PROBLEME programme suspect !!

Bonjour,

J'ai un petit soucis.
Ca fait plusieurs semaines que un programme nommé "k.exe" apparait à l'écran dans une fentre Vista.
En effet, une fenetre s'ouvre en disant :
"un probleme a fait que le programme a cessé de fonctionner correctement... Fermer le programme"
Donc si vous aviez une idée de ce que ca peut être ...
Je ne sais pas du tout ce qu'est ce programme et quand je recherche sur mon disque dur il ne le trouve pas ...
Serait il possible que ce soit un programme malveillant ?
J'utilise aantivir et spybot destroy...

Voilà
Merci de votre aide ! ;)
Configuration: Windows Vista
Firefox 3.0.5

37 réponses

Résumé de la discussion

Un souci lié à un programme nommé k.exe apparaît sur Windows Vista, avec une fenêtre indiquant que le programme a cessé de fonctionner et qu'il n'est pas facilement localisable sur le disque. Des réponses recommandent d'utiliser Random's System Information Tool (RSIT) pour analyser et générer des fichiers log (log.txt et info.txt), puis de les poster pour analyse. Il est conseillé de ne pas utiliser d’outils non demandés et de redémarrer après, avec des rapports qui peuvent aider à diagnostiquer une éventuelle infection malware et les mesures de désinfection. En parallèle, certains échanges détaillent les noms de processus et les emplacements typiques des fichiers suspects, notamment dans les dossiers AppData Roaming et le dossier Temp.

Bobot (l’IA à votre service)
  1. C'est ce que j'ai fait il me semble ...
    Je referrais ca prochainement ! ;)

    Bye
    1. FINDYKILL OPTION 2 !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

      1. ----------------- FindyKill V4.712 ------------------

        * User : Maxime - PC-DES-MOITEL
        * Emplacement : C:\Program Files\FindyKill
        * Outils Mis a jours le 14/01/09 par Chiquitine29
        * Recherche effectuée à 17:59:25 le 14/01/2009
        * Windows Vista - Internet Explorer 7.0.6001.18000

        ((((((((((((((((( *** Recherche *** ))))))))))))))))))

        --------------- [ Processus actifs ] ----------------

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
        C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Windows\RtHDVCpl.exe
        C:\Acer\Empowering Technology\SysMonitor.exe
        C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
        C:\Windows\System32\nvraidservice.exe
        C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
        C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Windows\ehome\ehtray.exe
        C:\Users\Maxime\AppData\Roaming\tmobd.exe
        C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
        C:\Program Files\DAEMON Tools Lite\daemon.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Windows\System32\rundll32.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\System32\mobsync.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.exe
        C:\Program Files\OpenOffice.org 3\program\soffice.bin
        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
        C:\Users\Maxime\AppData\Roaming\tmobd.exe
        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
        C:\Program Files\Windows Media Player\wmplayer.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Windows\system32\SearchFilterHost.exe

        --------------- [ Fichiers/Dossiers infectieux ] ----------------

        »»»» Presence des fichiers dans C:

        »»»» Presence des fichiers dans C:\Windows

        »»»» Presence des fichiers dans C:\Windows\Prefetch

        »»»» Presence des fichiers dans C:\Windows\system32

        »»»» Presence des fichiers dans C:\Windows\system32\drivers

        »»»» Presence des fichiers dans C:\Users\Maxime\AppData\Roaming

        »»»» Presence des fichiers dans C:\Users\Maxime\AppData\Local\Temp

        --------------- [ Registre / Startup ] ----------------

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
        Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        Acer Tour Reminder=C:\Acer\AcerTour\Reminder.exe
        ehTray.exe=C:\Windows\ehome\ehTray.exe
        tmobd=C:\Users\Maxime\AppData\Roaming\tmobd.exe
        ssf=C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
        DAEMON Tools Lite="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
        Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
        RtHDVCpl=RtHDVCpl.exe
        Acer Empowering Technology Monitor=C:\Acer\Empowering Technology\SysMonitor.exe
        eDataSecurity Loader=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
        PCMMediaSharing=C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
        Acer Tour=
        Apanel=C:\ACERSW\config\NewSetApanel.cmd
        WarReg_PopUp=C:\Acer\WR_PopUp\WarReg_PopUp.exe
        eRecoveryService=
        NVRaidService=C:\Windows\system32\nvraidservice.exe
        Acer Tour Reminder=C:\Acer\AcerTour\Reminder.exe
        PlayMovie="C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe"
        SystrayORAHSS="C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
        avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
        iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
        TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        Skytel=Skytel.exe
        NvSvc=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
        NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
        HP Software Update=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        hpqSRMon=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
        Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        Blubster=C:\Program Files\Blubster\Blubster.exe SILENT
        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
        <NO NAME>=
        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
        Installed=1
        <NO NAME>=
        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
        NoChange=1
        Installed=1
        <NO NAME>=
        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
        Installed=1
        <NO NAME>=

        [HKEY_CURRENT_USER\software\local appwizard-generated applications\DestComp]
        [HKEY_CURRENT_USER\software\local appwizard-generated applications\playplus]
        [HKEY_CURRENT_USER\software\local appwizard-generated applications\SkyTel]
        [HKEY_CURRENT_USER\software\local appwizard-generated applications\vscap]

        --------------- [ Registre / Clés infectieuses ] ----------------

        --------------- [ Etat / Services ] ----------------

        +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

        Ndisuio - Type de démarrage = 3

        EapHost - Type de démarrage = 3

        Wlansvc - Type de démarrage = 3

        SharedAccess - Type de démarrage = 3

        wuauserv - Type de démarrage = 2

        wscsvc - Type de démarrage = 2

        WinDefend - Type de démarrage = 2

        -> UAC is Enable

        --------------- [ Recherche dans supports amovibles] ----------------

        +- Informations :

        C: - Lecteur fixe
        D: - Lecteur fixe
        M: - Lecteur amovible

        +- presence des fichiers :

        --------------- [ Registre / Mountpoint2 ] ----------------

        -> Not found !

        ------------------- ! Fin du rapport ! --------------------

        Voici le rapport Findy Kill après l'option 2 ...
        1. Voilà j'ai refait une analyse Navilog puis une suppression avec les paramètres donnés ensuite ! ;)

          Voici le nouveau rapport :

          Clean Navipromo version 3.7.1 commencé le 07/02/2009 à 20:28:44,93

          Outil exécuté depuis C:\Program Files\navilog1

          Mise à jour le 02.01.2009 à 19h00 par IL-MAFIOSO

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
          X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz )
          BIOS : BIOS Date: 11/23/07 18:30:01 Ver: 08.00.15
          USER : Maxime ( Administrator )
          BOOT : Normal boot

          Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)

          C:\ (Local Disk) - NTFS - Total:228 Go (Free:108 Go)
          D:\ (Local Disk) - NTFS - Total:227 Go (Free:84 Go)
          E:\ (CD or DVD)
          F:\ (CD or DVD)
          G:\ (USB)
          H:\ (USB)
          I:\ (USB)
          J:\ (USB)
          K:\ (CD or DVD)
          O:\ (USB)

          Mode suppression automatique
          avec prise en charge résultats Catchme et GNS

          Nettoyage exécuté au redémarrage de l'ordinateur

          *** fsbl1.txt non trouvé ***
          (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

          *** Suppression avec sauvegardes résultats GenericNaviSearch ***

          * Suppression dans "C:\Windows\System32" *

          * Suppression dans "C:\Users\Maxime\AppData\Local\Microsoft" *

          * Suppression dans "C:\Users\Maxime\AppData\Local\virtualstore\windows\system32" *

          * Suppression dans "C:\Users\Maxime\AppData\Local" *

          *** Suppression dossiers dans "C:\Windows" ***

          *** Suppression dossiers dans "C:\Program Files" ***

          *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

          *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

          *** Suppression dossiers dans "C:\ProgramData" ***

          *** Suppression dossiers dans c:\users\maxime\appdata\roaming\micros~1\windows\startm~1\programs ***

          *** Suppression dossiers dans "C:\Users\Maxime\AppData\Local\virtualstore\Program Files" ***

          *** Suppression dossiers dans "C:\Users\Maxime\AppData\Local" ***

          *** Suppression dossiers dans "C:\Users\Maxime\AppData\Roaming" ***

          *** Suppression fichiers ***

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\Windows\Temp effectué !
          Nettoyage contenu C:\Users\Maxime\AppData\Local\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

          2)Recherche, création sauvegardes et suppression Heuristique :

          * Dans "C:\Windows\system32" *

          * Dans "C:\Users\Maxime\AppData\Local\Microsoft" *

          * Dans "C:\Users\Maxime\AppData\Local\virtualstore\windows\system32" *

          * Dans "C:\Users\Maxime\AppData\Local" *

          *** Sauvegarde du Registre vers dossier Safebackup ***

          sauvegarde du Registre réalisée avec succès !

          *** Nettoyage Registre ***

          Nettoyage Registre Ok

          *** Certificats ***

          Certificat Egroup absent !
          Certificat Electronic-Group absent !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit absent !
          Certificat Sunny-Day-Design-Ltdt absent !

          *** Recherche autres dossiers et fichiers connus ***

          *** Nettoyage terminé le 07/02/2009 à 20:31:01,22 ***

          Merci de votre aide !
          A très bientot !
          :)
          1. Voici le rapport après la suppression avec Navilog comme demandé ;) :

            *** Suppression dossiers dans "C:\Users\Maxime\AppData\Roaming" ***

            *** Suppression fichiers ***

            *** Suppression fichiers temporaires ***

            Nettoyage contenu C:\Windows\Temp effectué !
            Nettoyage contenu C:\Users\Maxime\AppData\Local\Temp effectué !

