A voir également:
- CODE 28
- Code ascii - Guide
- Code puk bloqué - Guide
- Comment déverrouiller un téléphone quand on a oublié le code - Guide
- Code activation windows 10 - Guide
- Code blocks - Télécharger - Langages
11 réponses
lol
Télécharge OTL de OLDTimer
▶ enregistre le sur ton Bureau.
▶ Double clic ( pour vista / 7 => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.
▶ Coche les 2 cases Lop et Purity
▶ Coche la case devant scan all users
▶ règle-le sur "60 Days"
▶ dans la colonne de gauche , mets tout sur "all"
ne modifie pas ceci :
"files created whithin" et "files modified whithin"
▶Clic sur Run Scan.
A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).
Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)
▶▶▶ NE LE POSTE PAS SUR LE FORUM
Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/
▶ Clique sur Parcourir et cherche le fichier ci-dessus.
▶ Clique sur Ouvrir.
▶ Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt
est ajouté dans la page.
▶ Copie ce lien dans ta réponse.
▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
Télécharge OTL de OLDTimer
▶ enregistre le sur ton Bureau.
▶ Double clic ( pour vista / 7 => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.
▶ Coche les 2 cases Lop et Purity
▶ Coche la case devant scan all users
▶ règle-le sur "60 Days"
▶ dans la colonne de gauche , mets tout sur "all"
ne modifie pas ceci :
"files created whithin" et "files modified whithin"
▶Clic sur Run Scan.
A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).
Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)
▶▶▶ NE LE POSTE PAS SUR LE FORUM
Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/
▶ Clique sur Parcourir et cherche le fichier ci-dessus.
▶ Clique sur Ouvrir.
▶ Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt
est ajouté dans la page.
▶ Copie ce lien dans ta réponse.
▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
▶ Télécharge UsbFix
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
▶ Double clic sur le raccourci UsbFix présent sur ton bureau .
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]
▶ Laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra.
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
(!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
▶ Double clic sur le raccourci UsbFix présent sur ton bureau .
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]
▶ Laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra.
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
############################## | UsbFix V6.098 |
User : ns (Administrateurs) # BUREAU-B2FB610D
Update on 03/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 12:48:55 | 04/03/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Celeron(R) M processor 1.50GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23
C:\ -> Disque fixe local # 26,27 Go (25,3 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 26,67 Go (12,02 Go free) # NTFS
E:\ -> Disque CD-ROM
################## | Elements infectieux |
D:\DOCUME~1\ns\LOCALS~1\Temp\QDF.exe
C:\autorun.inf
################## | Registre |
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500BCA15-57A7-4eaf-8143-8C619470B13D}]
[HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}]
[HKLM\Software\Classes\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}]
################## | Mountpoints2 |
################## | Vaccin |
################## | ! Fin du rapport # UsbFix V6.098 ! |
User : ns (Administrateurs) # BUREAU-B2FB610D
Update on 03/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 12:48:55 | 04/03/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Celeron(R) M processor 1.50GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23
C:\ -> Disque fixe local # 26,27 Go (25,3 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 26,67 Go (12,02 Go free) # NTFS
E:\ -> Disque CD-ROM
################## | Elements infectieux |
D:\DOCUME~1\ns\LOCALS~1\Temp\QDF.exe
C:\autorun.inf
################## | Registre |
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500BCA15-57A7-4eaf-8143-8C619470B13D}]
[HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}]
[HKLM\Software\Classes\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}]
################## | Mountpoints2 |
################## | Vaccin |
################## | ! Fin du rapport # UsbFix V6.098 ! |
▶ (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir
▶ Double clic (clic droit "en tant qu'administrateur" pour Vista)sur le raccourci UsbFix présent sur ton bureau
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]
▶ Ton bureau disparaitra et le pc redémarrera .
▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
▶ Double clic (clic droit "en tant qu'administrateur" pour Vista)sur le raccourci UsbFix présent sur ton bureau
▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
▶ Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]
▶ Ton bureau disparaitra et le pc redémarrera .
▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .
Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
############################## | UsbFix V6.098 |
User : ns (Administrateurs) # BUREAU-B2FB610D
Update on 03/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:17:12 | 04/03/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Celeron(R) M processor 1.50GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23
C:\ -> Disque fixe local # 26,27 Go (25,3 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 26,67 Go (11,99 Go free) # NTFS
E:\ -> Disque CD-ROM
################## | Elements infectieux |
Supprimé ! D:\DOCUME~1\ns\LOCALS~1\Temp\QDF.exe
Supprimé ! C:\autorun.inf
Supprimé ! D:\Recycler\S-1-5-21-725345543-1202660629-2147112213-1004
################## | Registre |
Supprimé ! [HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}]
################## | Mountpoints2 |
################## | Listing des fichiers présent |
[27/04/2009 20:26|--a------|230432] C:\SPC230NC.DAT
[08/04/2009 21:20|--a------|0] C:\Tech_Vista.log
[06/09/2004 15:40|---hs----|512] C:\BOOTSECT.DOS
[05/08/2004 12:00|-rahs----|4952] C:\Bootfont.bin
[29/08/2008 19:52|-rahs----|252240] C:\ntldr
[05/08/2004 05:00|-rahs----|47564] C:\NTDETECT.COM
[03/09/2008 21:05|--ahs----|120586240] C:\pagefile.sys
[13/08/2005 13:08|--ahs----|1193] C:\PATCH.REV
[08/07/2005 19:01|-rahs----|73] C:\PRELOAD.AAA
[13/04/2008 19:34|--a------|28672] C:\setupSNK.exe
[08/07/2005 19:01|-rahs----|73] C:\PRELOAD.REV
[10/02/2010 11:35|--a------|61019] C:\EPSON
[03/09/2008 20:33|--ahs----|258461696] C:\hiberfil.sys
[07/03/2009 20:28|---hs----|323] C:\boot.ini
[03/09/2008 21:17|--a------|0] C:\CONFIG.SYS
[03/09/2008 21:17|--a------|0] C:\AUTOEXEC.BAT
[24/06/2007 19:42|-rahs----|0] C:\MSDOS.SYS
[24/06/2007 19:42|-rahs----|0] C:\IO.SYS
[04/11/2008 05:18|--a------|6165292] D:\e8a5b28205eaea0293c4a735946c3010KRN_DATA
[29/02/2004 16:44|--a------|52576] D:\orange.bmp
[?|?|?] D:\pagefile.sys
[18/09/2008 22:34|--a------|1664591] D:\pf-setup.exe
[04/03/2010 13:21|--a------|2265] D:\UsbFix.txt
################## | Vaccination |
# C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
# D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
################## | Upload |
Veuillez envoyer le fichier : D:\UsbFix_Upload_Me_BUREAU-B2FB610D.zip : https://www.ionos.fr/?affiliate_id=77097
Merci pour votre contribution .
################## | ! Fin du rapport # UsbFix V6.098 ! |
User : ns (Administrateurs) # BUREAU-B2FB610D
Update on 03/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 13:17:12 | 04/03/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Celeron(R) M processor 1.50GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23
C:\ -> Disque fixe local # 26,27 Go (25,3 Go free) [ACER] # FAT32
D:\ -> Disque fixe local # 26,67 Go (11,99 Go free) # NTFS
E:\ -> Disque CD-ROM
################## | Elements infectieux |
Supprimé ! D:\DOCUME~1\ns\LOCALS~1\Temp\QDF.exe
Supprimé ! C:\autorun.inf
Supprimé ! D:\Recycler\S-1-5-21-725345543-1202660629-2147112213-1004
################## | Registre |
Supprimé ! [HKCR\CLSID\{500BCA15-57A7-4EAF-8143-8C619470B13D}]
################## | Mountpoints2 |
################## | Listing des fichiers présent |
[27/04/2009 20:26|--a------|230432] C:\SPC230NC.DAT
[08/04/2009 21:20|--a------|0] C:\Tech_Vista.log
[06/09/2004 15:40|---hs----|512] C:\BOOTSECT.DOS
[05/08/2004 12:00|-rahs----|4952] C:\Bootfont.bin
[29/08/2008 19:52|-rahs----|252240] C:\ntldr
[05/08/2004 05:00|-rahs----|47564] C:\NTDETECT.COM
[03/09/2008 21:05|--ahs----|120586240] C:\pagefile.sys
[13/08/2005 13:08|--ahs----|1193] C:\PATCH.REV
[08/07/2005 19:01|-rahs----|73] C:\PRELOAD.AAA
[13/04/2008 19:34|--a------|28672] C:\setupSNK.exe
[08/07/2005 19:01|-rahs----|73] C:\PRELOAD.REV
[10/02/2010 11:35|--a------|61019] C:\EPSON
[03/09/2008 20:33|--ahs----|258461696] C:\hiberfil.sys
[07/03/2009 20:28|---hs----|323] C:\boot.ini
[03/09/2008 21:17|--a------|0] C:\CONFIG.SYS
[03/09/2008 21:17|--a------|0] C:\AUTOEXEC.BAT
[24/06/2007 19:42|-rahs----|0] C:\MSDOS.SYS
[24/06/2007 19:42|-rahs----|0] C:\IO.SYS
[04/11/2008 05:18|--a------|6165292] D:\e8a5b28205eaea0293c4a735946c3010KRN_DATA
[29/02/2004 16:44|--a------|52576] D:\orange.bmp
[?|?|?] D:\pagefile.sys
[18/09/2008 22:34|--a------|1664591] D:\pf-setup.exe
[04/03/2010 13:21|--a------|2265] D:\UsbFix.txt
################## | Vaccination |
# C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
# D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
################## | Upload |
Veuillez envoyer le fichier : D:\UsbFix_Upload_Me_BUREAU-B2FB610D.zip : https://www.ionos.fr/?affiliate_id=77097
Merci pour votre contribution .
