Virus violation loi francaise

Fermé
Bisbee - 15 déc. 2011 à 01:35
 Utilisateur anonyme - 10 févr. 2012 à 21:01
Bonjour,




J'ai le meme probleme que beaucoup ici, j'ai tenté d'allumer l'ordi en mode sans échec pour mettre en
route mon malawarebytes. Mais en mode sans échec je ne peux rien déplacer, le curseur est immobile il n'y a aucune
réaction sur mon pavé tactile. Je n'ai pas d'autres sessions sur mon ordi.
Je suis sous Vista.
Merci de.votre aide,

Bisbee
A voir également:

85 réponses

Ils m'indiquent à chaque fois que la protection antivirus est désactivée ce qui est faut avast fonctionne normalement, pareil pour windows defender, donc je dois mettre plusieurs fois par jour "activer".
0
Et après ils me redisent la même chose avec l'anti-spyware
0
Utilisateur anonyme
21 déc. 2011 à 12:14
ok

reprend pre_script ici :

http://dl.dropbox.com/u/21363431/Pre_Script.exe

ouvre-le , colle ca dedans :

________________________________
Tray::

Reboot::

________________________________

au redemarrage est-ce pareil ?
0
Je ne peux pas ouvrir le lien que tu me donnes, ils me disent qu'ils ne trouvent pas le chemin spécifié.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Et ça me dit "Windows ne trouve pas C:\Kill'em\ERUNT.exe"
0
Utilisateur anonyme
21 déc. 2011 à 12:31
ok les modules sont absents

retelcharge pre_scan et refais un scan

http://dl.dropbox.com/u/21363431/Pre_Scan.exe
0
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan | 2.004 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤ XP | Vista | Seven - 32/64 bits ¤¤¤¤¤

~ Mis à jour le 21/12/2011 | 01.30 par g3n-h@ckm@n
~ Informations : http://gen-hackman.forum-pro.fr/t64-historique-de-l-outil
~ Remontées & Feedback : http://gen-hackman.forum-pro.fr/f12-depot-infos-remontees-rogues-visible-par-tous

~ Utilisateur : Camille (Administrateurs) | SID = S-1-5-21-1063571713-2971834971-3172925857-1000
~ Ordinateur : PC-DE-CAMILLE

~ Système d'exploitation : Windows Vista (TM) Home Premium (32 bits) HomePremium Service Pack 2
~ Enregistré sous : Camille
~ Processeur : Intel(R) Core(TM) Duo CPU T2350 @ 1.86GHz
~ Identification : x86 Family 6 Model 14 Stepping 12
Internet Explorer : 7.0.6002.18005
Mozilla Firefox : 8.0.1 (fr)
Pare-feu windows : Actif
Windows Defender : Actif

c:\ -> [Fixed] | [VistaOS] | Total : 76310 Mo | Free : 40660 Mo -> NTFS
d:\ -> [Fixed] | [DATA] | Total : 69310 Mo | Free : 52190 Mo -> NTFS
e:\ -> [Removable] | []
f:\ -> [CDROM] | []

Scan : 12:41:46 | 21/12/2011


¤¤¤¤¤¤¤¤¤¤ | Sessions

~ [HKLM | ProfileList] | S-1-5-21-1063571713-2971834971-3172925857-1000 : ProfileImagePath -> C:\Users\Camille
~ [HKLM | ProfileList] | S-1-5-21-1063571713-2971834971-3172925857-1000 : RefCount -> 4
~ [HKLM | ProfileList] | S-1-5-21-1063571713-2971834971-3172925857-1000 : State -> 0

¤¤¤¤¤¤¤¤¤¤ | Contrôle MD5

[MD5.D07D4C3038F3578FFCE1C0237F2A1253] -- [20/10/2009 | 09:54:08] -- C:\windows\explorer.exe
[MD5.FD8C53FB002217F6F888BCF6F5D7084D] -- [02/11/2006 | 09:47:18] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[MD5.6D06CD98D954FE87FB2DB8108793B399] -- [14/11/2007 | 22:39:00] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[MD5.37440D09DEAE0B672A04DCCF7ABF06BE] -- [11/12/2008 | 10:39:36] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[MD5.BD06F0BF753BC704B653C3A50F89D362] -- [14/11/2007 | 22:38:59] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[MD5.E7156B0B74762D9DE0E66BDCDE06E5FB] -- [11/12/2008 | 10:39:36] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[MD5.FFA764631CB70A30065C12EF8E174F9F] -- [20/08/2008 | 16:45:52] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
[MD5.4F554999D7D5F05DAAEBBA7B5BA1089D] -- [11/12/2008 | 10:39:36] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[MD5.50BA5850147410CDE89C523AD3BC606E] -- [11/12/2008 | 10:39:36] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[MD5.D07D4C3038F3578FFCE1C0237F2A1253] -- [20/10/2009 | 09:54:08] -- C:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[MD5.0E135526E9785D085BCD9AEDE6FBCBF9] -- [20/08/2008 | 16:44:04] -- C:\Windows\System32\Userinit.exe
[MD5.898E7C06A350D4A1A64A9EA264D55452] -- [20/10/2009 | 09:53:31] -- C:\Windows\System32\Winlogon.exe
[MD5.101BA3EA053480BB5D957EF37C06B5ED] -- [20/08/2008 | 16:45:07] -- C:\Windows\System32\Wininit.exe
[MD5.4B555106290BD117334E9A08761C035A] -- [02/11/2006 | 09:48:33] -- C:\Windows\System32\rundll32.exe
[MD5.1F05B78AB91C9075565A9D8A4B880BC4] -- [20/10/2009 | 09:53:20] -- C:\Windows\System32\Drivers\Atapi.sys
[MD5.6B4BFFB9BECD728097024276430DB314] -- [20/10/2009 | 09:52:44] -- C:\Windows\system32\drivers\Cdrom.sys
[MD5.147281C01FCB1DF9252DE2A10D5E7093] -- [20/10/2009 | 09:53:26] -- C:\Windows\System32\Drivers\Volsnap.sys

