J'ai un virus...

Résolu
Bonjour,
J'ai ouvert mon pc ce matin et impossible de faire quoi que ce soit car j'ai 2 fenêtres qui s'ouvrent et qui bloque mon bureau?
Le message est "https://onlineregister.com/" je ne peut pas en sortir les 2 fenêtres sont l'une sur l'autre et rien ne bouge...
Pouvez-vous m'aider S.V.P.
Merci d'avance.
utile83

PS: j'ai windows 7 sur un Packard Bell onenettwo m u5124

33 réponses

Résumé de la discussion

Deux fenêtres s'ouvrent simultanément et bloquent le bureau, affichant un message dirigé vers https://onlineregister.com/ qui suggère une infection par logiciel malveillant nécessitant une intervention rapide. La solution préconisée consiste à lancer RogueKiller pour détecter et supprimer les processus malveillants et nettoyer les entrées de registre et les éléments de démarrage afin de reprendre le contrôle du système. Parmi les éléments signalés, des processus comme Protector-txnj.exe et FacebookMessenger.exe sont identifiés comme suspects, avec des entrées Run et des paramètres Image File Execution Options ciblés à supprimer. En cas d'infection étendue, d'autres outils peuvent être utiles, notamment le démarrage en mode sans échec et la vérification ciblée des services, des clés Run et des chemins d'accès problématiques.

Bobot (l’IA à votre service)
  1. Modérateur
    0
    1. Bonjour,
      Merci pour la rapidité de votre réponse, j'ai redémarre en mode sans échec et le service pack1 s'est télécharge, mais le problème demeure, le virus est toujours là, chaque fois que je me connecte a internet explorer, impossible de rester sur le navigateur...
      Un message "systeme update adward" s'affiche...
      Que faire?
      Utile83
      0
    2. Modérateur
      Ok, fais un scan avec RogueKiller et poste le rapport :
      https://www.commentcamarche.net/faq/30719-utiliser-roguekiller#utilisation-de-roguekiller
      0
    3. Re,
      Voici le1er rapport,

      RogueKiller V7.5.1 [28/05/2012] par Tigzy
      mail: tigzyRK<at>gmail<dot>com
      Remontees: https://www.luanagames.com/index.fr.html
      Blog: http://tigzyrk.blogspot.com

      Systeme d'exploitation: Windows 7 (6.1.7600 ) 64 bits version
      Demarrage : Mode normal
      Utilisateur: packardbell [Droits d'admin]
      Mode: Recherche -- Date: 30/05/2012 15:40:43

      ¤¤¤ Processus malicieux: 2 ¤¤¤
      [SUSP PATH] Protector-txnj.exe -- C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe -> KILLED [TermProc]
      [SUSP PATH] FacebookMessenger.exe -- C:\Users\packardbell\AppData\Local\Facebook\Messenger\2.1.4520.0\FacebookMessenger.exe -> KILLED [TermProc]