            *** Traitement Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

            2)Recherche, création sauvegardes et suppression Heuristique :

            * Dans "C:\Windows\system32" *

            * Dans "C:\Users\Maxime\AppData\Local\Microsoft" *

            * Dans "C:\Users\Maxime\AppData\Local\virtualstore\windows\system32" *

            * Dans "C:\Users\Maxime\AppData\Local" *

            quygomi.dat trouvé !
            Copie quygomi.dat réalisée avec succès !
            quygomi.dat supprimé !

            quygomi_nav.dat trouvé !
            Copie quygomi_nav.dat réalisée avec succès !
            quygomi_nav.dat supprimé !

            quygomi_navps.dat trouvé !
            Copie quygomi_navps.dat réalisée avec succès !
            quygomi_navps.dat supprimé !

            uiako.dat trouvé !
            Copie uiako.dat réalisée avec succès !
            uiako.dat supprimé !

            uiako_nav.dat trouvé !
            Copie uiako_nav.dat réalisée avec succès !
            uiako_nav.dat supprimé !

            uiako_navps.dat trouvé !
            Copie uiako_navps.dat réalisée avec succès !
            uiako_navps.dat supprimé !

            *** Sauvegarde du Registre vers dossier Safebackup ***

            sauvegarde du Registre réalisée avec succès !

            *** Nettoyage Registre ***

            Nettoyage Registre Ok

            *** Certificats ***

            Certificat Egroup supprimé !
            Certificat Electronic-Group supprimé !
            Certificat Montorgueil absent !
            Certificat OOO-Favorit supprimé !
            Certificat Sunny-Day-Design-Ltdt absent !

            *** Recherche autres dossiers et fichiers connus ***

            *** Nettoyage terminé le 07/02/2009 à 20:05:12,20 ***

            J'enchaine avec la suite ! ;)
            1. Voici le rapport après la suppression avec findy kill :

              ----------------- FindyKill V4.712 ------------------

              * User : Maxime - PC-DES-MOITEL
              * Emplacement : C:\Program Files\FindyKill
              * Outils Mis a jours le 14/01/09 par Chiquitine29
              * Recherche effectuée à 17:59:25 le 14/01/2009
              * Windows Vista - Internet Explorer 7.0.6001.18000

              ((((((((((((((((( *** Recherche *** ))))))))))))))))))

              --------------- [ Processus actifs ] ----------------

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
              C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
              C:\Windows\system32\WUDFHost.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Windows\RtHDVCpl.exe
              C:\Acer\Empowering Technology\SysMonitor.exe
              C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
              C:\Windows\System32\nvraidservice.exe
              C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
              C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Windows\ehome\ehtray.exe
              C:\Users\Maxime\AppData\Roaming\tmobd.exe
              C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
              C:\Program Files\DAEMON Tools Lite\daemon.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\Windows\System32\rundll32.exe
              C:\Windows\system32\wbem\unsecapp.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Windows\System32\mobsync.exe
              C:\Program Files\OpenOffice.org 3\program\soffice.exe
              C:\Program Files\OpenOffice.org 3\program\soffice.bin
              C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
              C:\Users\Maxime\AppData\Roaming\tmobd.exe
              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
              C:\Program Files\Windows Media Player\wmplayer.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe

              --------------- [ Fichiers/Dossiers infectieux ] ----------------

              »»»» Presence des fichiers dans C:

              »»»» Presence des fichiers dans C:\Windows

              »»»» Presence des fichiers dans C:\Windows\Prefetch

              »»»» Presence des fichiers dans C:\Windows\system32

              »»»» Presence des fichiers dans C:\Windows\system32\drivers

              »»»» Presence des fichiers dans C:\Users\Maxime\AppData\Roaming

              »»»» Presence des fichiers dans C:\Users\Maxime\AppData\Local\Temp

              --------------- [ Registre / Startup ] ----------------

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
              Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              Acer Tour Reminder=C:\Acer\AcerTour\Reminder.exe
              ehTray.exe=C:\Windows\ehome\ehTray.exe
              tmobd=C:\Users\Maxime\AppData\Roaming\tmobd.exe
              ssf=C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
              DAEMON Tools Lite="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
              SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
              Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
              RtHDVCpl=RtHDVCpl.exe
              Acer Empowering Technology Monitor=C:\Acer\Empowering Technology\SysMonitor.exe
              eDataSecurity Loader=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
              PCMMediaSharing=C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
              Acer Tour=
              Apanel=C:\ACERSW\config\NewSetApanel.cmd
              WarReg_PopUp=C:\Acer\WR_PopUp\WarReg_PopUp.exe
              eRecoveryService=
              NVRaidService=C:\Windows\system32\nvraidservice.exe
              Acer Tour Reminder=C:\Acer\AcerTour\Reminder.exe
              PlayMovie="C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe"
              SystrayORAHSS="C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
              avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
              iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
              TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              Skytel=Skytel.exe
              NvSvc=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
              NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
              HP Software Update=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              hpqSRMon=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
              Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              Blubster=C:\Program Files\Blubster\Blubster.exe SILENT
              HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
              <NO NAME>=
              HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
              Installed=1
              <NO NAME>=
              HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
              NoChange=1
              Installed=1
              <NO NAME>=
              HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
              Installed=1
              <NO NAME>=

              [HKEY_CURRENT_USER\software\local appwizard-generated applications\DestComp]
              [HKEY_CURRENT_USER\software\local appwizard-generated applications\playplus]
              [HKEY_CURRENT_USER\software\local appwizard-generated applications\SkyTel]
              [HKEY_CURRENT_USER\software\local appwizard-generated applications\vscap]

              --------------- [ Registre / Clés infectieuses ] ----------------

              --------------- [ Etat / Services ] ----------------

              +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

              Ndisuio - Type de démarrage = 3

              EapHost - Type de démarrage = 3

              Wlansvc - Type de démarrage = 3

              SharedAccess - Type de démarrage = 3

              wuauserv - Type de démarrage = 2

              wscsvc - Type de démarrage = 2

              WinDefend - Type de démarrage = 2

              -> UAC is Enable

              --------------- [ Recherche dans supports amovibles] ----------------

              +- Informations :

              C: - Lecteur fixe
              D: - Lecteur fixe
              M: - Lecteur amovible

              +- presence des fichiers :

              --------------- [ Registre / Mountpoint2 ] ----------------

              -> Not found !

              ------------------- ! Fin du rapport ! --------------------

              J'enchaine avec lles autres rapports ! ;)
              1. ok occupe toi de findykill option 2 et :

                ensuite :

                # Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection) :
                - Va dans démarrer puis panneau de configuration
                - Double clique sur l'icône "Comptes d'utilisateurs"
                - Clique ensuite sur activer ou désactiver le controle des comptes utilisateur
                - Décoche la case "utiliser le contrôle....." puis valide
                - Redémarre l'ordinateur

                # Si tu as Spybot, désactive le TeaTimer de Spybot (tu le réactiveras après ta désinfection) :
                Lance Spybot --> clique sur Mode => coche Mode avancé => Outils => Résident => décoche la case Résident Tea Timer

                # Relance Navilog en faisant un clic-droit sur le raccourci Navilog présent sur ton bureau et en choisissant "Exécuter en tant qu'administrateur"

                Au menu principal, choisis 2 et valide.
                Le fix va t'informer qu'il va alors redémarrer ton PC
                Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                Appuie sur une touche comme demandé.
                (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                Au redémarrage de ton PC, choisis ta session habituelle.

                Patiente jusqu'au message :
                *** Nettoyage Termine le ..... ***

                Le bloc note va s'ouvrir, copie/colle ici le rapport, comme tu l’as fait pour l’autre.
                1. Désolé pas trop le temps de faire ca en ce moment !
                  Je ferais ca ce week end ou le suivant !

                  A Bientot ! Merci de ton aide ! ;)
                  1. Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                    --> Fais clic droit sur le raccourci FindyKill sur ton bureau

                    --> Au menu principal,choisi l option 2 (Suppression)

                    /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

                    /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

                    -------> ensuite post le rapport FindyKill.txt

                    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

                    ensuite :

                    Relance Navilog en faisant un clic-droit sur le raccourci Navilog présent sur ton bureau et en choisissant "Exécuter en tant qu'administrateur"

                    Au menu principal, choisis 2 et valide.
                    Le fix va t'informer qu'il va alors redémarrer ton PC
                    Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                    Appuie sur une touche comme demandé.
                    (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                    Au redémarrage de ton PC, choisis ta session habituelle.

