Fichier .exe virus?

Bonjour, Il y a quelques jours, voulant telecharger un programme , je telecharge un frichier .exe qui ne pese que 10 ko ,.sachant que ce n'est pas mon progrmame je l'ouvre pour voir ce que sais , pensant que c'est un virus mais je l'ai quand meme ouvert . maintenant , je me suis rendu compte que mon Norton 2009 ne s'ouvre plus depuis longtemps , et je recoit des fenetre pop up sur internet explorer alors que j'utilise google chrome. Est ce un virus ? Peut il prendre mes données personelles? Aidez moi.
Configuration: Windows XP / Google Chrome

22 réponses

  1. Contributeur sécurité
    Téléchargez MalwareByte's Anti-Malware

    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    . Enregistres le sur le bureau
    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
    . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
    . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
    . Une fois la mise à jour terminé
    . Rend-toi dans l'onglet, Recherche
    . Sélectionnes Exécuter un examen complet (examen assez long)
    . Cliques sur Rechercher
    . Le scan démarre.
    . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
    . Cliques sur Ok pour poursuivre.
    . Si des malwares ont été détectés, clique sur Afficher les résultats
    . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
    . Rends toi dans l'onglet rapport/log
    . Tu cliques dessus pour l'afficher, une fois affiché
    . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
    . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
    . tu cliques droit dans le cadre de la reponse et coller

    Si tu as besoin d'aide regarde ces tutoriels :
    Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
    0
    1. Kill'em by g3n-h@ckm@n 1.2.5.3

      User : Martin (Administrateurs)
      Update on 19/02/2010 by g3n-h@ckm@n ::::: 13.15
      Start at: 20:52:05 | 22/02/2010
      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

      Intel(R) Pentium(R) 4 CPU 2.80GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
      Internet Explorer 7.0.5730.11
      Windows Firewall Status : Disabled
      AV : Norton Internet Security 2006 2006 [ Enabled | Updated ]
      AV : avast! Antivirus 5.0.83886498 [ Enabled | Updated ]
      FW : Norton Internet Worm Protection[ (!) Disabled ]2006
      FW : Norton Internet Security 2006[ Enabled ]2006

      A:\ -> Lecteur de disquettes 3 ½ pouces
      C:\ -> Disque fixe local | 295,05 Go (223,43 Go free) | NTFS
      D:\ -> Disque CD-ROM

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\system32\PnkBstrB.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast5\AvastUI.exe
      C:\Program Files\Nowe Gadu-Gadu\gg.exe
      C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
      C:\Program Files\List_Kill'em\List_Kill'em.scr
      C:\WINDOWS\system32\cmd.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\Program Files\Google\Chrome\Application\chrome.exe
      C:\WINDOWS\system32\notepad.exe
      C:\Program Files\List_Kill'em\List_Kill'em.scr
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Documents and Settings\Martin\Local Settings\Temp\7C.tmp\ERUNT.EXE
      C:\Documents and Settings\Martin\Local Settings\Temp\7C.tmp\pv.exe

      Detections :
      ==========

      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

      Quarantined & Deleted !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
      Quarantined & Deleted !! : C:\Program Files\MyWaySA
      Quarantined & Deleted !! : C:\WINDOWS\config.ini

      Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
      Quarantined & Deleted !! : C:\WINDOWS\System32\pmsbfn32.dll
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\Local Settings\Temp\88.tmp
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\Local Settings\Temp\dw.log
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\kb891122.exe
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\nowegg.upgr.exe
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\wlsetup-cvr.exe
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\AVRES_OPTRF_LiveUpdate.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_23c.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_3f4.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_570.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_5c0.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_778.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_83c.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_8b0.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_8dc.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_9d8.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_a08.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_a3c.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_a74.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_ab4.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_b40.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_ec8.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_ecc.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_f98.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_fa8.dat
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\nos_uninstall_Adobe.dll
      Quarantined & Deleted !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\tgyq5dc3.dll