      ¤¤¤ Entrees de registre: 773 ¤¤¤
      [SUSP PATH] HKCU\[...]\Run : Inspector (C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe) -> FOUND
      [SUSP PATH] HKUS\S-1-5-21-1638807749-3425671960-761767505-1000[...]\Run : Inspector (C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe) -> FOUND
      [SUSP PATH] Facebook Messenger.lnk @packardbell : C:\Users\packardbell\AppData\Local\Facebook\Messenger\2.1.4520.0\FacebookMessenger.exe -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : a.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : aAvgApi.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AAWTray.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : About.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ackwin32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : Ad-Aware.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : adaware.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : advxdwin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AdwarePrj.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : agent.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : agentsvr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : agentw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : alertsvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : alevir.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : alogserv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AlphaAV (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AlphaAV.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AluSchedulerSvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : amon9x.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : anti-trojan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : Anti-Virus Professional.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AntispywarXP2009.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : antivirus.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPlus (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPlus.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPro_2010.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusXP (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusXP.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : antivirusxppro2009.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AntiVirus_Pro.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ants.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : apimonitor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : aplica32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : apvxdwin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : arr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashAvast.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashBug.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashChest.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashCnsnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashDisp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashLogV.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashMaiSv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashPopWz.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashQuick.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashServ.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashSimp2.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashSimpl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashSkPcc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashSkPck.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashUpd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ashWebSv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : aswChLic.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : aswRegSvr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : aswRunDll.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : aswUpdSv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : atcon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : atguard.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : atro55en.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : atupdater.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : atwatch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : au.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : aupdate.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : auto-protect.nav80try.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : autodown.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : autotrace.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : autoupdate.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : av360.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avadmin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avastSvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avastUI.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AVCare.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avcenter.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avciman.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avconfig.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avconsol.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ave32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AVENGINE.EXE (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgcc32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgchk.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgcmgr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgcsrvx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgctrl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgdumpx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgemc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgiproxy.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgnsx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgrsx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgscanx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgserv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgserv9.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgsrmax.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgtray.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avguard.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgupd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avgwdsvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avkpop.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avkserv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avkservice.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avkwctl9.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avltmain.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avmailc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avmcdlg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avnotify.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avp32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avpcc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avpdos32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avpm.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avptc32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avpupd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avsched32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avshadow.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avsynmgr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avupgsvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : AVWEBGRD.EXE (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avwin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avwin95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avwinnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avwsc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avwupd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avwupd32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avwupsrv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avxmonitor9x.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avxmonitornt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : avxquar.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : b.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : backweb.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bargains.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bdfvcl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bdfvwiz.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : BDInProcPatch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bdmcon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : BDMsnScan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : BDSurvey.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bd_professional.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : beagle.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : belt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bidef.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bidserver.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bipcp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bipcpevalsetup.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bisp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : blackd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : blackice.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : blink.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : blss.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bootconf.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bootwarn.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : borg2.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bpc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : brasil.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : brastk.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : brw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bs120.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bspatch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bundle.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : bvt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : c.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cavscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ccapp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ccevtmgr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ccpxysvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ccSvcHst.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cdp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfgwiz.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfiadmin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfiaudit.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfinet.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfinet32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfpconfg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfplogvw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cfpupdat.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : claw95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : claw95cf.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : clean.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cleaner.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cleaner3.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cleanIELow.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cleanpc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : click.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cmd32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cmdagent.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cmesys.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cmgrdian.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cmon016.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : connectionmonitor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : control (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cpd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cpf9x206.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cpfnt206.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : crashrep.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : csc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cssconfg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cssupdat.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cssurf.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ctrl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cwnb181.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : cwntdwmo.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : d.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : datemanager.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dcomx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : defalert.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : defscangui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : defwatch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : deloeminfs.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : deputy.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : divx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dllcache.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dllreg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : doors.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dop.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dpf.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dpfsetup.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dpps2.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : driverctrl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : drwatson.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : drweb32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : drwebupw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dssagent.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dvp95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : dvp95_0.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ecengine.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : efpeadm.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : emsw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ent.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : esafe.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : escanhnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : escanv95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : espwatch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ethereal.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : etrustcipe.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : evpn.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : exantivirus-cnet.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : exe.avxw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : expert.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : explore.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : f-agnt95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : f-prot.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : f-prot95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : f-stopw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fact.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fameh32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fast.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fch32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fih32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : findviru.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : firewall.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fixcfg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fixfp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fnrb32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fp-win.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fp-win_trial.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fprot.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : frmwrk32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : frw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsaa.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsav.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsav32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsav530stbyb.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsav530wtbyb.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsav95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsgk32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsm32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsma32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : fsmb32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : gator.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : gav.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : gbmenu.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : gbn976rl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : gbpoll.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : generics.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : gmt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : guard.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : guarddog.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : guardgui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : guardxkickoff.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : hacktracersetup.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : hbinst.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : hbsrv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : History.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : homeav2010.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : hotactio.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : hotpatch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : htlog.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : htpatch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : hwpe.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : hxdl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : hxiul.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : iamapp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : iamserv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : iamstats.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ibmasn.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ibmavsp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : icload95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : icloadnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : icmon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : icsupp95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : icsuppnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : Identity.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : idle.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : iedll.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : iedriver.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : IEShow.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : iface.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ifw2000.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : inetlnfo.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : infus.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : infwin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : init.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : init32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : install[1].exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : install[2].exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : install[3].exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : install[4].exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : install[5].exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : intdel.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : intren.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : iomon98.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : istsvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : jammer.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : jdbgmrg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : jedi.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : JsRcGen.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : kavlite40eng.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : kavpers40eng.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : kavpf.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : kazza.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : keenvalue.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : kerio-pf-213-en-win.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : kerio-wrl-421-en-win.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : kerio-wrp-421-en-win.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : killprocesssetup161.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ldnetmon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ldpro.