¤¤¤¤¤¤¤¤¤¤ | Processus en cours

Demarrage : Normal

460 | C:\Windows\System32\smss.exe - SYSTEM - Normal - \SystemRoot\System32\smss.exe - 4
592 | C:\Windows\system32\csrss.exe - SYSTEM - Normal - C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 - 580
644 | C:\Windows\system32\wininit.exe - SYSTEM - High - wininit.exe - 580
656 | C:\Windows\system32\csrss.exe - SYSTEM - Normal - C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 - 636
692 | C:\Windows\system32\services.exe - SYSTEM - Normal - C:\Windows\system32\services.exe - 644
704 | C:\Windows\system32\lsass.exe - SYSTEM - Normal - C:\Windows\system32\lsass.exe - 644
712 | C:\Windows\system32\lsm.exe - SYSTEM - Normal - C:\Windows\system32\lsm.exe - 644
760 | C:\Windows\system32\winlogon.exe - SYSTEM - High - winlogon.exe - 636
900 | C:\Windows\system32\svchost.exe - SYSTEM - Normal - C:\Windows\system32\svchost.exe -k DcomLaunch - 692
972 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k rpcss - 692
1008 | C:\Windows\System32\svchost.exe - SYSTEM - Normal - C:\Windows\System32\svchost.exe -k secsvcs - 692
1112 | C:\Windows\System32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - 692
1144 | C:\Windows\System32\svchost.exe - SYSTEM - Normal - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - 692
1184 | C:\Windows\system32\svchost.exe - SYSTEM - Normal - C:\Windows\system32\svchost.exe -k netsvcs - 692
1356 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k LocalService - 692
1412 | C:\Windows\system32\Ati2evxx.exe - SYSTEM - Normal - Ati2evxx.exe -Client - 1096
1568 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k NetworkService - 692
1876 | C:\Program Files\AVAST Software\Avast\AvastSvc.exe - SYSTEM - Normal - "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" - 692
1892 | C:\Windows\system32\Dwm.exe - Camille - High - "C:\Windows\system32\Dwm.exe" - 1144
380 | C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe - Camille - Normal - "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions - 1924
1492 | C:\Program Files\AVAST Software\Avast\AvastUI.exe - Camille - Normal - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui - 1924
1908 | C:\Windows\ehome\ehtray.exe - Camille - Normal - "C:\Windows\ehome\ehtray.exe" - 1924
2076 | C:\Windows\ehome\ehmsas.exe - Camille - Normal - C:\Windows\ehome\ehmsas.exe -Embedding - 900
2364 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - 692
2516 | C:\Windows\system32\taskeng.exe - Camille - Normal - taskeng.exe {F9CC11A5-2EFB-426D-8517-6827460288ED} - 1184
2888 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k bthsvcs - 692
3216 | C:\Windows\system32\svchost.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted - 692
3304 | C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe - SYSTEM - Normal - "C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe" - 692
3324 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k imgsvc - 692
3484 | C:\Windows\System32\svchost.exe - SYSTEM - Normal - C:\Windows\System32\svchost.exe -k WerSvcGroup - 692
2524 | C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe - Camille - Normal - "C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe" -Embedding - 900
2568 | C:\Windows\system32\svchost.exe - SERVICE LOCAL - Normal - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation - 692
4292 | C:\Users\Camille\Downloads\Pre_Scan.exe - Camille - High - "C:\Users\Camille\Downloads\Pre_Scan.exe" - 1924
2676 | C:\Windows\System32\rundll32.exe - Camille - Normal - C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {3eef301f-b596-4c0b-bd92-013beafce793} -Embedding - 900
5700 | C:\Windows\system32\SearchIndexer.exe - SYSTEM - Normal - C:\Windows\system32\SearchIndexer.exe /Embedding - 692
5820 | C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE - SYSTEM - Normal - "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" - 692
2672 | C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe - SYSTEM - Normal - WLIDSvcM.exe 5820 - 5820
5048 | C:\Windows\system32\SearchProtocolHost.exe - SYSTEM - Idle - "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" - 5700
5916 | C:\Windows\system32\SearchFilterHost.exe - SYSTEM - Idle - "C:\Windows\system32\SearchFilterHost.exe" 0 640 644 652 65536 648 - 5700
3024 | C:\Windows\System32\spoolsv.exe - SYSTEM - Normal - C:\Windows\System32\spoolsv.exe - 692
4424 | C:\Windows\system32\SLsvc.exe - SERVICE RÉSEAU - Normal - C:\Windows\system32\SLsvc.exe - 692
1264 | C:\Windows\system32\cmd.exe - Camille - Normal - cmd /c ""C:\Kill'em\Pv.bat" " - 4292
4860 | C:\Windows\system32\conime.exe - Camille - Normal - C:\Windows\system32\conime.exe - 1264
4668 | C:\Kill'em\Pv.exe - Camille - Normal - C:\Kill'em\pv.exe -o"%i | %f - %u - %p - %l - %r" - 1264

¤¤¤¤¤¤¤¤¤¤ | Démarrage principaux avant suppression

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"RtHDVCpl"=RtHDVCpl.exe
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [09/10/2006|20:43:43]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [25/07/2007|22:27:47]
"ASUSTPE"=C:\Windows\system32\ASUSTPE.exe [25/07/2007|22:28:40]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [23/11/2006|06:27:27]
"ASUS Camera ScreenSaver"=C:\Windows\ASScrProlog.exe [25/07/2007|22:31:04]
"ASUS Screen Saver Protector"=C:\Windows\ASScrPro.exe [25/07/2007|22:31:15]
"PowerForPhone"=C:\Program Files\PowerForPhone\PowerForPhone.exe [25/07/2007|22:32:25]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_USERS\S-1-5-21-1063571713-2971834971-3172925857-1000\Software\Microsoft\Windows\CurrentVersion\Run]
""=
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [10/11/2006|20:35:24]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [20/08/2008|16:44:20]
"Connexion SFR 9props.exe"="C:\Program Files\SFR\Kit\9props.exe" /trayicon
"KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [06/09/2010|09:33:28]

[HKEY_USERS\S-1-5-21-1063571713-2971834971-3172925857-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce]


[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce]


¤¤¤¤¤¤¤¤¤¤ | Autres Démarrages Silencieux


¤

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] | {4F07DA45-8170-4859-9B5F-037EF2970034} -> OA Shell Helper

¤

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar]
"{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}"=

¤

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"ITBar7Layout"=0x13000000000000000000000020000000100000000000000001000000800600005E010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] | {8C7461EF-2B13-11d2-BE35-3078302C2030} -> Component Categories cache daemon

