PC infecté par worm.win32.autorun.spw ?

Bonjour, depuis quelque jour je rencontre des problèmes avec mon pc, j'utilise l'antivirus ORANGE (f-secure) qui me détecte sans arret le virus suivant : worm.win32.autorun.spw.
L'antivirus me demande de le nettoyer mais en vain, le problème persiste.....
Lors de mes recherche sur internet, je suis sans arret redirigé vers d'autres site, et les pages internet defile de haut en bas sans arret à me donner mal à la tête....
J'utilise egalement Ccleaner......

Pourriez vous me donner les démarches a suivre, je ne trouve que des sites en anglais sur ce virus !!!

Encore merci et bonnes fêtes..........
Configuration: Windows XP
Internet Explorer 6.0

9 réponses

  1. Contributeur sécurité
    non garde internet explorer 6 car windows n'utilise que lui pour se mettre a jour

    vire ce qui a été trouve par malwarebyte

    puis

    télécharge combofix (par sUBs) ici :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    et enregistre le sur le bureau.

    déconnecte toi d'internet et ferme toutes tes applications.

    désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

    double-clique sur combofix.exe et suis les instructions

    à la fin, il va produire un rapport C:\ComboFix.txt

    réactive ton parefeu, ton antivirus, la garde de ton antispyware

    copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

    Tu as un tutoriel complet ici :

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
    0
    1. Contributeur sécurité
      mets firefox ici:

      http://www.mozilla-europe.org/fr/firefox/

      pour malwarebyte ici:
      http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebytes anti malware

      pour mettre a jour windows: DEMARRER puis TOUS LES PROGRAMMES puis WINDOWS UPDATE et suivre la procedure
      0
      1. Encore merci je viens d'installer firefox qui fonctionne correctement ainsi que la mise a jour de windows, par contre je dois supprimer internet explorer6 ou pas ?

        Voici le rapport de malwarebyte, il me semble que le pc soit encore infecté....

        Malwarebytes' Anti-Malware 1.31
        Version de la base de données: 1578
        Windows 5.1.2600 Service Pack 2

        30/12/2008 20:36:58
        mbam-log-2008-12-30 (20-36-44).txt

        Type de recherche: Examen complet (C:\|D:\|J:\|)
        Eléments examinés: 134052
        Temps écoulé: 1 hour(s), 4 minute(s), 38 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 1
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 6

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_CLASSES_ROOT\videosoft (Trojan.DNSChanger) -> No action taken.

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        C:\Program Files\Everest Poker\var\Everest Casino.exe (Rogue.AdorableCasino) -> No action taken.
        C:\WINDOWS\system32\msqpdxymxxtfnd.dll (Trojan.TDSS) -> No action taken.
        C:\WINDOWS\system32\drivers\msqpdxltxjikha.sys (Trojan.Agent) -> No action taken.
        C:\WINDOWS\system32\drivers\msqpdxujhioetl.sys (Trojan.Agent) -> No action taken.
        C:\WINDOWS\system32\drivers\msqpdxvorsgvnt.sys (Trojan.Agent) -> No action taken.
        C:\WINDOWS\system32\drivers\msqpdxvsewsrfw.sys (Trojan.Agent) -> No action taken.
        0
    2. Une fois sur le site il m'est impossible de charger l'aplication il ne trouve pas la page ou alors je tombe sur le moteur de recherche.
      Je veux bien utiliser firefox, a partir du moment ou je suis moins embeter et comment faire pour mettre à jour windows avec le sp3?
      0
      1. Contributeur sécurité
        ok les clés sont clean

        fais ceci pour verifier

        télécharge malwarebyte mets le a jour et colle un rapport avec :

        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        ______________

        pour internet explorer il faudrait sinon navigue avec firefox ou opera ou safari moins touchés pasr les infections surtout si internet explorer non a jour: on verra a la fin pour tenter de mettre internet explorer 7 ou sinon mets internet explorer 8: en version beta 2:

        https://www.microsoft.com/en-us/windows/

        _________________

        et il faut aussi mettre windows a jour avec le sp3
        0
        1. Contributeur sécurité
          c'est pas le bon rapport usbfix tu peut refaire pour voir?

          puis

          colle un scan en ligne avec un des deux suivants:

          bitdefender en ligne :
          http://www.bitdefender.fr/scan_fr/scan8/ie.html

          Panda en ligne :
          http://pandasoftware.fr

          pour internet explorer on verra après
          0
          1. Voici le nouveau rapport Usbfix qui doit etre le bon, ainsi que le rapport du scan effectué par activescan qui suite au scan à detecter 1 virus et qui me l'a apparement désinfecter.
            Les disques dur sont t'il vraiment désinfecter ?
            Que dois-je faire pour internet explorer ? Est t'il important de télécharger la derniere version ?

            Usbfix

            -------------- UsbFix V2.413.8 ---------------

            * User : HP_Propri‚taire - NOM-641695C7437
            * Outils mis a jours le 27/12/2008 par Chiquitine29 et Chimay8
            * Recherche effectuée à 16:55:36 le 30/12/2008
            * Windows Xp - Internet Explorer 6.0.2900.2180

            --------------- [ Processus actifs ] ----------------

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\logonui.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\userinit.exe
            C:\WINDOWS\Explorer.EXE

            --------------- [ Informations lecteurs ] ----------------

            C: - Lecteur fixe

            D: - Lecteur fixe

            E: - Lecteur de CD-ROM

            J: - Lecteur fixe

            +- Contenu de l'autorun : C:\autorun.inf

            [autorun]
            ;fieixyjuwtc
            shellexecute="resycled\boot.com c:"
            ;ohoqjnhvscwjqtqsommjnsadngdvbrogdeirwfmizaxtpzbszrvyhgwevkwiqkwnzvmistsuqzkqhbmhfnfdke
            shell\Open\command="resycled\boot.com c:"
            ;qdahycrwicbaevnmlzdprrcnlciufakpfcxhwvagxayggyuosjsc
            shell=

            +- Contenu de l'autorun : D:\autorun.inf

            [autorun]
            ;nflwclhcidnuezyxkonxmnsgarpjqligsatdtqidjyhizssxnftqcntrzersajyjc
            shellexecute="resycled\boot.com d:"
            ;szicfkuutwakdribnraeuditkmzt
            shell\Open\command="resycled\boot.com d:"
            ;zxyrsirqymaklejees
            shell=Open
            ;utisvjkaxqmcrffherlpfzxwkgimimm

            +- Contenu de l'autorun : J:\autorun.inf

            [autorun]
            ;dgnvyrohrjiwphoipftpzxesgirhcbuyzgpdamhticaxskkt
            shellexecute="resycled\boot.com j:"
            ;zcenlaxm
            shell\Open\command="resycled\boot.com j:"
            ;objsglpbjlzkveyczanxjcjdovnirqjsctyrjcallyudgaoheffojqmjxreqqexewnbyjhsesre
            shell=Open
            ;awonuvzxkln

            --------------- [ Lecteur C ] ----------------

            C: - Lecteur fixe

            +- Listing des fichiers présents :

