\..\RunOnce: [msfi.exe] C:\WINDOWS\system32\msfi.exe
                  O4 - HKLM\..\RunOnce: [addjm.exe] C:\WINDOWS\system32\addjm.exe
                  O4 - HKLM\..\RunOnce: [mfcum32.exe] C:\WINDOWS\system32\mfcum32.exe
                  O4 - HKLM\..\RunOnce: [ntku.exe] C:\WINDOWS\system32\ntku.exe
                  O4 - HKLM\..\RunOnce: [d3oy32.exe] C:\WINDOWS\system32\d3oy32.exe
                  O4 - HKLM\..\RunOnce: [sdkxy.exe] C:\WINDOWS\system32\sdkxy.exe
                  O4 - HKLM\..\RunOnce: [apiqp.exe] C:\WINDOWS\apiqp.exe
                  O4 - HKLM\..\RunOnce: [addmb.exe] C:\WINDOWS\system32\addmb.exe
                  O4 - HKLM\..\RunOnce: [sdkhn.exe] C:\WINDOWS\sdkhn.exe
                  O4 - HKLM\..\RunOnce: [netwu.exe] C:\WINDOWS\netwu.exe
                  O4 - HKLM\..\RunOnce: [addgn32.exe] C:\WINDOWS\system32\addgn32.exe
                  O4 - HKLM\..\RunOnce: [atlag.exe] C:\WINDOWS\system32\atlag.exe
                  O4 - HKLM\..\RunOnce: [ipek.exe] C:\WINDOWS\ipek.exe
                  O4 - HKLM\..\RunOnce: [crod32.exe] C:\WINDOWS\system32\crod32.exe
                  O4 - HKLM\..\RunOnce: [iefk.exe] C:\WINDOWS\system32\iefk.exe
                  O4 - HKLM\..\RunOnce: [appio.exe] C:\WINDOWS\appio.exe
                  O4 - HKLM\..\RunOnce: [mfcxz32.exe] C:\WINDOWS\mfcxz32.exe
                  O4 - HKLM\..\RunOnce: [netik.exe] C:\WINDOWS\system32\netik.exe
                  O4 - HKLM\..\RunOnce: [javamo32.exe] C:\WINDOWS\system32\javamo32.exe
                  O4 - HKLM\..\RunOnce: [ipvo.exe] C:\WINDOWS\system32\ipvo.exe
                  O4 - HKLM\..\RunOnce: [ntbl32.exe] C:\WINDOWS\system32\ntbl32.exe
                  O4 - HKLM\..\RunOnce: [ipqi32.exe] C:\WINDOWS\ipqi32.exe
                  O4 - HKLM\..\RunOnce: [appue32.exe] C:\WINDOWS\system32\appue32.exe
                  O4 - HKLM\..\RunOnce: [ntxq32.exe] C:\WINDOWS\ntxq32.exe
                  O4 - HKLM\..\RunOnce: [crcu.exe] C:\WINDOWS\system32\crcu.exe
                  O4 - HKLM\..\RunOnce: [addye.exe] C:\WINDOWS\system32\addye.exe
                  O4 - HKLM\..\RunOnce: [d3ft32.exe] C:\WINDOWS\d3ft32.exe
                  O4 - HKLM\..\RunOnce: [ntvj32.exe] C:\WINDOWS\ntvj32.exe
                  O4 - HKLM\..\RunOnce: [sdkvr.exe] C:\WINDOWS\system32\sdkvr.exe
                  O4 - HKLM\..\RunOnce: [ipdr.exe] C:\WINDOWS\ipdr.exe
                  O4 - HKLM\..\RunOnce: [msto.exe] C:\WINDOWS\system32\msto.exe
                  O4 - HKLM\..\RunOnce: [javaiv32.exe] C:\WINDOWS\system32\javaiv32.exe
                  O4 - HKLM\..\RunOnce: [d3cp.exe] C:\WINDOWS\d3cp.exe
                  O4 - HKLM\..\RunOnce: [winyt32.exe] C:\WINDOWS\winyt32.exe
                  O4 - HKLM\..\RunOnce: [msht.exe] C:\WINDOWS\msht.exe
                  O4 - HKLM\..\RunOnce: [netqz.exe] C:\WINDOWS\system32\netqz.exe
                  O4 - HKLM\..\RunOnce: [sysoy.exe] C:\WINDOWS\system32\sysoy.exe
                  O4 - HKLM\..\RunOnce: [javayr.exe] C:\WINDOWS\javayr.exe
                  O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\system32\apirk32.exe
                  O4 - HKLM\..\RunOnce: [ipcv32.exe] C:\WINDOWS\system32\ipcv32.exe
                  O4 - HKLM\..\RunOnce: [addhr32.exe] C:\WINDOWS\addhr32.exe
                  O4 - HKLM\..\RunOnce: [ntkl.exe] C:\WINDOWS\system32\ntkl.exe
                  O4 - HKLM\..\RunOnce: [mfcgp.exe] C:\WINDOWS\mfcgp.exe
                  O4 - HKLM\..\RunOnce: [javade32.exe] C:\WINDOWS\system32\javade32.exe
                  O4 - HKLM\..\RunOnce: [msum.exe] C:\WINDOWS\msum.exe
                  O4 - HKLM\..\RunOnce: [appqq32.exe] C:\WINDOWS\appqq32.exe
                  O4 - HKLM\..\RunOnce: [syshy.exe] C:\WINDOWS\syshy.exe
                  O4 - HKLM\..\RunOnce: [winnn32.exe] C:\WINDOWS\winnn32.exe
                  O4 - HKLM\..\RunOnce: [sysbk32.exe] C:\WINDOWS\system32\sysbk32.exe
                  O4 - HKLM\..\RunOnce: [javagg32.exe] C:\WINDOWS\system32\javagg32.exe
                  O4 - HKLM\..\RunOnce: [winbs32.exe] C:\WINDOWS\system32\winbs32.exe
                  O4 - HKLM\..\RunOnce: [atlgw.exe] C:\WINDOWS\atlgw.exe
                  O4 - HKLM\..\RunOnce: [apppe32.exe] C:\WINDOWS\system32\apppe32.exe
                  O4 - HKLM\..\RunOnce: [adddt32.exe] C:\WINDOWS\adddt32.exe
                  O4 - HKLM\..\RunOnce: [crax32.exe] C:\WINDOWS\system32\crax32.exe
                  O4 - HKLM\..\RunOnce: [appdj32.exe] C:\WINDOWS\appdj32.exe
                  O4 - HKLM\..\RunOnce: [apiin.exe] C:\WINDOWS\system32\apiin.exe
                  O4 - HKLM\..\RunOnce: [apihe.exe] C:\WINDOWS\apihe.exe
                  O4 - HKLM\..\RunOnce: [netan.exe] C:\WINDOWS\system32\netan.exe
                  O4 - HKLM\..\RunOnce: [sdkzv.exe] C:\WINDOWS\sdkzv.exe
                  O4 - HKLM\..\RunOnce: [d3kw.exe] C:\WINDOWS\system32\d3kw.exe
                  O4 - HKLM\..\RunOnce: [netjd32.exe] C:\WINDOWS\system32\netjd32.exe
                  O4 - HKLM\..\RunOnce: [msqs32.exe] C:\WINDOWS\msqs32.exe
                  O4 - HKLM\..\RunOnce: [apixa.exe] C:\WINDOWS\apixa.exe
                  O4 - HKLM\..\RunOnce: [appte.exe] C:\WINDOWS\appte.exe
                  O4 - HKLM\..\RunOnce: [ntjt32.exe] C:\WINDOWS\system32\ntjt32.exe
                  O4 - HKLM\..\RunOnce: [crhb32.exe] C:\WINDOWS\system32\crhb32.exe
                  O4 - HKLM\..\RunOnce: [sdkcn.exe] C:\WINDOWS\sdkcn.exe
                  O4 - HKLM\..\RunOnce: [mfcbc32.exe] C:\WINDOWS\system32\mfcbc32.exe
                  O4 - HKLM\..\RunOnce: [winzs32.exe] C:\WINDOWS\winzs32.exe
                  O4 - HKLM\..\RunOnce: [winza.exe] C:\WINDOWS\winza.exe
                  O4 - HKLM\..\RunOnce: [msdj32.exe] C:\WINDOWS\msdj32.exe
                  O4 - HKLM\..\RunOnce: [crnh32.exe] C:\WINDOWS\system32\crnh32.exe
                  O4 - HKLM\..\RunOnce: [sdkwq.exe] C:\WINDOWS\system32\sdkwq.exe
                  O4 - HKLM\..\RunOnce: [sdkce32.exe] C:\WINDOWS\system32\sdkce32.exe
                  O4 - HKLM\..\RunOnce: [sdkqb32.exe] C:\WINDOWS\sdkqb32.exe
                  O4 - HKLM\..\RunOnce: [atlvx32.exe] C:\WINDOWS\system32\atlvx32.exe
                  O4 - HKLM\..\RunOnce: [javaqr32.exe] C:\WINDOWS\javaqr32.exe
                  O4 - HKLM\..\RunOnce: [sysak32.exe] C:\WINDOWS\system32\sysak32.exe
                  O4 - HKLM\..\RunOnce: [ipis.exe] C:\WINDOWS\ipis.exe
                  O4 - HKLM\..\RunOnce: [mfcew.exe] C:\WINDOWS\system32\mfcew.exe
                  O4 - HKLM\..\RunOnce: [sdktt32.exe] C:\WINDOWS\sdktt32.exe
                  O4 - HKLM\..\RunOnce: [msra.exe] C:\WINDOWS\msra.exe
                  O4 - HKLM\..\RunOnce: [addne32.exe] C:\WINDOWS\system32\addne32.exe
                  O4 - HKLM\..\RunOnce: [addif.exe] C:\WINDOWS\addif.exe
                  O4 - HKLM\..\RunOnce: [netsv32.exe] C:\WINDOWS\netsv32.exe
                  O4 - HKLM\..\RunOnce: [d3np.exe] C:\WINDOWS\d3np.exe
                  O4 - HKLM\..\RunOnce: [iptp32.exe] C:\WINDOWS\system32\iptp32.exe
                  O4 - HKLM\..\RunOnce: [sdkrt32.exe] C:\WINDOWS\system32\sdkrt32.exe
                  O4 - HKLM\..\RunOnce: [mfcpi.exe] C:\WINDOWS\mfcpi.exe
                  O4 - HKLM\..\RunOnce: [d3mw.exe] C:\WINDOWS\system32\d3mw.exe
                  O4 - HKLM\..\RunOnce: [wincl.exe] C:\WINDOWS\system32\wincl.exe
                  O4 - HKLM\..\RunOnce: [mssa32.exe] C:\WINDOWS\system32\mssa32.exe
                  O4 - HKLM\..\RunOnce: [winfc.exe] C:\WINDOWS\winfc.exe
                  O4 - HKLM\..\RunOnce: [atlyd32.exe] C:\WINDOWS\system32\atlyd32.exe
                  O4 - HKLM\..\RunOnce: [netol.exe] C:\WINDOWS\system32\netol.exe
                  O4 - HKLM\..\RunOnce: [javasp32.exe] C:\WINDOWS\system32\javasp32.exe
                  O4 - HKLM\..\RunOnce: [ntcq.exe] C:\WINDOWS\system32\ntcq.exe
                  O4 - HKLM\..\RunOnce: [ntim32.exe] C:\WINDOWS\system32\ntim32.exe
