Actualité informatique
Test comparatif matériel informatique
Jeux vidéo
Astuces informatique
Vidéo
Télécharger
Services en ligne
Forum informatique
01Business

|-  SECURITE


|||-  

Invasion virus, plus de connection internet! (RESOLU)

 

56 utilisateurs inconnus
 

 
Page photos
 
     
Vider la liste des messages à citer
 
 Page :
1  2
Dernière Page
Page Suivante
Page Précédente
Première Page
Auteur
 Sujet :

Invasion virus, plus de connection internet! (RESOLU)

RÉSOLU
Prévenir les modérateurs en cas d'abus 
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 16/03/2012 à 19:09:14  
  1. Prévenir les modérateurs en cas d'abus
 
Bonjour,

 Mon ordinateur s'est infesté de virus, en ouvrant une page internet. Depuis je n'ai plus accès à internet. Des messages de sécurité s'ouvrent continuellement.
 En faisant un scan avec Avast plusieurs virus s'affichent, je n'arrive pas à les supprimer, et leurs nombres augmentent à chaque scan complet.
 J'ai un second ordinateur qui me permet d'envoyer ce message sur internet;

 Pourriez vous m'aidez s'il vous plaît!

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 16/03/2012 à 22:06:15  
  1. Prévenir les modérateurs en cas d'abus
 
salut arrives tu as demarrer en mode sans echec
 avec prise en charge reseau ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
(Publicité)
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 16/03/2012 à 23:31:46  
  1. Prévenir les modérateurs en cas d'abus
 

 

did80 a écrit :

salut arrives tu as demarrer en mode sans echec
 avec prise en charge reseau ;)

 




 Bonsoir,
 Je suis novice en informatique, comment fait-on cela, à quoi ça correspond?
 Merci

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 17/03/2012 à 15:43:30  
  1. Prévenir les modérateurs en cas d'abus
 
:hello: vahi

 tu tapotes plusieurs fois sur F8 (F5pour certains pc) au démarrage du pc

 tu obtiens cet ecran

 http://lafibre.info/images/tut​o/windows_xp_mode_sans_echec.p​ng

 la prise en charge réseau permet d'obtenir internet  ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 17/03/2012 à 20:09:28  
  1. Prévenir les modérateurs en cas d'abus
 

 Voilà, j'ai redémarré en "Mode sans échec avec prise en charge réseau"
 Tout apparaît en gros caractères, et j'ai bien accès à internet.
 Que faire maintenant?

(Publicité)
Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 17/03/2012 à 21:53:52  
  1. Prévenir les modérateurs en cas d'abus
 

  :super:  pour les gros caractères c'est normal

  fais ceci

 Télécharge Adwcleaner

  adwcleaner ICI
 Télécharges Pour Vista et Windows 7 : il faut lancer le fichier par clic-droit "Exécuter en tant qu'administrateur"

 Lance AdwCleaner.exe
 Acceptes l'avertissement qui suit
 Clic sur suppression
 
 

 copies/colles sur le forum  le rapport qui apparait à la fin.

 Il est sauvegardé aussi sous (C:\AdwCleaner[S1].txt)
 Click sur Quitter
 ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 17/03/2012 à 22:36:49  
  1. Prévenir les modérateurs en cas d'abus
 
Voici le rapport:

 # AdwCleaner v1.502 - Rapport créé le 17/03/2012 à 10:16:19
 # Mis à jour le 17/03/2012 par Xplode
 # Système d'exploitation : Windows Vista (TM) Business Service Pack 2 (32 bits)
 # Nom d'utilisateur : Mahine - PCMAHINE
 # Exécuté depuis : C:\Users\Mahine\Downloads\adwc​leaner (1).exe
 # Option [Suppression]


 ***** [Services] *****


 ***** [Fichiers / Dossiers] *****

 Dossier Supprimé : C:\Users\Mahine\AppData\LocalL​ow\Conduit
 Dossier Supprimé : C:\Users\Mahine\AppData\Roamin​g\Mozilla\Firefox\Profiles\tmr​hgqhl.default\Conduit
 Dossier Supprimé : C:\Users\Mahine\AppData\Roamin​g\Mozilla\Firefox\Profiles\tmr​hgqhl.default\extensions\{872b​5b88-9db5-4310-bdd0-ac189557e5​f5}
 Fichier Supprimé : C:\Users\Mahine\AppData\Roamin​g\Mozilla\Firefox\Profiles\tmr​hgqhl.default\searchplugins\Co​nduit.xml

 ***** [H. Navipromo] *****


 ***** [Registre] *****

 
  • Clé Supprimée : HKLM\SOFTWARE\Classes\Toolbar.​CT2269050
Clé Supprimée : HKCU\Software\AppDataLow\Softw​are\Conduit
 Clé Supprimée : HKLM\SOFTWARE\Classes\Interfac​e\{8AD9AD05-36BE-4E40-BA62-542​2EB0D02FB}
 Clé Supprimée : HKLM\SOFTWARE\Classes\Interfac​e\{AEBF09E2-0C15-43C8-99BF-928​C645D98A0}
 Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\​{CDCA70D8-C6A6-49EE-9BED-7429D​6C477A2}
 Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\​{D136987F-E1C4-4CCC-A220-893DF​03EC5DF}
 Clé Supprimée : HKCU\Software\Microsoft\Intern​et Explorer\SearchScopes\{afdbdda​a-5d3f-42ee-b79c-185a7020515b}
 Clé Supprimée : HKLM\SOFTWARE\Microsoft\Intern​et Explorer\SearchScopes\{afdbdda​a-5d3f-42ee-b79c-185a7020515b}

 ***** [Navigateurs] *****

 -\\ Internet Explorer v9.0.8112.16421

 [OK] Le registre ne contient aucune entrée illégitime.

 -\\ Mozilla Firefox v10.0.2 (fr)

 Profil : tmrhgqhl.default
 Fichier : C:\Users\Mahine\AppData\Roamin​g\Mozilla\Firefox\Profiles\tmr​hgqhl.default\prefs.js

 Supprimée : user_pref("CT2269050.AboutPriv​acyUrl", "hxxp://www.conduit.com/privac​y/Default.aspx" );
 Supprimée : user_pref("CT2269050.CTID", "CT2269050" );
 Supprimée : user_pref("CT2269050.CurrentSe​rverDate", "13-12-2010" );
 Supprimée : user_pref("CT2269050.DialogsAl​ignMode", "LTR" );
 Supprimée : user_pref("CT2269050.DownloadR​eferralCookieData", "" );
 Supprimée : user_pref("CT2269050.EMailNoti​fierPollDate", "Mon Dec 13 2010 08:30:23 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.FirstServ​erDate", "16-11-2010" );
 Supprimée : user_pref("CT2269050.FirstTime​", true);
 Supprimée : user_pref("CT2269050.FirstTime​FF3", true);
 Supprimée : user_pref("CT2269050.FirstTime​SettingsDone", true);
 Supprimée : user_pref("CT2269050.FixPageNo​tFoundErrors", true);
 Supprimée : user_pref("CT2269050.GroupingS​erverCheckInterval", 1440);
 Supprimée : user_pref("CT2269050.GroupingS​erviceUrl", "hxxp://grouping.services.cond​uit.com/" );
 Supprimée : user_pref("CT2269050.Initializ​e", true);
 Supprimée : user_pref("CT2269050.Initializ​eCommonPrefs", true);
 Supprimée : user_pref("CT2269050.Installat​ionAndCookieDataSentCount", 3);
 Supprimée : user_pref("CT2269050.Installat​ionType", "UnknownIntegration" );
 Supprimée : user_pref("CT2269050.Installed​Date", "Tue Nov 16 2010 06:52:20 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.Invalidat​eCache", false);
 Supprimée : user_pref("CT2269050.IsGroupin​g", false);
 Supprimée : user_pref("CT2269050.IsMultico​mmunity", false);
 Supprimée : user_pref("CT2269050.IsOpenTha​nkYouPage", false);
 Supprimée : user_pref("CT2269050.IsOpenUni​nstallPage", false);
 Supprimée : user_pref("CT2269050.LanguageP​ackLastCheckTime", "Sun Dec 12 2010 16:49:06 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.LanguageP​ackReloadIntervalMM", 1440);
 Supprimée : user_pref("CT2269050.LanguageP​ackServiceUrl", "hxxp://translation.users.cond​uit.com/Translation.ashx[...]
 Supprimée : user_pref("CT2269050.LastLogin​_2.7.0.14", "Mon Dec 13 2010 08:30:25 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.LatestVer​sion", "3.2.5.2" );
 Supprimée : user_pref("CT2269050.Locale", "en" );
 Supprimée : user_pref("CT2269050.LoginCach​e", 4);
 Supprimée : user_pref("CT2269050.MCDetectT​ooltipHeight", "83" );
 Supprimée : user_pref("CT2269050.MCDetectT​ooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank​/tooltip/?version=1" );
 Supprimée : user_pref("CT2269050.MCDetectT​ooltipWidth", "295" );
 Supprimée : user_pref("CT2269050.RadioIsPo​dcast", false);
 Supprimée : user_pref("CT2269050.RadioLast​CheckTime", "Sun Dec 12 2010 16:49:07 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.RadioLast​UpdateIPServer", "3" );
 Supprimée : user_pref("CT2269050.RadioLast​UpdateServer", "129132338014870000" );
 Supprimée : user_pref("CT2269050.RadioMedi​aID", "12473383" );
 Supprimée : user_pref("CT2269050.RadioMedi​aType", "Media Player" );
 Supprimée : user_pref("CT2269050.RadioMenu​SelectedID", "EBRadioMenu_CT226905012473383​" );
 Supprimée : user_pref("CT2269050.RadioStat​ionName", "Hotmix%20108" );
 Supprimée : user_pref("CT2269050.RadioStat​ionURL", "hxxp://67.202.67.18:8082" );
 Supprimée : user_pref("CT2269050.SavedHome​page", "resource:/browserconfig.prope​rties" );
 Supprimée : user_pref("CT2269050.SearchEng​ine", "Search||hxxp://search.conduit​.com/Results.aspx?q=UCM_SEARCH​_TER[...]
 Supprimée : user_pref("CT2269050.SearchFro​mAddressBarIsInit", true);
 Supprimée : user_pref("CT2269050.SearchFro​mAddressBarUrl", "hxxp://search.conduit.com/Res​ultsExt.aspx?ctid=CT226[...]
 Supprimée : user_pref("CT2269050.SearchInN​ewTabEnabled", true);
 Supprimée : user_pref("CT2269050.SearchInN​ewTabIntervalMM", 1440);
 Supprimée : user_pref("CT2269050.SearchInN​ewTabLastCheckTime", "Sun Dec 12 2010 16:49:04 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.SearchInN​ewTabServiceUrl", "hxxp://newtab.conduit-hosting​.com/newtab/?ctid=EB_T[...]
 Supprimée : user_pref("CT2269050.SearchInN​ewTabUsageUrl", "hxxp://Usage.Hosting.conduit-​services.com/UsageServic[...]
 Supprimée : user_pref("CT2269050.SettingsC​heckIntervalMin", 120);
 Supprimée : user_pref("CT2269050.SettingsL​astCheckTime", "Mon Dec 13 2010 08:30:22 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.SettingsL​astUpdate", "1288889980" );
 Supprimée : user_pref("CT2269050.ThirdPart​yComponentsInterval", 504);
 Supprimée : user_pref("CT2269050.ThirdPart​yComponentsLastCheck", "Sun Dec 12 2010 16:49:03 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.ThirdPart​yComponentsLastUpdate", "1246790578" );
 Supprimée : user_pref("CT2269050.TrusteLin​kUrl", "hxxp://www.truste.org/pvr.php​?page=validate&softwareProgram​Id=[...]
 Supprimée : user_pref("CT2269050.UserID", "UN89359174883153478" );
 Supprimée : user_pref("CT2269050.WeatherNe​twork", "" );
 Supprimée : user_pref("CT2269050.WeatherPo​llDate", "Mon Dec 13 2010 08:30:25 GMT-1000 (Hawaii)" );
 Supprimée : user_pref("CT2269050.WeatherUn​it", "F" );
 Supprimée : user_pref("CT2269050.alertChan​nelId", "666138" );
 Supprimée : user_pref("CT2269050.clientLog​IsEnabled", false);
 Supprimée : user_pref("CT2269050.clientLog​ServiceUrl", "hxxp://clientlog.users.condui​t.com/ClientDiagnostics.asm[...]
 Supprimée : user_pref("CT2269050.myStuffEn​abled", true);
 Supprimée : user_pref("CT2269050.myStuffPu​blihserMinWidth", 400);
 Supprimée : user_pref("CT2269050.myStuffSe​archUrl", "hxxp://Apps.conduit.com/searc​h?q=SEARCH_TERM&SearchSourceOr[...]
 Supprimée : user_pref("CT2269050.myStuffSe​rviceIntervalMM", 1440);
 Supprimée : user_pref("CT2269050.myStuffSe​rviceUrl", "hxxp://mystuff.conduit-servic​es.com/MyStuffService.ashx?Co[...]
 Supprimée : user_pref("CT2269050.uninstall​LogServiceUrl", "hxxp://uninstall.users.condui​t.com/Uninstall.asmx/Reg[...]
 Supprimée : user_pref("CommunityToolbar.Se​archFromAddressBarSavedUrl", "chrome://browser-region/local​e/region.pr[...]
 Supprimée : user_pref("CommunityToolbar.To​olbarsList", "CT2269050" );
 Supprimée : user_pref("CommunityToolbar.To​olbarsList2", "CT2269050" );
 Supprimée : user_pref("CommunityToolbar.al​ert.alertInfoInterval", 1440);
 Supprimée : user_pref("CommunityToolbar.al​ert.alertInfoLastCheckTime", "Mon Dec 13 2010 08:30:22 GMT-1000 (Hawai[...]
 Supprimée : user_pref("CommunityToolbar.al​ert.clientsServerUrl", "hxxp://alert.client.conduit.c​om" );
 Supprimée : user_pref("CommunityToolbar.al​ert.locale", "en" );
 Supprimée : user_pref("CommunityToolbar.al​ert.loginIntervalMin", 1440);
 Supprimée : user_pref("CommunityToolbar.al​ert.loginLastCheckTime", "Sun Dec 12 2010 16:49:03 GMT-1000 (Hawaii)" )[...]
 Supprimée : user_pref("CommunityToolbar.al​ert.loginLastUpdateTime", "1291052234" );
 Supprimée : user_pref("CommunityToolbar.al​ert.messageShowTimeSec", 20);
 Supprimée : user_pref("CommunityToolbar.al​ert.servicesServerUrl", "hxxp://alert.services.conduit​.com" );
 Supprimée : user_pref("CommunityToolbar.al​ert.showTrayIcon", false);
 Supprimée : user_pref("CommunityToolbar.al​ert.userCloseIntervalMin", 300);
 Supprimée : user_pref("CommunityToolbar.al​ert.userId", "{a80eb6ae-916d-4852-93f7-e47e​e1c651ec}" );
 Supprimée : user_pref("CommunityToolbar.fa​cebook.settingsLastCheckTime", "Sun Dec 12 2010 16:49:07 GMT-1000 (Haw[...]
 Supprimée : user_pref("CommunityToolbar.ke​ywordURLSelectedCTID", "CT2269050" );
 Supprimée : user_pref("browser.search.defa​ulturl", "hxxp://search.conduit.com/Res​ultsExt.aspx?ctid=CT2269050&Se​a[...]
 Supprimée : user_pref("browser.startup.hom​epage", "hxxp://search.conduit.com/?ct​id=CT2269050&SearchSource=13" )​;
 Supprimée : user_pref("keyword.URL", "hxxp://search.conduit.com/Res​ultsExt.aspx?ctid=CT2269050&q=​" );