¤

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"=Microsoft Data Link
"{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"=Computers and Devices
"{E7DE9B1A-7533-4556-9484-B26FB486475E}"=
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"=MMC Icon Handler
"{08165EA0-E946-11CF-9C87-00AA005127ED}"=WebCheckWebCrawler
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"=Code Download Agent
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"=WebCheck SyncMgr Handler
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"=Subscription Mgr
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"=WebCheck
"{F5175861-2688-11d0-9C5E-00AA00A45957}"=Subscription Folder
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"=Network Connections
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"=Network Connections
"{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}"=IGD Property Sheet Handler
"{92dbad9f-5025-49b0-9078-2d78f935e341}"=Microsoft Windows Mail Html Preview Handler
"{b9815375-5d7f-4ce2-9245-c9d4da436930}"=Microsoft Windows Mail Html Preview Handler
"{f8b8412b-dea3-4130-b36c-5e8be73106ac}"=Microsoft Windows Mail Html Preview Handler
"{5FA29220-36A1-40f9-89C6-F4B384B7642E}"=Shell Message Handler
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"=Shell DocObject Viewer
"{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}"=Microsoft Browser Architecture
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"=InternetShortcut
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"=Microsoft Url History Service
"{FF393560-C2A7-11CF-BFF4-444553540000}"=History
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"=Temporary Internet Files
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"=Temporary Internet Files
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=Microsoft Url Search Hook
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"=The Internet
"{73CFD649-CD48-4fd8-A272-2070EA56526B}"=IE BandProxy
"{07C45BB1-4A8C-4642-A1F5-237E7215FF66}"=IE Microsoft BrowserBand
"{43886CD5-6529-41c4-A707-7B3C92C05E68}"=IE Navigation Bar
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"=IE Search Band
"{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}"=IE Registry Tree Options Utility
"{3028902F-6374-48b2-8DC6-9725E775B926}"=IE AutoComplete
"{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}"=IE MRU AutoComplete List
"{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}"=IE Custom MRU AutoCompleted List
"{6038EF75-ABFC-4e59-AB6F-12D397F6568D}"=IE Microsoft History AutoComplete List
"{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}"=IE Microsoft Shell Folder AutoComplete List
"{B31C5FAE-961F-415b-BAF0-E697A5178B94}"=IE Microsoft Multiple AutoComplete List Container
"{E6EE9AAC-F76B-4947-8260-A9F136138E11}"=IE Shell Band Site Menu
"{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"=IE Shell Rebar BandSite
"{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}"=IE User Assist
"{4B78D326-D922-44f9-AF2A-07805C2A3560}"=IE Menu Band
"{6CF48EF8-44CD-45d2-8832-A16EA016311B}"=IE IShellFolderBand
"{F2CF5485-4E02-4f68-819C-B92DE9277049}"=&Links
"{1C1EDB47-CE22-4bbb-B608-77B48F83C823}"=IE Fade Task
"{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}"=IE Tracking Shell Menu
"{44C76ECD-F7FA-411c-9929-1B77BA77F524}"=IE Menu Site
"{205D7A97-F16D-4691-86EF-F3075DCCA57D}"=IE Menu Desk Bar
"{871C5380-42A0-1069-A2EA-08002B30309D}"=Internet Name Space
"{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}"=IE RSS Feeder Folder
"{8856f961-340a-11d0-a96b-00c04fd705a2}"=Microsoft Web Browser
"{3050f3d9-98b5-11cf-bb82-00aa00bdce0b}"=MSHTML Document
"{25336920-03f9-11cf-8fd0-00aa00686f13}"=HTML Document
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"=Mail Service
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"=Desktop Shortcut
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"=Web Publishing Wizard
"{add36aa8-751a-4579-a266-d66f5202ccbb}"=Print Ordering via the Web
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"=Shell Publishing Wizard Object
"{176d6597-26d3-11d1-b350-080036a75b03}"=ICM Scanner Management
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"=ICM Monitor Management
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"=ICM Printer Management
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"=ICC Profile
"{b2c761c6-29bc-4f19-9251-e6195265baf1}"=Color Control Panel Applet
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"=Directory Property UI
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"=Directory Context Menu Verbs
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"=Directory Query UI
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"=Shell properties for a DS object
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"=Directory Object Find
"{F020E586-5264-11d1-A532-0000F8757D7E}"=Directory Start/Search Find
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"=Printers Security Page
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"=NTFS Security Page
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"=Shell extensions for sharing
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"=Shell extensions for sharing
"{77597368-7b15-11d0-a0c2-080036af3f03}"=Web Printer Shell Extension
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"=DS Security Page
"{41E300E0-78B6-11ce-849B-444553540000}"=PlusPack CPL Extension
"{74246bfc-4c96-11d0-abef-0020af6b0b7a}"=Device Manager
"{7A979262-40CE-46ff-AEEE-7884AC3B6136}"=Add New Hardware
"{7b81be6a-ce2b-4676-a29e-eb907a5126c5}"=Programs and Features
"{15eae92e-f17a-4431-9f28-805e482dafd4}"=Install New Programs
"{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd}"=Installed Updates
"{ceefea1b-3e29-4ef1-b34c-fec79c4f70af}"=New Shortcut Wizard
"{0BFCF7B7-E7B6-433a-B205-2904FCF040DD}"=New Shortcut Wizard Modal
"{CFCCC7A0-A282-11D1-9082-006008059382}"=Darwin App Publisher
"{3e7efb4c-faf1-453d-89eb-56026875ef90}"=Get Programs Online
"{59099400-57FF-11CE-BD94-0020AF85B590}"=Disk Copy Extension
"{ECF03A32-103D-11d2-854D-006008059367}"=MyDocs Drop Target
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"=MyFolder Properties
"{44f3dab6-4392-4186-bb7b-6282ccb7a9f6}"=MyDocuments menu and properties
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"=Taskbar and Start Menu
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"=Search
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"=Help and Support
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"=Help and Support
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"=Run...
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"=Internet
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"=E-mail
"{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}"=Start Menu OEM Command
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"=Set Program Access and Defaults
"{3080F90D-D7AD-11D9-BD98-0000947B0257}"=Show Desktop
"{3080F90E-D7AD-11D9-BD98-0000947B0257}"=Window Switcher
"{eb124705-128b-40d4-8dd8-d93ed12589a4}"=WPL property store
"{3c2654c6-7372-4f6b-b310-55d6128f49d2}"=Alphabetical Categorizer