            [01/01/2004 14:06][--a------] C:\AUTOEXEC.BAT
            [05/08/2004 04:00][-rahs----] C:\NTDETECT.COM
            [29/12/2008 11:11][-rahs----] C:\boot.ini
            [30/12/2008 16:19][-r-hs----] C:\autorun.inf
            [29/12/2008 23:05][--a------] C:\log_lobby.txt
            [29/12/2008 23:05][--a------] C:\log_lobby_dumper.txt
            [29/12/2008 23:05][--a------] C:\UsbFix.txt
            [01/01/2004 14:06][--a------] C:\CONFIG.SYS
            [01/01/2004 14:06][--a------] C:\hiberfil.sys
            [01/01/2004 14:06][--a------] C:\IO.SYS
            [01/01/2004 14:06][--a------] C:\MSDOS.SYS
            [01/01/2004 14:06][--a------] C:\pagefile.sys

            --------------- [ Lecteur D ] ----------------

            D: - Lecteur fixe

            +- Listing des fichiers présents :

            [27/07/2001 22:07][---hs----] D:\AUTOEXEC.BAT
            [25/07/2001 14:00][---hs----] D:\NTDETECT.COM
            [30/04/2004 14:00][---hs----] D:\Info.exe
            [30/04/2004 14:00][---hs----] D:\setupSNK.exe
            [09/01/2002 11:52][---hs----] D:\BOOT.INI
            [09/01/2002 11:52][---hs----] D:\Desktop.ini
            [09/01/2002 11:52][---hs----] D:\WINBOM.INI
            [30/12/2008 16:20][-r-hs----] D:\autorun.inf
            [10/09/2002 09:21][---hs----] D:\Folder.htt
            [27/07/2001 22:07][---hs----] D:\CONFIG.SYS
            [27/07/2001 22:07][---hs----] D:\IO.SYS
            [27/07/2001 22:07][---hs----] D:\MSDOS.SYS
            [27/07/2001 22:07][---hs----] D:\RCBoot.sys

            --------------- [ Lecteur E ] ----------------

            E: - Lecteur de CD-ROM

            +- Listing des fichiers présents :

            --------------- [ Lecteur J ] ----------------

            J: - Lecteur fixe

            +- Listing des fichiers présents :

            [07/03/2001 19:11][--a------] J:\WINWORD.EXE
            [30/12/2008 16:20][-r-hs----] J:\autorun.inf

            --------------- [ Registre / Startup ] ----------------

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Search Page"="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop"
            "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
            hpsysdrv=c:\windows\system\hpsysdrv.exe
            HPHUPD06=c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
            HPHmon06=C:\WINDOWS\system32\hphmon06.exe
            KBD=C:\HP\KBD\KBD.EXE
            Home Theater SchSvr="C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
            WINREMOTE="C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
            iTunesHelper=C:\Program Files\iTunes\iTunesHelper.exe
            Recguard=C:\WINDOWS\SMINST\RECGUARD.EXE
            NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            nwiz=nwiz.exe /installquiet /keeploaded /nodetect
            VTTimer=VTTimer.exe
            SiS Windows KeyHook=C:\WINDOWS\system32\keyhook.exe
            PS2=C:\WINDOWS\system32\ps2.exe
            SSC_UserPrompt=c:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
            AGRSMMSG=AGRSMMSG.exe
            AlcxMonitor=ALCXMNTR.EXE
            Reminder="C:\Windows\Creator\Remind_XP.exe"
            ORAHSSSessionManager=C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
            F-Secure Manager="C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
            F-Secure TNB="C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
            Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
            <NO NAME>=
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
            Installed=1
            <NO NAME>=
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
            NoChange=1
            Installed=1
            <NO NAME>=
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
            Installed=1
            <NO NAME>=

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveTypeAutoRun"=dword:00000091

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

            --------------- [ Registre / Mountpoint2 ] ----------------

            -> Recherche négative.

            --------------- [ Nettoyage des disques ] ----------------

            C:\autorun.inf ~> fichier appelé : "C:\"resycled\boot.com c:"" ( absent ! )
            D:\autorun.inf ~> fichier appelé : "D:\"resycled\boot.com d:"" ( absent ! )
            J:\autorun.inf ~> fichier appelé : "J:\"resycled\boot.com j:"" ( absent ! )
            Supprimé ! - [30/12/2008 16:19][-r-hs----] C:\autorun.inf
            Supprimé ! - [20/12/2008 19:12][-r-hs----] C:\resycled\boot.com
            Supprimé ! - [30/12/2008 16:55][dr-hs----] C:\resycled
            Supprimé ! - [30/12/2008 16:20][-r-hs----] D:\autorun.inf
            Supprimé ! - [10/09/2002 09:21][---hs----] D:\Folder.htt
            Supprimé ! - [30/04/2004 14:00][---hs----] D:\info.exe
            Supprimé ! - [20/12/2008 19:12][-r-hs----] D:\resycled\boot.com
            Supprimé ! - [24/12/2008 12:16][dr-hs----] D:\resycled
            Supprimé ! - [30/12/2008 16:20][-r-hs----] J:\autorun.inf
            Supprimé ! - [20/12/2008 19:12][-r-hs----] J:\resycled\boot.com
            Supprimé ! - [17/10/2007 22:59][--ahs----] J:\THUMBS.DB
            Supprimé ! - [24/12/2008 12:16][dr-hs----] J:\resycled

            --------------- [ Resumé ] ----------------

            -> /!\ Le resultat doit etre interprété par un spécialiste /!\

            [01/01/2004 14:06][--a------] C:\AUTOEXEC.BAT
            [05/08/2004 04:00][-rahs----] C:\NTDETECT.COM
            [29/12/2008 11:11][-rahs----] C:\boot.ini
            [27/07/2001 22:07][---hs----] D:\AUTOEXEC.BAT
            [25/07/2001 14:00][---hs----] D:\NTDETECT.COM
            [04/08/2004 00:55][--a------] D:\setupSNK.exe
            [09/01/2002 11:52][---hs----] D:\BOOT.INI
            [09/01/2002 11:52][---hs----] D:\Desktop.ini
            [09/01/2002 11:52][---hs----] D:\WINBOM.INI
            [07/03/2001 19:11][--a------] J:\WINWORD.EXE