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ldpromenu.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ldscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : licmgr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : lnetinfo.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : loader.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : localnet.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : lockdown.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : lockdown2000.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : lookout.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : lordpe.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : lsetup.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : luall.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : luau.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : lucomserver.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : luinit.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : luspt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : MalwareRemoval.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mapisvc32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mbam.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mbamgui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mbamservice.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcagent.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcmnhdlr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcmpeng.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcmscsvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcnasvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcproxy.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : McSACore.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcshell.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcshield.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcsysmon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mctool.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcupdate.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcvsrte.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mcvsshld.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : md.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mfin32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mfw2en.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mfweng3.02d30.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mgavrtcl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mgavrte.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mghtml.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mgui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : minilog.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mmod.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : monitor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : moolive.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mostat.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mpfagent.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mpfservice.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : MPFSrv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mpftray.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mrflux.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mrt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msa.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msapp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : MSASCui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msbb.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msblast.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mscache.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msccn32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mscman.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msconfig (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msdm.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msdos.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msiexec16.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mslaugh.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msmgt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msmsgri32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msseces.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mssmmc32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mssys.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : msvxd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mu0311ad.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : mwatch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : n32scanw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nav.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navap.navapsvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navapsvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navapw32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navdx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navlu32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navstub.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navw32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : navwnt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nc2000.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ncinst4.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ndd32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : neomonitor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : neowatchlog.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : netarmor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : netd32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : netinfo.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : netmon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : netscanpro.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : netspyhunter-1.2.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : netutils.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nisserv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nisum.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nmain.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nod32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : normist.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : norton_internet_secu_3.0_407.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : notstart.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : npf40_tw_98_nt_me_2k.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : npfmessenger.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nprotect.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : npscheck.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : npssvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nsched32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nssys32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nstask32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nsupdate.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ntrtscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ntvdm.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ntxconfig.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nupgrade.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nvarch16.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nvc95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nvsvc32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nwinst4.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nwservice.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : nwtool16.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : OAcat.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : OAhlp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : OAReg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : oasrv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : oaui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : oaview.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ODSW.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ollydbg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : onsrvr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : optimize.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ostronet.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : otfix.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : outpost.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : outpostinstall.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : outpostproinstall.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ozn695m5.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : padmin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : panixk.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : patch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pav.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pavcl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PavFnSvr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pavproxy.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pavprsrv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pavsched.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pavsrv51.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pavw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pccwin98.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pcfwallicon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pcip10117_0.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pcscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pctsAuxs.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pctsGui.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pctsSvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pctsTray.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PC_Antispyware2010.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pdfndr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pdsetup.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PerAvir.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : periscope.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : persfw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : personalguard (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : personalguard.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : perswf.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pf2.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pfwadmin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pgmonitr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pingscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : platin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pop3trap.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : poproxy.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : popscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : portdetective.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : portmonitor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : powerscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ppinupdt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pptbc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ppvstop.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : prizesurfer.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : prmt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : prmvr.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : procdump.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : processmonitor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : procexplorerv1.0.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : programauditor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : proport.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : protector.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : protectx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PSANCU.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PSANHost.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PSANToManager.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PsCtrls.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PsImSvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PskSvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : pspf.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : PSUNMain.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : purge.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : qconsole.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : qh.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : qserver.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : Quick Heal.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : QuickHealCleaner.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rapapp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rav7.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rav7win.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rav8win32eng.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ray.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rb32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rcsync.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : realmon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : reged.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : regedit.exe (C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe reg) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : regedt32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rescue.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rescue32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rrguard.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rscdwld.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rshell.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rtvscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rtvscn95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rulaunch.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rwg (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : rwg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : SafetyKeeper.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : safeweb.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sahagent.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : Save.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : SaveArmor.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : SaveDefense.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : SaveKeep.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : savenow.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sbserv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : scam32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : scan32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : scan95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : scanpm.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : scrscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : Secure Veteran.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : secureveteran.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : Security Center.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : SecurityFighter.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : securitysoldier.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : serv95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : setloadorder.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : setupvameeval.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : setup_flowprotector_us.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sgssfw32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sh.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : shellspyinstall.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : shield.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : shn.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : showbehind.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : signcheck.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : smart.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : smartprotector.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : smc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : smrtdefp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sms.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : smss32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : snetcfg.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : soap.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sofi.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : SoftSafeness.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sperm.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : spf.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sphinx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : spoler.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : spoolcv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : spoolsv32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : spywarexpguard.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : spyxx.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : srexe.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : srng.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ss3edit.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ssgrate.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : ssg_4104.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : st2.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : start.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : stcloader.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : supftrl.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : support.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : supporter5.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : svc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : svchostc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : svchosts.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : svshost.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sweep95.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sweepnet.sweepsrv.sys.swnetsup.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : symlcsvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : symproxysvc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : symtray.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : system.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : system32.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : sysupd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tapinstall.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : taskmgr.exe (C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe task) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : taumon.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tbscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tca.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tcm.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tds-3.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tds2-98.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tds2-nt.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : teekids.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tfak.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tfak5.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tgbob.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : titanin.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : titaninxp.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : TPSrv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : trickler.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : trjscan.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : trjsetup.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : trojantrap3.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : TrustWarrior.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tsadbot.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tsc.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tvmd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : tvtmd.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : undoboot.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : updat.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : upgrad.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : utpost.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : vbcmserv.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : vbcons.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : vbust.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : vbwin9x.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : vbwinntw.exe (svchost.exe) -> FOUND
      [IFEO] HKLM\[...]\Image File Execution Options : vcsetup.exe (svchost.
      0
    4. Modérateur
      Ok, utilise l'option "Suppression" de RogueKiller et poste le rapport.