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"=Summary Info Thumbnail handler (DOCFILES)
"{708e1662-b832-42a8-bbe1-0a77121e3908}"=Tree property value folder
"{71f96385-ddd6-48d3-a0c1-ae06e8b055fb}"=Explorer Browser
"{b2952b16-0e07-4e5a-b993-58c52cb94cae}"=Search Folders
"{437ff9c0-a07f-4fa0-af80-84b6c6440a16}"=Command Folder
"{90f8c90b-04e0-4e92-a186-e6e9c125d664}"=Property Labels
"{1b24a030-9b20-49bc-97ac-1be4426f9e59}"=ActiveDirectory Folder
"{34449847-FD14-4fc8-A75A-7432F5181EFB}"=ActiveDirectory Folder
"{C8494E42-ACDD-4739-B0FB-217361E4894F}"=Sam Account Folder
"{E29F9716-5C08-4FCD-955A-119FDB5A522D}"=Sam Account Folder
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"=Fonts
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"=Administrative Tools
"{b155bdf8-02f0-451e-9a26-ae317cfd7779}"=nethood delegate folder
"{DFFACDC5-679F-4156-8947-C5C76BC0B67F}"=users files delegate folder
"{ed50fc29-b964-48a9-afb3-15ebb9b97f36}"=printhood delegate folder
"{328B0346-7EAF-4BBE-A479-7CB88A095F5B}"=Layout Folder
"{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}"=Control Panel command object for Start menu
"{E44E5D18-0652-4508-A4E2-8A090067BCB0}"=Default Programs command object for Start menu
"{4336a54d-038b-4685-ab02-99bb52d3fb8b}"=Public Folder
"{00021401-0000-0000-C000-000000000046}"=Shortcut
"{C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9}"=Search Folder
"{0AFCCBA6-BF90-4A4E-8482-0AC960981F5B}"=.fon, .otf, .ttc or .ttf files
"{66742402-F9B9-11D1-A202-0000F81FEDEE}"=.cpl, .dll, .exe, .ocx, .rll or .sys files
"{D34A6CA6-62C2-4C34-8A7C-14709C1AD938}"=Common Places Folder
"{865e5e76-ad83-4dca-a109-50dc2113ce9a}"=Programs Folder and Fast Items
"{21ec2020-3aea-1069-a2dd-08002b30309d}"=Control Panel
"{25585dc7-4da0-438d-ad04-e42c8d2d64b9}"=Client application shell extension
"{6dfd7c5c-2451-11d3-a299-00c04f8ef6af}"=Folder Options
"{a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3}"=Microsoft Windows RTF Preview Handler
"{1531d583-8375-4d3f-b5fb-d23bbd169f22}"=Window TXT Preview Handler
"{97e467b4-98c6-4f19-9588-161b7773d6f6}"=Office Document Property Handler
"{88C6C381-2E85-11D0-94DE-444553540000}"=ActiveX Cache Folder
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"=Microsoft Internet Toolbar
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"=Microsoft BrowserBand
"{056440FD-8568-48e7-A632-72157243B55B}"=Explorer Navigation Bar
"{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980}"=Explorer Travel Band
"{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F}"=Explorer Search Band
"{2C2577C2-63A7-40e3-9B7F-586602617ECB}"=Explorer Query Band
"{21569614-B795-46b1-85F4-E737A8DC09AD}"=Search Band
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"=In-pane search
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"=Registry Tree Options Utility
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"=&Address
"{a542e116-8088-4146-a352-b0d06e7f6af6}"=Address EditBox
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"=BandProxy
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"=Microsoft AutoComplete
"{596742A5-1393-4e13-8765-AE1DF71ACAFB}"=Microsoft Breadcrumb Bar
"{6756A641-DE71-11d0-831B-00AA005B4383}"=MRU AutoComplete List
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"=Custom MRU AutoCompleted List
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"=Microsoft History AutoComplete List
"{03C036F1-A186-11D0-824A-00AA005B4383}"=Microsoft Shell Folder AutoComplete List
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"=Microsoft Multiple AutoComplete List Container
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"=Shell Band Site Menu
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"=Shell DeskBarApp
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"=Shell Rebar BandSite
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"=User Assist
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"=Global Folder Settings
"{fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}"=Search Control
"{4d5c8c2a-d075-11d0-b416-00c04fb90376}"=Microsoft CommBand
"{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}"=File Open Dialog
"{C0B4E2F3-BA21-4773-8DBA-335EC946EB8B}"=File Save Dialog
"{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}"=Shell Icon Handler for Application References
"{e82a2d71-5b2f-43a0-97b8-81be15854de8}"=ShellLink for Application References
"{92337A8C-E11D-11D0-BE48-00C04FC30DF6}"=OlePrn.PrinterURL
"{45670FA8-ED97-4F44-BC93-305082590BFB}"=Microsoft XPS Properties
"{44121072-A222-48f2-A58A-6D9AD51EBBE9}"=Microsoft XPS Thumbnail
"{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}"=View Available Networks
"{13D3C4B8-B179-4ebb-BF62-F704173E7448}"=Windows Contact Preview Handler
"{32714800-2E5F-11d0-8B85-00AA0044F941}"=For &People...
"{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}"=Contacts folder
"{4F58F63F-244B-4c07-B29F-210BE59BE9B4}"=.group shell extension handler
"{8082C5E6-4C27-48ec-A809-B8E1122E8F97}"=.contact shell extension handler
"{16C2C29D-0E5F-45f3-A445-03E03F587B7D}"=group_wab_auto_file
"{CF67796C-F57F-45F8-92FB-AD698826C602}"=contact_wab_auto_file
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"=Crypto PKO Extension
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"=Crypto Sign Extension
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"=Compatibility Property Page
"{F0152790-D56E-4445-850E-4F3117DB740C}"=Remote Sessions CPL Extension
"{4026492f-2f69-46b8-b9bf-5654fc07e423}"=Windows Firewall
"{D555645E-D4F8-4c29-A827-D93C859C4F2A}"=
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"=Extensions Manager Folder
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"=Shell extensions for Windows Script Host
"{fcfeecae-ee1b-4849-ae50-685dcf7717ec}"=Problem Reports and Solutions
"{a304259d-52b8-4526-8b1a-a1d6cecc8243}"=iSCSI Initiator
"{8E908FC9-BECC-40f6-915B-F4CA0E70D03D}"=
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"=Microsoft Agent Character Property Sheet Handler
"{025A5937-A6BE-4686-A844-36FE4BEC8B6D}"=Microsoft Power Options
"{BB06C0E4-D293-4f75-8A90-CB05B6477EEE}"=
"{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921}"=
"{17cd9488-1228-4b2f-88ce-4298e93e0966}"=
"{60632754-c523-4b62-b45c-4172da012619}"=
"{9C60DE1E-E5FC-40f4-A487-460851A8D915}"=
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"=Display Adapter CPL Extension
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"=Display Monitor CPL Extension
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"=Display TroubleShoot CPL Extension
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"=OLE Docfile Property Page
"{11dbb47c-a525-400b-9e80-a54615a090c0}"=Execute Folder
"{90b9bce2-b6db-4fd3-8451-35917ea1081b}"=Search Execute Command
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"=Disk Quota UI
"{BD84B380-8CA2-1069-AB1D-08000948F534}"=Microsoft Windows Font Folder
"{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}"=Microsoft Windows Font File Icon Handler
"{1a184871-359e-4f67-aad9-5b9905d62232}"=Microsoft Windows Font File Context Menu Handler