      ==============
      host file OK !
      ==============

      ========
      Registry
      ========

      Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
      Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
      Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
      Deleted : HKCR\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
      Deleted : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
      Deleted : HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
      Deleted : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_BHDRVX86
      Deleted : HKLM\SYSTEM\ControlSet003\Enum\Root\Legacy_BHDRVX86
      ========
      Services
      =========

      Ndisuio : Start = 3
      Ip6Fw : Start = 2
      SharedAccess : Start = 2
      wuauserv : Start = 2
      wscsvc : Start = 2

      ============
      Disk Cleaned
      ============

      =================
      anti-ver blaster : OK !!
      =================

      ================
      Prefetch cleaned
      ================

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
      0
      1. Ouai ouai il est en route depuis tout a l'heure ^^
        0
        1. Contributeur sécurité
          ok

          il a fait le job

          => killem option 2
          0
          1. ############################## | UsbFix V6.097 |

            User : Martin (Administrateurs) # DDFFV82J
            Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
            Start at: 18:35:01 | 22/02/2010
            Website : http://pagesperso-orange.fr/NosTools/index.html
            Contact : FindyKill.Contact@gmail.com

            Intel(R) Pentium(R) 4 CPU 2.80GHz
            Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
            Internet Explorer 7.0.5730.11
            Windows Firewall Status : Enabled
            AV : Norton Internet Security 2006 2006 [ Enabled | Updated ]
            AV : avast! Antivirus 5.0.83886498 [ Enabled | Updated ]
            FW : Norton Internet Worm Protection[ (!) Disabled ]2006
            FW : Norton Internet Security 2006[ Enabled ]2006

            A:\ -> Lecteur de disquettes 3 ½ pouces
            C:\ -> Disque fixe local # 295,05 Go (223,27 Go free) # NTFS
            D:\ -> Disque CD-ROM

            ############################## | Processus actifs |

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Alwil Software\Avast5\setup\avast.setup
            C:\WINDOWS\system32\svchost.exe
            C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\WINDOWS\system32\PnkBstrA.exe
            C:\Program Files\Google\Update\GoogleUpdate.exe
            C:\WINDOWS\system32\PnkBstrB.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Google\Update\GoogleUpdate.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\WINDOWS\System32\alg.exe

            ################## | Elements infectieux |

            Supprimé ! C:\DOCUME~1\Martin\LOCALS~1\Temp\a.dat
            Supprimé ! C:\DOCUME~1\Martin\LOCALS~1\Temp\Ucf.exe
            Supprimé ! C:\DOCUME~1\Martin\LOCALS~1\Temp\Ucg.exe
            Supprimé ! C:\Recycler\S-1-5-21-3966213416-3144993490-1582255675-1006
            Supprimé ! C:\Recycler\S-1-5-21-3966213416-3144993490-1582255675-1008

            ################## | Registre |

            Supprimé ! [HKCU\SOFTWARE\Microsoft\Handle]
            Supprimé ! [HKCU\SOFTWARE\ROUA3O12PW]
            Supprimé ! [HKCU\SOFTWARE\TOY5KNQ8OC]
            Supprimé ! [HKCU\SOFTWARE\XML]
            Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "MSConfig"
            Supprimé ! [HKLM\software\microsoft\shared tools\msconfig\startupreg\TOY5KNQ8OC]
            Supprimé ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SSHNAS]
            Supprimé ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SSHNAS]

            ################## | Mountpoints2 |

            Supprimé ! HKCU\...\Explorer\MountPoints2\{8b4b3452-1868-11df-8fdd-0008d3055344}\Shell\AutoRun\Command
            Supprimé ! HKCU\...\Explorer\MountPoints2\{c341bfce-008a-11dc-b04d-0060b3b8f6c7}\Shell\Auto\Command