      Passe par http://pjjoint.malekal.com/ pour héberger le rapport car il risque d'être long.
      0
    5. Re,
      2eme rapport,

      RogueKiller V7.5.1 [28/05/2012] par Tigzy
      mail: tigzyRK<at>gmail<dot>com
      Remontees: https://www.luanagames.com/index.fr.html
      Blog: http://tigzyrk.blogspot.com

      Systeme d'exploitation: Windows 7 (6.1.7600 ) 64 bits version
      Demarrage : Mode normal
      Utilisateur: packardbell [Droits d'admin]
      Mode: Suppression -- Date: 30/05/2012 15:42:45

      ¤¤¤ Processus malicieux: 2 ¤¤¤
      [SUSP PATH] Protector-txnj.exe -- C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe -> KILLED [TermProc]
      [SUSP PATH] FacebookMessenger.exe -- C:\Users\packardbell\AppData\Local\Facebook\Messenger\2.1.4520.0\FacebookMessenger.exe -> KILLED [TermProc]

      ¤¤¤ Entrees de registre: 772 ¤¤¤
      [SUSP PATH] HKCU\[...]\Run : Inspector (C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe) -> DELETED
      [SUSP PATH] Facebook Messenger.lnk @packardbell : C:\Users\packardbell\AppData\Local\Facebook\Messenger\2.1.4520.0\FacebookMessenger.exe -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : a.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : aAvgApi.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AAWTray.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : About.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ackwin32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : Ad-Aware.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : adaware.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : advxdwin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AdwarePrj.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : agent.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : agentsvr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : agentw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : alertsvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : alevir.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : alogserv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AlphaAV (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AlphaAV.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AluSchedulerSvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : amon9x.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : anti-trojan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : Anti-Virus Professional.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AntispywarXP2009.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : antivirus.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPlus (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPlus.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPro_2010.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusXP (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AntivirusXP.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : antivirusxppro2009.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AntiVirus_Pro.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ants.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : apimonitor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : aplica32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : apvxdwin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : arr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashAvast.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashBug.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashChest.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashCnsnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashDisp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashLogV.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashMaiSv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashPopWz.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashQuick.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashServ.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashSimp2.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashSimpl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashSkPcc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashSkPck.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashUpd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ashWebSv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : aswChLic.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : aswRegSvr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : aswRunDll.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : aswUpdSv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : atcon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : atguard.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : atro55en.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : atupdater.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : atwatch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : au.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : aupdate.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : auto-protect.nav80try.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : autodown.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : autotrace.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : autoupdate.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : av360.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avadmin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avastSvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avastUI.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AVCare.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avcenter.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avciman.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avconfig.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avconsol.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ave32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AVENGINE.EXE (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgcc32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgchk.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgcmgr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgcsrvx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgctrl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgdumpx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgemc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgiproxy.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgnsx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgrsx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgscanx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgserv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgserv9.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgsrmax.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgtray.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avguard.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgupd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avgwdsvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avkpop.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avkserv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avkservice.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avkwctl9.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avltmain.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avmailc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avmcdlg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avnotify.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avp32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avpcc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avpdos32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avpm.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avptc32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avpupd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avsched32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avshadow.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avsynmgr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avupgsvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : AVWEBGRD.EXE (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avwin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avwin95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avwinnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avwsc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avwupd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avwupd32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avwupsrv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avxmonitor9x.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avxmonitornt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : avxquar.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : b.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : backweb.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bargains.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bdfvcl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bdfvwiz.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : BDInProcPatch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bdmcon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : BDMsnScan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : BDSurvey.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bd_professional.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : beagle.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : belt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bidef.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bidserver.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bipcp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bipcpevalsetup.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bisp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : blackd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : blackice.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : blink.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : blss.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bootconf.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bootwarn.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : borg2.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bpc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : brasil.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : brastk.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : brw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bs120.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bspatch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bundle.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : bvt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : c.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cavscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ccapp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ccevtmgr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ccpxysvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ccSvcHst.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cdp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfgwiz.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfiadmin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfiaudit.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfinet.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfinet32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfpconfg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfplogvw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cfpupdat.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : claw95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : claw95cf.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : clean.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cleaner.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cleaner3.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cleanIELow.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cleanpc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : click.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cmd32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cmdagent.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cmesys.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cmgrdian.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cmon016.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : connectionmonitor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : control (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cpd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cpf9x206.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cpfnt206.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : crashrep.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : csc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cssconfg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cssupdat.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cssurf.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ctrl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cwnb181.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : cwntdwmo.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : d.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : datemanager.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dcomx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : defalert.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : defscangui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : defwatch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : deloeminfs.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : deputy.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : divx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dllcache.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dllreg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : doors.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dop.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dpf.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dpfsetup.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dpps2.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : driverctrl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : drwatson.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : drweb32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : drwebupw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dssagent.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dvp95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : dvp95_0.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ecengine.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : efpeadm.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : emsw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ent.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : esafe.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : escanhnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : escanv95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : espwatch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ethereal.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : etrustcipe.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : evpn.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : exantivirus-cnet.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : exe.avxw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : expert.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : explore.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : f-agnt95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : f-prot.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : f-prot95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : f-stopw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fact.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fameh32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fast.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fch32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fih32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : findviru.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : firewall.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fixcfg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fixfp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fnrb32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fp-win.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fp-win_trial.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fprot.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : frmwrk32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : frw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsaa.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsav.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsav32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsav530stbyb.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsav530wtbyb.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsav95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsgk32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsm32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsma32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : fsmb32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : gator.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : gav.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : gbmenu.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : gbn976rl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : gbpoll.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : generics.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : gmt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : guard.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : guarddog.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : guardgui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : guardxkickoff.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : hacktracersetup.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : hbinst.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : hbsrv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : History.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : homeav2010.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : hotactio.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : hotpatch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : htlog.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : htpatch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : hwpe.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : hxdl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : hxiul.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : iamapp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : iamserv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : iamstats.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ibmasn.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ibmavsp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : icload95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : icloadnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : icmon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : icsupp95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : icsuppnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : Identity.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : idle.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : iedll.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : iedriver.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : IEShow.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : iface.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ifw2000.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : inetlnfo.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : infus.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : infwin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : init.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : init32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : install[1].exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : install[2].exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : install[3].exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : install[4].exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : install[5].exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : intdel.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : intren.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : iomon98.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : istsvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : jammer.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : jdbgmrg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : jedi.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : JsRcGen.