            --------------- ! Fin du rapport ! ----------------

            Activescan

            ;***********************************************************************************************************************************************************************************
            ANALYSIS: 2008-12-30 18:05:42
            PROTECTIONS: 2
            MALWARE: 1
            SUSPECTS: 0
            ;***********************************************************************************************************************************************************************************
            PROTECTIONS
            Description Version Active Updated
            ;===================================================================================================================================================================================
            F-Secure Antivirus 7.44 No Yes
            F-Secure Internet Security 6.16 No No
            ;===================================================================================================================================================================================
            MALWARE
            Id Description Type Active Severity Disinfectable Disinfected Location
            ;===================================================================================================================================================================================
            02919763 Trj/Downloader.MDW Virus/Trojan No 0 Yes No J:\System Volume Information\_restore{A51C5CDE-3710-45ED-AEAF-4DBEE7E77752}\RP5\A0001156.EXE
            ;===================================================================================================================================================================================
            SUSPECTS
            Sent Location V
            ;===================================================================================================================================================================================
            ;===================================================================================================================================================================================
            VULNERABILITIES
            Id Severity Description V
            ;===================================================================================================================================================================================
            184380 MEDIUM MS08-002 V
            184379 MEDIUM MS08-001 V
            182048 HIGH MS07-069 V
            182046 HIGH MS07-067 V
            182043 HIGH MS07-064 V
            179553 HIGH MS07-061 V
            176382 HIGH MS07-057 V
            176383 HIGH MS07-058 V
            170911 HIGH MS07-050 V
            170907 HIGH MS07-046 V
            170906 HIGH MS07-045 V
            170904 HIGH MS07-043 V
            164915 HIGH MS07-035 V
            164913 HIGH MS07-033 V
            164911 HIGH MS07-031 V
            160623 HIGH MS07-027 V
            157262 HIGH MS07-022 V
            157261 HIGH MS07-021 V
            157260 HIGH MS07-020 V
            157259 HIGH MS07-019 V
            156477 HIGH MS07-017 V
            150253 HIGH MS07-016 V
            150249 HIGH MS07-013 V
            150248 HIGH MS07-012 V
            150247 HIGH MS07-011 V
            150243 HIGH MS07-008 V
            150242 HIGH MS07-007 V
            150241 MEDIUM MS07-006 V
            141034 HIGH MS06-076 V
            141033 MEDIUM MS06-075 V
            141030 HIGH MS06-072 V
            137571 HIGH MS06-070 V
            137568 HIGH MS06-067 V
            133387 MEDIUM MS06-065 V
            133386 MEDIUM MS06-064 V
            133385 MEDIUM MS06-063 V
            133379 HIGH MS06-057 V
            131654 HIGH MS06-055 V
            129977 MEDIUM MS06-053 V
            129976 MEDIUM MS06-052 V
            126093 HIGH MS06-051 V
            126092 MEDIUM MS06-050 V
            126087 HIGH MS06-046 V
            126086 MEDIUM MS06-045 V
            126083 HIGH MS06-042 V
            126082 HIGH MS06-041 V
            126081 HIGH MS06-040 V
            123421 HIGH MS06-036 V
            123420 HIGH MS06-035 V
            120825 MEDIUM MS06-032 V
            120823 MEDIUM MS06-030 V
            120818 HIGH MS06-025 V
            120815 HIGH MS06-022 V
            120814 HIGH MS06-021 V
            117384 MEDIUM MS06-018 V
            114666 HIGH MS06-015 V
            114664 HIGH MS06-013 V
            108744 MEDIUM MS06-008 V
            108743 MEDIUM MS06-007 V
            108742 MEDIUM MS06-006 V
            104567 HIGH MS06-002 V
            104237 HIGH MS06-001 V
            96574 HIGH MS05-053 V
            93395 HIGH MS05-051 V
            93394 HIGH MS05-050 V
            93454 MEDIUM MS05-049 V
            ;===================================================================================================================================================================================
            0
        2. PAR CONTRE ikl m'est impossible de mettre a jour interner explorer 7, lors de l'instalation il me demande de redémarrer le PC car l'instalation a échoué, je doit donc utiliser le raccourci, met leur méthode m'ont l'air bien compliqué, il me demande de démarre le PC en mode minimal pour pouvoir l'installer. Est ce normal ?

          Voici le lien du raccourci :
          https://support.microsoft.com/en-us/help/917925
          0
          1. Voici les résultat pourL'aplication USBfix : changelog Usbfix

            Changelog UsbFix établit le 2 decembre 2008
            outils créé par Chiquitine29 , aide aux mises a jours -> Chimay8

            >>>>>>in "ProgramFiles"<<<<<<<<<

            Internet Explorer\Connection Wizard\icwconn1\rada
            Internet Explorer\Connection Wizard\icwconn1\rade
            Internet Explorer\Connection Wizard\icwconn1\radf
            Internet Explorer\Connection Wizard\icwconn1\rad5
            Internet Explorer\Connection Wizard\icwconn1\rad0
            Internet Explorer\Connection Wizard\icwconn1\rad9
            Internet Explorer\Connection Wizard\icwconn1\rad4
            Internet Explorer\Connection Wizard\icwconn1\rad1
            Internet Explorer\Connection Wizard\icwconn1
            Movie Maker\explorer.exe
            Internet Explorer\explorer.exe

            >>>>>>in "Windows"<<<<<<<<<

            autorun.inf
            autorun.exe
            autorun.vbs
            autorun.reg
            autorun.ini
            autorun.fcb
            autorun.bat
            autorun.com
            AdobeR.exe
            Alecks.vbs
            bittorrent.exe
            cmd32.exe
            CwbRmDir.bat
            Fonts\Fonts.exe
            FS6519.dll.vbs
            funny.exe
            GMOGLFEO.exe
            hiqalowo.inf
            icapy.scr
            ilezyvu.bin
            Lany.vbs
            lumy.exe
            manulopa.reg
            MS32DLL.dll.vbs
            MyMP3.vbs
            nar.vbs
            osok.inf
            osotilasiq.pif
            oxafa.com
            qobo.dat
            rundll32.vbe
            sleep.vbe
            SysRes.vbs
            takice.lib
            tusoha.exe
            unahafiwik.exe
            waol.exe
            waziqepehi.ban
            WillPolo.vbs
            Win32DLL.vbs
            win.vbe
            window.exe
            wyzeha.com
            xcopy.exe
            yjilu.inf
            ylacupyb.dll

            RECYCLER\systems.com

            temp\039.tmp

            >>>>>>in "Windows\system32"<<<<<<<<<

            agucuri.vbs
            ahr.exe
            Alecks.vbs
            antinul.vbe
            amvo.exe
            amvo0.dll
            amvo1.dll
            amvo2.dll
            autorun.bat
            Autorun.com
            autorun.exe
            autorun.fcb
            autorun.inf
            autorun.ini
            autorun.reg
            autorun.vbs
            Autoruns.exe
            avpo.exe
            avpo0.dll
            avpo1.dll
            Bitkvo.exe
            Bitkv0.dll
            Bitkv1.dll
            cftmonn.exe
            Christina.jpg
            Christina.vbs
            ckvo.exe
            ckvo0.dll
            ckvo1.dll
            ckvo2.dll
            cradle_of_filth.vbe
            delself.bat
            FS6519.dll.vbs
            GMOGLFEO.exe
            icf.exe.exe
            ie.exe
            jvvo.exe
            jvvo0.dll
            jvvo1.dll
            jvvo2.dll
            jvvo3.dll
            j3ewro.exe
            jwedsfdo0.dll
            jwedsfdo1.dll
            jwedsfdo2.dll
            jwedsfdo3.dll
            jxnraqjxg.exe
            kavo.exe
            kamsoft.exe
            kav0.dll
            kav1.dll
            kav2.dll
            kav3.dll
            kavo0.dll
            kavo1.dll
            kavo2.dll
            kavo3.dll
            kdkfm.exe
            KEYBOARD.exe
            keygen.exe
            kulitut.bat
            kulitut.vbs
            kxvo.exe
            kxvo0.dll
            kxvo1.dll
            kxvo2.dll
            kxvo3.dll
            lExplore.exe
            loader.exe
            logoneui.exe
            LOVE-LETTER-FOR-YOU.HTM
            LOVE-LETTER-FOR-YOU.TXT.vbs
            msfun80.exe
            msime82.exe
            MSKernel32.vbs
            ne0kS.dll.wsf
            ne0kS.exe
            OeApi.vbs
            pubnet.vbs
            rs32net.exe
            SemiAntiVirus.vbs
            Sexy Girls.scr
            SpiderH.bmp
            SpiderH.jpeg
            SpiderH.vbs
            sys.vbs
            Syso.vbs
            SysRes.vbs
            syx.exe
            taso.exe
            tavo.exe
            tavo0.dll
            tavo1.dll
            tavo2.dll
            tavo3.dll
            temp1.exe
            temp2.exe
            temp?.exe
            text.txt
            Ecran.exe
            THe Girls
            tmp.reg
            tmp.txt
            t.txt
            vb@dock.vbs
            vl@dock.vbs
            Win32.vbs
            winudp64.exe