            ################## | Listing des fichiers présent |

            [20/08/2004 10:37|--a------|0] C:\AUTOEXEC.BAT
            [22/02/2010 18:06|-rahs----|216] C:\boot.ini
            [05/08/2004 12:00|-rahs----|4952] C:\Bootfont.bin
            [20/08/2004 10:37|--a------|0] C:\CONFIG.SYS
            [18/05/2006 20:27|-rah-----|4632] C:\dell.sdr
            [?|?|?] C:\hiberfil.sys
            [29/05/2006 14:56|--a------|4128] C:\INFCACHE.1
            [20/08/2004 10:37|--ah-----|0] C:\IO.SYS
            [18/05/2006 20:45|--ah-----|830] C:\IPH.PH
            [17/01/2010 17:25|--a------|296292] C:\ituneslib.itl
            [02/11/2007 09:15|--a------|107] C:\main.c
            [20/08/2004 10:37|--ah-----|0] C:\MSDOS.SYS
            [05/08/2004 12:00|-rahs----|47564] C:\NTDETECT.COM
            [05/08/2004 12:00|-rahs----|251712] C:\ntldr
            [?|?|?] C:\pagefile.sys
            [12/07/2007 17:13|--a------|0] C:\paklog.txt
            [13/08/2009 18:32|--a------|13030] C:\PDOXUSRS.NET
            [30/04/2007 18:41|--a------|510] C:\s16o
            [06/05/2007 18:11|--a------|510] C:\s198
            [01/05/2007 08:22|--a------|510] C:\s1qc
            [09/05/2007 20:17|--a------|510] C:\s27c
            [09/05/2007 19:50|--a------|510] C:\s290
            [09/05/2007 20:10|--a------|510] C:\s2js
            [05/05/2007 15:57|--a------|510] C:\s2k8
            [23/04/2007 11:22|--a------|510] C:\s2qs
            [30/04/2007 08:01|--a------|510] C:\s30k
            [27/04/2007 19:59|--a------|510] C:\s35s
            [02/05/2007 18:38|--a------|510] C:\s3f4
            [09/05/2007 11:29|--a------|510] C:\s3nc
            [08/05/2007 09:50|--a------|510] C:\s3sg
            [29/04/2007 17:43|--a------|510] C:\s3sk
            [07/05/2007 18:45|--a------|510] C:\s4h8
            [04/05/2007 18:39|--a------|510] C:\s4kk
            [28/04/2007 21:11|--a------|510] C:\s5ng
            [23/08/2007 12:20|--a------|91] C:\Setup.log
            [02/05/2007 09:39|--a------|510] C:\svo
            [29/05/2006 17:39|--a------|1168] C:\temp.log
            [22/02/2010 18:40|--a------|4886] C:\UsbFix.txt

            ################## | Vaccination |

            # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

            ################## | Upload |

            Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_DDFFV82J.zip : https://www.ionos.fr/?affiliate_id=77097
            Merci pour votre contribution .

            ################## | ! Fin du rapport # UsbFix V6.097 ! |
            0
            1. Contributeur sécurité
              bon si on veut avancer fais plutôt ce que je demande...il sera toujours tant à la fin de faire tourner avast

              donc le rapport usbfis se trouve comme indiqué ici C:\UsbFix.txt

              ensuite fais killem option 2 et postes le rapport stp
              0
              1. Bah usbfix je l'ai fait mais le rapport je sais pas ce qu'il c'est passé il a du se fermer.je n'ai plus de fenetre pop up mais je comprend pas comment tu va trouver l'ingfection . j'ai fait une analyse avec avast et il n'y a rien .
                0
                1. Contributeur sécurité
                  ok

                  quel outil restait bloqué à 90 % ?

                  si tu fais usbfix postes le rapport stp

                  oublies pour l'instant mon post 13

                  ensuite

                  ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

                  mais cette fois-ci :

                  ▶ choisis l'option 2 = Mode Suppression

                  laisse travailler l'outil.

                  en fin de scan un rapport s'ouvre

                  ▶ colle le contenu dans ta reponse

                  Tu peux le désinstaller ensuite

                  0
                  1. List'em by g3n-h@ckm@n 1.2.5.3

                    User : Martin (Administrateurs)
                    Update on 19/02/2010 by g3n-h@ckm@n ::::: 13.15
                    Start at: 19:18:02 | 22/02/2010
                    Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                    Intel(R) Pentium(R) 4 CPU 2.80GHz
                    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
                    Internet Explorer 7.0.5730.11
                    Windows Firewall Status : Disabled
                    AV : Norton Internet Security 2006 2006 [ Enabled | Updated ]
                    AV : avast! Antivirus 5.0.83886498 [ (!) Disabled | Updated ]
                    FW : Norton Internet Worm Protection[ (!) Disabled ]2006
                    FW : Norton Internet Security 2006[ Enabled ]2006