 *************************

 AdwCleaner[S1].txt - [9387 octets] - [17/03/2012 10:16:19]

 ########## EOF - C:\AdwCleaner[S1].txt - [9515 octets] ##########

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 17/03/2012 à 22:45:08  
  1. Prévenir les modérateurs en cas d'abus
 
:super: on continue

 meme procedure  avec ad remover cette fois

 tu le télécharges

 http://www.donnemoilinfo.com/t [...] emover.php

 copies/colles le rapport ad reportCLEAN1.txt ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
(Publicité)
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 17/03/2012 à 23:07:33  
  1. Prévenir les modérateurs en cas d'abus
 
Voici le rapport:

 ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

 Mis à jour par TeamXscript le 12/04/11
 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
 Site web: http://www.teamxscript.org

 C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 10:57:41 le 17/03/2012, Mode sans echec

 Microsoft® Windows Vista™ Professionnel  Service Pack 2 (X86)
 Mahine@PCMAHINE (ASUSTeK Computer Inc. N20A)
 
 ============== ACTION(S) ==============


 Dossier supprimé: C:\Program Files\blinkx Remote Toolbar
 Dossier supprimé: C:\Users\Mahine\AppData\LocalL​ow\ShoppingReport
 Dossier supprimé: C:\Program Files\ShoppingReport

 (!) -- Fichiers temporaires supprimés.


 Clé supprimée: HKLM\Software\Classes\Shopping​Report.HbAx
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.HbAx.1
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.HbInfoBand
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.HbInfoBand.1
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.IEButton
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.IEButton.1
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.IEButtonA
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.IEButtonA.1
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.RprtCtrl
 Clé supprimée: HKLM\Software\Classes\Shopping​Report.RprtCtrl.1
 Clé supprimée: HKLM\Software\ShoppingReport
 Clé supprimée: HKCU\Software\ShoppingReport
 Clé supprimée: HKCU\Software\AppDataLow\Softw​are\ShoppingReport
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\App Management\ARPCache\ShoppingRe​port
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Uninstall\Sho​ppingReport


 ============== SCAN ADDITIONNEL ==============

 **** Mozilla Firefox Version [10.0.2 (fr)] ****

 Searchplugins\bing.xml (    hxxp://www.bing.com/search)
 Components\browsercomps.dll (Mozilla Foundation)
 Extensions\{82AF8DCA-6DE9-405D​-BD5E-43525BDAD38A} (Skype Click to Call)

 -- C:\Users\Mahine\AppData\Roamin​g\Mozilla\FireFox\Profiles\tmr​hgqhl.default --
 Extensions\{ACAA314B-EEBA-48e4​-AD47-84E31C44796C} (Free YouTube Download (Free Studio) Menu)
 Prefs.js - browser.download.lastDir, C:\\Users\\Mahine
 Prefs.js - browser.startup.homepage_overr​ide.buildID, 20120215223356
 Prefs.js - browser.startup.homepage_overr​ide.mstone, rv:10.0.2

 ==============================​==========

 **** Internet Explorer Version [9.0.8112.16421] ****

 HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi​/redir.dll?prd=ie&pver=6&ar=ms​nhome
 HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi​/redir.dll?prd=ie&ar=iesearch
 HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink​/?linkid=54896
 HKCU_Main|Start Page - hxxp://fr.msn.com/
 HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink​/?LinkId=54896
 HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi​/redir.dll?prd=ie&ar=iesearch
 HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.​htm
 HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi​/redir.dll?prd=ie&ar=iesearch
 HKLM_Main|Start Page - hxxp://fr.msn.com/
 HKCU_URLSearchHooks|{F08555B0-​9CC3-11D2-AA8E-000000000567} (x)
 HKCU_Toolbar\WebBrowser|{759D9​886-0C6F-4498-BAB6-4A5F47C6C72​F} (C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll)
 HKLM_Toolbar|{759D9886-0C6F-44​98-BAB6-4A5F47C6C72F} (C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll)
 HKLM_ElevationPolicy\59aaf7e3-​a04c-41fd-883e-c733268bf1d0 - C:\Program Files\DVDVideoSoftTB\DVDVideoS​oftTBToolbarHelper.exe (x)
 HKLM_ElevationPolicy\{07d873dc​-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\system32\wpcer.exe (x)
 HKLM_ElevationPolicy\{70f641fd​-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x)
 BHO\{6EBF7485-159F-4bff-A14F-B​9E3AAC4465B} - "Search Helper" (C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll)
 BHO\{AE805869-2E5C-4ED4-8F7B-F​1F7851A4497} - "Skype Browser Helper" (C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll)

 ==============================​==========

 C:\Program Files\Ad-Remover\Quarantine: 8 Fichier(s)
 C:\Program Files\Ad-Remover\Backup: 15 Fichier(s)

 C:\Ad-Report-CLEAN[1].txt - 17/03/2012 10:58:31 (0 Octet(s))

 Fin à: 11:00:06, 17/03/2012
 
 ============== E.O.F ==============

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 18/03/2012 à 14:40:51  
  1. Prévenir les modérateurs en cas d'abus
 

  :hello: vahi

  fais ceci

  Télécharge zhpdiag

 http://telechargement.zebulon.fr/zhpdiag.html


 Enregistrer le Fichier sur  le bureau important
 exécuter en tant qu'administrateur pour Vista/7)  pour lancer le programme d'assistant d'installation
 Scanner le pc en cliquant sur image de la loupe
 Enregistrer le rapport image de la disquette

 si vista/ seven il faut désactiver l'uac

 aide en image
 http://www.commentcamarche.net [...] -util(...)

 très volumineux incomplet sur le forum

 il faut le poster sur  www.mydoc.tk

 1 parcourir : zhpdiag.txt sur le bureau

 2 déposer

 3 me donner le lien formé qui ressemble a çà
 http://mydoc.tk/3/8762ZHPDiag.txt
 ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 18/03/2012 à 21:32:02  
  1. Prévenir les modérateurs en cas d'abus
 
Bonsoir did80 :)

 Voici le lien:

 http://mydoc.tk/3/6960ZHPDiag.txt

(Publicité)
Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 18/03/2012 à 21:57:02  
  1. Prévenir les modérateurs en cas d'abus
 

 eh bien dis donc :fou:
 du jamais vu

 hosts infecté comme pas possible + rogue et autre

 je comprends pourquoi tu démarres pas

 fais ceci on commence parles hosts

 télécharges MYHOSTS de jeanmmigab

 http://sites.google.com/site/j [...] -myhosts-1

 ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 18/03/2012 à 22:05:26  
  1. Prévenir les modérateurs en cas d'abus
 
J'ai téléchargé comme tu m'as dis et j'ai suivis les instruction du site voilà le rapport

 ** Rapport MyHosts.txt **

 MyHosts V.1.0.0.2 de jeanmimigab

 Merci à la team MH, W-T ,C_XX, Laddy et à Batch_man pour leurs aides
 
 Résultat de l'opération:restauration du fichier hosts réussi...

 ** Fin du rapport **

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 18/03/2012 à 22:26:29  
  1. Prévenir les modérateurs en cas d'abus
 

 :super:

 fais ceci

 Télécharges  sur le Bureau  Roguekiller
 et pas ailleurs.
 http://up.sur-la-toile.com/4Z2Y

 • Quitte tous les programmes en cours.
 • Sous Vista/Seven , clic droit -> lancer en tant qu'administrateur
 • Sinon lance simplement RogueKiller.exe
 Après le préscan  cliques sur scan
 Le scan fini cliques sur rapport
 • Un rapport s'ouvrira (RKreport[1].txt qui se trouve également à côté de l'exécutable),
 Copies/colles ce rapport.
  ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
(Publicité)
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 18/03/2012 à 22:40:25  
  1. Prévenir les modérateurs en cas d'abus
 
voilà le rapport

 RogueKiller V7.3.1 [10/03/2012] par Tigzy
 mail: tigzyRK<at>gmail<dot>com
 Remontees: http://www.sur-la-toile.com/di [...] ntees.html
 Blog: http://tigzyrk.blogspot.com

 Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
 Demarrage : Mode normal
 Utilisateur: Mahine [Droits d'admin]
 Mode: Recherche -- Date: 18/03/2012 10:39:30