                  O4 - HKLM\..\RunOnce: [ntwj32.exe] C:\WINDOWS\ntwj32.exe
                  O4 - HKLM\..\RunOnce: [appbf32.exe] C:\WINDOWS\system32\appbf32.exe
                  O4 - HKLM\..\RunOnce: [atlbt32.exe] C:\WINDOWS\system32\atlbt32.exe
                  O4 - HKLM\..\RunOnce: [mfcsp32.exe] C:\WINDOWS\system32\mfcsp32.exe
                  O4 - HKLM\..\RunOnce: [d3sp.exe] C:\WINDOWS\d3sp.exe
                  O4 - HKLM\..\RunOnce: [sdkwb.exe] C:\WINDOWS\system32\sdkwb.exe
                  O4 - HKLM\..\RunOnce: [ielq32.exe] C:\WINDOWS\ielq32.exe
                  O4 - HKLM\..\RunOnce: [d3pa.exe] C:\WINDOWS\system32\d3pa.exe
                  O4 - HKLM\..\RunOnce: [ntzt32.exe] C:\WINDOWS\ntzt32.exe
                  O4 - HKLM\..\RunOnce: [sdkle.exe] C:\WINDOWS\sdkle.exe
                  O4 - HKLM\..\RunOnce: [mspi.exe] C:\WINDOWS\system32\mspi.exe
                  O4 - HKLM\..\RunOnce: [mfcxq.exe] C:\WINDOWS\mfcxq.exe
                  O4 - HKLM\..\RunOnce: [sdktu.exe] C:\WINDOWS\system32\sdktu.exe
                  O4 - HKLM\..\RunOnce: [iege32.exe] C:\WINDOWS\system32\iege32.exe
                  O4 - HKLM\..\RunOnce: [javawu32.exe] C:\WINDOWS\javawu32.exe
                  O4 - HKLM\..\RunOnce: [sysuz32.exe] C:\WINDOWS\sysuz32.exe
                  O4 - HKLM\..\RunOnce: [appsh32.exe] C:\WINDOWS\appsh32.exe
                  O4 - HKLM\..\RunOnce: [winnk.exe] C:\WINDOWS\winnk.exe
                  O4 - HKLM\..\RunOnce: [ieju.exe] C:\WINDOWS\system32\ieju.exe
                  O4 - HKLM\..\RunOnce: [atlnq32.exe] C:\WINDOWS\system32\atlnq32.exe
                  O4 - HKLM\..\RunOnce: [winwy.exe] C:\WINDOWS\system32\winwy.exe
                  O4 - HKLM\..\RunOnce: [ipfz.exe] C:\WINDOWS\system32\ipfz.exe
                  O4 - HKLM\..\RunOnce: [syszk.exe] C:\WINDOWS\system32\syszk.exe
                  O4 - HKLM\..\RunOnce: [d3pz.exe] C:\WINDOWS\d3pz.exe
                  O4 - HKLM\..\RunOnce: [ipzs32.exe] C:\WINDOWS\ipzs32.exe
                  O4 - HKLM\..\RunOnce: [winnv32.exe] C:\WINDOWS\winnv32.exe
                  O4 - HKLM\..\RunOnce: [winus.exe] C:\WINDOWS\system32\winus.exe
                  O4 - HKLM\..\RunOnce: [winhg.exe] C:\WINDOWS\system32\winhg.exe
                  O4 - HKLM\..\RunOnce: [javanl.exe] C:\WINDOWS\javanl.exe
                  O4 - HKLM\..\RunOnce: [addhw.exe] C:\WINDOWS\system32\addhw.exe
                  O4 - HKLM\..\RunOnce: [sysxd.exe] C:\WINDOWS\system32\sysxd.exe
                  O4 - HKLM\..\RunOnce: [atlvz32.exe] C:\WINDOWS\system32\atlvz32.exe
                  O4 - HKLM\..\RunOnce: [appkv32.exe] C:\WINDOWS\appkv32.exe
                  O4 - HKLM\..\RunOnce: [msps32.exe] C:\WINDOWS\msps32.exe
                  O4 - HKLM\..\RunOnce: [atlkd32.exe] C:\WINDOWS\atlkd32.exe
                  O4 - HKLM\..\RunOnce: [netoi.exe] C:\WINDOWS\system32\netoi.exe
                  O4 - HKLM\..\RunOnce: [apixi32.exe] C:\WINDOWS\apixi32.exe
                  O4 - HKLM\..\RunOnce: [mfcmf32.exe] C:\WINDOWS\system32\mfcmf32.exe
                  O4 - HKLM\..\RunOnce: [netll.exe] C:\WINDOWS\netll.exe
                  O4 - HKLM\..\RunOnce: [syslt32.exe] C:\WINDOWS\system32\syslt32.exe
                  O4 - HKLM\..\RunOnce: [winem.exe] C:\WINDOWS\winem.exe
                  O4 - HKLM\..\RunOnce: [nttj32.exe] C:\WINDOWS\nttj32.exe
                  O4 - HKLM\..\RunOnce: [d3jq.exe] C:\WINDOWS\d3jq.exe
                  O4 - HKLM\..\RunOnce: [ntid.exe] C:\WINDOWS\system32\ntid.exe
                  O4 - HKLM\..\RunOnce: [d3eh.exe] C:\WINDOWS\system32\d3eh.exe
                  O4 - HKLM\..\RunOnce: [syswi32.exe] C:\WINDOWS\system32\syswi32.exe
                  O4 - HKLM\..\RunOnce: [ipqu32.exe] C:\WINDOWS\system32\ipqu32.exe
                  O4 - HKLM\..\RunOnce: [apigr32.exe] C:\WINDOWS\system32\apigr32.exe
                  O4 - HKLM\..\RunOnce: [d3px.exe] C:\WINDOWS\system32\d3px.exe
                  O4 - HKLM\..\RunOnce: [appem32.exe] C:\WINDOWS\appem32.exe
                  O4 - HKLM\..\RunOnce: [apidt.exe] C:\WINDOWS\apidt.exe
                  O4 - HKLM\..\RunOnce: [ipiy.exe] C:\WINDOWS\system32\ipiy.exe
                  O4 - HKLM\..\RunOnce: [ntwv32.exe] C:\WINDOWS\system32\ntwv32.exe
                  O4 - HKLM\..\RunOnce: [ipcs32.exe] C:\WINDOWS\ipcs32.exe
                  O4 - HKLM\..\RunOnce: [appho32.exe] C:\WINDOWS\appho32.exe
                  O4 - HKLM\..\RunOnce: [atlvq.exe] C:\WINDOWS\system32\atlvq.exe
                  O4 - HKLM\..\RunOnce: [ntzu32.exe] C:\WINDOWS\system32\ntzu32.exe
                  O4 - HKLM\..\RunOnce: [sdker32.exe] C:\WINDOWS\sdker32.exe
                  O4 - HKLM\..\RunOnce: [netgu.exe] C:\WINDOWS\system32\netgu.exe
                  O4 - HKLM\..\RunOnce: [ipcm.exe] C:\WINDOWS\ipcm.exe
                  O4 - HKLM\..\RunOnce: [d3ni32.exe] C:\WINDOWS\system32\d3ni32.exe
                  O4 - HKLM\..\RunOnce: [crvj32.exe] C:\WINDOWS\crvj32.exe
                  O4 - HKLM\..\RunOnce: [mspu.exe] C:\WINDOWS\mspu.exe
                  O4 - HKLM\..\RunOnce: [crzi32.exe] C:\WINDOWS\crzi32.exe
                  O4 - HKLM\..\RunOnce: [d3sb32.exe] C:\WINDOWS\d3sb32.exe
                  O4 - HKLM\..\RunOnce: [ipxy32.exe] C:\WINDOWS\system32\ipxy32.exe
                  O4 - HKLM\..\RunOnce: [winzf32.exe] C:\WINDOWS\system32\winzf32.exe
                  O4 - HKLM\..\RunOnce: [mfcqn.exe] C:\WINDOWS\system32\mfcqn.exe
                  O4 - HKLM\..\RunOnce: [ntur32.exe] C:\WINDOWS\ntur32.exe
                  O4 - HKLM\..\RunOnce: [apidr.exe] C:\WINDOWS\system32\apidr.exe
                  O4 - HKLM\..\RunOnce: [netjo32.exe] C:\WINDOWS\netjo32.exe
                  O4 - HKLM\..\RunOnce: [apixl32.exe] C:\WINDOWS\system32\apixl32.exe
                  O4 - HKLM\..\RunOnce: [winch32.exe] C:\WINDOWS\system32\winch32.exe
                  O4 - HKLM\..\RunOnce: [ieac32.exe] C:\WINDOWS\system32\ieac32.exe
                  O4 - HKLM\..\RunOnce: [appqj.exe] C:\WINDOWS\system32\appqj.exe
                  O4 - HKLM\..\RunOnce: [netmn32.exe] C:\WINDOWS\netmn32.exe
                  O4 - HKLM\..\RunOnce: [atleo.exe] C:\WINDOWS\system32\atleo.exe
                  O4 - HKLM\..\RunOnce: [mfcjk32.exe] C:\WINDOWS\mfcjk32.exe
                  O4 - HKLM\..\RunOnce: [atlyh32.exe] C:\WINDOWS\system32\atlyh32.exe
                  O4 - HKLM\..\RunOnce: [iede32.exe] C:\WINDOWS\system32\iede32.exe
                  O4 - HKLM\..\RunOnce: [mfcyp32.exe] C:\WINDOWS\system32\mfcyp32.exe
                  O4 - HKLM\..\RunOnce: [addmm32.exe] C:\WINDOWS\addmm32.exe
                  O4 - HKLM\..\RunOnce: [d3ri32.exe] C:\WINDOWS\system32\d3ri32.exe
                  O4 - HKLM\..\RunOnce: [appuu.exe] C:\WINDOWS\appuu.exe
                  O4 - HKLM\..\RunOnce: [sysqg32.exe] C:\WINDOWS\system32\sysqg32.exe
                  O4 - HKLM\..\RunOnce: [apind32.exe] C:\WINDOWS\apind32.exe
                  O4 - HKLM\..\RunOnce: [javadl32.exe] C:\WINDOWS\javadl32.exe
                  O4 - HKLM\..\RunOnce: [ntpt32.exe] C:\WINDOWS\ntpt32.exe
                  O4 - HKLM\..\RunOnce: [crfb32.exe] C:\WINDOWS\system32\crfb32.exe
                  O4 - HKLM\..\RunOnce: [sdkif.exe] C:\WINDOWS\system32\sdkif.exe
                  O4 - HKLM\..\RunOnce: [mfchu32.exe] C:\WINDOWS\system32\mfchu32.exe
                  O4 - HKLM\..\RunOnce: [winyk.exe] C:\WINDOWS\winyk.exe
                  O4 - HKLM\..\RunOnce: [addva.exe] C:\WINDOWS\addva.exe
                  O4 - HKLM\..\RunOnce: [cror32.exe] C:\WINDOWS\system32\cror32.exe
                  O4 - HKLM\..\RunOnce: [nettn32.exe] C:\WINDOWS\nettn32.exe
                  O4 - HKLM\..\RunOnce: [d3oz32.exe] C:\WINDOWS\system32\d3oz32.exe
                  O4 - HKLM\..\RunOnce: [systd.exe] C:\WINDOWS\system32\systd.exe
                  O4 - HKLM\..\RunOnce: [mscd32.exe] C:\WINDOWS\system32\mscd32.exe
                  O4 - HKLM\..\RunOnce: [ipvc.exe] C:\WINDOWS\system32\ipvc.exe
