Attaque réseau

Salut,

durant cette semaine, quand je suis connectée à internet, mon antivirus m'a annoncé 6 fois qu'il a décelé une attaque (de réseau), et il m'a aussi donné l'adresse IP de l'attaquant mais quand j'ai cherché son emplacement, j'ai remarqué que ce dernier ainsi que l'adresse ip sont changés d'une attaque à l'autre (je pense que cela est du au proxy que l'attaquant utilise). Je pense que cela est peut être causé par un spam??!!

Si vous pensez que c'est le cas, veuillez s'il vous plait m'aider à m'en débarrasser; sinon j'espère recevoir votre aide dans tous les cas car j'en ai vraiment besoin.

Merci d'avance

note : Hier j'ai téléchargé Ad-Aware et il a détecté 6 éléments dont il a supprimé 5 (Cookies) et mis 1 (fichier que j'ai supprimé apès) en quarantaine.



--
"La haine est la voix de celui qui a laissé la souffrance planter son drapeau aisément sur son encéphale"

46 réponses

Résumé de la discussion

Des alertes répétées d'attaque réseau ont été signalées par l'antivirus durant la semaine, l'adresse IP de l'attaquant semblant changer à chaque incident, vraisemblablement via un proxy. Plusieurs réponses recommandent des outils de diagnostic comme ZHPDiag et GMER pour repérer des rootkits et générer des rapports exploitables. D'autres conseils suggèrent d'utiliser List-Kill'em et des procédures de nettoyage associées, puis de partager les résultats via des liens de rapports afin d'obtenir une aide coordonnée. En dépit des outils évoqués, certains échanges montrent une prudence sur l'efficacité des antivirus gratuits et soulignent la nécessité de vérifier les modifications système et les éléments malveillants détectés.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonsoir

    on peut regarder

    Télécharge ZHPDiag ( de Nicolas coolman ).
    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

    (outil de diagnostic)

    Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

    Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin pour vista )

    Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

    Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

    Rend toi sur Cjoint : http://www.cijoint.fr/

    Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

    Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

    Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

    1
    1. Merci beaucoup :-) , voici le lien du rapport :

      http://www.cijoint.fr/cjlink.php?file=cj201004/cijeokMSQ2.txt
      0
      1. Contributeur sécurité
        ok

        System drive C: has 1 GB (2%) free of 49 GB


        => faire de la place

        sinon infection par support usb

        1)

        Téléchargez USBFIX de El Desaparecido, C_xx

        http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
        ou
        https://www.ionos.fr/?affiliate_id=77097

        /!\ Utilisateur de vista et windows 7 :
        ne pas oublier de désactiver Le contrôle des comptes utilisateurs
        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

        * Double clic sur le raccourci UsbFix présent sur le bureau .

        * Choisir l'option2 suppression
        (d'autres options disponibles, voir le tutoriel).
        * Laissez travailler l'outil.
        Le menu démarrer et les icônes vont disparaître.. c'est normal.

        Si un message te demande de redémarrer l'ordinateur fais le ...

        ? Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

        ? Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

        * Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

        * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        * Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

        UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

        Il est enregistré sur ton bureau.

        Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

        .................................

        2)

        Téléchargez MalwareByte's Anti-Malware (que tu pourras garder ensuite)

        http://www.malwarebytes.org/mbam/program/mbam-setup.exe

        . Enregistres le sur le bureau
        . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
        . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
        . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
        . Une fois la mise à jour terminé
        . Rend-toi dans l'onglet, Recherche
        . Sélectionnes Exécuter un examen complet (examen assez long)
        . Cliques sur Rechercher
        . Le scan démarre.
        . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
        . Cliques sur Ok pour poursuivre.
        . Si des malwares ont été détectés, clique sur Afficher les résultats
        . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
        . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
        . Rends toi dans l'onglet rapport/log
        . Tu cliques dessus pour l'afficher, une fois affiché
        . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
        . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
        . tu cliques droit dans le cadre de la reponse et coller

        Si tu as besoin d'aide regarde ces tutoriels :
        Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
        http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

        0
        1. OK merci moment de grace ^^, je vais télécharger USBFIX; pour MalwareByte's Anti-Malware je l'ai déjà sur mon pc et aujourd'hui je l'ai mis à jour pour faire un examen complet et il n'a rien détecté

          merci encore
          0
          1. Contributeur sécurité
            ok

            on maintient usbfix

            et ensuite à la place de MBAM

            Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

            Télécharge et installe List&Kill'em et enregistre le sur ton bureau

            http://sd-1.archive-host.com/...

            double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

            coche la case "creer une icone sur le bureau"

            une fois terminée , clic sur "terminer" et le programme se lancer seul

            choisis la langue puis choisis l'option SEARCH

            laisse travailler l'outil

            à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

            un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

            Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

            tu peux supprimer le rapport catchme.log de ton bureau maintenant.


            Je cherche beaucoup...et maintenant je trouve !
            (sourire)
            0
            1. Rapport de UsbFix:

              ############################## | UsbFix V6.106 |

              User : user (Administrateurs) # HANAA
              Update on 19/04/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 21:55:21 | 19/04/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
              Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
              Internet Explorer 7.0.5730.13
              Windows Firewall Status : Enabled
              AV : Kaspersky Anti-Virus 6.0.3.837 [ Enabled | Updated ]
              FW : Kaspersky Anti-Virus[ Enabled ]6.0.3.837

              C:\ -> Disque fixe local # 48,83 Go (266,39 Mo free) # NTFS
              D:\ -> Disque fixe local # 87,86 Go (86,15 Go free) # NTFS
              E:\ -> Disque CD-ROM
              H:\ -> Disque amovible # 1,86 Go (1,86 Go free) [PUBLIC] # FAT32

