Win32.bactera.worm

emmavin Messages postés 11 Date d'inscription   Statut Membre Dernière intervention   -  
 Utilisateur anonyme -
Je rencontre depuis quelques semaines maintenant un problème récurent sur mon PC . En effet celui-ci a tendance à planter et s'éteindre subitement lors de l'utilisation.
J'ai dans un premier temps vu s'afficher au milieu de mon écran
un rectangle bleu sur lequel était inscrit :
" VIRUS SYSTEM"
"WIN32.BACTERA.WORM"
après cela impossible de lancer le moindre scan sans qu'il ne s'arrête à nouveau . J'ai essayé différents antivirus sans succès.
Il s'avère que toutes mes tentatives ont échoué et ce malgré plusieurs formatages et réinstallations consécutifs, rien n'y fait.

de plus après un moment il ne veut plus redémarrer du tout. je suis obligé de la laisser reposer quelques minutes voir quelques heures.

Je vous remercie tous de votre aide et espère que l'un d'entre vous pourra m'aider à résoudre ce problème.

Merci @+
Configuration: XP pro

10 réponses

  1. aranjuez31 Messages postés 8161 Date d'inscription   Statut Contributeur 354
     
    hello
    on va essayer de faire qque chose bien sur
    ---
    ah un truc au passage pour la qualité de ton introduction
    http://www.technicland.com/malpolitus.swf
    --------
    il faudrait que tu arrives à scanner avec ceci
    ewido (dowload)
    http://www.ewido.net/fr/download/
    et me COLLER le rapport
    -----------
    qu as tu comme autres utilitaires de désinfection ?
    -----------

    telech ceci
    http://telechargement.zebulon.fr/160-patch-francais-pour-hijackthis-1991.html
    mode d emploi
    http://pageperso.aol.fr/balltrap34/Hijenr.gif
    http://pageperso.aol.fr/balltrap34/demohijack.htm
    0
  2. emmavin Messages postés 11 Date d'inscription   Statut Membre Dernière intervention  
     
    Ok,
    je vais essayer dès qu'il me sera possible d'utiliser mon système car je suis en train d'essayer de réinstaller, pas facile, il coupe toujours avant la fin de la procédure.

    c'est une vraie partie de plaisir..!!!!

    dès ma réinstall finie je vais suivre tes recommandations et compte sur toi pour me sortir de cette impasse.

    D' avance merci

    @+
    0
  3. aranjuez31 Messages postés 8161 Date d'inscription   Statut Contributeur 354
     
    B O N J O U R
    ok
    à +
    0
  4. emmavin Messages postés 11 Date d'inscription   Statut Membre Dernière intervention  
     
    j'ai essayé a2 Square, avast, stinger, avg , trend, norton, xsoft,
    et bien d'autres....

    impossible d'aller au bout du scan, il s' éteind .
    0
    1. boulepate
       
      Salut,

      fait ceci:

      télécharge hijackthis:
      http://www.hijackthis.de/downloads/hijackthis_199.zip

      Installe le dans son propre dossier:
      Par exemple C:\hijackthis
      Lance le, clique sur "do a system scan and save logfile"
      Puis copie et colle le rapport ici.

      A++
      0
    2. emmavin > boulepate
       
      Voilà tu trouveras ci-dessous le journal .

      Merci de ton aide

      @+



      Logfile of HijackThis v1.99.1
      Scan saved at 15:19:20, on 04/02/2006
      Platform: Windows XP (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      C:\WINDOWS\System32\wltrysvc.exe
      C:\WINDOWS\System32\bcmwltry.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\ltmoh\Ltmoh.exe
      C:\Program Files\Launch Manager\LaunchAp.exe
      C:\Program Files\Launch Manager\PowerKey.exe
      C:\Program Files\Launch Manager\HotkeyApp.exe
      C:\Program Files\Launch Manager\CtrlVol.exe
      C:\Program Files\Launch Manager\OSDCtrl.exe
      C:\Program Files\Launch Manager\Wbutton.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\WINDOWS\System32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\ewido anti-malware\ewidoguard.exe
      C:\Program Files\ewido anti-malware\ewidoctrl.exe
      C:\Documents and Settings\Emma et Vincent\Local Settings\Temp\Répertoire temporaire 1 pour hijackthis_199.zip\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cegetel.net
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [adiras] adiras.exe
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
      O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
      O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\HotkeyApp.exe
      O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
      O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe
      O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      O4 - Global Startup: BTTray.lnk = ?
      O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
      O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
      O17 - HKLM\System\CCS\Services\Tcpip\..\{2AE23B9F-513E-43C5-ADE0-FA4E242F6388}: NameServer =
      O17 - HKLM\System\CS1\Services\Tcpip\..\{2AE23B9F-513E-43C5-ADE0-FA4E242F6388}: NameServer =
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
      O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
      0
    3. boulepate > emmavin
       