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : kavlite40eng.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : kavpers40eng.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : kavpf.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : kazza.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : keenvalue.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : kerio-pf-213-en-win.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : kerio-wrl-421-en-win.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : kerio-wrp-421-en-win.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : killprocesssetup161.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ldnetmon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ldpro.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ldpromenu.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ldscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : licmgr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : lnetinfo.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : loader.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : localnet.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : lockdown.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : lockdown2000.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : lookout.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : lordpe.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : lsetup.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : luall.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : luau.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : lucomserver.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : luinit.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : luspt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : MalwareRemoval.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mapisvc32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mbam.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mbamgui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mbamservice.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcagent.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcmnhdlr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcmpeng.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcmscsvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcnasvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcproxy.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : McSACore.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcshell.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcshield.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcsysmon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mctool.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcupdate.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcvsrte.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mcvsshld.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : md.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mfin32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mfw2en.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mfweng3.02d30.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mgavrtcl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mgavrte.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mghtml.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mgui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : minilog.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mmod.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : monitor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : moolive.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mostat.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mpfagent.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mpfservice.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : MPFSrv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mpftray.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mrflux.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mrt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msa.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msapp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : MSASCui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msbb.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msblast.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mscache.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msccn32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mscman.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msconfig (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msdm.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msdos.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msiexec16.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mslaugh.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msmgt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msmsgri32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msseces.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mssmmc32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mssys.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : msvxd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mu0311ad.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : mwatch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : n32scanw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nav.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navap.navapsvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navapsvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navapw32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navdx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navlu32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navstub.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navw32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : navwnt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nc2000.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ncinst4.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ndd32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : neomonitor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : neowatchlog.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : netarmor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : netd32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : netinfo.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : netmon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : netscanpro.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : netspyhunter-1.2.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : netutils.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nisserv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nisum.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nmain.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nod32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : normist.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : norton_internet_secu_3.0_407.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : notstart.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : npf40_tw_98_nt_me_2k.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : npfmessenger.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nprotect.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : npscheck.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : npssvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nsched32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nssys32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nstask32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nsupdate.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ntrtscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ntvdm.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ntxconfig.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nupgrade.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nvarch16.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nvc95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nvsvc32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nwinst4.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nwservice.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : nwtool16.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : OAcat.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : OAhlp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : OAReg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : oasrv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : oaui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : oaview.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ODSW.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ollydbg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : onsrvr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : optimize.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ostronet.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : otfix.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : outpost.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : outpostinstall.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : outpostproinstall.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ozn695m5.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : padmin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : panixk.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : patch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pav.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pavcl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PavFnSvr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pavproxy.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pavprsrv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pavsched.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pavsrv51.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pavw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pccwin98.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pcfwallicon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pcip10117_0.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pcscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pctsAuxs.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pctsGui.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pctsSvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pctsTray.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PC_Antispyware2010.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pdfndr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pdsetup.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PerAvir.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : periscope.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : persfw.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : personalguard (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : personalguard.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : perswf.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pf2.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pfwadmin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pgmonitr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pingscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : platin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pop3trap.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : poproxy.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : popscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : portdetective.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : portmonitor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : powerscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ppinupdt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pptbc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ppvstop.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : prizesurfer.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : prmt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : prmvr.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : procdump.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : processmonitor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : procexplorerv1.0.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : programauditor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : proport.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : protector.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : protectx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PSANCU.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PSANHost.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PSANToManager.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PsCtrls.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PsImSvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PskSvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : pspf.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : PSUNMain.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : purge.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : qconsole.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : qh.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : qserver.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : Quick Heal.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : QuickHealCleaner.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rapapp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rav7.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rav7win.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rav8win32eng.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ray.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rb32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rcsync.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : realmon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : reged.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : regedit.exe (C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe reg) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : regedt32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rescue.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rescue32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rrguard.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rscdwld.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rshell.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rtvscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rtvscn95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rulaunch.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rwg (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : rwg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : SafetyKeeper.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : safeweb.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sahagent.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : Save.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : SaveArmor.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : SaveDefense.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : SaveKeep.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : savenow.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sbserv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : scam32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : scan32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : scan95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : scanpm.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : scrscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : Secure Veteran.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : secureveteran.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : Security Center.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : SecurityFighter.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : securitysoldier.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : serv95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : setloadorder.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : setupvameeval.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : setup_flowprotector_us.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sgssfw32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sh.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : shellspyinstall.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : shield.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : shn.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : showbehind.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : signcheck.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : smart.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : smartprotector.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : smc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : smrtdefp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sms.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : smss32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : snetcfg.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : soap.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sofi.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : SoftSafeness.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sperm.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : spf.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sphinx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : spoler.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : spoolcv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : spoolsv32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : spywarexpguard.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : spyxx.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : srexe.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : srng.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ss3edit.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ssgrate.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : ssg_4104.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : st2.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : start.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : stcloader.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : supftrl.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : support.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : supporter5.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : svc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : svchostc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : svchosts.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : svshost.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sweep95.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sweepnet.sweepsrv.sys.swnetsup.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : symlcsvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : symproxysvc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : symtray.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : system.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : system32.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : sysupd.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tapinstall.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : taskmgr.exe (C:\Users\packardbell\AppData\Roaming\Protector-txnj.exe task) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : taumon.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tbscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tc.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tca.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tcm.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tds-3.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tds2-98.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tds2-nt.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : teekids.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tfak.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tfak5.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tgbob.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : titanin.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : titaninxp.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : TPSrv.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : trickler.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : trjscan.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : trjsetup.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : trojantrap3.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : TrustWarrior.exe (svchost.exe) -> DELETED
      [IFEO] HKLM\[...]\Image File Execution Options : tsadbot.exe (svchost.exe) -> DELETED
      [IFEO] HK
      0
  2. Modérateur
    Tu peux de nouveau te servir de ton PC ?