              ################## | Elements infectieux |

              Supprimé ! C:\DOCUME~1\user\LOCALS~1\Temp\NEW5.tmp.exe
              Supprimé ! C:\DOCUME~1\user\LOCALS~1\Temp\pyl8.tmp.exe
              Supprimé ! C:\DOCUME~1\user\LOCALS~1\Temp\pylB.tmp.exe
              Supprimé ! C:\DOCUME~1\user\LOCALS~1\Temp\pylC.tmp.exe
              Supprimé ! C:\Recycler\S-1-5-21-1214440339-162531612-682003330-1003
              Supprimé ! C:\Recycler\S-1-5-21-1214440339-162531612-682003330-500
              Supprimé ! D:\Recycler\S-1-5-21-1214440339-162531612-682003330-1003
              Supprimé ! D:\Recycler\S-1-5-21-1214440339-162531612-682003330-500

              ################## | Registre |

              ################## | Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{35eede66-e86f-11dd-9b1d-001d722cb9b2}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{35eede69-e86f-11dd-9b1d-001d722cb9b2}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{35eede6a-e86f-11dd-9b1d-001d722cb9b2}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{35eede6b-e86f-11dd-9b1d-001d722cb9b2}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{4abd921e-e221-11dd-9b09-001d722cb9b2}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{75da474b-2aa3-11de-9c09-001d722cb9b2}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{9446ba77-cdbf-11dd-9aca-001d722cb9b2}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{a69fbc48-0295-11de-9b76-001d722cb9b2}\Shell\explore\Command

              ################## | Listing des fichiers présent |

              [11/01/2010 03:34|--a------|1024] C:\.rnd
              [19/04/2010 21:54|--a------|601] C:\aaw7boot.log
              [20/11/2008 18:57|---hs----|212] C:\boot.ini
              [24/08/2001 14:00|-rahs----|4952] C:\Bootfont.bin
              [20/11/2008 19:03|--a------|0] C:\CONFIG.SYS
              [26/12/2009 12:11|--a------|128] C:\emu8086.io
              [12/12/2009 22:43|---------|85000] C:\essai.odp
              [?|?|?] C:\hiberfil.sys
              [20/11/2008 19:03|-rahs----|0] C:\IO.SYS
              [27/06/2008 18:00|---h-----|8682] C:\MessengerStyleSheet.xsl
              [13/12/2008 20:10|--a------|12336] C:\mpsn32.exe
              [20/11/2008 19:03|-rahs----|0] C:\MSDOS.SYS
              [12/12/2009 22:43|---------|10323] C:\no air.odt
              [03/08/2004 22:38|---hs----|47564] C:\NTDETECT.COM
              [03/08/2004 22:59|-rahs----|251712] C:\ntldr
              [?|?|?] C:\pagefile.sys
              [19/04/2010 22:05|--a------|3064] C:\UsbFix.txt
              [28/01/2010 23:38|--a------|35664] D:\usb-modeswitch-1.1.0.tar.bz2

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
              # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

              ################## | Upload |

              Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_HANAA.zip : https://www.ionos.fr/?affiliate_id=77097
              Merci pour votre contribution .

              ################## | ! Fin du rapport # UsbFix V6.106 ! |

              0
              1. Contributeur sécurité
                vu

                H:\ -> Disque amovible # 1,86 Go (1,86 Go free) [PUBLIC] # FAT32

                il n'était pas là au moment du scan....
                0
                1. vous parlez du disque amovible?
                  (si oui, il était là, son nom est "PUBLIC" et il était vide car je l'ai formaté depuis 2 jours)
                  0
                  1. Contributeur sécurité
                    oui repasses l'option 2 avec lui branché au pc
                    0
                2. Salut ^^ voici le rapport (et la clé était certainement là :) )

                  ############################## | UsbFix V6.106 |

                  User : user (Administrateurs) # HANAA
                  Update on 19/04/2010 by El Desaparecido , C_XX & Chimay8
                  Start at: 20:58:47 | 21/04/2010
                  Website : http://pagesperso-orange.fr/NosTools/index.html
                  Contact : FindyKill.Contact@gmail.com

                  Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                  Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                  Internet Explorer 7.0.5730.13
                  Windows Firewall Status : Enabled
                  AV : Kaspersky Anti-Virus 6.0.3.837 [ Enabled | Updated ]
                  FW : Kaspersky Anti-Virus[ Enabled ]6.0.3.837

                  C:\ -> Disque fixe local # 48,83 Go (747,99 Mo free) # NTFS
                  D:\ -> Disque fixe local # 87,86 Go (86,15 Go free) # NTFS
                  E:\ -> Disque CD-ROM
                  H:\ -> Disque amovible # 1,86 Go (1,86 Go free) [PUBLIC] # FAT32

                  ################## | Elements infectieux |

                  Supprimé ! C:\Recycler\S-1-5-21-1214440339-162531612-682003330-1003
                  Supprimé ! D:\Recycler\S-1-5-21-1214440339-162531612-682003330-1003