      Salut,

      ton anti-virus s'appelle ..transparent?!
      0
    4. emmavin > emmavin
       
      Oui, c'est normal, je ne l'avais pas encore installé car je venais de rebooter mon systeme.
      Ok pour l'anti-virus mais pour le reste tu as une idée ?
      Pour rappel, impossibilité d'executer le Mode sans échec... s'éteind lors de tous scans...

      Je compte sur toi et d'avance merci.
      0
    5. boulepate > emmavin
       
      Re

      à l'heure ou tu l'as mit il avait l'air propre mais sans anti-virus tu as dû etre infecté, fais ce scan anti-virus en ligne et colle le rapport ici une fois finit

      http://www.kaspersky.com/scanforvirus

      A++
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. emmavin Messages postés 11 Date d'inscription   Statut Membre Dernière intervention  
     
    à 40 % du scan il s'éteind
    0
  7. emmavin Messages postés 11 Date d'inscription   Statut Membre Dernière intervention  
     
    mon problème est le suivant:

    Dès lors que j'essaier d'exécuter un antivirus antispyware
    mon Pc s'éteind systèmatiquement

    je vais faire une tentative avec a2 square c'est le seul qui semble
    aller à son terme.
    0
  8. emmavin Messages postés 11 Date d'inscription   Statut Membre Dernière intervention  
     
    Filename: csrss.exe
    Default path: %winpath%\
    [Note: %winpath% is usually c:\windows or c:\winnt (Win NT4 and 2000) on English systems]
    Clsid:
    Operating systems: Win 98/ME, Win NT4, Win 2000, Win XP, Win 2003

    Software name: W32.Ahlem.A@mm
    Company name:
    Company website:
    Is part of products: W32.Ahlem.A@mm
    Runs as service: No
    Is visible task: No

    Status: 2 - Worm, Virus
    0
    1. Kristopher Messages postés 3752 Statut Contributeur 106
       
      De quoi s'agit-il ?
      0
    2. emmavin Messages postés 11 Date d'inscription   Statut Membre Dernière intervention  
       
      autant pour moi j'ai copier cela par erreur
      0
    3. emmavin
       
      Logfile of HijackThis v1.99.1
      Scan saved at 12:32:35, on 05/02/2006
      Platform: Windows XP (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      C:\Program Files\ewido anti-malware\ewidoctrl.exe
      C:\Program Files\ewido anti-malware\ewidoguard.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\ltmoh\Ltmoh.exe
      C:\Program Files\Launch Manager\LaunchAp.exe
      C:\Program Files\Launch Manager\PowerKey.exe
      C:\Program Files\Launch Manager\HotkeyApp.exe
      C:\Program Files\Launch Manager\CtrlVol.exe
      C:\Program Files\Launch Manager\OSDCtrl.exe
      C:\Program Files\Launch Manager\Wbutton.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\WINDOWS\System32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
      C:\Program Files\a-squared\a2guard.exe
      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\WINDOWS\System32\wuauclt.exe
      C:\WINDOWS\System32\wbem\wmiprvse.exe
      C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
      C:\WINDOWS\System32\wuauclt.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.commentcamarche.net/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Accessibility Toolbar - {11352A67-0178-46B1-8855-D50B2F81C054} - C:\PROGRA~1\WAT_FR1\ACCESS~1.DLL
      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [adiras] adiras.exe
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
      O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
      O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\HotkeyApp.exe
      O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
      O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe
      O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      O4 - Global Startup: BTTray.lnk = ?
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
      O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
      O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
      O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1139097024528
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{2AE23B9F-513E-43C5-ADE0-FA4E242F6388}: NameServer = 217.19.192.132 217.19.192.131
      O17 - HKLM\System\CS1\Services\Tcpip\..\{2AE23B9F-513E-43C5-ADE0-FA4E242F6388}: NameServer = 217.19.192.132 217.19.192.131
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
      0
    4. boulepate > emmavin
       