################## | ! Fin du rapport # UsbFix V6.098 ! |
DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)
▶ Télécharge List_Kill'em et enregistre le sur ton bureau
double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation
coche la case "creer une icone sur le bureau"
une fois terminée , clic sur "terminer" et le programme se lancera seul
choisis la langue puis choisis l'option 1 = Mode Recherche
▶ laisse travailler l'outil
à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.
un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan
▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
▶ Télécharge List_Kill'em et enregistre le sur ton bureau
double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation
coche la case "creer une icone sur le bureau"
une fois terminée , clic sur "terminer" et le programme se lancera seul
choisis la langue puis choisis l'option 1 = Mode Recherche
▶ laisse travailler l'outil
à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.
un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan
▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
List'em by g3n-h@ckm@n 1.2.8.5
User : ns (Administrateurs)
Update on 03/03/2010 by g3n-h@ckm@n ::::: 18.30
Start at: 13:33:36 | 04/03/2010
Contact : https://forums.commentcamarche.net/forum/virus-securite-7
Intel(R) Celeron(R) M processor 1.50GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23
C:\ -> Disque fixe local | 26,27 Go (25,62 Go free) [ACER] | FAT32
D:\ -> Disque fixe local | 26,67 Go (12,17 Go free) | NTFS
E:\ -> Disque CD-ROM
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\SYSTEM32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\LEXPPS.EXE
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
D:\WINDOWS\system32\cmd.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\alg.exe
D:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
D:\WINDOWS\explorer.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\SYSTEM32\notepad.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Windows Live\Toolbar\wltuser.exe
D:\Program Files\List_Kill'em\List_Kill'em.scr
D:\WINDOWS\system32\cmd.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Documents and Settings\ns\Local Settings\Temp\7.tmp\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
swg REG_SZ D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
ctfmon.exe REG_SZ D:\WINDOWS\system32\ctfmon.exe
qgauaam REG_SZ "d:\windows\system32\qgauaam.exe" qgauaam
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
SoftwareHelper REG_SZ D:\Documents and Settings\xavier marchant\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
My Web Search Bar Search Scope Monitor REG_SZ "D:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
EPSON Stylus Photo RX520 Series REG_SZ D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAGE.EXE /P31 "EPSON Stylus Photo RX520 Series" /O6 "USB002" /M "Stylus Photo RX520"
SoundMan REG_SZ SOUNDMAN.EXE
IgfxTray REG_SZ D:\WINDOWS\system32\igfxtray.exe
HotKeysCmds REG_SZ D:\WINDOWS\system32\hkcmd.exe
Persistence REG_SZ D:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
NoDriveAutoRun REG_DWORD 255 (0xff)
HonorAutoRunSetting REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoDriveAutoRun REG_DWORD 255 (0xff)
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell REG_DWORD 1 (0x1)
DefaultDomainName REG_SZ BUREAU-B2FB610D
DefaultUserName REG_SZ ns
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ D:\WINDOWS\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 0 (0x0)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ ns
AltDefaultDomainName REG_SZ BUREAU-B2FB610D
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
D:\Program Files\eMule\emule.exe REG_SZ D:\Program Files\eMule\emule.exe:*:Disabled:eMule
D:\Program Files\LimeWire\LimeWire.exe REG_SZ D:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
D:\Program Files\Philips\Intelligent Agent\Philips Intelligent Agent.exe REG_SZ D:\Program Files\Philips\Intelligent Agent\Philips Intelligent Agent.exe:*:Disabled:Philips Intelligent Agent
D:\Program Files\BitComet\BitComet.exe REG_SZ D:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client
D:\Program Files\BearFlix\bearflix.exe REG_SZ D:\Program Files\BearFlix\bearflix.exe:*:Enabled:BearFlix
D:\Documents and Settings\xavier marchant\Local Settings\Temp\usmt\migwiz.exe REG_SZ D:\Documents and Settings\xavier marchant\Local Settings\Temp\usmt\migwiz.exe:*:Enabled:Assistant Transfert de fichiers et de paramètres
D:\WINDOWS\system32\LEXPPS.EXE REG_SZ D:\WINDOWS\system32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE
D:\Program Files\Messenger\msmsgs.exe REG_SZ D:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
D:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ D:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
D:\Program Files\Crux P2P\Crux P2P.exe REG_SZ D:\Program Files\Crux P2P\Crux P2P.exe:*:Enabled:Crux P2P
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
D:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ D:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
D:\Program Files\ma-config.com\maconfservice.exe REG_SZ D:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
D:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ D:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
D:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ D:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
===============
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\CabBuilder
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0CCA191D-13A6-4E29-B746-314DEE697D83}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{20A60F0D-9AFA-4515-A0FD-83BD84642501}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5C051655-FCD5-4969-9182-770EA5AA5565}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{867E13F2-7F31-44FB-AC97-CD38E0DC46EF}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B8BE5E93-A60C-4D26-A2DC-220313175592}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{BD393C14-72AD-4790-A095-76522973D6B8}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{BD8667B7-38D8-4C77-B580-18C3E146372C}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D0C0F75C-683A-4390-A791-1ACFD5599AB8}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D71F9A27-723E-4B8B-B428-B725E47CBA3E}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E6187999-9FEC-46A1-A20F-F4CA977D5643}
===============
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
==============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0E896FCA-D07E-45FE-901F-6A26FCF59C02}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0EEDB912-C5FA-486F-8334-57288578C627}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2C86C605-6081-D104-96F7-F765C20B22F1}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{500BCA15-57A7-4eaf-8143-8C619470B13D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{97CCDAD1-0D8B-E032-5580-45C52906683C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
===
DNS
===
HKLM\SYSTEM\CCS\Services\Tcpip\..\{CDF79D0D-05F7-4A7D-BA91-280C302B8C64}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{FC321F97-3990-42C1-8E9E-073EFB3528FD}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CDF79D0D-05F7-4A7D-BA91-280C302B8C64}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{CDF79D0D-05F7-4A7D-BA91-280C302B8C64}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{FC321F97-3990-42C1-8E9E-073EFB3528FD}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x3 ( OK = 2 )
SharedAccess : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\$NtServicePackUninstall$\atapi.sys
##
95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,D:\WINDOWS\$NtServicePackUninstall$\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\ServicePackFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,D:\WINDOWS\ServicePackFiles\i386\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\system32\dllcache\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,D:\WINDOWS\system32\dllcache\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\system32\drivers\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,D:\WINDOWS\system32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,D:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
Référence :
==========
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
=======
Drive :
=======
D‚fragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
26,67 Go total, 12,17 Go libre (45%), 19% fragment‚ (fragmentation du fichier 38%)
Vous devriez d‚fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : D:\Documents and Settings\All Users\Application Data\file joy proc deaf
Present !! : D:\Documents and Settings\LocalService\Application Data\agi
Present !! : D:\Program Files\FunWebProducts
Present !! : D:\Program Files\FunWebProducts
Present !! : D:\Program Files\Internet Explorer\msimg32.dll
Present !! : D:\Program Files\InternetGameBox
Present !! : D:\Program Files\MyWebSearch
Present !! : D:\Program Files\P2P_Energy
Present !! : D:\Program Files\PlayMP3z
Present !! : D:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadD500.exe
Present !! : D:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadX800.exe
Present !! : D:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadZ510.exe
Present !! : D:\Program Files\Windows Live\Messenger\Riched20.dll
Present !! : D:\WINDOWS\002911_.tmp
Present !! : D:\WINDOWS\SET3.tmp
Present !! : D:\WINDOWS\SET4.tmp
Present !! : D:\WINDOWS\SET8.tmp
Present !! : D:\WINDOWS\System32\*.dll-UNINST.exe
Present !! : D:\WINDOWS\System32\*_nav*.dat
Present !! : D:\WINDOWS\System32\*_nav.dat
Present !! : D:\WINDOWS\System32\drivers\etc\hosts.msn
Present !! : D:\WINDOWS\System32\f3PSSavr.scr