                    Patiente jusqu'au message :
                    *** Nettoyage Termine le ..... ***

                    Le bloc note va s'ouvrir, copie/colle ici le rapport, comme tu l’as fait pour l’autre.
                    1. Et Voilà le second rapport, celui de Navilog :

                      Search Navipromo version 3.7.1 commencé le 14/01/2009 à 18:03:42,31

                      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                      !!! Postez ce rapport sur le forum pour le faire analyser !!!
                      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                      Outil exécuté depuis C:\Program Files\navilog1

                      Mise à jour le 02.01.2009 à 19h00 par IL-MAFIOSO

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                      X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz )
                      BIOS : BIOS Date: 11/23/07 18:30:01 Ver: 08.00.15
                      USER : Maxime ( Administrator )
                      BOOT : Normal boot

                      Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)

                      C:\ (Local Disk) - NTFS - Total:228 Go (Free:131 Go)
                      D:\ (Local Disk) - NTFS - Total:227 Go (Free:85 Go)
                      E:\ (CD or DVD)
                      F:\ (CD or DVD)
                      G:\ (USB)
                      H:\ (USB)
                      I:\ (USB)
                      J:\ (USB)
                      K:\ (CD or DVD)
                      M:\ (USB) - FAT32 - Total:119 Mo (Free:0 Go)

                      Recherche executé en mode normal

                      *** Recherche Programmes installés ***

                      *** Recherche dossiers dans "C:\Windows" ***

                      *** Recherche dossiers dans "C:\Program Files" ***

                      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                      *** Recherche dossiers dans "C:\ProgramData" ***

                      *** Recherche dossiers dans "c:\users\maxime\appdata\roaming\micros~1\windows\startm~1\programs" ***

                      *** Recherche dossiers dans "C:\Users\Maxime\AppData\Local\virtualstore\Program Files" ***

                      *** Recherche dossiers dans "C:\Users\Maxime\AppData\Local" ***

                      *** Recherche dossiers dans "C:\Users\Maxime\AppData\Roaming" ***

                      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                      pour + d'infos : http://www.gmer.net

                      *** Recherche avec GenericNaviSearch ***
                      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                      !!! A vérifier impérativement avant toute suppression manuelle !!!

                      * Recherche dans "C:\Windows\system32" *

                      * Recherche dans "C:\Users\Maxime\AppData\Local\Microsoft" *

                      * Recherche dans "C:\Users\Maxime\AppData\Local\virtualstore\windows\system32" *

                      * Recherche dans "C:\Users\Maxime\AppData\Local" *

                      *** Recherche fichiers ***

                      *** Recherche clés spécifiques dans le Registre ***
                      !! Les clés trouvées ne sont pas forcément infectées !!

                      HKEY_CURRENT_USER\Software\Lanconfig

                      *** Module de Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Recherche nouveaux fichiers Instant Access :

                      2)Recherche Heuristique :

                      * Dans "C:\Windows\system32" :

                      * Dans "C:\Users\Maxime\AppData\Local\Microsoft" :

                      * Dans "C:\Users\Maxime\AppData\Local\virtualstore\windows\system32" :

                      * Dans "C:\Users\Maxime\AppData\Local" :

                      quygomi.dat trouvé !
                      quygomi_nav.dat trouvé !
                      quygomi_navps.dat trouvé !
                      uiako.exe trouvé !
                      uiako.dat trouvé !
                      uiako_nav.dat trouvé !
                      uiako_navps.dat trouvé !

                      3)Recherche Certificats :

                      Certificat Egroup trouvé !
                      Certificat Electronic-Group trouvé !
                      Certificat Montorgueil absent !
                      Certificat OOO-Favorit trouvé !
                      Certificat Sunny-Day-Design-Ltd absent !

                      4)Recherche autres dossiers et fichiers connus :

                      *** Analyse terminée le 14/01/2009 à 18:12:07,07 ***

                      Merci Beaucoup de t'occuper de mon problème ;)
                      Bonne soirée !
                      A Bientot ! ;)
                      1. Voici le rapport findykill :

                        ----------------- FindyKill V4.712 ------------------

                        * User : Maxime - PC-DES-MOITEL
                        * Emplacement : C:\Program Files\FindyKill
                        * Outils Mis a jours le 14/01/09 par Chiquitine29
                        * Recherche effectuée à 17:59:25 le 14/01/2009
                        * Windows Vista - Internet Explorer 7.0.6001.18000

                        ((((((((((((((((( *** Recherche *** ))))))))))))))))))

                        --------------- [ Processus actifs ] ----------------

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
                        C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                        C:\Windows\system32\WUDFHost.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Acer\Empowering Technology\SysMonitor.exe
                        C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                        C:\Windows\System32\nvraidservice.exe
                        C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
                        C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Users\Maxime\AppData\Roaming\tmobd.exe
                        C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
                        C:\Program Files\DAEMON Tools Lite\daemon.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Windows\System32\mobsync.exe
                        C:\Program Files\OpenOffice.org 3\program\soffice.exe
                        C:\Program Files\OpenOffice.org 3\program\soffice.bin
                        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                        C:\Users\Maxime\AppData\Roaming\tmobd.exe
                        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                        C:\Program Files\Windows Media Player\wmplayer.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Windows\system32\conime.exe
                        C:\Windows\system32\SearchProtocolHost.exe
                        C:\Windows\system32\SearchFilterHost.exe

                        --------------- [ Fichiers/Dossiers infectieux ] ----------------

                        »»»» Presence des fichiers dans C:

                        »»»» Presence des fichiers dans C:\Windows

                        »»»» Presence des fichiers dans C:\Windows\Prefetch

                        »»»» Presence des fichiers dans C:\Windows\system32

                        »»»» Presence des fichiers dans C:\Windows\system32\drivers

                        »»»» Presence des fichiers dans C:\Users\Maxime\AppData\Roaming

                        »»»» Presence des fichiers dans C:\Users\Maxime\AppData\Local\Temp

                        --------------- [ Registre / Startup ] ----------------

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                        Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        Acer Tour Reminder=C:\Acer\AcerTour\Reminder.exe
                        ehTray.exe=C:\Windows\ehome\ehTray.exe
                        tmobd=C:\Users\Maxime\AppData\Roaming\tmobd.exe
                        ssf=C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
                        DAEMON Tools Lite="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                        SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                        Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        RtHDVCpl=RtHDVCpl.exe
                        Acer Empowering Technology Monitor=C:\Acer\Empowering Technology\SysMonitor.exe
                        eDataSecurity Loader=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                        PCMMediaSharing=C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
                        Acer Tour=
                        Apanel=C:\ACERSW\config\NewSetApanel.cmd
                        WarReg_PopUp=C:\Acer\WR_PopUp\WarReg_PopUp.exe
                        eRecoveryService=
                        NVRaidService=C:\Windows\system32\nvraidservice.exe
                        Acer Tour Reminder=C:\Acer\AcerTour\Reminder.exe
                        PlayMovie="C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe"
                        SystrayORAHSS="C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
                        avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
                        TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        Skytel=Skytel.exe
                        NvSvc=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                        HP Software Update=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        hpqSRMon=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                        Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        Blubster=C:\Program Files\Blubster\Blubster.exe SILENT
                        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                        <NO NAME>=
                        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                        Installed=1
                        <NO NAME>=
                        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                        NoChange=1
                        Installed=1
                        <NO NAME>=
                        HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                        Installed=1
                        <NO NAME>=

                        [HKEY_CURRENT_USER\software\local appwizard-generated applications\DestComp]
                        [HKEY_CURRENT_USER\software\local appwizard-generated applications\playplus]
                        [HKEY_CURRENT_USER\software\local appwizard-generated applications\SkyTel]
                        [HKEY_CURRENT_USER\software\local appwizard-generated applications\vscap]

                        --------------- [ Registre / Clés infectieuses ] ----------------

                        --------------- [ Etat / Services ] ----------------

                        +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

                        Ndisuio - Type de démarrage = 3

                        EapHost - Type de démarrage = 3

                        Wlansvc - Type de démarrage = 3

                        SharedAccess - Type de démarrage = 3

                        wuauserv - Type de démarrage = 2

                        wscsvc - Type de démarrage = 2

                        WinDefend - Type de démarrage = 2

                        -> UAC is Enable

                        --------------- [ Recherche dans supports amovibles] ----------------

                        +- Informations :

                        C: - Lecteur fixe
                        D: - Lecteur fixe
                        M: - Lecteur amovible

                        +- presence des fichiers :

                        --------------- [ Registre / Mountpoint2 ] ----------------

                        -> Not found !

                        ------------------- ! Fin du rapport ! --------------------
                        1. desinstalle usbfix et :

                          Telecharge maintenant FindyKill sur ton bureau :

                          http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

                          --> Lance l installation avec les parametres par default

                          --> Fais un clic droit sur le raccourci FindyKill sur ton bureau

                          --> Choisi executer en tant qu administrateur

                          --> Au menu principal,choisi l option 1 (Recherche)

                          --> Post le rapport FindyKill.txt

                          Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

                          ensuite :

                          Télécharge Navilog1 depuis-ce lien :
                          http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                          Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                          Ensuite double clique sur navilog1.exe pour lancer l'installation.

                          Une fois l'installation terminée, le fix s'exécutera automatiquement.
                          (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                          Au menu principal, Fais le choix 1 >> Recherche
                          Laisse toi guider et patiente.
                          Patiente jusqu'au message :
                          *** Analyse Termine le ..... *** >>>>> Le fix peut durer une dizaine de minutes ;)
                          Appuie sur une touche le bloc note va s'ouvrir.
                          Copie-colle le rapport ici.
                          1. Logfile of random's system information tool 1.05 (written by random/random)
                            Run by Maxime at 2009-01-11 20:52:54
                            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                            System drive C: has 132 GB (56%) free of 234 GB
                            Total RAM: 3070 MB (57% free)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 20:53:11, on 11/01/2009
                            Platform: Windows Vista SP1 (WinNT 6.00.1905)
                            MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                            Boot mode: Normal