                  O4 - HKLM\..\RunOnce: [sysqo.exe] C:\WINDOWS\sysqo.exe
                  O4 - HKLM\..\RunOnce: [d3fv.exe] C:\WINDOWS\d3fv.exe
                  O4 - HKLM\..\RunOnce: [sdkjh.exe] C:\WINDOWS\system32\sdkjh.exe
                  O4 - HKLM\..\RunOnce: [mskw32.exe] C:\WINDOWS\system32\mskw32.exe
                  O4 - HKLM\..\RunOnce: [mfcrt32.exe] C:\WINDOWS\system32\mfcrt32.exe
                  O4 - HKLM\..\RunOnce: [d3rt.exe] C:\WINDOWS\d3rt.exe
                  O4 - HKLM\..\RunOnce: [sdkvf.exe] C:\WINDOWS\sdkvf.exe
                  O4 - HKLM\..\RunOnce: [sysku32.exe] C:\WINDOWS\system32\sysku32.exe
                  O4 - HKLM\..\RunOnce: [windn.exe] C:\WINDOWS\system32\windn.exe
                  O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\iehp.exe
                  O4 - HKLM\..\RunOnce: [appdt32.exe] C:\WINDOWS\appdt32.exe
                  O4 - HKLM\..\RunOnce: [sdkqr.exe] C:\WINDOWS\sdkqr.exe
                  O4 - HKLM\..\RunOnce: [javayp.exe] C:\WINDOWS\system32\javayp.exe
                  O4 - HKLM\..\RunOnce: [winrl.exe] C:\WINDOWS\winrl.exe
                  O4 - HKLM\..\RunOnce: [winrz.exe] C:\WINDOWS\winrz.exe
                  O4 - HKLM\..\RunOnce: [ntlk.exe] C:\WINDOWS\ntlk.exe
                  O4 - HKLM\..\RunOnce: [apibs.exe] C:\WINDOWS\apibs.exe
                  O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe
                  O4 - HKLM\..\RunOnce: [crhv32.exe] C:\WINDOWS\crhv32.exe
                  O4 - HKLM\..\RunOnce: [iexc32.exe] C:\WINDOWS\iexc32.exe
                  O4 - HKLM\..\RunOnce: [javawq.exe] C:\WINDOWS\system32\javawq.exe
                  O4 - HKLM\..\RunOnce: [d3bu.exe] C:\WINDOWS\system32\d3bu.exe
                  O4 - HKLM\..\RunOnce: [d3pr32.exe] C:\WINDOWS\d3pr32.exe
                  O4 - HKLM\..\RunOnce: [javaqt32.exe] C:\WINDOWS\system32\javaqt32.exe
                  O4 - HKLM\..\RunOnce: [crkn.exe] C:\WINDOWS\crkn.exe
                  O4 - HKLM\..\RunOnce: [netjc32.exe] C:\WINDOWS\netjc32.exe
                  O4 - HKLM\..\RunOnce: [apphk32.exe] C:\WINDOWS\system32\apphk32.exe
                  O4 - HKLM\..\RunOnce: [appha32.exe] C:\WINDOWS\system32\appha32.exe
                  O4 - HKLM\..\RunOnce: [ipqs32.exe] C:\WINDOWS\system32\ipqs32.exe
                  O4 - HKLM\..\RunOnce: [winqa32.exe] C:\WINDOWS\winqa32.exe
                  O4 - HKLM\..\RunOnce: [winqz32.exe] C:\WINDOWS\winqz32.exe
                  O4 - HKLM\..\RunOnce: [ntpw32.exe] C:\WINDOWS\ntpw32.exe
                  O4 - HKLM\..\RunOnce: [winly.exe] C:\WINDOWS\winly.exe
                  O4 - HKLM\..\RunOnce: [addrv32.exe] C:\WINDOWS\system32\addrv32.exe
                  O4 - HKLM\..\RunOnce: [wings32.exe] C:\WINDOWS\wings32.exe
                  O4 - HKLM\..\RunOnce: [crko32.exe] C:\WINDOWS\crko32.exe
                  O4 - HKLM\..\RunOnce: [addfa32.exe] C:\WINDOWS\addfa32.exe
                  O4 - HKLM\..\RunOnce: [d3nn32.exe] C:\WINDOWS\d3nn32.exe
                  O4 - HKLM\..\RunOnce: [netyh32.exe] C:\WINDOWS\system32\netyh32.exe
                  O4 - HKLM\..\RunOnce: [ipgx.exe] C:\WINDOWS\system32\ipgx.exe
                  O4 - HKLM\..\RunOnce: [apihx.exe] C:\WINDOWS\apihx.exe
                  O4 - HKLM\..\RunOnce: [crwm32.exe] C:\WINDOWS\system32\crwm32.exe
                  O4 - HKLM\..\RunOnce: [sysut.exe] C:\WINDOWS\system32\sysut.exe
                  O4 - HKLM\..\RunOnce: [atlqx32.exe] C:\WINDOWS\system32\atlqx32.exe
                  O4 - HKLM\..\RunOnce: [winay.exe] C:\WINDOWS\system32\winay.exe
                  O4 - HKLM\..\RunOnce: [sdkie32.exe] C:\WINDOWS\sdkie32.exe
                  O4 - HKLM\..\RunOnce: [mshb.exe] C:\WINDOWS\mshb.exe
                  O4 - HKLM\..\RunOnce: [netmy32.exe] C:\WINDOWS\system32\netmy32.exe
                  O4 - HKLM\..\RunOnce: [ipgr32.exe] C:\WINDOWS\ipgr32.exe
                  O4 - HKLM\..\RunOnce: [appkn32.exe] C:\WINDOWS\appkn32.exe
                  O4 - HKLM\..\RunOnce: [atluh32.exe] C:\WINDOWS\atluh32.exe
                  O4 - HKLM\..\RunOnce: [ipkg.exe] C:\WINDOWS\system32\ipkg.exe
                  O4 - HKLM\..\RunOnce: [appjw32.exe] C:\WINDOWS\system32\appjw32.exe
                  O4 - HKLM\..\RunOnce: [atljm32.exe] C:\WINDOWS\system32\atljm32.exe
                  O4 - HKLM\..\RunOnce: [iphb32.exe] C:\WINDOWS\system32\iphb32.exe
                  O4 - HKLM\..\RunOnce: [javamf.exe] C:\WINDOWS\javamf.exe
                  O4 - HKLM\..\RunOnce: [sdkvg32.exe] C:\WINDOWS\system32\sdkvg32.exe
                  O4 - HKLM\..\RunOnce: [nettj32.exe] C:\WINDOWS\nettj32.exe
                  O4 - HKLM\..\RunOnce: [sdkjr.exe] C:\WINDOWS\sdkjr.exe
                  O4 - HKLM\..\RunOnce: [msnn32.exe] C:\WINDOWS\msnn32.exe
                  O4 - HKLM\..\RunOnce: [iequ32.exe] C:\WINDOWS\system32\iequ32.exe
                  O4 - HKLM\..\RunOnce: [sysqc.exe] C:\WINDOWS\system32\sysqc.exe
                  O4 - HKLM\..\RunOnce: [ierc.exe] C:\WINDOWS\ierc.exe
                  O4 - HKLM\..\RunOnce: [atlor.exe] C:\WINDOWS\system32\atlor.exe
                  O4 - HKLM\..\RunOnce: [adddg32.exe] C:\WINDOWS\system32\adddg32.exe
                  O4 - HKLM\..\RunOnce: [apppa.exe] C:\WINDOWS\apppa.exe
                  O4 - HKLM\..\RunOnce: [nettw32.exe] C:\WINDOWS\nettw32.exe
                  O4 - HKLM\..\RunOnce: [mfcce.exe] C:\WINDOWS\mfcce.exe
                  O4 - HKLM\..\RunOnce: [mfcit32.exe] C:\WINDOWS\mfcit32.exe
                  O4 - HKLM\..\RunOnce: [addgw32.exe] C:\WINDOWS\system32\addgw32.exe
                  O4 - HKLM\..\RunOnce: [apifd.exe] C:\WINDOWS\system32\apifd.exe
                  O4 - HKLM\..\RunOnce: [sdkbh32.exe] C:\WINDOWS\sdkbh32.exe
                  O4 - HKLM\..\RunOnce: [netki.exe] C:\WINDOWS\system32\netki.exe
                  O4 - HKLM\..\RunOnce: [ipyf32.exe] C:\WINDOWS\ipyf32.exe
                  O4 - HKLM\..\RunOnce: [mszh.exe] C:\WINDOWS\mszh.exe
                  O4 - HKLM\..\RunOnce: [mfcqo32.exe] C:\WINDOWS\mfcqo32.exe
                  O4 - HKLM\..\RunOnce: [javaft32.exe] C:\WINDOWS\system32\javaft32.exe
                  O4 - HKLM\..\RunOnce: [netdi32.exe] C:\WINDOWS\netdi32.exe
                  O4 - HKLM\..\RunOnce: [apifr.exe] C:\WINDOWS\apifr.exe
                  O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
                  O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
                  O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                  O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                  O4 - HKCU\..\Run: [MessengerPlus3] "\" /WinStart
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
                  O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                  O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                  O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                  O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
                  O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                  O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                  O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\mfcmp32.exe" /s (file missing)
                  O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                  O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
                  O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
                  O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                  O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                  O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
                  O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                  O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                  O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                  0
                  1. LOG DE SMITFRAUDFIX :
                    SmitFraudFix v1.84