                    A:\ -> Lecteur de disquettes 3 ½ pouces
                    C:\ -> Disque fixe local | 295,05 Go (223,43 Go free) | NTFS
                    D:\ -> Disque CD-ROM

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\WINDOWS\system32\HPZipm12.exe
                    C:\WINDOWS\system32\PnkBstrA.exe
                    C:\WINDOWS\system32\PnkBstrB.exe
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\WINDOWS\explorer.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Google\Chrome\Application\chrome.exe
                    C:\Program Files\Google\Chrome\Application\chrome.exe
                    C:\Program Files\Google\Chrome\Application\chrome.exe
                    C:\Program Files\Google\Chrome\Application\chrome.exe
                    C:\WINDOWS\system32\notepad.exe
                    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                    C:\Program Files\Nowe Gadu-Gadu\gg.exe
                    C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
                    C:\Program Files\List_Kill'em\List_Kill'em.scr
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\Documents and Settings\Martin\Local Settings\Temp\34.tmp\pv.exe

                    ======================
                    Keys "Run"
                    ======================
                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                    LVCOMSX REG_SZ C:\WINDOWS\system32\LVCOMSX.EXE
                    igfxtray REG_SZ C:\WINDOWS\system32\igfxtray.exe
                    igfxpers REG_SZ C:\WINDOWS\system32\igfxpers.exe
                    igfxhkcmd REG_SZ C:\WINDOWS\system32\hkcmd.exe
                    DMXLauncher REG_SZ C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                    DLA REG_SZ C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                    ccApp REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    avast5 REG_SZ C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                    =====================
                    Other Keys
                    =====================
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                    dontdisplaylastusername REG_DWORD 0 (0x0)
                    legalnoticecaption REG_SZ
                    legalnoticetext REG_SZ
                    shutdownwithoutlogon REG_DWORD 1 (0x1)
                    undockwithoutlogon REG_DWORD 1 (0x1)

                    ===============
                    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                    NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                    NoDriveAutoRun REG_DWORD 255 (0xff)
                    HonorAutoRunSetting REG_DWORD 0 (0x0)

                    ===============
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                    HonorAutoRunSetting REG_DWORD 0 (0x0)
                    NoCDBurning REG_DWORD 0 (0x0)
                    NoDriveAutoRun REG_DWORD 255 (0xff)
                    NoDriveTypeAutoRun REG_DWORD 255 (0xff)

                    ===============
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    AppInit_DLLS REG_SZ

                    ===============
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    AutoRestartShell REG_DWORD 1 (0x1)
                    DefaultDomainName REG_SZ DDFFV82J
                    DefaultUserName REG_SZ Martin
                    LegalNoticeCaption REG_SZ
                    LegalNoticeText REG_SZ
                    PowerdownAfterShutdown REG_SZ 0
                    ReportBootOk REG_SZ 1
                    Shell REG_SZ explorer.exe
                    ShutdownWithoutLogon REG_SZ 0
                    System REG_SZ
                    Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                    VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                    SfcQuota REG_DWORD -1 (0xffffffff)
                    allocatecdroms REG_SZ 0
                    allocatedasd REG_SZ 0
                    allocatefloppies REG_SZ 0
                    cachedlogonscount REG_SZ 10
                    forceunlocklogon REG_DWORD 0 (0x0)
                    passwordexpirywarning REG_DWORD 14 (0xe)
                    scremoveoption REG_SZ 0
                    AllowMultipleTSSessions REG_DWORD 1 (0x1)
                    UIHost REG_EXPAND_SZ logonui.exe
                    LogonType REG_DWORD 1 (0x1)
                    Background REG_SZ 0 0 0
                    DebugServerCommand REG_SZ no
                    SFCDisable REG_DWORD 0 (0x0)
                    WinStationsDisabled REG_SZ 0
                    HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                    ShowLogonOptions REG_DWORD 0 (0x0)
                    AltDefaultUserName REG_SZ Martin
                    AltDefaultDomainName REG_SZ DDFFV82J

