
je mets que ça , y'a que ça qui m'intrigue

Starting search for hidden objects.
Catched Exception in <SCAN_Process>
ACCESS_VIOLATION
EAX = 00CB7F70 EBX = 02ECEF78
ECX = 02ECEBD4 EDX = 00000000
ESI = 00CB7F70 EDI = 00000178
EIP = 0041140A EBP = 02ECEE60
ESP = 02ECEBD0 Flg = 00010206
CS = 00000023 SS = 0000001B
HKEY_USERS\S-1-5-21-1123561945-492894223-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\hrzr_ehacngu
[NOTE] The registry entry is invisible.
HKEY_USERS\S-1-5-21-1123561945-492894223-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\hrzr_ehacngu:p:\jvaqbjf\flfgrz32\abgrcnq.rkr
putain , si qlq1 a une reponse là dessus

j'pete le contenu quand meme
Windows Registry Editor Version 5.00
[HKEY_USERS\S-1-5-21-1123561945-492894223-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count]
"HRZR_PGYFRFFVBA"=hex:00,00,00,00,00,00,00,00
"HRZR_PGYPHNPbhag:pgbe"=hex:00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00
"HRZR_HVFPHG"=hex:00,00,00,00,0b,00,00,00,b0,e3,da,ad,0e,30,cb,01
"HRZR_EHACNGU"=hex:00,00,00,00,23,00,00,00,10,6d,80,e6,0f,30,cb,01
"HRZR_EHACNGU:P:\\Qbphzragf naq Frggvatf\\cuernx\\Ohernh\\Gpcivrj.rkr"=hex:00,\
00,00,00,06,00,00,00,f0,62,45,a0,06,30,cb,01
"HRZR_EHACNGU:P:\\Qbphzragf naq Frggvatf\\cuernx\\Ohernh\\cebprkc.rkr"=hex:00,\
00,00,00,06,00,00,00,70,db,e2,a0,06,30,cb,01
"HRZR_EHACNGU:P:\\JVAQBJF\\flfgrz32\\riragije.rkr"=hex:00,00,00,00,06,00,00,00,\
b0,93,a2,b1,06,30,cb,01
"HRZR_EHACNGU:guhaqreoveq.yax"=hex:00,00,00,00,06,00,00,00,b0,77,84,18,07,30,\
cb,01
"HRZR_EHACNGU:P:\\Cebtenz Svyrf\\guhaqreoveq-2.0.0.20cer.ra-HF.jva32\\guhaqreoveq\\guhaqreoveq.rkr"=hex:00,\
00,00,00,07,00,00,00,10,34,3b,60,0a,30,cb,01
"HRZR_EHACNGU:SversbkCbegnoyr.yax"=hex:00,00,00,00,06,00,00,00,b0,3f,34,19,07,\
30,cb,01
"HRZR_EHACNGU:P:\\Cebtenz Svyrf\\SS\\SversbkCbegnoyr\\SversbkCbegnoyr.rkr"=hex:00,\
00,00,00,09,00,00,00,b0,e1,72,ef,0e,30,cb,01
"HRZR_EHACNGU:iyp.yax"=hex:00,00,00,00,06,00,00,00,70,f8,07,59,07,30,cb,01
"HRZR_EHACNGU:P:\\Cebtenz Svyrf\\iyp-1.1.2-jva32\\iyp-1.1.2\\iyp.rkr"=hex:00,\
00,00,00,06,00,00,00,f0,47,1a,59,07,30,cb,01
"HRZR_EHACNGU:P:\\JVAQBJF\\flfgrz32\\ABGRCNQ.RKR"=hex:00,00,00,00,11,00,00,00,\
30,66,0f,d5,0f,30,cb,01
"HRZR_EHACNGU:P:\\Qbphzragf naq Frggvatf\\cuernx\\Zrf qbphzragf\\ybtf_eng\\7M\\7-MvcCbegnoyr\\7-MvcCbegnoyr.rkr"=hex:00,\
00,00,00,06,00,00,00,70,06,fe,f9,07,30,cb,01
"HRZR_EHACNGU:P:\\Qbphzragf naq Frggvatf\\cuernx\\Zrf qbphzragf\\AvfFpevcg_2.3\\AvfFpevcg 2.3\\zvep.rkr"=hex:00,\
00,00,00,06,00,00,00,90,66,df,ce,08,30,cb,01
"HRZR_EHACVQY"=hex:00,00,00,00,09,00,00,00,b0,e1,72,ef,0e,30,cb,01
"HRZR_EHACVQY:P:\\Qbphzragf naq Frggvatf\\cuernx\\Ohernh\\SversbkCbegnoyr.yax"=hex:00,\
00,00,00,08,00,00,00,b0,e1,72,ef,0e,30,cb,01
"HRZR_EHACVQY:P:\\Qbphzragf naq Frggvatf\\cuernx\\Ohernh\\guhaqreoveq.yax"=hex:00,\
00,00,00,06,00,00,00,10,34,3b,60,0a,30,cb,01
"HRZR_EHACNGU:P:\\JVAQBJF\\flfgrz32\\zfcnvag.rkr"=hex:00,00,00,00,06,00,00,00,\
a0,28,bc,d6,0b,30,cb,01
"HRZR_EHACNGU:P:\\Qbphzragf naq Frggvatf\\cuernx\\Ohernh\\VprFjbeq122ra\\VprFjbeq.rkr"=hex:00,\
00,00,00,06,00,00,00,90,86,15,af,0e,30,cb,01
"HRZR_EHACNGU:P:\\JVAQBJF\\ertrqvg.rkr"=hex:00,00,00,00,06,00,00,00,10,6d,80,\
e6,0f,30,cb,01

http://imagesup.org/images7/1280512475-sans-titre.jpg
que dalle sur l'hex avec http://www.pieter-arntz.info/infodomein ... unhex.html ou reghexenc