                    Rapport fait à 1:25:41,07 le 18/09/2005
                    Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600]

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32\LogFiles

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Propri‚taire\Application Data

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Propri‚taire\Bureau

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de la clé HKLM\SOFTWARE\SHUDDERLTD

                    HKLM\SOFTWARE\SHUDDERLTD non trouvé.

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
                    0
                    1. Bonjour,

                      Méthode à suivre dans l'ordre...
                      ----------------------------------------------------------------------------
                      ¤Télécharge ces logiciels mais que tu n‘utilises pas tout de suite:

                      1/Spybot S&D 1.4 <<nouvelle version
                      http://www.safer-networking.org/fr/index.html

                      Démo d’utilisation (merci à Balltrap34 pour cette réalisation)
                      http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

                      2/Ad-Aware SE 1.06 <<nouvelle version
                      http://www.lavasoftusa.com/software/adaware/
                      -Une aide:
                      http://www.tutopat.com/viewtopic.php?t=1191
                      - installe le patch français, tu pourras le trouver ici:
                      http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
                      et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation)
                      http://pageperso.aol.fr/balltrap34/adawrevid.asf

                      3/Clean Up 40:
                      http://pageperso.aol.fr/balltrap34/CleanUp40.exe
                      -aide en image:(merci à Balltrap34)
                      http://pageperso.aol.fr/balltrap34/democleanup.htm

                      4/about buster:
                      http://www.majorgeeks.com/download4289.html

                      Clique "Check for updates".
                      Télécharge les mises à jour
                      referme le
                      on l‘utilisera plus tard.

                      5/A2 Free (anti-trojans et worms)
                      http://www.emsisoft.net/fr/software/download/

                      ----------------------------------------------------------------------------
                      ¤Démarre en mode sans échec :
                      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                      (Si F8 ne marche pas utilise la touche F5)
                      ----------------------------------------------------------------------------
                      ¤Désactive ta restauration système (uniquement si tu es sous XP):
                      Clic droit sur poste de travail puis,
                      propriété, tu cliques sur onglet restauration système
                      tu coches la case « désactiver la restauration » et applique
                      ----------------------------------------------------------------------------
                      ¤Affiche tous les fichiers et dossiers :
                      Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

                      Coche « afficher les fichiers et dossiers cachés »

                      Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                      Décoche « masquer les extensions dont le type est connu »
                      Puis fais «Ok» pour valider les changements.

                      Et appliquer !
                      ----------------------------------------------------------------------------
                      ¤Vide tes fichiers temps et tempory internet file:
                      utilise ceci pour le faire (tu as téléchargé avant)
                      http://pageperso.aol.fr/balltrap34/CleanUp40.exe
                      ----------------------------------------------------------------------------
                      ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\acams.dll/sp.html#37049

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\acams.dll/sp.html#37049

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\acams.dll/sp.html#37049

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\acams.dll/sp.html#37049

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\acams.dll/sp.html#37049

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\acams.dll/sp.html#37049

                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\acams.dll/sp.html#37049

                      R3 - Default URLSearchHook is missing

                      O2 - BHO: Class - {BFBFA424-9910-08B0-2FBF-CC5180D847C2} - C:\WINDOWS\system32\sysrz.dll

