Pourriez vous analyser mon rapport hijack svp

camille72 Messages postés 6 Statut Membre -  
camille72 Messages postés 6 Statut Membre -
Bonjour,

Comme beaucoup ici, j'ai un GROS problème avec un spyware, qui a remplacé mon fond d'écran, et m'ouvre plein de fenêtres internet, comme pour m'obliger à télécharger des logiciels, ou à nettoyer mon disque dur! Je me suis renseignée en regardant les forums, et j'ai donc fait un analyse avec Hijack. Pourriez-vous l'analyser svp? Merci d'avance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:20, on 02/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\issch.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\uiscan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2.fr/startpage/adsl/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {174c62de-1dd2-11b2-8dae-a098e99f6568} - C:\WINDOWS\system32\rf2gwu8D.dll (file missing)
O2 - BHO: (no name) - {1a6d4baa-1dd2-11b2-8ceb-cba26927efbf} - C:\WINDOWS\system32\iPbsIyoz.dll (file missing)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O2 - BHO: Her - {FFFFFFFF-F538-4f86-ABAF-E9D94D5C007C} - C:\WINDOWS\system32\marwin32.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [fepajink.exe] C:\WINDOWS\system32\fepajink.exe
O4 - HKLM\..\Run: [wrujghor] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\wrujghor.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Fichiers communs\DisqudurProtection\strpmon.exe" dm=http://disqudurprotection.com ad=http://disqudurprotection.com sd=http://repay.disqudurprotection.com
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-2540935256-2595362651-1665068133-1008\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'Camille')
O4 - HKUS\S-1-5-21-2540935256-2595362651-1665068133-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Camille')
O4 - HKUS\S-1-5-18\..\RunOnce: [STMADSL] control stmadsl.cpl (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [STMADSL] control stmadsl.cpl (User 'Default user')
O4 - S-1-5-21-2540935256-2595362651-1665068133-1008 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Camille')
O4 - S-1-5-21-2540935256-2595362651-1665068133-1008 Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Camille')
O4 - S-1-5-21-2540935256-2595362651-1665068133-1008 User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Camille')
O4 - S-1-5-21-2540935256-2595362651-1665068133-1008 User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Camille')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?e62801b114e541adb2da4a7594308b3e
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?e62801b114e541adb2da4a7594308b3e
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {7EED9A13-A696-46E3-8888-09CDE606B3D1} (CDownloader Object) - http://www-compat.tf1.fr/sony/prog/videoDL.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{11A9C77C-6874-4D99-9DE0-B2F9CE7505AF}: NameServer = 85.255.116.153,85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\..\{14CEFF43-13F6-487C-83B9-1093F958110D}: NameServer = 85.255.116.153,85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\..\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}: NameServer = 85.255.116.153,85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\..\{4887E182-24CB-4C15-907B-E0BA00A8E04A}: NameServer = 85.255.116.153 85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\..\{572BE222-CD40-4F33-8F90-8A14B279382A}: NameServer = 85.255.116.153,85.255.112.20
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{11A9C77C-6874-4D99-9DE0-B2F9CE7505AF}: NameServer = 85.255.116.153,85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.153 85.255.112.20
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
A voir également:

7 réponses

Utilisateur anonyme
 
Bonjour

Comment par désinstaller un anti-virus soit Avast soit Bitdefender, masi pas les deux.

* Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"
- S'il manque des lignes n'y tient pas compte.
- Ferme Internet Explorer avant de cliquer sur Fix checked

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {174c62de-1dd2-11b2-8dae-a098e99f6568} - C:\WINDOWS\system32\rf2gwu8D.dll (file missing)
O2 - BHO: (no name) - {1a6d4baa-1dd2-11b2-8ceb-cba26927efbf} - C:\WINDOWS\system32\iPbsIyoz.dll (file missing)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)

O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O2 - BHO: Her - {FFFFFFFF-F538-4f86-ABAF-E9D94D5C007C} - C:\WINDOWS\system32\marwin32.dl
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\issch.exe" -start
lO4 - HKLM\..\Run: [fepajink.exe] C:\WINDOWS\system32\fepajink.exe
O4 - HKLM\..\Run: [wrujghor] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\wrujghor.dll"

+ toutes les O16

* Télécharge FixWareout sur le bureau
---> https://www.bleepingcomputer.com/download/linux/

Double clic dessus.
Clic sur Next, puis Install, puis assure toi que "Run fixit" est activé puis clic sur Finish.
Le fix va commencer, suis les messages à l'écran.
Il te sera demandé de redémarrer ton ordinateur, fais-le.
Ton système mettra un peu plus de temps au démarrage, c'est normal.
Copie et colle ici le contenu du fichier report.txt qui s'affichera à l'écran aussi présent dans C:\fixwareout\report.txt

* ¤ Fais ce nettoyage: à faire réguliérement

*Télécharge et installe CCleaner (n'installe pas la barre d'outil Yahoo)
---> https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

- Dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis clic en bas sur "chercher des erreurs" une fois terminé, clic sur "reparer les erreurs" et tu auras un message pour sauvegarder ta base de registre tu clic "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
Les sauvegardes que tu aura faites, tu pourras les supprimer si ton ordinateur n'a plus de problémes.

- Relance Ccleaner, vas dans l'onglet "nettoyeur" présent sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"

Si tu as besoin d'aide avec Ccleaner, regarde ce tutoriel :
https://kerio.probb.fr/t242-tuto-ccleaner-v-2

* Télécharge et installe AVG anti-spyware : mets le à jour
Tu fais un scan complet de ton système, dès qu'il a fini.
Si il te trouve des espions,supprime les. Enregistre le rapport et colle le ici stp

AVG anti-spyware : reste gratuit après la période d'essai en français
----> https://www.01net.com/telecharger/

Si tu as besoin d'aide avec Ewido(devenu AVG-antispyware) regarde ce tutoriel:
--> https://kerio.probb.fr/t387-tuto-avg-anti-spyware-anti-spyware

ET

* A² squared : gratuit en français (fait un scan rusé et colle le rapport ici stp)
----> https://www.01net.com/telecharger/

Si tu as besoin d'aide avec A-squared regarde ce tutoriel :
--> https://kerio.probb.fr/t223-tuto-pour-a-squared-free

Ton PC en a bien besoin, fais tout ça on continuera après.
0
camille72
 
Merci pour les premières instructions deja! Alors voici mon raport fix:

Username "Camille" - 02/03/2008 20:13:44 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdrej.exe"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.153 85.255.112.20" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{11A9C77C-6874-4D99-9DE0-B2F9CE7505AF}
"nameserver"="85.255.116.153,85.255.112.20" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{14CEFF43-13F6-487C-83B9-1093F958110D}
"nameserver"="85.255.116.153,85.255.112.20" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}
"nameserver"="85.255.116.153,85.255.112.20" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{4887E182-24CB-4C15-907B-E0BA00A8E04A}
"nameserver"="85.255.116.153" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{572BE222-CD40-4F33-8F90-8A14B279382A}
"nameserver"="85.255.116.153,85.255.112.20" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{14CEFF43-13F6-487C-83B9-1093F958110D}
"DhcpNameServer"="85.255.116.153,85.255.112.20" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{1CEDAE29-FA41-4AE6-BD3D-D3CBBA6A701C}
"DhcpNameServer"="85.255.116.153,85.255.112.20" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{572BE222-CD40-4F33-8F90-8A14B279382A}
"DhcpNameServer"="85.255.116.153,85.255.112.20" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{E94CD3C3-E65D-4892-98BF-03B73E253DF1}
"DhcpNameServer"="85.255.116.153,85.255.112.20" <Value cleared.

Cache de résolution DNS vidé.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Other
C:\WINDOWS\Temp\kdrej.ren 73753 13/06/2007

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"ftutil2"="rundll32.exe ftutil2.dll,SetWriteCacheMode"
"RTHDCPL"="RTHDCPL.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /installquiet /keeploaded /nodetect"
"DMAScheduler"="\"c:\\Program Files\\HP DigitalMedia Archive\\DMAScheduler.exe\""
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"PCDrProfiler"=""
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"Reminder"="\"C:\\Windows\\Creator\\Remind_XP.exe\""
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"DXDllRegExe"="dxdllreg.exe"
"AdslTaskBar"="rundll32.exe stmctrl.dll,TaskBar"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"Sony Ericsson PC Suite"="\"C:\\Program Files\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"
"Salestart(1)"="\"C:\\Program Files\\Fichiers communs\\DisqudurProtection\\strpmon.exe\" dm=http://disqudurprotection.com ad=http://disqudurprotection.com sd=http://repay.disqudurprotection.com"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BitDefender Antiphishing Helper"="\"C:\\Program Files\\BitDefender\\BitDefender 2008\\IEShow.exe\""
"BDAgent"="\"C:\\Program Files\\BitDefender\\BitDefender 2008\\bdagent.exe\""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe\" /background"
"WinButler"="C:\\Documents and Settings\\Camille\\Application Data\\WinButler\\WinButler.exe"
"SfKg6wIPu"="C:\\Documents and Settings\\Camille\\Application Data\\Microsoft\\Windows\\pqkuva.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~

Ensuite j'ai téléchargé CCleaner comme tu m'as dit, sauf que je n'ai pas marqué "erreur" ds la colonne de gauche...j'ai juste "nettoyeur", "registre", "outils" ou "options"...donc je suis un peu bloquée en fait...

Pourrez-tu encore m'aider?
0
Utilisateur anonyme
 
Choisis "Registre".
Puis passe à la suite ;-)
0
camille72 Messages postés 6 Statut Membre
 
C'est encore moi!