 ¤¤¤ Processus malicieux: 0 ¤¤¤

 ¤¤¤ Entrees de registre: 772 ¤¤¤
 [PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (127.0.0.1:25402) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : a.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : aAvgApi.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AAWTray.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : About.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ackwin32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Ad-Aware.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : adaware.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : advxdwin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AdwarePrj.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : agent.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : agentsvr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : agentw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : alertsvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : alevir.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : alogserv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AlphaAV (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AlphaAV.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AluSchedulerSvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : amon9x.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : anti-trojan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Anti-Virus Professional.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AntispywarXP2009.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : antivirus.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPlus (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPlus.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPro_2010.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusXP (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusXP.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : antivirusxppro2009.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AntiVirus_Pro.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ants.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : apimonitor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : aplica32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : apvxdwin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : arr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Arrakis3.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashAvast.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashBug.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashChest.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashCnsnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashDisp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashLogV.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashMaiSv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashPopWz.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashQuick.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashServ.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashSimp2.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashSimpl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashSkPcc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashSkPck.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashUpd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ashWebSv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : aswChLic.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : aswRegSvr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : aswRunDll.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : aswUpdSv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : atcon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : atguard.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : atro55en.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : atupdater.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : atwatch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : au.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : aupdate.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : auto-protect.nav80try.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : autodown.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : autotrace.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : autoupdate.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : av360.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avadmin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AVCare.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avcenter.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avciman.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avconfig.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avconsol.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ave32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AVENGINE.EXE (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgcc32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgchk.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgcmgr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgcsrvx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgctrl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgdumpx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgemc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgiproxy.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgnsx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgrsx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgscanx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgserv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgserv9.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgsrmax.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgtray.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgupd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avgwdsvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avkpop.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avkserv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avkservice.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avkwctl9.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avltmain.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avmailc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avmcdlg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avnotify.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avp32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avpcc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avpdos32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avpm.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avptc32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avpupd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avsched32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avsynmgr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avupgsvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : AVWEBGRD.EXE (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avwin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avwin95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avwinnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avwsc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avwupd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avwupd32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avwupsrv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avxmonitor9x.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avxmonitornt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : avxquar.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : b.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : backweb.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bargains.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bdagent.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bdfvcl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bdfvwiz.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : BDInProcPatch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bdmcon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : BDMsnScan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bdreinit.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bdsubwiz.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : BDSurvey.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bdtkexec.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bdwizreg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bd_professional.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : beagle.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : belt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bidef.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bidserver.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bipcp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bipcpevalsetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bisp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : blackd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : blackice.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : blink.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : blss.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bootconf.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bootwarn.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : borg2.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bpc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : brasil.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : brastk.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : brw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bs120.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bspatch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bundle.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : bvt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : c.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cavscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ccapp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ccevtmgr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ccpxysvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ccSvcHst.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cdp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfgwiz.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfiadmin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfiaudit.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfinet.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfinet32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfpconfg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfplogvw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cfpupdat.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Cl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : claw95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : claw95cf.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : clean.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cleaner.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cleaner3.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cleanIELow.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cleanpc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : click.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cmd32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cmdagent.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cmesys.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cmgrdian.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cmon016.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : connectionmonitor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : control (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cpd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cpf9x206.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cpfnt206.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : crashrep.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : csc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cssconfg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cssupdat.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cssurf.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ctrl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cwnb181.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : cwntdwmo.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : d.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : datemanager.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dcomx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : defalert.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : defscangui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : defwatch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : deloeminfs.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : deputy.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : divx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dllcache.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dllreg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : doors.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dop.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dpf.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dpfsetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dpps2.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : driverctrl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : drwatson.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : drweb32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : drwebupw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dssagent.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dvp95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : dvp95_0.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ecengine.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : efpeadm.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : egui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ekrn.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : emsw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ent.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : esafe.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : escanhnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : escanv95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : espwatch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ethereal.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : etrustcipe.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : evpn.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : exantivirus-cnet.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : exe.avxw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : expert.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : explore.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : f-agnt95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : f-prot.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : f-prot95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : f-stopw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fact.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fameh32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fast.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fch32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fih32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : findviru.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : firewall.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fixcfg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fixfp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fnrb32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fp-win.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fp-win_trial.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fprot.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : frmwrk32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : frw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsaa.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsav.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsav32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsav530stbyb.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsav530wtbyb.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsav95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsgk32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsm32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsma32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : fsmb32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : gator.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : gav.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : gbmenu.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : gbn976rl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : gbpoll.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : generics.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : gmt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : guard.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : guarddog.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : guardgui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : hacktracersetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : hbinst.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : hbsrv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : History.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : homeav2010.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : hotactio.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : hotpatch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : htlog.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : htpatch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : hwpe.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : hxdl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : hxiul.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : iamapp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : iamserv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : iamstats.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ibmasn.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ibmavsp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : icload95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : icloadnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : icmon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : icsupp95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : icsuppnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Identity.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : idle.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : iedll.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : iedriver.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : IEShow.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : iface.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ifw2000.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : inetlnfo.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : infus.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : infwin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : init.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : init32.exe  (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : install.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : install[1].exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : install[2].exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : install[3].exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : install[4].exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : install[5].exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : intdel.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : intren.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : iomon98.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : istsvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : jammer.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : jdbgmrg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : jedi.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : JsRcGen.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : kavlite40eng.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : kavpers40eng.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : kavpf.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : kazza.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : keenvalue.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : kerio-pf-213-en-win.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : kerio-wrl-421-en-win.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : kerio-wrp-421-en-win.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : killprocesssetup161.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ldnetmon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ldpro.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ldpromenu.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ldscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : licmgr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : livesrv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : lnetinfo.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : loader.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : localnet.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : lockdown.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : lockdown2000.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : lookout.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : lordpe.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : lsetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : luall.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : luau.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : lucomserver.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : luinit.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : luspt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : MalwareRemoval.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mapisvc32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcagent.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcmnhdlr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcmscsvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcnasvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcproxy.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : McSACore.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcshell.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcshield.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcsysmon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mctool.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcupdate.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcvsrte.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mcvsshld.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : md.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mfin32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mfw2en.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mfweng3.02d30.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mgavrtcl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mgavrte.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mghtml.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mgui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : minilog.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mmod.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : monitor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : moolive.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mostat.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mpfagent.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mpfservice.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : MPFSrv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mpftray.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mrflux.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mrt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msa.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msapp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : MSASCui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msbb.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msblast.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mscache.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msccn32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mscman.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msconfig (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msdm.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msdos.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msiexec16.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mslaugh.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msmgt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msmsgri32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msseces.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mssmmc32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mssys.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : msvxd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mu0311ad.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : mwatch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : n32scanw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nav.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navap.navapsvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navapsvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navapw32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navdx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navlu32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navstub.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navw32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : navwnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nc2000.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ncinst4.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ndd32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : neomonitor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : neowatchlog.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : netarmor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : netd32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : netinfo.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : netmon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : netscanpro.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : netspyhunter-1.2.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : netutils.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nisserv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nisum.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nmain.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nod32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : normist.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : norton_internet_secu_3.0_407.e​xe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : notstart.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : npf40_tw_98_nt_me_2k.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : npfmessenger.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nprotect.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : npscheck.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : npssvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nsched32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nssys32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nstask32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nsupdate.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ntrtscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ntvdm.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ntxconfig.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nupgrade.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nvarch16.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nvc95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nvsvc32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nwinst4.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nwservice.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : nwtool16.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : OAcat.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : OAhlp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : OAReg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : oasrv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : oaui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : oaview.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ODSW.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ollydbg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : onsrvr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : optimize.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ostronet.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : otfix.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : outpost.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : outpostinstall.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : outpostproinstall.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ozn695m5.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : padmin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : panixk.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : patch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pav.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pavcl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PavFnSvr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pavproxy.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pavprsrv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pavsched.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pavsrv51.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pavw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pccwin98.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pcfwallicon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pcip10117_0.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pcscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pctsAuxs.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pctsGui.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pctsSvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pctsTray.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PC_Antispyware2010.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pdfndr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pdsetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PerAvir.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : periscope.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : persfw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : personalguard (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : personalguard.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : perswf.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pf2.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pfwadmin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pgmonitr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pingscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : platin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pop3trap.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : poproxy.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : popscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : portdetective.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : portmonitor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : powerscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ppinupdt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pptbc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ppvstop.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : prizesurfer.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : prmt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : prmvr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : procdump.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : processmonitor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : procexplorerv1.0.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : programauditor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : proport.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : protector.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : protectx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PSANCU.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PSANHost.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PSANToManager.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PsCtrls.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PsImSvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PskSvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : pspf.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : PSUNMain.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : purge.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : qconsole.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : qh.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : qserver.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Quick Heal.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : QuickHealCleaner.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rapapp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rav7.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rav7win.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rav8win32eng.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ray.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rb32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rcsync.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : realmon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : reged.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : regedt32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rescue.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rescue32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rrguard.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rscdwld.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rshell.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rtvscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rtvscn95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rulaunch.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rwg (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : rwg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : SafetyKeeper.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : safeweb.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sahagent.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Save.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : SaveArmor.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : SaveDefense.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : SaveKeep.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : savenow.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sbserv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : scam32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : scan32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : scan95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : scanpm.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : scrscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : seccenter.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Secure Veteran.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : secureveteran.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : Security Center.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : SecurityFighter.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : securitysoldier.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : serv95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : setloadorder.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : setupvameeval.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : setup_flowprotector_us.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sgssfw32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sh.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : shellspyinstall.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : shield.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : shn.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : showbehind.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : signcheck.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : smart.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : smartprotector.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : smc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : smrtdefp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sms.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : smss32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : snetcfg.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : soap.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sofi.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : SoftSafeness.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sperm.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : spf.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sphinx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : spoler.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : spoolcv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : spoolsv32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : spywarexpguard.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : spyxx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : srexe.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : srng.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ss3edit.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ssgrate.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : ssg_4104.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : st2.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : start.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : stcloader.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : supftrl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : support.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : supporter5.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : svc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : svchostc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : svchosts.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : svshost.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sweep95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sweepnet.sweepsrv.sys.swnetsup​.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : symlcsvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : symproxysvc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : symtray.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : system.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : system32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : sysupd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tapinstall.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : taskmgr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : taumon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tbscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tca.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tcm.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tds-3.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tds2-98.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tds2-nt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : teekids.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tfak.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tfak5.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tgbob.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : titanin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : titaninxp.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : TPSrv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : trickler.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : trjscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : trjsetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : trojantrap3.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : TrustWarrior.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tsadbot.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tsc.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tvmd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : tvtmd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : uiscan.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : undoboot.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : updat.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : upgrad.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : upgrepl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : utpost.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vbcmserv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vbcons.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vbust.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vbwin9x.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vbwinntw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vcsetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vet32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vet95.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vettray.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vfsetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vir-help.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : virusmdpersonalfirewall.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : VisthAux.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : VisthLic.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : VisthUpd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vnlan300.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vnpc3000.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vpc32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vpc42.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vpfw30s.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vptray.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vscan40.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vscenu6.02d30.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vsched.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vsecomr.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vshwin32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vsisetup.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vsmain.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vsmon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vsserv.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vsstat.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vswin9xe.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vswinntse.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : vswinperse.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : w32dsm89.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : W3asbas.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : w9x.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : watchdog.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : webdav.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : WebProxy.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : webscanx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : webtrap.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wfindv32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : whoswatchingme.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wimmun32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : win-bugsfix.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : win32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : win32us.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winactive.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winav.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : windll32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : window.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : windows Police Pro.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : windows.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wininetd.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wininitx.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winlogin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winmain.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winppr32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winrecon.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winservn.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winssk32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winstart.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winstart001.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wintsk32.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : winupdate.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wkufind.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wnad.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wnt.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wradmin.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wrctrl.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wsbgate.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wscfxas.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wscfxav.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wscfxfw.exe (svchost.exe) -> FOUND
 [IFEO] HKLM\[...]\Image File Execution Options : wsctool.exe (svchost.exe) -> FOUND
 [I

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 18/03/2012 à 22:49:48  
  1. Prévenir les modérateurs en cas d'abus
 

 ok tu les collectionnes franchement

 relance le apres le scan found cochées cliques suppression

 copies/colles le rapport   ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 18/03/2012 à 22:57:49  
  1. Prévenir les modérateurs en cas d'abus
 
voilà le rapport

 RogueKiller V7.3.1 [10/03/2012] par Tigzy
 mail: tigzyRK<at>gmail<dot>com
 Remontees: http://www.sur-la-toile.com/di [...] ntees.html
 Blog: http://tigzyrk.blogspot.com

 Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
 Demarrage : Mode normal
 Utilisateur: Mahine [Droits d'admin]
 Mode: Suppression -- Date: 18/03/2012 10:57:09