                    ===============
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                    ===============
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                    {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                    ===============
                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                    C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
                    C:\Program Files\MSN Messenger\msncall.exe REG_SZ C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hposid01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe
                    C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe REG_SZ C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe
                    C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe REG_SZ C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe
                    C:\Program Files\eMule\emule.exe REG_SZ C:\Program Files\eMule\emule.exe:*:Enabled:eMule
                    C:\Program Files\Morpheus\Morpheus.exe REG_SZ C:\Program Files\Morpheus\Morpheus.exe:*:Enabled:Morpheus
                    C:\WINDOWS\system32\rtcshare.exe REG_SZ C:\WINDOWS\system32\rtcshare.exe:*:Enabled:Partage de l'application RTC
                    C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
                    C:\Program Files\World of Warcraft\WoW-2.0.10.6448-to-2.0.12.6546-frFR-downloader.exe REG_SZ C:\Program Files\World of Warcraft\WoW-2.0.10.6448-to-2.0.12.6546-frFR-downloader.exe:*:Enabled:Blizzard Downloader
                    C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
                    C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
                    C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                    C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                    C:\Program Files\MSN Messenger\msncall.exe REG_SZ C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)
                    C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
                    C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

                    ===============
                    ActivX controls
                    ===============
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{20A60F0D-9AFA-4515-A0FD-83BD84642501}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5C051655-FCD5-4969-9182-770EA5AA5565}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{644E432F-49D3-41A1-8DD5-E099162EEEC5}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D821DC4A-0814-435E-9820-661C543A4679}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
                    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}

                    ===============
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{19D3025C-95D2-D61F-456F-2F92CCD7474E}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1F2A8F63-1AD8-966D-CBC1-7607F3D54ADE}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8b15971b-5355-4c82-8c07-7e181ea07608}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{91AA735A-B1CE-4765-7E6F-71B703724172}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{94de52c8-2d59-4f1b-883e-79663d2d9a8c}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9A394342-4A68-4EBA-85A6-55B559F4E700}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D6C3D57F-4657-9785-7167-83D028A42509}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                    ==============
                    BHO :
                    ======
                    [<NO NAME> REG_SZ ]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AE7CD045-E861-484f-8273-0445EE161910}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}]

                    ================
                    Internet Explorer :
                    ================
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.msn.com/fr-fr

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                    ========
                    Services
                    ========
                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                    Ndisuio : 0x3 ( OK = 3 )
                    SharedAccess : 0x2 ( OK = 2 )
                    wuauserv : 0x2 ( OK = 2 )

                    =========
                    Atapi.sys
                    =========

                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Documents and Settings\Martin\Local Settings\Temp\34.tmp
                    ## C:\> hashdeep C:\WINDOWS\System32\Drivers\atapi.sys
                    ##
                    95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\System32\Drivers\atapi.sys

                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Documents and Settings\Martin\Local Settings\Temp\34.tmp
                    ## C:\> hashdeep C:\WINDOWS\System32\DllCache\atapi.sys
                    ##
                    95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\System32\DllCache\atapi.sys

                    Sources
                    =======

                    Référence :
                    ==========

                    Win XP_32b : a64013e98426e1877cb653685c5c0009
                    Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                    Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                    Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                    Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                    Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                    Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                    Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                    Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                    =======
                    Drive :
                    =======

                    D‚fragmenteur de disque Windows
                    Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                    Rapport d'analyse
                    295 Go total, 223 Go libre (75%), 14% fragment‚ (fragmentation du fichier 28%)

                    Vous devriez d‚fragmenter ce volume.