            dllcache\Default.exe

            >>>>>>in "Windows\system32\drivers"<<<<<<<<<

            ._Sanaa style-1 les formes.exe
            0hct8ybw.exe
            1ere partie du projet modifier.exe
            abdelali lahrach.exe
            Analyse transactionnelle.exe
            AutoRun.exe
            Bernoulli01215.exe"
            Cahiers français Quels modes de financement pour les entreprises - La Documentation française.exe
            Copie de Devoir I.exe
            e-ticket Juba Paris.exe
            fdfp2.exe
            fihi ghizlane Rapport de stage.exe
            graphic.exe
            intel.exe
            isew32.exe
            kheireddine.exe
            le_cadeau_du_sud(1).exe
            LEADERSHIP SKILLS FINAL.exe
            lettre de motivation.exe
            MSDS.exe
            Note.exe
            PREMIER CHAPITRE modifié.exe
            Raila Odinga.exe
            Rapport NADIA.exe
            spectro_masse1.exe
            td de reacteur.exe
            these-223.exe
            xyw9tmdj.exe

            >>>>>>in "Documents and Settings"<<<<<<<<<

            tazebama.dl_
            hook.dl_

            >>>>>>in "appdata"<<<<<<<<<

            fetomiv.vbs
            gumugy.vbs
            jicapikase.vbs
            mobyhikaja.vbs
            nebohozi.com
            orimuwy.exe
            sidymyvig.vbs
            tazebama\tazebama.log
            tazebama\zPharaoh.dat
            tazebama

            >>>>>>in "Temp files"<<<<<<<<<

            1.reg
            2.dll
            6257890.exe
            fq9.dll
            help.exe
            help1.rar
            inst.exe
            system.dll
            w2e.sys
            winhqqo.exe
            wintoift.exe
            xhjb.dll
            xxx6042.exe
            zb5ok.dll

