Decidemment je suis pas doué je viens de le retrouver le voici :
List'em by g3n-h@ckm@n 1.0.5.3
Thx to Chiquitine29.....
User : Home (Administrateurs) # PC-DE-HOME
Update on 09/11/2009 by g3n-h@ckm@n ::::: 20.30
Start at: 18:28:42 | 10/11/2009
Contact : g3n-h@ckm@n sur CCM
Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18828
Windows Firewall Status : Disabled
AV : AVG Anti-Virus plus Firewall 8.0 [ Enabled | Updated ]
C:\ -> Disque fixe local | 144,29 Go (29,96 Go free) [ACER] | NTFS
D:\ -> Disque fixe local | 144,04 Go (39,31 Go free) [DATA] | NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque CD-ROM
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque amovible
J:\ -> Disque fixe local | 232,88 Go (52,06 Go free) [BUTCH] | NTFS
K:\ -> Disque CD-ROM
L:\ -> Disque amovible
M:\ -> Disque CD-ROM
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processus en cours
C:\Windows\System32\smss.exe 472
C:\Windows\system32\csrss.exe 604
C:\Windows\system32\wininit.exe 656
C:\Windows\system32\csrss.exe 668
C:\Program Files\AVG\AVG9\avgchsvx.exe 680
C:\Program Files\AVG\AVG9\avgrsx.exe 688
C:\Program Files\AVG\AVG9\avgcsrvx.exe 732
C:\Windows\system32\services.exe 752
C:\Windows\system32\lsass.exe 768
C:\Windows\system32\lsm.exe 776
C:\Windows\system32\winlogon.exe 928
C:\Windows\system32\svchost.exe 952
C:\Windows\system32\svchost.exe 1016
C:\Windows\System32\svchost.exe 1136
C:\Windows\System32\svchost.exe 1172
C:\Windows\system32\svchost.exe 1184
C:\Windows\system32\svchost.exe 1376
C:\Windows\system32\SLsvc.exe 1396
C:\Windows\system32\svchost.exe 1568
C:\Windows\system32\svchost.exe 1732
C:\Windows\System32\spoolsv.exe 1988
C:\Windows\system32\svchost.exe 2012
C:\Windows\system32\Dwm.exe 1852
C:\Windows\system32\taskeng.exe 2020
C:\Windows\Explorer.EXE 872
C:\Windows\system32\taskeng.exe 2060
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe 2364
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe 2380
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 2444
C:\Program Files\AVG\AVG9\avgwdsvc.exe 2496
C:\Program Files\AVG\AVG9\avgfws9.exe 2508
C:\Program Files\Bonjour\mDNSResponder.exe 2524
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe 2556
C:\Program Files\AVG\AVG9\avgam.exe 2692
C:\Program Files\AVG\AVG9\avgnsx.exe 2712
C:\Program Files\Common Files\LightScribe\LSSrvc.exe 3008
C:\Windows\system32\PnkBstrA.exe 3164
C:\Windows\system32\PnkBstrB.exe 3180
C:\Windows\system32\svchost.exe 3196
C:\Program Files\CyberLink\Shared Files\RichVideo.exe 3236
C:\Windows\system32\svchost.exe 3280
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe 3304
C:\Windows\System32\svchost.exe 3336
C:\Windows\system32\SearchIndexer.exe 3396
C:\Program Files\AVG\AVG9\avgemc.exe 3412
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe 3456
C:\Windows\system32\WUDFHost.exe 3560
C:\Program Files\AVG\AVG9\avgcsrvx.exe 3580
C:\Windows\RtHDVCpl.exe 2236
C:\Acer\Empowering Technology\SysMonitor.exe 2252
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe 1512
C:\Windows\system32\wbem\wmiprvse.exe 2536
C:\Program Files\Common Files\Real\Update_OB\realsched.exe 1056
C:\Windows\System32\rundll32.exe 3988
C:\Program Files\iTunes\iTunesHelper.exe 4080
C:\Program Files\Java\jre6\bin\jusched.exe 2092
C:\Program Files\Windows Sidebar\sidebar.exe 1592
C:\Windows\ehome\ehtray.exe 1536
C:\Program Files\Windows Live\Messenger\msnmsgr.exe 1272
C:\Program Files\AVG\AVG9\avgcsrvx.exe 2340
C:\Windows\ehome\ehmsas.exe 4244