                  ################## | Registre |

                  ################## | Mountpoints2 |

                  ################## | Listing des fichiers présent |

                  [11/01/2010 03:34|--a------|1024] C:\.rnd
                  [21/04/2010 20:57|--a------|2393] C:\aaw7boot.log
                  [20/11/2008 18:57|---hs----|212] C:\boot.ini
                  [24/08/2001 14:00|-rahs----|4952] C:\Bootfont.bin
                  [20/11/2008 19:03|--a------|0] C:\CONFIG.SYS
                  [26/12/2009 12:11|--a------|128] C:\emu8086.io
                  [12/12/2009 22:43|---------|85000] C:\essai.odp
                  [?|?|?] C:\hiberfil.sys
                  [20/11/2008 19:03|-rahs----|0] C:\IO.SYS
                  [27/06/2008 18:00|---h-----|8682] C:\MessengerStyleSheet.xsl
                  [13/12/2008 20:10|--a------|12336] C:\mpsn32.exe
                  [20/11/2008 19:03|-rahs----|0] C:\MSDOS.SYS
                  [12/12/2009 22:43|---------|10323] C:\no air.odt
                  [03/08/2004 22:38|---hs----|47564] C:\NTDETECT.COM
                  [03/08/2004 22:59|-rahs----|251712] C:\ntldr
                  [?|?|?] C:\pagefile.sys
                  [21/04/2010 21:07|--a------|1851] C:\UsbFix.txt
                  [19/04/2010 22:05|--a------|1894886] C:\UsbFix_Upload_Me_HANAA.zip
                  [28/01/2010 23:38|--a------|35664] D:\usb-modeswitch-1.1.0.tar.bz2

                  ################## | Vaccination |

                  # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                  # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                  ################## | Upload |

                  Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_HANAA.zip : https://www.ionos.fr/?affiliate_id=77097
                  Merci pour votre contribution .

                  ################## | ! Fin du rapport # UsbFix V6.106 ! |

                  0
                  1. Contributeur sécurité
                    en relisant ton sujet, je vois aussi un peripherique F infecté et ne le vois pas sur ton rapport usbfix ?

                    de plus

                    Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                    Télécharge et installe List&Kill'em et enregistre le sur ton bureau

                    http://sd-1.archive-host.com/...

                    double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                    coche la case "creer une icone sur le bureau"

                    une fois terminée , clic sur "terminer" et le programme se lancer seul

                    choisis la langue puis choisis l'option SEARCH

                    laisse travailler l'outil

                    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                    un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                    Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                    tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                    0
                    1. Salut,
                      j'ai essayé de télécharger List&Kill'em mais le lien ne marche pas (erreur de chargement de la page), alors je l'ai cherché sur net mais la même chose arrivait tout le temps, je sais pas quoi faire :(
                      0
                      1. Contributeur sécurité
                        je viens de tester le lien, il fonctionne

                        l'outil devait être en cours de mise à jour
                        0
                        1. Enfin j'ai pu télécharger List&Kill'em :) et voici le rapport de search:

                          List'em by g3n-h@ckm@n 1.3.2.1

                          User : user (Administrateurs)
                          Update on 10/03/2010 by g3n-h@ckm@n ::::: 17.30
                          Start at: 22:53:21 | 25/04/2010
                          Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                          Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                          Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                          Internet Explorer 7.0.5730.13
                          Windows Firewall Status : Disabled
                          AV : Kaspersky Anti-Virus 6.0.3.837 [ (!) Disabled | Updated ]
                          FW : Kaspersky Anti-Virus[ (!) Disabled ]6.0.3.837

                          C:\ -> Disque fixe local | 48,83 Go (1,92 Go free) | NTFS
                          D:\ -> Disque fixe local | 87,86 Go (86,15 Go free) | NTFS
                          E:\ -> Disque CD-ROM

                          Boot: Normal

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\RTHDCPL.EXE
                          C:\WINDOWS\system32\igfxtray.exe
                          C:\WINDOWS\system32\hkcmd.exe
                          C:\WINDOWS\system32\igfxpers.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
                          C:\WINDOWS\system32\igfxsrvc.exe
                          C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
                          C:\Program Files\Lexmark 2600 Series\ezprint.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Program Files\Messenger\msmsgs.exe
                          C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
                          C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
                          C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
                          C:\Program Files\Free Download Manager\fdm.exe
                          C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe
                          C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                          C:\Program Files\Menara\dslmon.exe
                          C:\WINDOWS\system32\lxdncoms.exe
                          c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE
                          C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\wscntfy.exe
                          C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                          C:\WINDOWS\system32\wbem\unsecapp.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
                          C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
                          C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
                          C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
                          C:\DOCUME~1\user\LOCALS~1\Temp\RtkBtMnt.exe
                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                          C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                          C:\Program Files\List_Kill'em\List_Kill'em.exe
                          C:\WINDOWS\system32\cmd.exe
                          C:\Program Files\List_Kill'em\FxEx.scr
                          C:\WINDOWS\system32\cmd.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\Program Files\List_Kill'em\pv.exe

                          ======================
                          Keys "Run"
                          ======================
                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
                          MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          UMService REG_SZ C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                          MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
                          ares REG_SZ "C:\Program Files\Ares\Ares.exe" -h
                          swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          REVAService REG_SZ C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
                          PC Suite Tray REG_SZ "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
                          Software Informer REG_SZ "C:\Program Files\Software Informer\softinfo.exe" -autorun
                          Free Download Manager REG_SZ "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                          Z810SysStart REG_SZ C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe
                          Z810PNP REG_SZ C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
                          RTHDCPL REG_SZ RTHDCPL.EXE
                          Alcmtr REG_SZ ALCMTR.EXE
                          AzMixerSel REG_SZ C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                          IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
                          HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
                          Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
                          BroadcomWireless REG_SZ C:\Program Files\Broadcom\Wireless\Utility\WlanUtil.exe
                          TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          NokiaMServer REG_SZ C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer /watchfiles
                          SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                          AVP REG_SZ "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe"
                          lxdnmon.exe REG_SZ "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe"
                          EzPrint REG_SZ "C:\Program Files\Lexmark 2600 Series\ezprint.exe"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                          =====================
                          Other Keys
                          =====================
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                          dontdisplaylastusername REG_DWORD 0 (0x0)
                          legalnoticecaption REG_SZ
                          legalnoticetext REG_SZ
                          shutdownwithoutlogon REG_DWORD 1 (0x1)
                          undockwithoutlogon REG_DWORD 1 (0x1)