            >>>>>>in "All Drives"<<<<<<<<<

            ._autorun.inf
            autorun.inf
            autorun.ini
            autorun.reg
            autorun.bat
            autorun.vbs
            autorun2.inf
            autosys.exe
            00hoeav.com
            096.bat
            0gjn3yw.exe
            0qx0sc6.bat
            0tmhoc.cmd
            0u.cmd
            0w.com
            0wk2.cmd
            108i.cmd
            1aq1obb.bat
            1bbvq96y.com
            1dg.exe
            1i.com
            1nkbd8h.bat
            1rfw8hjr.com
            1u0o8bnq.cmd
            1weicxa.com
            1XXEC.exe
            22xo.exe
            2ifetri.cmd
            2y8la.exe
            30ed3.exe
            33gmhso.bat
            39lpji.com
            3o.exe
            3wcxx91.cmd
            3xXx31.exe
            4vzjaw3o.sys
            62oop0ak.bat
            68.exe
            6tkoyhx.cmd
            6x8be16.cmd
            8e9gmih.bat
            8ng8w.com
            93vx0c.com
            9yqusig.bat
            22wcb21o.exe
            31n3b2h.exe
            39lpji.com
            80avp08.com
            82r9.cmd
            83fgj.com
            83l3v.cmd
            8df.exe >
            8h3hh3m.exe
            8tss2gwq.bat
            90imhpnc.exe
            92j11sm.com
            9es.com
            a1.bat
            a9.com
            abk.bat
            activexdebugger32.exe
            Administrateur_Fichiers.exe
            admp.exe
            adobeR.exe
            Akon.exe
            Alecks.vbs
            antihost.exe
            antinul.vbe
            aoutfq.exe
            ar.exe
            Atisetup.exe
            auto.exe
            autorum.exe
            AutoRun\Demo.exe
            autorun.exe
            autorun.pif
            autoruns.exe
            AutoScr.exe
            ay8p6v3.cmd
            Ayame.exe
            b3b9u.com
            bicsxk03.com
            bittorrent.exe
            bndafai.exe
            bo1dhu.bat
            bobm.exe
            boot.exe
            bootin.exe
            bplrl98.cmd
            buis.exe
            bwpncb6.com
            bxuup9r.bat c18vk.exe
            c9.com
            c9hehpa.bat
            camp.exe
            cayfq2.cmd
            cd8idoyl.com
            cdr.exe
            ceb6eu98.bat
            cekbru.pif
            clear.bat
            ClickMe.exe
            cftmonn.exe
            cfv90h.com
            Christina.vbs
            cjq.exe
            commands.txt
            comment.htt
            copetttt.com
            copy.exe
            cradle_of_filth.vbe
            cqdis.cmd
            cvqkuk.exe
            d3bn0j.exe
            ddyikr.cmd
            delautorun.bat
            DFD34719171.bat
            DFD34719375.bat
            DFD34719609.bat
            DFD34723328.bat
            DFD34723375.bat
            DFD34723781.bat
            DFD34724390.bat
            DFD34719609.bat
            DFD34724531.bat
            DFD34724656.bat
            DFD34725125.bat
            DFD34725218.bat
            DFD34726312.bat
            DFD34724390.bat
            DFD34726328.bat
            DFD34729609.bat
            DFD34730531.bat
            DFD34730937.bat
            DFD34734937.bat
            DFD34739859.bat
            DFD34741421.bat
            DFD34741734.bat
            DFD34741843.bat
            DFD*.bat
            dhv2u8.cmd
            DPFMate.exe
            dstart.exe
            dtqlv.exe
            dynrn6e.cmd
            e898.com
            e9ehn1m8.com
            eb9ehyh.exe
            Ecran.exe
            ek.com
            ekf6dbg0.com
            ekugb3.bat
            erdeIect.com
            esta ig.vbs
            ev60a2.cmd
            explorer.exe
            exqmmle.exe
            f0.cmd
            f2ir.com
            fe.bat
            ffojc.com
            fi.cmd
            FLIPART.EXE
            folder.exe
            Folder.htt
            fooool.exe
            Form5.exe
            forSV.exe
            FS6519.dll.vbs
            fucker.vbs
            fun.xls.exe
            g2p3s.exe
            g2pfnid.com
            g83816.com
            gdmae.bmp
            Ghost.pif
            gkyzcijfb.exe
            GMOGLFEO.exe
            gqsk.bat
            graphic.exe
            gsxlexd.cmd
            gxlxknou.exe
            gy.cmd
            h0s2.bat h2.com
            hfhludy.exe
            hgu.bat
            hni.cmd
            host.exe
            hsomklg.exe
            hxt9.bat
            i0.cmd
            i8.cmd
            ie.exe
            igxv.cmd
            ij.bat
            ilpg9ejd.com
            info.exe
            infrom.exe
            ino6.com
            install.exe
            intel.exe
            intro.exe
            ipy.cmd
            iq0ecwcj.cmd
            lsass.exe
            itsduel.exe
            iwjj.com
            j4c8t8b5l3a6.exe
            j8q8d.cmd
            jbfqv8j.cmd
            jdhc2x2.com
            jdwx.exe
            jfjsipw.exe
            jfvkcsy.bat
            jiwsxh39.exe
            JJJ.exe
            Jojo.exe
            jwwgtuh.exe
            jxnraqjxg.exe
            jxpiinstall.exe
            k6wkwon2.exe
            ka1nk.bat
            kaq86asx.bat
            kayira.bat
            kbqbptn.exe
            kdkfm.exe
            kdy.cmd
            kfmyoc.pif
            khbph.exe
            killVBS.vbs
            kk3.bat
            KM.exe
            kmd.exe
            kn6jhgc.cmd
            kqnns.exe
            kqsr.exe
            krg62.cmd
            kulitut.bat
            kulitut.vbs
            kxax.cmd
            l2f.cmd
            l9dwu8.bat
            lExplore.exe
            lgcadwx.bat
            lgrncie.bat
            lky.exe
            ln9.exe
            lo.exe
            loader.exe
            logoneui.exe
            Long.exe
            LOVE.PIF
            ltljrg.exe
            lumy.exe
            lurjlnps.exe
            lvxvo1xg.cmd
            m1t8ta.com
            m9j.com
            mail.exe
            manulopa.reg
            mcxa.exe
            Menu.exe
            mgjpcfdg.cm
            mnl6on3.com
            mp.bat
            mp.cmd
            mp.com
            Movie1.exe
            mrsne.bat
            MS-DOS.com
            MS32DLL.dll.vbs
            MSd040.vbs
            MSdC64.vbs
            MSdFB7.vbs
            MSd141.vbs
            MSd191.vbs
            MSd49A.vbs
            MSdE78.vbs
            MSd*.vbs
            mshta.exe
            MSKernel32.vbs
            muniu.exe
            MyMP3.vbs
            n1detect.com
            n2de.cmd
            n6j.com
            n6j6pc0.com
            n6t1h.cmd
            nansy ajram.vbs
            nar.vbs
            ne0kS.exe
            nemesis.exe
            nemesis.inf
            nfdmg.com
            nideiect.com
            niu.exe
            njibyekk.com
            nl.com
            nncu6kk.com
            NoLimit.exe
            np.exe
            nq0cq.cmd
            nqvarn.pif
            nriljal.exe
            ntde1ect.com
            ntdelect.com
            nq.bat
            nq0cq.cmd
            nqgcd.com
            nsv.bat
            nw0t1l0d.exe
            o2yf0w.bat
            o9o2u.bat
            o6opnro.bat
            OeApi.vbs
            oegbi.exe
            ogcikeq.com
            oka3yrf.bat
            oq.cmd
            oskkofa.exe
            osotilasiq.pif
            osy3.sys
            otyh.cmd
            oufddh.exe
            oxafa.com
            p3r1ud.exe
            p83gjy.exe
            p9.exe
            pa39xth.cmd
            pagefile.pif
            pbwkwj.com
            pefbutr.exe
            pkxfkrki.bat
            ph.com
            phgr1j.bat
            phim_nguoi_lon.exe
            pnc.exe
            prhyper.exe
            psqrhqn.exe
            pxka.exe
            q3v.com
            q83iwmgf.bat
            q8sywiva.cmd
            qcwpung.exe
            qd.cmd
            qjfl.exe
            qkarc.exe
            qquq.bat
            qqzjnhuoi.exe
            qpe6.com
            qobo.dat
            qrkugxtw.exe
            qxbx9blb.com
            r1y1.bat
            r2nl.com
            r6r.exe
            r813.bat
            Raila Odinga.exe
            Raila Odinga.gif
            ranvrgn.exe
            ravmon.exe
            ravmon.log
            ReadMe.exe
            RecInfo\RecInfo.exe
            Recycle.exe
            Recycled\ctfmon.exe
            RECYCLED\INFO.exe
            Recycled.exe
            RECYCLER\Lock Folder.exe
            RECYCLER\RECYCLER.exe
            RECYCLER\*.exe
            regxpcom.exe
            resycled\boot.com
            resycled\ctfmon.exe
            revo.exe
            rggbw.exe
            rjiybg.exe
            rn.exe
            rombkaewl.exe
            rosftpm.exe
            rqq2v.bat
            rs.cmd
            rt.exe
            Run.exe
            runaut~1\autorun.pif
            RunDll32.exe
            rxukgcm.exe
            s38k.exe
            sal.xls.exe
            sasyg1y8.com
            script.bat
            scriptlo.txt
            scvhosts.exe
            sdcvhost.exe
            SemiAntiVirus.vbs
            smkjd.cmd
            smss.exe
            semo2x.exe
            spq.bat
            serivces.exe
            server.exe
            server.inf
            Sex City.jpg.wsf
            sowar.vbs
            SpiderH.vbs
            sq.com
            sqlserv.exe
            SSVICHOSST.exe
            stwi.com
            svch0st.exe
            scvhosts.exe
            svdioajm.cmd
            sxs.exe
            sydp.exe
            sys.vbs
            Syso.vbs
            SysRes.vbs
            system.exe
            system32.exe
            systems.com
            systems.exe
            t82e2v.cmd
            TAE7ESLP.exe
            taipingtianguov1.1.exe
            takice.lib
            tel.xls.exe
            temp.bat
            temp.exe
            temp.temp
            temp1.exe
            temp2.exe
            test.exe
            testfile.bat
            testflo.bat
            tfk8.exe
            The_Cars.vbs
            THe Girls
            tknapl.exe
            tknn6.bat
            tmf3w3g0.com
            TMMDW8LP.exe
            Toy.exe
            tusoha.exe
            tyktjfww.exe
            u18vxqle.com
            u6k.cmd
            u9dyi.exe
            udnnnvq.exe
            UFO.exe
            ufuaugwq.exe
            uis.com
            uis.exe
            um.cmd
            un9.cmd
            unahafiwik.exe
            UnplugDrive.exe
            uorys.cmd
            update.exe
            uqhqx1.cmd
            usdeiect.com
            userinit.exe
            utdetect.com
            uxdeiect.com
            u?de?ect.com
            v2h3.exe
            v3pif.bat
            VB6FR.DLL
            vb@dock.vbs
            vfpkkbq.exe
            vksucydrh.exe
            vl@dock.vbs
            vmhr.bat
            vmyphd.bat
            vva0hc0p.cmd
            vxl.exe
            w0o.com
            w0owgn.bat
            w32sys.exe
            w3dn9f.bat
            waziqepehi.ban
            wa6.vbs
            Wallpaper.vbs
            WallpaperMEHDI.vbs
            wfhth.exe
            whi.com
            WillPolo.vbs
            WINDOWS.EXE
            Windows.scr
            winfile.exe
            winglogon.exe
            winrun.vbs
            winstall.exe
            wjlfhtfm.cmd
            wol.exe
            wsctf.exe
            wtbcccq.exe
            x0.cmd
            XAdeIect.com
            xcopy.exe
            xfoolavp.com
            xih9.cmd
            xj.bat
            xk2n.bat
            xlk9.com
            xlu8a8sy.exe
            xmnm2.cmd
            xn1i9x.com
            xnynrnh.exe
            xo8wr9.exe
            xp19.com
            xpbkh.com
            xqf.com
            xvlyb.exe
            xyhav.pif
            y82td3td.com
            ybj8df.exe
            yew.bat
            yg.cmd
            yjilu.inf
            ylacupyb.dl
            ylr.exe
            yjkjfuo.cmd
            yjvmtaa.exe
            ynfs9ks.cmd
            yssjnngm.cmd
            yvmkdwn.exe
            zPharaoh.exe
            0.cmd
            1.cmd
            2.cmd
            3.cmd
            4.cmd
            5.cmd
            6.cmd
            7.cmd
            8.cmd
            9.cmd
            0.bat
            1.bat
            2.bat
            3.bat
            4.bat
            5.bat
            6.bat
            7.bat
            8.bat
            9.bat
            0.exe
            1.exe
            2.exe
            3.exe
            4.exe
            5.exe
            6.exe
            7.exe
            8.exe
            9.exe
            0.com
            1.com
            2.com
            3.com
            4.com
            5.com
            6.com
            7.com
            8.com
            9.com
            0.vbs
            1.vbs
            2.vbs
            3.vbs
            4.vbs
            5.vbs
            6.vbs
            7.vbs
            8.vbs
            9.vbs
            a.com
            b.com
            c.com
            d.com
            e.com
            f.com
            g.com
            h.com
            i.com
            j.com
            k.com
            l.com
            m.com
            n.com
            o.com
            p.com
            q.com
            r.com
            s.com
            t.com
            u.com
            v.com
            w.com
            x.com
            y.com
            z.com
            a.bat
            b.bat
            c.bat
            d.bat
            e.bat
            f.bat
            g.bat
            h.bat
            i.bat
            j.bat
            k.bat
            l.bat
            m.bat
            n.bat
            o.bat
            p.bat
            q.bat
            r.bat
            s.bat
            t.bat
            u.bat
            v.bat
            w.bat
            x.bat
            y.bat
            z.bat
            a.cmd
            b.cmd
            c.cmd
            d.cmd
            e.cmd
            f.cmd
            g.cmd
            h.cmd
            i.cmd
            j.cmd
            k.cmd
            l.cmd
            m.cmd
            n.cmd
            o.cmd
            p.cmd
            q.cmd
            r.cmd
            s.cmd
            t.cmd
            u.cmd
            v.cmd
            w.cmd
            x.cmd
            y.cmd
            z.cmd
            a.exe
            b.exe
            c.exe
            d.exe
            e.exe
            f.exe
            g.exe
            h.exe
            i.exe
            j.exe
            k.exe
            l.exe
            m.exe
            n.exe
            o.exe
            p.exe
            q.exe
            r.exe
            s.exe
            t.exe
            u.exe
            v.exe
            w.exe
            x.exe
            y.exe
            z.exe
            a.vbs
            b.vbs
            c.vbs
            d.vbs
            e.vbs
            f.vbs
            g.vbs
            h.vbs
            i.vbs
            j.vbs
            k.vbs
            l.vbs
            m.vbs
            n.vbs
            o.vbs
            p.vbs
            q.vbs
            r.vbs
            s.vbs
            t.vbs
            u.vbs
            v.vbs
            w.vbs
            x.vbs
            y.vbs
            z.vbs
            *.dll.vbs

