Merci pour votre réponse !
Voici le message :
List'em by g3n-h@ckm@n 1.0.4.8
Thx to Chiquitine29.....
User : toph () # PC-DE-TOPH
Update on 29/10/2009 by g3n-h@ckm@n ::::: 18.30
Start at: 12:21:01 | 30/10/2009
Contact : g3n-h@ckm@n sur CCM
Intel(R) Pentium(R) Dual CPU E2220 @ 2.40GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 7.0.6001.18000
Windows Firewall Status : Enabled
C:\ -> Disque fixe local | 762,26 Go (358,36 Go free) [OS] | NTFS
D:\ -> Disque CD-ROM
E:\ -> Disque CD-ROM
H:\ -> Disque amovible | 1,92 Go (417,72 Mo free) [MightyDrive] | FAT
M:\ -> Disque fixe local | 97,66 Go (26,5 Go free) [mp3] | NTFS
W:\ -> Disque fixe local | 58,59 Go (58,5 Go free) [system] | NTFS
Nom de l'image PID Nom de la sessio Num‚ro de s Utilisation
========================= ======== ================ =========== ============
System Idle Process 0 Services 0 24 Ko
System 4 Services 0 3ÿ912 Ko
smss.exe 280 Services 0 720 Ko
csrss.exe 404 Services 0 5ÿ588 Ko
csrss.exe 440 Console 1 7ÿ472 Ko
wininit.exe 448 Services 0 3ÿ516 Ko
services.exe 484 Services 0 4ÿ928 Ko
winlogon.exe 508 Console 1 4ÿ220 Ko
lsass.exe 536 Services 0 7ÿ668 Ko
lsm.exe 544 Services 0 3ÿ740 Ko
svchost.exe 684 Services 0 4ÿ900 Ko
svchost.exe 740 Services 0 5ÿ080 Ko
svchost.exe 780 Services 0 27ÿ832 Ko
svchost.exe 864 Services 0 5ÿ480 Ko
svchost.exe 888 Services 0 12ÿ208 Ko
svchost.exe 972 Services 0 8ÿ468 Ko
explorer.exe 1228 Console 1 34ÿ568 Ko
List_Killem.exe 1772 Console 1 5ÿ584 Ko
cmd.exe 1796 Console 1 2ÿ232 Ko
WmiPrvSE.exe 1964 Services 0 8ÿ016 Ko
tasklist.exe 2028 Console 1 4ÿ652 Ko
======================
Cles de demarrage "Run"
======================
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter"
"SmpcSys"="C:\\Program Files\\PACKARD BELL\\SetUpMyPC\\SmpSys.exe"
"ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe"
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,4d,00,53,\
00,41,00,53,00,43,00,75,00,69,00,2e,00,65,00,78,00,65,00,20,00,2d,00,68,00,\
69,00,64,00,65,00,00,00
"RtHDVCpl"="RtHDVCpl.exe"
"SmpcSys"="C:\\Program Files\\Packard Bell\\SetupMyPC\\SmpSys.exe"
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup"
"FujiKeyboard"="c:\\Acer\\Preload\\Autorun\\DRV\\FUJI Keyboard\\ABoard.exe"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"eRecoveryService"=""
"Setresolution"="C:\\ACER\\config\\1920X1200.cmd"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"snp2std"="C:\\Windows\\vsnp2std.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre6\\bin\\jusched.exe\""
"VirtualCloneDrive"="\"C:\\Program Files\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s"
"EKIJ5000StatusMonitor"="C:\\Windows\\system32\\spool\\DRIVERS\\W32X86\\3\\EKIJ5000MUI.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"hpqSRMon"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqSRMon.exe"
"MobileConnect"=hex(2):25,00,70,00,72,00,6f,00,67,00,72,00,61,00,6d,00,66,00,\
69,00,6c,00,65,00,73,00,25,00,5c,00,56,00,6f,00,64,00,61,00,66,00,6f,00,6e,\