                          ===============
                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          NoSaveSettings REG_DWORD 0 (0x0)
                          NoDriveAutoRun REG_DWORD 255 (0xff)
                          NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                          HonorAutoRunSetting REG_DWORD 0 (0x0)

                          ===============
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          HonorAutoRunSetting REG_DWORD 0 (0x0)
                          NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                          NoDriveAutoRun REG_DWORD 255 (0xff)

                          ===============
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          AppInit_DLLS REG_SZ C:\PROGRA~1\KASPER~1\KASPER~1.0FO\adialhk.dll

                          ===============
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          AutoRestartShell REG_DWORD 1 (0x1)
                          DefaultDomainName REG_SZ HANAA
                          DefaultUserName REG_SZ user
                          LegalNoticeCaption REG_SZ
                          LegalNoticeText REG_SZ
                          PowerdownAfterShutdown REG_SZ 0
                          ReportBootOk REG_SZ 1
                          Shell REG_SZ explorer.exe
                          ShutdownWithoutLogon REG_SZ 0
                          System REG_SZ
                          Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                          VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                          SfcQuota REG_DWORD -1 (0xffffffff)
                          allocatecdroms REG_SZ 0
                          allocatedasd REG_SZ 0
                          allocatefloppies REG_SZ 0
                          cachedlogonscount REG_SZ 10
                          forceunlocklogon REG_DWORD 0 (0x0)
                          passwordexpirywarning REG_DWORD 14 (0xe)
                          scremoveoption REG_SZ 0
                          AllowMultipleTSSessions REG_DWORD 1 (0x1)
                          UIHost REG_EXPAND_SZ logonui.exe
                          LogonType REG_DWORD 1 (0x1)
                          Background REG_SZ 0 0 0
                          DebugServerCommand REG_SZ no
                          HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                          SFCDisable REG_DWORD 0 (0x0)
                          WinStationsDisabled REG_SZ 0
                          ShowLogonOptions REG_DWORD 0 (0x0)
                          AltDefaultUserName REG_SZ user
                          AltDefaultDomainName REG_SZ HANAA

                          ===============
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\klogon]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                          ===============
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                          {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                          ===============
                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                          C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
                          C:\wamp\Apache2\bin\httpd.exe REG_SZ C:\wamp\Apache2\bin\httpd.exe:*:Enabled:Apache HTTP Server
                          C:\wamp\bin\apache\Apache2.2.11\bin\httpd.exe REG_SZ C:\wamp\bin\apache\Apache2.2.11\bin\httpd.exe:*:Enabled:Apache HTTP Server
                          C:\Program Files\Ares\Ares.exe REG_SZ C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows
                          C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe REG_SZ C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix
                          C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                          C:\Program Files\aMSN\bin\wish.exe REG_SZ C:\Program Files\aMSN\bin\wish.exe:*:Disabled:Wish Application
                          C:\Program Files\Packet Tracer 5.0\bin\PacketTracer5.exe REG_SZ C:\Program Files\Packet Tracer 5.0\bin\PacketTracer5.exe:*:Enabled:PacketTracer5
                          C:\Program Files\Recosoft PDF2Office\PDF2Office v5.0\PDF2Office.exe REG_SZ C:\Program Files\Recosoft PDF2Office\PDF2Office v5.0\PDF2Office.exe:*:Enabled:PDF2Office
                          C:\Program Files\Recosoft PDF2Office\PDF2Office v5.0\PDF2OfficeDesktopServer.exe REG_SZ C:\Program Files\Recosoft PDF2Office\PDF2Office v5.0\PDF2OfficeDesktopServer.exe:*:Enabled:PDF2OfficeDesktopServer
                          C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE REG_SZ C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE:*:Enabled:Microsoft Office Word
                          C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE REG_SZ C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE:*:Enabled:Microsoft Office PowerPoint
                          C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE REG_SZ C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE:*:Disabled:Microsoft Office Excel
                          C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe REG_SZ C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe:*:Enabled:Apache HTTP Server
                          C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
                          C:\Program Files\Microsoft Office\Office12\WINWORD.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\WINWORD.EXE:*:Enabled:Microsoft Office Word
                          C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE:*:Enabled:Microsoft Office PowerPoint
                          C:\WINDOWS\system32\lxdncoms.exe REG_SZ C:\WINDOWS\system32\lxdncoms.exe:*:Enabled:Lexmark Communications System
                          C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnpswx.exe REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnpswx.exe:*:Enabled:Printer Status Window Interface
                          C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdntime.exe REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdntime.exe:*:Enabled:Lexmark Connect Time Executable
                          C:\Program Files\Lexmark 2600 Series\lxdnmon.exe REG_SZ C:\Program Files\Lexmark 2600 Series\lxdnmon.exe:*:Enabled:Printer Device Monitor
                          C:\Documents and Settings\user\Bureau\eclipse\eclipse.exe REG_SZ C:\Documents and Settings\user\Bureau\eclipse\eclipse.exe:*:Enabled:eclipse
                          C:\Program Files\Java\jre6\bin\javaw.exe REG_SZ C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary
                          C:\Documents and Settings\user\temp\TeamViewer\Version5\TeamViewer.exe REG_SZ C:\Documents and Settings\user\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer
                          C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnjswx.exe REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnjswx.exe:*:Enabled:Job Status Window Interface
                          C:\Documents and Settings\user\Mes documents\cours\FSTS\JAVA\eclipse\eclipse.exe REG_SZ C:\Documents and Settings\user\Mes documents\cours\FSTS\JAVA\eclipse\eclipse.exe:*:Enabled:eclipse

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                          C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
                          C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

                          ===============
                          ActivX controls
                          ===============
                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

                          ===============
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3F7924B9-D148-3141-87B1-68F36043A940}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