                            Running processes:
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\Explorer.EXE
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Windows\RtHDVCpl.exe
                            C:\Acer\Empowering Technology\SysMonitor.exe
                            C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                            C:\Windows\System32\nvraidservice.exe
                            C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
                            C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                            C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                            C:\Program Files\Blubster\Blubster.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Users\Maxime\AppData\Roaming\tmobd.exe
                            C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
                            C:\Program Files\DAEMON Tools Lite\daemon.exe
                            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Users\Maxime\AppData\Local\uiako.exe
                            C:\Windows\System32\mobsync.exe
                            C:\Windows\system32\wbem\unsecapp.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            C:\Program Files\OpenOffice.org 3\program\soffice.exe
                            C:\Program Files\OpenOffice.org 3\program\soffice.bin
                            C:\Users\Maxime\AppData\Roaming\tmobd.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Internet Explorer\IEUser.exe
                            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                            C:\Program Files\Blubster\BGCheck.exe
                            C:\Windows\system32\conime.exe
                            C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
                            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                            C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Users\Maxime\Downloads\RSIT.exe
                            C:\Program Files\trend micro\Maxime.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                            O1 - Hosts: ::1 localhost
                            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                            O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                            O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                            O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                            O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
                            O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                            O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
                            O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd
                            O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                            O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
                            O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                            O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe"
                            O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
                            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKLM\..\Run: [Skytel] Skytel.exe
                            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
                            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                            O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                            O4 - HKCU\..\Run: [tmobd] C:\Users\Maxime\AppData\Roaming\tmobd.exe
                            O4 - HKCU\..\Run: [ssf] C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
                            O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKCU\..\Run: [uiako] "c:\users\maxime\appdata\local\uiako.exe" uiako
                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                            O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                            O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                            O4 - Global Startup: E_SPSU01.lnk = C:\Windows\System32\spool\drivers\w32x86\3\E_SPSU01.EXE
                            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                            O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                            O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                            O13 - Gopher Prefix:
                            O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
                            O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
                            O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
                            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                            O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
                            O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                            O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                            O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                            O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                            1. autant pour moi c etait le changelog(dossier interne au pogiciel)qui datait du 2.12

                              non donne moi juste le rapport LOG
                              1. Je comprends pas je trouves pas le fichier que tu me demandes purtant jl'ai fait deux fois !
                                Pas possible qu'il date du 02/12 puisque j'avais pas ce logiciel ... Bizarre

                                Okaii'
                                Tu veux les 2 ?
                                1. Est ce que c'est ca ?

                                  Changelog UsbFix établit le 2 decembre 2008
                                  outils créé par Chiquitine29 , aide aux mises a jours -> Chimay8

                                  >>>>>>in "ProgramFiles"<<<<<<<<<

                                  Internet Explorer\Connection Wizard\icwconn1\rada
                                  Internet Explorer\Connection Wizard\icwconn1\rade
                                  Internet Explorer\Connection Wizard\icwconn1\radf
                                  Internet Explorer\Connection Wizard\icwconn1\rad5
                                  Internet Explorer\Connection Wizard\icwconn1\rad0
                                  Internet Explorer\Connection Wizard\icwconn1\rad9
                                  Internet Explorer\Connection Wizard\icwconn1\rad4
                                  Internet Explorer\Connection Wizard\icwconn1\rad1
                                  Internet Explorer\Connection Wizard\icwconn1
                                  Movie Maker\explorer.exe
                                  Internet Explorer\explorer.exe

                                  >>>>>>in "Windows"<<<<<<<<<

                                  autorun.inf
                                  autorun.exe
                                  autorun.vbs
                                  autorun.reg
                                  autorun.ini
                                  autorun.fcb
                                  autorun.bat
                                  autorun.com
                                  AdobeR.exe
                                  Alecks.vbs
                                  bittorrent.exe
                                  cmd32.exe
                                  CwbRmDir.bat
                                  Fonts\Fonts.exe
                                  FS6519.dll.vbs
                                  funny.exe
                                  GMOGLFEO.exe
                                  hiqalowo.inf
                                  icapy.scr
                                  ilezyvu.bin
                                  Lany.vbs
                                  lumy.exe
                                  manulopa.reg
                                  MS32DLL.dll.vbs
                                  MyMP3.vbs
                                  nar.vbs
                                  osok.inf
                                  osotilasiq.pif
                                  oxafa.com
                                  qobo.dat
                                  rundll32.vbe
                                  sleep.vbe
                                  SysRes.vbs
                                  takice.lib
                                  tusoha.exe
                                  unahafiwik.exe
                                  waol.exe
                                  waziqepehi.ban
                                  WillPolo.vbs
                                  Win32DLL.vbs
                                  win.vbe
                                  window.exe
                                  wyzeha.com
                                  xcopy.exe
                                  yjilu.inf
                                  ylacupyb.dll

                                  RECYCLER\systems.com

                                  temp\039.tmp

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  agucuri.vbs
                                  ahr.exe
                                  Alecks.vbs
                                  antinul.vbe
                                  amvo.exe
                                  amvo0.dll
                                  amvo1.dll
                                  amvo2.dll
                                  autorun.bat
                                  Autorun.com
                                  autorun.exe
                                  autorun.fcb
                                  autorun.inf
                                  autorun.ini
                                  autorun.reg
                                  autorun.vbs
                                  Autoruns.exe
                                  avpo.exe
                                  avpo0.dll
                                  avpo1.dll
                                  Bitkvo.exe
                                  Bitkv0.dll
                                  Bitkv1.dll
                                  cftmonn.exe
                                  Christina.jpg
                                  Christina.vbs
                                  ckvo.exe
                                  ckvo0.dll
                                  ckvo1.dll
                                  ckvo2.dll
                                  cradle_of_filth.vbe
                                  delself.bat
                                  FS6519.dll.vbs
                                  GMOGLFEO.exe
                                  icf.exe.exe
                                  ie.exe
                                  jvvo.exe
                                  jvvo0.dll
                                  jvvo1.dll
                                  jvvo2.dll
                                  jvvo3.dll
                                  j3ewro.exe
                                  jwedsfdo0.dll
                                  jwedsfdo1.dll
                                  jwedsfdo2.dll
                                  jwedsfdo3.dll
                                  jxnraqjxg.exe
                                  kavo.exe
                                  kamsoft.exe
                                  kav0.dll
                                  kav1.dll
                                  kav2.dll
                                  kav3.dll
                                  kavo0.dll
                                  kavo1.dll
                                  kavo2.dll
                                  kavo3.dll
                                  kdkfm.exe
                                  KEYBOARD.exe
                                  keygen.exe
                                  kulitut.bat
                                  kulitut.vbs
                                  kxvo.exe
                                  kxvo0.dll
                                  kxvo1.dll
                                  kxvo2.dll
                                  kxvo3.dll
                                  lExplore.exe
                                  loader.exe
                                  logoneui.exe
                                  LOVE-LETTER-FOR-YOU.HTM
                                  LOVE-LETTER-FOR-YOU.TXT.vbs
                                  msfun80.exe
                                  msime82.exe
                                  MSKernel32.vbs
                                  ne0kS.dll.wsf
                                  ne0kS.exe
                                  OeApi.vbs
                                  pubnet.vbs
                                  rs32net.exe
                                  SemiAntiVirus.vbs
                                  Sexy Girls.scr
                                  SpiderH.bmp
                                  SpiderH.jpeg
                                  SpiderH.vbs
                                  sys.vbs
                                  Syso.vbs
                                  SysRes.vbs
                                  syx.exe
                                  taso.exe
                                  tavo.exe
                                  tavo0.dll
                                  tavo1.dll
                                  tavo2.dll
                                  tavo3.dll
                                  temp1.exe
                                  temp2.exe
                                  temp?.exe
                                  text.txt
                                  Ecran.exe
                                  THe Girls
                                  tmp.reg
                                  tmp.txt
                                  t.txt
                                  vb@dock.vbs
                                  vl@dock.vbs
                                  Win32.vbs
                                  winudp64.exe

                                  dllcache\Default.exe

                                  >>>>>>in "Windows\system32\drivers"<<<<<<<<<

                                  ._Sanaa style-1 les formes.exe
                                  0hct8ybw.exe
                                  1ere partie du projet modifier.exe
                                  abdelali lahrach.exe
                                  Analyse transactionnelle.exe
                                  AutoRun.exe
                                  Bernoulli01215.exe"
                                  Cahiers français Quels modes de financement pour les entreprises - La Documentation française.exe
                                  Copie de Devoir I.exe
                                  e-ticket Juba Paris.exe
                                  fdfp2.exe
                                  fihi ghizlane Rapport de stage.exe
                                  graphic.exe
                                  intel.exe
                                  isew32.exe
                                  kheireddine.exe
                                  le_cadeau_du_sud(1).exe
                                  LEADERSHIP SKILLS FINAL.exe
                                  lettre de motivation.exe
                                  MSDS.exe
                                  Note.exe
                                  PREMIER CHAPITRE modifié.exe
                                  Raila Odinga.exe
                                  Rapport NADIA.exe
                                  spectro_masse1.exe
                                  td de reacteur.exe
                                  these-223.exe
                                  xyw9tmdj.exe

                                  >>>>>>in "Documents and Settings"<<<<<<<<<

                                  tazebama.dl_
                                  hook.dl_

                                  >>>>>>in "appdata"<<<<<<<<<

                                  fetomiv.vbs
                                  gumugy.vbs
                                  jicapikase.vbs
                                  mobyhikaja.vbs
                                  nebohozi.com
                                  orimuwy.exe
                                  sidymyvig.vbs
                                  tazebama\tazebama.log
                                  tazebama\zPharaoh.dat
                                  tazebama

                                  >>>>>>in "Temp files"<<<<<<<<<

                                  1.reg
                                  2.dll
                                  6257890.exe
                                  fq9.dll
                                  help.exe
                                  help1.rar
                                  inst.exe
                                  system.dll
                                  w2e.sys
                                  winhqqo.exe
                                  wintoift.exe
                                  xhjb.dll
                                  xxx6042.exe
                                  zb5ok.dll