            >>Dossiers :

            AutoRun
            autorun.inf
            fsc.tmp
            RecInfo
            Recycled\Recycled
            Recycler\Recycler
            resycled
            runaut~1
            sdlflzoip

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Window Title"=-
            "Start Page"=-
            "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN]
            "Start Page"="https://www.msn.com/fr-fr"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "fucker"=-
            "SysDir"=-
            "ms32dll"=-
            "cftmonn"=-
            "Lany"=-
            "Zip"=-
            "RavAV"=-
            "cmd32"=-
            "Install.exe"=-
            "FIXEDFON.FON"=-
            "MS-RAD0"=-
            "MS-RAD1"=-
            "MS-RAD2"=-
            "MS-RAD3"=-
            "MS-RAD4"=-
            "MS-RAD5"=-
            "MS-RAD6"=-
            "MS-RAD7"=-
            "MS-RAD8"=-
            "MS-RAD9"=-
            "MS-RADA"=-
            "MS-RADB"=-
            "MS-RADC"=-
            "MS-RADD"=-
            "MS-RADE"=-
            "MS-RADF"=-
            "MS-RADG"=-
            "MS-RADH"=-
            "MS-RADI"=-
            "MS-RADJ"=-
            "MS-RADK"=-
            "MS-RADL"=-
            "MS-RADM"=-
            "MS-RADN"=-
            "MS-RADO"=-
            "MS-RADP"=-
            "MS-RADQ"=-
            "MS-RADR"=-
            "MS-RADS"=-
            "MS-RADT"=-
            "MS-RADU"=-
            "MS-RADV"=-
            "MS-RADW"=-
            "MS-RADX"=-
            "MS-RADY"=-
            "MS-RADZ"=-
            " "=-
            "winrun.dll"=-
            "loader.exe"=-
            "recinfo49"=-
            "System"=-
            "System Updater Machine"=-
            "SpiderH"=-
            "winudp64.exe"=-
            "System12"=-
            "System64"=-
            "IMJPMIG8.2"=-
            "CARPService"=-
            "039.tmp"=-
            "userd"=-
            "nar"=-
            "MSKernel32"=-
            "WillPolo"=-
            "MyMP3"=-
            "FS6519"=-
            "Windows\SysRes.vbs"=-
            "SysRes"=-
            "Raila Odinga"=-
            "reginit"=-
            "lnternet Update"=-
            "GMOGLFEO"=-
            "WintelUpdate"=-
            "Pubnet"=-
            "antihost"=-

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
            "System Updater Machine"=-
            "Win32DLL"=-
            "lnternet Update"=-

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
            " "=-

            [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "kamsoft"=-
            "amva"=-
            "kava"=-
            "tava"=-
            "avpa"=-
            "internet_explorer"=-
            "anti-virus 2007"=-
            "Mp3 player"=-
            "kxvo"=-
            "EXPLORER.EXE"=-
            "wsctf.exe"=-
            "loader.exe"=-
            "jvvo"=-
            "taso"=-
            "Avg_AntiHost"=-
            "jvsoft"=-
            "tasoft"=-
            "SpiderH"=-
            "MsServer"=-
            "MSFox"=-
            "msn"=-
            "????r"=-
            "Windows Update"=-
            "Microsoft Debug Manager"=-
            "protect_autorun"=-
            "Le Petit Robert Hyperappel"=-
            "firewall 2008"=-
            " "=-

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
            " "=-

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
            "test"=-
            "Msn"=-
            "MsnHost"=-
            "MsnLoad"=-
            "MsnConvert"=-
            "MsnMessendger"=-
            "sys"=-

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "DefaultUserName"=-
            "LegalNoticeCaption"=-
            "LegalNoticeText"=-

            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\NoChangingWallPaper]

            -------------------------------------------------------------------------------------------------------------

            Mises a jours du 5 decembre 2008

            >>>>>>in "All Drives"<<<<<<<<<

            6xdgw26.com
            6xig.com
            8386nac.com
            8e.com
            8u.com
            8uot.exe
            arun.exe
            asneg.com
            bpu.exe
            br1e.com
            cdwfql2v.com
            ceqfqp.bat
            cm0.com
            d1y36.com
            dh66ln.cmd
            dpu1.exe
            dyr2j6mv.exe
            ermvu8.cmd
            fblfnthuh.exe
            fn20.exe
            fufb6tq3.cmd
            g2o1n.exe
            gx.com h3hi1k3.exe
            i8.com
            ivcvknr.bat
            jv.exe
            kernel32.dll.vbs
            kg2v.com
            klp8j6i.com
            ktnquo.exe
            l1.cmd
            lp3c.bat
            m0g8sqx.cmd
            m6dqm2vd.exe
            m8wafly.com
            m9as2c.cmd
            MicrosoftPowerPoint.exe
            MSd30D.vbs
            msnmsgr_plus.exe
            ncyrf.bat
            ntdeIect.com
            ntnq.exe
            ntphyy.com
            NTsys.exe
            o6pq1n8.com
            okhr.exe
            ous.exe
            ox.cmd
            p1f6b.exe
            program.exe
            qeoc6sj.exe
            qwultj1.bat
            rcukd.cmd
            rdsfk.com
            rjx0.exe
            rqb0v2ot.bat
            scene.exe
            Server082.exe
            tigi.cmd
            uh31.exe
            uwlmj.com
            uxkktr.cmd
            vd91t29.exe
            w2qagd.com
            welcome.exe
            WindowsXP.exe
            winsys3.exe
            ypjq1.cmd