                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                    Present !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
                    Present !! : C:\Program Files\MyWaySA
                    Present !! : C:\WINDOWS\config.ini
                    Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                    Present !! : C:\WINDOWS\System32\pmsbfn32.dll
                    Present !! : C:\Documents and Settings\Martin\Local Settings\Temp\88.tmp
                    Present !! : C:\Documents and Settings\Martin\Local Settings\Temp\dw.log
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\kb891122.exe
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\nowegg.upgr.exe
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\wlsetup-cvr.exe
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\AVRES_OPTRF_LiveUpdate.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_23c.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_3f4.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_570.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_5c0.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_778.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_83c.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_8b0.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_8dc.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_9d8.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_a08.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_a3c.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_a74.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_ab4.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_b40.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_ec8.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_ecc.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_f98.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\Perflib_Perfdata_fa8.dat
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\catchme.dll
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\nos_uninstall_Adobe.dll
                    Present !! : C:\Documents and Settings\Martin\LOCAL Settings\Temp\tgyq5dc3.dll

                    ¤¤¤¤¤¤¤¤¤¤ Keys :

                    Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                    Present !! : HKCR\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
                    Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
                    Present !! : HKLM\Software\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
                    Present !! : HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
                    Present !! : HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
                    Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_BHDRVX86
                    Present !! : HKLM\SYSTEM\ControlSet003\Enum\Root\Legacy_BHDRVX86
                    Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_BHDRVX86

                    ============

                    catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2010-02-22 19:26:26
                    Windows 5.1.2600 Service Pack 2 NTFS

                    scanning hidden processes ...

                    scanning hidden services & system hive ...

                    scanning hidden registry entries ...

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
                    "TracesProcessed"=dword:000040ec

                    scanning hidden files ...

                    C:\Documents and Settings\Martin\Local Settings\Temp\chrome_shutdown_ms.txt 5 bytes

                    scan completed successfully
                    hidden processes: 0
                    hidden services: 0
                    hidden files: 1

                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                    device: opened successfully
                    user: MBR read successfully
                    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
                    kernel: MBR read successfully
                    user & kernel MBR OK

                    ==========
                    Programs
                    ==========

                    Adobe
                    Alwil Software
                    AnswerWorks 4.0
                    Apple Software Update
                    Audacity
                    AutoCAD 2005
                    Autodesk
                    AviSynth 2.5
                    Bonjour
                    Borland
                    CodeBlocks
                    ComPlus Applications
                    Conduit
                    Corel
                    Corel Corporation
                    Dell
                    DYNALOG
                    eMule
                    Fichiers communs
                    GeoGebra
                    Google
                    GUILD WARS
                    Hercules
                    Hewlett-Packard
                    HP
                    Infogrames
                    Installshield Installation Information
                    Intel
                    InterActual
                    Internet Explorer
                    Inventel
                    iPod
                    iTunes
                    Java
                    jv16 PowerTools
                    Lavalys
                    Learn2.com
                    List_Kill'em
                    Logitech
                    Messenger
                    Microsoft
                    Microsoft CAPICOM 2.1.0.2
                    microsoft frontpage
                    Microsoft Games
                    Microsoft Office
                    Microsoft Works
                    Movie Maker
                    MSBuild
                    MSN
                    MSN Gaming Zone
                    MSN Messenger
                    MSXML 4.0
                    MSXML 6.0
                    MyWaySA
                    NetMeeting
                    NewSoft
                    Nowe Gadu-Gadu
                    Online Services
                    OpenOffice.org 2.0
                    Orange
                    Outlook Express
                    QuickTime
                    Real
                    Reference Assemblies
                    Research In Motion
                    Roxio
                    SAGEM
                    SAGEM Wi-Fi USB 802.11g
                    ScanSoft
                    Services en ligne
                    Sigmatel
                    Sonic
                    Stellarium
                    Symantec
                    Teamspeak2_RC2
                    Tiscali
                    TomTom DesktopSuite
                    TomTom HOME 2
                    TomTom International B.V
                    trend micro
                    Uninstall Information
                    Viewpoint
                    Wanadoo Europe
                    Windows Journal Viewer
                    Windows Live
                    Windows Live SkyDrive
                    Windows Media Connect 2
                    Windows Media Player
                    Windows NT
                    WindowsUpdate
                    WinStars2
                    World of Warcraft
                    WowCartographe
                    xerox
                    Your Company Name