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\100.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\101.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\102.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\103.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\104.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\105.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\107.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\117.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\118.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\119.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\11B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\126.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\128.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\138.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\139.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\13D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\141.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\148.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\14C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15F.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\160.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\161.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\162.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\163.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\164.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\165.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\166.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\167.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\168.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\169.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\16A.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\16B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\16C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\16F.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\170.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\171.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\172.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\173.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\174.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\175.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\176.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\177.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\178.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\17B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1AF.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1C5.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1C7.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CA.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CB.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CC.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CF.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1D0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1D4.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1E1.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1E3.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1ED.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1EE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1EF.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1F0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1F1.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1F2.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1F3.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\21E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\225.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\227.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\253.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2E4.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2E6.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2EA.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2EB.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2F2.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2F4.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2FE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\302.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\37.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\372.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\37D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\38.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\39.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3AD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3AE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3AF.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3D0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E1.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E2.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E3.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3F.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\40.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\41.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\42.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\43.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\44.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\45.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\46.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\47.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\48.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\49.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4A.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4F.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\50.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\51.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\52.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\53.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\54.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\55.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\56.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\57.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\58.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\59.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5A.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5B4.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5CB.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5CC.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5CD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D3.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D5.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D6.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D7.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D8.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\6.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\71.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\73.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\74.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\75.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\76.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\77.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\78.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\88.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\93.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\9B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\A82.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\BD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\C8.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\C9.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\DB.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\DC.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\DD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\DE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\dw.log
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\E0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\FE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\FF.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\ar500fra.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\final_step.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\FP_PL_MSI_INSTALLER.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\IE8-Setup-Full-XP.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\RtkBtMnt.EXE
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\TFRB.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\instopts.dat
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1089.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1096.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp118A.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp13C7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1451.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp15C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1827.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1CCB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1DA7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1E0D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1E99.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1F59.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2167.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp21E2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp27AE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp28DE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2B11.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2BDD.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2C4.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2CB9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2D97.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2F0C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp301E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp3064.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp30EC.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp323C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp33AC.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp348F.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp382.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp3994.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp3D3C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp3FB4.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4075.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4325.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp441E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4562.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp473.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp47DB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4944.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4A04.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4BC0.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4DF0.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5187.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp52F1.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp54A6.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp59C7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5BD2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5D39.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5E18.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5F28.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp61B9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp62BC.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp64CE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp65EE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp660C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp69BC.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp6D80.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp6E02.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7153.