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  ._autorun.inf
                                  autorun.inf
                                  autorun.ini
                                  autorun.reg
                                  autorun.bat
                                  autorun.vbs
                                  autorun2.inf
                                  autosys.exe
                                  00hoeav.com
                                  096.bat
                                  0gjn3yw.exe
                                  0qx0sc6.bat
                                  0tmhoc.cmd
                                  0u.cmd
                                  0w.com
                                  0wk2.cmd
                                  108i.cmd
                                  1aq1obb.bat
                                  1bbvq96y.com
                                  1dg.exe
                                  1i.com
                                  1nkbd8h.bat
                                  1rfw8hjr.com
                                  1u0o8bnq.cmd
                                  1weicxa.com
                                  1XXEC.exe
                                  22xo.exe
                                  2ifetri.cmd
                                  2y8la.exe
                                  30ed3.exe
                                  33gmhso.bat
                                  39lpji.com
                                  3o.exe
                                  3wcxx91.cmd
                                  3xXx31.exe
                                  4vzjaw3o.sys
                                  62oop0ak.bat
                                  68.exe
                                  6tkoyhx.cmd
                                  6x8be16.cmd
                                  8e9gmih.bat
                                  8ng8w.com
                                  93vx0c.com
                                  9yqusig.bat
                                  22wcb21o.exe
                                  31n3b2h.exe
                                  39lpji.com
                                  80avp08.com
                                  82r9.cmd
                                  83fgj.com
                                  83l3v.cmd
                                  8df.exe >
                                  8h3hh3m.exe
                                  8tss2gwq.bat
                                  90imhpnc.exe
                                  92j11sm.com
                                  9es.com
                                  a1.bat
                                  a9.com
                                  abk.bat
                                  activexdebugger32.exe
                                  Administrateur_Fichiers.exe
                                  admp.exe
                                  adobeR.exe
                                  Akon.exe
                                  Alecks.vbs
                                  antihost.exe
                                  antinul.vbe
                                  aoutfq.exe
                                  ar.exe
                                  Atisetup.exe
                                  auto.exe
                                  autorum.exe
                                  AutoRun\Demo.exe
                                  autorun.exe
                                  autorun.pif
                                  autoruns.exe
                                  AutoScr.exe
                                  ay8p6v3.cmd
                                  Ayame.exe
                                  b3b9u.com
                                  bicsxk03.com
                                  bittorrent.exe
                                  bndafai.exe
                                  bo1dhu.bat
                                  bobm.exe
                                  boot.exe
                                  bootin.exe
                                  bplrl98.cmd
                                  buis.exe
                                  bwpncb6.com
                                  bxuup9r.bat c18vk.exe
                                  c9.com
                                  c9hehpa.bat
                                  camp.exe
                                  cayfq2.cmd
                                  cd8idoyl.com
                                  cdr.exe
                                  ceb6eu98.bat
                                  cekbru.pif
                                  clear.bat
                                  ClickMe.exe
                                  cftmonn.exe
                                  cfv90h.com
                                  Christina.vbs
                                  cjq.exe
                                  commands.txt
                                  comment.htt
                                  copetttt.com
                                  copy.exe
                                  cradle_of_filth.vbe
                                  cqdis.cmd
                                  cvqkuk.exe
                                  d3bn0j.exe
                                  ddyikr.cmd
                                  delautorun.bat
                                  DFD34719171.bat
                                  DFD34719375.bat
                                  DFD34719609.bat
                                  DFD34723328.bat
                                  DFD34723375.bat
                                  DFD34723781.bat
                                  DFD34724390.bat
                                  DFD34719609.bat
                                  DFD34724531.bat
                                  DFD34724656.bat
                                  DFD34725125.bat
                                  DFD34725218.bat
                                  DFD34726312.bat
                                  DFD34724390.bat
                                  DFD34726328.bat
                                  DFD34729609.bat
                                  DFD34730531.bat
                                  DFD34730937.bat
                                  DFD34734937.bat
                                  DFD34739859.bat
                                  DFD34741421.bat
                                  DFD34741734.bat
                                  DFD34741843.bat
                                  DFD*.bat
                                  dhv2u8.cmd
                                  DPFMate.exe
                                  dstart.exe
                                  dtqlv.exe
                                  dynrn6e.cmd
                                  e898.com
                                  e9ehn1m8.com
                                  eb9ehyh.exe
                                  Ecran.exe
                                  ek.com
                                  ekf6dbg0.com
                                  ekugb3.bat
                                  erdeIect.com
                                  esta ig.vbs
                                  ev60a2.cmd
                                  explorer.exe
                                  exqmmle.exe
                                  f0.cmd
                                  f2ir.com
                                  fe.bat
                                  ffojc.com
                                  fi.cmd
                                  FLIPART.EXE
                                  folder.exe
                                  Folder.htt
                                  fooool.exe
                                  Form5.exe
                                  forSV.exe
                                  FS6519.dll.vbs
                                  fucker.vbs
                                  fun.xls.exe
                                  g2p3s.exe
                                  g2pfnid.com
                                  g83816.com
                                  gdmae.bmp
                                  Ghost.pif
                                  gkyzcijfb.exe
                                  GMOGLFEO.exe
                                  gqsk.bat
                                  graphic.exe
                                  gsxlexd.cmd
                                  gxlxknou.exe
                                  gy.cmd
                                  h0s2.bat h2.com
                                  hfhludy.exe
                                  hgu.bat
                                  hni.cmd
                                  host.exe
                                  hsomklg.exe
                                  hxt9.bat
                                  i0.cmd
                                  i8.cmd
                                  ie.exe
                                  igxv.cmd
                                  ij.bat
                                  ilpg9ejd.com
                                  info.exe
                                  infrom.exe
                                  ino6.com
                                  install.exe
                                  intel.exe
                                  intro.exe
                                  ipy.cmd
                                  iq0ecwcj.cmd
                                  lsass.exe
                                  itsduel.exe
                                  iwjj.com
                                  j4c8t8b5l3a6.exe
                                  j8q8d.cmd
                                  jbfqv8j.cmd
                                  jdhc2x2.com
                                  jdwx.exe
                                  jfjsipw.exe
                                  jfvkcsy.bat
                                  jiwsxh39.exe
                                  JJJ.exe
                                  Jojo.exe
                                  jwwgtuh.exe
                                  jxnraqjxg.exe
                                  jxpiinstall.exe
                                  k6wkwon2.exe
                                  ka1nk.bat
                                  kaq86asx.bat
                                  kayira.bat
                                  kbqbptn.exe
                                  kdkfm.exe
                                  kdy.cmd
                                  kfmyoc.pif
                                  khbph.exe
                                  killVBS.vbs
                                  kk3.bat
                                  KM.exe
                                  kmd.exe
                                  kn6jhgc.cmd
                                  kqnns.exe
                                  kqsr.exe
                                  krg62.cmd
                                  kulitut.bat
                                  kulitut.vbs
                                  kxax.cmd
                                  l2f.cmd
                                  l9dwu8.bat
                                  lExplore.exe
                                  lgcadwx.bat
                                  lgrncie.bat
                                  lky.exe
                                  ln9.exe
                                  lo.exe
                                  loader.exe
                                  logoneui.exe
                                  Long.exe
                                  LOVE.PIF
                                  ltljrg.exe
                                  lumy.exe
                                  lurjlnps.exe
                                  lvxvo1xg.cmd
                                  m1t8ta.com
                                  m9j.com
                                  mail.exe
                                  manulopa.reg
                                  mcxa.exe
                                  Menu.exe
                                  mgjpcfdg.cm
                                  mnl6on3.com
                                  mp.bat
                                  mp.cmd
                                  mp.com
                                  Movie1.exe
                                  mrsne.bat
                                  MS-DOS.com
                                  MS32DLL.dll.vbs
                                  MSd040.vbs
                                  MSdC64.vbs
                                  MSdFB7.vbs
                                  MSd141.vbs
                                  MSd191.vbs
                                  MSd49A.vbs
                                  MSdE78.vbs
                                  MSd*.vbs
                                  mshta.exe
                                  MSKernel32.vbs
                                  muniu.exe
                                  MyMP3.vbs
                                  n1detect.com
                                  n2de.cmd
                                  n6j.com
                                  n6j6pc0.com
                                  n6t1h.cmd
                                  nansy ajram.vbs
                                  nar.vbs
                                  ne0kS.exe
                                  nemesis.exe
                                  nemesis.inf
                                  nfdmg.com
                                  nideiect.com
                                  niu.exe
                                  njibyekk.com
                                  nl.com
                                  nncu6kk.com
                                  NoLimit.exe
                                  np.exe
                                  nq0cq.cmd
                                  nqvarn.pif
                                  nriljal.exe
                                  ntde1ect.com
                                  ntdelect.com
                                  nq.bat
                                  nq0cq.cmd
                                  nqgcd.com
                                  nsv.bat
                                  nw0t1l0d.exe
                                  o2yf0w.bat
                                  o9o2u.bat
                                  o6opnro.bat
                                  OeApi.vbs
                                  oegbi.exe
                                  ogcikeq.com
                                  oka3yrf.bat
                                  oq.cmd
                                  oskkofa.exe
                                  osotilasiq.pif
                                  osy3.sys
                                  otyh.cmd
                                  oufddh.exe
                                  oxafa.com
                                  p3r1ud.exe
                                  p83gjy.exe
                                  p9.exe
                                  pa39xth.cmd
                                  pagefile.pif
                                  pbwkwj.com
                                  pefbutr.exe
                                  pkxfkrki.bat
                                  ph.com
                                  phgr1j.bat
                                  phim_nguoi_lon.exe
                                  pnc.exe
                                  prhyper.exe
                                  psqrhqn.exe
                                  pxka.exe
                                  q3v.com
                                  q83iwmgf.bat
                                  q8sywiva.cmd
                                  qcwpung.exe