                          ==============
                          BHO :
                          ======
                          [<NO NAME> REG_SZ ]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                          ===
                          DNS
                          ===

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{EA1660F8-3782-493E-B3DF-6967A2A233AC}: NameServer=192.168.1.200,212.217.0.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{EA1660F8-3782-493E-B3DF-6967A2A233AC}: NameServer=192.168.1.200,212.217.0.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{EA1660F8-3782-493E-B3DF-6967A2A233AC}: NameServer=192.168.1.200,212.217.0.1

                          ================
                          Internet Explorer :
                          ================
                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          Start Page REG_SZ https://www.msn.com/fr-fr

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                          ========
                          Services
                          ========
                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                          Ndisuio : 0x3 ( OK = 3 )
                          SharedAccess : 0x2 ( OK = 2 )
                          wuauserv : 0x2 ( OK = 2 )

                          =========
                          Atapi.sys
                          =========

                          %%%% HASHDEEP-1.0
                          %%%% size,md5,sha256,filename
                          ## Invoked from: C:\Program Files\List_Kill'em
                          ## C:\> hashdeep.exe C:\WINDOWS\SoftwareDistribution\Download\d43a20c40794c502928d4b7d8ff0ea20\atapi.sys
                          ##
                          96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\SoftwareDistribution\Download\d43a20c40794c502928d4b7d8ff0ea20\atapi.sys
                          %%%% HASHDEEP-1.0
                          %%%% size,md5,sha256,filename
                          ## Invoked from: C:\Program Files\List_Kill'em
                          ## C:\> hashdeep.exe C:\WINDOWS\system32\dllcache\atapi.sys
                          ##
                          95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\dllcache\atapi.sys
                          %%%% HASHDEEP-1.0
                          %%%% size,md5,sha256,filename
                          ## Invoked from: C:\Program Files\List_Kill'em
                          ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
                          ##
                          95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\drivers\atapi.sys
                          %%%% HASHDEEP-1.0
                          %%%% size,md5,sha256,filename
                          ## Invoked from: C:\Program Files\List_Kill'em
                          ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
                          ##
                          95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
                          %%%% HASHDEEP-1.0
                          %%%% size,md5,sha256,filename
                          ## Invoked from: C:\Program Files\List_Kill'em
                          ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
                          ##
                          95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

                          Référence :
                          ==========

                          Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                          Win XP_32b : a64013e98426e1877cb653685c5c0009
                          Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                          Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                          Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                          Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                          Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                          Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                          Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                          Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                          =======
                          Drive :
                          =======

                          D'fragmenteur de disque Windows
                          Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                          Rapport d'analyse
                          48,83 Go total, 1,92 Go libre (3%), 27% fragment' (fragmentation du fichier 48%)

                          Vous devriez d'fragmenter ce volume.

                          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                          Present !! : C:\WINDOWS\SET3.tmp
                          Present !! : C:\WINDOWS\SET4.tmp
                          Present !! : C:\WINDOWS\SET8.tmp
                          Present !! : C:\WINDOWS\System32\Desktop_.ini
                          Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                          Present !! : C:\WINDOWS\System32\SET*.tmp
                          Present !! : C:\Documents and Settings\user\Local Settings\Temp\dw.log
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\apatch.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\DataCard_Setup.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\GoogleChromeInstaller.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\LOCKv233.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\msxml6-KB927977-enu-x86.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\ResetDevice.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\RtkBtMnt.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\setup_wm.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\sspatch.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\Toolbar.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\uninst.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\uninstall.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\wlsetup-cvr.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\wpsetup.exe
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\Perflib_Perfdata_b90.dat
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\SysConfig.dat
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\bassmod.dll
                          Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\NEventMessages.dll

                          ¤¤¤¤¤¤¤¤¤¤ Keys :

                          Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                          Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                          Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
                          Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
                          Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
                          Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
                          Present !! : HKCR\OutlookAddin.Addin
                          Present !! : HKCR\OutlookAddin.Addin.1
                          Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
                          Present !! : HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\OutlookAddin.Addin

                          ============

                          catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2010-04-25 23:09:09
                          Windows 5.1.2600 Service Pack 2 FAT NTAPI

                          scanning hidden processes ...

                          scanning hidden services ...

                          scanning hidden autostart entries ...

                          HKCU\Software\Microsoft\Windows\CurrentVersion\Run
                          Z810SysStart = C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe???w????s??wR??w??Z?}???????b??w????????????????4???s??|??????????Z?}???????????????D?A????w???w???w???????????????????wt;??????L??????w????????????????'?????A?????????????????r?A???????????????????????A
                          Z810PNP = C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe???? ??|'??|????]??|pi?w????????'???D??????w'???'??????????w???w|???|??????w???w'???????????????T??????w???????w???w???????w??@?'???P???P??????w??@?????????????????x?"|x?"|????l?6M%??????

                          scanning hidden files ...

                          scan completed successfully
                          hidden processes: 0
                          hidden services: 0
                          hidden files: 0

                          Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                          device: opened successfully
                          user: MBR read successfully
                          called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A5C11F8]<<
                          kernel: MBR read successfully
                          detected MBR rootkit hooks:
                          \Driver\atapi -> 0x8a5c11f8
                          Warning: possible MBR rootkit infection !
                          user & kernel MBR OK
                          Use "Recovery Console" command "fixmbr" to clear infection !