      Salut,

      je veux bien t'aider mais je ne vois toujours pas ton anti-virus..ç asert à rien de vouloir nettoyer ton pc si tu n'as pas d'anti-virus..et dans la foulée installe un pare-feu pour te proteger du net

      installe en un en voici un gratuit puis remet un rapport HijackThis

      Avast:
      Avast Edition Familiale

      Kerio:
      https://www.01net.com/telecharger/windows/Securite/firewall/fiches/22418.html
      -tutoriel: pour configurer et comprendre Kerio
      http://kerio.probb.fr/

      A++
      0
    5. Kristopher Messages postés 3752 Statut Contributeur 106 > boulepate
       
      Re boulepate :)

      S'il aurait eu l'intelligence de me répondre à la question que je lui avait justement posé :
      " - à part ewido, c'est quoi ta protection ? " (cf. poste < 12 > ) je lui aurait conseillé la même chose :)

      ++
      0
  9. emmavin
     
    voici le rapport d'Analyse d' a2hijackfree

    j'espère que vous y trouverez une solution à mon problème

    Merci à tous

    <?xml version="1.0" encoding="Windows-1252" ?>
    - <a2hijackfreelog>
    <version>1.20</version>
    <datecreated>2006-02-05 13:13</datecreated>
    <language>fr-fr</language>
    <ie_version>6.0.2800.1106</ie_version>
    <os>XP</os>
    <os_version>5.1.2600</os_version>
    <os_csd />
    <programpath>C:\Program Files</programpath>
    <startuppath>C:\Documents and Settings\Emma et Vincent\Menu Démarrer\Programmes\Démarrage</startuppath>
    <systempath>C:\WINDOWS\System32</systempath>
    <winpath>C:\WINDOWS</winpath>
    - <autoruns>
    - <autorun category="registry">
    <name>adiras</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>adiras.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>ATIModeChange</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>Ati2mdxx.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>ATIPTA</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\ATI Technologies\ATI Control Panel\atiptaxx.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>SoundMan</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>SOUNDMAN.EXE</filepath>
    </autorun>
    - <autorun category="registry">
    <name>SynTPLpr</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Synaptics\SynTP\SynTPLpr.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>SynTPEnh</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Synaptics\SynTP\SynTPEnh.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>AGRSMMSG</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>AGRSMMSG.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>LtMoh</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\ltmoh\Ltmoh.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>LaunchAp</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Launch Manager\LaunchAp.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>PowerKey</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Launch Manager\PowerKey.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>LManager</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Launch Manager\HotkeyApp.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>CtrlVol</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Launch Manager\CtrlVol.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>LMgrOSD</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Launch Manager\OSDCtrl.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>Wbutton</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Launch Manager\Wbutton.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>RemoteControl</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\CyberLink\PowerDVD\PDVDServ.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>Google Desktop Search</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Google\Google Desktop Search\GoogleDesktop.exe /startup</filepath>
    </autorun>
    - <autorun category="registry">
    <name>CTFMON.EXE</name>
    <location>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%systempath%\ctfmon.exe</filepath>
    </autorun>
    - <autorun category="registry">
    <name>MSMSGS</name>
    <location>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\Messenger\msmsgs.exe /background</filepath>
    </autorun>
    - <autorun category="registry">
    <name>MsnMsgr</name>
    <location>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\MSN Messenger\MsnMsgr.Exe /background</filepath>
    </autorun>
    - <autorun category="registry">
    <name>a-squared</name>
    <location>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</location>
    <filepath>%programpath%\a-squared\a2guard.exe</filepath>
    </autorun>
    - <autorun category="startupfiles">
    <location>win.ini</location>
    <name>load</name>
    <filepath />
    </autorun>
    - <autorun category="startupfiles">
    <location>win.ini</location>
    <name>run</name>
    <filepath />
    </autorun>
    - <autorun category="startupfiles">
    <location>win.ini</location>
    <name>shell</name>
    <filepath>Explorer.exe</filepath>
    </autorun>
    - <autorun category="startupfiles">
    <location>win.ini</location>
    <name>scrnsave.exe</name>
    <filepath>%systempath%\logon.scr</filepath>