                      O4 - HKLM\..\Run: [sysrz.exe] C:\WINDOWS\system32\sysrz.exe
                      O4 - HKLM\..\RunOnce: [mfcmp32.exe] C:\WINDOWS\system32\mfcmp32.exe
                      O4 - HKLM\..\RunOnce: [msfu.exe] C:\WINDOWS\msfu.exe
                      O4 - HKLM\..\RunOnce: [sysuq32.exe] C:\WINDOWS\sysuq32.exe
                      O4 - HKLM\..\RunOnce: [addvu32.exe] C:\WINDOWS\system32\addvu32.exe
                      O4 - HKLM\..\RunOnce: [d3aw.exe] C:\WINDOWS\system32\d3aw.exe
                      O4 - HKLM\..\RunOnce: [javaxt.exe] C:\WINDOWS\system32\javaxt.exe
                      O4 - HKLM\..\RunOnce: [mfcdn.exe] C:\WINDOWS\system32\mfcdn.exe
                      O4 - HKLM\..\RunOnce: [appmo32.exe] C:\WINDOWS\system32\appmo32.exe
                      O4 - HKLM\..\RunOnce: [d3sq.exe] C:\WINDOWS\system32\d3sq.exe
                      O4 - HKLM\..\RunOnce: [mfcmb.exe] C:\WINDOWS\mfcmb.exe
                      O4 - HKLM\..\RunOnce: [ierw32.exe] C:\WINDOWS\ierw32.exe
                      O4 - HKLM\..\RunOnce: [apppd32.exe] C:\WINDOWS\system32\apppd32.exe
                      O4 - HKLM\..\RunOnce: [ntpf32.exe] C:\WINDOWS\system32\ntpf32.exe
                      O4 - HKLM\..\RunOnce: [ntfy32.exe] C:\WINDOWS\ntfy32.exe
                      O4 - HKLM\..\RunOnce: [appls.exe] C:\WINDOWS\appls.exe
                      O4 - HKLM\..\RunOnce: [javacw32.exe] C:\WINDOWS\system32\javacw32.exe
                      O4 - HKLM\..\RunOnce: [ntmw.exe] C:\WINDOWS\system32\ntmw.exe
                      O4 - HKLM\..\RunOnce: [sdkst.exe] C:\WINDOWS\system32\sdkst.exe
                      O4 - HKLM\..\RunOnce: [appfy.exe] C:\WINDOWS\appfy.exe
                      O4 - HKLM\..\RunOnce: [sdkaj.exe] C:\WINDOWS\system32\sdkaj.exe
                      O4 - HKLM\..\RunOnce: [ippq.exe] C:\WINDOWS\system32\ippq.exe
                      O4 - HKLM\..\RunOnce: [appzj32.exe] C:\WINDOWS\appzj32.exe
                      O4 - HKLM\..\RunOnce: [atllc.exe] C:\WINDOWS\atllc.exe
                      O4 - HKLM\..\RunOnce: [appmw32.exe] C:\WINDOWS\appmw32.exe
                      O4 - HKLM\..\RunOnce: [winkr.exe] C:\WINDOWS\winkr.exe
                      O4 - HKLM\..\RunOnce: [javabz32.exe] C:\WINDOWS\javabz32.exe
                      O4 - HKLM\..\RunOnce: [addpo.exe] C:\WINDOWS\system32\addpo.exe
                      O4 - HKLM\..\RunOnce: [atlov.exe] C:\WINDOWS\atlov.exe
                      O4 - HKLM\..\RunOnce: [netzw.exe] C:\WINDOWS\system32\netzw.exe
                      O4 - HKLM\..\RunOnce: [winyw32.exe] C:\WINDOWS\system32\winyw32.exe
                      O4 - HKLM\..\RunOnce: [appsn32.exe] C:\WINDOWS\appsn32.exe
                      O4 - HKLM\..\RunOnce: [addgk.exe] C:\WINDOWS\system32\addgk.exe
                      O4 - HKLM\..\RunOnce: [appmg.exe] C:\WINDOWS\system32\appmg.exe
                      O4 - HKLM\..\RunOnce: [crsd.exe] C:\WINDOWS\system32\crsd.exe
                      O4 - HKLM\..\RunOnce: [atlmo.exe] C:\WINDOWS\system32\atlmo.exe
                      O4 - HKLM\..\RunOnce: [winbe.exe] C:\WINDOWS\system32\winbe.exe
                      O4 - HKLM\..\RunOnce: [crmw32.exe] C:\WINDOWS\crmw32.exe
                      O4 - HKLM\..\RunOnce: [msfi.exe] C:\WINDOWS\system32\msfi.exe
                      O4 - HKLM\..\RunOnce: [addjm.exe] C:\WINDOWS\system32\addjm.exe
                      O4 - HKLM\..\RunOnce: [mfcum32.exe] C:\WINDOWS\system32\mfcum32.exe
                      O4 - HKLM\..\RunOnce: [ntku.exe] C:\WINDOWS\system32\ntku.exe
                      O4 - HKLM\..\RunOnce: [d3oy32.exe] C:\WINDOWS\system32\d3oy32.exe
                      O4 - HKLM\..\RunOnce: [sdkxy.exe] C:\WINDOWS\system32\sdkxy.exe
                      O4 - HKLM\..\RunOnce: [apiqp.exe] C:\WINDOWS\apiqp.exe
                      O4 - HKLM\..\RunOnce: [addmb.exe] C:\WINDOWS\system32\addmb.exe
                      O4 - HKLM\..\RunOnce: [sdkhn.exe] C:\WINDOWS\sdkhn.exe
                      O4 - HKLM\..\RunOnce: [netwu.exe] C:\WINDOWS\netwu.exe
                      O4 - HKLM\..\RunOnce: [addgn32.exe] C:\WINDOWS\system32\addgn32.exe
                      O4 - HKLM\..\RunOnce: [atlag.exe] C:\WINDOWS\system32\atlag.exe
                      O4 - HKLM\..\RunOnce: [ipek.exe] C:\WINDOWS\ipek.exe
                      O4 - HKLM\..\RunOnce: [crod32.exe] C:\WINDOWS\system32\crod32.exe
                      O4 - HKLM\..\RunOnce: [iefk.exe] C:\WINDOWS\system32\iefk.exe
                      O4 - HKLM\..\RunOnce: [appio.exe] C:\WINDOWS\appio.exe
                      O4 - HKLM\..\RunOnce: [mfcxz32.exe] C:\WINDOWS\mfcxz32.exe
                      O4 - HKLM\..\RunOnce: [netik.exe] C:\WINDOWS\system32\netik.exe
                      O4 - HKLM\..\RunOnce: [javamo32.exe] C:\WINDOWS\system32\javamo32.exe
                      O4 - HKLM\..\RunOnce: [ipvo.exe] C:\WINDOWS\system32\ipvo.exe
                      O4 - HKLM\..\RunOnce: [ntbl32.exe] C:\WINDOWS\system32\ntbl32.exe
                      O4 - HKLM\..\RunOnce: [ipqi32.exe] C:\WINDOWS\ipqi32.exe
                      O4 - HKLM\..\RunOnce: [appue32.exe] C:\WINDOWS\system32\appue32.exe
                      O4 - HKLM\..\RunOnce: [ntxq32.exe] C:\WINDOWS\ntxq32.exe
                      O4 - HKLM\..\RunOnce: [crcu.exe] C:\WINDOWS\system32\crcu.exe
                      O4 - HKLM\..\RunOnce: [addye.exe] C:\WINDOWS\system32\addye.exe
                      O4 - HKLM\..\RunOnce: [d3ft32.exe] C:\WINDOWS\d3ft32.exe
                      O4 - HKLM\..\RunOnce: [ntvj32.exe] C:\WINDOWS\ntvj32.exe
                      O4 - HKLM\..\RunOnce: [sdkvr.exe] C:\WINDOWS\system32\sdkvr.exe
                      O4 - HKLM\..\RunOnce: [ipdr.exe] C:\WINDOWS\ipdr.exe
                      O4 - HKLM\..\RunOnce: [msto.exe] C:\WINDOWS\system32\msto.exe
                      O4 - HKLM\..\RunOnce: [javaiv32.exe] C:\WINDOWS\system32\javaiv32.exe
                      O4 - HKLM\..\RunOnce: [d3cp.exe] C:\WINDOWS\d3cp.exe
                      O4 - HKLM\..\RunOnce: [winyt32.exe] C:\WINDOWS\winyt32.exe
                      O4 - HKLM\..\RunOnce: [msht.exe] C:\WINDOWS\msht.exe
                      O4 - HKLM\..\RunOnce: [netqz.exe] C:\WINDOWS\system32\netqz.exe
                      O4 - HKLM\..\RunOnce: [sysoy.exe] C:\WINDOWS\system32\sysoy.exe
                      O4 - HKLM\..\RunOnce: [javayr.exe] C:\WINDOWS\javayr.exe
                      O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\system32\apirk32.exe
                      O4 - HKLM\..\RunOnce: [ipcv32.exe] C:\WINDOWS\system32\ipcv32.exe
                      O4 - HKLM\..\RunOnce: [addhr32.exe] C:\WINDOWS\addhr32.exe
                      O4 - HKLM\..\RunOnce: [ntkl.exe] C:\WINDOWS\system32\ntkl.exe
                      O4 - HKLM\..\RunOnce: [mfcgp.exe] C:\WINDOWS\mfcgp.exe
                      O4 - HKLM\..\RunOnce: [javade32.exe] C:\WINDOWS\system32\javade32.exe
                      O4 - HKLM\..\RunOnce: [msum.exe] C:\WINDOWS\msum.exe
                      O4 - HKLM\..\RunOnce: [appqq32.exe] C:\WINDOWS\appqq32.exe
                      O4 - HKLM\..\RunOnce: [syshy.exe] C:\WINDOWS\syshy.exe
                      O4 - HKLM\..\RunOnce: [winnn32.exe] C:\WINDOWS\winnn32.exe
                      O4 - HKLM\..\RunOnce: [sysbk32.exe] C:\WINDOWS\system32\sysbk32.exe
                      O4 - HKLM\..\RunOnce: [javagg32.exe] C:\WINDOWS\system32\javagg32.exe
                      O4 - HKLM\..\RunOnce: [winbs32.exe] C:\WINDOWS\system32\winbs32.exe
                      O4 - HKLM\..\RunOnce: [atlgw.exe] C:\WINDOWS\atlgw.exe
                      O4 - HKLM\..\RunOnce: [apppe32.exe] C:\WINDOWS\system32\apppe32.exe
                      O4 - HKLM\..\RunOnce: [adddt32.exe] C:\WINDOWS\adddt32.exe
                      O4 - HKLM\..\RunOnce: [crax32.exe] C:\WINDOWS\system32\crax32.exe
                      O4 - HKLM\..\RunOnce: [appdj32.exe] C:\WINDOWS\appdj32.exe
                      O4 - HKLM\..\RunOnce: [apiin.exe] C:\WINDOWS\system32\apiin.exe
                      O4 - HKLM\..\RunOnce: [apihe.exe] C:\WINDOWS\apihe.exe
                      O4 - HKLM\..\RunOnce: [netan.exe] C:\WINDOWS\system32\netan.exe
                      O4 - HKLM\..\RunOnce: [sdkzv.exe] C:\WINDOWS\sdkzv.exe
                      O4 - HKLM\..\RunOnce: [d3kw.exe] C:\WINDOWS\system32\d3kw.exe
                      O4 - HKLM\..\RunOnce: [netjd32.exe] C:\WINDOWS\system32\netjd32.exe
                      O4 - HKLM\..\RunOnce: [msqs32.exe] C:\WINDOWS\msqs32.exe
                      O4 - HKLM\..\RunOnce: [apixa.exe] C:\WINDOWS\apixa.exe
                      O4 - HKLM\..\RunOnce: [appte.exe] C:\WINDOWS\appte.exe
                      O4 - HKLM\..\RunOnce: [ntjt32.exe] C:\WINDOWS\system32\ntjt32.exe
                      O4 - HKLM\..\RunOnce: [crhb32.exe] C:\WINDOWS\system32\crhb32.exe