Voici mon raport AVG:

---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 22:00:54 02/03/2008

+ Résultat de l'analyse:



HKU\S-1-5-21-2540935256-2595362651-1665068133-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Nettoyé.
HKU\S-1-5-21-2540935256-2595362651-1665068133-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{944864A5-3916-46E2-96A9-A2E84F3F1208} -> Adware.Accoona : Nettoyé.
HKU\S-1-5-21-2540935256-2595362651-1665068133-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1ADBCCE8-CF84-441E-9B38-AFC7A19C06A4} -> Adware.ActivShopper : Nettoyé.
HKU\S-1-5-21-2540935256-2595362651-1665068133-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1ADBCCE8-CF84-441E-9B38-AFC7A19C06A4} -> Adware.ActivShopper : Nettoyé.
C:\Program Files\SpyShredder\SpyShredder0.ss -> Adware.DrAntispy : Nettoyé.
HKU\S-1-5-21-2540935256-2595362651-1665068133-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5AF2622-8C75-4DFB-9693-23AB7686A456} -> Adware.Generic : Nettoyé.
HKU\S-1-5-21-2540935256-2595362651-1665068133-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5AF2622-8C75-4DFB-9693-23AB7686A456} -> Adware.Generic : Nettoyé.
C:\Program Files\p2pnetworks -> Adware.MediaPipe : Nettoyé.
C:\Program Files\p2pnetworks\amp2pl.exe -> Adware.MediaPipe : Nettoyé.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP548\A0057779.exe -> Downloader.Agent.dwc : Nettoyé.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP548\A0057778.exe -> Downloader.Agent.fwr : Nettoyé.
C:\Documents and Settings\Camille\Application Data\WinButler\WinBuninstaller.exe -> Downloader.Agent.gzp : Nettoyé.
C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\CT8N1I05\common[1].js -> Downloader.Agent.zf : Nettoyé.
C:\Documents and Settings\Patrick\Local Settings\Temp\routipqno.exe -> Downloader.Zlob.evr : Nettoyé.
C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\WDIB0DYZ\ParisHilton[1].exe -> Dropper.Agent.cwp : Nettoyé.
C:\WINDOWS\kopmet.dll -> Not-A-Virus.Adware.Vapsup : Nettoyé.
C:\WINDOWS\Downloaded Program Files\UWA7PV_0001_N96M0206NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Nettoyé.
C:\Documents and Settings\Patrick\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\game.class-506f6b50-14948243.class -> Not-A-Virus.Exploit.Java.Gimsh.a : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@247realmedia[2].txt -> TrackingCookie.247realmedia : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@canalplus.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@clubmed.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@cupolaventures.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@karavel.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@himedia.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@netcash.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@www.abcsearch[2].txt -> TrackingCookie.Abcsearch : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@adbrite[1].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@4.adbrite[1].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@adbrite[2].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@clicks.adengage[2].txt -> TrackingCookie.Adengage : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@adtech[2].txt -> TrackingCookie.Adtech : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@adtech[2].txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.11:C:\Documents and Settings\HP_Administrateur\Application Data\Mozilla\Firefox\Profiles\mnia604y.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.12:C:\Documents and Settings\HP_Administrateur\Application Data\Mozilla\Firefox\Profiles\mnia604y.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.13:C:\Documents and Settings\HP_Administrateur\Application Data\Mozilla\Firefox\Profiles\mnia604y.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.14:C:\Documents and Settings\HP_Administrateur\Application Data\Mozilla\Firefox\Profiles\mnia604y.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@advertising[1].txt -> TrackingCookie.Advertising : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@advertising[2].txt -> TrackingCookie.Advertising : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@adviva[1].txt -> TrackingCookie.Adviva : Nettoyé.
C:\Documents and Settings\Camille\Cookies\camille@atdmt[1].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@www.belstat[1].txt -> TrackingCookie.Belstat : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@casalemedia[1].txt -> TrackingCookie.Casalemedia : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@casalemedia[1].txt -> TrackingCookie.Casalemedia : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@clickbank[1].txt -> TrackingCookie.Clickbank : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@cz5.clickzs[2].txt -> TrackingCookie.Clickzs : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@vip.clickzs[1].txt -> TrackingCookie.Clickzs : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@cz11.clickzs[1].txt -> TrackingCookie.Clickzs : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@cz4.clickzs[1].txt -> TrackingCookie.Clickzs : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@cz5.clickzs[2].txt -> TrackingCookie.Clickzs : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@cz7.clickzs[1].txt -> TrackingCookie.Clickzs : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@cz8.clickzs[1].txt -> TrackingCookie.Clickzs : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@commission-junction[2].txt -> TrackingCookie.Commission-junction : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@connextra[2].txt -> TrackingCookie.Connextra : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@dealtime[1].txt -> TrackingCookie.Dealtime : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@stat.dealtime[1].txt -> TrackingCookie.Dealtime : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@dealtime[1].txt -> TrackingCookie.Dealtime : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.8:C:\Documents and Settings\HP_Administrateur\Application Data\Mozilla\Firefox\Profiles\mnia604y.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@enhance[2].txt -> TrackingCookie.Enhance : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@enhance[1].txt -> TrackingCookie.Enhance : Nettoyé.
C:\Documents and Settings\Camille\Cookies\camille@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@fastclick[1].txt -> TrackingCookie.Fastclick : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@fastclick[2].txt -> TrackingCookie.Fastclick : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@findwhat[1].txt -> TrackingCookie.Findwhat : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@goclick[1].txt -> TrackingCookie.Goclick : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@goclick[2].txt -> TrackingCookie.Goclick : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@ehg-playboy.hitbox[1].txt -> TrackingCookie.Hitbox : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@hotlog[1].txt -> TrackingCookie.Hotlog : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@searchportal.information[1].txt -> TrackingCookie.Information : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@server.lon.liveperson[1].txt -> TrackingCookie.Liveperson : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@image.masterstats[1].txt -> TrackingCookie.Masterstats : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@mediaplex[2].txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@stat.onestat[2].txt -> TrackingCookie.Onestat : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@overture[2].txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@perf.overture[1].txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@overture[1].txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@paycounter[1].txt -> TrackingCookie.Paycounter : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@ads.planetactive[1].txt -> TrackingCookie.Planetactive : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@pro-market[1].txt -> TrackingCookie.Pro-market : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@questionmarket[2].txt -> TrackingCookie.Questionmarket : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@questionmarket[2].txt -> TrackingCookie.Questionmarket : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@revenue[2].txt -> TrackingCookie.Revenue : Nettoyé.
C:\Documents and Settings\Camille\Cookies\camille@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Camille\Cookies\camille@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@sexlist[1].txt -> TrackingCookie.Sexlist : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter1.sextracker[1].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter12.sextracker[1].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter13.sextracker[1].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter14.sextracker[1].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter15.sextracker[2].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter16.sextracker[2].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter2.sextracker[2].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter6.sextracker[2].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter7.sextracker[1].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@counter9.sextracker[1].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@sextracker[1].txt -> TrackingCookie.Sextracker : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@smartadserver[2].txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@spylog[2].txt -> TrackingCookie.Spylog : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@tacoda[1].txt -> TrackingCookie.Tacoda : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@tacoda[2].txt -> TrackingCookie.Tacoda : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Nettoyé.
C:\Documents and Settings\Camille\Cookies\camille@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@m.webtrends[2].txt -> TrackingCookie.Webtrends : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@m.webtrends[2].txt -> TrackingCookie.Webtrends : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@yadro[1].txt -> TrackingCookie.Yadro : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@yadro[2].txt -> TrackingCookie.Yadro : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@zedo[1].txt -> TrackingCookie.Zedo : Nettoyé.
C:\Documents and Settings\Patrick\Cookies\patrick@zedo[1].txt -> TrackingCookie.Zedo : Nettoyé.
C:\System Volume Information\_restore{512DF77D-45B5-4AE1-9C2A-EC48B0F584C1}\RP530\A0056131.ocx -> Trojan.Agent.dfy : Nettoyé.


Fin du rapport



0
camille72 Messages postés 6 Statut Membre
 
Et voici la dernière chose que tu m'as demandé, le rapport a-squared:

Version - a-squared Free 3.1
Dernière mise à jour: N/A

Réglages Scan:

Objets: Mémoire, Traces, Cookies, C:\WINDOWS\, C:\Program Files
Scan archives: Marche
Heuristiques: Marche
Scan ADS: Marche

Début du scan: 02/03/2008 21:58:35

c:\program files\akl Détecter: Trace.Directory.AbsoluteKeyLogger
c:\program files\accoona Détecter: Trace.Directory.Accoona
c:\program files\amsys Détecter: Trace.Directory.ActivityMonitor
c:\program files\3721 Détecter: Trace.Directory.CnsMin
c:\program files\3721\assist Détecter: Trace.Directory.CnsMin
c:\program files\fichiers communs\totem shared Détecter: Trace.Directory.ISTbar
c:\program files\akl\akl.dll Détecter: Trace.File.AbsoluteKeyLogger
c:\program files\akl\akl.exe Détecter: Trace.File.AbsoluteKeyLogger
c:\program files\akl\uninstall.exe Détecter: Trace.File.AbsoluteKeyLogger
c:\program files\akl\unsetup.exe Détecter: Trace.File.AbsoluteKeyLogger
c:\program files\accoona\asearchassist.dll Détecter: Trace.File.Accoona Toolbar
c:\windows\fhfmm.exe Détecter: Trace.File.AdBreak.FHFMM
c:\windows\cbinst$.exe Détecter: Trace.File.ADBreak
c:\windows\hcwprn.exe Détecter: Trace.File.ADBreak
c:\windows\kkcomp.dll Détecter: Trace.File.ADBreak
c:\windows\kkcomp.exe Détecter: Trace.File.ADBreak
c:\windows\kvnab$.exe Détecter: Trace.File.ADBreak
c:\windows\kvnab.dll Détecter: Trace.File.ADBreak
c:\windows\kvnab.exe Détecter: Trace.File.ADBreak
c:\windows\liqad.dll Détecter: Trace.File.ADBreak
c:\windows\liqad.exe Détecter: Trace.File.ADBreak
c:\windows\liqui.dll Détecter: Trace.File.ADBreak
c:\windows\liqui.exe Détecter: Trace.File.ADBreak
c:\windows\pbsysie.dll Détecter: Trace.File.ADBreak
c:\windows\settn.dll Détecter: Trace.File.ADBreak
c:\windows\wbecheck.exe Détecter: Trace.File.ADBreak
c:\windows\xadbrk.dll Détecter: Trace.File.ADBreak
c:\windows\xadbrk.exe Détecter: Trace.File.ADBreak
c:\windows\iexplorr23.dll Détecter: Trace.File.AtomWire
c:\program files\3721\helper.dll Détecter: Trace.File.CnsMin
c:\windows\system32\msole32.exe Détecter: Trace.File.SmitFraud
Value: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run --> reminder Détecter: Trace.Registry.FTPAttack
c:\program files\e-zshopper Détecter: Trace.Directory.e-Zshopper
c:\program files\spyaway Détecter: Trace.Directory.SpyAway
c:\program files\spyshredder Détecter: Trace.Directory.SpyShredder
c:\program files\spyaway\stat.bin Détecter: Trace.File.SpyAway
c:\program files\spyaway\uninstall.exe Détecter: Trace.File.SpyAway
c:\program files\spyaway\uninstall.log Détecter: Trace.File.SpyAway
c:\program files\spyshredder\spyshredder.exe Détecter: Trace.File.SpyShredder
c:\program files\spyshredder\spyshredder.lic Détecter: Trace.File.SpyShredder
c:\program files\spyshredder\spyshredder1.ss Détecter: Trace.File.SpyShredder
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@adserver.aol[2].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@adserver[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@cgi-bin[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@commentcamarche[2].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@count.rbc[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@indextools[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@metriweb[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@specificclick[2].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@tripod[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\Camille\Cookies\camille@bs.serving-sys[2].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\Camille\Cookies\camille@commentcamarche[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\Camille\Cookies\camille@weborama[1].txt Détecter: Trace.TrackingCookie
C:\Program Files\SpyAway\uninstall.exe Détecter: Heuristic.Dialer.Vendor