    </autorun>
    - <autorun category="autostartmenu">
    <location>C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\</location>
    <name>DSLMON</name>
    </autorun>
    - <autorun category="autostartmenu">
    <location>C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\</location>
    <name>BTTray</name>
    </autorun>
    - <autorun category="autostartmenu">
    <location>C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\</location>
    <name>Microsoft Office</name>
    </autorun>
    - <autorun category="tricky">
    <name>CTFMON.EXE</name>
    <location>HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Run\</location>
    <filepath>%systempath%\CTFMON.EXE</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Shell</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\</location>
    <filepath>Explorer.exe</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>rundll32.exe advpack.dll,LaunchINFSection %winpath%\INF\mplayer2.inf,PerUserStub.NT</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{2C7339CF-2B09-4501-B3F3-F3508C9228ED}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>%systempath%\system32\regsvr32.exe /s /n /i:/UserInstall %systempath%\system32\themeui.dll</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{44BBA840-CC51-11CF-AAFA-00AA00B6015C}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>%programpath%\Outlook Express\setup50.exe /APP:OE /CALLER:WINNT /user /install</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{44BBA842-CC51-11CF-AAFA-00AA00B6015B}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>rundll32.exe advpack.dll,LaunchINFSection %winpath%\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{5945c046-1e7d-11d1-bc44-00c04fd912be}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>rundll32.exe advpack.dll,LaunchINFSection %winpath%\INF\msmsgs.inf,BLC.Install.PerUser</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{6BF52A52-394A-11d3-B153-00C04F79FAA6}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>rundll32.exe advpack.dll,LaunchINFSection %winpath%\INF\wmp.inf,PerUserStub</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{7790769C-0471-11d2-AF11-00C04FA35D02}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>%programpath%\Outlook Express\setup50.exe /APP:WAB /CALLER:WINNT /user /install</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{89820200-ECBD-11cf-8B85-00AA005B4340}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>regsvr32.exe /s /n /i:U shell32.dll</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{89820200-ECBD-11cf-8B85-00AA005B4383}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>%systempath%\System32\ie4uinit.exe</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>%systempath%\System32\updcrl.exe -e -u %systempath%\System32\verisignpub1.crl</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\</location>
    <filepath>rundll32 iesetup.dll,IEAccessUserInst</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Fichier script VBScript</name>
    <location>HKEY_CLASSES_ROOT\vbsfile\shell\open\command\</location>
    <filepath>%systempath%\System32\WScript.exe %1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Fichier script VBScript</name>
    <location>HKEY_CLASSES_ROOT\vbefile\shell\open\command\</location>
    <filepath>%systempath%\System32\WScript.exe %1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Fichier script JScript</name>
    <location>HKEY_CLASSES_ROOT\jsfile\shell\open\command\</location>
    <filepath>%systempath%\System32\WScript.exe %1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Fichier script JScript</name>
    <location>HKEY_CLASSES_ROOT\jsefile\shell\open\command\</location>
    <filepath>%systempath%\System32\WScript.exe %1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Fichier des paramètres de Windows Script Host</name>
    <location>HKEY_CLASSES_ROOT\wshfile\shell\open\command\</location>
    <filepath>%systempath%\System32\WScript.exe %1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Fichier script Windows</name>
    <location>HKEY_CLASSES_ROOT\wsffile\shell\open\command\</location>
    <filepath>%systempath%\System32\WScript.exe %1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Application</name>
    <location>HKEY_CLASSES_ROOT\exefile\shell\open\command\</location>
    <filepath>%1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Application MS-DOS</name>
    <location>HKEY_CLASSES_ROOT\comfile\shell\open\command\</location>
    <filepath>%1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Fichier de commande MS-DOS</name>
    <location>HKEY_CLASSES_ROOT\batfile\shell\open\command\</location>
    <filepath>%1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Écran de veille</name>
    <location>HKEY_CLASSES_ROOT\scrfile\shell\open\command\</location>
    <filepath>%1 /S</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>Raccourci pour le programme MS-DOS</name>
    <location>HKEY_CLASSES_ROOT\piffile\shell\open\command\</location>
    <filepath>%1 %*</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\</location>
    <filepath>C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>SCRNSAVE.EXE</name>