                      O4 - HKLM\..\RunOnce: [sdkcn.exe] C:\WINDOWS\sdkcn.exe
                      O4 - HKLM\..\RunOnce: [mfcbc32.exe] C:\WINDOWS\system32\mfcbc32.exe
                      O4 - HKLM\..\RunOnce: [winzs32.exe] C:\WINDOWS\winzs32.exe
                      O4 - HKLM\..\RunOnce: [winza.exe] C:\WINDOWS\winza.exe
                      O4 - HKLM\..\RunOnce: [msdj32.exe] C:\WINDOWS\msdj32.exe
                      O4 - HKLM\..\RunOnce: [crnh32.exe] C:\WINDOWS\system32\crnh32.exe
                      O4 - HKLM\..\RunOnce: [sdkwq.exe] C:\WINDOWS\system32\sdkwq.exe
                      O4 - HKLM\..\RunOnce: [sdkce32.exe] C:\WINDOWS\system32\sdkce32.exe
                      O4 - HKLM\..\RunOnce: [sdkqb32.exe] C:\WINDOWS\sdkqb32.exe
                      O4 - HKLM\..\RunOnce: [atlvx32.exe] C:\WINDOWS\system32\atlvx32.exe
                      O4 - HKLM\..\RunOnce: [javaqr32.exe] C:\WINDOWS\javaqr32.exe
                      O4 - HKLM\..\RunOnce: [sysak32.exe] C:\WINDOWS\system32\sysak32.exe
                      O4 - HKLM\..\RunOnce: [ipis.exe] C:\WINDOWS\ipis.exe
                      O4 - HKLM\..\RunOnce: [mfcew.exe] C:\WINDOWS\system32\mfcew.exe
                      O4 - HKLM\..\RunOnce: [sdktt32.exe] C:\WINDOWS\sdktt32.exe
                      O4 - HKLM\..\RunOnce: [msra.exe] C:\WINDOWS\msra.exe
                      O4 - HKLM\..\RunOnce: [addne32.exe] C:\WINDOWS\system32\addne32.exe
                      O4 - HKLM\..\RunOnce: [addif.exe] C:\WINDOWS\addif.exe
                      O4 - HKLM\..\RunOnce: [netsv32.exe] C:\WINDOWS\netsv32.exe
                      O4 - HKLM\..\RunOnce: [d3np.exe] C:\WINDOWS\d3np.exe
                      O4 - HKLM\..\RunOnce: [iptp32.exe] C:\WINDOWS\system32\iptp32.exe
                      O4 - HKLM\..\RunOnce: [sdkrt32.exe] C:\WINDOWS\system32\sdkrt32.exe
                      O4 - HKLM\..\RunOnce: [mfcpi.exe] C:\WINDOWS\mfcpi.exe
                      O4 - HKLM\..\RunOnce: [d3mw.exe] C:\WINDOWS\system32\d3mw.exe
                      O4 - HKLM\..\RunOnce: [wincl.exe] C:\WINDOWS\system32\wincl.exe
                      O4 - HKLM\..\RunOnce: [mssa32.exe] C:\WINDOWS\system32\mssa32.exe
                      O4 - HKLM\..\RunOnce: [winfc.exe] C:\WINDOWS\winfc.exe
                      O4 - HKLM\..\RunOnce: [atlyd32.exe] C:\WINDOWS\system32\atlyd32.exe
                      O4 - HKLM\..\RunOnce: [netol.exe] C:\WINDOWS\system32\netol.exe
                      O4 - HKLM\..\RunOnce: [javasp32.exe] C:\WINDOWS\system32\javasp32.exe
                      O4 - HKLM\..\RunOnce: [ntcq.exe] C:\WINDOWS\system32\ntcq.exe
                      O4 - HKLM\..\RunOnce: [ntim32.exe] C:\WINDOWS\system32\ntim32.exe
                      O4 - HKLM\..\RunOnce: [ntwj32.exe] C:\WINDOWS\ntwj32.exe
                      O4 - HKLM\..\RunOnce: [appbf32.exe] C:\WINDOWS\system32\appbf32.exe
                      O4 - HKLM\..\RunOnce: [atlbt32.exe] C:\WINDOWS\system32\atlbt32.exe
                      O4 - HKLM\..\RunOnce: [mfcsp32.exe] C:\WINDOWS\system32\mfcsp32.exe
                      O4 - HKLM\..\RunOnce: [d3sp.exe] C:\WINDOWS\d3sp.exe
                      O4 - HKLM\..\RunOnce: [sdkwb.exe] C:\WINDOWS\system32\sdkwb.exe
                      O4 - HKLM\..\RunOnce: [ielq32.exe] C:\WINDOWS\ielq32.exe
                      O4 - HKLM\..\RunOnce: [d3pa.exe] C:\WINDOWS\system32\d3pa.exe
                      O4 - HKLM\..\RunOnce: [ntzt32.exe] C:\WINDOWS\ntzt32.exe
                      O4 - HKLM\..\RunOnce: [sdkle.exe] C:\WINDOWS\sdkle.exe
                      O4 - HKLM\..\RunOnce: [mspi.exe] C:\WINDOWS\system32\mspi.exe
                      O4 - HKLM\..\RunOnce: [mfcxq.exe] C:\WINDOWS\mfcxq.exe
                      O4 - HKLM\..\RunOnce: [sdktu.exe] C:\WINDOWS\system32\sdktu.exe
                      O4 - HKLM\..\RunOnce: [iege32.exe] C:\WINDOWS\system32\iege32.exe
                      O4 - HKLM\..\RunOnce: [javawu32.exe] C:\WINDOWS\javawu32.exe
                      O4 - HKLM\..\RunOnce: [sysuz32.exe] C:\WINDOWS\sysuz32.exe
                      O4 - HKLM\..\RunOnce: [appsh32.exe] C:\WINDOWS\appsh32.exe
                      O4 - HKLM\..\RunOnce: [winnk.exe] C:\WINDOWS\winnk.exe
                      O4 - HKLM\..\RunOnce: [ieju.exe] C:\WINDOWS\system32\ieju.exe
                      O4 - HKLM\..\RunOnce: [atlnq32.exe] C:\WINDOWS\system32\atlnq32.exe
                      O4 - HKLM\..\RunOnce: [winwy.exe] C:\WINDOWS\system32\winwy.exe
                      O4 - HKLM\..\RunOnce: [ipfz.exe] C:\WINDOWS\system32\ipfz.exe
                      O4 - HKLM\..\RunOnce: [syszk.exe] C:\WINDOWS\system32\syszk.exe
                      O4 - HKLM\..\RunOnce: [d3pz.exe] C:\WINDOWS\d3pz.exe
                      O4 - HKLM\..\RunOnce: [ipzs32.exe] C:\WINDOWS\ipzs32.exe
                      O4 - HKLM\..\RunOnce: [winnv32.exe] C:\WINDOWS\winnv32.exe
                      O4 - HKLM\..\RunOnce: [winus.exe] C:\WINDOWS\system32\winus.exe
                      O4 - HKLM\..\RunOnce: [winhg.exe] C:\WINDOWS\system32\winhg.exe
                      O4 - HKLM\..\RunOnce: [javanl.exe] C:\WINDOWS\javanl.exe
                      O4 - HKLM\..\RunOnce: [addhw.exe] C:\WINDOWS\system32\addhw.exe
                      O4 - HKLM\..\RunOnce: [sysxd.exe] C:\WINDOWS\system32\sysxd.exe
                      O4 - HKLM\..\RunOnce: [atlvz32.exe] C:\WINDOWS\system32\atlvz32.exe
                      O4 - HKLM\..\RunOnce: [appkv32.exe] C:\WINDOWS\appkv32.exe
                      O4 - HKLM\..\RunOnce: [msps32.exe] C:\WINDOWS\msps32.exe
                      O4 - HKLM\..\RunOnce: [atlkd32.exe] C:\WINDOWS\atlkd32.exe
                      O4 - HKLM\..\RunOnce: [netoi.exe] C:\WINDOWS\system32\netoi.exe
                      O4 - HKLM\..\RunOnce: [apixi32.exe] C:\WINDOWS\apixi32.exe
                      O4 - HKLM\..\RunOnce: [mfcmf32.exe] C:\WINDOWS\system32\mfcmf32.exe
                      O4 - HKLM\..\RunOnce: [netll.exe] C:\WINDOWS\netll.exe
                      O4 - HKLM\..\RunOnce: [syslt32.exe] C:\WINDOWS\system32\syslt32.exe
                      O4 - HKLM\..\RunOnce: [winem.exe] C:\WINDOWS\winem.exe
                      O4 - HKLM\..\RunOnce: [nttj32.exe] C:\WINDOWS\nttj32.exe
                      O4 - HKLM\..\RunOnce: [d3jq.exe] C:\WINDOWS\d3jq.exe
                      O4 - HKLM\..\RunOnce: [ntid.exe] C:\WINDOWS\system32\ntid.exe
                      O4 - HKLM\..\RunOnce: [d3eh.exe] C:\WINDOWS\system32\d3eh.exe
                      O4 - HKLM\..\RunOnce: [syswi32.exe] C:\WINDOWS\system32\syswi32.exe
                      O4 - HKLM\..\RunOnce: [ipqu32.exe] C:\WINDOWS\system32\ipqu32.exe
                      O4 - HKLM\..\RunOnce: [apigr32.exe] C:\WINDOWS\system32\apigr32.exe
                      O4 - HKLM\..\RunOnce: [d3px.exe] C:\WINDOWS\system32\d3px.exe
                      O4 - HKLM\..\RunOnce: [appem32.exe] C:\WINDOWS\appem32.exe
                      O4 - HKLM\..\RunOnce: [apidt.exe] C:\WINDOWS\apidt.exe
                      O4 - HKLM\..\RunOnce: [ipiy.exe] C:\WINDOWS\system32\ipiy.exe
                      O4 - HKLM\..\RunOnce: [ntwv32.exe] C:\WINDOWS\system32\ntwv32.exe
                      O4 - HKLM\..\RunOnce: [ipcs32.exe] C:\WINDOWS\ipcs32.exe
                      O4 - HKLM\..\RunOnce: [appho32.exe] C:\WINDOWS\appho32.exe
                      O4 - HKLM\..\RunOnce: [atlvq.exe] C:\WINDOWS\system32\atlvq.exe
                      O4 - HKLM\..\RunOnce: [ntzu32.exe] C:\WINDOWS\system32\ntzu32.exe
                      O4 - HKLM\..\RunOnce: [sdker32.exe] C:\WINDOWS\sdker32.exe
                      O4 - HKLM\..\RunOnce: [netgu.exe] C:\WINDOWS\system32\netgu.exe
                      O4 - HKLM\..\RunOnce: [ipcm.exe] C:\WINDOWS\ipcm.exe
                      O4 - HKLM\..\RunOnce: [d3ni32.exe] C:\WINDOWS\system32\d3ni32.exe
                      O4 - HKLM\..\RunOnce: [crvj32.exe] C:\WINDOWS\crvj32.exe
                      O4 - HKLM\..\RunOnce: [mspu.exe] C:\WINDOWS\mspu.exe
                      O4 - HKLM\..\RunOnce: [crzi32.exe] C:\WINDOWS\crzi32.exe
                      O4 - HKLM\..\RunOnce: [d3sb32.exe] C:\WINDOWS\d3sb32.exe
                      O4 - HKLM\..\RunOnce: [ipxy32.exe] C:\WINDOWS\system32\ipxy32.exe
                      O4 - HKLM\..\RunOnce: [winzf32.exe] C:\WINDOWS\system32\winzf32.exe
                      O4 - HKLM\..\RunOnce: [mfcqn.exe] C:\WINDOWS\system32\mfcqn.exe
                      O4 - HKLM\..\RunOnce: [ntur32.exe] C:\WINDOWS\ntur32.exe
                      O4 - HKLM\..\RunOnce: [apidr.exe] C:\WINDOWS\system32\apidr.exe
                      O4 - HKLM\..\RunOnce: [netjo32.exe] C:\WINDOWS\netjo32.exe
                      O4 - HKLM\..\RunOnce: [apixl32.exe] C:\WINDOWS\system32\apixl32.exe
                      O4 - HKLM\..\RunOnce: [winch32.exe] C:\WINDOWS\system32\winch32.exe