Scanné

Fichiers: 47337
Traces: 386461
Cookies: 565
Processus: 64

Trouver

Fichiers: 1
Traces: 41
Cookies: 12
Processus: 0
Clés de Registre: 0

Fin du Scan: 02/03/2008 22:20:47
Temps du Scan: 0:22:12

C:\Program Files\SpyAway\uninstall.exe Quarantaine Heuristic.Dialer.Vendor
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@adserver.aol[2].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@adserver[1].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@cgi-bin[1].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@commentcamarche[2].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@count.rbc[1].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@indextools[1].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@metriweb[1].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@specificclick[2].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\HP_Administrateur\Cookies\hp_administrateur@tripod[1].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\Camille\Cookies\camille@bs.serving-sys[2].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\Camille\Cookies\camille@commentcamarche[1].txt Quarantaine Trace.TrackingCookie
C:\Documents and Settings\Camille\Cookies\camille@weborama[1].txt Quarantaine Trace.TrackingCookie
c:\program files\spyshredder\spyshredder.exe Quarantaine Trace.File.SpyShredder
c:\program files\spyshredder\spyshredder.lic Quarantaine Trace.File.SpyShredder
c:\program files\spyshredder\spyshredder1.ss Quarantaine Trace.File.SpyShredder
c:\program files\spyaway\stat.bin Quarantaine Trace.File.SpyAway
c:\program files\spyaway\uninstall.exe Quarantaine Trace.File.SpyAway
c:\program files\spyaway\uninstall.log Quarantaine Trace.File.SpyAway
c:\program files\spyshredder Quarantaine Trace.Directory.SpyShredder
c:\program files\spyaway Quarantaine Trace.Directory.SpyAway
c:\program files\e-zshopper Quarantaine Trace.Directory.e-Zshopper
Value: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run --> reminder Quarantaine Trace.Registry.FTPAttack
c:\windows\system32\msole32.exe Quarantaine Trace.File.SmitFraud
c:\program files\3721\helper.dll Quarantaine Trace.File.CnsMin
c:\windows\iexplorr23.dll Quarantaine Trace.File.AtomWire
c:\windows\cbinst$.exe Quarantaine Trace.File.ADBreak
c:\windows\hcwprn.exe Quarantaine Trace.File.ADBreak
c:\windows\kkcomp.dll Quarantaine Trace.File.ADBreak
c:\windows\kkcomp.exe Quarantaine Trace.File.ADBreak
c:\windows\kvnab$.exe Quarantaine Trace.File.ADBreak
c:\windows\kvnab.dll Quarantaine Trace.File.ADBreak
c:\windows\kvnab.exe Quarantaine Trace.File.ADBreak
c:\windows\liqad.dll Quarantaine Trace.File.ADBreak
c:\windows\liqad.exe Quarantaine Trace.File.ADBreak
c:\windows\liqui.dll Quarantaine Trace.File.ADBreak
c:\windows\liqui.exe Quarantaine Trace.File.ADBreak
c:\windows\pbsysie.dll Quarantaine Trace.File.ADBreak
c:\windows\settn.dll Quarantaine Trace.File.ADBreak
c:\windows\wbecheck.exe Quarantaine Trace.File.ADBreak
c:\windows\xadbrk.dll Quarantaine Trace.File.ADBreak
c:\windows\xadbrk.exe Quarantaine Trace.File.ADBreak
c:\windows\fhfmm.exe Quarantaine Trace.File.AdBreak.FHFMM
c:\program files\accoona\asearchassist.dll Quarantaine Trace.File.Accoona Toolbar
c:\program files\akl\akl.dll Quarantaine Trace.File.AbsoluteKeyLogger
c:\program files\akl\akl.exe Quarantaine Trace.File.AbsoluteKeyLogger
c:\program files\akl\uninstall.exe Quarantaine Trace.File.AbsoluteKeyLogger
c:\program files\akl\unsetup.exe Quarantaine Trace.File.AbsoluteKeyLogger
c:\program files\fichiers communs\totem shared Quarantaine Trace.Directory.ISTbar
c:\program files\3721 Quarantaine Trace.Directory.CnsMin
c:\program files\3721\assist Quarantaine Trace.Directory.CnsMin
c:\program files\amsys Quarantaine Trace.Directory.ActivityMonitor
c:\program files\accoona Quarantaine Trace.Directory.Accoona
c:\program files\akl Quarantaine Trace.Directory.AbsoluteKeyLogger

Quarantaine

Fichiers: 1
Traces: 41
Cookies: 12
0
Utilisateur anonyme
 
C'est pas triste !

As-tu utilisé l'option "nettoyeur", "nettoyeur" de CCleaner ? Pense à l'utiliser plusieurs fois par semaine.

Ensuite à faire dans l'ordre :

1. Télécharge ComboFix
---> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Ferme ton navigateur web avant d'exécuter ce programme
Double-clic dessus et appuye sur "1" pour continuer
Attends quelques minutes..
Un rapport va s'ouvrir enregistre son contenu, puis copie et colle le ici stp
Tu peux jeter le programme dès que c'est fait.

2. Fais ce scan anti-virus en ligne avec Internet Explorer, dès qu'il a terminé, colle le rapport ici. Tout est expliqué sur le lien ci-dessous
-------> https://kerio.probb.fr/t673-bitdefender-antivirus-en-ligne
0
camille72
 
Bonjour!
Voici mon raport combo fix:

ComboFix 08-03-03.6 - Camille 2008-03-03 9:56:13.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.485 [GMT 1:00]
Endroit: C:\Documents and Settings\Camille\Local Settings\Temporary Internet Files\Content.IE5\MJA1O9OB\ComboFix[1].exe
* Création d'un nouveau point de restauration
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft\Network\Downloader\qmgr0.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft\Network\Downloader\qmgr1.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ActivationCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ProductCode
C:\Documents and Settings\Camille\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\Camille\Application Data\WinAntiVirus Pro 2007\avtasks.dat
C:\Documents and Settings\Camille\Application Data\WinAntiVirus Pro 2007\CookieList.dat
C:\Documents and Settings\Camille\Application Data\WinAntiVirus Pro 2007\history.db
C:\Documents and Settings\Camille\Application Data\WinAntiVirus Pro 2007\Logs\update.log
C:\Documents and Settings\Camille\Application Data\WinAntiVirus Pro 2007\Logs\wa7Support.log
C:\Documents and Settings\Camille\Application Data\WinAntiVirus Pro 2007\Logs\winav.log
C:\Documents and Settings\Camille\Application Data\WinAntiVirus Pro 2007\PGE.dat
C:\Documents and Settings\Camille\err.log
C:\Documents and Settings\Camille\ResErrors.log
C:\Documents and Settings\Patrick\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\Patrick\Application Data\WinAntiVirus Pro 2007\history.db
C:\Documents and Settings\Patrick\Application Data\WinAntiVirus Pro 2007\Logs\update.log
C:\Documents and Settings\Patrick\Application Data\WinAntiVirus Pro 2007\Logs\wa7Support.log
C:\Documents and Settings\Patrick\Application Data\WinAntiVirus Pro 2007\Logs\winav.log
C:\Documents and Settings\Patrick\Application Data\WinAntiVirus Pro 2007\PGE.dat
C:\Documents and Settings\Patrick\err.log
C:\Documents and Settings\Patrick\ResErrors.log
C:\Program Files\Fichiers communs\winantivirus pro 2007
C:\Program Files\Fichiers communs\winantivirus pro 2007\err.log
C:\Program Files\Fichiers communs\winantivirus pro 2007\mfc71.dll
C:\Program Files\Fichiers communs\winantivirus pro 2007\msvcp71.dll
C:\Program Files\Fichiers communs\winantivirus pro 2007\msvcr71.dll
C:\Program Files\video activex access
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\aconti.exe
C:\WINDOWS\aconti.ini
C:\WINDOWS\aconti.sdb
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\adbar.dll
C:\WINDOWS\daxtime.dll
C:\WINDOWS\default.htm
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\adult.txt
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\finance.txt
C:\WINDOWS\system32\lt.res
C:\WINDOWS\system32\other.txt
C:\WINDOWS\system32\pharma.txt
C:\WINDOWS\system32\sft.res
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
D:\Autorun.inf

----- BITS: Possible sites infectés -----

hxxp://thenetworkcom.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_NJC30


((((((((((((((((((((((((((((( Fichiers créés 2008-02-03 to 2008-03-03 ))))))))))))))))))))))))))))))))))))
.