"{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01}"=Microsoft Windows Font Previewer
"{63da6ec0-2e98-11cf-8d82-444553540000}"=FTP Folders Webview
"{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}"=Compressed (zipped) Folder
"{BD472F60-27FA-11cf-B8B4-444553540000}"=Compressed (zipped) Folder Right Drag Handler
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"=Compressed (zipped) Folder SendTo Target
"{b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af}"=Compressed (zipped) Folder Context Menu
"{ed9d80b9-d157-457b-9192-0e7280313bf0}"=Compressed (zipped) Folder Drop Handler
"{911051fa-c21c-4246-b470-070cd8df6dc4}"=.cab or .zip files
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=.CAB file viewer
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"=Shell extensions for Microsoft Windows Network objects
"{da67b8ad-e81b-4c70-9b91b417b5e33527}"=Windows Search Shell Service
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"=DfsShell.DfsShell Property Sheet
"{BC65FB43-1958-4349-971A-210290480130}"=Network Explorer Property Sheet Handler
"{d3e34b21-9d75-101a-8c3d-00aa001a1652}"=Bitmap Image
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"=Video Media Properties Handler
"{E598560B-28D5-46aa-A14A-8A3BEA34B576}"=Windows Photo Gallery Viewer Video Verbs
"{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}"=Microsoft.ScannersAndCameras
"{0a4286ea-e355-44fb-8086-af3df7645bd9}"=Windows Media Player
"{BB6B2374-3D79-41DB-87F4-896C91846510}"=EMDFileProperties
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"=Audio Media Properties Handler
"{E95A4861-D57A-4be1-AD0F-35267E261739}"=
"{89D83576-6BD1-4c86-9454-BEB04E94C819}"=MAPI Search Namespace Extension
"{7A0F6AB7-ED84-46B6-B47E-02AA159A152B}"=Sync Center Simple Conflict Presenter
"{9D687A4C-1404-41ef-A089-883B6FBECDE6}"=Windows Photo Gallery Viewer Autoplay Handler
"{BE122A0E-4503-11DA-8BDE-F66BAD1E3F3A}"=
"{60fd46de-f830-4894-a628-6fa81bc0190d}"=DropTarget Object for Photo Printing Wizard
"{37efd44d-ef8d-41b1-940d-96973a50e9e0}"=Windows Sidebar Properties
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"=Portable Media Devices
"{00f20eb5-8fd6-4d9d-b75e-36801766c8f1}"=PhotoAcqDropTarget
"{BC48B32F-5910-47F5-8570-5074A8A5636A}"=Sync Results Delegate Folder
"{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}"=Games Folder
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"=Windows Media Player Add to Playlist Context Menu Handler
"{E413D040-6788-4C22-957E-175D1C513A34}"=Sync Center Conflict Delegate Folder
"{67718415-c450-4f3c-bf8a-b487642dc39b}"=Windows Features
"{335a31dd-f04b-4d76-a925-d6b47cf360df}"=
"{91ADC906-6722-4B05-A12B-471ADDCCE132}"=Touch Band
"{7D4734E6-047E-41e2-AEAA-E763B4739DC4}"=Windows Media Player Play as Playlist Context Menu Handler
"{2781761E-28E0-4109-99FE-B9D127C57AFE}"=Windows Defender IOfficeAntiVirus implementation
"{96AE8D84-A250-4520-95A5-A47A7E3C548B}"=
"{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A}"=Windows Photo Gallery Viewer Image Verbs
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"=Windows Media Player Play as Playlist Context Menu Handler
"{4B534112-3AF6-4697-A77C-D62CE9B9E7CF}"=Sync Center Event Properties Extension
"{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C}"=Sync Setup Delegate Folder
"{85BBD920-42A0-1069-A2E4-08002B30309D}"=Briefcase
"{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}"=GameUX.RichGameMediaThumbnail
"{d8559eb9-20c0-410e-beda-7ed416aecc2a}"=Windows Defender
"{576C9E85-1300-4EF5-BF6B-D00509F4EDCD}"=Sync Center Handler Properties Extension
"{5ea4f148-308c-46d7-98a9-49041b1dd468}"=Mobility Center Control Panel
"{289978AC-A101-4341-A817-21EBA7FD046D}"=Sync Center Conflict Folder
"{877ca5ac-cb41-4842-9c69-9136e42d47e2}"=File Backup Index
"{71D99464-3B6B-475C-B241-E15883207529}"=Sync Results Folder
"{B32D3949-ED98-4DBB-B347-17A144969BBA}"=Sync Center Item Properties Extension
"{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}"=Portable Devices Menu
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"=Windows Media Player Burn Audio CD Context Menu Handler
"{2E9E59C0-B437-4981-A647-9C34B9B90891}"=Sync Setup Folder
"{58E3C745-D971-4081-9034-86E34B30836A}"=
"{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}"=Sync Center Folder
"{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1}"=Welcome Center
"{15D633E2-AD00-465b-9EC7-F56B7CDF8E27}"=Tablet PC Input Panel
"{78F3955E-3B90-4184-BD14-5397C15F1EFC}"=
"{F04CC277-03A2-4277-96A9-77967471BDFF}"=Sync Center Conflict Properties Extension
"{53BEDF0B-4E5B-4183-8DC9-B844344FA104}"=Microsoft Windows MAPI Preview Handler
"{6b9228da-9c15-419e-856c-19e768a13bdc}"=Windows gadget DropTarget
"{8E25992B-373E-486E-80E5-BD23AE417E66}"=Sync Center Device Notification Sink
"{35786D3C-B075-49b9-88DD-029876E11C01}"=Portable Devices
"{031EE060-67BC-460d-8847-E4A7C5E45A27}"=Windows Media Player Rich Preview Handler
"{1FA9085F-25A2-489B-85D4-86326EEDCD87}"=Manage Wireless Networks
"{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60}"=RichGameMediaPropertyStore Class
"{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}"=Client Side Cache Namespace Extension
"{8A734961-C4AA-4741-AC1E-791ACEBF5B39}"=Windows Media Player Shop Music Context Menu Handler
"{7A9D77BD-5403-11d2-8785-2E0420524153}"=User Accounts
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"=Video Thumbnail Extractor
"InCDShellExt extension"={CAE3251E-9B15-4810-B268-852AD9792A59}
"InCDUdfPerm extension"={B3D9AEDE-B2C3-406d-A254-6BE07767B08B}
"{2F5AC606-70CF-461C-BFE1-6063670C3484}"=Mouse CPL Extension
"{2F603045-309F-11CF-9774-0020AFD0CFF6}"=Synaptics Control Panel
"{5E2121EE-0300-11D4-8D3B-444553540000}"=Catalyst Context Menu extension
"{738D66C6-0149-4D40-84E4-A7BB2D0CE949}"=Gestionnaire de fichiers Sony Ericsson
"{52B87208-9CCF-42C9-B88E-069281105805}"=Trojan Remover Shell Extension
"{03DAACC5-10BA-4E3E-9D54-2A569F6B4B87}"=Gestionnaire de fichiers Sony Ericsson
"{4EB37360-49E8-11D3-95B5-004033382980}"=ALZip 4.0 Context Menu Shell Extension
"{CA5FEE26-14C1-4B5A-86E9-233FC0EE2682}"=IZArc DragDrop Menu
"{8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5}"=IZArc Shell Context Menu
"{28803F59-3A75-4058-995F-4EE5503B023C}"=Wireless Devices
"{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}"=Enhanced Storage Data Source
"{06A2568A-CED6-4187-BB20-400B8C02BE5A}"=
"{00F33137-EE26-412F-8D71-F84E4C2C6625}"=
"{2BE99FD4-A181-4996-BFA9-58C5FFD11F6C}"=Windows Live Photo Gallery Autoplay Drop Target
"{00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C}"=Windows Live Photo Gallery Viewer Drop Target
"{00F374B7-B390-4884-B372-2FC349F2172B}"=Windows Live Photo Gallery Editor Drop Target
"{00F346CB-35A4-465B-8B8F-65A29DBAB1F6}"=Windows Live Photo Gallery Viewer Drop Target Shim
"{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D}"=Windows Live Photo Gallery Editor Drop Target Shim
"{00F30F90-3E96-453B-AFCD-D71989ECC2C7}"=Windows Live Photo Gallery Autoplay Drop Target Shim
"{472083B0-C522-11CF-8763-00608CC02F24}"=avast
"{4F07DA46-8170-4859-9B5F-037EF2970034}"=Online Armor Shell Extension