    --> Télécharge ZHPDiag (de Nicolas Coolman).

    --> Double-clique sur le fichier d'installation. Installe ZHPDiag avec les paramètres par défaut (N'oublie pas de cocher "Créer une icône sur le Bureau").

    --> Lance ZHPDiag en double-cliquant sur le raccourci présent sur ton Bureau.
    (Sous Vista/Win7, il faut cliquer droit sur le raccourci de ZHPDiag et choisir Exécuter en tant qu'administrateur)

    --> Clique sur la loupe (Lancer le diagnostic) puis laisse l'outil scanner.

    --> Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier (le rapport de l'analyse) sur ton Bureau.

    --> Pour me transmettre le rapport, utilise le site http://pjjoint.malekal.com/ car le rapport ZHPDiag est plutôt long. Copie-colle le lien donné par le site ici.
    0
    1. Modérateur
      Tu as deux antivirus, Avira AntiVir et Microsoft Security Essentials.

      Les deux sont actifs ?

      --> Télécharge et lance AdwCleaner (de Xplode), choisis l'option "Suppression" et poste le rapport :
      http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/2-adwcleaner
      0
      1. Voici le rapport
        # AdwCleaner v1.608 - Rapport créé le 30/05/2012 à 19:13:14
        # Mis à jour le 27/05/2012 par Xplode
        # Système d'exploitation : Windows 7 Home Premium (64 bits)
        # Nom d'utilisateur : packardbell - PACKARDBELL-PC
        # Exécuté depuis : C:\Users\packardbell\Downloads\adwcleaner.exe
        # Option [Suppression]

        ***** [Services] *****

        ***** [Fichiers / Dossiers] *****

        Dossier Supprimé : C:\Users\packardbell\AppData\Local\APN
        Dossier Supprimé : C:\Users\packardbell\AppData\Local\Conduit
        Dossier Supprimé : C:\Users\packardbell\AppData\Local\freetvradio Air
        Dossier Supprimé : C:\Users\packardbell\AppData\Local\Ilivid Player
        Dossier Supprimé : C:\Users\PACKAR~1\AppData\Local\Temp\AskSearch
        Dossier Supprimé : C:\Users\PACKAR~1\AppData\Local\Temp\Iminent
        Dossier Supprimé : C:\Users\packardbell\AppData\LocalLow\Conduit
        Dossier Supprimé : C:\Users\packardbell\AppData\LocalLow\searchquband
        Dossier Supprimé : C:\Users\packardbell\AppData\LocalLow\Toolbar4
        Dossier Supprimé : C:\Users\packardbell\AppData\Roaming\freeTVRadio
        Dossier Supprimé : C:\Users\packardbell\AppData\Roaming\OfferBox
        Dossier Supprimé : C:\ProgramData\boost_interprocess
        Dossier Supprimé : C:\Program Files (x86)\Conduit
        Dossier Supprimé : C:\Program Files (x86)\Ilivid
        Dossier Supprimé : C:\Program Files (x86)\Iminent
        Dossier Supprimé : C:\Program Files (x86)\OfferBox

        ***** [Registre] *****

        [*] Clé Supprimée : HKLM\SOFTWARE\Classes\Toolbar.CT2186548
        [*] Clé Supprimée : HKLM\SOFTWARE\Classes\Toolbar.CT3148726
        Clé Supprimée : HKCU\Software\DataMngr
        Clé Supprimée : HKCU\Software\freeTVRadio
        Clé Supprimée : HKCU\Software\Iminent
        Clé Supprimée : HKCU\Software\Offerbox
        Clé Supprimée : HKCU\Software\Softonic
        Clé Supprimée : HKCU\Software\Spointer
        Clé Supprimée : HKCU\Software\AppDataLow\Software\Conduit
        Clé Supprimée : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
        Clé Supprimée : HKCU\Software\AppDataLow\Software\searchqutoolbar
        Clé Supprimée : HKLM\SOFTWARE\Conduit
        Clé Supprimée : HKLM\SOFTWARE\Iminent
        Clé Supprimée : HKLM\SOFTWARE\Offerbox
        Clé Supprimée : HKLM\SOFTWARE\Software
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.TbTask
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
        Clé Supprimée : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
        Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
        Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
        Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\bjeikeheijdjdfjbmknpefojickbkmom
        Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
        [x64] Clé Supprimée : HKLM\SOFTWARE\DataMngr

        ***** [Registre - GUID] *****

        Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
        Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
        Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
        Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
        Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
        Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
        Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
        Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
        Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
        Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
        Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
        Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
        Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
        Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
        Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
        Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
        Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
        Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
        Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
        Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
        Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{28387537-E3F9-4ED7-860C-11E69AF4A8A0}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{58124A0B-DC32-4180-9BFF-E0E21AE34026}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28387537-E3F9-4ED7-860C-11E69AF4A8A0}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{58124A0B-DC32-4180-9BFF-E0E21AE34026}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
        Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C}
        Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{28387537-E3F9-4ED7-860C-11E69AF4A8A0}]
        Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
        Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
        Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
        [x64] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}

        ***** [Navigateurs] *****

        -\\ Internet Explorer v8.0.7600.16385

        [OK] Le registre ne contient aucune entrée illégitime.

        -\\ Google Chrome v19.0.1084.52

        Fichier : C:\Users\packardbell\AppData\Local\Google\Chrome\User Data\Default\Preferences

        Supprimée : "urls_to_restore_on_startup": [ "hxxp://search.iminent.com/?appId=183C36E7-3253-404D-AB1B-A[...]
        Supprimée : "urls_to_restore_on_startup": [ "hxxp://search.iminent.com/?appId=183C36E7-3253-404D-AB1B-A1D9[...]

        *************************

        AdwCleaner[S1].txt - [17576 octets] - [30/05/2012 19:13:14]

        ########## EOF - C:\AdwCleaner[S1].txt - [17705 octets] ##########
        0
        1. Modérateur
          --> Relance AdwCleaner et choisis "Désinstallation".

          Et pour ma question par rapport aux antivirus ?
          0
          1. Re,
            voila, j'ai suivi vos instructions, oui j'ai deux anti virus, un qui est livré avec le PC et antivir que j'ai installé moi-même parce que j'ai l'habitude de le mettre sur mes PC.
            0
            1. Modérateur
              Tu n'as pas la dernière version d'AntiVir car dans la dernière version, ils n'utilisent plus le nom "AntiVir".

              http://www.01net.com/operations/avira/

              --> Fais un examen rapide avec Malwarebytes' Anti-Malware (mets-le à jour avant), supprime tout ce qu'il trouve et poste le rapport :
              https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
              0
              1. Voici le rapport
                Malwarebytes Anti-Malware (Essai) 1.61.0.1400
                www.malwarebytes.org

                Version de la base de données: v2012.05.30.05

                Windows 7 x64 NTFS
                Internet Explorer 8.0.7600.16385
                packardbell :: PACKARDBELL-PC [administrateur]

                Protection: Activé

                30/05/2012 20:21:45
                mbam-log-2012-05-30 (20-21-45).txt

                Type d'examen: Examen rapide
                Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
                Options d'examen désactivées: P2P
                Elément(s) analysé(s): 204587
                Temps écoulé: 2 minute(s), 7 seconde(s)

                Processus mémoire détecté(s): 0
                (Aucun élément nuisible détecté)

                Module(s) mémoire détecté(s): 0
                (Aucun élément nuisible détecté)

                Clé(s) du Registre détectée(s): 0
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre détectée(s): 0
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre détecté(s): 0
                (Aucun élément nuisible détecté)

                Dossier(s) détecté(s): 0
                (Aucun élément nuisible détecté)

                Fichier(s) détecté(s): 0
                (Aucun élément nuisible détecté)

                (fin)
                0
                1. Modérateur
                  Plus de souci ?