2008-03-02 21:56 . 2008-03-03 09:55 <REP> d-------- C:\Program Files\a-squared Free
2008-03-02 20:47 . 2008-03-02 20:47 <REP> d-------- C:\Documents and Settings\Camille\Application Data\Grisoft
2008-03-02 20:46 . 2008-03-02 20:46 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
2008-03-02 20:46 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-02 20:22 . 2008-03-02 20:22 <REP> d-------- C:\Program Files\CCleaner
2008-03-02 20:13 . 2008-03-02 20:18 <REP> d-------- C:\fixwareout
2008-03-02 16:13 . 2008-03-02 16:13 1,167 --a------ C:\WINDOWS\mozver.dat
2008-03-02 15:02 . 2008-03-02 15:02 <REP> d-------- C:\Documents and Settings\Patrick\Application Data\BitDefender
2008-03-02 13:52 . 2008-03-02 13:52 <REP> d-------- C:\Documents and Settings\Camille\Application Data\BitDefender
2008-03-02 13:04 . 2008-03-02 13:04 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-03-02 12:44 . 2008-03-02 12:44 <REP> d-------- C:\Program Files\Trend Micro
2008-03-02 12:21 . 2008-03-03 10:02 121 --a------ C:\WINDOWS\bdagent.INI
2008-03-02 12:19 . 2008-03-02 12:19 <REP> d-------- C:\Program Files\BitDefender
2008-03-02 12:19 . 2008-03-02 12:19 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\Bitdefender
2008-03-02 12:19 . 2008-03-02 12:20 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender
2008-03-02 12:18 . 2008-03-02 12:19 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-03-02 11:48 . 2008-03-02 11:48 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-03-01 20:29 . 2008-03-01 20:29 <REP> d-------- C:\Program Files\Windows Defender
2008-03-01 14:29 . 2008-03-01 14:29 <REP> d-------- C:\Program Files\Lavasoft
2008-03-01 14:29 . 2008-03-01 14:30 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2008-03-01 13:32 . 2008-03-02 20:16 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-01 12:51 . 2008-03-01 12:51 89,107 --a------ C:\WINDOWS\system32\mgmrwmrv.exe
2008-03-01 12:51 . 2008-03-01 12:51 4 --a------ C:\WINDOWS\system32\winfrun32.bin
2008-02-26 09:33 . 2008-02-26 09:33 <REP> d-------- C:\Documents and Settings\Camille\Application Data\disqudurprotection
2008-02-25 23:41 . 2008-02-25 23:41 <REP> d-------- C:\Documents and Settings\Patrick\Application Data\disqudurprotection
2008-02-25 22:39 . 2008-02-25 22:39 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\disqudurprotection
2008-02-25 22:33 . 2008-03-01 18:13 <REP> d-------- C:\Program Files\Fichiers communs\DisqudurProtection
2008-02-25 22:33 . 2008-02-29 10:02 <REP> d-------- C:\Program Files\DisqudurProtection
2008-02-25 22:33 . 2008-02-25 22:33 <REP> dr------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SalesMon
2008-02-25 22:33 . 2008-02-25 22:33 <REP> dr------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\disqudurprotection
2008-02-25 22:32 . 2008-02-25 22:31 260,632 --a------ C:\Documents and Settings\HP_Administrateur\Application Data\setup_fr[1].exe
2008-02-25 22:29 . 2008-03-02 11:32 <REP> d-------- C:\Program Files\IKEA HomePlanner
2008-02-25 22:28 . 2008-03-02 11:32 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-20 12:29 . 2008-03-01 10:28 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\AdobeUM
2008-02-17 14:50 . 2008-02-17 14:50 167,936 --a------ C:\WINDOWS\system32\drivers\Njc30.sys
2008-02-17 14:50 . 2008-02-17 14:50 54,272 --a------ C:\ukbdtg.exe
2008-02-17 14:50 . 2008-02-17 14:50 29 --a------ C:\WINDOWS\system32\iifeffio.tmp
2008-02-17 14:50 . 2008-02-17 14:50 2 --a------ C:\-664524276
2008-02-17 14:46 . 2007-06-13 14:22 1,078,482 --a------ C:\WINDOWS\fgtwhml.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-02 18:07 7,026 ----a-w C:\Documents and Settings\Camille\Application Data\wklnhst.dat
2008-03-02 12:07 --------- d-----w C:\Program Files\Google
2008-03-02 12:07 --------- d-----w C:\Program Files\Fichiers communs\Labtec
2008-03-02 10:41 --------- d-----w C:\Program Files\Yahoo!
2008-03-02 10:40 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-03-02 10:40 --------- d-----w C:\Program Files\Windows Live
2008-03-02 10:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-02 10:39 --------- d-----w C:\Documents and Settings\Camille\Application Data\Samsung
2008-03-02 10:38 --------- d-----w C:\Program Files\Samsung
2008-03-02 10:38 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-03-02 10:33 --------- d-----w C:\Program Files\Labtec
2008-03-02 10:31 --------- d-----w C:\Program Files\DivX
2008-03-02 10:30 --------- d-----w C:\Program Files\eMule
2008-03-01 17:03 --------- d-----w C:\Documents and Settings\Camille\Application Data\HP
2008-03-01 12:38 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2008-02-20 14:51 22,342 ----a-w C:\Documents and Settings\HP_Administrateur\Application Data\wklnhst.dat
2008-01-28 12:33 --------- d-----w C:\Documents and Settings\Camille\Application Data\WinButler
2008-01-20 14:59 --------- d-----w C:\Program Files\Intel
2008-01-18 14:06 --------- d-----w C:\Program Files\muvee Technologies
2008-01-18 14:06 --------- d-----w C:\Program Files\Fichiers communs\muvee Technologies
2008-01-18 14:05 --------- d-----w C:\Program Files\RichVideoCodec
2007-06-04 17:37 550 ----a-w C:\Documents and Settings\Patrick\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}

[HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
[HKEY_CLASSES_ROOT\BitDefender Toolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 12:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 19:34 64512]
"ftutil2"="ftutil2.dll" [2004-06-07 13:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-22 00:56 16261632 C:\WINDOWS\RTHDCPL.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-21 01:06 7622656]
"nwiz"="nwiz.exe" [2006-06-21 01:06 1519616 C:\WINDOWS\system32\nwiz.exe]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 08:05 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 21:14 237568]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 21:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"DXDllRegExe"="dxdllreg.exe" []
"AdslTaskBar"="stmctrl.dll" [2004-06-04 14:03 151552 C:\WINDOWS\system32\stmctrl.dll]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 15:17 159744]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 15:46 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-03-02 12:24 360448]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 22:50 221184]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"STMADSL"="control stmadsl.cpl" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Services en ligne\\Tele2\\t2ch6.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 17:29]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2004-06-04 14:03]
R3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2004-06-04 14:03]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 12:00]
S3 Navcar;Navman In-car Navigator USB Driver Service;C:\WINDOWS\system32\DRIVERS\Navcar.sys [2006-12-13 22:25]
S3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe [2004-08-10 12:00]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 16:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 16:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 16:59]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 08:42]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 08:42]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 08:42]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 08:42]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 08:42]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-03 10:07:19
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

Balayage des fichiers cachés ...

Scan terminé avec succès
Les fichiers cachés: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-03 10:09:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-03 09:09:45
.
2008-02-15 02:00:46 --- E O F ---

La je suis en train de faire le scan en ligne...
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
camille72
 
Voici le résultat du scan online

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\Downloaded Program Files\\messengerstatsclient.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\Downloaded Program Files\\GAME_UNO1.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\Downloaded Program Files\\solitaireshowdown.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\Downloaded Program Files\\CONFLICT.1\\SolitaireShowdown.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\Downloaded Program Files\\MessengerStatsPAClient.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\Downloaded Program Files\\MsnPUpld.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\system32\\CDDBControl.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\system32\\CDDBUI.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Fichiers communs\\LogiShrd\\LComMgr\\AIMPlugn.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Fichiers communs\\LogiShrd\\LComMgr\\DevMngr.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Fichiers communs\\LogiShrd\\MV\\fltrinst.exe"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Fichiers communs\\LogiShrd\\SrvLnch\\SrvLnch.exe"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\Downloaded Program Files\\videoDL.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.exe"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\iPodService.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\da.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\de.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\en.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\es.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\fi.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\fr.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\it.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\ja.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\ko.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\nb.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\nl.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\ru.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\sv.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\zh_CN.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\iPod\\bin\\iPodService.Resources\\zh_TW.lproj\\iPodServiceLocalized.dll"=dword:80000000

[HKEY_CLASSES_ROOT\.mve]
@="muvee.Document"

[HKEY_CLASSES_ROOT\.xlm]
@="ExcelViewer.Macrosheet"

[HKEY_CLASSES_ROOT\.xlw]
@="ExcelViewer.Workspace"

[HKEY_CLASSES_ROOT\DefaultIcon]

[HKEY_CLASSES_ROOT\FMObex.Semc.FMObjectProperties=]

[HKEY_CLASSES_ROOT\FMObexServer.Sony]

[HKEY_CLASSES_ROOT\ObexAuthenticationServiceDll.Sony]

[HKEY_CLASSES_ROOT\ObexOperationDll.Sony]

[HKEY_CLASSES_ROOT\s]

[HKEY_CLASSES_ROOT\SysmonLogManager.Snapin]

[HKEY_CLASSES_ROOT\WMPCD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\OpenWithProgids]
"RealPlayer.3GPP2.10"=hex(0):
"QuickTime.3g2"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\OpenWithList]
"a"="RealPlay.exe"
"MRUList"="ba"
"b"="iexplore.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\OpenWithProgids]
"RealPlayer.3GPP_AMR.10"=hex(0):
"QuickTime.3gp"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr\OpenWithProgids]
"RealPlayer.AMR.10"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.awb]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.awb\OpenWithProgids]
"RealPlayer.AMR_WB.10"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\OpenWithProgids]
"RealPlayer.DIVX.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpf\OpenWithList]
"a"="IKEA Home Planner.exe"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itms]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itms\OpenWithProgids]
"iTunes.itms"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itpc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itpc\OpenWithProgids]
"iTunes.itpc"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\OpenWithProgids]
"iTunes.m4a"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4e]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4e\OpenWithProgids]
"RealPlayer.MP4.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\OpenWithProgids]
"iTunes.m4p"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp1]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp1\OpenWithProgids]
"RealPlayer.MP1.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\OpenWithProgids]
"RealPlayer.MP4.6"=hex(0):
"QuickTime.mp4"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpga]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpga\OpenWithProgids]
"RealPlayer.MPGA.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcast]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcast\OpenWithProgids]
"iTunes.pcast"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\OpenWithProgids]
"iTunes.pls"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra\OpenWithProgids]
"RealPlayer.RA.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram\OpenWithProgids]
"RealPlayer.RAM.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rax]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rax\OpenWithProgids]
"RealPlayer.RAX.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rjs]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rjt]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm\OpenWithProgids]
"RealPlayer.RM.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmj]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmj\OpenWithProgids]
"RealJukebox.RMJ.1"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmm]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmm\OpenWithProgids]
"RealPlayer.RAM.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmp]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmp\OpenWithProgids]
"RealJukebox.RMP.1"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rms]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rms\OpenWithProgids]
"RealPlayer.RMS.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb\OpenWithProgids]
"RealPlayer.RMVB.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmx]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmx\OpenWithProgids]
"RealJukebox.RMX.1"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rnx]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rp]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsml]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsml\OpenWithProgids]
"RealPlayer.RSML.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rt]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rv]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rv\OpenWithProgids]
"RealPlayer.RV.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rvx]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rvx\OpenWithProgids]
"RealPlayer.RVX.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sdp]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi\OpenWithProgids]
"RealPlayer.SMIL.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil\OpenWithProgids]
"RealPlayer.SMIL.6"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ssm]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ssm\OpenWithProgids]
"SSM"=hex(0):

[HKEY_CLASSES_ROOT\acrobat\DefaultIcon]
@="C:\\Program Files\\Adobe\\Acrobat 7.0\\Acrobat\\AcroRd32.exe"

[HKEY_CLASSES_ROOT\AcroIEHelper.AcroIEHlprObj]
@="AcroIEHlprObj Class"

[HKEY_CLASSES_ROOT\AcroIEHelper.AcroIEHlprObj\CLSID]
@="{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"

[HKEY_CLASSES_ROOT\AcroIEHelper.AcroIEHlprObj\CurVer]
@="AcroIEHelper.AcroIEHlprObj.1"

[HKEY_CLASSES_ROOT\AcroIEHelper.AcroIEHlprObj.1]
@="AcroIEHlprObj Class"

[HKEY_CLASSES_ROOT\AcroIEHelper.AcroIEHlprObj.1\CLSID]
@="{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"

[HKEY_CLASSES_ROOT\ADCS]
@="Conteneur de classe Annuaire"

[HKEY_CLASSES_ROOT\ADCS\CLSID]
@="{89E30300-764D-11d0-B282-00A0C90F56FC}"

[HKEY_CLASSES_ROOT\Connection Manager Profile\DefaultIcon]
@="C:\\WINDOWS\\system32\\CMMGR32.EXE,1"

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open]

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open\command]
@="C:\\WINDOWS\\system32\\CMMGR32.EXE \"%1\""

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...]