¤


¤¤¤¤¤¤¤¤¤¤ | BHO

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] | (Adobe PDF Link Helper) -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [05/09/2011|18:04:56]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] | (Java(tm) Plug-In SSV Helper) -> C:\Program Files\Java\jre6\bin\ssv.dll [10/11/2011|08:01:32]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] | (avast! WebRep) -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [18/12/2011|18:02:20]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] | (Windows Live ID Sign-in Helper) -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [21/09/2010|13:08:38]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] | (Java(tm) Plug-In 2 SSV Helper) -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [10/11/2011|08:01:32]

¤¤¤¤¤¤¤¤¤¤ | ActiveX

[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\ccc-core-static] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] | ->
[HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] | ->

[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] | WMPACCESS -> Microsoft Windows Media Player
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}] | IEACCESS -> Internet Explorer
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] | BRANDING.CAB -> Browser Customizations
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\ccc-core-static] | ->
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}] | JAVAVM -> Java (Sun)
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}] | ->
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] | -> Microsoft Windows Media Player 11.0
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{2A3320D6-C805-4280-B423-B665BDE33D8F}] | M979906 -> Microsoft .NET Framework 1.1 Security Update (KB979906)
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] | Theme Component -> Themes Setup
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}] | MobilePk -> Offline Browsing Pack
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3C3901C5-3455-3E0A-A214-0B093A5070A6}] | .NETFramework -> .NET Framework
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{411EDCF7-755D-414E-A74B-3DCD6583F589}] | S867460 -> Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] | MailNews -> Microsoft Windows Mail 7
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}] | ->
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}] | DirectDrawEx -> DirectDrawEx
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}] | HelpCont -> Internet Explorer Help
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}] | MSVBScript -> Microsoft Windows Script 5.6
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}] | GenSetup -> Internet Explorer Setup Tools
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}] | ExtraPack -> Browsing Enhancements
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}] | Microsoft Windows Media Player -> Microsoft Windows Media Player
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}] | MSN_Auth -> MSN Site Access
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] | WebFolders -> Dossiers Web
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}] | -> Address Book 7
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}] | .NETFramework -> .NET Framework
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}] | IE4_SHELLID -> Windows Desktop Update
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}] | BASEIE40_W2K -> Internet Explorer
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}] | DOTNETFRAMEWORKS ->
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}] | Tridata -> Dynamic HTML Data Binding
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}] | .NETFramework -> .NET Framework
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}] | Fontcore -> Internet Explorer Core Fonts
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}] | .NETFramework -> .NET Framework
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}] | Windows Movie Maker v2.1 ->
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11CF-96B8-444553540000}] | Flash -> Adobe Flash Player
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}] | HTMLHelp -> HTML Help
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}] | ADSI -> Active Directory Service Interface
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{EFCE7BE0-510E-4932-9475-F44CD90DE16A}] | M2572067 -> Microsoft .NET Framework 1.1 Security Update (KB2572067)


[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}] | -> Java Runtime Environment 1.6.0
[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}] | ->
[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}] | -> Java Runtime Environment 1.6.0
[HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}] | -> Java Runtime Environment 1.6.0

¤¤¤¤¤¤¤¤¤¤ | AppPaths

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ACMON.exe] -> C:\Program Files\ASUS\Splendid\ACMON.exe [25/07/2007|22:32:55]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AcroRd32.exe] -> C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe [05/09/2011|18:04:56]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ALZip.exe] ->
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AvastUI.exe] -> C:\Program Files\AVAST Software\Avast\AvastUI.exe [18/12/2011|18:02:20]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ccleaner.exe] -> C:\Program Files\CCleaner\CCleaner.exe [28/11/2011|16:52:58]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe] ->
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:] ->
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\DMEDIA.EXE] -> C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [25/07/2007|22:27:47]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\dvdmaker.exe] -> %ProgramFiles%\Movie Maker\dvdmaker.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\E:] ->
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe] -> C:\PROGRA~1\MICROS~2\Office\EXCEL.EXE [21/03/1999|01:54:56]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\FileMaker Pro.exe] -> C:\Program Files\FileMaker\FileMaker Pro 8.5\FileMaker Pro.exe [20/06/2006|21:00:50]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe] -> C:\Program Files\Mozilla Firefox\firefox.exe [23/09/2008|13:11:33]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\frontpg.exe] -> C:\PROGRA~1\MICROS~2\Office\FRONTPG.EXE [20/03/1999|07:06:38]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\fsquirt.exe] ->
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\gimp-2.6.exe] -> C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe [03/12/2009|19:29:53]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE] -> C:\Program Files\Internet Explorer\IEXPLORE.EXE [20/10/2009|09:53:53]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\inkball.exe] -> %ProgramFiles%\Microsoft Games\inkball\inkball.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\install.exe] ->
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IZArc] -> C:\Program Files\IZArc\IZArc.exe [12/03/2009|12:45:26]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\javaws.exe] -> C:\Program Files\Java\jre6\bin\javaws.exe [29/04/2010|22:12:20]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Journal.exe] -> %ProgramFiles%\Windows Journal\Journal.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\LangSelector.exe] -> C:\Program Files\Windows Live\Installer\LangSelector.exe [10/11/2010|01:09:12]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mbam.exe] -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [26/09/2008|11:31:32]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MovieMaker.exe] -> C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe [10/11/2010|01:28:00]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\moviemk.exe] -> %ProgramFiles%\Movie Maker\moviemk.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mplayer2.exe] -> %ProgramFiles%\Windows Media Player\wmplayer.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mplayerc.exe] -> "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\msimn.exe] -> %ProgramFiles%\Windows Mail\WinMail.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSNMSGR.EXE] -> C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [10/11/2010|01:54:18]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Net4Switch.exe] -> C:\Program Files\ASUS\Net4Switch\Net4Switch.exe [25/07/2007|22:30:42]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\pbrush.exe] -> %SystemRoot%\System32\mspaint.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PictureViewer.exe] -> C:\Program Files\QuickTime\PictureViewer.exe [19/10/2007|19:16:06]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PowerShell.exe] -> %SystemRoot%\system32\WindowsPowerShell\v1.0\PowerShell.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QuickTimePlayer.exe] -> C:\Program Files\QuickTime\QuickTimePlayer.exe [19/10/2007|19:17:52]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\setup.exe] ->
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sidebar.exe] -> "%ProgramFiles%\Windows Sidebar\sidebar.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SnippingTool.exe] -> C:\Windows\System32\SnippingTool.exe [20/10/2009|09:52:58]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\stikynot.exe] -> C:\Windows\System32\stikynot.exe [02/11/2006|13:35:47]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\table30.exe] ->
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\TabTip.exe] -> %CommonProgramFiles%\microsoft shared\ink\TabTip.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wab.exe] -> %ProgramFiles%\Windows Mail\wab.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wabmig.exe] -> %ProgramFiles%\Windows Mail\wabmig.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinCal.exe] -> "%ProgramFiles%\Windows Calendar\wincal.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WindowsLivePhotoViewer.exe] -> C:\Program Files\Windows Live\Photo Gallery\WindowsLivePhotoViewer.exe [10/11/2010|01:28:00]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winflash.exe] -> C:\Program Files\ASUS\WinFlash\Winflash.exe [25/07/2007|22:30:02]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinMail.exe] -> %ProgramFiles%\Windows Mail\WinMail.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe] -> C:\PROGRA~1\MICROS~2\Office\WINWORD.EXE [17/04/1999|06:45:52]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wlarp.exe] -> C:\Program Files\Windows Live\Installer\wlarp.exe [22/09/2010|23:17:00]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wlsettings.exe] -> C:\Program Files\Windows Live\Installer\wlsettings.exe [10/11/2010|01:09:12]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wlstartup.exe] -> C:\Program Files\Windows Live\Installer\wlstartup.exe [10/11/2010|01:09:12]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WLXAlbumDownloadWizard.exe] -> C:\Program Files\Windows Live\Photo Gallery\WLXAlbumDownloadWizard.exe [10/11/2010|01:28:00]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WLXPhotoGallery.exe] -> C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe [10/11/2010|01:28:54]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wmplayer.exe] -> %ProgramFiles%\Windows Media Player\wmplayer.exe
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WORDPAD.EXE] -> "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WRITE.EXE] -> "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\XPSViewer.exe] -> "C:\Windows\System32\XPSViewer\XPSViewer.exe"