                                  qd.cmd
                                  qjfl.exe
                                  qkarc.exe
                                  qquq.bat
                                  qqzjnhuoi.exe
                                  qpe6.com
                                  qobo.dat
                                  qrkugxtw.exe
                                  qxbx9blb.com
                                  r1y1.bat
                                  r2nl.com
                                  r6r.exe
                                  r813.bat
                                  Raila Odinga.exe
                                  Raila Odinga.gif
                                  ranvrgn.exe
                                  ravmon.exe
                                  ravmon.log
                                  ReadMe.exe
                                  RecInfo\RecInfo.exe
                                  Recycle.exe
                                  Recycled\ctfmon.exe
                                  RECYCLED\INFO.exe
                                  Recycled.exe
                                  RECYCLER\Lock Folder.exe
                                  RECYCLER\RECYCLER.exe
                                  RECYCLER\*.exe
                                  regxpcom.exe
                                  resycled\boot.com
                                  resycled\ctfmon.exe
                                  revo.exe
                                  rggbw.exe
                                  rjiybg.exe
                                  rn.exe
                                  rombkaewl.exe
                                  rosftpm.exe
                                  rqq2v.bat
                                  rs.cmd
                                  rt.exe
                                  Run.exe
                                  runaut~1\autorun.pif
                                  RunDll32.exe
                                  rxukgcm.exe
                                  s38k.exe
                                  sal.xls.exe
                                  sasyg1y8.com
                                  script.bat
                                  scriptlo.txt
                                  scvhosts.exe
                                  sdcvhost.exe
                                  SemiAntiVirus.vbs
                                  smkjd.cmd
                                  smss.exe
                                  semo2x.exe
                                  spq.bat
                                  serivces.exe
                                  server.exe
                                  server.inf
                                  Sex City.jpg.wsf
                                  sowar.vbs
                                  SpiderH.vbs
                                  sq.com
                                  sqlserv.exe
                                  SSVICHOSST.exe
                                  stwi.com
                                  svch0st.exe
                                  scvhosts.exe
                                  svdioajm.cmd
                                  sxs.exe
                                  sydp.exe
                                  sys.vbs
                                  Syso.vbs
                                  SysRes.vbs
                                  system.exe
                                  system32.exe
                                  systems.com
                                  systems.exe
                                  t82e2v.cmd
                                  TAE7ESLP.exe
                                  taipingtianguov1.1.exe
                                  takice.lib
                                  tel.xls.exe
                                  temp.bat
                                  temp.exe
                                  temp.temp
                                  temp1.exe
                                  temp2.exe
                                  test.exe
                                  testfile.bat
                                  testflo.bat
                                  tfk8.exe
                                  The_Cars.vbs
                                  THe Girls
                                  tknapl.exe
                                  tknn6.bat
                                  tmf3w3g0.com
                                  TMMDW8LP.exe
                                  Toy.exe
                                  tusoha.exe
                                  tyktjfww.exe
                                  u18vxqle.com
                                  u6k.cmd
                                  u9dyi.exe
                                  udnnnvq.exe
                                  UFO.exe
                                  ufuaugwq.exe
                                  uis.com
                                  uis.exe
                                  um.cmd
                                  un9.cmd
                                  unahafiwik.exe
                                  UnplugDrive.exe
                                  uorys.cmd
                                  update.exe
                                  uqhqx1.cmd
                                  usdeiect.com
                                  userinit.exe
                                  utdetect.com
                                  uxdeiect.com
                                  u?de?ect.com
                                  v2h3.exe
                                  v3pif.bat
                                  VB6FR.DLL
                                  vb@dock.vbs
                                  vfpkkbq.exe
                                  vksucydrh.exe
                                  vl@dock.vbs
                                  vmhr.bat
                                  vmyphd.bat
                                  vva0hc0p.cmd
                                  vxl.exe
                                  w0o.com
                                  w0owgn.bat
                                  w32sys.exe
                                  w3dn9f.bat
                                  waziqepehi.ban
                                  wa6.vbs
                                  Wallpaper.vbs
                                  WallpaperMEHDI.vbs
                                  wfhth.exe
                                  whi.com
                                  WillPolo.vbs
                                  WINDOWS.EXE
                                  Windows.scr
                                  winfile.exe
                                  winglogon.exe
                                  winrun.vbs
                                  winstall.exe
                                  wjlfhtfm.cmd
                                  wol.exe
                                  wsctf.exe
                                  wtbcccq.exe
                                  x0.cmd
                                  XAdeIect.com
                                  xcopy.exe
                                  xfoolavp.com
                                  xih9.cmd
                                  xj.bat
                                  xk2n.bat
                                  xlk9.com
                                  xlu8a8sy.exe
                                  xmnm2.cmd
                                  xn1i9x.com
                                  xnynrnh.exe
                                  xo8wr9.exe
                                  xp19.com
                                  xpbkh.com
                                  xqf.com
                                  xvlyb.exe
                                  xyhav.pif
                                  y82td3td.com
                                  ybj8df.exe
                                  yew.bat
                                  yg.cmd
                                  yjilu.inf
                                  ylacupyb.dl
                                  ylr.exe
                                  yjkjfuo.cmd
                                  yjvmtaa.exe
                                  ynfs9ks.cmd
                                  yssjnngm.cmd
                                  yvmkdwn.exe
                                  zPharaoh.exe
                                  0.cmd
                                  1.cmd
                                  2.cmd
                                  3.cmd
                                  4.cmd
                                  5.cmd
                                  6.cmd
                                  7.cmd
                                  8.cmd
                                  9.cmd
                                  0.bat
                                  1.bat
                                  2.bat
                                  3.bat
                                  4.bat
                                  5.bat
                                  6.bat
                                  7.bat
                                  8.bat
                                  9.bat
                                  0.exe
                                  1.exe
                                  2.exe
                                  3.exe
                                  4.exe
                                  5.exe
                                  6.exe
                                  7.exe
                                  8.exe
                                  9.exe
                                  0.com
                                  1.com
                                  2.com
                                  3.com
                                  4.com
                                  5.com
                                  6.com
                                  7.com
                                  8.com
                                  9.com
                                  0.vbs
                                  1.vbs
                                  2.vbs
                                  3.vbs
                                  4.vbs
                                  5.vbs
                                  6.vbs
                                  7.vbs
                                  8.vbs
                                  9.vbs
                                  a.com
                                  b.com
                                  c.com
                                  d.com
                                  e.com
                                  f.com
                                  g.com
                                  h.com
                                  i.com
                                  j.com
                                  k.com
                                  l.com
                                  m.com
                                  n.com
                                  o.com
                                  p.com
                                  q.com
                                  r.com
                                  s.com
                                  t.com
                                  u.com
                                  v.com
                                  w.com
                                  x.com
                                  y.com
                                  z.com
                                  a.bat
                                  b.bat
                                  c.bat
                                  d.bat
                                  e.bat
                                  f.bat
                                  g.bat
                                  h.bat
                                  i.bat
                                  j.bat
                                  k.bat
                                  l.bat
                                  m.bat
                                  n.bat
                                  o.bat
                                  p.bat
                                  q.bat
                                  r.bat
                                  s.bat
                                  t.bat
                                  u.bat
                                  v.bat
                                  w.bat
                                  x.bat
                                  y.bat
                                  z.bat
                                  a.cmd
                                  b.cmd
                                  c.cmd
                                  d.cmd
                                  e.cmd
                                  f.cmd
                                  g.cmd
                                  h.cmd
                                  i.cmd
                                  j.cmd
                                  k.cmd
                                  l.cmd
                                  m.cmd
                                  n.cmd
                                  o.cmd
                                  p.cmd
                                  q.cmd
                                  r.cmd
                                  s.cmd
                                  t.cmd
                                  u.cmd
                                  v.cmd
                                  w.cmd
                                  x.cmd
                                  y.cmd
                                  z.cmd
                                  a.exe
                                  b.exe
                                  c.exe
                                  d.exe
                                  e.exe
                                  f.exe
                                  g.exe
                                  h.exe
                                  i.exe
                                  j.exe
                                  k.exe
                                  l.exe
                                  m.exe
                                  n.exe
                                  o.exe
                                  p.exe
                                  q.exe
                                  r.exe
                                  s.exe
                                  t.exe
                                  u.exe
                                  v.exe
                                  w.exe
                                  x.exe
                                  y.exe
                                  z.exe
                                  a.vbs
                                  b.vbs
                                  c.vbs
                                  d.vbs
                                  e.vbs
                                  f.vbs
                                  g.vbs
                                  h.vbs
                                  i.vbs
                                  j.vbs
                                  k.vbs
                                  l.vbs
                                  m.vbs
                                  n.vbs
                                  o.vbs
                                  p.vbs
                                  q.vbs
                                  r.vbs
                                  s.vbs
                                  t.vbs
                                  u.vbs
                                  v.vbs
                                  w.vbs
                                  x.vbs
                                  y.vbs
                                  z.vbs
                                  *.dll.vbs