C:\Windows\System32\rundll32.exe 4256
C:\Program Files\Windows Media Player\wmpnscfg.exe 4328
C:\Program Files\Windows Media Player\wmpnetwk.exe 4520
C:\Program Files\Windows Sidebar\sidebar.exe 4540
C:\Windows\system32\wbem\wmiprvse.exe 4652
C:\Program Files\iPod\bin\iPodService.exe 4804
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE 4844
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE 4912
C:\Windows\system32\wbem\unsecapp.exe 5296
C:\Program Files\Mozilla Firefox\firefox.exe 2328
C:\Windows\system32\conime.exe 1652
C:\Program Files\Windows Media Player\wmplayer.exe 1584
C:\Windows\System32\mobsync.exe 4560
C:\Users\Home\Desktop\List_Killem.exe 3848
C:\Windows\system32\cmd.exe 6120
C:\Users\Home\AppData\Local\Temp\119F.tmp\pv.exe 6072
======================
Cles de demarrage "Run"
======================
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"
"Acer Tour Reminder"="C:\\Acer\\AcerTour\\Reminder.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe"
"MsnMsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe\" /background"
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe AcRdB7_1_0"
"EPSON Stylus DX4400 Series"="C:\\Windows\\system32\\spool\\DRIVERS\\W32X86\\3\\E_FATICAE.EXE /FU \"C:\\Windows\\TEMP\\E_S8B5E.tmp\" /EF \"HKCU\""
"DAEMON Tools Lite"="\"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe\" -autorun"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"TurboNet"="C:\\Users\\Home\\AppData\\Local\\Temp\\b.exe"
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,4d,00,53,\
00,41,00,53,00,43,00,75,00,69,00,2e,00,65,00,78,00,65,00,20,00,2d,00,68,00,\
69,00,64,00,65,00,00,00
"RtHDVCpl"="RtHDVCpl.exe"
"Acer Empowering Technology Monitor"="C:\\Acer\\Empowering Technology\\SysMonitor.exe"
"eDataSecurity Loader"="C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSloader.exe"
"PCMMediaSharing"="C:\\Program Files\\Acer Arcade Live\\Acer HomeMedia Connect\\Kernel\\DMS\\PCMMediaSharing.exe"
"Acer Tour"=""
"eRecoveryService"=""
"Apanel"="C:\\ACERSW\\config\\NewSetApanel.cmd"
"WarReg_PopUp"="C:\\Acer\\WR_PopUp\\WarReg_PopUp.exe"
"Acer Tour Reminder"="C:\\Acer\\AcerTour\\Reminder.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NvSvc"="RUNDLL32.EXE C:\\Windows\\system32\\nvsvc.dll,nvsvcStart"
"NvCplDaemon"="RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre6\\bin\\jusched.exe\""
"Skytel"="Skytel.exe"
"AVG9_TRAY"="C:\\PROGRA~1\\AVG\\AVG9\\avgtray.exe"
"Malwarebytes Anti-Malware (reboot)"="\"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe\" /runcleanupscript"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
=====================
cles additionnelles
=====================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"EnableUIADesktopToggle"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
===============
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
===============
===============
===============
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
======
BHO :
======
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
@="WormRadar.com IESiteBlocker.NavFilter"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
@="Ask Toolbar BHO"
"NoExplorer"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
"NoExplorer"=dword:00000001
==========================
=========================
Environnement variables :
=========================
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Home\AppData\Roaming
choix=1