¤¤¤¤¤¤¤¤¤¤ | HKCR\Applications

[HKCR\Applications\ehshell.exe\Shell\open\command] | -> "C:\Windows\eHome\ehshell.exe" "%1"
[HKCR\Applications\gimp-2.6.exe\Shell\open\command] | -> "C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe" "%1"
[HKCR\Applications\iexplore.exe\Shell\open\command] | -> "C:\Program Files\Internet Explorer\iexplore.exe" %1
[HKCR\Applications\MovieMaker.exe\Shell\open\command] | -> "C:\Program Files\Windows Live\Photo Gallery\MovieMaker.exe" "%1"
[HKCR\Applications\mplayerc.exe\Shell\open\command] | -> "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" "%1"
[HKCR\Applications\Net4Switch.exe\Shell\open\command] | -> "C:\Program Files\ASUS\Net4Switch\Net4Switch.exe" "%1"
[HKCR\Applications\notepad.exe\Shell\open\command] | -> %SystemRoot%\system32\NOTEPAD.EXE %1
[HKCR\Applications\photoviewer.dll\Shell\open\command] | -> %SystemRoot%\System32\rundll32.exe "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll", ImageView_Fullscreen %1
[HKCR\Applications\PicasaPhotoViewer.exe\Shell\open\command] | -> "C:\Program Files\Google\Picasa3\PicasaPhotoViewer.exe" "%1"
[HKCR\Applications\vlc.exe\Shell\open\command] | -> "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file "%1"
[HKCR\Applications\WinCal.exe\Shell\open\command] | -> "%ProgramFiles%\Windows Calendar\wincal.exe" "%1"
[HKCR\Applications\WINWORD.EXE\Shell\open\command] | -> "C:\Program Files\Microsoft Office\Office\WINWORD.EXE" "%1"
[HKCR\Applications\WLXPhotoViewer.dll\Shell\open\command] | -> "C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe" /LaunchPhotoViewer /v "%1"
[HKCR\Applications\wmplayer.exe\Shell\open\command] | -> "%ProgramFiles%\Windows Media Player\wmplayer.exe" /Open "%L"
[HKCR\Applications\wordpad.exe\Shell\open\command] | -> "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"

¤¤¤¤¤¤¤¤¤¤ | Windows

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=
"LoadAppInit_DLLs"=0

¤¤¤¤¤¤¤¤¤¤ | Winlogon


¤

[HKLM | Winlogon] | Shell : explorer.exe
[HKLM | Winlogon] | AutoRestartShell : 1 -> 0
[HKLM | Winlogon] | userinit : C:\Windows\system32\userinit.exe,
[HKLM | Winlogon] | PowerDownAfterShutdown : 1
[HKLM | Winlogon] | System :
[HKLM | Winlogon] | Taskman :

¤¤¤¤¤¤¤¤¤¤ | Winlogon\Notify


¤¤¤¤¤¤¤¤¤¤ | Associations

[.exe] : exefile
[exefile | command] : "%1" %*
[.com] : comfile
[comfile | command] : "%1" %*
[.reg] : regfile
[regfile | command] : regedit.exe "%1"
[.scr] : scrfile
[scrfile | command] : "%1" /S
[.bat] : batfile
[batfile | command] : "%1" %*
[.cmd] : cmdfile
[cmdfile | command] : "%1" %*
[.pif] : piffile
[piffile | command] : "%1" %*
[.url] : InternetShortcut
[InternetShortcut | command] : rundll32.exe ieframe.dll,OpenURL %l -> rundll32.exe ieframe.dll,OpenURL %l
[Application.Manifest | command] : rundll32.exe dfshim.dll,ShOpenVerbApplication %1
[Application.Reference | command] : rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
[Folder | command] : C:\Windows\explorer.exe

¤

[Firefox | Command] | @ : "C:\Program Files\Mozilla Firefox\Firefox.exe"
[Firefox - Safemode | Command] | @ : "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
[IE | Command] | @ : "C:\Program Files\Internet Explorer\iexplore.exe"
[Applications | IE | Command] | @ : "C:\Program Files\Internet Explorer\iexplore.exe" %1
[Assoc | Applications] | @ : http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s

¤¤¤¤¤¤¤¤¤¤ | Divers

[HKCU | HideDesktopIcons\NewStartPanel] | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> 0
[HKCU | HideDesktopIcons\NewStartPanel] | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} : 1 -> 0
[HKCU | HideDesktopIcons\ClassicStartMenu] | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} : 1 -> 0
[HKCU | HideDesktopIcons\ClassicStartMenu] | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> 0
[HKLM | HideDesktopIcons\ClassicStartMenu] | {9343812e-1c37-4a49-a12e-4b2d810d956b} : 0
[HKLM | HideDesktopIcons\NewStartPanel] | {F02C1A0D-BE21-4350-88B0-7367FC96EF3C} : 0
[HKLM | HideDesktopIcons\NewStartPanel] | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0
[HKLM | HideDesktopIcons\NewStartPanel] | {208D2C60-3AEA-1069-A2D7-08002B30309D} : 0
[HKLM | HideDesktopIcons\NewStartPanel] | {871C5380-42A0-1069-A2EA-08002B30309D} : 0
[HKLM | HideDesktopIcons\NewStartPanel] | {5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0} : 0
[HKLM | HideDesktopIcons\NewStartPanel] | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0
[HKLM | HideDesktopIcons\NewStartPanel] | {9343812e-1c37-4a49-a12e-4b2d810d956b} : 0
[HKLM | Advanced\Folder\Hidden\SHOWALL] | CheckedValue : 1
[HKLM | Explorer\Advanced] | Start_ShowMyMusic : 1
[HKLM | Explorer\Advanced] | Start_ShowMyPics : 1
[HKLM | Explorer\Advanced] | Start_ShowUser : 1
[HKLM | Explorer\Advanced] | Start_ShowMyDocs : 1
[HKLM | Explorer\Advanced] | Start_ShowHelp : 1
[HKLM | Explorer\Advanced] | Start_EnableDragDrop : 1
[HKLM | Explorer\Advanced] | Start_ShowMyComputer : 1
[HKLM | Explorer\Advanced] | Start_ShowSearch : 1
[HKCU | Desktop] | Wallpaper : C:\Users\Camille\AppData\Roaming\Microsoft\Windows Photo Gallery\Papier peint de la Galerie de photos Windows.jpg