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp736B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7636.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7830.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7BE2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7CDA.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7E27.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7E61.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7F4B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp817A.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp81B5.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp837D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp8486.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp854E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp85B2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp85C9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp90E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp92B2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp932C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp9540.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp96CB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp989C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp9BA8.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp9D7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp9DAD.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA0A9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA1A8.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA3BA.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA4B2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA790.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA9F2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpAF22.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpAF6D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpAF9B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB036.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB182.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB25A.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB28E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB320.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB481.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB72B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB993.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBB13.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBB5A.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBC63.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBD76.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBDA9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC282.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC2CE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC498.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC5A0.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC5A5.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC6DA.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC9AB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpCD3F.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpCEC0.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD0B8.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD415.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD454.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD544.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD7C1.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD859.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDACD.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDB39.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDB81.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDF9D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDFC2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE00D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE0B7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE140.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE162.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE2EB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE394.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE424.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE4EA.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE603.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE6E9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE83C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE886.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE997.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpEA0D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpED41.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpEE59.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF1F4.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF274.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF44.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF484.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF579.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF686.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF6F8.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF712.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF823.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF848.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF8D1.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF943.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF992.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFA47.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFC6.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFD0B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFE0D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFF07.tmp
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor
Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SoftwareHelper
Present !! : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Present !! : "HKCU\software\Fun Web Products"
Present !! : "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}"
Present !! : "HKLM\software\Fun Web Products"
Present !! : "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyWebSearch bar Uninstall"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d}"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall"
Present !! : HKCR\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d}
Present !! : HKCR\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca}
Present !! : HKCR\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
Present !! : HKCR\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3}
Present !! : HKCR\FunWebProducts.DataControl
Present !! : HKCR\FunWebProducts.DataControl.1
Present !! : HKCR\FunWebProducts.HistoryKillerScheduler
Present !! : HKCR\FunWebProducts.HistoryKillerScheduler.1
Present !! : HKCR\FunWebProducts.HistorySwatterControlBar
Present !! : HKCR\FunWebProducts.HistorySwatterControlBar.1
Present !! : HKCR\FunWebProducts.HTMLMenu
Present !! : HKCR\FunWebProducts.HTMLMenu.1
Present !! : HKCR\FunWebProducts.HTMLMenu.2
Present !! : HKCR\FunWebProducts.IECookiesManager
Present !! : HKCR\FunWebProducts.IECookiesManager.1
Present !! : HKCR\FunWebProducts.KillerObjManager
Present !! : HKCR\FunWebProducts.KillerObjManager.1
Present !! : HKCR\FunWebProducts.PopSwatterBarButton
Present !! : HKCR\FunWebProducts.PopSwatterBarButton.1
Present !! : HKCR\FunWebProducts.PopSwatterSettingsControl
Present !! : HKCR\FunWebProducts.PopSwatterSettingsControl.1
Present !! : HKCR\interface\{1093995a-ba37-41d2-836e-091067c4ad17}
Present !! : HKCR\interface\{120927bf-1700-43bc-810f-fab92549b390}
Present !! : HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Present !! : HKCR\interface\{1f52a5fa-a705-4415-b975-88503b291728}
Present !! : HKCR\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a}
Present !! : HKCR\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc}
Present !! : HKCR\interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc}
Present !! : HKCR\interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495}
Present !! : HKCR\interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
Present !! : HKCR\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca}
Present !! : HKCR\interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff}
Present !! : HKCR\interface\{90449521-d834-4703-bb4e-d3aa44042ff8}
Present !! : HKCR\interface\{991AAC62-B100-47CE-8B75-253965244f69}
Present !! : HKCR\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc}
Present !! : HKCR\interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d}
Present !! : HKCR\interface\{cf54be1c-9359-4395-8533-1657cf209cfe}
Present !! : HKCR\interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1}
Present !! : HKCR\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477}
Present !! : HKCR\interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e}
Present !! : HKCR\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8}
Present !! : HKCR\MyWebSearch.ChatSessionPlugin
Present !! : HKCR\MyWebSearch.ChatSessionPlugin.1
Present !! : HKCR\MyWebSearch.HTMLPanel
Present !! : HKCR\MyWebSearch.HTMLPanel.1
Present !! : HKCR\MyWebSearch.OutlookAddin
Present !! : HKCR\MyWebSearch.OutlookAddin.1
Present !! : HKCR\MyWebSearch.PseudoTransparentPlugin
Present !! : HKCR\MyWebSearch.PseudoTransparentPlugin.1
Present !! : HKCR\MyWebSearchToolBar.SettingsPlugin
Present !! : HKCR\MyWebSearchToolBar.SettingsPlugin.1
Present !! : HKCR\MyWebSearchToolBar.ToolbarPlugin
Present !! : HKCR\MyWebSearchToolBar.ToolbarPlugin.1
Present !! : HKCR\screensavercontrol.screensaverinstaller
Present !! : HKCR\screensavercontrol.screensaverinstaller.1
Present !! : HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
Present !! : HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
Present !! : HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}
Present !! : HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}
Present !! : HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
Present !! : HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
Present !! : HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
Present !! : HKCR\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac}
Present !! : HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
Present !! : HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
Present !! : HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
Present !! : HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
Present !! : HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}
Present !! : HKCR\xml.xml
Present !! : HKCR\xml.xml.1
Present !! : HKCU\SOFTWARE\AppDataLow\HavingFunOnline
Present !! : HKCU\SOFTWARE\EoRezo
Present !! : HKCU\SOFTWARE\fcn
Present !! : HKCU\SOFTWARE\FunWebProducts
Present !! : HKCU\Software\livesvc
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d}