                      O4 - HKLM\..\RunOnce: [ieac32.exe] C:\WINDOWS\system32\ieac32.exe
                      O4 - HKLM\..\RunOnce: [appqj.exe] C:\WINDOWS\system32\appqj.exe
                      O4 - HKLM\..\RunOnce: [netmn32.exe] C:\WINDOWS\netmn32.exe
                      O4 - HKLM\..\RunOnce: [atleo.exe] C:\WINDOWS\system32\atleo.exe
                      O4 - HKLM\..\RunOnce: [mfcjk32.exe] C:\WINDOWS\mfcjk32.exe
                      O4 - HKLM\..\RunOnce: [atlyh32.exe] C:\WINDOWS\system32\atlyh32.exe
                      O4 - HKLM\..\RunOnce: [iede32.exe] C:\WINDOWS\system32\iede32.exe
                      O4 - HKLM\..\RunOnce: [mfcyp32.exe] C:\WINDOWS\system32\mfcyp32.exe
                      O4 - HKLM\..\RunOnce: [addmm32.exe] C:\WINDOWS\addmm32.exe
                      O4 - HKLM\..\RunOnce: [d3ri32.exe] C:\WINDOWS\system32\d3ri32.exe
                      O4 - HKLM\..\RunOnce: [appuu.exe] C:\WINDOWS\appuu.exe
                      O4 - HKLM\..\RunOnce: [sysqg32.exe] C:\WINDOWS\system32\sysqg32.exe
                      O4 - HKLM\..\RunOnce: [apind32.exe] C:\WINDOWS\apind32.exe
                      O4 - HKLM\..\RunOnce: [javadl32.exe] C:\WINDOWS\javadl32.exe
                      O4 - HKLM\..\RunOnce: [ntpt32.exe] C:\WINDOWS\ntpt32.exe
                      O4 - HKLM\..\RunOnce: [crfb32.exe] C:\WINDOWS\system32\crfb32.exe
                      O4 - HKLM\..\RunOnce: [sdkif.exe] C:\WINDOWS\system32\sdkif.exe
                      O4 - HKLM\..\RunOnce: [mfchu32.exe] C:\WINDOWS\system32\mfchu32.exe
                      O4 - HKLM\..\RunOnce: [winyk.exe] C:\WINDOWS\winyk.exe
                      O4 - HKLM\..\RunOnce: [addva.exe] C:\WINDOWS\addva.exe
                      O4 - HKLM\..\RunOnce: [cror32.exe] C:\WINDOWS\system32\cror32.exe
                      O4 - HKLM\..\RunOnce: [nettn32.exe] C:\WINDOWS\nettn32.exe
                      O4 - HKLM\..\RunOnce: [d3oz32.exe] C:\WINDOWS\system32\d3oz32.exe
                      O4 - HKLM\..\RunOnce: [systd.exe] C:\WINDOWS\system32\systd.exe
                      O4 - HKLM\..\RunOnce: [mscd32.exe] C:\WINDOWS\system32\mscd32.exe
                      O4 - HKLM\..\RunOnce: [ipvc.exe] C:\WINDOWS\system32\ipvc.exe
                      O4 - HKLM\..\RunOnce: [sysqo.exe] C:\WINDOWS\sysqo.exe
                      O4 - HKLM\..\RunOnce: [d3fv.exe] C:\WINDOWS\d3fv.exe
                      O4 - HKLM\..\RunOnce: [sdkjh.exe] C:\WINDOWS\system32\sdkjh.exe
                      O4 - HKLM\..\RunOnce: [mskw32.exe] C:\WINDOWS\system32\mskw32.exe
                      O4 - HKLM\..\RunOnce: [mfcrt32.exe] C:\WINDOWS\system32\mfcrt32.exe
                      O4 - HKLM\..\RunOnce: [d3rt.exe] C:\WINDOWS\d3rt.exe
                      O4 - HKLM\..\RunOnce: [sdkvf.exe] C:\WINDOWS\sdkvf.exe
                      O4 - HKLM\..\RunOnce: [sysku32.exe] C:\WINDOWS\system32\sysku32.exe
                      O4 - HKLM\..\RunOnce: [windn.exe] C:\WINDOWS\system32\windn.exe
                      O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\iehp.exe
                      O4 - HKLM\..\RunOnce: [appdt32.exe] C:\WINDOWS\appdt32.exe
                      O4 - HKLM\..\RunOnce: [sdkqr.exe] C:\WINDOWS\sdkqr.exe
                      O4 - HKLM\..\RunOnce: [javayp.exe] C:\WINDOWS\system32\javayp.exe
                      O4 - HKLM\..\RunOnce: [winrl.exe] C:\WINDOWS\winrl.exe
                      O4 - HKLM\..\RunOnce: [winrz.exe] C:\WINDOWS\winrz.exe
                      O4 - HKLM\..\RunOnce: [ntlk.exe] C:\WINDOWS\ntlk.exe
                      O4 - HKLM\..\RunOnce: [apibs.exe] C:\WINDOWS\apibs.exe
                      O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe
                      O4 - HKLM\..\RunOnce: [crhv32.exe] C:\WINDOWS\crhv32.exe
                      O4 - HKLM\..\RunOnce: [iexc32.exe] C:\WINDOWS\iexc32.exe
                      O4 - HKLM\..\RunOnce: [javawq.exe] C:\WINDOWS\system32\javawq.exe
                      O4 - HKLM\..\RunOnce: [d3bu.exe] C:\WINDOWS\system32\d3bu.exe
                      O4 - HKLM\..\RunOnce: [d3pr32.exe] C:\WINDOWS\d3pr32.exe
                      O4 - HKLM\..\RunOnce: [javaqt32.exe] C:\WINDOWS\system32\javaqt32.exe
                      O4 - HKLM\..\RunOnce: [crkn.exe] C:\WINDOWS\crkn.exe
                      O4 - HKLM\..\RunOnce: [netjc32.exe] C:\WINDOWS\netjc32.exe
                      O4 - HKLM\..\RunOnce: [apphk32.exe] C:\WINDOWS\system32\apphk32.exe
                      O4 - HKLM\..\RunOnce: [appha32.exe] C:\WINDOWS\system32\appha32.exe
                      O4 - HKLM\..\RunOnce: [ipqs32.exe] C:\WINDOWS\system32\ipqs32.exe
                      O4 - HKLM\..\RunOnce: [winqa32.exe] C:\WINDOWS\winqa32.exe
                      O4 - HKLM\..\RunOnce: [winqz32.exe] C:\WINDOWS\winqz32.exe
                      O4 - HKLM\..\RunOnce: [ntpw32.exe] C:\WINDOWS\ntpw32.exe
                      O4 - HKLM\..\RunOnce: [winly.exe] C:\WINDOWS\winly.exe
                      O4 - HKLM\..\RunOnce: [addrv32.exe] C:\WINDOWS\system32\addrv32.exe
                      O4 - HKLM\..\RunOnce: [wings32.exe] C:\WINDOWS\wings32.exe
                      O4 - HKLM\..\RunOnce: [crko32.exe] C:\WINDOWS\crko32.exe
                      O4 - HKLM\..\RunOnce: [addfa32.exe] C:\WINDOWS\addfa32.exe
                      O4 - HKLM\..\RunOnce: [d3nn32.exe] C:\WINDOWS\d3nn32.exe
                      O4 - HKLM\..\RunOnce: [netyh32.exe] C:\WINDOWS\system32\netyh32.exe
                      O4 - HKLM\..\RunOnce: [ipgx.exe] C:\WINDOWS\system32\ipgx.exe
                      O4 - HKLM\..\RunOnce: [apihx.exe] C:\WINDOWS\apihx.exe
                      O4 - HKLM\..\RunOnce: [crwm32.exe] C:\WINDOWS\system32\crwm32.exe
                      O4 - HKLM\..\RunOnce: [sysut.exe] C:\WINDOWS\system32\sysut.exe
                      O4 - HKLM\..\RunOnce: [atlqx32.exe] C:\WINDOWS\system32\atlqx32.exe
                      O4 - HKLM\..\RunOnce: [winay.exe] C:\WINDOWS\system32\winay.exe
                      O4 - HKLM\..\RunOnce: [sdkie32.exe] C:\WINDOWS\sdkie32.exe
                      O4 - HKLM\..\RunOnce: [mshb.exe] C:\WINDOWS\mshb.exe
                      O4 - HKLM\..\RunOnce: [netmy32.exe] C:\WINDOWS\system32\netmy32.exe
                      O4 - HKLM\..\RunOnce: [ipgr32.exe] C:\WINDOWS\ipgr32.exe
                      O4 - HKLM\..\RunOnce: [appkn32.exe] C:\WINDOWS\appkn32.exe
                      O4 - HKLM\..\RunOnce: [atluh32.exe] C:\WINDOWS\atluh32.exe
                      O4 - HKLM\..\RunOnce: [ipkg.exe] C:\WINDOWS\system32\ipkg.exe
                      O4 - HKLM\..\RunOnce: [appjw32.exe] C:\WINDOWS\system32\appjw32.exe
                      O4 - HKLM\..\RunOnce: [atljm32.exe] C:\WINDOWS\system32\atljm32.exe
                      O4 - HKLM\..\RunOnce: [iphb32.exe] C:\WINDOWS\system32\iphb32.exe
                      O4 - HKLM\..\RunOnce: [javamf.exe] C:\WINDOWS\javamf.exe
                      O4 - HKLM\..\RunOnce: [sdkvg32.exe] C:\WINDOWS\system32\sdkvg32.exe
                      O4 - HKLM\..\RunOnce: [nettj32.exe] C:\WINDOWS\nettj32.exe
                      O4 - HKLM\..\RunOnce: [sdkjr.exe] C:\WINDOWS\sdkjr.exe
                      O4 - HKLM\..\RunOnce: [msnn32.exe] C:\WINDOWS\msnn32.exe
                      O4 - HKLM\..\RunOnce: [iequ32.exe] C:\WINDOWS\system32\iequ32.exe
                      O4 - HKLM\..\RunOnce: [sysqc.exe] C:\WINDOWS\system32\sysqc.exe
                      O4 - HKLM\..\RunOnce: [ierc.exe] C:\WINDOWS\ierc.exe
                      O4 - HKLM\..\RunOnce: [atlor.exe] C:\WINDOWS\system32\atlor.exe
                      O4 - HKLM\..\RunOnce: [adddg32.exe] C:\WINDOWS\system32\adddg32.exe
                      O4 - HKLM\..\RunOnce: [apppa.exe] C:\WINDOWS\apppa.exe
                      O4 - HKLM\..\RunOnce: [nettw32.exe] C:\WINDOWS\nettw32.exe
                      O4 - HKLM\..\RunOnce: [mfcce.exe] C:\WINDOWS\mfcce.exe
                      O4 - HKLM\..\RunOnce: [mfcit32.exe] C:\WINDOWS\mfcit32.exe
                      O4 - HKLM\..\RunOnce: [addgw32.exe] C:\WINDOWS\system32\addgw32.exe
                      O4 - HKLM\..\RunOnce: [apifd.exe] C:\WINDOWS\system32\apifd.exe
                      O4 - HKLM\..\RunOnce: [sdkbh32.exe] C:\WINDOWS\sdkbh32.exe
                      O4 - HKLM\..\RunOnce: [netki.exe] C:\WINDOWS\system32\netki.exe
                      O4 - HKLM\..\RunOnce: [ipyf32.exe] C:\WINDOWS\ipyf32.exe
                      O4 - HKLM\..\RunOnce: [mszh.exe] C:\WINDOWS\mszh.exe
                      O4 - HKLM\..\RunOnce: [mfcqo32.exe] C:\WINDOWS\mfcqo32.exe
                      O4 - HKLM\..\RunOnce: [javaft32.exe] C:\WINDOWS\system32\javaft32.exe
                      O4 - HKLM\..\RunOnce: [netdi32.exe] C:\WINDOWS\netdi32.exe
                      O4 - HKLM\..\RunOnce: [apifr.exe] C:\WINDOWS\apifr.exe