                          ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                          End of scan : 23:09:33,48
                          0
                          1. J'ai enfin pu télécharger List&Kill'am :) et voici le rapport de search :

                            List'em by g3n-h@ckm@n 1.3.2.1

                            User : user (Administrateurs)
                            Update on 10/03/2010 by g3n-h@ckm@n ::::: 17.30
                            Start at: 22:53:21 | 25/04/2010
                            Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                            Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                            Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                            Internet Explorer 7.0.5730.13
                            Windows Firewall Status : Disabled
                            AV : Kaspersky Anti-Virus 6.0.3.837 [ (!) Disabled | Updated ]
                            FW : Kaspersky Anti-Virus[ (!) Disabled ]6.0.3.837

                            C:\ -> Disque fixe local | 48,83 Go (1,92 Go free) | NTFS
                            D:\ -> Disque fixe local | 87,86 Go (86,15 Go free) | NTFS
                            E:\ -> Disque CD-ROM

                            Boot: Normal

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\csrss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\RTHDCPL.EXE
                            C:\WINDOWS\system32\igfxtray.exe
                            C:\WINDOWS\system32\hkcmd.exe
                            C:\WINDOWS\system32\igfxpers.exe
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
                            C:\WINDOWS\system32\igfxsrvc.exe
                            C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
                            C:\Program Files\Lexmark 2600 Series\ezprint.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
                            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe
                            C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
                            C:\Program Files\Free Download Manager\fdm.exe
                            C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe
                            C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe
                            C:\Program Files\Java\jre6\bin\jqs.exe
                            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                            C:\Program Files\Menara\dslmon.exe
                            C:\WINDOWS\system32\lxdncoms.exe
                            c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE
                            C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\wscntfy.exe
                            C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                            C:\WINDOWS\system32\wbem\unsecapp.exe
                            C:\WINDOWS\system32\wbem\wmiprvse.exe
                            C:\WINDOWS\System32\alg.exe
                            C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
                            C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
                            C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
                            C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
                            C:\DOCUME~1\user\LOCALS~1\Temp\RtkBtMnt.exe
                            C:\WINDOWS\system32\wbem\wmiapsrv.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Program Files\Windows Live\Contacts\wlcomm.exe
                            C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                            C:\Program Files\List_Kill'em\List_Kill'em.exe
                            C:\WINDOWS\system32\cmd.exe
                            C:\Program Files\List_Kill'em\FxEx.scr
                            C:\WINDOWS\system32\cmd.exe
                            C:\WINDOWS\system32\wbem\wmiprvse.exe
                            C:\Program Files\List_Kill'em\pv.exe

                            ======================
                            Keys "Run"
                            ======================
                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
                            MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                            UMService REG_SZ C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                            MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
                            ares REG_SZ "C:\Program Files\Ares\Ares.exe" -h
                            swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            REVAService REG_SZ C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
                            PC Suite Tray REG_SZ "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
                            Software Informer REG_SZ "C:\Program Files\Software Informer\softinfo.exe" -autorun
                            Free Download Manager REG_SZ "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                            Z810SysStart REG_SZ C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe
                            Z810PNP REG_SZ C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
                            RTHDCPL REG_SZ RTHDCPL.EXE
                            Alcmtr REG_SZ ALCMTR.EXE
                            AzMixerSel REG_SZ C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                            IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
                            HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
                            Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
                            BroadcomWireless REG_SZ C:\Program Files\Broadcom\Wireless\Utility\WlanUtil.exe
                            TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            NokiaMServer REG_SZ C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer /watchfiles
                            SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                            AVP REG_SZ "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe"
                            lxdnmon.exe REG_SZ "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe"
                            EzPrint REG_SZ "C:\Program Files\Lexmark 2600 Series\ezprint.exe"

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                            =====================
                            Other Keys
                            =====================
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                            dontdisplaylastusername REG_DWORD 0 (0x0)
                            legalnoticecaption REG_SZ
                            legalnoticetext REG_SZ
                            shutdownwithoutlogon REG_DWORD 1 (0x1)
                            undockwithoutlogon REG_DWORD 1 (0x1)

                            ===============
                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            NoSaveSettings REG_DWORD 0 (0x0)
                            NoDriveAutoRun REG_DWORD 255 (0xff)
                            NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                            HonorAutoRunSetting REG_DWORD 0 (0x0)

                            ===============
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            HonorAutoRunSetting REG_DWORD 0 (0x0)
                            NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                            NoDriveAutoRun REG_DWORD 255 (0xff)

                            ===============
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                            AppInit_DLLS REG_SZ C:\PROGRA~1\KASPER~1\KASPER~1.0FO\adialhk.dll

                            ===============
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            AutoRestartShell REG_DWORD 1 (0x1)
                            DefaultDomainName REG_SZ HANAA
                            DefaultUserName REG_SZ user
                            LegalNoticeCaption REG_SZ
                            LegalNoticeText REG_SZ
                            PowerdownAfterShutdown REG_SZ 0
                            ReportBootOk REG_SZ 1
                            Shell REG_SZ explorer.exe
                            ShutdownWithoutLogon REG_SZ 0
                            System REG_SZ
                            Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                            VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                            SfcQuota REG_DWORD -1 (0xffffffff)
                            allocatecdroms REG_SZ 0
                            allocatedasd REG_SZ 0
                            allocatefloppies REG_SZ 0
                            cachedlogonscount REG_SZ 10
                            forceunlocklogon REG_DWORD 0 (0x0)
                            passwordexpirywarning REG_DWORD 14 (0xe)
                            scremoveoption REG_SZ 0
                            AllowMultipleTSSessions REG_DWORD 1 (0x1)
                            UIHost REG_EXPAND_SZ logonui.exe
                            LogonType REG_DWORD 1 (0x1)
                            Background REG_SZ 0 0 0
                            DebugServerCommand REG_SZ no
                            HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                            SFCDisable REG_DWORD 0 (0x0)
                            WinStationsDisabled REG_SZ 0
                            ShowLogonOptions REG_DWORD 0 (0x0)
                            AltDefaultUserName REG_SZ user
                            AltDefaultDomainName REG_SZ HANAA

