Rapport navilog; pub intempestivesous firefox

malou35000 Messages postés 9 Statut Membre -  
ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   -
Bonjour,
je sais tout le monde pose la même question mais quelqu'un peut m'aider sur mon rapport navilog.
Car ça me soule profondément d'avoir des pub intempestives;;;;;;;;;;
J'en ai marre des antivirus et des casinos en ligne
Please help me

voilà mon rapport:::

Search Navipromo version 3.5.0 commencé le 15/03/2008 à 18:07:43,45

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO

Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2900.2180
Système de fichiers : NTFS

Executé en mode normal

*** Recherche Programmes installés ***

*** Recherche dossiers dans C:\WINDOWS ***

*** Recherche dossiers dans C:\Program Files ***

*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

*** Recherche dossiers dans "C:\Documents and Settings\Maëlle\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\Maëlle\locals~1\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\Maëlle\menudm~1\progra~1" ***

*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Fichier(s) caché(s) :

C:\WINDOWS\system32\artigb.dat
C:\WINDOWS\system32\artigb.exe
C:\WINDOWS\system32\artigb_nav.dat
C:\WINDOWS\system32\artigb_navps.dat

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\WINDOWS\system32 *

Fichiers trouvés :

ancyua.exe trouvé !
kuqhcpq.exe trouvé !
obitez.exe trouvé !
vahwxw.exe trouvé !
vnfbpyfl.exe trouvé !
vuiawj.exe trouvé !

* Recherche dans "C:\Documents and Settings\Maëlle\locals~1\applic~1" *

*** Recherche fichiers ***

C:\WINDOWS\pack.epk trouvé !
C:\WINDOWS\tmlpcert2007 trouvé !

*** Recherche clés spécifiques dans le Registre ***

HKEY_CURRENT_USER\Software\Lanconfig trouvé !
HKEY_CURRENT_USER\Software\mc trouvé !

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :

2)Recherche Heuristique :

* Dans C:\WINDOWS\system32 :

artigb.dat trouvé !
boqxkmmo.dat trouvé !

* Dans "C:\Documents and Settings\Maëlle\locals~1\applic~1" :

3)Recherche Certificats :

Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat OOO-Favorit trouvé !

4)Recherche fichiers connus :

*** Analyse terminée le 15/03/2008 à 18:17:08,71 ***
Configuration: Windows XP
Firefox 2.0.0.12

13 réponses

  1. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonjour

    oui en effet tu peux passer à l'option 2 de navilog
    je te conseille aussi de faire clean
    Télecharge http://www.malekal.com/download/clean.zip sur le bureau
    Dézippe sur le bureau.
    = ouvrir le dossier clean
    = clique sur le symbole roue dentée avec le nom clean
    = choisir l'option 1 et laisser clean travailler jusqu'à l'apparition du texte "appuyer sur une touche pour continuer"
    = ensuite colle le rapport que tu trouveras dans C:

    ensuite de faire un hijackthis
    Télécharge sur le bureau

    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    = Double-clic dessus pour l'installer
    = Clic Do a system scan and save the log
    =coller le rapport
    si problème voir l'aide
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    @+
    0
    1. malou35000 Messages postés 9 Statut Membre
       
      VOILA LE RAPPORT CLEAN

      15/03/2008 a 19:12:22,40

      *** Recherche des fichiers dans C:

      *** Recherche des fichiers dans C:\WINDOWS\
      C:\WINDOWS\WMCRRS.exe FOUND

      *** Recherche des fichiers dans C:\WINDOWS\system32

      *** Recherche des fichiers dans C:\Program Files
      "C:\Program Files\Multi_Media_France\" FOUND
      *** Fin du rapport !
      0
  2. malou35000 Messages postés 9 Statut Membre
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:22:12, on 15/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\bgsvcgen.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\Wanadoo\CnxMon.exe
    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Eraser\Eraser.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
    O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [mav_startupmon] "C:\Program Files\Fichiers communs\WinAntiVirus Pro 2007\mav_startupmon.exe"
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AutoTBar] C:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
    O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"
    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - S-1-5-18 Startup: AutoTBar.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: AutoTBar.exe (User 'Default user')
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
    O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117fd.bay117.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
    O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Program Files\Canon\DIAS\CnxDIAS.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    0
  3. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    relance Navilog et tu choisis l'option 2.
    Poste le nouveau rapport.

    lance clean.zip en mode sans echec
    pend cette fois-ci l'option 2 et poste le rapport.