                      O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\mfcmp32.exe" /s (file missing)

                      ----------------------------------------------------------------------------
                      ¤Recherche et supprime ceci:
                      attention seulement les fichiers (si présents)

                      C:\WINDOWS\system32\mfcmp32.exe" /s

                      -----------------------------------------------------------------------
                      ¤Passe a² et supprime tout ce qu il trouve
                      ----------------------------------------------------------------------------
                      ¤Arrête ces services :

                      Clique sur Démarrer->exécuter->tape: services.msc

                      Double-clique: Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I)

                      Règle-le sur "Arrêté" et "Désactivé".
                      ----------------------------------------------------------------------------
                      ¤ Passe about buster autant de fois qu il trouve qqchose (5/10/15 fois si besoin)
                      ----------------------------------------------------------------------------
                      ¤ Passe Ad-Aware et vire tout ce qu’il trouve
                      ----------------------------------------------------------------------------
                      ¤ Passe Spybot et vire tout ce qu’il trouve
                      ----------------------------------------------------------------------------
                      > Tu vides ta poubelle et tu redémarres en mode normal et refait un HijackThis

                      Précise tes soucis s’il en reste....

                      Tiens-moi au courant

                      a+
                      0
                      1. Ca y est on a reussi a virer cette saloperie!!
                        je te remercie et heureusement qu'il y a des mecs comme toi sur le net!!!
                        J'habite dans le 92 a saint cloud, je te paye un verre de champ quand tu veux!!
                        @+++
                        Fred
                        0
                        1. salut fred ^^
                          ravi que ton soucis soit resolu
                          reactive ta restauration systeme+reache tes fichiers caches

                          bon surf et si je passe sur paris on se contacte, je passerais avec ma belle lili te voir lol

                          a+
                          0