¤¤¤¤¤¤¤¤¤¤ | Services

[RPCSS] | Start : 2 : Actif
[Ndisuio] | Start : 3 : Actif
[Profsvc] | Start : 2 : Actif
[PlugPlay] | Start : 2 : Actif
[PEAUTH] | Start : 2 : Actif
[Parvdm] | Start : 2 : Inactif
[nsi] | Start : 2 : Actif
[NLASvc] | Start : 2 : Actif
[MPSsvc] | Start : 2 : Actif
[MMCSS] | Start : 2 : Actif
[luafv] | Start : 2 : Actif
[lltdio] | Start : 2 : Actif
[Iphlpsvc] | Start : 2 : Actif
[IKEEXT] | Start : 2 : Actif
[gpsvc] | Start : 2 : Actif
[lmhosts] | Start : 2 : Actif
[LanmanWorkstation] | Start : 2 : Actif
[LanmanServer] | Start : 2 : Actif
[agp440] | Start : 2 : Inactif
[AudioEndpointBuilder] | Start : 2 : Actif
[Audiosrv] | Start : 2 : Actif
[BFE] | Start : 2 : Actif
[Bits] | Start : 2 : Actif
[CryptSvc] | Start : 2 : Actif
[EapHost] | Start : 2 : Actif
[Wlansvc] | Start : 2 : Actif
[SharedAccess] | Start : 2 : Inactif
[windefend] | Start : 2 : Actif
[wuauserv] | Start : 2 : Actif
[WerSvc] | Start : 2 : Actif
[wscsvc] | Start : 2 : Actif

¤¤¤¤¤¤¤¤¤¤ | Internet Explorer

[HKCU | Main] | Start Page : http://www.google.com/
[HKCU | Main] | Local Page : C:\Windows\system32\blank.htm
[HKCU | Main] | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[HKCU | Main] | Use Custom Search URL : 0

[HKLM | Search] | SearchAssistant : http://www.google.com/ie
[HKLM | Main] | Start Page : http://go.microsoft.com/fwlink/?LinkId=69157
[HKLM | Main] | Local Page : %SystemRoot%\system32\blank.htm -> C:\Windows\system32\blank.htm
[HKLM | Main] | Default_Search_URL : http://go.microsoft.com/fwlink/?LinkId=54896
[HKLM | Main] | Default_Page_URL : http://go.microsoft.com/fwlink/?LinkId=69157
[HKLM | Main] | Search Page : http://go.microsoft.com/fwlink/?LinkId=54896

¤

[HKCU | PhishingFilter] | Enabled : 2
[HKCU | PhishingFilter] | EnabledV8 : 1
[HKCU | Internet settings] | ProxyOverride : *.local
0
J'ai redémarré je n'ai plus l'alerte de sécurité.
MAis mon icône internet n'est toujours pas revenue...
0
J'ai parlé trop vite, la même icône est revenue...
0
Je parle de l'alerte de sécurité.
0
Utilisateur anonyme
22 déc. 2011 à 07:28
hello faut heberger le rapport sur http://pjjoint.malekal.com il est trop long
0
http://pjjoint.malekal.com/files.php?id=20111222_b8y9d6d6r13
0
Utilisateur anonyme
23 déc. 2011 à 10:21
re

fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

Lance Pre_script , une page vierge va s'ouvrir.

selectionne tout le texte en gras ci-dessous, puis (clic droit/copier ou ctrl+c) :
___________________________________________________
Kill::

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=-
[HKLM\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring"=DWORD:00000000

file::
C:\Users\Camille\AppData\Roaming\L84577898.5v1

clean::

Reboot::

___________________________________________________

colle-le ensuite (clic droit/coller ou ctrl+V) dans la page vierge.

puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail

si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer

================================

▶ Télécharge ici : USBFIX sur ton bureau

branche tous tes periphériques USB sans les ouvrir

/!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."


sur l'icône Usbfix située sur ton Bureau.
Sur la page, clique sur le bouton :

▶ choisi l option Suppression

▶ UsbFix scannera ton pc , laisse travailler l outil.

▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

0
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 1.0.2.125 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤ XP | Vista | Seven - 32/64 bits ¤¤¤¤¤

Mise à jour : 12/12/2011 | 15.00 Par g3n-h@ckm@n
Utilisateur : Camille (Administrateurs)
Ordinateur : PC-DE-CAMILLE
Système d'exploitation : Windows Vista (TM) Home Premium (32 bits)
Internet Explorer : 7.0.6002.18005
Mozilla Firefox : 8.0.1 (fr)

Switchs possibles :

processes:: | file:: | folder:: | Registry::
Driver:: | replace:: | DNS:: | Command::
attrib:: | txt:: | Host:: | NsLook::
list:: | IP:: | ADS:: | Kill:: | clean::
Reboot:: | MBR:: | Fixmbr:: | 40:: | Zip::
Tray::

Script : 17:46:17

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

Modification du registre effectuée

¤

Supprimé : C:\Users\Camille\AppData\Roaming\L84577898.5v1

¤


¤¤¤¤¤¤¤¤¤¤ | Nettoyage disque

Nettoyage du disque effectué

¤


explorer.exe -> Processus redémarré

Fin : 17:48:41

¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
0
Qu'entends-tu par "branche tous tes périphériques usb"? Il faut que je mette une clé USB ou imprimante ou je ne sais quoi dans mes trois périphériques USB? parce que je n'ai pas de quoi... je n'ai que mon ordi.
0
Utilisateur anonyme
24 déc. 2011 à 00:13
re

dans ce cas , fais sans
0
Bonjour!

Désolée j'étais en vacances. Je n'ai pas eu accès à internet.
Les news: l'icône internet n'est jamais revenue, et je ne peux lire aucun fichier vidéo (ni DVD neuf, ni divX, ni film de mon disque dur), et cela ni sur windows media player, vlc, media player classic etc...

Merci de ton aide
0
Utilisateur anonyme
5 janv. 2012 à 13:05
salut

touche windows+R , puis tape :

SFC /SCANNOW (espace avant le "/")
0
J'ai mis le scan en route, je suis partie et lorsque je suis revenue il n'y avait plus la fenêtre du scan, et aucun doc récapitulatif. Que fais-je?
0
Utilisateur anonyme
5 janv. 2012 à 18:12
mmmmm....vois si ces deux derniers soucis sont toujours presents apres redemarrage de l ordi
0
C'est ok pour les films, j'entends le son!
Par contre cette chère icône internet est toujours marquée d'une belle croix rouge...
0