                                  >>Dossiers :

                                  AutoRun
                                  autorun.inf
                                  fsc.tmp
                                  RecInfo
                                  Recycled\Recycled
                                  Recycler\Recycler
                                  resycled
                                  runaut~1
                                  sdlflzoip

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                  "Window Title"=-
                                  "Start Page"=-
                                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN]
                                  "Start Page"="https://www.msn.com/fr-fr"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "fucker"=-
                                  "SysDir"=-
                                  "ms32dll"=-
                                  "cftmonn"=-
                                  "Lany"=-
                                  "Zip"=-
                                  "RavAV"=-
                                  "cmd32"=-
                                  "Install.exe"=-
                                  "FIXEDFON.FON"=-
                                  "MS-RAD0"=-
                                  "MS-RAD1"=-
                                  "MS-RAD2"=-
                                  "MS-RAD3"=-
                                  "MS-RAD4"=-
                                  "MS-RAD5"=-
                                  "MS-RAD6"=-
                                  "MS-RAD7"=-
                                  "MS-RAD8"=-
                                  "MS-RAD9"=-
                                  "MS-RADA"=-
                                  "MS-RADB"=-
                                  "MS-RADC"=-
                                  "MS-RADD"=-
                                  "MS-RADE"=-
                                  "MS-RADF"=-
                                  "MS-RADG"=-
                                  "MS-RADH"=-
                                  "MS-RADI"=-
                                  "MS-RADJ"=-
                                  "MS-RADK"=-
                                  "MS-RADL"=-
                                  "MS-RADM"=-
                                  "MS-RADN"=-
                                  "MS-RADO"=-
                                  "MS-RADP"=-
                                  "MS-RADQ"=-
                                  "MS-RADR"=-
                                  "MS-RADS"=-
                                  "MS-RADT"=-
                                  "MS-RADU"=-
                                  "MS-RADV"=-
                                  "MS-RADW"=-
                                  "MS-RADX"=-
                                  "MS-RADY"=-
                                  "MS-RADZ"=-
                                  " "=-
                                  "winrun.dll"=-
                                  "loader.exe"=-
                                  "recinfo49"=-
                                  "System"=-
                                  "System Updater Machine"=-
                                  "SpiderH"=-
                                  "winudp64.exe"=-
                                  "System12"=-
                                  "System64"=-
                                  "IMJPMIG8.2"=-
                                  "CARPService"=-
                                  "039.tmp"=-
                                  "userd"=-
                                  "nar"=-
                                  "MSKernel32"=-
                                  "WillPolo"=-
                                  "MyMP3"=-
                                  "FS6519"=-
                                  "Windows\SysRes.vbs"=-
                                  "SysRes"=-
                                  "Raila Odinga"=-
                                  "reginit"=-
                                  "lnternet Update"=-
                                  "GMOGLFEO"=-
                                  "WintelUpdate"=-
                                  "Pubnet"=-
                                  "antihost"=-

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
                                  "System Updater Machine"=-
                                  "Win32DLL"=-
                                  "lnternet Update"=-

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                                  " "=-

                                  [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "kamsoft"=-
                                  "amva"=-
                                  "kava"=-
                                  "tava"=-
                                  "avpa"=-
                                  "internet_explorer"=-
                                  "anti-virus 2007"=-
                                  "Mp3 player"=-
                                  "kxvo"=-
                                  "EXPLORER.EXE"=-
                                  "wsctf.exe"=-
                                  "loader.exe"=-
                                  "jvvo"=-
                                  "taso"=-
                                  "Avg_AntiHost"=-
                                  "jvsoft"=-
                                  "tasoft"=-
                                  "SpiderH"=-
                                  "MsServer"=-
                                  "MSFox"=-
                                  "msn"=-
                                  "????r"=-
                                  "Windows Update"=-
                                  "Microsoft Debug Manager"=-
                                  "protect_autorun"=-
                                  "Le Petit Robert Hyperappel"=-
                                  "firewall 2008"=-
                                  " "=-

                                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                                  " "=-

                                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
                                  "test"=-
                                  "Msn"=-
                                  "MsnHost"=-
                                  "MsnLoad"=-
                                  "MsnConvert"=-
                                  "MsnMessendger"=-
                                  "sys"=-

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                  "DefaultUserName"=-
                                  "LegalNoticeCaption"=-
                                  "LegalNoticeText"=-

                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\NoChangingWallPaper]

                                  -------------------------------------------------------------------------------------------------------------

                                  Mises a jours du 5 decembre 2008

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  6xdgw26.com
                                  6xig.com
                                  8386nac.com
                                  8e.com
                                  8u.com
                                  8uot.exe
                                  arun.exe
                                  asneg.com
                                  bpu.exe
                                  br1e.com
                                  cdwfql2v.com
                                  ceqfqp.bat
                                  cm0.com
                                  d1y36.com
                                  dh66ln.cmd
                                  dpu1.exe
                                  dyr2j6mv.exe
                                  ermvu8.cmd
                                  fblfnthuh.exe
                                  fn20.exe
                                  fufb6tq3.cmd
                                  g2o1n.exe
                                  gx.com h3hi1k3.exe
                                  i8.com
                                  ivcvknr.bat
                                  jv.exe
                                  kernel32.dll.vbs
                                  kg2v.com
                                  klp8j6i.com
                                  ktnquo.exe
                                  l1.cmd
                                  lp3c.bat
                                  m0g8sqx.cmd
                                  m6dqm2vd.exe
                                  m8wafly.com
                                  m9as2c.cmd
                                  MicrosoftPowerPoint.exe
                                  MSd30D.vbs
                                  msnmsgr_plus.exe
                                  ncyrf.bat
                                  ntdeIect.com
                                  ntnq.exe
                                  ntphyy.com
                                  NTsys.exe
                                  o6pq1n8.com
                                  okhr.exe
                                  ous.exe
                                  ox.cmd
                                  p1f6b.exe
                                  program.exe
                                  qeoc6sj.exe
                                  qwultj1.bat
                                  rcukd.cmd
                                  rdsfk.com
                                  rjx0.exe
                                  rqb0v2ot.bat
                                  scene.exe
                                  Server082.exe
                                  tigi.cmd
                                  uh31.exe
                                  uwlmj.com
                                  uxkktr.cmd
                                  vd91t29.exe
                                  w2qagd.com
                                  welcome.exe
                                  WindowsXP.exe
                                  winsys3.exe
                                  ypjq1.cmd

                                  .MGT_reg32.dll.vbs
                                  achitasin.dll.vbs
                                  autoupdate.dll.vbs
                                  bat32.txt
                                  happy.vbs
                                  ie.vbs
                                  killgodzilla.vbs
                                  maskrider.dll.vbs
                                  maskrider2001.vbs
                                  msiexec.dll.vbs
                                  MsUpdate.sys.vbs
                                  nohack.vbs
                                  RUNDLL64.dll.vbs
                                  setup.dll.vbs
                                  VBRuntime32.dll.vbs
                                  viva.dll.vbs
                                  Win32.dll.vbs
                                  winconfig.dll.vbs
                                  xepet.html
                                  xepet.txt

                                  >>>>>>in "Windows"<<<<<<<<<

                                  .MGT_reg32.dll.vbs
                                  achitasin.dll.vbs
                                  autoupdate.dll.vbs
                                  bat32.txt
                                  boot.ini
                                  happy.vbs
                                  ie.vbs
                                  killgodzilla.vbs
                                  maskrider.dll.vbs
                                  maskrider2001.vbs
                                  msiexec.dll.vbs
                                  MsUpdate.sys.vbs
                                  nohack.vbs
                                  RUNDLL64.dll.vbs
                                  setup.dll.vbs
                                  VBRuntime32.dll.vbs
                                  viva.dll.vbs
                                  Win32.dll.vbs
                                  winconfig.dll.vbs
                                  xepet.html
                                  xepet.txt

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  kdyul.exe
                                  gasretyw0.dll
                                  gasretyw1.dll
                                  gasretyw2.dll
                                  gasretyw3.dll
                                  DC4491.DLL

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "Winboot"=-

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "UC"=-
                                  "r4n694-24y"=-
                                  "kernel32"=-
                                  "MSConfigs"=-
                                  "Microsoft"=-
                                  "MGT_reg"=-
                                  "Winboot"=-
                                  "Winamp"=-
                                  "Macromedia"=-
                                  "WINFIX"=-
                                  "winconfig"=-
                                  "Achitasin"=-
                                  "mcafee"=-
                                  "wscript32dll"=-
                                  "Batch32"=-
                                  "maskrider"=-
                                  "autoupdate"=-
                                  "KILLMS32DLL"=-
                                  "WinExpress"=-
                                  "WinDebugger"=-
                                  "C:\WINDOWS\system32\kdyul.exe"=-

                                  mises a jours du 6 Décembre 2008

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  lgrncie.bat
                                  info.bat
                                  iqosrtk.bat
                                  0oyl662q.cmd
                                  eb.bat
                                  New Folder.exe
                                  Setup_ver1.1779.2.exe
                                  Setup_ver*.exe

                                  >>>>>>in "Windows"<<<<<<<<<

                                  SSVICHOSST.exe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  SSVICHOSST.exe
                                  kdxkt.exe
                                  kdjay.exe
                                  kdwzh.exe
                                  msiconf.exe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                                  "MsUpdate"=-
                                  "C:\WINDOWS\system32\kdxkt.exe"=-
                                  "C:\WINDOWS\system32\kdjay.exe"=-
                                  "C:\WINDOWS\system32\kdwzh.exe"=-

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                                  "msiexec.exe"=-
                                  "Yahoo Messengger"=-