Present !! : HKCU\software\MyWebSearch
Present !! : HKLM\SOFTWARE\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
Present !! : HKLM\Software\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
Present !! : HKLM\SOFTW
User : ns (Administrateurs)
Update on 03/03/2010 by g3n-h@ckm@n ::::: 18.30
Start at: 13:33:36 | 04/03/2010
Contact : https://forums.commentcamarche.net/forum/virus-securite-7
Intel(R) Celeron(R) M processor 1.50GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23
C:\ -> Disque fixe local | 26,27 Go (25,62 Go free) [ACER] | FAT32
D:\ -> Disque fixe local | 26,67 Go (12,17 Go free) | NTFS
E:\ -> Disque CD-ROM
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\SYSTEM32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\LEXPPS.EXE
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
D:\WINDOWS\system32\cmd.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\alg.exe
D:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
D:\WINDOWS\explorer.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\SYSTEM32\notepad.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Windows Live\Toolbar\wltuser.exe
D:\Program Files\List_Kill'em\List_Kill'em.scr
D:\WINDOWS\system32\cmd.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Documents and Settings\ns\Local Settings\Temp\7.tmp\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
swg REG_SZ D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
ctfmon.exe REG_SZ D:\WINDOWS\system32\ctfmon.exe
qgauaam REG_SZ "d:\windows\system32\qgauaam.exe" qgauaam
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
SoftwareHelper REG_SZ D:\Documents and Settings\xavier marchant\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
My Web Search Bar Search Scope Monitor REG_SZ "D:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
EPSON Stylus Photo RX520 Series REG_SZ D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAGE.EXE /P31 "EPSON Stylus Photo RX520 Series" /O6 "USB002" /M "Stylus Photo RX520"
SoundMan REG_SZ SOUNDMAN.EXE
IgfxTray REG_SZ D:\WINDOWS\system32\igfxtray.exe
HotKeysCmds REG_SZ D:\WINDOWS\system32\hkcmd.exe
Persistence REG_SZ D:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
NoDriveAutoRun REG_DWORD 255 (0xff)
HonorAutoRunSetting REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoDriveAutoRun REG_DWORD 255 (0xff)
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell REG_DWORD 1 (0x1)
DefaultDomainName REG_SZ BUREAU-B2FB610D
DefaultUserName REG_SZ ns
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ D:\WINDOWS\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 0 (0x0)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ ns
AltDefaultDomainName REG_SZ BUREAU-B2FB610D
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
D:\Program Files\eMule\emule.exe REG_SZ D:\Program Files\eMule\emule.exe:*:Disabled:eMule
D:\Program Files\LimeWire\LimeWire.exe REG_SZ D:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
D:\Program Files\Philips\Intelligent Agent\Philips Intelligent Agent.exe REG_SZ D:\Program Files\Philips\Intelligent Agent\Philips Intelligent Agent.exe:*:Disabled:Philips Intelligent Agent
D:\Program Files\BitComet\BitComet.exe REG_SZ D:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client
D:\Program Files\BearFlix\bearflix.exe REG_SZ D:\Program Files\BearFlix\bearflix.exe:*:Enabled:BearFlix
D:\Documents and Settings\xavier marchant\Local Settings\Temp\usmt\migwiz.exe REG_SZ D:\Documents and Settings\xavier marchant\Local Settings\Temp\usmt\migwiz.exe:*:Enabled:Assistant Transfert de fichiers et de paramètres
D:\WINDOWS\system32\LEXPPS.EXE REG_SZ D:\WINDOWS\system32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE
D:\Program Files\Messenger\msmsgs.exe REG_SZ D:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
D:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ D:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
D:\Program Files\Crux P2P\Crux P2P.exe REG_SZ D:\Program Files\Crux P2P\Crux P2P.exe:*:Enabled:Crux P2P
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
D:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ D:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
D:\Program Files\ma-config.com\maconfservice.exe REG_SZ D:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
D:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ D:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
D:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ D:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ D:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
===============
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\CabBuilder
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0CCA191D-13A6-4E29-B746-314DEE697D83}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{20A60F0D-9AFA-4515-A0FD-83BD84642501}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5C051655-FCD5-4969-9182-770EA5AA5565}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{867E13F2-7F31-44FB-AC97-CD38E0DC46EF}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B8BE5E93-A60C-4D26-A2DC-220313175592}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{BD393C14-72AD-4790-A095-76522973D6B8}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{BD8667B7-38D8-4C77-B580-18C3E146372C}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D0C0F75C-683A-4390-A791-1ACFD5599AB8}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D71F9A27-723E-4B8B-B428-B725E47CBA3E}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E6187999-9FEC-46A1-A20F-F4CA977D5643}
===============
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
==============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0E896FCA-D07E-45FE-901F-6A26FCF59C02}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0EEDB912-C5FA-486F-8334-57288578C627}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2C86C605-6081-D104-96F7-F765C20B22F1}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{500BCA15-57A7-4eaf-8143-8C619470B13D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{97CCDAD1-0D8B-E032-5580-45C52906683C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
===
DNS
===
HKLM\SYSTEM\CCS\Services\Tcpip\..\{CDF79D0D-05F7-4A7D-BA91-280C302B8C64}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{FC321F97-3990-42C1-8E9E-073EFB3528FD}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CDF79D0D-05F7-4A7D-BA91-280C302B8C64}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{CDF79D0D-05F7-4A7D-BA91-280C302B8C64}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{FC321F97-3990-42C1-8E9E-073EFB3528FD}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x3 ( OK = 2 )
SharedAccess : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\$NtServicePackUninstall$\atapi.sys
##
95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,D:\WINDOWS\$NtServicePackUninstall$\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\ServicePackFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,D:\WINDOWS\ServicePackFiles\i386\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\system32\dllcache\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,D:\WINDOWS\system32\dllcache\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\system32\drivers\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,D:\WINDOWS\system32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: D:\Documents and Settings\ns\Local Settings\Temp\7.tmp
## D:\> hashdeep.exe D:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,D:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
Référence :
==========
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
=======
Drive :
=======
D‚fragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
26,67 Go total, 12,17 Go libre (45%), 19% fragment‚ (fragmentation du fichier 38%)
Vous devriez d‚fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : D:\Documents and Settings\All Users\Application Data\file joy proc deaf
Present !! : D:\Documents and Settings\LocalService\Application Data\agi
Present !! : D:\Program Files\FunWebProducts
Present !! : D:\Program Files\FunWebProducts
Present !! : D:\Program Files\Internet Explorer\msimg32.dll
Present !! : D:\Program Files\InternetGameBox
Present !! : D:\Program Files\MyWebSearch
Present !! : D:\Program Files\P2P_Energy
Present !! : D:\Program Files\PlayMP3z
Present !! : D:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadD500.exe
Present !! : D:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadX800.exe
Present !! : D:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadZ510.exe
Present !! : D:\Program Files\Windows Live\Messenger\Riched20.dll
Present !! : D:\WINDOWS\002911_.tmp
Present !! : D:\WINDOWS\SET3.tmp
Present !! : D:\WINDOWS\SET4.tmp
Present !! : D:\WINDOWS\SET8.tmp
Present !! : D:\WINDOWS\System32\*.dll-UNINST.exe
Present !! : D:\WINDOWS\System32\*_nav*.dat
Present !! : D:\WINDOWS\System32\*_nav.dat
Present !! : D:\WINDOWS\System32\drivers\etc\hosts.msn
Present !! : D:\WINDOWS\System32\f3PSSavr.scr
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\100.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\101.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\102.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\103.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\104.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\105.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\107.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\117.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\118.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\119.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\11B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\126.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\128.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\138.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\139.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\13D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\141.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\148.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\14C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\15F.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\160.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\161.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\162.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\163.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\164.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\165.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\166.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\167.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\168.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\169.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\16A.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\16B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\16C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\16F.