00,65,00,5c,00,56,00,6f,00,64,00,61,00,66,00,6f,00,6e,00,65,00,20,00,4d,00,\
6f,00,62,00,69,00,6c,00,65,00,20,00,43,00,6f,00,6e,00,6e,00,65,00,63,00,74,\
00,5c,00,42,00,69,00,6e,00,5c,00,4d,00,6f,00,62,00,69,00,6c,00,65,00,43,00,\
6f,00,6e,00,6e,00,65,00,63,00,74,00,2e,00,65,00,78,00,65,00,20,00,2f,00,73,\
00,69,00,6c,00,65,00,6e,00,74,00,00,00
"avgnt"="\"C:\\Program Files\\Avira\\AntiVir Desktop\\avgnt.exe\" /min"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
@=""
=====================
cles additionnelles
=====================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"EnableUIADesktopToggle"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
===============
===============
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
======
BHO :
======
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
@=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
@="AcroIEHelperStub"
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
@="Skype add-on (mastermind)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
@="BitComet ClickCapture"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
@="HP Smart BHO Class"
"NoExplorer"=dword:00000001
==========================
===============
Path : C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Nero\Lib\
===============
¤¤¤¤¤¤¤¤¤¤ Fichiers et dossiers presents :
C:\ProgramData\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Users\toph\LOCAL Settings\Temp\EAD2B34.exe
C:\Users\toph\LOCAL Settings\Temp\EAD2E6F.exe
C:\Users\toph\LOCAL Settings\Temp\EAD3AAF.exe
C:\Users\toph\LOCAL Settings\Temp\EAD4AC5.exe
C:\Users\toph\LOCAL Settings\Temp\EAD7E40.exe
C:\Users\toph\LOCAL Settings\Temp\EAD9414.exe
C:\Users\toph\LOCAL Settings\Temp\EADB9BD.exe
C:\Users\toph\LOCAL Settings\Temp\EADE61.exe
C:\Users\toph\LOCAL Settings\Temp\FlashPlayerUpdate.exe
C:\Users\toph\LOCAL Settings\Temp\Fruity Loops 3 Full Final.exe
C:\Users\toph\LOCAL Settings\Temp\GoogleChromeInstaller.exe
C:\Users\toph\LOCAL Settings\Temp\jre-6u15-windows-i586-iftw.exe
C:\Users\toph\LOCAL Settings\Temp\SearchWithGoogleUpdate.exe
C:\Users\toph\LOCAL Settings\Temp\vlc.exe
C:\Users\toph\LOCAL Settings\Temp\wlsetup-custom.exe
¤¤¤¤¤¤¤¤¤¤ Clés de registre Presentes :
"HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker"
"HKCU\Software\Grand Virtual"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
¤¤¤¤¤¤¤¤¤¤ C:\Windows\Prefetch :
7ZFM.EXE-69B8961D.pf
ACRORD32.EXE-172CF576.pf
ACRORD32INFO.EXE-1C0557AA.pf
ADOBE_UPDATER.EXE-D7992733.pf
AgAppLaunch.db
AgCx_SC1.db
AgCx_SC1.db.trx
AgCx_SC2.db
AGENT.EXE-D2852D29.pf
AgGlFaultHistory.db
AgGlFgAppHistory.db
AgGlGlobalHistory.db
AgGlUAD_P_S-1-5-21-660370928-1177540912-2443105282-1000.db
AgGlUAD_P_S-1-5-21-660370928-1177540912-2443105282-1001.db
AgGlUAD_S-1-5-21-660370928-1177540912-2443105282-1000.db
AgGlUAD_S-1-5-21-660370928-1177540912-2443105282-1001.db
AgRobust.db
AVNOTIFY.EXE-FEC2FEC4.pf
AVSCAN.EXE-E289CD20.pf
AVWSC.EXE-4630B658.pf