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...\command]
@="C:\\WINDOWS\\system32\\CMMGR32.EXE /settings \"%1\""

[HKEY_CLASSES_ROOT\DBC.MPEG.1\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\DBC.MPEG.1\shell\open]

[HKEY_CLASSES_ROOT\DBC.MPEG.1\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\gnutella1\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-128"

[HKEY_CLASSES_ROOT\gnutella1\shell\open]

[HKEY_CLASSES_ROOT\gnutella1\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%L\""

[HKEY_CLASSES_ROOT\gnutella1\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\gnutella1\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\gnutella1\shell\open\ddeexec\Topic]
@="URL"

[HKEY_CLASSES_ROOT\gnutella2\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-128"

[HKEY_CLASSES_ROOT\gnutella2\shell\open]

[HKEY_CLASSES_ROOT\gnutella2\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%L\""

[HKEY_CLASSES_ROOT\gnutella2\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\gnutella2\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\gnutella2\shell\open\ddeexec\Topic]
@="URL"

[HKEY_CLASSES_ROOT\LiveUpdate.MIDI.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\LiveUpdate.MIDI.6\shell\open]

[HKEY_CLASSES_ROOT\LiveUpdate.MIDI.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\MarkAny ContentSAFER Client\shell\Open]

[HKEY_CLASSES_ROOT\MarkAny ContentSAFER Client\shell\Open\Command]
@="\"C:\\Program Files\\MarkAny\\ContentSAFER\\MaCSMgr.exe\" \"%1\""

[HKEY_CLASSES_ROOT\MsnPhotoUpload.PhotoUploadCtl]
@="MSN Photo Upload Tool"

[HKEY_CLASSES_ROOT\MsnPhotoUpload.PhotoUploadCtl\CLSID]
@="{4F1E5B1A-2A80-42ca-8532-2D05CB959537}"

[HKEY_CLASSES_ROOT\MsnPhotoUpload.PhotoUploadCtl\CurVer]
@="MsnPhotoUpload.PhotoUploadCtl.1"

[HKEY_CLASSES_ROOT\MsnPhotoUpload.PhotoUploadCtl.1]
@="MSN Photo Upload Tool"

[HKEY_CLASSES_ROOT\MsnPhotoUpload.PhotoUploadCtl.1\CLSID]
@="{4F1E5B1A-2A80-42ca-8532-2D05CB959537}"

[HKEY_CLASSES_ROOT\RealPlayer.AIFF.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.AIFF.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.AIFF.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.AU.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.AU.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.AU.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.AVI.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.AVI.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.AVI.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.MP2.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.MP2.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.MP2.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.MPA.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.MPA.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.MPA.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.MPEG.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.MPEG.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.MPEG.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.wax.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.wax.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.wax.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.wm.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.wm.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.wm.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.wmf.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.wmf.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.wmf.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.wmv.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.wmv.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.wmv.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.wmx.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.wmx.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.wmx.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\RealPlayer.wvx.6\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe,1"

[HKEY_CLASSES_ROOT\RealPlayer.wvx.6\shell\open]

[HKEY_CLASSES_ROOT\RealPlayer.wvx.6\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" \"%1\""

[HKEY_CLASSES_ROOT\sa_ie_monitor.ie_monitor]
@="sa_ie_monitor.ie_monitor"

[HKEY_CLASSES_ROOT\sa_ie_monitor.ie_monitor\Clsid]
@="{548E1154-FA99-4B77-9FC5-02C9D8C9D24D}"

[HKEY_CLASSES_ROOT\Shareaza.Collection\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-244"

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open]

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%1\""

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open\ddeexec\Topic]
@="COLLECTION"

[HKEY_CLASSES_ROOT\Shareaza.SkinInfoExtractor.1]
@="Shareaza Skin Metadata Extractor"

[HKEY_CLASSES_ROOT\Shareaza.SkinInfoExtractor.1\CLSID]
@="{0EEDB912-C5FA-486F-8334-57288578C627}"

[HKEY_CLASSES_ROOT\SymWriter.pdb]
@="Pdb based SymWriter"

[HKEY_CLASSES_ROOT\SymWriter.pdb\CLSID]
@="{520DC67A-752E-11D3-8D56-00C04F680B2B}"

[HKEY_CLASSES_ROOT\uhc\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-128"

[HKEY_CLASSES_ROOT\uhc\shell\open]

[HKEY_CLASSES_ROOT\uhc\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%L\""

[HKEY_CLASSES_ROOT\uhc\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\uhc\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\uhc\shell\open\ddeexec\Topic]
@="URL"

[HKEY_CLASSES_ROOT\ukhl\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-128"

[HKEY_CLASSES_ROOT\ukhl\shell\open]

[HKEY_CLASSES_ROOT\ukhl\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%L\""

[HKEY_CLASSES_ROOT\ukhl\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\ukhl\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\ukhl\shell\open\ddeexec\Topic]
@="URL"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}]
@="ActiveXPlugin Object"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Control]

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\InprocServer32]
@="C:\\WINDOWS\\system32\\plugin.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\ProgID]
@="Microsoft.ActiveXPlugin.1"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\ToolboxBitmap32]
@="C:\\WINDOWS\\system32\\plugin.ocx, 1"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\TypeLib]
@="{06DD38D0-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\VersionIndependentProgID]
@="Microsoft.ActiveXPlugin"

[HKEY_CLASSES_ROOT\CLSID\{07D8026C-F806-459D-9797-ED72536F0EF8}]
@="CddbUI2 Class"

[HKEY_CLASSES_ROOT\CLSID\{07D8026C-F806-459D-9797-ED72536F0EF8}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBUI.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{07D8026C-F806-459D-9797-ED72536F0EF8}\ProgID]
@="CDDBUIControl.CddbUI2.1"

[HKEY_CLASSES_ROOT\CLSID\{07D8026C-F806-459D-9797-ED72536F0EF8}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{07D8026C-F806-459D-9797-ED72536F0EF8}\TypeLib]
@="{26BF9366-95A2-463B-8237-238114494AF7}"

[HKEY_CLASSES_ROOT\CLSID\{07D8026C-F806-459D-9797-ED72536F0EF8}\VersionIndependentProgID]
@="CDDBUIControl.CddbUI2"

[HKEY_CLASSES_ROOT\CLSID\{0932B8A4-BBB4-4bc0-A8AB-91C626950C75}]
@="Device Settings"

[HKEY_CLASSES_ROOT\CLSID\{0932B8A4-BBB4-4bc0-A8AB-91C626950C75}\InprocServer32]
@="C:\\WINDOWS\\system32\\LVUI2.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{09AC4892-81B7-4d39-B235-8F0DB0DAF4F8}]
@="Status"

[HKEY_CLASSES_ROOT\CLSID\{09AC4892-81B7-4d39-B235-8F0DB0DAF4F8}\InprocServer32]
@="C:\\WINDOWS\\system32\\LVUI2.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{1159F2AF-F989-4d11-8B34-9550029269BB}]
@="Advanced properties"

[HKEY_CLASSES_ROOT\CLSID\{1159F2AF-F989-4d11-8B34-9550029269BB}\InprocServer32]
@="C:\\WINDOWS\\system32\\LVUI2.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{1B62A3D1-9C04-4BD5-84B5-D2607302501F}]
@="DivX Decoder Filter Post-Processing Page"

[HKEY_CLASSES_ROOT\CLSID\{1B62A3D1-9C04-4BD5-84B5-D2607302501F}\InprocServer32]
@="C:\\WINDOWS\\system32\\divxdec.ax"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{1E33F406-AB8F-4153-A5C8-089AEFF5CC87}]
@="mdReg.clsReg"

[HKEY_CLASSES_ROOT\CLSID\{1E33F406-AB8F-4153-A5C8-089AEFF5CC87}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{1E33F406-AB8F-4153-A5C8-089AEFF5CC87}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{1E33F406-AB8F-4153-A5C8-089AEFF5CC87}\InprocServer32]
@="C:\\Program Files\\SpyAway\\clsReg.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{1E33F406-AB8F-4153-A5C8-089AEFF5CC87}\ProgID]
@="mdReg.clsReg"

[HKEY_CLASSES_ROOT\CLSID\{1E33F406-AB8F-4153-A5C8-089AEFF5CC87}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{1E33F406-AB8F-4153-A5C8-089AEFF5CC87}\TypeLib]
@="{F4F41439-82FC-4681-ACB0-7D3798F685C0}"

[HKEY_CLASSES_ROOT\CLSID\{1E33F406-AB8F-4153-A5C8-089AEFF5CC87}\VERSION]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{2E2C342C-BFC8-422A-AFCB-92F5A63BC067}]

[HKEY_CLASSES_ROOT\CLSID\{2E2C342C-BFC8-422A-AFCB-92F5A63BC067}\LocalServer32]
@="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe /StiDevice:%1 /StiEvent:%2"

[HKEY_CLASSES_ROOT\CLSID\{2ef001cc-1dd2-11b2-99c6-a432472165eb}]

[HKEY_CLASSES_ROOT\CLSID\{2ef001cc-1dd2-11b2-99c6-a432472165eb}\InprocServer32]
@="C:\\WINDOWS\\system32\\5Eem9Vbf.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{3836A5BF-51B3-4B37-8E96-9D429C22183C}]
@="CddbUIOptions Class"

[HKEY_CLASSES_ROOT\CLSID\{3836A5BF-51B3-4B37-8E96-9D429C22183C}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBControl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{3836A5BF-51B3-4B37-8E96-9D429C22183C}\ProgID]
@="CDDBControl.CddbUIOptions.1"

[HKEY_CLASSES_ROOT\CLSID\{3836A5BF-51B3-4B37-8E96-9D429C22183C}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{3836A5BF-51B3-4B37-8E96-9D429C22183C}\TypeLib]
@="{B0528CD1-F67E-11D2-8F8E-00C04F4C3B9F}"

[HKEY_CLASSES_ROOT\CLSID\{3836A5BF-51B3-4B37-8E96-9D429C22183C}\VersionIndependentProgID]
@="CDDBControl.CddbUIOptions"

[HKEY_CLASSES_ROOT\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}]
@="Partial AVI Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}\ProgID]
@="Shareaza.AVIPreviewer.1"

[HKEY_CLASSES_ROOT\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}\VersionIndependentProgID]
@="Shareaza.AVIPreviewer"

[HKEY_CLASSES_ROOT\CLSID\{4166b91f-3e58-47b0-bb5e-c88e57232085}]
@="CddbFileCleanInfo Class"

[HKEY_CLASSES_ROOT\CLSID\{4166b91f-3e58-47b0-bb5e-c88e57232085}\InprocServer32]
@="C:\\WINDOWS\\system32\\CddbCleanSamsung.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{4166b91f-3e58-47b0-bb5e-c88e57232085}\ProgID]
@="CddbCleanSamsung.CddbFileCleanInfo.1"

[HKEY_CLASSES_ROOT\CLSID\{4166b91f-3e58-47b0-bb5e-c88e57232085}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{4166b91f-3e58-47b0-bb5e-c88e57232085}\TypeLib]
@="{d337b415-6c2d-458b-9c13-a9502f832022}"