    = Redémarre en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
    Attention, pas d’accès à internet dans ce mode. Enregistre ou imprime les consignes.

    Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
    Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel

    ensuite

    Télécharge sur le bureau [url=http://siri.urz.free.fr/Fix/SmitfraudFix.zip]SmitfraudFix.zip[/url]
    => Double clic sur SmitfraudFix.zip
    => Extraire tout
    => Double clic sur SmitfraudFix
    => Double Clic sur SmitfraudFix.cmd
    => Choisir Option 1
    => poste le rapport
    @+
    0
    1. malou35000 Messages postés 9 Statut Membre
       
      Clean Navipromo version 3.5.0 commencé le 15/03/2008 à 19:03:59,98

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO


      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 6.0.2900.2180
      Système de fichiers : NTFS

      Mode suppression automatique
      avec prise en charge résultats Catchme et GNS


      *** Creation backups fichiers trouvés par Catchme ***

      Copie vers "C:\Program Files\navilog1\Backupnavi"

      Copie C:\WINDOWS\system32\artigb.dat réalisée avec succès !
      Copie C:\WINDOWS\system32\artigb.exe réalisée avec succès !
      Copie C:\WINDOWS\system32\artigb_nav.dat réalisée avec succès !
      Copie C:\WINDOWS\system32\artigb_navps.dat réalisée avec succès !

      *** Suppression des fichiers trouvés avec Catchme ***

      C:\WINDOWS\system32\artigb.dat supprimé !
      C:\WINDOWS\system32\artigb.exe supprimé !
      C:\WINDOWS\system32\artigb_nav.dat supprimé !
      C:\WINDOWS\system32\artigb_navps.dat supprimé !

      ** 2ème passage avec résultats Catchme **

      * Dans C:\WINDOWS\system32 *


      C:\WINDOWS\prefetch\artigb*.pf trouvé !
      Copie C:\WINDOWS\prefetch\artigb*.pf réalisée avec succès !
      C:\WINDOWS\prefetch\artigb*.pf supprimé !

      * Dans "C:\Documents and Settings\Maëlle\locals~1\applic~1" *


      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

      * Suppression dans C:\WINDOWS\System32 *

      ancyua.exe trouvé !
      Copie ancyua.exe réalisée avec succès !
      ancyua.exe supprimé !

      kuqhcpq.exe trouvé !
      Copie kuqhcpq.exe réalisée avec succès !
      kuqhcpq.exe supprimé !

      obitez.exe trouvé !
      Copie obitez.exe réalisée avec succès !
      obitez.exe supprimé !

      vahwxw.exe trouvé !
      Copie vahwxw.exe réalisée avec succès !
      vahwxw.exe supprimé !

      vnfbpyfl.exe trouvé !
      Copie vnfbpyfl.exe réalisée avec succès !
      vnfbpyfl.exe supprimé !

      vuiawj.exe trouvé !
      Copie vuiawj.exe réalisée avec succès !
      vuiawj.exe supprimé !


      * Suppression dans "C:\Documents and Settings\Maëlle\locals~1\applic~1" *



      *** Suppression dossiers dans C:\WINDOWS ***


      *** Suppression dossiers dans C:\Program Files ***


      *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***


      *** Suppression dossiers dans "C:\Documents and Settings\Maëlle\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\Maëlle\locals~1\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\Maëlle\menudm~1\progra~1" ***


      *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***



      *** Suppression fichiers ***

      C:\WINDOWS\pack.epk supprimé !
      C:\WINDOWS\tmlpcert2007 supprimé !

