Voila le rapport de list killem:
List'em by g3n-h@ckm@n 1.0.5.0
Thx to Chiquitine29.....
User : David (Administrateurs) # PC-DE-DAVID
Update on 05/11/2009 by g3n-h@ckm@n ::::: 19.00
Start at: 08:35:14 | 07/11/2009
Contact : g3n-h@ckm@n sur CCM
Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18828
Windows Firewall Status : Disabled
C:\ -> Disque fixe local | 141,04 Go (100,25 Go free) [HDD] | NTFS
D:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processus en cours
C:\Windows\System32\smss.exe 520
C:\Windows\system32\csrss.exe 596
C:\Windows\system32\wininit.exe 648
C:\Windows\system32\csrss.exe 660
C:\Windows\system32\services.exe 696
C:\Windows\system32\winlogon.exe 752
C:\Windows\system32\lsass.exe 772
C:\Windows\system32\lsm.exe 780
C:\Windows\system32\svchost.exe 932
C:\Windows\system32\svchost.exe 992
C:\Windows\System32\svchost.exe 1028
C:\Windows\System32\svchost.exe 1084
C:\Windows\System32\svchost.exe 1124
C:\Windows\system32\svchost.exe 1152
C:\Windows\system32\svchost.exe 1228
C:\Windows\system32\SLsvc.exe 1252
C:\Windows\system32\svchost.exe 1308
C:\Windows\system32\svchost.exe 1504
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1624
C:\Windows\System32\spoolsv.exe 1740
C:\Windows\system32\svchost.exe 1764
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1944
C:\Program Files\Bonjour\mDNSResponder.exe 1980
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe 2004
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE 340
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE 396
C:\Program Files\F-Secure Internet Security\Common\FSHDLL32.EXE 600
C:\Windows\system32\svchost.exe 732
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe 1192
C:\Program Files\Google\Update\GoogleUpdate.exe 1432
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 1484
C:\Windows\System32\svchost.exe 2068
C:\Windows\system32\IoctlSvc.exe 2120
C:\Windows\System32\svchost.exe 2160
C:\Windows\system32\svchost.exe 2192
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2240
C:\Windows\system32\svchost.exe 2284
C:\Windows\System32\svchost.exe 2332
C:\Windows\system32\SearchIndexer.exe 2356
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 2432
C:\Windows\system32\Dwm.exe 3492
C:\Windows\system32\taskeng.exe 3516
C:\Windows\Explorer.EXE 3564
C:\Windows\system32\taskeng.exe 3600
C:\Program Files\Common Files\Real\Update_OB\realsched.exe 4000
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 4008
C:\Program Files\Java\jre6\bin\jusched.exe 4020
C:\Windows\System32\rundll32.exe 4040
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe 4088
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe 1940
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE 2116
C:\Program Files\iTunes\iTunesHelper.exe 2352
C:\Program Files\Windows Media Player\wmpnscfg.exe 2420
C:\Windows\ehome\ehtray.exe 2748
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe 988
C:\Windows\ehome\ehmsas.exe 3228
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe 3828
C:\Windows\System32\rundll32.exe 3524
C:\Windows\system32\wbem\wmiprvse.exe 2504
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN 3940
C:\Windows\system32\svchost.exe 728
C:\Windows\system32\wbem\unsecapp.exe 3176
C:\Program Files\F-Secure Internet Security\ORSP Client\fsorsp.exe 2636
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe 3260
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe 1288
C:\Program Files\Windows Media Player\wmpnetwk.exe 1368
C:\Program Files\iPod\bin\iPodService.exe 4144
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe 4700
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe 4784
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe 4872
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe 4204
C:\Windows\servicing\TrustedInstaller.exe 5096
C:\Program Files\Google\Chrome\Application\chrome.exe 5132
C:\Program Files\Google\Chrome\Application\chrome.exe 3284
C:\Program Files\Windows Live\Messenger\msnmsgr.exe 4920
C:\Program Files\Windows Live\Contacts\wlcomm.exe 4632
C:\Program Files\Windows Live\Messenger\wlcsdk.exe 4964
C:\Program Files\Mozilla Firefox\firefox.exe 2304
C:\Windows\system32\sdclt.exe 3348
C:\Windows\system32\svchost.exe 3376
C:\Program Files\F-Secure Internet Security\FSGUI\fscuif.exe 4440
C:\Windows\system32\SearchProtocolHost.exe 5332
C:\Windows\system32\SearchFilterHost.exe 1236
C:\Users\David\Downloads\List_Killem.exe 4268
C:\Windows\system32\conime.exe 288
C:\Windows\system32\cmd.exe 3804
C:\Windows\system32\wbem\wmiprvse.exe 1184
C:\Users\David\AppData\Local\Temp\914.tmp\pv.exe 6000
======================
Cles de demarrage "Run"
======================
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe"