            .MGT_reg32.dll.vbs
            achitasin.dll.vbs
            autoupdate.dll.vbs
            bat32.txt
            happy.vbs
            ie.vbs
            killgodzilla.vbs
            maskrider.dll.vbs
            maskrider2001.vbs
            msiexec.dll.vbs
            MsUpdate.sys.vbs
            nohack.vbs
            RUNDLL64.dll.vbs
            setup.dll.vbs
            VBRuntime32.dll.vbs
            viva.dll.vbs
            Win32.dll.vbs
            winconfig.dll.vbs
            xepet.html
            xepet.txt

            >>>>>>in "Windows"<<<<<<<<<

            .MGT_reg32.dll.vbs
            achitasin.dll.vbs
            autoupdate.dll.vbs
            bat32.txt
            boot.ini
            happy.vbs
            ie.vbs
            killgodzilla.vbs
            maskrider.dll.vbs
            maskrider2001.vbs
            msiexec.dll.vbs
            MsUpdate.sys.vbs
            nohack.vbs
            RUNDLL64.dll.vbs
            setup.dll.vbs
            VBRuntime32.dll.vbs
            viva.dll.vbs
            Win32.dll.vbs
            winconfig.dll.vbs
            xepet.html
            xepet.txt

            >>>>>>in "Windows\system32"<<<<<<<<<

            kdyul.exe
            gasretyw0.dll
            gasretyw1.dll
            gasretyw2.dll
            gasretyw3.dll
            DC4491.DLL

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Winboot"=-

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "UC"=-
            "r4n694-24y"=-
            "kernel32"=-
            "MSConfigs"=-
            "Microsoft"=-
            "MGT_reg"=-
            "Winboot"=-
            "Winamp"=-
            "Macromedia"=-
            "WINFIX"=-
            "winconfig"=-
            "Achitasin"=-
            "mcafee"=-
            "wscript32dll"=-
            "Batch32"=-
            "maskrider"=-
            "autoupdate"=-
            "KILLMS32DLL"=-
            "WinExpress"=-
            "WinDebugger"=-
            "C:\WINDOWS\system32\kdyul.exe"=-

            mises a jours du 6 Décembre 2008

            >>>>>>in "All Drives"<<<<<<<<<

            lgrncie.bat
            info.bat
            iqosrtk.bat
            0oyl662q.cmd
            eb.bat
            New Folder.exe
            Setup_ver1.1779.2.exe
            Setup_ver*.exe

            >>>>>>in "Windows"<<<<<<<<<

            SSVICHOSST.exe

            >>>>>>in "Windows\system32"<<<<<<<<<

            SSVICHOSST.exe
            kdxkt.exe
            kdjay.exe
            kdwzh.exe
            msiconf.exe

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            "MsUpdate"=-
            "C:\WINDOWS\system32\kdxkt.exe"=-
            "C:\WINDOWS\system32\kdjay.exe"=-
            "C:\WINDOWS\system32\kdwzh.exe"=-

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            "msiexec.exe"=-
            "Yahoo Messengger"=-

            mises a jours du 11 Décembre 2008

            >>>>>>in "All Drives"<<<<<<<<<

            Secret.exe
            hupxj.bat
            fphj6j31.bat
            shell.exe
            Installer.exe
            fvbk.exe
            snaoc9i.exe
            bt8vuaw.com
            wjlc.exe
            6fnlpetp.exe
            g8rruyw.exe
            o1.com
            yannh.cmd
            1t6yxlxx.cmd
            2h60k.cmd
            3rl3lqbq.bat
            ewatr.cmd
            Maradona.exe
            iw.bat
            m2nl.bat
            ov.cmd
            pnt.com
            t1ypkh.exe
            grgarevn.inf
            microsvn.inf
            refsanvn.inf
            Zidan vs Tito.exe
            desktop.exe
            omsirutnarg.exe
            Alisa.exe
            blazzers.exe
            burimi.exe
            nfd.exe
            repppp.exe
            wax.exe
            wny.exe
            msv2008.exe
            GETBOOTD.BAT
            tbm9.bat
            08dgu.com

            >>>>>>in "Windows\system32"<<<<<<<<<

            vamsoft.exe
            vbsdfe0.dll
            vbsdfe1.dll
            vbsdfe2.dll
            vbsdfe3.dll
            syx.exe

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            "Host Process for Windows Services"=-
            "Advanced DHTML Enable"=-

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices]
            "Host Process for Windows Services"=-

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            "Runonce"=-
            "vamsoft"=-

            mises a jours du 17 Décembre 2008

            >>>>>>in "Windows"<<<<<<<<<

            pagefile.sys.vbs
            backinf.tab
            session.exe
            startup.vbs
            KAT.vbs
            explorar.vbs

            help\destrukto.vbs
            inf\destrukto.vbs
            registration\destrukto.vbs

            >>>>>>in "Windows\system32"<<<<<<<<<

            filekan.exe
            socksa.exe
            KAT.vbs
            destrukto.vbs
            security.vbs
            explorar.vbs
            destrukto.html

            >>>>>>in "Windows\system32\drivers"<<<<<<<<<

            Memoire Jeff EYEGHE.exe

            >>>>>>in "All Drives"<<<<<<<<<

            .\Recycled\Driveinfo.exe
            m9ma.exe
            JIM.exe
            iri.exe
            lol.exe
            mpsn.exe
            pagefile.sys.vbs
            al.xls.exe
            MDM.EXE
            RavManE.exe
            iexp1ore.exe
            msvcr71.dll
            BSserver
            FileKan.exe
            ASocksrv.exe
            algsrv.exe
            BACKINF.TAB
            ufdata2000.log
            twunk32.exe
            windhcp.ocx
            algssl.exe
            msfir80.exe
            msime80.exe
            destrukto.vbs
            Xsfr.exe
            Zser.exe
            THUMBS.DB.COM
            KAT.vbs
            startup.vbs
            THUMBS.DB
            MrHelloween.scr
            mig2.exe
            Perso_Stress.exe
            msfun80.exe
            IMJPMIG8.2
            msime82.exe
            IMJPMIG8.1
            algsrvs.exe
            pr2.exe
            sdfgh.exe
            p1y2.cmd h3.bat
            session.exe
            explorar.vbs
            security.vbs

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "MSRegInfo"=-
            "ASocksrv"=-
            "Startup"=-
            "Explorer"=-

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "BSserver"=-

            Mises a jours de 21 decembre 2008

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "zakariag"=-

            >>>>>>in "Windows"<<<<<<<<<

            csrss.exe

            >>>>>>in "Windows\system32"<<<<<<<<<

            GG.bat
            install.exe

            >>>>>>in "All Drives"<<<<<<<<<

            yt8a.exe
            log.exe
            iri.exe
            okea.exe
            system43.exe
            system9.exe
            xx.exe
            recycled\sirc32.exe
            iky.bat
            GuelmimG.bat