                    ============
                    Drive C:
                    ============

                    apps
                    AUTOEXEC.BAT
                    autorun.inf
                    b0a50c316619b1690e
                    boot.ini
                    Bootfont.bin
                    CanonMF
                    Config.Msi
                    CONFIG.SYS
                    dell
                    dell.sdr
                    Documents and Settings
                    drivers
                    f8e4811719695cdb76
                    Fraps
                    hiberfil.sys
                    i386
                    INFCACHE.1
                    IO.SYS
                    IPH.PH
                    ituneslib.itl
                    Kill'em
                    List'em.txt
                    main.c
                    MSDOS.SYS
                    My Music
                    NTDETECT.COM
                    ntldr
                    pagefile.sys
                    paklog.txt
                    PDOXUSRS.NET
                    Program Files
                    RECYCLER
                    rsit
                    s16o
                    s198
                    s1qc
                    s27c
                    s290
                    s2js
                    s2k8
                    s2qs
                    s30k
                    s35s
                    s3f4
                    s3nc
                    s3sg
                    s3sk
                    s4h8
                    s4kk
                    s5ng
                    Setup.log
                    svo
                    System Volume Information
                    temp
                    temp.log
                    UsbFix
                    UsbFix.txt
                    UsbFix_Upload_Me_DDFFV82J.zip
                    WINDOWS

                    ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                    End of scan : 20:29:39,76
                    0
                    1. Contributeur sécurité
                      ok

                      si ubfix coince sur l'affaire on y reviendra plus tard..

                      on reporte également killem

                      fais ceci

                      • Téléchargez FindyKill sur le Bureau.

                      http://pagesperso-orange.fr/NosTools/Chiquitine29/Setup.exe

                      Mirroir :

                      http://findykill.changelog.fr/Setup.exe

                      • Double-cliquez sur FindyKill présent sur le Bureau.

                      • Choisissez l'option 1 (Recherche).

                      • Laissez travailler l'outil.

                      • Ensuite postez le rapport FindyKill.txt qui apparaîtra (si vous avez créé un sujet sur un forum pour vous faire aider).

                      • Note : Le rapport FindyKill.txt est sauvegardé à la racine du disque (C:\FindyKill.txt).

                      (CTRL+A pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller)

                      • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                      • Tuto : http://pagesperso-orange.fr/NosTools/index.html

                      0
                      1. c'est normal que sa fait logtemps que c'est a 90% ?je pense que oui mais bon . Donc mes mot de passe et tou ça non aucun risque a etre pris?
                        0
                        1. ah ? mais c'est etrange , l'infection je l'ai depuis que j'ai dl ce fichier . Et je ne comprends pas pourquoi mon Norton ne s'ouvrait plus . de tte facon je l'ai remplacé par avast mais bon.
                          0
                          1. Contributeur sécurité
                            ceci est l'infection dont je parle

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c341bfce-008a-11dc-b04d-0060b3b8f6c7}]
                            shell\Auto\command - AdobeR.exe e
                            shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e


                            aucun risque pour tes données perso
                            0
                            1. Non je l'ai eu en telechargant un fichier . le programme est en cours je te l'envoye a la fin ^^ . mais pense tu qu'il peut preendre mes donées perso ou non?
                              0
                              1. Contributeur sécurité
                                oui mais t'as quand même une infection qui t'as été transmise par un support usb

                                donc usbfix
                                0
                                1. Mais ce n'est pas sur une clé usb que j'ai eu le fichier .
                                  0
                                  1. Contributeur sécurité
                                    voir post 4
                                    0
                                    1. Maintenant je n'arrive pas a envoyer le info.txt il me dit que j'ai deja envoyé le message x) . bref , je sais que il ne fallais pas ll'executer mais bon . et aussi quand la fenetre s'ouvre audemarrage de windows , a chaque demarage car jj'ai changé les programme et service de demarage , a chaque fois je fait ok et sa se ferme , maintenat quand je fait ok il me disent qu'il y a une erreur et que je pourrait essayer de me mettre admin , mais je le suis ! Cela peut il etre un virus qui me prend mes coordonées? merci de votre aide !
                                      0
                                      1. Contributeur sécurité
                                        ok

                                        1)

                                        Téléchargez USBFIX de El Desaparecido, C_xx

                                        http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                                        ou
                                        https://www.ionos.fr/?affiliate_id=77097

                                        /!\ Utilisateur de vista et windows 7 :
                                        ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                                        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                                        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                                        • Double clic sur le raccourci UsbFix présent sur le bureau .