 ¤¤¤ Processus malicieux: 0 ¤¤¤

 ¤¤¤ Entrees de registre: 772 ¤¤¤
 [PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (127.0.0.1:25402) -> NOT REMOVED, USE PROXYFIX
 [IFEO] HKLM\[...]\Image File Execution Options : a.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : aAvgApi.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AAWTray.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : About.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ackwin32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Ad-Aware.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : adaware.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : advxdwin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AdwarePrj.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : agent.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : agentsvr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : agentw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : alertsvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : alevir.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : alogserv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AlphaAV (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AlphaAV.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AluSchedulerSvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : amon9x.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : anti-trojan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Anti-Virus Professional.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AntispywarXP2009.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : antivirus.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPlus (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPlus.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusPro_2010.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusXP (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AntivirusXP.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : antivirusxppro2009.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AntiVirus_Pro.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ants.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : apimonitor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : aplica32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : apvxdwin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : arr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Arrakis3.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashAvast.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashBug.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashChest.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashCnsnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashDisp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashLogV.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashMaiSv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashPopWz.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashQuick.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashServ.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashSimp2.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashSimpl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashSkPcc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashSkPck.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashUpd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ashWebSv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : aswChLic.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : aswRegSvr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : aswRunDll.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : aswUpdSv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : atcon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : atguard.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : atro55en.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : atupdater.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : atwatch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : au.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : aupdate.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : auto-protect.nav80try.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : autodown.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : autotrace.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : autoupdate.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : av360.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avadmin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AVCare.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avcenter.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avciman.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avconfig.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avconsol.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ave32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AVENGINE.EXE (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgcc32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgchk.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgcmgr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgcsrvx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgctrl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgdumpx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgemc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgiproxy.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgnsx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgrsx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgscanx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgserv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgserv9.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgsrmax.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgtray.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgupd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avgwdsvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avkpop.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avkserv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avkservice.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avkwctl9.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avltmain.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avmailc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avmcdlg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avnotify.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avp32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avpcc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avpdos32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avpm.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avptc32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avpupd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avsched32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avsynmgr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avupgsvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : AVWEBGRD.EXE (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avwin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avwin95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avwinnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avwsc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avwupd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avwupd32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avwupsrv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avxmonitor9x.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avxmonitornt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : avxquar.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : b.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : backweb.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bargains.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bdagent.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bdfvcl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bdfvwiz.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : BDInProcPatch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bdmcon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : BDMsnScan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bdreinit.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bdsubwiz.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : BDSurvey.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bdtkexec.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bdwizreg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bd_professional.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : beagle.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : belt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bidef.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bidserver.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bipcp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bipcpevalsetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bisp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : blackd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : blackice.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : blink.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : blss.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bootconf.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bootwarn.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : borg2.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bpc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : brasil.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : brastk.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : brw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bs120.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bspatch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bundle.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : bvt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : c.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cavscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ccapp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ccevtmgr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ccpxysvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ccSvcHst.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cdp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfgwiz.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfiadmin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfiaudit.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfinet.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfinet32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfpconfg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfplogvw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cfpupdat.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Cl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : claw95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : claw95cf.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : clean.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cleaner.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cleaner3.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cleanIELow.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cleanpc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : click.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cmd32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cmdagent.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cmesys.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cmgrdian.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cmon016.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : connectionmonitor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : control (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cpd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cpf9x206.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cpfnt206.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : crashrep.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : csc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cssconfg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cssupdat.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cssurf.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ctrl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cwnb181.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : cwntdwmo.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : d.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : datemanager.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dcomx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : defalert.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : defscangui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : defwatch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : deloeminfs.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : deputy.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : divx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dllcache.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dllreg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : doors.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dop.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dpf.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dpfsetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dpps2.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : driverctrl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : drwatson.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : drweb32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : drwebupw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dssagent.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dvp95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : dvp95_0.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ecengine.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : efpeadm.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : egui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ekrn.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : emsw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ent.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : esafe.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : escanhnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : escanv95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : espwatch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ethereal.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : etrustcipe.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : evpn.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : exantivirus-cnet.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : exe.avxw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : expert.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : explore.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : f-agnt95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : f-prot.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : f-prot95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : f-stopw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fact.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fameh32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fast.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fch32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fih32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : findviru.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : firewall.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fixcfg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fixfp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fnrb32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fp-win.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fp-win_trial.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fprot.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : frmwrk32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : frw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsaa.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsav.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsav32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsav530stbyb.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsav530wtbyb.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsav95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsgk32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsm32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsma32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : fsmb32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : gator.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : gav.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : gbmenu.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : gbn976rl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : gbpoll.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : generics.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : gmt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : guard.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : guarddog.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : guardgui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : hacktracersetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : hbinst.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : hbsrv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : History.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : homeav2010.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : hotactio.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : hotpatch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : htlog.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : htpatch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : hwpe.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : hxdl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : hxiul.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : iamapp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : iamserv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : iamstats.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ibmasn.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ibmavsp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : icload95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : icloadnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : icmon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : icsupp95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : icsuppnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Identity.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : idle.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : iedll.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : iedriver.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : IEShow.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : iface.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ifw2000.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : inetlnfo.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : infus.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : infwin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : init.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : init32.exe  (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : install.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : install[1].exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : install[2].exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : install[3].exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : install[4].exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : install[5].exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : intdel.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : intren.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : iomon98.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : istsvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : jammer.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : jdbgmrg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : jedi.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : JsRcGen.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : kavlite40eng.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : kavpers40eng.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : kavpf.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : kazza.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : keenvalue.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : kerio-pf-213-en-win.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : kerio-wrl-421-en-win.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : kerio-wrp-421-en-win.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : killprocesssetup161.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ldnetmon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ldpro.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ldpromenu.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ldscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : licmgr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : livesrv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : lnetinfo.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : loader.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : localnet.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : lockdown.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : lockdown2000.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : lookout.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : lordpe.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : lsetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : luall.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : luau.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : lucomserver.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : luinit.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : luspt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : MalwareRemoval.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mapisvc32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcagent.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcmnhdlr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcmscsvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcnasvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcproxy.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : McSACore.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcshell.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcshield.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcsysmon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mctool.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcupdate.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcvsrte.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mcvsshld.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : md.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mfin32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mfw2en.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mfweng3.02d30.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mgavrtcl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mgavrte.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mghtml.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mgui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : minilog.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mmod.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : monitor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : moolive.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mostat.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mpfagent.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mpfservice.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : MPFSrv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mpftray.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mrflux.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mrt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msa.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msapp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : MSASCui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msbb.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msblast.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mscache.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msccn32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mscman.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msconfig (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msdm.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msdos.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msiexec16.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mslaugh.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msmgt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msmsgri32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msseces.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mssmmc32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mssys.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : msvxd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mu0311ad.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : mwatch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : n32scanw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nav.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navap.navapsvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navapsvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navapw32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navdx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navlu32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navstub.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navw32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : navwnt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nc2000.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ncinst4.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ndd32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : neomonitor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : neowatchlog.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : netarmor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : netd32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : netinfo.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : netmon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : netscanpro.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : netspyhunter-1.2.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : netutils.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nisserv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nisum.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nmain.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nod32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : normist.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : norton_internet_secu_3.0_407.e​xe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : notstart.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : npf40_tw_98_nt_me_2k.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : npfmessenger.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nprotect.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : npscheck.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : npssvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nsched32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nssys32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nstask32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nsupdate.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ntrtscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ntvdm.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ntxconfig.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nupgrade.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nvarch16.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nvc95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nvsvc32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nwinst4.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nwservice.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : nwtool16.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : OAcat.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : OAhlp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : OAReg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : oasrv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : oaui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : oaview.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ODSW.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ollydbg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : onsrvr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : optimize.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ostronet.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : otfix.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : outpost.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : outpostinstall.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : outpostproinstall.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ozn695m5.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : padmin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : panixk.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : patch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pav.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pavcl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PavFnSvr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pavproxy.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pavprsrv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pavsched.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pavsrv51.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pavw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pccwin98.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pcfwallicon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pcip10117_0.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pcscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pctsAuxs.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pctsGui.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pctsSvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pctsTray.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PC_Antispyware2010.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pdfndr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pdsetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PerAvir.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : periscope.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : persfw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : personalguard (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : personalguard.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : perswf.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pf2.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pfwadmin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pgmonitr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pingscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : platin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pop3trap.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : poproxy.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : popscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : portdetective.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : portmonitor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : powerscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ppinupdt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pptbc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ppvstop.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : prizesurfer.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : prmt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : prmvr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : procdump.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : processmonitor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : procexplorerv1.0.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : programauditor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : proport.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : protector.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : protectx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PSANCU.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PSANHost.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PSANToManager.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PsCtrls.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PsImSvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PskSvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : pspf.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : PSUNMain.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : purge.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : qconsole.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : qh.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : qserver.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Quick Heal.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : QuickHealCleaner.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rapapp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rav7.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rav7win.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rav8win32eng.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ray.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rb32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rcsync.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : realmon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : reged.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : regedt32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rescue.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rescue32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rrguard.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rscdwld.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rshell.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rtvscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rtvscn95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rulaunch.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rwg (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : rwg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : SafetyKeeper.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : safeweb.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sahagent.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Save.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : SaveArmor.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : SaveDefense.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : SaveKeep.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : savenow.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sbserv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : scam32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : scan32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : scan95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : scanpm.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : scrscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : seccenter.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Secure Veteran.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : secureveteran.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : Security Center.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : SecurityFighter.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : securitysoldier.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : serv95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : setloadorder.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : setupvameeval.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : setup_flowprotector_us.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sgssfw32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sh.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : shellspyinstall.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : shield.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : shn.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : showbehind.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : signcheck.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : smart.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : smartprotector.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : smc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : smrtdefp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sms.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : smss32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : snetcfg.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : soap.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sofi.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : SoftSafeness.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sperm.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : spf.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sphinx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : spoler.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : spoolcv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : spoolsv32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : spywarexpguard.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : spyxx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : srexe.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : srng.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ss3edit.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ssgrate.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : ssg_4104.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : st2.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : start.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : stcloader.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : supftrl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : support.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : supporter5.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : svc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : svchostc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : svchosts.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : svshost.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sweep95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sweepnet.sweepsrv.sys.swnetsup​.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : symlcsvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : symproxysvc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : symtray.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : system.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : system32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : sysupd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tapinstall.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : taskmgr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : taumon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tbscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tca.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tcm.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tds-3.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tds2-98.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tds2-nt.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : teekids.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tfak.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tfak5.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tgbob.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : titanin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : titaninxp.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : TPSrv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : trickler.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : trjscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : trjsetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : trojantrap3.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : TrustWarrior.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tsadbot.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tsc.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tvmd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : tvtmd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : uiscan.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : undoboot.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : updat.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : upgrad.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : upgrepl.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : utpost.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vbcmserv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vbcons.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vbust.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vbwin9x.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vbwinntw.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vcsetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vet32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vet95.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vettray.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vfsetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vir-help.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : virusmdpersonalfirewall.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : VisthAux.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : VisthLic.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : VisthUpd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vnlan300.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vnpc3000.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vpc32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vpc42.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vpfw30s.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vptray.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vscan40.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vscenu6.02d30.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vsched.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vsecomr.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vshwin32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vsisetup.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vsmain.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vsmon.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vsserv.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vsstat.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vswin9xe.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vswinntse.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : vswinperse.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : w32dsm89.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : W3asbas.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : w9x.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : watchdog.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : webdav.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : WebProxy.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : webscanx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : webtrap.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : wfindv32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : whoswatchingme.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : wimmun32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : win-bugsfix.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : win32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : win32us.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : winactive.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : winav.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : windll32.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : window.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : windows Police Pro.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : windows.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : wininetd.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : wininitx.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : winlogin.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : winmain.exe (svchost.exe) -> DELETED
 [IFEO] HKLM\[...]\Image File Execution Options : winppr32.exe (s

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 18/03/2012 à 23:42:56  
  1. Prévenir les modérateurs en cas d'abus
 

 re relance le

 apres le scan

  cliques proxyraz

 copies/colles le rapport  ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 18/03/2012 à 23:47:19  
  1. Prévenir les modérateurs en cas d'abus
 
voilà

 RogueKiller V7.3.1 [10/03/2012] par Tigzy
 mail: tigzyRK<at>gmail<dot>com
 Remontees: http://www.sur-la-toile.com/di [...] ntees.html
 Blog: http://tigzyrk.blogspot.com

 Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
 Demarrage : Mode normal
 Utilisateur: Mahine [Droits d'admin]
 Mode: Proxy RAZ -- Date: 18/03/2012 11:47:03

 ¤¤¤ Processus malicieux: 0 ¤¤¤

 ¤¤¤ Driver: [CHARGE] ¤¤¤

 ¤¤¤ Entrees de registre: 1 ¤¤¤
 [PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (127.0.0.1:25402) -> DELETED

 Termine : << RKreport[5].txt >>
 RKreport[1].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt



Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 18/03/2012 à 23:57:13  
  1. Prévenir les modérateurs en cas d'abus
 

 ok dis moi deja si tu redemarres normalement

 et si tu as internet  ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 19/03/2012 à 00:05:52  
  1. Prévenir les modérateurs en cas d'abus
 
oui c'est bon tout redémarre normalement c'est impec! Merci beaucoup en tout cas ça ma bien dépanné je voulais aussi te demander si je pouvais désinstaller les logiciels que j'ai télécharger ?

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 19/03/2012 à 11:03:05  
  1. Prévenir les modérateurs en cas d'abus
 

 salut vahi  :super:  mais ce n'est pas fini

 reposte moi un zhpdiag sur www.mydoc.tk ou www.cjoint.com stp

 donne moi le nouveau lien

 ne désinstalle aucun outil je te le demanderai quand tout sera clean

 et je te donnerai la procédure  ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 20/03/2012 à 07:21:46  
  1. Prévenir les modérateurs en cas d'abus
 
Bonjour did80 j'ai fais comme tu m'as dis voilà le lien
 http://mydoc.tk/3/6759ZHPDiag.txt

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 20/03/2012 à 11:42:47  
  1. Prévenir les modérateurs en cas d'abus
 


  :hello: vahi

  tu es infécté par rogue et adware

  dans un premier temps fais ceci

  Télécharges Malwarebytes version free
 http://www.malwarebytes.org/pr [...] bytes_free

 on le garde sous le coude


 2/
 Télécharges  sur le Bureau  Roguekiller
 et pas ailleurs.
 http://up.sur-la-toile.com/4Z2Y

 • Quitte tous les programmes en cours.
 • Sous Vista/Seven , clic droit -> lancer en tant qu'administrateur
 • Sinon lance simplement RogueKiller.exe
 
 Après le préscan  cliques sur scan

 Le scan fini sil trouve des choses cliques sur suppression

 copies /colles le rapport

 ferme roguekiller

 n'eteind pas le pc

 et lance mbam  tu le mets a jour  

  scan complet
 çà peut etre assez long


 s’il trouve des infections  important
  coches les cases et supprimes la sélection

 Copies colles le rapport
 ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 20/03/2012 à 22:34:41  
  1. Prévenir les modérateurs en cas d'abus
 
bonjour did80 voilà les deux rapports
 RogueKiller V7.3.2 [20/03/2012] par Tigzy
 mail: tigzyRK<at>gmail<dot>com
 Remontees: http://www.sur-la-toile.com/di [...] ntees.html
 Blog: http://tigzyrk.blogspot.com

 Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
 Demarrage : Mode normal
 Utilisateur: Mahine [Droits d'admin]
 Mode: Suppression -- Date: 20/03/2012 08:43:26

 ¤¤¤ Processus malicieux: 0 ¤¤¤

 ¤¤¤ Entrees de registre: 0 ¤¤¤

 ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

 ¤¤¤ Driver: [CHARGE] ¤¤¤

 ¤¤¤ Infection :  ¤¤¤

 ¤¤¤ Fichier HOSTS: ¤¤¤
 127.0.0.1       localhost
 ::1             localhost


 ¤¤¤ MBR Verif: ¤¤¤

 +++++ PhysicalDrive0: ST9320320AS +++++
 --- User ---
 [MBR] 3aeadd09d0bb3b707ca2cc8fae1227​2f
 [BSP] 68a9a69bc00139773c4fa2984750db​a9 : Windows Vista/7 MBR Code
 Partition table:
 0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 63 | Size: 12001 Mo
 1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 24579450 | Size: 152617 Mo
 2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 337140090 | Size: 140623 Mo
 User = LL1 ... OK!
 User = LL2 ... OK!

 Termine : << RKreport[2].txt >>
 RKreport[1].txt ; RKreport[2].txt

 Windows Vista Service Pack 2 x86 NTFS
 Internet Explorer 9.0.8112.16421
 Mahine :: PCMAHINE [administrateur]

 20/03/2012 08:47:03
 mbam-log-2012-03-20 (08-47-03).txt

 Type d'examen: Examen complet
 Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
 Options d'examen désactivées: P2P
 Elément(s) analysé(s): 327096
 Temps écoulé: 1 heure(s), 27 minute(s), 54 seconde(s)

 Processus mémoire détecté(s): 0
 (Aucun élément nuisible détecté)

 Module(s) mémoire détecté(s): 0
 (Aucun élément nuisible détecté)

 Clé(s) du Registre détectée(s): 6
 HKCU\SOFTWARE\Microsoft\Window​s\CurrentVersion\Ext\Stats\{6F​D31ED6-7C94-4BBC-8E95-F927F4D3​A949} (Adware.180Solutions) -> Mis en quarantaine et supprimé avec succès.
 HKCU\SOFTWARE\CE8SIIFGSU (Trojan.FakeAlert) -> Mis en quarantaine et supprimé avec succès.
 HKCU\SOFTWARE\VXEG3ZNNE5 (Trojan.FakeAlert) -> Mis en quarantaine et supprimé avec succès.
 HKCU\SOFTWARE\XML (Trojan.FakeAlert) -> Mis en quarantaine et supprimé avec succès.
 HKCU\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Mis en quarantaine et supprimé avec succès.
 HKCU\Software\Microsoft\Window​s\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Mis en quarantaine et supprimé avec succès.