                            ===============
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\klogon]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                            ===============
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                            {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                            ===============
                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                            %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                            C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
                            C:\wamp\Apache2\bin\httpd.exe REG_SZ C:\wamp\Apache2\bin\httpd.exe:*:Enabled:Apache HTTP Server
                            C:\wamp\bin\apache\Apache2.2.11\bin\httpd.exe REG_SZ C:\wamp\bin\apache\Apache2.2.11\bin\httpd.exe:*:Enabled:Apache HTTP Server
                            C:\Program Files\Ares\Ares.exe REG_SZ C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows
                            C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe REG_SZ C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix
                            C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                            C:\Program Files\aMSN\bin\wish.exe REG_SZ C:\Program Files\aMSN\bin\wish.exe:*:Disabled:Wish Application
                            C:\Program Files\Packet Tracer 5.0\bin\PacketTracer5.exe REG_SZ C:\Program Files\Packet Tracer 5.0\bin\PacketTracer5.exe:*:Enabled:PacketTracer5
                            C:\Program Files\Recosoft PDF2Office\PDF2Office v5.0\PDF2Office.exe REG_SZ C:\Program Files\Recosoft PDF2Office\PDF2Office v5.0\PDF2Office.exe:*:Enabled:PDF2Office
                            C:\Program Files\Recosoft PDF2Office\PDF2Office v5.0\PDF2OfficeDesktopServer.exe REG_SZ C:\Program Files\Recosoft PDF2Office\PDF2Office v5.0\PDF2OfficeDesktopServer.exe:*:Enabled:PDF2OfficeDesktopServer
                            C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE REG_SZ C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE:*:Enabled:Microsoft Office Word
                            C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE REG_SZ C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE:*:Enabled:Microsoft Office PowerPoint
                            C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE REG_SZ C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE:*:Disabled:Microsoft Office Excel
                            C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe REG_SZ C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe:*:Enabled:Apache HTTP Server
                            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
                            C:\Program Files\Microsoft Office\Office12\WINWORD.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\WINWORD.EXE:*:Enabled:Microsoft Office Word
                            C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE:*:Enabled:Microsoft Office PowerPoint
                            C:\WINDOWS\system32\lxdncoms.exe REG_SZ C:\WINDOWS\system32\lxdncoms.exe:*:Enabled:Lexmark Communications System
                            C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnpswx.exe REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnpswx.exe:*:Enabled:Printer Status Window Interface
                            C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdntime.exe REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdntime.exe:*:Enabled:Lexmark Connect Time Executable
                            C:\Program Files\Lexmark 2600 Series\lxdnmon.exe REG_SZ C:\Program Files\Lexmark 2600 Series\lxdnmon.exe:*:Enabled:Printer Device Monitor
                            C:\Documents and Settings\user\Bureau\eclipse\eclipse.exe REG_SZ C:\Documents and Settings\user\Bureau\eclipse\eclipse.exe:*:Enabled:eclipse
                            C:\Program Files\Java\jre6\bin\javaw.exe REG_SZ C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary
                            C:\Documents and Settings\user\temp\TeamViewer\Version5\TeamViewer.exe REG_SZ C:\Documents and Settings\user\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer
                            C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnjswx.exe REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnjswx.exe:*:Enabled:Job Status Window Interface
                            C:\Documents and Settings\user\Mes documents\cours\FSTS\JAVA\eclipse\eclipse.exe REG_SZ C:\Documents and Settings\user\Mes documents\cours\FSTS\JAVA\eclipse\eclipse.exe:*:Enabled:eclipse

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                            %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                            C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
                            C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

                            ===============
                            ActivX controls
                            ===============
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

                            ===============
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3F7924B9-D148-3141-87B1-68F36043A940}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

                            ==============
                            BHO :
                            ======
                            [<NO NAME> REG_SZ ]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                            ===
                            DNS
                            ===

                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{EA1660F8-3782-493E-B3DF-6967A2A233AC}: NameServer=192.168.1.200,212.217.0.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{EA1660F8-3782-493E-B3DF-6967A2A233AC}: NameServer=192.168.1.200,212.217.0.1
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{EA1660F8-3782-493E-B3DF-6967A2A233AC}: NameServer=192.168.1.200,212.217.0.1

                            ================
                            Internet Explorer :
                            ================
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.msn.com/fr-fr

                            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                            ========
                            Services
                            ========
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                            Ndisuio : 0x3 ( OK = 3 )
                            SharedAccess : 0x2 ( OK = 2 )
                            wuauserv : 0x2 ( OK = 2 )

                            =========
                            Atapi.sys
                            =========

                            %%%% HASHDEEP-1.0
                            %%%% size,md5,sha256,filename
                            ## Invoked from: C:\Program Files\List_Kill'em
                            ## C:\> hashdeep.exe C:\WINDOWS\SoftwareDistribution\Download\d43a20c40794c502928d4b7d8ff0ea20\atapi.sys
                            ##
                            96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\SoftwareDistribution\Download\d43a20c40794c502928d4b7d8ff0ea20\atapi.sys
                            %%%% HASHDEEP-1.0
                            %%%% size,md5,sha256,filename
                            ## Invoked from: C:\Program Files\List_Kill'em
                            ## C:\> hashdeep.exe C:\WINDOWS\system32\dllcache\atapi.sys
                            ##
                            95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\dllcache\atapi.sys
                            %%%% HASHDEEP-1.0
                            %%%% size,md5,sha256,filename
                            ## Invoked from: C:\Program Files\List_Kill'em
                            ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
                            ##
                            95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\drivers\atapi.sys
                            %%%% HASHDEEP-1.0
                            %%%% size,md5,sha256,filename
                            ## Invoked from: C:\Program Files\List_Kill'em
                            ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
                            ##
                            95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
                            %%%% HASHDEEP-1.0
                            %%%% size,md5,sha256,filename
                            ## Invoked from: C:\Program Files\List_Kill'em
                            ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
                            ##
                            95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

                            Référence :
                            ==========

                            Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                            Win XP_32b : a64013e98426e1877cb653685c5c0009
                            Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                            Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                            Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                            Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                            Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                            Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                            Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                            Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                            =======
                            Drive :
                            =======

                            D'fragmenteur de disque Windows
                            Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                            Rapport d'analyse
                            48,83 Go total, 1,92 Go libre (3%), 27% fragment' (fragmentation du fichier 48%)

                            Vous devriez d'fragmenter ce volume.