    <location>HKEY_CURRENT_USER\Control Panel\Desktop\</location>
    <filepath>%systempath%\logon.scr</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>BootExecute</name>
    <location>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\</location>
    <filepath>autocheck autochk *</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>PostBootReminder</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\</location>
    <filepath>%systempath%\system32\SHELL32.dll</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>CDBurn</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\</location>
    <filepath>%systempath%\system32\SHELL32.dll</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>WebCheck</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\</location>
    <filepath>%systempath%\System32\webcheck.dll</filepath>
    </autorun>
    - <autorun category="tricky">
    <name>SysTray</name>
    <location>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\</location>
    <filepath>%systempath%\stobject.dll</filepath>
    </autorun>
    </autoruns>
    - <addons>
    - <addon category="bho">
    <clsid>{AA58ED58-01DD-4d91-8333-CF10577473F7}</clsid>
    <name>Google Toolbar Helper</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\</location>
    <filepath>%programpath%\google\googletoolbar1.dll</filepath>
    </addon>
    - <addon category="shellexecutehooks">
    <clsid>{AEB6717E-7E19-11d0-97EE-00C04FD91972}</clsid>
    <name>URL Exec Hook</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\</location>
    <filepath>shell32.dll</filepath>
    </addon>
    - <addon category="shellexecutehooks">
    <clsid>{54D9498B-CF93-414F-8984-8CE7FDE0D391}</clsid>
    <name>CShellExecuteHookImpl Object</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\</location>
    <filepath>%programpath%\ewido anti-malware\shellhook.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{00022613-0000-0000-C000-000000000046}</clsid>
    <name>Feuille de propriétés du fichier multimédia</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>mmsys.cpl</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{176d6597-26d3-11d1-b350-080036a75b03}</clsid>
    <name>Gestion de scanneur ICM</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>icmui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{1F2E5C40-9550-11CE-99D2-00AA006E086C}</clsid>
    <name>Extension de lenvironnement de sécurité</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>rshx32.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{3EA48300-8CF6-101B-84FB-666CCB9BCD32}</clsid>
    <name>Page des propriétés de OLE DocFile</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>docprop.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{40dd6e20-7c17-11ce-a804-00aa003ca9f6}</clsid>
    <name>Extensions de linterpréteur de commandes pour le partage</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>ntshrui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{41E300E0-78B6-11ce-849B-444553540000}</clsid>
    <name>Extension du Panneau de configuration PlusPack</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\themeui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{42071712-76d4-11d1-8b24-00a0c9068ff3}</clsid>
    <name>Extension Affichage Carte du Panneau de configuration</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>deskadp.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{42071713-76d4-11d1-8b24-00a0c9068ff3}</clsid>
    <name>Extension Affichage Écran du Panneau de configuration</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>deskmon.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{42071714-76d4-11d1-8b24-00a0c9068ff3}</clsid>
    <name>Extension Affichage Panorama du Panneau de configuration</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>deskpan.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{4E40F770-369C-11d0-8922-00A024AB2DBB}</clsid>
    <name>Extension de lenvironnement de sécurité</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>dssec.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}</clsid>
    <name>Page de compatibilité</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>SlayerXP.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{56117100-C0CD-101B-81E2-00AA004AE837}</clsid>
    <name>Gestionnaire de données endommagées de lenvironnement</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>shscrap.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{59099400-57FF-11CE-BD94-0020AF85B590}</clsid>
    <name>Extension copie de disquette</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>diskcopy.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{59be4990-f85c-11ce-aff7-00aa003ca9f6}</clsid>
    <name>Extensions de lenvironnement pour les objets réseau de Microsoft Windows</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>ntlanui2.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{5DB2625A-54DF-11D0-B6C4-0800091AA605}</clsid>
    <name>Gestion décran ICM</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\icmui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{675F097E-4C4D-11D0-B6C1-0800091AA605}</clsid>