[HKEY_CLASSES_ROOT\CLSID\{4166b91f-3e58-47b0-bb5e-c88e57232085}\VersionIndependentProgID]
@="CddbCleanSamsung.CddbFileCleanInfo"

[HKEY_CLASSES_ROOT\CLSID\{46A84F21-16C0-460D-98E4-C12FE587BDCB}]
@="CIMSM_PLUGIN Object"
"AppID"=""

[HKEY_CLASSES_ROOT\CLSID\{46A84F21-16C0-460D-98E4-C12FE587BDCB}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{46A84F21-16C0-460D-98E4-C12FE587BDCB}\Implemented Categories\{B038FC36-34CF-4FB8-BDA2-59B774BCF358}]

[HKEY_CLASSES_ROOT\CLSID\{46A84F21-16C0-460D-98E4-C12FE587BDCB}\InprocServer32]
@="c:\\program files\\intel\\intel matrix storage manager\\pi_imsm.dll"
"ThreadingModel"="apartment"

[HKEY_CLASSES_ROOT\CLSID\{46A84F21-16C0-460D-98E4-C12FE587BDCB}\ProgID]
@="PI_IMSM.IMSM_PLUGIN.1"

[HKEY_CLASSES_ROOT\CLSID\{46A84F21-16C0-460D-98E4-C12FE587BDCB}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{46A84F21-16C0-460D-98E4-C12FE587BDCB}\TypeLib]
@="{56032B01-C4EE-446E-ADED-0DE3953C1D5F}"

[HKEY_CLASSES_ROOT\CLSID\{46A84F21-16C0-460D-98E4-C12FE587BDCB}\VersionIndependentProgID]
@="PI_IMSM.IMSM_PLUGIN"

[HKEY_CLASSES_ROOT\CLSID\{4C5B3552-E18F-45BE-BEA8-78ACEC1F2C6B}]
@="aspn Property Page"

[HKEY_CLASSES_ROOT\CLSID\{4C5B3552-E18F-45BE-BEA8-78ACEC1F2C6B}\InprocServer32]
@="C:\\PROGRA~1\\RICHVI~1\\RICHVI~1.OCX"

[HKEY_CLASSES_ROOT\CLSID\{4C8DD17E-7079-4c7e-96E5-A7AFDB12F132}]
@="Registers"

[HKEY_CLASSES_ROOT\CLSID\{4C8DD17E-7079-4c7e-96E5-A7AFDB12F132}\InprocServer32]
@="C:\\WINDOWS\\system32\\LVUI2.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{4FE8FFE1-FCCA-49c4-A363-525AB7C5B7CF}]
@="Bandwidth Control"

[HKEY_CLASSES_ROOT\CLSID\{4FE8FFE1-FCCA-49c4-A363-525AB7C5B7CF}\InprocServer32]
@="C:\\WINDOWS\\system32\\LVUI2.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{517539A3-905F-4755-9F94-D91B095A07CC}]
@="Troubleshooting"

[HKEY_CLASSES_ROOT\CLSID\{517539A3-905F-4755-9F94-D91B095A07CC}\InprocServer32]
@="C:\\WINDOWS\\system32\\LVUI2.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{5872C980-0AAF-4cdb-A62D-4F453DA2EFAD}]
@="Debug"

[HKEY_CLASSES_ROOT\CLSID\{5872C980-0AAF-4cdb-A62D-4F453DA2EFAD}\InprocServer32]
@="C:\\WINDOWS\\system32\\LVUI2.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}]
@="SimpleScopes Audio Visualisation for Shareaza"

[HKEY_CLASSES_ROOT\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}\ProgID]
@="Shareaza.SimpleScope.1"

[HKEY_CLASSES_ROOT\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}\VersionIndependentProgID]
@="Shareaza.SimpleScope"

[HKEY_CLASSES_ROOT\CLSID\{629466f7-8320-4ab4-908c-d09c8a9757cd}]
@="CDDBMusicIDUIManager Class"

[HKEY_CLASSES_ROOT\CLSID\{629466f7-8320-4ab4-908c-d09c8a9757cd}\InprocServer32]
@="C:\\WINDOWS\\system32\\CddbMusicIDUISamsung.dll"
"ThreadingModel"="both"

[HKEY_CLASSES_ROOT\CLSID\{629466f7-8320-4ab4-908c-d09c8a9757cd}\ProgID]
@="CddbMusicIDUISamsung.CDDBSamsungMusicIDUIManager.1"

[HKEY_CLASSES_ROOT\CLSID\{629466f7-8320-4ab4-908c-d09c8a9757cd}\VersionIndependentProgID]
@="CddbMusicIDUISamsung.CDDBSamsungMusicIDUIManager"

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}]
@="DivXBrowserPlugin Object"

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}\Control]

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}]

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}\InprocServer32]
@="C:\\Program Files\\DivX\\DivX Web Player\\npdivx32.dll"
"ThreadingModel"="both"

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{67DABFBF-D0AB-41fa-9C46-CC0F21721616}\TypeLib]
@="{B5AA9C9D-FFB8-4296-9CAD-57EAF1357354}"

[HKEY_CLASSES_ROOT\CLSID\{69E9B473-22E6-471D-8683-84BD1E4BECE1}]
@="CDDBControl2 Class"

[HKEY_CLASSES_ROOT\CLSID\{69E9B473-22E6-471D-8683-84BD1E4BECE1}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBControl.dll"
"ThreadingModel"="both"

[HKEY_CLASSES_ROOT\CLSID\{69E9B473-22E6-471D-8683-84BD1E4BECE1}\ProgID]
@="CDDBControl.CDDBControl2.1"

[HKEY_CLASSES_ROOT\CLSID\{69E9B473-22E6-471D-8683-84BD1E4BECE1}\VersionIndependentProgID]
@="CDDBControl.CDDBControl2"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}]
@="GFL Library Builder"
"AppID"="{F74AD137-A43F-46FD-A1FE-6532C3FC3E88}"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\GFLLibraryBuilder.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}\ProgID]
@="GFLLibraryBuilder.Builder.1"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}\TypeLib]
@="{7B8046FF-0D3A-4D85-9424-7DFCCD1BCA45}"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}\VersionIndependentProgID]
@="GFLLibraryBuilder.Builder"

[HKEY_CLASSES_ROOT\CLSID\{706fdb72-be03-4ab6-a535-048d94c23e6c}]
@="CddbFilenameTemplate Class"

[HKEY_CLASSES_ROOT\CLSID\{706fdb72-be03-4ab6-a535-048d94c23e6c}\InprocServer32]
@="C:\\WINDOWS\\system32\\CddbCleanSamsung.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{706fdb72-be03-4ab6-a535-048d94c23e6c}\ProgID]
@="CddbCleanSamsung.CddbFilenameTemplate.1"

[HKEY_CLASSES_ROOT\CLSID\{706fdb72-be03-4ab6-a535-048d94c23e6c}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{706fdb72-be03-4ab6-a535-048d94c23e6c}\TypeLib]
@="{d337b415-6c2d-458b-9c13-a9502f832022}"

[HKEY_CLASSES_ROOT\CLSID\{706fdb72-be03-4ab6-a535-048d94c23e6c}\VersionIndependentProgID]
@="CddbCleanSamsung.CddbFilenameTemplate"

[HKEY_CLASSES_ROOT\CLSID\{81F0237C-E2FD-49E6-8E99-1434D6E13375}]
@="ASWrapComponent Class"

[HKEY_CLASSES_ROOT\CLSID\{81F0237C-E2FD-49E6-8E99-1434D6E13375}\InprocServer32]
@="c:\\Program Files\\HP\\bin\\hpqSonWr.dll"
"InprocServer32"=hex(7):4e,00,21,00,26,00,45,00,26,00,33,00,2a,00,7d,00,69,\
00,40,00,5d,00,4f,00,24,00,72,00,53,00,4f,00,59,00,35,00,6a,00,77,00,43,00,\
50,00,5f,00,53,00,6c,00,69,00,64,00,65,00,73,00,68,00,6f,00,77,00,50,00,6c,\
00,75,00,67,00,69,00,6e,00,3e,00,3d,00,5f,00,4e,00,49,00,25,00,4a,00,57,00,\
30,00,5a,00,40,00,74,00,6f,00,25,00,5b,00,6f,00,31,00,61,00,6b,00,30,00,79,\
00,00,00,3036,00,2a0a,00,a,00,11,00,11,00,1f6,00,c,00,00,00,d408,00,92,00,d408,\
00,92,00,ee18,00,17,00,d424,00,92,00,d424,00,92,00,be48,00,16,00,d448,00,92,\
00,d430,00,92,00,c450,00,16,00,d454,00,92,00,d43c,00,92,00,c488,00,16,00,d460,\
00,92,00,d448,00,92,00,c4d0,00,16,00,d46c,00,92,00,d454,00,92,00,c4f8,00,16,\
00,d478,00,92,00,d460,00,92,00,c550,00,16,00,d484,00,92,00,d46c,00,92,00,c598,\
00,16,00,d490,00,92,00,d478,00,92,00,c5d0,00,16,00,00,00,d484,00,92,00,c608,\
00,16,00,00,00,11,00,11,00,1e1,00,8,00,dad,00,00,00,17,00,7cd4,00,49,00,00,00,a8ac,\
00,99,00,00,00,00,00
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{81F0237C-E2FD-49E6-8E99-1434D6E13375}\ProgID]
@="ASWrapper.ASWrapComponent.1"

[HKEY_CLASSES_ROOT\CLSID\{81F0237C-E2FD-49E6-8E99-1434D6E13375}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{81F0237C-E2FD-49E6-8E99-1434D6E13375}\TypeLib]
@="{88AC17A8-28FD-40C9-BD21-F7853F849E46}"

[HKEY_CLASSES_ROOT\CLSID\{81F0237C-E2FD-49E6-8E99-1434D6E13375}\VersionIndependentProgID]
@="ASWrapper.ASWrapComponent"

[HKEY_CLASSES_ROOT\CLSID\{83E66439-05D5-488C-A236-AA20E543D384}]
@="DivX Decoder Filter Quality Page"

[HKEY_CLASSES_ROOT\CLSID\{83E66439-05D5-488C-A236-AA20E543D384}\InprocServer32]
@="C:\\WINDOWS\\system32\\divxdec.ax"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{8722111A-DE20-48ac-832D-0CEDA23212AB}]
@="CddbInfoWindow2 Class"

[HKEY_CLASSES_ROOT\CLSID\{8722111A-DE20-48ac-832D-0CEDA23212AB}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBUI.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{8722111A-DE20-48ac-832D-0CEDA23212AB}\ProgID]
@="CDDBUIControl.CddbInfoWindow2.1"

[HKEY_CLASSES_ROOT\CLSID\{8722111A-DE20-48ac-832D-0CEDA23212AB}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{8722111A-DE20-48ac-832D-0CEDA23212AB}\TypeLib]
@="{26BF9366-95A2-463B-8237-238114494AF7}"