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\170.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\171.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\172.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\173.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\174.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\175.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\176.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\177.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\178.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\17B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1AF.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1C5.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1C7.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CA.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CB.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CC.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1CF.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1D0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1D4.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1E1.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1E3.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1ED.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1EE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1EF.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1F0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1F1.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1F2.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\1F3.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\21E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\225.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\227.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\253.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2E4.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2E6.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2EA.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2EB.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2F2.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2F4.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\2FE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\302.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\37.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\372.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\37D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\38.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\39.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3AD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3AE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3AF.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3D0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E1.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E2.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3E3.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\3F.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\40.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\41.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\42.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\43.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\44.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\45.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\46.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\47.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\48.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\49.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4A.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4C.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4D.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4E.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\4F.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\50.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\51.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\52.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\53.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\54.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\55.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\56.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\57.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\58.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\59.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5A.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5B4.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5CB.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5CC.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5CD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D3.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D5.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D6.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D7.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\5D8.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\6.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\71.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\73.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\74.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\75.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\76.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\77.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\78.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\88.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\93.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\9B.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\A82.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\BD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\C8.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\C9.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\DB.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\DC.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\DD.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\DE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\dw.log
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\E0.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\FE.tmp
Present !! : D:\Documents and Settings\ns\Local Settings\Temp\FF.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\ar500fra.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\final_step.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\FP_PL_MSI_INSTALLER.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\IE8-Setup-Full-XP.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\RtkBtMnt.EXE
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\TFRB.exe
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\instopts.dat
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1089.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1096.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp118A.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp13C7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1451.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp15C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1827.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1CCB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1DA7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1E0D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1E99.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp1F59.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2167.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp21E2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp27AE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp28DE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2B11.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2BDD.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2C4.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2CB9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2D97.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp2F0C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp301E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp3064.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp30EC.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp323C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp33AC.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp348F.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp382.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp3994.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp3D3C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp3FB4.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4075.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4325.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp441E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4562.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp473.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp47DB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4944.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4A04.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4BC0.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp4DF0.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5187.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp52F1.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp54A6.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp59C7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5BD2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5D39.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5E18.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp5F28.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp61B9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp62BC.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp64CE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp65EE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp660C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp69BC.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp6D80.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp6E02.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7153.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp736B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7636.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7830.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7BE2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7CDA.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7E27.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7E61.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp7F4B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp817A.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp81B5.