                  Je voudrais un nouveau rapport ZHPDiag.
                  0
                  1. Modérateur
                    As-tu bien lancé ZHPDiag en tant qu'administrateur ?
                    0
                    1. Bonjour,
                      Il me semble oui, parceque lorsque je lance le programme un message me demande si je veux l'ouvrir ou non?
                      Pourquoi, est-ce que le rapport a un problème?
                      0
                      1. Modérateur
                        Oui, il manque des choses.

                        "(Sous Vista/Win7, il faut cliquer droit sur le raccourci de ZHPDiag et choisir Exécuter en tant qu'administrateur)"
                        0
                        1. Modérateur
                          Le rapport est complet cette fois-ci.

                          --> Copie tout le texte présent en gras ci-dessous (Sélectionne-le, clique droit dessus et choisis "Copier").

                          SysRestore
                          O2 - BHO: Ask Toolbar BHO [64Bits] - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask - Avira SearchFree Toolbar.) -- C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
                          OPT:O4 - HKLM\..\Wow6432Node\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files (x86)\QuickTime\QTTask.exe
                          O4 - HKLM\..\Wow6432Node\Run: [ApnUpdater] . (.Ask - Ask Updater.) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe
                          [MD5.BB92A5F10D76140569216E8C4D67115A] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files (x86)\Ask.com\UpdateTask.exe
                          [MD5.00000000000000000000000000000000] [APT] [{2DE57B22-9AC9-44CC-B705-7DA130F86BD9}] (...) -- C:\Users\packardbell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0IIY3Z2W\eMule0.49b-Installer1[1].exe (.not file.)
                          [MD5.00000000000000000000000000000000] [APT] [{9BE3EFC2-3218-43EC-876A-370AFAD82750}] (...) -- C:\Program Files (x86)\Packard Bell GameZone\Airport Mania First Flight\Uninstall.exe (.not file.)
                          O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE}
                          [HKCU\Software\AppDataLow\Software\AskToolbar]
                          [HKCU\Software\AppDataLow\Software\Smartbar]
                          [HKLM\Software\APN]
                          [HKLM\Software\AskToolbar]
                          [HKLM\Software\TelevisionFanaticEI]
                          O43 - CFD: 30/05/2012 - 20:40:02 - [3,989] ----D C:\Program Files (x86)\Ask.com
                          O43 - CFD: 09/04/2012 - 18:24:24 - [0] ----D C:\Program Files (x86)\iMesh Applications
                          O43 - CFD: 10/03/2012 - 22:00:38 - [0,238] ----D C:\Program Files (x86)\TelevisionFanaticEI
                          O43 - CFD: 18/03/2012 - 20:31:00 - [0,004] ----D C:\ProgramData\0294
                          O43 - CFD: 30/05/2012 - 20:39:31 - [0,157] ----D C:\Users\packardbell\AppData\Local\APN
                          O43 - CFD: 30/05/2012 - 20:39:49 - [0,871] ----D C:\Users\packardbell\AppData\Local\AskToolbar
                          O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} [DefaultScope] - (Search Results) - https://www.search.ask.com/web?l=dis&q=&o=APN10655A&apn_dtid=%5EBND101%5EYY%5EFR&shad=s_0048&gct=hp&apn_ptnrs=%5EAG5&d=101-0&lang=en&atb=sysid%3D101%3Auid%3D58c9331d816657ac%3Asrc%3Dhmp%3Ao%3DAPN10655A%3Atg%3D&p2=%5EAG5%5EBND101%5EYY%5EFR
                          [HKLM\Software\WOW6432Node\Classes\AppID\GenericAskToolbar.DLL]
                          [HKLM\Software\WOW6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}]
                          [HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
                          [HKLM\Software\WOW6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}]
                          [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}]
                          [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}]
                          [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}]
                          [HKLM\Software\WOW6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}]
                          [HKLM\Software\WOW6432Node\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}]
                          [HKLM\Software\WOW6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}]
                          [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
                          [HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
                          [HKLM\Software\WOW6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}]
                          [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}]
                          [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}]
                          [HKLM\Software\WOW6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}]
                          [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
                          [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a}]
                          [HKCU\Software\APN]
                          [HKLM\Software\WOW6432Node\APN]
                          [HKCU\Software\Ask.com]
                          [HKCU\Software\Ask.com]
                          [HKCU\Software\AskToolbar]
                          [HKCU\Software\AppDataLow\Software\AskToolbar]
                          [HKLM\Software\WOW6432Node\AskToolbar]
                          [HKCU\Software\iMesh]
                          [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}]
                          [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440}
                          C:\Program Files (x86)\Ask.com
                          C:\Program Files (x86)\iMesh Applications
                          C:\Users\packardbell\AppData\Local\AskToolbar
                          C:\Users\packardbell\AppData\LocalLow\AskToolbar
                          C:\Users\packardbell\AppData\Local\Temp\AskSearch
                          C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
                          EmptyFlash
                          EmptyTemp


                          --> Puis lance ZHPFix depuis le raccourci situé sur ton Bureau.
                          (Sous Vista/Win7, il faut cliquer droit sur le raccourci de ZHPFix et choisir Exécuter en tant qu'administrateur)

                          --> Une fois ZHPFix ouvert, clique sur le bouton "H" (Coller les lignes Helper).