    <name>Gestion dimprimante ICM</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\icmui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{764BF0E1-F219-11ce-972D-00AA00A14F56}</clsid>
    <name />
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath />
    </addon>
    - <addon category="shellextension">
    <clsid>{77597368-7b15-11d0-a0c2-080036af3f03}</clsid>
    <name>Extension de lenvironnement dimpression Web</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>printui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7988B573-EC89-11cf-9C00-00AA00A14F56}</clsid>
    <name>Microsoft Disk Quota UI</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>dskquoui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}</clsid>
    <name />
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath />
    </addon>
    - <addon category="shellextension">
    <clsid>{85BBD920-42A0-1069-A2E4-08002B30309D}</clsid>
    <name>Porte-documents</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>syncui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{88895560-9AA2-1069-930E-00AA0030EBC8}</clsid>
    <name>HyperTerminal Icon Ext</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\hticons.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{BD84B380-8CA2-1069-AB1D-08000948F534}</clsid>
    <name>Fonts</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>fontext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{DBCE2480-C732-101B-BE72-BA78E9AD5B27}</clsid>
    <name>Profil ICC</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\icmui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}</clsid>
    <name>Extension de lenvironnement de sécurité</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>rshx32.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}</clsid>
    <name>Extensions de linterpréteur de commandes pour le partage</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>ntshrui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{f92e8c40-3d33-11d2-b1aa-080036a75b03}</clsid>
    <name>Display TroubleShoot CPL Extension</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>deskperf.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7444C717-39BF-11D1-8CD9-00C04FC29D45}</clsid>
    <name>CryptPKO Class</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\cryptext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7444C719-39BF-11D1-8CD9-00C04FC29D45}</clsid>
    <name>CryptSig Class</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\cryptext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7007ACC7-3202-11D1-AAD2-00805FC1270E}</clsid>
    <name>Connexions réseau</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\NETSHELL.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{992CFFA0-F557-101A-88EC-00DD010CCC48}</clsid>
    <name>Connexions réseau</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\NETSHELL.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{E211B736-43FD-11D1-9EFB-0000F8757FCD}</clsid>
    <name>Scanneurs et appareils photo</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>wiashext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}</clsid>
    <name>Scanneurs et appareils photo</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>wiashext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{905667aa-acd6-11d2-8080-00805f6596d2}</clsid>
    <name />
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>wiashext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{3F953603-1008-4f6e-A73A-04AAC7A992F1}</clsid>
    <name>Scanneurs et appareils photo</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>wiashext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{83bbcbf3-b28a-4919-a5aa-73027445d672}</clsid>
    <name />
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>wiashext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{F0152790-D56E-4445-850E-4F3117DB740C}</clsid>
    <name>Remote Sessions CPL Extension</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\remotepg.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{5F327514-6C5E-4d60-8F16-D07FA08A78ED}</clsid>
    <name>Auto Update Property Sheet Extension</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\wuaucpl.cpl</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{60254CA5-953B-11CF-8C96-00AA00B8708C}</clsid>
    <name>Shell Extension For Windows Script Host</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\wshext.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{2206CDB2-19C1-11D1-89E0-00C04FD7A829}</clsid>
    <name>Microsoft OLE DB Service Component Data Links</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%programpath%\Fichiers communs\System\Ole DB\oledb32.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}</clsid>
    <name>Scheduling UI icon handler</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\mstask.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}</clsid>
    <name>Scheduling UI property sheet handler</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\mstask.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{D6277990-4C6A-11CF-8D87-00AA0060F5BF}</clsid>