BITCOMET.EXE-615D9C04.pf
CALC.EXE-77FDF17F.pf
CONSENT.EXE-531BD9EA.pf
DEFRAG.EXE-588F90AD.pf
DFRGNTFS.EXE-7E4077FE.pf
DLLHOST.EXE-5E46FA0D.pf
DLLHOST.EXE-766398D2.pf
DLLHOST.EXE-B2EB1806.pf
DRVINST.EXE-4CB4314A.pf
EXPLORER.EXE-A80E4F97.pf
EZSCRSVR.SCR-A027EAA8.pf
FIREFOX.EXE-A606B53C.pf
FLASHUTIL10B.EXE-06DAF439.pf
GOOGLEDESKTOP.EXE-C9B032BF.pf
GOOGLETOOLBARMANAGER_E582EA55-42B1A95D.pf
GOOGLETOOLBARNOTIFIER.EXE-EB3F2433.pf
GOOGLETOOLBARUSER_32.EXE-4E14BB2A.pf
GOOGLEUPDATERSERVICE.EXE-09540BCD.pf
GUS51BE.TMP-C71898A7.pf
HELPER.EXE-8AEDE3E3.pf
HELPPANE.EXE-FEDC965B.pf
HPQBAM08.EXE-5B656772.pf
HPQDIREC.EXE-6B6EA665.pf
HPQGPC01.EXE-92C87699.pf
HPQSTE08.EXE-8FA26316.pf
HPQUSGL.EXE-BF611759.pf
HPRBLOG.EXE-EF38A44E.pf
HPSWP_CLIPBOOK.EXE-B27200F4.pf
IE4UINIT.EXE-3A7E0C67.pf
IEUSER.EXE-7C0FE221.pf
IEXPLORE.EXE-908C99F8.pf
IEXPLORER.EXE-8A91DCCC.pf
IEXPLORER.EXE-FC5EA834.pf
JAVA.EXE-E27B75C2.pf
JP2LAUNCHER.EXE-7C1F11C1.pf
Layout.ini
LOGONUI.EXE-09140401.pf
MFPMP.EXE-26F35380.pf
MOBILECONNECT.EXE-CBD0C46B.pf
MOBSYNC.EXE-C5E2284F.pf
MPAS-D.EXE-40FE95BA.pf
MPCMDRUN.EXE-F401FBB4.pf
MPSIGSTUB.EXE-42C567E9.pf
MPSIGSTUB.EXE-97FE0C7E.pf
MSASCUI.EXE-07E0123F.pf
MSFEEDSSYNC.EXE-6E6FBDF4.pf
MSIEXEC.EXE-A2D55CB6.pf
NOTEPAD.EXE-D8414F97.pf
NTOSBOOT-B00DFAAD.pf
NVCPLUI.EXE-AB2777E5.pf
PAMELA-POUR-SKYPE-BASIC_PAMEL-0AAA1198.pf
PAMELA.EXE-306905E6.pf
PCAUI.EXE-3E82C312.pf
PDFTOTEXT.EXE-935B1FD6.pf
PfSvPerfStats.bin
ReadyBoot
REALONEMESSAGECENTER.EXE-9A1F2949.pf
REALPLAY.EXE-A09C7945.pf
REALSCHED.EXE-A91B3084.pf
RECORDINGMANAGER.EXE-EF07FD0B.pf
REGSVR32.EXE-8461DBEE.pf
RPHELPERAPP.EXE-7719CDA2.pf
RUNDLL32.EXE-095C481F.pf
RUNDLL32.EXE-214B50C6.pf
RUNDLL32.EXE-230FC512.pf
RUNDLL32.EXE-2760EB45.pf
RUNDLL32.EXE-4F50FB32.pf
RUNDLL32.EXE-636CD077.pf
RUNDLL32.EXE-6D2968F1.pf
RUNDLL32.EXE-70A53FFC.pf
RUNDLL32.EXE-A13FF177.pf
RUNDLL32.EXE-A6251510.pf
RUNDLL32.EXE-B197135C.pf
RUNDLL32.EXE-B9DCC00E.pf
RUNDLL32.EXE-BF1A352E.pf
RUNDLL32.EXE-C211633D.pf
RUNDLL32.EXE-CA1F8280.pf
RUNDLL32.EXE-DE807C4D.pf
SCALC.EXE-A77089B3.pf
SEARCHFILTERHOST.EXE-77482212.pf
SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
SETUP_VMC_LITE.EXE-4E1F838A.pf
SETUP_VMC_LITE.EXE-54590E17.pf
SETUP_VMC_LITE.EXE-5A9298A4.pf
SETUP_WM.EXE-674F654A.pf
SKYPE.EXE-4929A84C.pf
SKYPENAMES.EXE-52288AB3.pf
SKYPEPM.EXE-EECA8925.pf
SNDVOL.EXE-5D4CC7D6.pf
SOFFICE.BIN-FFFF76B3.pf
SOFFICE.EXE-0C715DD8.pf
SSVAGENT.EXE-42E515EF.pf
SVCHOST.EXE-7CFEDEA3.pf
SVCHOST.EXE-DD9DE812.pf
TASKENG.EXE-48D4E289.pf
TASKMGR.EXE-5F5F473D.pf
TRUSTEDINSTALLER.EXE-3CC531E5.pf
UNREGMP2.EXE-2294B148.pf
UPDATE.EXE-026DCA13.pf
UPDATER.EXE-F209ED67.pf
UPNP.EXE-52ECBB69.pf
VERCLSID.EXE-7C52E31C.pf
VLC.EXE-A11F73EE.pf
VSSVC.EXE-B8AFC319.pf
WERCON.EXE-E36BD04E.pf
WERFAULT.EXE-E69F695A.pf
WERMGR.EXE-0F2AC88C.pf
WINMAIL.EXE-1092D371.pf
WMIADAP.EXE-F8DFDFA2.pf
WMIPRVSE.EXE-1628051C.pf
WMPLAYER.EXE-BAD6BD53.pf
WUAUCLT.EXE-70318591.pf
WUDFHOST.EXE-AFFEF87C.pf
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