                          --> Dans l'encadré principal, tu verras donc les lignes que tu as copié précédemment apparaître. Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

                          --> Clique sur "GO" pour lancer le nettoyage. Laisse l'outil travailler et ne touche à rien.

                          --> Une fois terminé, copie-colle le rapport dans ton prochain message.
                          0
                          1. Voila le rapport,
                            Rapport de ZHPFix 1.2.06 par Nicolas Coolman, Update du 17/05/2012
                            Fichier d'export Registre : C:\ZHP\ZHPExportRegistry-31-05-2012-17-25-51.txt
                            Run by packardbell at 31/05/2012 17:25:51
                            Windows 7 Home Premium Edition, 64-bit (Build 7600)
                            Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
                            Web site : http://nicolascoolman.skyrock.com/

                            ========== Logiciel(s) ==========
                            ABSENT Software Key: {86D4B82A-ABED-442A-BE86-96357B70F4FE}

                            ========== Processus mémoire ==========
                            SUPPRIME Reboot Memory Process: C:\Program Files (x86)\Ask.com\UpdateTask.exe

                            ========== Clé(s) du Registre ==========
                            ABSENT Key: CLSID BHO: {D4027C7F-154A-4066-A1AD-4243D8127440}
                            SUPPRIME Key*: HKCU\Software\AppDataLow\Software\AskToolbar
                            ABSENT Key: HKCU\Software\AppDataLow\Software\Smartbar
                            ABSENT Key: HKLM\Software\APN
                            ABSENT Key: HKLM\Software\AskToolbar
                            ABSENT Key: HKLM\Software\TelevisionFanaticEI
                            ABSENT SearchScopes :{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Classes\AppID\GenericAskToolbar.DLL
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
                            SUPPRIME Key: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
                            ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
                            ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
                            ABSENT Key: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
                            SUPPRIME Key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
                            SUPPRIME Key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
                            SUPPRIME Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
                            ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a}
                            ABSENT Key: HKCU\Software\APN
                            ABSENT Key: HKLM\Software\WOW6432Node\APN
                            ABSENT Key: HKCU\Software\Ask.com
                            SUPPRIME Key*: HKCU\Software\AskToolbar
                            SUPPRIME Key: HKLM\Software\WOW6432Node\AskToolbar
                            ABSENT Key: HKCU\Software\iMesh
                            ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}

                            ========== Valeur(s) du Registre ==========
                            ABSENT RunValue: QuickTime Task
                            ABSENT RunValue: ApnUpdater
                            ABSENT [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440}

                            ========== Dossier(s) ==========
                            SUPPRIME Reboot Folder**: C:\Program Files (x86)\Ask.com
                            SUPPRIME Reboot Folder**: C:\Program Files (x86)\iMesh Applications
                            SUPPRIME Reboot Folder**: C:\Program Files (x86)\TelevisionFanaticEI
                            ABSENT C:\ProgramData\0294
                            ABSENT C:\Users\packardbell\AppData\Local\APN
                            SUPPRIME Folder: C:\Users\packardbell\AppData\Local\AskToolbar
                            SUPPRIME Folder: c:\users\packardbell\appdata\locallow\asktoolbar
                            SUPPRIME Flash Cookies:
                            SUPPRIME Temporaires Windows:

                            ========== Fichier(s) ==========
                            SUPPRIME Reboot c:\program files (x86)\ask.com
                            ABSENT Folder/File: c:\users\packardbell\appdata\local\microsoft\windows\temporary internet files\content.ie5\0iiy3z2w\emule0.49b-installer1
                            ABSENT Folder/File: c:\users\packardbell\appdata\local\asktoolbar
                            ABSENT Folder/File: c:\users\packardbell\appdata\local\temp\asksearch
                            ABSENT Folder/File: c:\windows\system32\tasks\scheduled update for ask toolbar
                            SUPPRIME Flash Cookies:
                            SUPPRIME Temporaires Windows:

                            ========== Tache planifiée ==========
                            SUPPRIME Task: Scheduled Update for Ask Toolbar
                            SUPPRIME Task: {2DE57B22-9AC9-44CC-B705-7DA130F86BD9}
                            SUPPRIME Task: {9BE3EFC2-3218-43EC-876A-370AFAD82750}

                            ========== Restauration Système ==========
                            Point de restauration non crée

                            ========== Récapitulatif ==========
                            1 : Processus mémoire
                            32 : Clé(s) du Registre
                            3 : Valeur(s) du Registre
                            9 : Dossier(s)
                            7 : Fichier(s)
                            1 : Logiciel(s)
                            3 : Tache planifiée
                            1 : Restauration Système

                            End of clean in 00mn 10s

                            ========== Chemin de fichier rapport ==========
                            C:\ZHP\ZHPFix[R1].txt - 31/05/2012 16:24:11 [5081]
                            C:\ZHP\ZHPFix[R2].txt - 31/05/2012 17:25:51 [5076]
                            0
                            1. Modérateur
                              ZHPFix a bien été lancé en tant qu'administrateur aussi ?
                              0
                              1. Oui, je l'ai lancé avec administrateur, par contre j'ai eu un message "le point restauration début et fin n'est pas trouvé"
                                Faut-il recommencé....
                                0
                                1. Modérateur
                                  Je voudrais un nouveau rapport ZHPDiag.
                                  0
                                  • 1
                                  • 2