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre6\\bin\\jusched.exe\""
"NvSvc"="RUNDLL32.EXE C:\\Windows\\system32\\nvsvc.dll,nvsvcStart"
"NvMediaCenter"="RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit"
"NvCplDaemon"="RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup"
"NBKeyScan"="\"C:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\""
"Malwarebytes Anti-Malware (reboot)"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe\" /runcleanupscript"
"JMB36X IDE Setup"="C:\\Windows\\RaidTool\\xInsIDE.exe"
"IAAnotif"="\"C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\Iaanotif.exe\""
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"F-Secure TNB"="\"C:\\Program Files\\F-Secure Internet Security\\FSGUI\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Manager"="\"C:\\Program Files\\F-Secure Internet Security\\Common\\FSM32.EXE\" /splash"
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\""
"Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
@=""
=====================
cles additionnelles
=====================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"EnableUIADesktopToggle"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
===============
===============
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
===============
======
BHO :
======
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
@="AcroIEHelperStub"
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
@="Skype add-on (mastermind)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
@="Search Helper"
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C6867EB7-8350-4856-877F-93CF8AE3DC9C}]
@="LitmusBHO"
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
@="Google Dictionary Compression sdch"
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
"NoExplorer"=dword:00000001
==========================
===============
Path : C:\Program Files\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\Smart Projects\IsoBuster;C:\Program Files\QuickTime\QTSystem\
===============
¤¤¤¤¤¤¤¤¤¤ Fichiers et dossiers presents :
C:\ProgramData\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\System32\autorun.inf
C:\Windows\System32\drivers\etc\hosts.msn
¤¤¤¤¤¤¤¤¤¤ Clés de registre Presentes :
¤¤¤¤¤¤¤¤¤¤ C:\Windows\Prefetch :
AAWTRAY.EXE-75D4AE19.pf
AAWWSC.EXE-AC2B49A2.pf
AgAppLaunch.db
AgGlFaultHistory.db
AgGlFgAppHistory.db
AgGlGlobalHistory.db
AgGlUAD_P_S-1-5-21-3701140666-1405394053-1684418335-1002.db
AgGlUAD_S-1-5-21-3701140666-1405394053-1684418335-1002.db
AgRobust.db
CHROME.EXE-5A1054AF.pf
CMD.EXE-4A81B364.pf
COMPTE.EXE-F2B936D1.pf
CONIME.EXE-9781FD5F.pf
CONTROL.EXE-817F8F1D.pf
CSCRIPT.EXE-D1EF4768.pf
DEFRAG.EXE-588F90AD.pf
DFRGNTFS.EXE-7E4077FE.pf
DLLHOST.EXE-5E46FA0D.pf
DLLHOST.EXE-766398D2.pf
DLLHOST.EXE-EEE13F6D.pf
FIREFOX.EXE-A606B53C.pf
FSAV32.EXE-D41EADB4.pf
FSAVAUI.EXE-3C44DF02.pf
FSAVSTRT.EXE-F0A31D4C.pf
FSBLSRV.EXE-FE0CDF62.pf
FSCUIF.EXE-1B13FE5F.pf
FSDFWD.EXE-C3758D8C.pf
FSORSP.EXE-06583B71.pf
FSSM32.EXE-62B97081.pf
FSWSCS.EXE-08F9319B.pf
GOOGLECRASHHANDLER.EXE-8A3B4C33.pf
GOOGLEEARTH.EXE-4179DA94.pf
GOOGLEUPDATE.EXE-FE771DDA.pf
HPQBAM08.EXE-5B656772.pf
HPQSTE08.EXE-8FA26316.pf
HPQUSGH.EXE-720A2D45.pf
HPRBLOG.EXE-EF38A44E.pf
IEXPLORE.EXE-908C99F8.pf
IPODSERVICE.EXE-37C43D64.pf
JAVA.EXE-E27B75C2.pf
Layout.ini
LIST_KILLEM.EXE-23DB8921.pf
LITMUS-UPDATE-HANDLER.EXE-D2FCFFA5.pf
LOGONUI.EXE-09140401.pf
MCDCHECK.EXE-8DDBD8B7.pf
MCUPDATE.EXE-62E74733.pf
MOBSYNC.EXE-C5E2284F.pf
MODE.COM-DB34C082.pf
MPAS-D.EXE-40FE95BA.pf
MPSIGSTUB.EXE-E58D46B0.pf
MSNMSGR.EXE-9974F251.pf
NTOSBOOT-B00DFAAD.pf
PBCARNOT.EXE-21B8D0CA.pf
PfSvPerfStats.bin
PRESENTATIONSETTINGS.EXE-2F4708C9.pf
PV.EXE-E60DE304.pf
ReadyBoot
REALSCHED.EXE-A91B3084.pf
REG.EXE-E7E8BD26.pf
RUNDLL32.EXE-020F8AFD.pf
RUNDLL32.EXE-08CD1231.pf
RUNDLL32.EXE-1A95EFB3.pf
RUNDLL32.EXE-8BCA13E7.pf
SEARCHFILTERHOST.EXE-77482212.pf
SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
SNDVOL.EXE-5D4CC7D6.pf
SNIPPINGTOOL.EXE-EFFDAFDE.pf
SOFFICE.BIN-F438F228.pf
SOFFICE.EXE-00AAD94D.pf
SOUNDRECORDER.EXE-9865DC1B.pf
SSVAGENT.EXE-42E515EF.pf
SSVAGENT.EXE-D0A26E22.pf
STCLIENT_WRAPPER.EXE-7A90E0B8.pf
SVCHOST.EXE-40F9D24E.pf
SVCHOST.EXE-E2C2633A.pf
TASKENG.EXE-48D4E289.pf
THREATWORK.EXE-AEDFF3A3.pf
TNBUTIL.EXE-68B90E31.pf
TRUSTEDINSTALLER.EXE-3CC531E5.pf
UNSECAPP.EXE-A02905A6.pf
WERCON.EXE-E36BD04E.pf
WERFAULT.EXE-E69F695A.pf
WERMGR.EXE-0F2AC88C.pf
WISPTIS.EXE-595A3677.pf
WLCOMM.EXE-272FF9F7.pf
WLCSDK.EXE-9F99E7FE.pf
WMIADAP.EXE-F8DFDFA2.pf
WMIPRVSE.EXE-1628051C.pf
WMPNETWK.EXE-D9F2A96F.pf
WMPNSCFG.EXE-FC0D39BF.pf
WUAUCLT.EXE-70318591.pf
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
merci pour ton aide.
"on est ce qu on vit on est ce qu on mange" .david.