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp837D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp8486.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp854E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp85B2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp85C9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp90E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp92B2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp932C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp9540.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp96CB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp989C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp9BA8.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp9D7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmp9DAD.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA0A9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA1A8.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA3BA.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA4B2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA790.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpA9F2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpAF22.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpAF6D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpAF9B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB036.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB182.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB25A.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB28E.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB320.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB481.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB72B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpB993.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBB13.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBB5A.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBC63.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBD76.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpBDA9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC282.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC2CE.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC498.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC5A0.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC5A5.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC6DA.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpC9AB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpCD3F.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpCEC0.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD0B8.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD415.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD454.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD544.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD7C1.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpD859.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDACD.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDB39.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDB81.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDF9D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpDFC2.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE00D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE0B7.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE140.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE162.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE2EB.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE394.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE424.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE4EA.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE603.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE6E9.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE83C.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE886.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpE997.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpEA0D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpED41.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpEE59.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF1F4.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF274.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF44.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF484.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF579.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF686.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF6F8.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF712.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF823.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF848.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF8D1.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF943.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpF992.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFA47.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFC6.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFD0B.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFE0D.tmp
Present !! : D:\Documents and Settings\ns\LOCAL Settings\Temp\tmpFF07.tmp
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor
Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SoftwareHelper
Present !! : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Present !! : "HKCU\software\Fun Web Products"
Present !! : "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}"
Present !! : "HKLM\software\Fun Web Products"
Present !! : "HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}"
Present !! : "HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll"
Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyWebSearch bar Uninstall"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d}"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall"
Present !! : HKCR\CLSID\{00a6faf1-072e-44cf-8957-5838f569a31d}
Present !! : HKCR\CLSID\{07b18ea1-a523-4961-b6bb-170de4475cca}
Present !! : HKCR\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
Present !! : HKCR\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3}
Present !! : HKCR\FunWebProducts.DataControl
Present !! : HKCR\FunWebProducts.DataControl.1
Present !! : HKCR\FunWebProducts.HistoryKillerScheduler
Present !! : HKCR\FunWebProducts.HistoryKillerScheduler.1
Present !! : HKCR\FunWebProducts.HistorySwatterControlBar
Present !! : HKCR\FunWebProducts.HistorySwatterControlBar.1
Present !! : HKCR\FunWebProducts.HTMLMenu
Present !! : HKCR\FunWebProducts.HTMLMenu.1
Present !! : HKCR\FunWebProducts.HTMLMenu.2
Present !! : HKCR\FunWebProducts.IECookiesManager
Present !! : HKCR\FunWebProducts.IECookiesManager.1
Present !! : HKCR\FunWebProducts.KillerObjManager
Present !! : HKCR\FunWebProducts.KillerObjManager.1
Present !! : HKCR\FunWebProducts.PopSwatterBarButton
Present !! : HKCR\FunWebProducts.PopSwatterBarButton.1
Present !! : HKCR\FunWebProducts.PopSwatterSettingsControl
Present !! : HKCR\FunWebProducts.PopSwatterSettingsControl.1
Present !! : HKCR\interface\{1093995a-ba37-41d2-836e-091067c4ad17}
Present !! : HKCR\interface\{120927bf-1700-43bc-810f-fab92549b390}
Present !! : HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Present !! : HKCR\interface\{1f52a5fa-a705-4415-b975-88503b291728}
Present !! : HKCR\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a}
Present !! : HKCR\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc}
Present !! : HKCR\interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc}
Present !! : HKCR\interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495}
Present !! : HKCR\interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
Present !! : HKCR\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca}
Present !! : HKCR\interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff}
Present !! : HKCR\interface\{90449521-d834-4703-bb4e-d3aa44042ff8}
Present !! : HKCR\interface\{991AAC62-B100-47CE-8B75-253965244f69}
Present !! : HKCR\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc}
Present !! : HKCR\interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d}
Present !! : HKCR\interface\{cf54be1c-9359-4395-8533-1657cf209cfe}
Present !! : HKCR\interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1}
Present !! : HKCR\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477}
Present !! : HKCR\interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e}
Present !! : HKCR\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8}
Present !! : HKCR\MyWebSearch.ChatSessionPlugin
Present !! : HKCR\MyWebSearch.ChatSessionPlugin.1
Present !! : HKCR\MyWebSearch.HTMLPanel
Present !! : HKCR\MyWebSearch.HTMLPanel.1
Present !! : HKCR\MyWebSearch.OutlookAddin
Present !! : HKCR\MyWebSearch.OutlookAddin.1
Present !! : HKCR\MyWebSearch.PseudoTransparentPlugin
Present !! : HKCR\MyWebSearch.PseudoTransparentPlugin.1
Present !! : HKCR\MyWebSearchToolBar.SettingsPlugin
Present !! : HKCR\MyWebSearchToolBar.SettingsPlugin.1
Present !! : HKCR\MyWebSearchToolBar.ToolbarPlugin
Present !! : HKCR\MyWebSearchToolBar.ToolbarPlugin.1
Present !! : HKCR\screensavercontrol.screensaverinstaller
Present !! : HKCR\screensavercontrol.screensaverinstaller.1
Present !! : HKCR\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
Present !! : HKCR\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
Present !! : HKCR\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}
Present !! : HKCR\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}
Present !! : HKCR\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
Present !! : HKCR\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
Present !! : HKCR\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
Present !! : HKCR\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac}
Present !! : HKCR\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
Present !! : HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
Present !! : HKCR\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
Present !! : HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
Present !! : HKCR\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}
Present !! : HKCR\xml.xml
Present !! : HKCR\xml.xml.1
Present !! : HKCU\SOFTWARE\AppDataLow\HavingFunOnline
Present !! : HKCU\SOFTWARE\EoRezo
Present !! : HKCU\SOFTWARE\fcn
Present !! : HKCU\SOFTWARE\FunWebProducts
Present !! : HKCU\Software\livesvc
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca}
Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d}
Present !! : HKCU\software\MyWebSearch
Present !! : HKLM\SOFTWARE\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
Present !! : HKLM\Software\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
Present !! : HKLM\SOFTWARE\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
Present !! : HKLM\SOFTW