                            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                            Present !! : C:\WINDOWS\SET3.tmp
                            Present !! : C:\WINDOWS\SET4.tmp
                            Present !! : C:\WINDOWS\SET8.tmp
                            Present !! : C:\WINDOWS\System32\Desktop_.ini
                            Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                            Present !! : C:\WINDOWS\System32\SET*.tmp
                            Present !! : C:\Documents and Settings\user\Local Settings\Temp\dw.log
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\apatch.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\DataCard_Setup.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\GoogleChromeInstaller.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\LOCKv233.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\msxml6-KB927977-enu-x86.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\ResetDevice.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\RtkBtMnt.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\setup_wm.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\sspatch.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\Toolbar.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\uninst.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\uninstall.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\wlsetup-cvr.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\wpsetup.exe
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\Perflib_Perfdata_b90.dat
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\SysConfig.dat
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\bassmod.dll
                            Present !! : C:\Documents and Settings\user\LOCAL Settings\Temp\NEventMessages.dll

                            ¤¤¤¤¤¤¤¤¤¤ Keys :

                            Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                            Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                            Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\OutlookAddin.Addin
                            Present !! : HKCR\OutlookAddin.Addin.1
                            Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKLM\SOFTWARE\Microsoft\Office\Outlook\Addins\OutlookAddin.Addin

                            ============

                            catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2010-04-25 23:09:09
                            Windows 5.1.2600 Service Pack 2 FAT NTAPI

                            scanning hidden processes ...

                            scanning hidden services ...

                            scanning hidden autostart entries ...

                            HKCU\Software\Microsoft\Windows\CurrentVersion\Run
                            Z810SysStart = C:\Program Files\Modem Samsung SCH-U209\sysctrlU.exe???w????s??wR??w??Z?}???????b??w????????????????4???s??|??????????Z?}???????????????D?A????w???w???w???????????????????wt;??????L??????w????????????????'?????A?????????????????r?A???????????????????????A
                            Z810PNP = C:\Program Files\Modem Samsung SCH-U209\SamsungPnPServiceManager.exe???? ??|'??|????]??|pi?w????????'???D??????w'???'??????????w???w|???|??????w???w'???????????????T??????w???????w???w???????w??@?'???P???P??????w??@?????????????????x?"|x?"|????l?6M%??????

                            scanning hidden files ...

                            scan completed successfully
                            hidden processes: 0
                            hidden services: 0
                            hidden files: 0

                            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                            device: opened successfully
                            user: MBR read successfully
                            called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A5C11F8]<<
                            kernel: MBR read successfully
                            detected MBR rootkit hooks:
                            \Driver\atapi -> 0x8a5c11f8
                            Warning: possible MBR rootkit infection !
                            user & kernel MBR OK
                            Use "Recovery Console" command "fixmbr" to clear infection !

                            ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                            End of scan : 23:09:33,48

                            0
                            1. List'em by g3n-h@ckm@n 1.3.2.1

                              User : user (Administrateurs)
                              Update on 10/03/2010 by g3n-h@ckm@n ::::: 17.30

                              bonsoir elle est obsolete cette version....tiens le lien direct :

                              http://sd-1.archive-host.com/...
                              ?G3?-?@¢??@?(TM)©®?
                              0
                              1. http://www.cijoint.fr/cjlink.php?file=cj201004/cijwydlMZz.zip
                                0
                                1. Contributeur sécurité
                                  vu la discussion

                                  en attente du rapport killem derniere version (merci Gen)

                                  http://www.cijoint.fr/cjlink.php?file=cj201004/cijwydlMZz.zip

                                  0
                                  1. Merci beaucoup et voici le rapport:

                                    http://www.cijoint.fr/cjlink.php?file=cj201004/cijaYviVNg.txt

                                    0
                                    1. Contributeur sécurité
                                      ok

                                      1)

                                      Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                                      mais cette fois-ci :

                                      choisis l'option CLEAN
                                      ton PC va redemarrer,

                                      laisse travailler l'outil.

                                      en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                                      colle le contenu dans ta reponse

                                      .........................

                                      2)

                                      /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\
                                      * Télécharge mbr.exe de Gmer ici : http://www2.gmer.net/mbr/mbr.exe et enregistre le fichier sur le Bureau.
                                      * Merci à Malekal pour le tutoriel
                                      * Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
                                      * Double clique sur mbr.exe
                                      * Un rapport sera généré : mbr.log
                                      * En cas d'infection, ce message "MBR rootkit code detected" va apparaitre.
                                      * Pour supprimer le rootkit aller dans le menu Démarrer=> Exécuter et tapez la commande en gras: "%userprofile%\Bureau\mbr" -f
                                      * (veuillez à bien respecter les guillemets)
                                      * Dans le mbr.log cette ligne apparaitra "original MBR restored successfully !"
                                      * Réactive tes protections .Poste ce rapport et supprime le ensuite.

                                      o Pour vérifier désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
                                      o Relance mbr.exe
                                      o Réactive tes protections.
                                      o Le nouveau mbr.log devrait être celui-ci :
                                      o Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
                                      o device: opened successfully
                                      user: MBR read successfully
                                      kernel: MBR read successfully
                                      user & kernel MBR OK

                                      0
                                      • 1
                                      • 2
                                      • 3