    <name>Tâches planifiées</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\mstask.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{0DF44EAA-FF21-4412-828E-260A8728E7F1}</clsid>
    <name>Barre des tâches et menu Démarrer</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath />
    </addon>
    - <addon category="shellextension">
    <clsid>{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}</clsid>
    <name>Rechercher</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}</clsid>
    <name>Aide et support</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}</clsid>
    <name>Sécurité de Windows</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}</clsid>
    <name>Exécuter...</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}</clsid>
    <name>Internet</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}</clsid>
    <name>Courrier électronique</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{D20EA4E1-3957-11d2-A40B-0C5020524152}</clsid>
    <name>Polices</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{D20EA4E1-3957-11d2-A40B-0C5020524153}</clsid>
    <name>Outils dadministration</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\system32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}</clsid>
    <name>Audio Media Properties Handler</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shmedia.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}</clsid>
    <name>Video Media Properties Handler</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shmedia.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{E4B29F9D-D390-480b-92FD-7DDB47101D71}</clsid>
    <name>Wav Properties Handler</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shmedia.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{87D62D94-71B3-4b9a-9489-5FE6850DC73E}</clsid>
    <name>Avi Properties Handler</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shmedia.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{A6FD9E45-6E44-43f9-8644-08598F5A74D9}</clsid>
    <name>Midi Properties Handler</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shmedia.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{c5a40261-cd64-4ccf-84cb-c394da41d590}</clsid>
    <name>Video Thumbnail Extractor</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shmedia.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{5E6AB780-7743-11CF-A12B-00AA004AE837}</clsid>
    <name>Barre doutils Internet Microsoft</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{22BF0C20-6DA7-11D0-B373-00A0C9034938}</clsid>
    <name>État du téléchargement</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{91EA3F8B-C99B-11d0-9815-00C04FD91972}</clsid>
    <name>Dossier Bureau étendu</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{6413BA2C-B461-11d1-A18A-080036B11A03}</clsid>
    <name>Dossier du shell augmenté</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{F61FFEC1-754F-11d0-80CA-00AA005B4383}</clsid>
    <name>BandProxy</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7BA4C742-9E81-11CF-99D3-00AA004AE837}</clsid>
    <name>Bande du navigateur Microsoft</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{30D02401-6A81-11d0-8274-00C04FD5AE38}</clsid>
    <name>Bande de recherche</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{32683183-48a0-441b-a342-7c2a440a9478}</clsid>
    <name>Media Band</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{169A0691-8DF9-11d1-A1C4-00C04FD75D13}</clsid>
    <name>Volet intégré de recherche</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{07798131-AF23-11d1-9111-00A0C98BA67D}</clsid>
    <name>Recherche Web</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{AF4F6510-F982-11d0-8595-00AA004CD6D8}</clsid>
    <name>Utilitaire des options de larborescence du Registre</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{01E04581-4EEE-11d0-BFE9-00AA005B4383}</clsid>
    <name>Adresse</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{A08C11D2-A228-11d0-825B-00AA005B4383}</clsid>
    <name>Boîte dentrée de ladresse</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{00BB2763-6A77-11D0-A535-00C04FD7D062}</clsid>
    <name>Saisie semi-automatique Microsoft</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7376D660-C583-11d0-A3A5-00C04FD706EC}</clsid>
    <name>TridentImageExtractor</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{6756A641-DE71-11d0-831B-00AA005B4383}</clsid>
    <name>Liste de saisie semi-automatique MRU</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}</clsid>
    <name>Liste de saisie semi-automatique personnalisée MRU</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7e653215-fa25-46bd-a339-34a2790f3cb7}</clsid>
    <name>Accessible</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{acf35015-526e-4230-9596-becbe19f0ac9}</clsid>
    <name>Barre de progrès auto-ouvrante</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{E0E11A09-5CB8-4B6C-8332-E00720A168F2}</clsid>
    <name>Analyseur de la barre dadresses</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{00BB2764-6A77-11D0-A535-00C04FD7D062}</clsid>
    <name>Liste de saisie semi-automatique de lhistorique Microsoft</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{03C036F1-A186-11D0-824A-00AA005B4383}</clsid>