 Valeur(s) du Registre détectée(s): 0
 (Aucun élément nuisible détecté)

 Elément(s) de données du Registre détecté(s): 1
 HKCR\SOFTWARE\Microsoft\Intern​et Explorer\SearchScopes|URL (Hijack.SearchPage) -> Mauvais: (http://findgala.com/?&uid=220​8&q={searchTerms}) Bon: (http://www.google.com/search?​q={searchTerms}&rls=com.micros​oft:{language}&ie={inputEncodi​ng}&oe={outputEncoding}&startI​ndex={startIndex?}&startPage={​startPage}) -> Mis en quarantaine et réparé avec succès

 Dossier(s) détecté(s): 1
 C:\Users\Mahine\AppData\Roamin​g\Internet Antivirus 2011 (Rogue.InternetAntiVirus) -> Mis en quarantaine et supprimé avec succès.

 Fichier(s) détecté(s): 2
 C:\Users\Mahine\AppData\Roamin​g\Internet Antivirus 2011\cookies.sqlite (Rogue.InternetAntiVirus) -> Mis en quarantaine et supprimé avec succès.
 C:\Users\Mahine\AppData\Roamin​g\Internet Antivirus 2011\Instructions.ini (Rogue.InternetAntiVirus) -> Mis en quarantaine et supprimé avec succès.

 (fin)

 
 

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 20/03/2012 à 23:26:03  
  1. Prévenir les modérateurs en cas d'abus
 

 :hello: pour moi il y avait 2 rogues 1 detruit ok

 faire mbam ensuite sans eteindre le pc  :??:


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 21/03/2012 à 11:43:23  
  1. Prévenir les modérateurs en cas d'abus
 
:hello: vahi

 fais ceci
 Sélectionnes et copies les lignes bleues suivantes


 
 [HKLM\Software\Microsoft\Window​s\CurrentVersion\Ext\PreApprov​ed\{0069B690-7A2B-41C5-98CA-9F​535B4C8532}]   =>Trojan.BHO
 [HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{6f​d31ed6-7c94-4bbc-8e95-f927f4d3​a949}]   =>Adware.180Solutions
 [HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{F0​8555B0-9CC3-11D2-AA8E-00000000​0567}]   =>Trojan.BHO
 [HKCU\Software\Microsoft\handle​]   =>Malware.Trace
 [HKCU\Software\XML]   =>Trojan.FakeAlert
 [HKLM\Software\Microsoft\Window​s\CurrentVersion\Internet Settings\Zones\]   =>Hijack.Zones
 O4 - Global Startup: C:\Users\Mahine\AppData\Roamin​g\Microsoft\Internet Explorer\Quick Launch\Internet Antivirus 2011.lnk . (...)  -- C:\ProgramData\db594c\Internet​AV2011.exe (.not file.)
 [HKCU\Software\3]
 [HKCU\Software\XML]
 O43 - CFD: 13/12/2010 - 10:41:40 - [1,139] -SH-D- C:\ProgramData\db594c
 O43 - CFD: 12/12/2010 - 16:42:50 - [0,077] -SH-D- C:\Users\Mahine\AppData\Roamin​g\Internet Antivirus 2011    => Infection Rogue (Rogue.InternetAntiVirus)
 O53 - SMSR:HKLM\...\startupreg\Inter​net Antivirus 2011  [Key] . (...) -- C:\ProgramData\db594c\Internet​AV2011.exe (.not file.)    => Infection Rogue
 [HKCU\Software\3]
 [HKCU\Software\XML]
 O43 - CFD: 01/02/2012 - 06:11:46 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CA653DEA-0A14-4F00-A483-492AD​5F2AA25}
 O43 - CFD: 16/02/2012 - 06:45:08 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CC23BBEE-200B-4744-AE14-C1D13​C7B6632}
 O43 - CFD: 13/10/2011 - 07:50:32 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CC5BE535-6CD0-4810-B1A5-E31DD​D21DF2C}
 O43 - CFD: 29/11/2011 - 22:09:08 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CD1702EF-AD7E-4CE4-AC42-C17A6​3391E58}
 O43 - CFD: 19/01/2012 - 08:33:20 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CD788A4C-DFAE-4E2B-9EA1-6068C​6BB74E0}
 O43 - CFD: 06/10/2011 - 07:06:20 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CE036760-B3C8-4E99-B6B0-CAC02​D966A96}
 O43 - CFD: 19/02/2012 - 22:04:48 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CE683DDC-CB5A-49D5-A584-A1618​E4381AF}
 O43 - CFD: 19/01/2012 - 08:32:20 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CE956F82-75AB-4D77-97A1-24977​1CB061F}
 O43 - CFD: 05/04/2011 - 07:37:56 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CEC27842-E5F4-4F3C-A357-5CF57​1629C5F}
 O43 - CFD: 10/06/2011 - 11:34:08 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CEDDE730-3C25-4FFE-9B57-58A79​02771FB}
 O43 - CFD: 10/03/2012 - 16:22:10 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CF5763B4-D930-4A5F-8779-588C5​0FC96BF}
 O43 - CFD: 03/02/2012 - 05:51:56 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CF7ABF85-2689-41EF-B1DE-29A36​A284BB3}
 O43 - CFD: 31/07/2011 - 08:07:08 - [0] ----D- C:\Users\Mahine\AppData\Local\​{CFA67F51-F5AC-4EA3-A63F-07265​C173515}
 O43 - CFD: 05/10/2011 - 05:56:38 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D0045B0F-D588-48DA-B1CA-CE520​411E969}
 O43 - CFD: 15/12/2011 - 06:38:38 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D0362E67-F670-4480-B849-B0E0F​7A50908}
 O43 - CFD: 31/10/2011 - 07:41:54 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D0450E2E-DC71-4535-9926-41A37​3278E50}
 O43 - CFD: 28/07/2011 - 06:43:40 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D09ABF3F-75FF-464E-BC54-BED06​1E9C813}
 O43 - CFD: 25/08/2011 - 05:33:16 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D103524C-29B6-4F0A-8B28-2D42A​97C93F1}
 O43 - CFD: 23/09/2011 - 06:29:46 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D10914AD-5671-4476-B0E3-2711E​4DA6B00}
 O43 - CFD: 28/05/2011 - 19:32:06 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D1872CAD-62D7-433F-9BF1-8F355​B73B997}
 O43 - CFD: 19/01/2012 - 22:35:34 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D23D50A4-318C-4AB4-8A53-7D60B​9BF4C2A}
 O43 - CFD: 09/08/2011 - 08:43:58 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D29F95B4-8C99-4041-8237-91F5F​DB9E317}
 O43 - CFD: 24/10/2011 - 06:06:10 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D4C69CF9-F658-44F8-9FA3-5729D​6912D52}
 O43 - CFD: 02/12/2011 - 05:03:04 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D5C6387E-7BED-4F54-A5DD-3BC1E​4316138}
 O43 - CFD: 04/08/2011 - 05:59:34 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D6E8D97D-E96C-4E26-BB86-9020E​1664D25}
 O43 - CFD: 16/04/2011 - 07:00:18 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D7FFB464-3489-413A-829F-721BA​423402F}
 O43 - CFD: 09/10/2011 - 05:27:26 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D8505E46-1C2C-4AD2-9E84-96012​B0CF195}
 O43 - CFD: 26/11/2011 - 05:37:14 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D8B2C03A-D64C-47BE-B93B-7B712​A50F5F5}
 O43 - CFD: 04/08/2011 - 06:05:14 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D8CB7936-646D-4A23-859A-33491​02F508B}
 O43 - CFD: 09/03/2012 - 06:48:22 - [0] ----D- C:\Users\Mahine\AppData\Local\​{D8EF8AFA-37EF-455B-AF85-2D74E​EE466FD}
 O43 - CFD: 13/03/2012 - 22:28:24 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DA8D49F3-3BDD-48D4-92F3-A1C19​C141AEA}
 O43 - CFD: 05/08/2011 - 05:38:02 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DA9AA9B3-A642-4994-AB7D-E2B32​F0A923D}
 O43 - CFD: 07/10/2011 - 21:10:28 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DABB00A5-4C68-4BEB-8B84-B45CE​103EB51}
 O43 - CFD: 12/08/2011 - 05:57:00 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DAEC4936-3964-4789-B25E-CD0D4​DBA3DA0}
 O43 - CFD: 06/02/2012 - 05:35:58 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DB0AF22A-0B29-49B1-ADC8-8B88D​7BE59D5}
 O43 - CFD: 27/08/2011 - 06:35:30 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DBE4917F-23D4-49F9-8610-486C5​CB5A837}
 O43 - CFD: 06/11/2011 - 07:43:52 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DCB02449-8FD4-4C6B-9A91-9350A​DBB17AF}
 O43 - CFD: 21/02/2012 - 05:33:28 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DCEAF14B-013B-4CF3-B3A1-BD617​EFF664F}
 O43 - CFD: 10/12/2011 - 07:28:54 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DDA57874-FA15-41AD-B90D-68AAA​0FD0E9E}
 O43 - CFD: 30/11/2011 - 05:01:02 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DDB926B5-3148-44F3-AB7F-534B4​D1224B8}
 O43 - CFD: 27/06/2011 - 07:17:54 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DDD6E36D-000C-4A1D-82E4-F4AF1​6466F55}
 O43 - CFD: 31/08/2011 - 08:10:20 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DE3E1721-BCD4-4B37-8550-D5C59​9D60835}
 O43 - CFD: 23/04/2011 - 22:23:20 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DE666179-05C4-4F5D-AA0E-3CB59​79A56CE}
 O43 - CFD: 23/02/2012 - 05:50:44 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DE6E9593-9A82-4929-AF0B-67BF4​628273B}
 O43 - CFD: 23/02/2012 - 05:49:48 - [0] ----D- C:\Users\Mahine\AppData\Local\​{DF9D9A16-9A62-4502-867F-7B323​FB8F45B}
 O43 - CFD: 06/07/2011 - 08:25:38 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E07327F0-8897-4602-B185-BC018​3CA0FCD}
 O43 - CFD: 25/10/2011 - 05:44:22 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E11B660A-8E78-46B3-B907-87633​AC8393C}
 O43 - CFD: 14/02/2012 - 07:02:48 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E331B207-7C48-4F21-B6A6-E4EB9​AACD309}
 O43 - CFD: 16/08/2011 - 06:17:10 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E341A174-66B8-4843-8736-460B0​AD5D429}
 O43 - CFD: 15/01/2012 - 09:05:36 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E4A182F9-F66C-40B5-9037-D47E7​AB43C06}
 O43 - CFD: 05/02/2012 - 05:42:48 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E4C4054B-C939-4545-8992-FABE2​29F3582}
 O43 - CFD: 11/06/2011 - 07:29:28 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E4C6A844-BFE8-4D53-8711-10B4A​F4BF187}
 O43 - CFD: 19/08/2011 - 08:13:50 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E54214AF-34D7-4E1D-A018-F090C​FE10148}
 O43 - CFD: 06/08/2011 - 06:52:24 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E54677A9-928E-4F69-93F7-446D5​D7A70D3}
 O43 - CFD: 14/04/2011 - 07:37:16 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E55DCE4C-8ADD-4B0E-9D72-3C1AD​36E528E}
 O43 - CFD: 26/02/2012 - 08:27:28 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E5668250-7B2D-43A5-A3B2-BA7F0​B6586AD}
 O43 - CFD: 07/10/2011 - 21:09:26 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E68A1689-8DE5-496A-8016-DD944​C70E9E8}
 O43 - CFD: 18/03/2012 - 07:23:58 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E6CEC799-DC3E-4890-9EDF-476F8​04889F8}
 O43 - CFD: 24/11/2011 - 05:51:34 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E73F39D0-D34D-4629-8F4E-C9D2D​5E35444}
 O43 - CFD: 01/02/2012 - 21:51:24 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E89E32AF-D6CB-4641-AEDC-81C3D​6893226}
 O43 - CFD: 21/01/2012 - 05:38:22 - [0] ----D- C:\Users\Mahine\AppData\Local\​{E94568A1-24BC-4EB1-AD06-34B9A​521B78F}
 O43 - CFD: 08/10/2011 - 06:12:40 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EA15FCA6-0860-40C6-9AA0-1960D​C5EEE9D}
 O43 - CFD: 12/09/2011 - 05:22:58 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EA56C8A3-54F5-480C-AD1E-4201D​0493E0E}
 O43 - CFD: 11/08/2011 - 05:27:26 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EA5CF091-123B-4B46-945E-83408​5DEA68C}
 O43 - CFD: 07/08/2011 - 07:32:58 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EB4E13B1-5783-4448-84BA-707C9​6A47D0C}
 O43 - CFD: 16/12/2011 - 05:08:44 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EC3AC6BA-B601-45B8-AE4D-DEA10​CBF5AA3}
 O43 - CFD: 15/10/2011 - 06:56:22 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EC40CC42-D6CD-4EF0-87B2-E2900​69DD23A}
 O43 - CFD: 18/08/2011 - 20:59:26 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EC610443-768D-47CC-8A80-51CC5​DEE7189}
 O43 - CFD: 19/06/2011 - 08:03:50 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EC6E90D4-74A3-4427-81D3-D855E​B0619A2}
 O43 - CFD: 04/11/2011 - 07:05:54 - [0] ----D- C:\Users\Mahine\AppData\Local\​{ECA8276D-A6EB-4435-9FA8-1F0B9​4AC3724}
 O43 - CFD: 23/10/2011 - 07:59:52 - [0] ----D- C:\Users\Mahine\AppData\Local\​{ECBA7CC2-4AA3-4BB3-A5DE-B2273​18B25E3}
 O43 - CFD: 08/06/2011 - 07:39:14 - [0] ----D- C:\Users\Mahine\AppData\Local\​{ED59462E-4C80-4D95-AA7E-1DB18​A79EC4C}
 O43 - CFD: 12/06/2011 - 19:18:14 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EDD82362-3575-4274-9495-E5526​B250D15}
 O43 - CFD: 14/02/2012 - 07:01:32 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EE0DEC26-98F5-4AE5-B4FB-3567B​7BA1CBC}
 O43 - CFD: 25/09/2011 - 17:58:14 - [0] ----D- C:\Users\Mahine\AppData\Local\​{EF3E7F41-9DF8-4442-BB47-E9635​EF2FEF4}
 O43 - CFD: 28/02/2012 - 16:31:26 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F049FFD1-C1D6-409D-8A61-4724C​D703822}
 O43 - CFD: 13/10/2011 - 07:51:28 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F19BAEC4-2522-41DF-BD70-BA215​70CBB53}
 O43 - CFD: 12/12/2011 - 04:57:08 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F2A4CBAD-3AA6-487C-8051-2D32B​5016111}
 O43 - CFD: 25/09/2011 - 07:13:12 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F2AC209C-9F61-4684-B3AB-BFACC​353CFAB}
 O43 - CFD: 30/01/2012 - 06:04:40 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F313B154-C88E-4E37-B5E5-9E2B0​49F57CB}
 O43 - CFD: 18/03/2012 - 07:24:00 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F3211918-AADC-4B88-84BB-F84C6​97A4B48}
 O43 - CFD: 08/03/2012 - 06:40:22 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F5B62BDF-6A03-4BC4-B566-91BED​1BDB84F}
 O43 - CFD: 19/06/2011 - 17:58:10 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F5E91F49-A929-4653-88EE-B41F3​E751A56}
 O43 - CFD: 16/05/2011 - 12:08:44 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F6372C03-4EF1-4698-AD5D-EAC42​410701D}
 O43 - CFD: 09/10/2011 - 05:26:28 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F664E9CA-2B69-411E-89A3-303E6​86C0BC4}
 O43 - CFD: 04/03/2012 - 07:36:32 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F6E9210D-6B75-4A7B-B082-C3DC9​E67BD17}
 O43 - CFD: 30/08/2011 - 07:53:42 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F734F887-761D-4FFE-A38B-71ACB​CD96E4E}
 O43 - CFD: 26/09/2011 - 18:19:20 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F7A4C324-5BFE-453C-8AD1-55ED9​1140FE7}
 O43 - CFD: 31/05/2011 - 06:54:44 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F7FFEF56-45F3-4130-A208-EA9B8​77FFA1B}
 O43 - CFD: 26/04/2011 - 09:57:44 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F90DAE4F-4CE6-47BD-8D91-3E917​EEB5B01}
 O43 - CFD: 30/04/2011 - 13:33:12 - [0] ----D- C:\Users\Mahine\AppData\Local\​{F9A0DA53-6645-4803-A71B-90F27​FD68DE4}
 O43 - CFD: 08/09/2011 - 05:56:44 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FA5F0344-30FA-45A5-9EE0-7F4D4​8FC64E0}
 O43 - CFD: 07/11/2011 - 07:06:12 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FB15D935-35BD-4517-8011-FFEC5​8EABF42}
 O43 - CFD: 04/04/2011 - 19:09:36 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FB534F43-0491-4D0B-B6AF-29CD7​DC67ACF}
 O43 - CFD: 17/06/2011 - 07:02:02 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FBA182A8-CEAB-4E0D-8192-4B287​A40ACF4}
 O43 - CFD: 18/01/2012 - 06:25:14 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FC4DC73B-FF67-4DA2-B746-77940​A8717CD}
 O43 - CFD: 04/06/2011 - 10:04:56 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FD22C620-DB92-4626-AD11-B7E69​C79F7E1}
 O43 - CFD: 15/08/2011 - 08:02:18 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FE1015FB-2DB6-4684-B702-8D625​4EAC872}
 O43 - CFD: 15/07/2011 - 06:49:44 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FEA088FE-777C-4B92-9536-E13D8​578936C}
 O43 - CFD: 05/03/2012 - 06:29:32 - [0] ----D- C:\Users\Mahine\AppData\Local\​{FF679327-381C-478E-AB9D-05AFC​2CF0B48}
 O43 - CFD: 12/06/2011 - 08:27:40 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C25B3D00-3D04-4C6A-95BB-09E1C​8437B9A}
 O43 - CFD: 03/02/2012 - 05:50:58 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C32B1B30-0EDC-4BA7-A5A7-C1C4C​4B91D7B}
 O43 - CFD: 27/10/2011 - 05:51:02 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C45E0689-3680-4DDC-B1EE-E6813​42D815B}
 O43 - CFD: 16/06/2011 - 06:33:50 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C4E18528-EE30-406A-9D2B-6F9E3​2762482}
 O43 - CFD: 17/03/2012 - 20:43:12 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C59A80E6-A54A-43A6-AC5C-E5101​99A943B}
 O43 - CFD: 19/04/2011 - 06:27:32 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C59E6591-7B67-4F48-9E35-C244A​6281B9C}
 O43 - CFD: 15/06/2011 - 06:49:20 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C6287B4B-6CCC-40FE-B4AB-676BF​BB81F1C}
 O43 - CFD: 29/07/2011 - 06:17:38 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C679E85A-A292-41A6-A13F-B78FA​39014DC}
 O43 - CFD: 28/01/2012 - 05:30:16 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C6B66EA1-43E8-49C0-AB64-5160B​4E21772}
 O43 - CFD: 25/09/2011 - 07:12:14 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C6C8650F-1265-45ED-87DE-93535​C912FA1}
 O43 - CFD: 19/01/2012 - 22:34:40 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C8586522-7818-4724-97F8-B62AF​1665DF4}
 O43 - CFD: 28/04/2011 - 09:13:22 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C881A5AE-6DCC-413B-88DB-20EF8​6FFAAAC}
 O43 - CFD: 14/07/2011 - 07:03:44 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C92BE8AF-E659-4704-8EF6-ACFE0​283245E}
 O43 - CFD: 30/03/2011 - 14:28:04 - [0] ----D- C:\Users\Mahine\AppData\Local\​{C97058BE-0F40-42AE-B4B1-B0973​EFC61A2}
 FirewallRaz
 EmptyFlash
 EmptyTemp
 