                                        • Choisir l'option2 suppression

                                        (d’autres options disponibles, voir le tutoriel).
                                        • Laissez travailler l'outil.
                                        Le menu démarrer et les icônes vont disparaître.. c'est normal.

                                        Si un message te demande de redémarrer l'ordinateur fais le ...

                                        ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

                                        ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

                                        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                                        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                                        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                        • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

                                        UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

                                        Il est enregistré sur ton bureau.

                                        Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                                        .......................

                                        2)

                                        Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                                        ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                                        http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                                        double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                                        coche la case "creer une icone sur le bureau"

                                        une fois terminée , clic sur "terminer" et le programme se lancer seul

                                        choisis la langue puis choisis l'option 1 = Mode Recherche

                                        ▶ laisse travailler l'outil

                                        à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                                        un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                                        ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                                        tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                                        0
                                        1. Logfile of random's system information tool 1.06 (written by random/random)
                                          Run by Martin at 2010-02-22 18:03:54
                                          Microsoft Windows XP Édition familiale Service Pack 2
                                          System drive C: has 229 GB (76%) free of 302 GB
                                          Total RAM: 1014 MB (51% free)

                                          Logfile of Trend Micro HijackThis v2.0.2
                                          Scan saved at 18:03:56, on 22/02/2010
                                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                                          MSIE: Internet Explorer v7.00 (7.00.6000.16981)
                                          Boot mode: Normal

                                          Running processes:
                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                          C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                          C:\Program Files\Bonjour\mDNSResponder.exe
                                          C:\Program Files\Java\jre6\bin\jqs.exe
                                          C:\WINDOWS\system32\HPZipm12.exe
                                          C:\WINDOWS\system32\PnkBstrA.exe
                                          C:\WINDOWS\system32\PnkBstrB.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                                          C:\WINDOWS\system32\LVCOMSX.EXE
                                          C:\WINDOWS\system32\igfxpers.exe
                                          C:\WINDOWS\system32\hkcmd.exe
                                          C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                                          C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                                          C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
                                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\ctfmon.exe
                                          C:\Program Files\Hercules\WiFi Station\WifiStation.exe
                                          C:\WINDOWS\system32\wuauclt.exe
                                          C:\Program Files\Google\Chrome\Application\chrome.exe
                                          C:\Program Files\Google\Chrome\Application\chrome.exe
                                          C:\Program Files\Google\Chrome\Application\chrome.exe
                                          C:\Program Files\Google\Chrome\Application\chrome.exe
                                          C:\Program Files\Google\Chrome\Application\chrome.exe
                                          C:\Program Files\Google\Chrome\Application\chrome.exe
                                          C:\Documents and Settings\Martin\Mes documents\Downloads\RSIT.exe
                                          C:\Program Files\trend micro\Martin.exe

                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DR
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.fr/myway
                                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
                                          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL (file missing)
                                          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
                                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                          O2 - BHO: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaze.dll (file missing)
                                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                          O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
                                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                          O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Martin\Application Data\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
                                          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                                          O3 - Toolbar: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaze.dll (file missing)
                                          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                                          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                                          O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                                          O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                                          O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                                          O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                                          O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                                          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                                          O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                          O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
                                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                          O4 - Global Startup: WiFi Station pour Livebox.lnk = ?
                                          O4 - Global Startup: WiFi Station.lnk = ?
                                          O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
                                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL (file missing)
                                          O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by118fd.bay118.hotmail.msn.com/resources/MsnPUpld.cab
                                          O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                                          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                                          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                          O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
                                          O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                                          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                          O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                          O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                                          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                          O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe (file missing)
                                          O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe (file missing)
                                          O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                          O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                          O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
                                          O23 - Service: Norton Protection Center Service (NSCService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE (file missing)
                                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                          O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
                                          O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
                                          O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
                                          O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
                                          O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
                                          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                          O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                                          0
                                          • 1
                                          • 2