[HKEY_CLASSES_ROOT\CLSID\{8722111A-DE20-48ac-832D-0CEDA23212AB}\VersionIndependentProgID]
@="CDDBUIControl.CddbInfoWindow2"

[HKEY_CLASSES_ROOT\CLSID\{8FCA01DA-D48C-4B1C-9DD3-6C01F9D3D4AF}]
@="CddbWMATag Class"

[HKEY_CLASSES_ROOT\CLSID\{8FCA01DA-D48C-4B1C-9DD3-6C01F9D3D4AF}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBControl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{8FCA01DA-D48C-4B1C-9DD3-6C01F9D3D4AF}\ProgID]
@="CDDBControl.CddbWMATag.1"

[HKEY_CLASSES_ROOT\CLSID\{8FCA01DA-D48C-4B1C-9DD3-6C01F9D3D4AF}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{8FCA01DA-D48C-4B1C-9DD3-6C01F9D3D4AF}\TypeLib]
@="{B0528CD1-F67E-11D2-8F8E-00C04F4C3B9F}"

[HKEY_CLASSES_ROOT\CLSID\{8FCA01DA-D48C-4B1C-9DD3-6C01F9D3D4AF}\VersionIndependentProgID]
@="CDDBControl.CddbWMATag"

[HKEY_CLASSES_ROOT\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}]
@="Partial MPEG-1 Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}\ProgID]
@="Shareaza.MPEGPreviewer.1"

[HKEY_CLASSES_ROOT\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}\VersionIndependentProgID]
@="Shareaza.MPEGPreviewer"

[HKEY_CLASSES_ROOT\CLSID\{A0717E52-8AC8-4dd9-8682-0B76775125E6}]
@="DivX Settings Manager"

[HKEY_CLASSES_ROOT\CLSID\{A0717E52-8AC8-4dd9-8682-0B76775125E6}\LocalServer32]
@="C:\\WINDOWS\\system32\\divxsm.exe"

[HKEY_CLASSES_ROOT\CLSID\{a34dab28-7565-417e-9a5e-2e4937412fe1}]
@="CddbFileCleanInfoList Class"

[HKEY_CLASSES_ROOT\CLSID\{a34dab28-7565-417e-9a5e-2e4937412fe1}\InprocServer32]
@="C:\\WINDOWS\\system32\\CddbCleanSamsung.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{a34dab28-7565-417e-9a5e-2e4937412fe1}\ProgID]
@="CddbCleanSamsung.CddbFileCleanInfoList.1"

[HKEY_CLASSES_ROOT\CLSID\{a34dab28-7565-417e-9a5e-2e4937412fe1}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{a34dab28-7565-417e-9a5e-2e4937412fe1}\TypeLib]
@="{d337b415-6c2d-458b-9c13-a9502f832022}"

[HKEY_CLASSES_ROOT\CLSID\{a34dab28-7565-417e-9a5e-2e4937412fe1}\VersionIndependentProgID]
@="CddbCleanSamsung.CddbFileCleanInfoList"

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}]
@="Shareaza Skin Metadata Extractor"

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\SkinScanSKS.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\ProgID]
@="Shareaza.SkinInfoExtractor.1"

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\VersionIndependentProgID]
@="Shareaza.SkinInfoExtractor"

[HKEY_CLASSES_ROOT\CLSID\{a5d3a9ef-e801-4251-b80a-445040fd0176}]
@="CddbCleanGroupMgr Class"

[HKEY_CLASSES_ROOT\CLSID\{a5d3a9ef-e801-4251-b80a-445040fd0176}\InprocServer32]
@="C:\\WINDOWS\\system32\\CddbCleanSamsung.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{a5d3a9ef-e801-4251-b80a-445040fd0176}\ProgID]
@="CddbCleanSamsung.CddbCleanGroupMgr.1"

[HKEY_CLASSES_ROOT\CLSID\{a5d3a9ef-e801-4251-b80a-445040fd0176}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{a5d3a9ef-e801-4251-b80a-445040fd0176}\TypeLib]
@="{d337b415-6c2d-458b-9c13-a9502f832022}"

[HKEY_CLASSES_ROOT\CLSID\{a5d3a9ef-e801-4251-b80a-445040fd0176}\VersionIndependentProgID]
@="CddbCleanSamsung.CddbCleanGroupMgr"

[HKEY_CLASSES_ROOT\CLSID\{a82b3f71-9905-4885-8195-7a7fef30abbd}]
@="CddbFindAlbumsList Class"

[HKEY_CLASSES_ROOT\CLSID\{a82b3f71-9905-4885-8195-7a7fef30abbd}\InprocServer32]
@="C:\\WINDOWS\\system32\\CddbCleanSamsung.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{a82b3f71-9905-4885-8195-7a7fef30abbd}\ProgID]
@="CddbCleanSamsung.CddbFindAlbumsList.1"

[HKEY_CLASSES_ROOT\CLSID\{a82b3f71-9905-4885-8195-7a7fef30abbd}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{a82b3f71-9905-4885-8195-7a7fef30abbd}\TypeLib]
@="{d337b415-6c2d-458b-9c13-a9502f832022}"

[HKEY_CLASSES_ROOT\CLSID\{a82b3f71-9905-4885-8195-7a7fef30abbd}\VersionIndependentProgID]
@="CddbCleanSamsung.CddbFindAlbumsList"

[HKEY_CLASSES_ROOT\CLSID\{a845fffc-c621-4f9a-9b7d-11f27656883c}]
@="CddbSamsungCleanMgr Class"

[HKEY_CLASSES_ROOT\CLSID\{a845fffc-c621-4f9a-9b7d-11f27656883c}\InprocServer32]
@="C:\\WINDOWS\\system32\\CddbCleanSamsung.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{a845fffc-c621-4f9a-9b7d-11f27656883c}\ProgID]
@="CddbCleanSamsung.CddbSamsungCleanMgr.1"

[HKEY_CLASSES_ROOT\CLSID\{a845fffc-c621-4f9a-9b7d-11f27656883c}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{a845fffc-c621-4f9a-9b7d-11f27656883c}\TypeLib]
@="{d337b415-6c2d-458b-9c13-a9502f832022}"

[HKEY_CLASSES_ROOT\CLSID\{a845fffc-c621-4f9a-9b7d-11f27656883c}\VersionIndependentProgID]
@="CddbCleanSamsung.CddbSamsungCleanMgr"

[HKEY_CLASSES_ROOT\CLSID\{AA9B2BD7-B7AA-4d4a-AF5C-D7B2C8FB6582}]
@="CddbUIOptions2 Class"

[HKEY_CLASSES_ROOT\CLSID\{AA9B2BD7-B7AA-4d4a-AF5C-D7B2C8FB6582}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBUI.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{AA9B2BD7-B7AA-4d4a-AF5C-D7B2C8FB6582}\ProgID]
@="CDDBUIControl.CddbUIOptions2.1"

[HKEY_CLASSES_ROOT\CLSID\{AA9B2BD7-B7AA-4d4a-AF5C-D7B2C8FB6582}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{AA9B2BD7-B7AA-4d4a-AF5C-D7B2C8FB6582}\TypeLib]
@="{26BF9366-95A2-463B-8237-238114494AF7}"

[HKEY_CLASSES_ROOT\CLSID\{AA9B2BD7-B7AA-4d4a-AF5C-D7B2C8FB6582}\VersionIndependentProgID]
@="CDDBUIControl.CddbUIOptions2"

[HKEY_CLASSES_ROOT\CLSID\{AB7AB3FF-EB55-4B40-AE1D-80ECEFA32E17}]
@="CddbUI Class"

[HKEY_CLASSES_ROOT\CLSID\{AB7AB3FF-EB55-4B40-AE1D-80ECEFA32E17}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBUI.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{AB7AB3FF-EB55-4B40-AE1D-80ECEFA32E17}\ProgID]
@="CDDBUIControl.CddbUI.1"

[HKEY_CLASSES_ROOT\CLSID\{AB7AB3FF-EB55-4B40-AE1D-80ECEFA32E17}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{AB7AB3FF-EB55-4B40-AE1D-80ECEFA32E17}\TypeLib]
@="{26BF9366-95A2-463B-8237-238114494AF7}"

[HKEY_CLASSES_ROOT\CLSID\{AB7AB3FF-EB55-4B40-AE1D-80ECEFA32E17}\VersionIndependentProgID]
@="CDDBUIControl.CddbUI"

[HKEY_CLASSES_ROOT\CLSID\{B0528CE4-F67E-11D2-8F8E-00C04F4C3B9F}]
@="CddbDisc Class"

[HKEY_CLASSES_ROOT\CLSID\{B0528CE4-F67E-11D2-8F8E-00C04F4C3B9F}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBControl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{B0528CE4-F67E-11D2-8F8E-00C04F4C3B9F}\ProgID]
@="CDDBControl.CddbDisc.1"

[HKEY_CLASSES_ROOT\CLSID\{B0528CE4-F67E-11D2-8F8E-00C04F4C3B9F}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{B0528CE4-F67E-11D2-8F8E-00C04F4C3B9F}\TypeLib]
@="{B0528CD1-F67E-11D2-8F8E-00C04F4C3B9F}"

[HKEY_CLASSES_ROOT\CLSID\{B0528CE4-F67E-11D2-8F8E-00C04F4C3B9F}\VersionIndependentProgID]
@="CDDBControl.CddbDisc"

[HKEY_CLASSES_ROOT\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}]
@="Partial MP3 Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}\ProgID]
@="Shareaza.MP3Previewer.1"

[HKEY_CLASSES_ROOT\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}\VersionIndependentProgID]
@="Shareaza.MP3Previewer"

[HKEY_CLASSES_ROOT\CLSID\{BF3F7EF3-8527-4145-BE10-63F8C0DE6ABB}]
@="QuickTime Source Filter"

[HKEY_CLASSES_ROOT\CLSID\{BF3F7EF3-8527-4145-BE10-63F8C0DE6ABB}\InprocServer32]
@="C:\\Program Files\\Fichiers communs\\muvee Technologies\\030625\\QuickTimeSource.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{C073A662-A344-4611-8632-06452280EBB0}]
@="CddbInfoWindow Class"

[HKEY_CLASSES_ROOT\CLSID\{C073A662-A344-4611-8632-06452280EBB0}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBControl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{C073A662-A344-4611-8632-06452280EBB0}\ProgID]
@="CDDBControl.CddbInfoWindow.1"

[HKEY_CLASSES_ROOT\CLSID\{C073A662-A344-4611-8632-06452280EBB0}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{C073A662-A344-4611-8632-06452280EBB0}\TypeLib]
@="{B0528CD1-F67E-11D2-8F8E-00C04F4C3B9F}"

[HKEY_CLASSES_ROOT\CLSID\{C073A662-A344-4611-8632-06452280EBB0}\VersionIndependentProgID]
@="CDDBControl.CddbInfoWindow"

[HKEY_CLASSES_ROOT\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}]
@="Windows Media Player Visualisation Wrapper"

[HKEY_CLASSES_ROOT\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}\ProgID]
@="Shareaza.WMPVis.1"