      *** Suppression fichiers temporaires ***

      Nettoyage contenu C:\WINDOWS\Temp effectué !
      Nettoyage contenu C:\Documents and Settings\Ma‰lle\locals~1\Temp effectué !

      *** Traitement Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

      2)Recherche, création sauvegardes et suppression Heuristique :


      * Dans C:\WINDOWS\system32 *

      boqxkmmo.dat trouvé !
      Copie boqxkmmo.dat réalisée avec succès !
      boqxkmmo.dat supprimé !

      boqxkmmo_nav.dat trouvé !
      Copie boqxkmmo_nav.dat réalisée avec succès !
      boqxkmmo_nav.dat supprimé !

      boqxkmmo_navps.dat trouvé !
      Copie boqxkmmo_navps.dat réalisée avec succès !
      boqxkmmo_navps.dat supprimé !


      * Dans "C:\Documents and Settings\Maëlle\locals~1\applic~1" *


      *** Sauvegarde du Registre vers dossier Backupnavi ***

      sauvegarde du Registre réalisée avec succès !

      *** Nettoyage Registre ***

      Nettoyage Registre Ok


      *** Certificats ***

      Certificat Egroup supprimé !
      Certificat Electronic-Group supprimé !
      Certificat OOO-Favorit supprimé !

      *** Nettoyage terminé le 15/03/2008 à 19:10:28,71 ***
      0
  4. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ok j'attend clean et smitfraudfix
    @+
    0
    1. malou35000 Messages postés 9 Statut Membre
       
      Script execute en mode sans echec
      Rapport clean par Malekal_morte - http://www.malekal.com
      Script execute en mode sans echec 15/03/2008 a 19:58:35,87

      Microsoft Windows XP [version 5.1.2600]

      *** Suppression des fichiers dans C:

      *** Suppression des fichiers dans C:\WINDOWS\
      tentative de suppression de C:\WINDOWS\WMCRRS.exe

      *** Suppression des fichiers dans C:\WINDOWS\system32

      *** Suppression des fichiers dans C:\Program Files
      tentative de suppression de "C:\Program Files\Multi_Media_France\"

      *** Suppression des clefs du registre effectuee..
      *** Fin du rapport !
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. malou35000 Messages postés 9 Statut Membre
     
    SmitFraudFix v2.304

    Rapport fait à 20:08:41,37, 15/03/2008
    Executé à partir de C:\Documents and Settings\Ma‰lle\Bureau\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\PROGRA~1\Wanadoo\CnxMon.exe
    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
    C:\Program Files\Eraser\Eraser.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\bgsvcgen.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\cmd.exe
    C:\Program Files\Mozilla Firefox\firefox.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ma‰lle

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ma‰lle\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MALLE~1\Favoris

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

    »»»»»»»»»»»»»»»»»»»»»»»» Rustock

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: RCA USB Cable Modem - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 82.216.111.122
    DNS Server Search Order: 82.216.111.123
    DNS Server Search Order: 82.216.111.124
    DNS Server Search Order: 82.216.111.125
    DNS Server Search Order: 82.216.111.121

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{43651CE2-9894-4B3B-B02A-1409AB6D0632}: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{43651CE2-9894-4B3B-B02A-1409AB6D0632}: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
    HKLM\SYSTEM\CS2\Services\Tcpip\..\{2DC2A048-1EE1-40AC-A1D9-B65D560D0160}: DhcpNameServer=193.54.111.8 10.75.2.221
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{43651CE2-9894-4B3B-B02A-1409AB6D0632}: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=193.54.111.8 10.75.2.221
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin
    0
  7. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Télécharge Brute Force Uninstaller (de Merijn) ici: http://www.merijn.org/files/bfu.zip
    Créé un nouveau dossier directement à la racine de ton disque dur ou l'endroit qui te convient, nomme ce dossier BFU. Décompresse le fichier téléchargé dans ce nouveau dossier (par exemple C:\BFU)
    Ensuite, télécharge Winsoftware.bfu (de lazzzy) :
    Fais un clik droit ici : : http://www.alt-shift-return.org/Info/Fichiers/Winsoftware.bfu
    et choisis "Enregistrer la cible sous..." afin de télécharger Winsoftware.bfu (delazzzy).
    Sauvegarde dans le dossier créé (C:\BFU).
    **Note : si tu utilises Internet Explorer ; lors de la sauvegarde, assure-toi que le champs "Type :" affiche "Tous les fichiers".