 lance zhpfix

 tu colles les lignes avec le bouton H

 tu supprimes avec le bouton ok tous nettoyer

 copies colles zhpfixreport


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 21/03/2012 à 20:24:22  
  1. Prévenir les modérateurs en cas d'abus
 
Bonjour did80 voilà le rapport
 Rapport de ZHPFix 1.12.3381 par Nicolas Coolman, Update du 08/02/2011
 Fichier d'export Registre : C:\ZHP\ZHPExportRegistry-21-03​-2012-08-20-23.txt
 Run by Mahine at 21/03/2012 08:20:23
 Windows Vista Business Edition, 32-bit Service Pack 2 (Build 6002)
 Web site : http://www.premiumorange.com/z [...] hpfix.html
 Web site : http://nicolascoolman.skyrock.com/

 ========== Clé(s) du Registre ==========
 ABSENT Key: HKLM\Software\Microsoft\Window​s\CurrentVersion\Ext\PreApprov​ed\{0069B690-7A2B-41C5-98CA-9F​535B4C8532}
 ABSENT Key: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{6f​d31ed6-7c94-4bbc-8e95-f927f4d3​a949}
 SUPPRIME Key: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{F0​8555B0-9CC3-11D2-AA8E-00000000​0567}
 ABSENT Key: HKCU\Software\Microsoft\handle
 ABSENT Key: HKCU\Software\XML
 ABSENT Key: [HKLM\Software\Microsoft\Window​s\CurrentVersion\Internet Settings\Zones]
 SUPPRIME Key: HKCU\Software\3
 ABSENT Key:  StartupReg: Internet Antivirus 2011

 ========== Valeur(s) du Registre ==========
 ABSENT Valeur Standard Profile: FirewallRaz :
 ABSENT Valeur Domain Profile: FirewallRaz :
 Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)

 ========== Dossier(s) ==========
 SUPPRIME Folder: C:\ProgramData\db594c
 ABSENT C:\Users\Mahine\AppData\Roamin​g\Internet Antivirus 2011
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CA653DEA-0A14-4F00-A483-492AD​5F2AA25}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CC23BBEE-200B-4744-AE14-C1D13​C7B6632}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CC5BE535-6CD0-4810-B1A5-E31DD​D21DF2C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CD1702EF-AD7E-4CE4-AC42-C17A6​3391E58}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CD788A4C-DFAE-4E2B-9EA1-6068C​6BB74E0}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CE036760-B3C8-4E99-B6B0-CAC02​D966A96}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CE683DDC-CB5A-49D5-A584-A1618​E4381AF}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CE956F82-75AB-4D77-97A1-24977​1CB061F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CEC27842-E5F4-4F3C-A357-5CF57​1629C5F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CEDDE730-3C25-4FFE-9B57-58A79​02771FB}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CF5763B4-D930-4A5F-8779-588C5​0FC96BF}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CF7ABF85-2689-41EF-B1DE-29A36​A284BB3}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CFA67F51-F5AC-4EA3-A63F-07265​C173515}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D0045B0F-D588-48DA-B1CA-CE520​411E969}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D0362E67-F670-4480-B849-B0E0F​7A50908}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D0450E2E-DC71-4535-9926-41A37​3278E50}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D09ABF3F-75FF-464E-BC54-BED06​1E9C813}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D103524C-29B6-4F0A-8B28-2D42A​97C93F1}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D10914AD-5671-4476-B0E3-2711E​4DA6B00}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D1872CAD-62D7-433F-9BF1-8F355​B73B997}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D23D50A4-318C-4AB4-8A53-7D60B​9BF4C2A}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D29F95B4-8C99-4041-8237-91F5F​DB9E317}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D4C69CF9-F658-44F8-9FA3-5729D​6912D52}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D5C6387E-7BED-4F54-A5DD-3BC1E​4316138}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D6E8D97D-E96C-4E26-BB86-9020E​1664D25}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D7FFB464-3489-413A-829F-721BA​423402F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D8505E46-1C2C-4AD2-9E84-96012​B0CF195}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D8B2C03A-D64C-47BE-B93B-7B712​A50F5F5}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D8CB7936-646D-4A23-859A-33491​02F508B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D8EF8AFA-37EF-455B-AF85-2D74E​EE466FD}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DA8D49F3-3BDD-48D4-92F3-A1C19​C141AEA}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DA9AA9B3-A642-4994-AB7D-E2B32​F0A923D}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DABB00A5-4C68-4BEB-8B84-B45CE​103EB51}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DAEC4936-3964-4789-B25E-CD0D4​DBA3DA0}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DB0AF22A-0B29-49B1-ADC8-8B88D​7BE59D5}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DBE4917F-23D4-49F9-8610-486C5​CB5A837}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DCB02449-8FD4-4C6B-9A91-9350A​DBB17AF}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DCEAF14B-013B-4CF3-B3A1-BD617​EFF664F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DDA57874-FA15-41AD-B90D-68AAA​0FD0E9E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DDB926B5-3148-44F3-AB7F-534B4​D1224B8}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DDD6E36D-000C-4A1D-82E4-F4AF1​6466F55}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DE3E1721-BCD4-4B37-8550-D5C59​9D60835}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DE666179-05C4-4F5D-AA0E-3CB59​79A56CE}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DE6E9593-9A82-4929-AF0B-67BF4​628273B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DF9D9A16-9A62-4502-867F-7B323​FB8F45B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E07327F0-8897-4602-B185-BC018​3CA0FCD}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E11B660A-8E78-46B3-B907-87633​AC8393C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E331B207-7C48-4F21-B6A6-E4EB9​AACD309}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E341A174-66B8-4843-8736-460B0​AD5D429}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E4A182F9-F66C-40B5-9037-D47E7​AB43C06}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E4C4054B-C939-4545-8992-FABE2​29F3582}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E4C6A844-BFE8-4D53-8711-10B4A​F4BF187}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E54214AF-34D7-4E1D-A018-F090C​FE10148}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E54677A9-928E-4F69-93F7-446D5​D7A70D3}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E55DCE4C-8ADD-4B0E-9D72-3C1AD​36E528E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E5668250-7B2D-43A5-A3B2-BA7F0​B6586AD}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E68A1689-8DE5-496A-8016-DD944​C70E9E8}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E6CEC799-DC3E-4890-9EDF-476F8​04889F8}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E73F39D0-D34D-4629-8F4E-C9D2D​5E35444}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E89E32AF-D6CB-4641-AEDC-81C3D​6893226}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E94568A1-24BC-4EB1-AD06-34B9A​521B78F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EA15FCA6-0860-40C6-9AA0-1960D​C5EEE9D}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EA56C8A3-54F5-480C-AD1E-4201D​0493E0E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EA5CF091-123B-4B46-945E-83408​5DEA68C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EB4E13B1-5783-4448-84BA-707C9​6A47D0C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EC3AC6BA-B601-45B8-AE4D-DEA10​CBF5AA3}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EC40CC42-D6CD-4EF0-87B2-E2900​69DD23A}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EC610443-768D-47CC-8A80-51CC5​DEE7189}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EC6E90D4-74A3-4427-81D3-D855E​B0619A2}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{ECA8276D-A6EB-4435-9FA8-1F0B9​4AC3724}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{ECBA7CC2-4AA3-4BB3-A5DE-B2273​18B25E3}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{ED59462E-4C80-4D95-AA7E-1DB18​A79EC4C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EDD82362-3575-4274-9495-E5526​B250D15}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EE0DEC26-98F5-4AE5-B4FB-3567B​7BA1CBC}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EF3E7F41-9DF8-4442-BB47-E9635​EF2FEF4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F049FFD1-C1D6-409D-8A61-4724C​D703822}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F19BAEC4-2522-41DF-BD70-BA215​70CBB53}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F2A4CBAD-3AA6-487C-8051-2D32B​5016111}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F2AC209C-9F61-4684-B3AB-BFACC​353CFAB}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F313B154-C88E-4E37-B5E5-9E2B0​49F57CB}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F3211918-AADC-4B88-84BB-F84C6​97A4B48}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F5B62BDF-6A03-4BC4-B566-91BED​1BDB84F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F5E91F49-A929-4653-88EE-B41F3​E751A56}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F6372C03-4EF1-4698-AD5D-EAC42​410701D}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F664E9CA-2B69-411E-89A3-303E6​86C0BC4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F6E9210D-6B75-4A7B-B082-C3DC9​E67BD17}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F734F887-761D-4FFE-A38B-71ACB​CD96E4E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F7A4C324-5BFE-453C-8AD1-55ED9​1140FE7}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F7FFEF56-45F3-4130-A208-EA9B8​77FFA1B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F90DAE4F-4CE6-47BD-8D91-3E917​EEB5B01}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F9A0DA53-6645-4803-A71B-90F27​FD68DE4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FA5F0344-30FA-45A5-9EE0-7F4D4​8FC64E0}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FB15D935-35BD-4517-8011-FFEC5​8EABF42}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FB534F43-0491-4D0B-B6AF-29CD7​DC67ACF}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FBA182A8-CEAB-4E0D-8192-4B287​A40ACF4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FC4DC73B-FF67-4DA2-B746-77940​A8717CD}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FD22C620-DB92-4626-AD11-B7E69​C79F7E1}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FE1015FB-2DB6-4684-B702-8D625​4EAC872}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FEA088FE-777C-4B92-9536-E13D8​578936C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FF679327-381C-478E-AB9D-05AFC​2CF0B48}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C25B3D00-3D04-4C6A-95BB-09E1C​8437B9A}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C32B1B30-0EDC-4BA7-A5A7-C1C4C​4B91D7B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C45E0689-3680-4DDC-B1EE-E6813​42D815B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C4E18528-EE30-406A-9D2B-6F9E3​2762482}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C59A80E6-A54A-43A6-AC5C-E5101​99A943B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C59E6591-7B67-4F48-9E35-C244A​6281B9C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C6287B4B-6CCC-40FE-B4AB-676BF​BB81F1C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C679E85A-A292-41A6-A13F-B78FA​39014DC}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C6B66EA1-43E8-49C0-AB64-5160B​4E21772}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C6C8650F-1265-45ED-87DE-93535​C912FA1}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C8586522-7818-4724-97F8-B62AF​1665DF4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C881A5AE-6DCC-413B-88DB-20EF8​6FFAAAC}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C92BE8AF-E659-4704-8EF6-ACFE0​283245E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C97058BE-0F40-42AE-B4B1-B0973​EFC61A2}
 SUPPRIME Flash Cookies: 358
 SUPPRIME Temporaires Windows: : 623