CLASSPATH=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=PC-DE-HOME
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Home
LOCALAPPDATA=C:\Users\Home\AppData\Local
LOGONSERVER=\\PC-DE-HOME
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\QuickTime\QTSystem\C:\Program Files\DMV\MaxTV4\plugins;
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 13, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0d
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Home\AppData\Local\Temp
TMP=C:\Users\Home\AppData\Local\Temp
USERDOMAIN=PC-de-Home
USERNAME=Home
USERPROFILE=C:\Users\Home
windir=C:\Windows
¤¤¤¤¤¤¤¤¤¤ Fichiers et dossiers presents :
C:\ProgramData\.zreglib
C:\Windows\iun6002.exe
C:\Users\Home\LOCAL Settings\Temp\utt938B.tmp.exe
¤¤¤¤¤¤¤¤¤¤ Clés de registre Presentes :
"HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}"
¤¤¤¤¤¤¤¤¤¤ C:\Windows\Prefetch :
AgAppLaunch.db
AgCx_SC1.db
AgCx_SC1.db.trx
AgGlFaultHistory.db
AgGlFgAppHistory.db
AgGlGlobalHistory.db
AgGlUAD_P_S-1-5-21-1942739150-3024437067-2572189820-1000.db
AgGlUAD_S-1-5-21-1942739150-3024437067-2572189820-1000.db
AgRobust.db
ASKPARTNERCOBRANDINGTOOL.EXE-9A79EEDD.pf
AVGCMGR.EXE-27FF3A49.pf
AVGCMGR.EXE-7F3B658E.pf
AVGCSRVX.EXE-0C19085F.pf
AVGSCANX.EXE-5BD46372.pf
AVGSRMAX.EXE-D4A7AE38.pf
AVGUI.EXE-2D9AB8CF.pf
AVGUPD.EXE-A2A9EA76.pf
CMD.EXE-4A81B364.pf
CONIME.EXE-9781FD5F.pf
CONSENT.EXE-531BD9EA.pf
CONTROL.EXE-817F8F1D.pf
CSCRIPT.EXE-D1EF4768.pf
DLLHOST.EXE-5E46FA0D.pf
DLLHOST.EXE-766398D2.pf
DLLHOST.EXE-7FAA2E4C.pf
DLLHOST.EXE-8EF34503.pf
DLLHOST.EXE-B2EB1806.pf
DLLHOST.EXE-FDE983AF.pf
EAPLAUNCHER.EXE-13C674DB.pf
EXPLORER.EXE-A80E4F97.pf
FIREFOX.EXE-A606B53C.pf
FIXCFG.EXE-DEF5F496.pf
GETPOPUPINFO.EXE-29F941BC.pf
GOOGLEEARTH.EXE-8471DF9D.pf
GOOGLEUPDATE.EXE-FE771DDA.pf
GOOGLEUPDATER.EXE-39628337.pf
GOOGLEUPDATERSERVICE.EXE-09540BCD.pf
IELOWUTIL.EXE-3885C25E.pf
IEXPLORE.EXE-908C99F8.pf
IPODSERVICE.EXE-37C43D64.pf
JAVA.EXE-E27B75C2.pf
KMPLAYER.EXE-5C3C4305.pf
LADS.EXE-3D3801BD.pf
Layout.ini
LIST_KILLEM.EXE-EFA85689.pf
LOGONUI.EXE-09140401.pf
MFPMP.EXE-26F35380.pf
MOBSYNC.EXE-C5E2284F.pf
MODE.COM-DB34C082.pf
MSFEEDSSYNC.EXE-6E6FBDF4.pf
MSI27AB.TMP-E93D1A50.pf
MSIA1BF.TMP-29B16EC6.pf
MSICEAD.TMP-5ED45D7D.pf
MSIEXEC.EXE-A2D55CB6.pf
NEW1C2A.TMP.EXE-D142541E.pf
NEW956E.TMP.EXE-C8694E68.pf
NEWC3ED.TMP.EXE-A907258E.pf
NOTEPAD.EXE-D8414F97.pf
NTOSBOOT-B00DFAAD.pf
OMAHAINDICATOR.EXE-950D8A2C.pf
PfSvPerfStats.bin
PING.EXE-7E94E73E.pf
PKR.EXE-DB7E5BC8.pf
POKERAPP.EXE-4A74C8C9.pf
PPEXEC.EXE-1F850016.pf
PROCESSOR64BIT.EXE-B5E62222.pf
PV.EXE-329BA6A8.pf
PV.EXE-3533435D.pf
PV.EXE-A625FDCA.pf
PV.EXE-D244D687.pf
PV.EXE-E785DCF7.pf
ReadyBoot
REALPLAY.EXE-A09C7945.pf
REG.EXE-E7E8BD26.pf
SEARCHFILTERHOST.EXE-77482212.pf
SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
SNDVOL.EXE-5D4CC7D6.pf
SUBINACL.EXE-7FBD134E.pf
SVCHOST.EXE-7CFEDEA3.pf
TASKENG.EXE-48D4E289.pf
TASKMGR.EXE-5F5F473D.pf
TASKSCHEDULER.EXE-E5982EBC.pf
TRUSTEDINSTALLER.EXE-3CC531E5.pf
UTORRENT.EXE-1070971C.pf
UTORRENT.EXE-5F9AB773.pf
UTT1A75.TMP.EXE-7D7C1300.pf
UTT938B.TMP.EXE-31422B80.pf
UTTC277.TMP.EXE-CDC7B779.pf
VERCLSID.EXE-7C52E31C.pf
VSSVC.EXE-B8AFC319.pf
WERCON.EXE-E36BD04E.pf
WERFAULT.EXE-E69F695A.pf
WERMGR.EXE-0F2AC88C.pf
WMIADAP.EXE-F8DFDFA2.pf
WMIPRVSE.EXE-1628051C.pf
WMPLAYER.EXE-BAD6BD53.pf
WMPNETWK.EXE-D9F2A96F.pf
WMPNSCFG.EXE-FC0D39BF.pf
ZHPDIAG 1.24.22.EXE-6CBF8DD2.pf
ZHPDIAG 1.24.22.TMP-7A8545FF.pf
ZHPDIAG.EXE-5F50D22C.pf
ZHPFIX.EXE-85222C4E.pf
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