                                  mises a jours du 11 Décembre 2008

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  Secret.exe
                                  hupxj.bat
                                  fphj6j31.bat
                                  shell.exe
                                  Installer.exe
                                  fvbk.exe
                                  snaoc9i.exe
                                  bt8vuaw.com
                                  wjlc.exe
                                  6fnlpetp.exe
                                  g8rruyw.exe
                                  o1.com
                                  yannh.cmd
                                  1t6yxlxx.cmd
                                  2h60k.cmd
                                  3rl3lqbq.bat
                                  ewatr.cmd
                                  Maradona.exe
                                  iw.bat
                                  m2nl.bat
                                  ov.cmd
                                  pnt.com
                                  t1ypkh.exe
                                  grgarevn.inf
                                  microsvn.inf
                                  refsanvn.inf
                                  Zidan vs Tito.exe
                                  desktop.exe
                                  omsirutnarg.exe
                                  Alisa.exe
                                  blazzers.exe
                                  burimi.exe
                                  nfd.exe
                                  repppp.exe
                                  wax.exe
                                  wny.exe
                                  msv2008.exe
                                  GETBOOTD.BAT
                                  tbm9.bat
                                  08dgu.com

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  vamsoft.exe
                                  vbsdfe0.dll
                                  vbsdfe1.dll
                                  vbsdfe2.dll
                                  vbsdfe3.dll
                                  syx.exe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                                  "Host Process for Windows Services"=-
                                  "Advanced DHTML Enable"=-

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices]
                                  "Host Process for Windows Services"=-

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                                  "Runonce"=-
                                  "vamsoft"=-

                                  mises a jours du 17 Décembre 2008

                                  >>>>>>in "Windows"<<<<<<<<<

                                  pagefile.sys.vbs
                                  backinf.tab
                                  session.exe
                                  startup.vbs
                                  KAT.vbs
                                  explorar.vbs

                                  help\destrukto.vbs
                                  inf\destrukto.vbs
                                  registration\destrukto.vbs

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  filekan.exe
                                  socksa.exe
                                  KAT.vbs
                                  destrukto.vbs
                                  security.vbs
                                  explorar.vbs
                                  destrukto.html

                                  >>>>>>in "Windows\system32\drivers"<<<<<<<<<

                                  Memoire Jeff EYEGHE.exe

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  .\Recycled\Driveinfo.exe
                                  m9ma.exe
                                  JIM.exe
                                  iri.exe
                                  lol.exe
                                  mpsn.exe
                                  pagefile.sys.vbs
                                  al.xls.exe
                                  MDM.EXE
                                  RavManE.exe
                                  iexp1ore.exe
                                  msvcr71.dll
                                  BSserver
                                  FileKan.exe
                                  ASocksrv.exe
                                  algsrv.exe
                                  BACKINF.TAB
                                  ufdata2000.log
                                  twunk32.exe
                                  windhcp.ocx
                                  algssl.exe
                                  msfir80.exe
                                  msime80.exe
                                  destrukto.vbs
                                  Xsfr.exe
                                  Zser.exe
                                  THUMBS.DB.COM
                                  KAT.vbs
                                  startup.vbs
                                  THUMBS.DB
                                  MrHelloween.scr
                                  mig2.exe
                                  Perso_Stress.exe
                                  msfun80.exe
                                  IMJPMIG8.2
                                  msime82.exe
                                  IMJPMIG8.1
                                  algsrvs.exe
                                  pr2.exe
                                  sdfgh.exe
                                  p1y2.cmd h3.bat
                                  session.exe
                                  explorar.vbs
                                  security.vbs

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "MSRegInfo"=-
                                  "ASocksrv"=-
                                  "Startup"=-
                                  "Explorer"=-

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "BSserver"=-

                                  Mises a jours de 21 decembre 2008

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "zakariag"=-

                                  >>>>>>in "Windows"<<<<<<<<<

                                  csrss.exe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  GG.bat
                                  install.exe

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  yt8a.exe
                                  log.exe
                                  iri.exe
                                  okea.exe
                                  system43.exe
                                  system9.exe
                                  xx.exe
                                  recycled\sirc32.exe
                                  iky.bat
                                  GuelmimG.bat

                                  Mises a jours de 23 decembre 2008

                                  >>>>>>in "Windows"<<<<<<<<<

                                  help.exe
                                  mg.exe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  kav320.dll
                                  kav321.dll
                                  kav322.dll
                                  mldmm.exe
                                  spooIsv.exe
                                  system.exe

                                  >>>>>>in "Temp files"<<<<<<<<<

                                  help.rar
                                  nodB.tmp

                                  >>>>>>in "appdata"<<<<<<<<<

                                  addon.dat
                                  CISxCC.tmp
                                  ISxCB.tmp
                                  ISx97.tmp

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  MSd355.vbs
                                  xrdygg.bat
                                  MSd48F.vbs
                                  bold.log
                                  qthqdso.exe
                                  mguvbfr.exe
                                  kxhvehm.exe
                                  msvsc.exe
                                  2w.cmd
                                  x0.com
                                  u2.cmd
                                  je26200.com
                                  lkxcqdb.bat
                                  gr06t.cmd
                                  xfl3hx.exe
                                  1gk8ha.bat
                                  sucksa.exe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
                                  "mmsass"=-
                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "mmsass"=-
                                  "Spooler SubSystem App"=-

                                  Mises a jours de 24 decembre 2008 ( Feliz Navidad )

                                  >>>>>>in "Windows"<<<<<<<<<

                                  system32.exe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  dse235rgd1.dll
                                  kavo.exe
                                  kavo0.dll
                                  kavo1.dll
                                  kavo2.dll
                                  kavo3.dll
                                  wedasgads0.dll
                                  wedasgads1.dll
                                  wedasgads2.dll
                                  wedasgads3.dll
                                  WS2Fix.exe
                                  VCCLSID.exe
                                  VACFix.exe
                                  swxcacls.exe
                                  swsc.exe
                                  swreg.exe
                                  SrchSTS.exe
                                  Process.exe
                                  o4Patch.exe
                                  IEDFix.exe
                                  IEDFix.C.exe
                                  dumphive.exe
                                  Agent.OMZ.Fix.exe
                                  404Fix.exe

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  6j2j.com
                                  iok.exe
                                  MSd05E.vbs
                                  MSd329.vbs
                                  wi.com
                                  ab31.exe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "EXPLORER.EXE"=-
                                  "wsctf.exe"=-

                                  Mises a jours du 27 Décembre 2008

                                  >>>>>>in "Windows"<<<<<<<<<

                                  admintxt.txt
                                  u.bat
                                  u.vbe
                                  s.vbe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  temp#01.exe
                                  dse235rgd0.dll
                                  dse235rgd2.dll
                                  dse235rgd3.dll

                                  >>>>>>in "Temp files"<<<<<<<<<

                                  pa.exe

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  reps.exe
                                  bud3.bat
                                  sjqkci.cmd
                                  hehe.exe
                                  oskie.exe
                                  u.vbe
                                  Knight.exe
                                  sss.exe
                                  x6.bat
                                  sokeie.exe
                                  sucker.exe
                                  fhrqdpi.exe
                                  plugin.exe
                                  s.vbe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "vbe"=-

                                  Mises a jours du 09 Janvier 2009

                                  >>>>>>in "Windows"<<<<<<<<<

                                  wintask.exe
                                  svcwroot.exe
                                  smms.exe
                                  inf\csrss.exe
                                  inf\diskini.xp
                                  smms.bat
                                  k.txt

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  kav323.dll
                                  blastclnnn.exe
                                  Bitkv2.dll
                                  ahtn.htm
                                  kdjpf.exe
                                  kdind.exe
                                  warning.gif
                                  jjj.exe
                                  frmwrk32.exe
                                  ciuytr3.dll
                                  ciuytr2.dll
                                  ciuytr1.dll
                                  ciuytr0.dll

                                  >>>>>>in "Windows\system32\Drivers"<<<<<<<<<

                                  av.exe
                                  RACHIDA.exe

                                  >>>>>>in "Temp files"<<<<<<<<<

                                  a3a4_appcompat.txt
                                  1AFC3.dmp

                                  >>>>>>in "Application Data"<<<<<<<<<

                                  autorun.inf
                                  gadcom\gadcom.exe
                                  gadcom

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  e8kj.exe
                                  vfjc8mxm.exe
                                  iqe68o.bat
                                  fzqxyrlpa.exe
                                  Taskmgr.exe
                                  FullHouse
                                  Config\smss.exe
                                  Kurdish.exe
                                  desktop.dll

                                  escro.exe
                                  gdgd.exe
                                  ipyrs.exe
                                  spoolsn.exe
                                  300y.cmd
                                  cb.bat
                                  riky.exe
                                  VirusRemoval.vbs
                                  Pagefi1e.sys
                                  rox.exe
                                  yhiqadw.exe
                                  p2hhr.bat
                                  SCVHOST.exe
                                  yuqpba.exe
                                  vmsavzvx.exe
                                  8de.bat
                                  frslsryk.exe
                                  yb12j.cmd
                                  xcisvxl.com
                                  wqesvxa.exe
                                  inqfnq.exe
                                  qopitm.exe
                                  sjpj.exe
                                  vhmdq.exe
                                  RECYCLER\Lock Folder.exe
                                  1sertc.exe
                                  r8.bat
                                  knupkb.com

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "win32dll"=-
                                  "Framework Windows"=-
                                  "C:\WINDOWS\system32\kdjpf.exe"=-
                                  "C:\WINDOWS\system32\kdind.exe"=-
                                  "wintask"=-
                                  "MSN"=-
                                  "zzzHPSETUP"=-
                                  "I downloaded pirated Software from P2P and now I post my Hijack log whining"=-
                                  "Proyecto1"=-
                                  "svchost"=-

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                                  "autorun"=-

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "Windows"=-
                                  "Cognac"=-

                                  [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper]
                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper]
                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop]
                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges]
                                  [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop]
                                  [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges]

                                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explore\Run]
                                  "Manager Task"=-
                                  • 1
                                  • 2