 ========== Fichier(s) ==========
 SUPPRIME File: c:\users\mahine\appdata\roamin​g\microsoft\internet explorer\quick launch\internet antivirus 2011.lnk
 ABSENT File: c:\programdata\db594c\internet​av2011.exe
 SUPPRIME Flash Cookies: 163
 SUPPRIME Temporaires Windows: : 1731


 ========== Récapitulatif ==========
 8 : Clé(s) du Registre
 3 : Valeur(s) du Registre
 118 : Dossier(s)
 4 : Fichier(s)


 End of clean in 00mn 22s

 ========== Chemin de fichier rapport ==========
 C:\ZHP\ZHPFix[R1].txt - 21/03/2012 08:20:23 [11766]

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 21/03/2012 à 23:09:05  
  1. Prévenir les modérateurs en cas d'abus
 


  :hello: vahi

 on va vérifier si tu n'as pas un autre locataire

 fais ceci

 Télécharge load_tdsskiller de Loup Blanc sur ton Bureau
 http://fradesch.perso.cegetel. [...] killer.exe
 ou la:
 http://support.kaspersky.com/d [...] killer.zip

 Cet outil est conçu pour automatiser différentes tâches proposées par TDSSKiller, un fix de Kaspersky.

 Lance load_tdsskiller en double-cliquant dessus. Clic droit et exécuter en tant qu'administrateur avec Vista/Seven

 lance le scan.
 http://nsa26.casimages.com/img​/2011/01/27/11012708271111174.​jpg


 Si une entrée est trouvée  il faut cocher  CURE

 Continue et redémarrer le pc

 http://img62.imageshack.us/img​62/8674/tdsskillertraitement22​2.png
 Tu peux récupérer le rapport en validant Report

 Poste le rapport C:\TDSSKiller.version_date_heu​re_log.txt
 (C:\ est la partition contenant l'OS du PC).

 PS au cas ou tu n’aurais pas cure coches DELETE continues et rememarres

 ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 21/03/2012 à 23:55:23  
  1. Prévenir les modérateurs en cas d'abus
 
J'ai fais comme tu m'as dis aucune entrée n'a été trouvée dois-je redémarrer et en refaire un autre ou c'est bon?
 Sinon voilà le rapport du 1er scan

 Rapport de ZHPFix 1.12.3381 par Nicolas Coolman, Update du 08/02/2011
 Fichier d'export Registre : C:\ZHP\ZHPExportRegistry-21-03​-2012-08-20-23.txt
 Run by Mahine at 21/03/2012 08:20:23
 Windows Vista Business Edition, 32-bit Service Pack 2 (Build 6002)
 Web site : http://www.premiumorange.com/z [...] hpfix.html
 Web site : http://nicolascoolman.skyrock.com/

 ========== Clé(s) du Registre ==========
 ABSENT Key: HKLM\Software\Microsoft\Window​s\CurrentVersion\Ext\PreApprov​ed\{0069B690-7A2B-41C5-98CA-9F​535B4C8532}
 ABSENT Key: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{6f​d31ed6-7c94-4bbc-8e95-f927f4d3​a949}
 SUPPRIME Key: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{F0​8555B0-9CC3-11D2-AA8E-00000000​0567}
 ABSENT Key: HKCU\Software\Microsoft\handle
 ABSENT Key: HKCU\Software\XML
 ABSENT Key: [HKLM\Software\Microsoft\Window​s\CurrentVersion\Internet Settings\Zones]
 SUPPRIME Key: HKCU\Software\3
 ABSENT Key:  StartupReg: Internet Antivirus 2011

 ========== Valeur(s) du Registre ==========
 ABSENT Valeur Standard Profile: FirewallRaz :
 ABSENT Valeur Domain Profile: FirewallRaz :
 Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)

 ========== Dossier(s) ==========
 SUPPRIME Folder: C:\ProgramData\db594c
 ABSENT C:\Users\Mahine\AppData\Roamin​g\Internet Antivirus 2011
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CA653DEA-0A14-4F00-A483-492AD​5F2AA25}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CC23BBEE-200B-4744-AE14-C1D13​C7B6632}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CC5BE535-6CD0-4810-B1A5-E31DD​D21DF2C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CD1702EF-AD7E-4CE4-AC42-C17A6​3391E58}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CD788A4C-DFAE-4E2B-9EA1-6068C​6BB74E0}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CE036760-B3C8-4E99-B6B0-CAC02​D966A96}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CE683DDC-CB5A-49D5-A584-A1618​E4381AF}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CE956F82-75AB-4D77-97A1-24977​1CB061F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CEC27842-E5F4-4F3C-A357-5CF57​1629C5F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CEDDE730-3C25-4FFE-9B57-58A79​02771FB}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CF5763B4-D930-4A5F-8779-588C5​0FC96BF}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CF7ABF85-2689-41EF-B1DE-29A36​A284BB3}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{CFA67F51-F5AC-4EA3-A63F-07265​C173515}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D0045B0F-D588-48DA-B1CA-CE520​411E969}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D0362E67-F670-4480-B849-B0E0F​7A50908}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D0450E2E-DC71-4535-9926-41A37​3278E50}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D09ABF3F-75FF-464E-BC54-BED06​1E9C813}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D103524C-29B6-4F0A-8B28-2D42A​97C93F1}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D10914AD-5671-4476-B0E3-2711E​4DA6B00}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D1872CAD-62D7-433F-9BF1-8F355​B73B997}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D23D50A4-318C-4AB4-8A53-7D60B​9BF4C2A}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D29F95B4-8C99-4041-8237-91F5F​DB9E317}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D4C69CF9-F658-44F8-9FA3-5729D​6912D52}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D5C6387E-7BED-4F54-A5DD-3BC1E​4316138}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D6E8D97D-E96C-4E26-BB86-9020E​1664D25}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D7FFB464-3489-413A-829F-721BA​423402F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D8505E46-1C2C-4AD2-9E84-96012​B0CF195}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D8B2C03A-D64C-47BE-B93B-7B712​A50F5F5}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D8CB7936-646D-4A23-859A-33491​02F508B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{D8EF8AFA-37EF-455B-AF85-2D74E​EE466FD}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DA8D49F3-3BDD-48D4-92F3-A1C19​C141AEA}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DA9AA9B3-A642-4994-AB7D-E2B32​F0A923D}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DABB00A5-4C68-4BEB-8B84-B45CE​103EB51}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DAEC4936-3964-4789-B25E-CD0D4​DBA3DA0}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DB0AF22A-0B29-49B1-ADC8-8B88D​7BE59D5}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DBE4917F-23D4-49F9-8610-486C5​CB5A837}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DCB02449-8FD4-4C6B-9A91-9350A​DBB17AF}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DCEAF14B-013B-4CF3-B3A1-BD617​EFF664F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DDA57874-FA15-41AD-B90D-68AAA​0FD0E9E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DDB926B5-3148-44F3-AB7F-534B4​D1224B8}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DDD6E36D-000C-4A1D-82E4-F4AF1​6466F55}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DE3E1721-BCD4-4B37-8550-D5C59​9D60835}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DE666179-05C4-4F5D-AA0E-3CB59​79A56CE}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DE6E9593-9A82-4929-AF0B-67BF4​628273B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{DF9D9A16-9A62-4502-867F-7B323​FB8F45B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E07327F0-8897-4602-B185-BC018​3CA0FCD}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E11B660A-8E78-46B3-B907-87633​AC8393C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E331B207-7C48-4F21-B6A6-E4EB9​AACD309}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E341A174-66B8-4843-8736-460B0​AD5D429}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E4A182F9-F66C-40B5-9037-D47E7​AB43C06}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E4C4054B-C939-4545-8992-FABE2​29F3582}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E4C6A844-BFE8-4D53-8711-10B4A​F4BF187}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E54214AF-34D7-4E1D-A018-F090C​FE10148}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E54677A9-928E-4F69-93F7-446D5​D7A70D3}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E55DCE4C-8ADD-4B0E-9D72-3C1AD​36E528E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E5668250-7B2D-43A5-A3B2-BA7F0​B6586AD}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E68A1689-8DE5-496A-8016-DD944​C70E9E8}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E6CEC799-DC3E-4890-9EDF-476F8​04889F8}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E73F39D0-D34D-4629-8F4E-C9D2D​5E35444}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E89E32AF-D6CB-4641-AEDC-81C3D​6893226}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{E94568A1-24BC-4EB1-AD06-34B9A​521B78F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EA15FCA6-0860-40C6-9AA0-1960D​C5EEE9D}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EA56C8A3-54F5-480C-AD1E-4201D​0493E0E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EA5CF091-123B-4B46-945E-83408​5DEA68C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EB4E13B1-5783-4448-84BA-707C9​6A47D0C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EC3AC6BA-B601-45B8-AE4D-DEA10​CBF5AA3}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EC40CC42-D6CD-4EF0-87B2-E2900​69DD23A}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EC610443-768D-47CC-8A80-51CC5​DEE7189}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EC6E90D4-74A3-4427-81D3-D855E​B0619A2}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{ECA8276D-A6EB-4435-9FA8-1F0B9​4AC3724}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{ECBA7CC2-4AA3-4BB3-A5DE-B2273​18B25E3}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{ED59462E-4C80-4D95-AA7E-1DB18​A79EC4C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EDD82362-3575-4274-9495-E5526​B250D15}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EE0DEC26-98F5-4AE5-B4FB-3567B​7BA1CBC}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{EF3E7F41-9DF8-4442-BB47-E9635​EF2FEF4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F049FFD1-C1D6-409D-8A61-4724C​D703822}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F19BAEC4-2522-41DF-BD70-BA215​70CBB53}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F2A4CBAD-3AA6-487C-8051-2D32B​5016111}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F2AC209C-9F61-4684-B3AB-BFACC​353CFAB}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F313B154-C88E-4E37-B5E5-9E2B0​49F57CB}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F3211918-AADC-4B88-84BB-F84C6​97A4B48}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F5B62BDF-6A03-4BC4-B566-91BED​1BDB84F}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F5E91F49-A929-4653-88EE-B41F3​E751A56}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F6372C03-4EF1-4698-AD5D-EAC42​410701D}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F664E9CA-2B69-411E-89A3-303E6​86C0BC4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F6E9210D-6B75-4A7B-B082-C3DC9​E67BD17}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F734F887-761D-4FFE-A38B-71ACB​CD96E4E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F7A4C324-5BFE-453C-8AD1-55ED9​1140FE7}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F7FFEF56-45F3-4130-A208-EA9B8​77FFA1B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F90DAE4F-4CE6-47BD-8D91-3E917​EEB5B01}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{F9A0DA53-6645-4803-A71B-90F27​FD68DE4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FA5F0344-30FA-45A5-9EE0-7F4D4​8FC64E0}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FB15D935-35BD-4517-8011-FFEC5​8EABF42}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FB534F43-0491-4D0B-B6AF-29CD7​DC67ACF}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FBA182A8-CEAB-4E0D-8192-4B287​A40ACF4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FC4DC73B-FF67-4DA2-B746-77940​A8717CD}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FD22C620-DB92-4626-AD11-B7E69​C79F7E1}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FE1015FB-2DB6-4684-B702-8D625​4EAC872}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FEA088FE-777C-4B92-9536-E13D8​578936C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{FF679327-381C-478E-AB9D-05AFC​2CF0B48}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C25B3D00-3D04-4C6A-95BB-09E1C​8437B9A}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C32B1B30-0EDC-4BA7-A5A7-C1C4C​4B91D7B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C45E0689-3680-4DDC-B1EE-E6813​42D815B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C4E18528-EE30-406A-9D2B-6F9E3​2762482}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C59A80E6-A54A-43A6-AC5C-E5101​99A943B}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C59E6591-7B67-4F48-9E35-C244A​6281B9C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C6287B4B-6CCC-40FE-B4AB-676BF​BB81F1C}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C679E85A-A292-41A6-A13F-B78FA​39014DC}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C6B66EA1-43E8-49C0-AB64-5160B​4E21772}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C6C8650F-1265-45ED-87DE-93535​C912FA1}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C8586522-7818-4724-97F8-B62AF​1665DF4}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C881A5AE-6DCC-413B-88DB-20EF8​6FFAAAC}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C92BE8AF-E659-4704-8EF6-ACFE0​283245E}
 SUPPRIME Folder: C:\Users\Mahine\AppData\Local\​{C97058BE-0F40-42AE-B4B1-B0973​EFC61A2}
 SUPPRIME Flash Cookies: 358
 SUPPRIME Temporaires Windows: : 623