[HKEY_CLASSES_ROOT\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}\VersionIndependentProgID]
@="Shareaza.WMPVis"

[HKEY_CLASSES_ROOT\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}]
@="Sonique Visualisation Wrapper"

[HKEY_CLASSES_ROOT\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}\ProgID]
@="Shareaza.SoniqueVis.1"

[HKEY_CLASSES_ROOT\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}\VersionIndependentProgID]
@="Shareaza.SoniqueVis"

[HKEY_CLASSES_ROOT\CLSID\{D734EAE8-0810-4513-99B6-DDAC4BC30E29}]
@="CddbID3Tag Class"

[HKEY_CLASSES_ROOT\CLSID\{D734EAE8-0810-4513-99B6-DDAC4BC30E29}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBControl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{D734EAE8-0810-4513-99B6-DDAC4BC30E29}\ProgID]
@="CDDBControl.CddbID3Tag.1"

[HKEY_CLASSES_ROOT\CLSID\{D734EAE8-0810-4513-99B6-DDAC4BC30E29}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{D734EAE8-0810-4513-99B6-DDAC4BC30E29}\TypeLib]
@="{B0528CD1-F67E-11D2-8F8E-00C04F4C3B9F}"

[HKEY_CLASSES_ROOT\CLSID\{D734EAE8-0810-4513-99B6-DDAC4BC30E29}\VersionIndependentProgID]
@="CDDBControl.CddbID3Tag"

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}]
@="aspn Control"

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\Control]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\InprocServer32]
@="C:\\PROGRA~1\\RICHVI~1\\RICHVI~1.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\MiscStatus\1]
@="132241"

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\ProgID]
@="VAC.Video"

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\ToolboxBitmap32]
@="C:\\PROGRA~1\\RICHVI~1\\RICHVI~1.OCX, 1"

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\TypeLib]
@="{5216FD0F-3915-4F95-95CF-4F09659F58C3}"

[HKEY_CLASSES_ROOT\CLSID\{D79308A2-F924-4CD6-A52A-158C68EF41F8}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{DE7371F4-4CCD-47cd-B12B-8887C9125895}]
@="USB Traffic"

[HKEY_CLASSES_ROOT\CLSID\{DE7371F4-4CCD-47cd-B12B-8887C9125895}\InprocServer32]
@="C:\\WINDOWS\\system32\\LVUI2.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{DFEF3E96-F1D4-47CE-A429-2CC8C10DFDB6}]
@="CddbID3TagManager Class"

[HKEY_CLASSES_ROOT\CLSID\{DFEF3E96-F1D4-47CE-A429-2CC8C10DFDB6}\InprocServer32]
@="C:\\WINDOWS\\system32\\CDDBControl.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{DFEF3E96-F1D4-47CE-A429-2CC8C10DFDB6}\ProgID]
@="CDDBControl.CddbID3TagManager.1"

[HKEY_CLASSES_ROOT\CLSID\{DFEF3E96-F1D4-47CE-A429-2CC8C10DFDB6}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{DFEF3E96-F1D4-47CE-A429-2CC8C10DFDB6}\TypeLib]
@="{B0528CD1-F67E-11D2-8F8E-00C04F4C3B9F}"

[HKEY_CLASSES_ROOT\CLSID\{DFEF3E96-F1D4-47CE-A429-2CC8C10DFDB6}\VersionIndependentProgID]
@="CDDBControl.CddbID3TagManager"

[HKEY_CLASSES_ROOT\CLSID\{E70B0BD1-B1CE-41B6-AE14-38B63DD87F55}]
@="SNN_Cryptography Object"
"AppID"=""

[HKEY_CLASSES_ROOT\CLSID\{E70B0BD1-B1CE-41B6-AE14-38B63DD87F55}\InprocServer32]
@="C:\\WINDOWS\\system32\\SNN_Crypto.dll"
"ThreadingModel"=""

[HKEY_CLASSES_ROOT\CLSID\{E70B0BD1-B1CE-41B6-AE14-38B63DD87F55}\ProgID]
@="SNN_Crypto.SNN_Cryptography.1"

[HKEY_CLASSES_ROOT\CLSID\{E70B0BD1-B1CE-41B6-AE14-38B63DD87F55}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{E70B0BD1-B1CE-41B6-AE14-38B63DD87F55}\TypeLib]
@="{45C1044F-7B8E-4A89-81B5-FF50AF5DE0CD}"

[HKEY_CLASSES_ROOT\CLSID\{E70B0BD1-B1CE-41B6-AE14-38B63DD87F55}\VersionIndependentProgID]
@="SNN_Crypto.SNN_Cryptography"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}]
@="Document Metadata Reader and Thumbnailer"
"AppID"="{BEC42E3F-4B6B-49A3-A099-EB3D6752AA02}"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\DocumentReader.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}\ProgID]
@="Shareaza.DocReader.1"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}\TypeLib]
@="{607C3F69-850D-4413-A81A-CF1C849BF387}"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}\VersionIndependentProgID]
@="Shareaza.DocReader"

[HKEY_CLASSES_ROOT\CLSID\{ea09662c-1dd1-11b2-b5cb-876b830b4216}]

[HKEY_CLASSES_ROOT\CLSID\{ea09662c-1dd1-11b2-b5cb-876b830b4216}\InprocServer32]
@="C:\\WINDOWS\\system32\\USIPL5QW.dll"
"ThreadingModel"="Apartment"
"t"=dword:46c02991

[HKEY_CLASSES_ROOT\CLSID\{ec1921fe-1dd1-11b2-bbfc-c740e07ba44a}]

[HKEY_CLASSES_ROOT\CLSID\{ec1921fe-1dd1-11b2-bbfc-c740e07ba44a}\InprocServer32]
@="C:\\WINDOWS\\system32\\M7wZqQwb.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{F4BAFF02-F907-11D2-8F8F-00C04F4C3B9F}]
@="CDDBControl Class"

[HKEY_CLASSES_ROOT\CLSID\{F4BAFF02-F907-11D2-8F8F-00C04F4C3B9F}\Control]

[HKEY_CLASSES_ROOT\CLSID\{F4BAFF02-F907-11D2-8F8F-00C04F4C3B9F}\InprocServer32]
0
camille72 Messages postés 6 Statut Membre
 
Je ne sais pas s'il y a d'autres manipulations à faire, mais en tout cas il y a de gros changements qui sont apparus:

- Alors que je ne pouvais pas faire de restauration de système car le calendrier n'apparaissait pas, il apparait de nouveau!

- Je ne pouvais plus utiliser le gestionnaire de tâches car soit disant l'administrateur l'avait désactivé. Or j'avais fais des manipulations grâce à votre forum, et le gestionnaire ne marchait toujours pas. Maintenant il remarche!

- Et surtout ce message qui remplaçait mon fond d'écran a disparu, et plus aucune page (m'obligeant à télécharger des anti spyware, ou a scanner mon disque dur) n'apparait!

Donc pour moi ca relève dejà du génie :D
0
Utilisateur anonyme
 
Ton problème ne peut pas être résolu, ton PC est à nid à virus. Il faudrait revoir la manière dont les personnes utilisant cet ordinateur l'utilisent. Déjà éviter les sites pornos et de cliquer sur tout ce qui bouge, ton ordi à visiter des sites pornos ça c'est clair, maintenant faut réguler l'usage ou faire attention de bien scanner son PC après avoir visité des sites de "chaires fraîches" (sacrilège, doux Jèsus que ton pêché soit pardonné) lol (ô_0)

La suite :

Télécharge OTMoveIt sur ton bureau
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

Double clic sur OTMoveIt.exe
Sélectionne et copie les lignes ci-dessous

C:\WINDOWS\system32\mgmrwmrv.exe
C:\Documents and Settings\HP_Administrateur\Application Data\setup_fr[1].exe
C:\WINDOWS\system32\drivers\Njc30.sys
C:\ukbdtg.exe
C:\WINDOWS\system32\iifeffio.tmp
C:\-664524276
C:\WINDOWS\fgtwhml.exe
C:\WINDOWS\system32\marwin32.dl
C:\Documents and Settings\All Users\Application Data\wrujghor.dll
C:\WINDOWS\system32\fepajink.exe
C:\Program Files\RichVideoCodec
C:\Documents and Settings\Camille\Application Data\WinButler
c:\program files\3721\


Retourne dans OTMoveit, fais un clic droit dans la fenêtre "Paste Standard List of Files/Folders to move" et choisis "coller".
Clic sur le boutton rouge Moveit et clic sur Exit
Si un fichier ou un dossier ne peut être déplacer immédiatement il te sera demander de redémarrer ta machine pour finir l'exécution, si c'est le cas, clic sur "Yes"
Copie et colle le rapport qu'il va te générer ici stp. Le rapport d'OTMoveit se trouve dans ce dossier : C:\_OTMoveIt\MovedFiles

* ¤ Télécharge Clean
----> http://www.malekal.com/download/clean.zip

Dézippe tout le contenu dans le même dossier. Double clic sur clean ou clean.cmd choisissez l'option 1.
Un rapport va s'ouvrir, copie et colle le contenu ici stp
0
camille72 Messages postés 6 Statut Membre
 
Bonjour.

Je suis désolée de ne répondre qu'aujourd'hui, mais c'est l'ordinateur de chez mes parents qui a un problème, et je ne suis chez eux que le we.

Alors, voici le raport que tu m'as demandé lundi:

C:\WINDOWS\system32\mgmrwmrv.exe moved successfully.
C:\Documents and Settings\HP_Administrateur\Application Data\setup_fr[1].exe moved successfully.
File/Folder C:\WINDOWS\system32\drivers\Njc30.sys not found.
File/Folder C:\ukbdtg.exe not found.
C:\WINDOWS\system32\iifeffio.tmp moved successfully.
C:\-664524276 moved successfully.
File/Folder C:\WINDOWS\fgtwhml.exe not found.
File/Folder C:\WINDOWS\system32\marwin32.dl not found.
File/Folder C:\Documents and Settings\All Users\Application Data\wrujghor.dll not found.
File/Folder C:\WINDOWS\system32\fepajink.exe not found.
C:\Program Files\RichVideoCodec moved successfully.
C:\Documents and Settings\Camille\Application Data\WinButler moved successfully.
Folder c:\program files\3721\ not found.

OTMoveIt2 v1.0.20 log created on 03072008_112827

Pour clean, j'ai ce petit raport qui s'est ouvert:

07/03/2008 a 11:33:46,89

*** Recherche des fichiers dans C:

*** Recherche des fichiers dans C:\WINDOWS\

*** Recherche des fichiers dans C:\WINDOWS\system32
"C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND

*** Recherche des fichiers dans C:\Program Files
*** Fin du rapport !

Je ne sais pas si c'est cela qu'il fallait envoyer...




0
camille72 Messages postés 6 Statut Membre > camille72 Messages postés 6 Statut Membre
 
Pourriez-vous continuer de m'aider? :(
0