            Mises a jours de 23 decembre 2008

            >>>>>>in "Windows"<<<<<<<<<

            help.exe
            mg.exe

            >>>>>>in "Windows\system32"<<<<<<<<<

            kav320.dll
            kav321.dll
            kav322.dll
            mldmm.exe
            spooIsv.exe
            system.exe

            >>>>>>in "Temp files"<<<<<<<<<

            help.rar
            nodB.tmp

            >>>>>>in "appdata"<<<<<<<<<

            addon.dat
            CISxCC.tmp
            ISxCB.tmp
            ISx97.tmp

            >>>>>>in "All Drives"<<<<<<<<<

            MSd355.vbs
            xrdygg.bat
            MSd48F.vbs
            bold.log
            qthqdso.exe
            mguvbfr.exe
            kxhvehm.exe
            msvsc.exe
            2w.cmd
            x0.com
            u2.cmd
            je26200.com
            lkxcqdb.bat
            gr06t.cmd
            xfl3hx.exe
            1gk8ha.bat
            sucksa.exe

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
            "mmsass"=-
            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "mmsass"=-
            "Spooler SubSystem App"=-

            Mises a jours de 24 decembre 2008 ( Feliz Navidad )

            >>>>>>in "Windows"<<<<<<<<<

            system32.exe

            >>>>>>in "Windows\system32"<<<<<<<<<

            dse235rgd1.dll
            kavo.exe
            kavo0.dll
            kavo1.dll
            kavo2.dll
            kavo3.dll
            wedasgads0.dll
            wedasgads1.dll
            wedasgads2.dll
            wedasgads3.dll
            WS2Fix.exe
            VCCLSID.exe
            VACFix.exe
            swxcacls.exe
            swsc.exe
            swreg.exe
            SrchSTS.exe
            Process.exe
            o4Patch.exe
            IEDFix.exe
            IEDFix.C.exe
            dumphive.exe
            Agent.OMZ.Fix.exe
            404Fix.exe

            >>>>>>in "All Drives"<<<<<<<<<

            6j2j.com
            iok.exe
            MSd05E.vbs
            MSd329.vbs
            wi.com
            ab31.exe

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "EXPLORER.EXE"=-
            "wsctf.exe"=-

            Mises a jours du 27 Décembre 2008

            >>>>>>in "Windows"<<<<<<<<<

            admintxt.txt
            u.bat
            u.vbe
            s.vbe

            >>>>>>in "Windows\system32"<<<<<<<<<

            temp#01.exe
            dse235rgd0.dll
            dse235rgd2.dll
            dse235rgd3.dll

            >>>>>>in "Temp files"<<<<<<<<<

            pa.exe

            >>>>>>in "All Drives"<<<<<<<<<

            reps.exe
            bud3.bat
            sjqkci.cmd
            hehe.exe
            oskie.exe
            u.vbe
            Knight.exe
            sss.exe
            x6.bat
            sokeie.exe
            sucker.exe
            fhrqdpi.exe
            plugin.exe
            s.vbe

            >>>>>>"Registry"<<<<<<<<<

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "vbe"=-

            PAR CONTRE ikl m'est impossible de mettre a jour interner explorer 7, lors de l'instalation il me demande de redémarrer le PC car l'instalation a échoué, je doit donc utiliser le raccourci, met leur méthode m'ont l'air bien compliqué, il me demande de démarre le PC en mode minimal pour pouvoir l'installer. Est ce normal ?
            0
            1. Contributeur sécurité
              usbfix ici:

              http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

              ________________

              mets a jour java: demarrer puis panneau de configuration puis java puis mise a jour

              mets a jour adobe:
              https://www.01net.com/telecharger/windows/Internet/internet_utlitaire/fiches/14537.html

              mets a jour internet explorer:
              https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html

              ______________________

              colle un scan en ligne avec un des deux suivants:

              bitdefender en ligne :
              http://www.bitdefender.fr/scan_fr/scan8/ie.html

              Panda en ligne :
              http://pandasoftware.fr
              0
              1. Contributeur sécurité
                slt,

                Telecharge UsbFix sur ton bureau
                http://sd-1.archive-host.com/membres/up/116615172019703188/U­sbFix.exe

                --> Lance l installation avec les parametres par default

                Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                --> Double clic sur le raccourci UsbFix sur ton bureau

                --> Le pc va redémarer

                -->Apres redémarrage post le rapport UsbFix.txt

                Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
                Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

                ____________________

                Télécharge ici :

                http://images.malwareremoval.com/random/RSIT.exe

                random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

                Double-clique sur RSIT.exe afin de lancer RSIT.

                Clique Continue à l'écran Disclaimer.

                Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

                Poste le contenu de log.txt (<<qui sera affiché)
                ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

                NB : Les rapports sont sauvegardés dans le dossier C:\rsit
                0
                1. Dans un premeir temps, mille merci de m'aider dans cette lourde tâches pour ma part....

                  <souligne>Le premeir lien ne marche pas et me donne le textes suivant : </souligne>
                  Objet non trouvé !

                  L'URL requise n'a pu être trouvée sur ce serveur. Si vous avez tapé l'URL à la main, veuillez vérifier l'orthographe et réessayer.

                  Si vous pensez qu'il s'agit d'une erreur du serveur, veuillez contacter un administrateur à cette adresse : archive.host@gmail.com

                  Et voici les rapports de RSIT:

                  Logfile of random's system information tool 1.05 (written by random/random)
                  Run by HP_Propriétaire at 2008-12-30 12:55:48
                  Microsoft Windows XP Édition familiale Service Pack 2
                  System drive C: has 137 GB (93%) free of 147 GB
                  Total RAM: 511 MB (63% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 12:56:15, on 30/12/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                  C:\windows\system\hpsysdrv.exe
                  C:\WINDOWS\system32\hphmon06.exe
                  C:\HP\KBD\KBD.EXE
                  C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe
                  C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\WINDOWS\system32\keyhook.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\WINDOWS\AGRSMMSG.exe
                  C:\WINDOWS\ALCXMNTR.EXE
                  C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE
                  C:\Program Files\OrangeHSS\Launcher\Launcher.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\2\AlertModule.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\OrangeHSS\systray\systrayapp.exe
                  C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
                  C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
                  C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
                  C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
                  C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
                  C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\FSGK32.EXE
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\Program Files\Orange\AntivirusFirewall\Common\FSMB32.EXE
                  c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                  C:\Program Files\Orange\AntivirusFirewall\Common\FCH32.EXE
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\Program Files\Orange\AntivirusFirewall\Common\FAMEH32.EXE
                  C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsqh.exe
                  C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fssm32.exe
                  C:\Program Files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
                  C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
                  C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsus.exe
                  C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\2\FTCOMModule.exe
                  C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsav32.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\21QZA9G7\RSIT[1].exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\Program Files\trend micro\HP_Propriétaire.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail?kw=
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.orange.fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                  O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                  O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                  O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                  O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
                  O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                  O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                  O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                  O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                  O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                  O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                  O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                  O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                  O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
                  O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
                  O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
                  O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O15 - Trusted Zone: http://*.mappy.com
                  O15 - Trusted Zone: http://*.orange.fr
                  O15 - Trusted Zone: http://rw.search.ke.voila.fr
                  O15 - Trusted Zone: http://orange.weborama.fr
                  O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
                  O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
                  O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
                  O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                  0