 ========== Fichier(s) ==========
 SUPPRIME File: c:\users\mahine\appdata\roamin​g\microsoft\internet explorer\quick launch\internet antivirus 2011.lnk
 ABSENT File: c:\programdata\db594c\internet​av2011.exe
 SUPPRIME Flash Cookies: 163
 SUPPRIME Temporaires Windows: : 1731


 ========== Récapitulatif ==========
 8 : Clé(s) du Registre
 3 : Valeur(s) du Registre
 118 : Dossier(s)
 4 : Fichier(s)


 End of clean in 00mn 22s

 ========== Chemin de fichier rapport ==========
 C:\ZHP\ZHPFix[R1].txt - 21/03/2012 08:20:23 [11766]

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 22/03/2012 à 00:07:03  
  1. Prévenir les modérateurs en cas d'abus
 

 reposte moi un zhpdiag sur www.mydoc.tk

 çà doit etre clean je pense si oui

 on désinstallera les outils  :hello:


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 22/03/2012 à 06:24:36  
  1. Prévenir les modérateurs en cas d'abus
 
Bonjour voilà le lien
 http://mydoc.tk/3/7964ZHPDiag.txt

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 22/03/2012 à 10:59:16  
  1. Prévenir les modérateurs en cas d'abus
 


:hello: vahi

fais ceci

  Télécharge OTM

  OTM ici
 • Enregistre le fichier sur votre bureau.
 • AVAST reconnait ce logiciel comme un intrus, donc le désactiver le temps des manipulations.
 • Double-cliquez sur OTM.exe pour l'exécuter. (Si vous êtes sous Vista, cliquez-droit sur le fichier OTM.exe et exécutez-le en tant qu'administrateur.)

 Copies les  lignes suivantes en bleu dans le cadre de gauche sous
 paste  instructions for items to be moved

 http://static.commentcamarche.​net/www.commentcamarche.net/fa​q/images/0-skVZLpmV-otm-s-.png

 
 :Reg

 [-HKLM\Software\Microsoft\Windo​ws\CurrentVersion\Ext\PreAppro​ved\{0069B690-7A2B-41C5-98CA-9​F535B4C8532}]


 :Commands
 [purity]
 [emptytemp]


 Cliquez sur MOVE IT ! pour lancer la suppression.

 Attendre la fin du travail de l'outil puis fermer OTM

 Le résultat apparaitra dans le cadre Results.
 Clique sur Exit pour fermer.
 
 copie colle le rapport situé dans C:\_OTM\MovedFiles\06092009_13​0526.log "Exemple"

 NB: Il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
 si c'est le cas accepte par Oui/Yes.
 a+


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 23/03/2012 à 04:28:36  
  1. Prévenir les modérateurs en cas d'abus
 
Bonjour did80 j'ai fais comme tu m'as dis voilà les résultats

 All processes killed
 ========== REGISTRY ==========
 Registry key HKEY_LOCAL_MACHINE\Software\Mi​crosoft\Windows\CurrentVersion​\Ext\PreApproved\{0069B690-7A2​B-41C5-98CA-9F535B4C8532}\ not found.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{0069B690-7A2B-41C​5-98CA-9F535B4C8532}\ not found.
 ========== COMMANDS ==========
 
 [EMPTYTEMP]
 
 User: All Users
 
 User: Default
 ->Temp folder emptied: 0 bytes
 ->Temporary Internet Files folder emptied: 0 bytes
 
 User: Default User
 
 User: Mahine
 ->Temp folder emptied: 343671 bytes
 ->Temporary Internet Files folder emptied: 1060398 bytes
 ->Java cache emptied: 0 bytes
 ->FireFox cache emptied: 202465116 bytes
 ->Flash cache emptied: 3106956 bytes
 
 User: Public
 
 %systemdrive% .tmp files removed: 0 bytes
 %systemroot% .tmp files removed: 0 bytes
 %systemroot%\System32 .tmp files removed: 0 bytes
 %systemroot%\System32\drivers .tmp files removed: 0 bytes
 Windows Temp folder emptied: 4807945 bytes
 %systemroot%\system32\config\s​ystemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
 %systemroot%\system32\config\s​ystemprofile\AppData\Local\Mic​rosoft\Windows\Temporary Internet Files folder emptied: 18879315 bytes
 %systemroot%\system32\config\s​ystemprofile\AppData\LocalLow\​Sun\Java\Deployment folder emptied: 13690551 bytes
 RecycleBin emptied: 0 bytes
 
 Total Files Cleaned = 233,00 mb
 
 
 OTM by OldTimer - Version 3.1.19.0 log created on 03222012_161848

 Files moved on Reboot...
 File move failed. C:\Windows\temp\_avast_\Webshl​ock.txt scheduled to be moved on reboot.

 Registry entries deleted on Reboot...

 En revanche quand j'ai démarré OTM avast ne s'est pas manifesté comme tu me l'avais dis c'est normal ?  :??:

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 23/03/2012 à 10:46:07  
  1. Prévenir les modérateurs en cas d'abus
 
:hello: j'avais dit qu'il fallait désactiver avast pour faire otm

  maintenant il faut le réactiver pour te proteger


 2/ comment va ton pc :??:  ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 24/03/2012 à 22:45:33  
  1. Prévenir les modérateurs en cas d'abus
 
Bonjour did80, c'est bon tout est OK et redémarre comme il faut merci beaucoup pour ton aide en tout cas je n'aurai jamais pensé avoir autant de virus!  :sweat:

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 24/03/2012 à 23:03:32  
  1. Prévenir les modérateurs en cas d'abus
 
:super:  vahi

 fais ceci

 Télécharges delfix pour désinstaller les outils de désinfection qui ne vont plus te
 Servir  puisque mis a jour régulièrement

 http://general-changelog-team. [...] e/3-delfix
 fais  la phase 1 recherche
 copies/colles le rapport delfixsearch.txt
 ;)


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 25/03/2012 à 03:32:10  
  1. Prévenir les modérateurs en cas d'abus
 
bonjour did80 voilà le rapport
 # DelFix v8.8 - Rapport créé le 24/03/2012 à 16:31:01
 # Mis à jour le 12/02/12 par Xplode
 # Système d'exploitation : Windows Vista (TM) Business Service Pack 2 (32 bits)
 # Nom d'utilisateur : Mahine - PCMAHINE (Administrateur)
 # Exécuté depuis : C:\Users\Mahine\Downloads\delf​ix.exe
 # Option [Recherche]


 ~~~~~~ Dossiers(s) ~~~~~~

 Présent : C:\_OTM
 Présent : C:\MyHosts
 Présent : C:\ZHP
 Présent : C:\ProgramData\Microsoft\Windo​ws\Start Menu\Programs\ZHP
 Présent : C:\Users\Mahine\Favorites\Desk​top\RK_Quarantine
 Présent : C:\Program Files\Ad-Remover
 Présent : C:\Program Files\ZHPDiag

 ~~~~~~ Fichier(s) ~~~~~~

 Présent : C:\Ad-Report-CLEAN[1].txt
 Présent : C:\Ad-Report-CLEAN[2].txt
 Présent : C:\Ad-Report-SCAN[1].txt
 Présent : C:\AdwCleaner[S1].txt
 Présent : C:\MyHosts.txt
 Présent : C:\TDSSKiller.2.7.22.0_21.03.2​012_11.49.10_log.txt
 Présent : C:\Users\Mahine\Favorites\Desk​top\AD-R.lnk
 Présent : C:\Users\Mahine\Favorites\Desk​top\OTM.exe
 Présent : C:\Users\Mahine\Favorites\Desk​top\RogueKiller.exe
 Présent : C:\Users\Mahine\Favorites\Desk​top\ZHPDiag.txt
 Présent : C:\Users\Mahine\Favorites\Desk​top\ZHPDiag2.exe
 Présent : C:\Users\Mahine\Downloads\adwc​leaner (1).exe
 Présent : C:\Users\Mahine\Downloads\adwc​leaner.exe
 Présent : C:\Users\Mahine\Downloads\MyHo​sts.exe
 Présent : C:\Users\Mahine\Downloads\tdss​killer.zip
 Présent : C:\Users\Public\Desktop\ZHPDia​g.lnk
 Présent : C:\Users\Public\Desktop\ZHPFix​.lnk
 Présent : C:\Users\Public\Desktop\MBRChe​ck.lnk

 ~~~~~~ Registre ~~~~~~

 Clé Présente : HKCU\Software\Ad-Remover
 Clé Présente : HKLM\SOFTWARE\OldTimer Tools
 Clé Présente : HKLM\SOFTWARE\AdwCleaner
 Clé Présente : HKLM\SOFTWARE\Microsoft\Window​s\CurrentVersion\Uninstall\

Profil : Equipe sécurité
did80
Célèbre sur tout le forum (de 30 000 à 99 999 messages postés) Helpeur confirmé
  1. Posté le 25/03/2012 à 12:47:11  
  1. Prévenir les modérateurs en cas d'abus
 

  :hello: vahi

  relance delfix phase2 nettoyer/supprimer

  puis relance le pour le désinstaller


 2/ edites le titre de ton 1er message en cliquant sur le modifier

  marques résolu :jap:

 bon surf did80 :hello:


---------------
l'urgent est fait , l'impossible est en cours
pour les miracles prévoir des délais
vahi
Bébé forumeur (De 10 à 49 messages postés)
  1. Posté le 25/03/2012 à 22:04:02  
  1. Prévenir les modérateurs en cas d'abus
 
Super!
 Un grand merci à toi did80, qui a donné de ton temps pour m'aider!
 Mon problème est résolu, quel soulagement!  :super:

 MERCI!

 :hello:

 Page :
1  2
Dernière Page
Page Suivante
Page Précédente
Première Page

Aller à :
 

Sujets relatifs
un virus qui bloque ma connection wifi et eternet et empéche de reformater [RESOLU] Comment se débarrasser d'un cheval de troie ?
Invasion du cheval de troie TR/spy.GEN invasion poppups please aidé moi
Invasion de publiciels résolu Lenteur de mon ordi depuis invasion barbare
virus ou autre ? malgrès le blocage trafic internet continue  
Plus de sujets relatifs à : Invasion virus, plus de connection internet! (RESOLU)

Les 5 sujets de discussion précédents Nombre de réponses Dernier message
A l'aiiiide !! VIRUS GENDARMERIE 3
Fermeture intempestive du navigateur 0
agent tchat p2p reseau avast n'ont pu demarres 0
Virus "AUTORITE NT\ SYSTEME" 0
Fenêtres intempestives cachées 0