    <name>Liste de saisie semi-automatique du dossier Shell Microsoft</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{00BB2765-6A77-11D0-A535-00C04FD7D062}</clsid>
    <name>Conteneur de la liste de saisie semi-automatique multiple Microsoft</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{ECD4FC4E-521C-11D0-B792-00A0C90312E1}</clsid>
    <name>Menu Site de bandes</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}</clsid>
    <name>Shell DeskBarApp</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{ECD4FC4C-521C-11D0-B792-00A0C90312E1}</clsid>
    <name>Barre du Bureau</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{ECD4FC4D-521C-11D0-B792-00A0C90312E1}</clsid>
    <name>Shell Rebar BandSite</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{DD313E04-FEFF-11d1-8ECD-0000F87A470C}</clsid>
    <name>Assistance utilisateur</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}</clsid>
    <name>Paramètres du dossier global</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\browseui.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{EFA24E61-B078-11d0-89E4-00C04FC9E26E}</clsid>
    <name>Favorites Band</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{0A89A860-D7B1-11CE-8350-444553540000}</clsid>
    <name>Shell Automation Inproc Service</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}</clsid>
    <name>Shell DocObject Viewer</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}</clsid>
    <name>Microsoft Browser Architecture</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{FBF23B40-E3F0-101B-8488-00AA003E56F8}</clsid>
    <name>Raccourci Internet</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{3C374A40-BAE4-11CF-BF7D-00AA006946EE}</clsid>
    <name>Microsoft Url History Service</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{FF393560-C2A7-11CF-BFF4-444553540000}</clsid>
    <name>Historique</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7BD29E00-76C1-11CF-9DD0-00A0C9034933}</clsid>
    <name>Temporary Internet Files</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7BD29E01-76C1-11CF-9DD0-00A0C9034933}</clsid>
    <name>Temporary Internet Files</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{CFBFAE00-17A6-11D0-99CB-00C04FD64497}</clsid>
    <name>Microsoft Url Search Hook</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}</clsid>
    <name>Image de démarrage de la Suite IE4</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{67EA19A0-CCEF-11d0-8024-00C04FD75D13}</clsid>
    <name>CDF Extension Copy Hook</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{131A6951-7F78-11D0-A979-00C04FD705A2}</clsid>
    <name>ISFBand OC</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{9461b922-3c5a-11d2-bf8b-00c04fb93661}</clsid>
    <name>Search Assistant OC</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}</clsid>
    <name>Internet</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{871C5380-42A0-1069-A2EA-08002B30309D}</clsid>
    <name />
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{EFA24E64-B078-11d0-89E4-00C04FC9E26E}</clsid>
    <name>Explorer Band</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\shdocvw.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}</clsid>
    <name />
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\sendmail.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}</clsid>
    <name />
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\sendmail.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{88C6C381-2E85-11D0-94DE-444553540000}</clsid>
    <name>Dossier ActiveX Cache</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\occache.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{E6FB5E20-DE35-11CF-9C87-00AA005127ED}</clsid>
    <name>WebCheck</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\webcheck.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}</clsid>
    <name>Subscription Mgr</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\webcheck.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{F5175861-2688-11d0-9C5E-00AA00A45957}</clsid>
    <name>Dossier Inscription</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\webcheck.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{08165EA0-E946-11CF-9C87-00AA005127ED}</clsid>
    <name>WebCheckWebCrawler</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\webcheck.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}</clsid>
    <name>WebCheckChannelAgent</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\webcheck.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}</clsid>
    <name>TrayAgent</name>
    <location>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\</location>
    <filepath>%systempath%\System32\webcheck.dll</filepath>
    </addon>
    - <addon category="shellextension">
    <clsid>{7D559C10-9FE9-11d0-93F7-00AA0059CE02}</clsid>
    <name>Code Download Agen
    0
  10. aranjuez31 Messages postés 8161 Date d'inscription   Statut Contributeur 354
     
    bsr
    mince
    ai pas le mode d emploi pour cela
    0
  11. Utilisateur anonyme
     
    Salut

    Ou sont ils detectes?

    a+
    0