    Tu dois maintenant avoir deux fichiers dans le dossier C:\BFU : Winsoftware.bfu et BFU.exe (très important).

    -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-

    Tu as une démo animée ici (merci balltrap34):
    http://perso.orange.fr/rginformatique/section%20virus/bfu%20demo.htm
    _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
    Lance "Brute Force Uninstaller" en double-cliquant BFU.exe (Dans le dossier C:\BFU)
    - Clique sur le petit dossier jaune, et clique sur : Winsoftware.bfu
    - Coches la case Show log after scrïpt ends
    - Clique sur Execute pour que le fix fasse son boulot :-) Attends que le message Complete scrïpt execution apparaîsse et clique sur OK.
    Un rapport va s'afficher dans la fenetre du programme, copie et colle dans le bloc-notes, puis sauvegardes le, tu le posteras plus tard sur le forum.
    Clique Exit pour fermer le programme BFU.

    @+
    0
  8. malou35000 Messages postés 9 Statut Membre
     
    BFU v1.11.0
    Windows XP SP2 (WinNT 5.01.2600 SP2)
    Script started at 20:49:34, on 15/03/2008

    Option Unload Explorer: Yes
    Success: ProcessKillByPID 4020
    Success: ProcessKill C:\WINDOWS\explorer.exe|1
    Warning: The following line has unexpanded aliases and will be skipped: # Winsoftware.bfu
    # lazzzy 20/09/2006
    # Ce script cible ErrorSafe / Winfixer / ErrorGuard / DriveCleaner / SystemDoctor / WinAntiVirusPro / WinAntiSpyware / SysProtect

    OptionUnloadShell

    # 1 - Processus

    ProcessKill \AdwareProtector.exe|1
    ProcessKill \ErrorGuard.exe|1
    ProcessKill \ERScw.exe|1
    ProcessKill C:\Program Files\WinAntiVirus Pro 2006\fat.exe|1
    ProcessKill \sd2006.exe|1
    ProcessKill \SDR6cw.exe|1
    ProcessKill \SDRmon.exe|1
    ProcessKill C:\Program Files\SystemDoctor 2006 Free\startmon.exe|1
    ProcessKill C:\WINDOWS\Downloaded Program Files\U*_*_*NetInstaller.exe|1
    ProcessKill C:\Program Files\systemdoctor 2006 free\updater.exe|1
    ProcessKill C:\Program Files\DriveCleaner 2006 Free\UDC2006.exe|1
    ProcessKill C:\Program Files\DriveCleaner 2006 Free\udc6cw.exe|1
    ProcessKill C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe|1
    ProcessKill C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe|1
    ProcessKill C:\Program Files\WinAntiSpyware 2006 Scanner\updater.exe|1
    ProcessKill C:\Program Files\SystemDoctor 2006 Free\usdr6cw.exe|1
    ProcessKill C:\Program Files\SysProtect Free\USYP.exe|1
    ProcessKill C:\Program Files\WinAntiVirus Pro 2006\uwa6pcw.exe|1
    ProcessKill uwasffNT.exe|1
    ProcessKill \was6.exe|1
    ProcessKill \WinAV.exe|1
    ProcessKill \WinPG2005.exe|1

    # 2 - Services

    ServiceStop FWSvc
    ServiceDisable FWSvc
    ServiceDelete FWSvc

    # 3 - Registre

    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|AdwareProtector
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe Free
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|ErrorSafeFree
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_N57M1212
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect Free
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2006
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer2005
    RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinPopupGuard 2005

    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cmonitor
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|CompanionWizard
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dc6_check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DC6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dc6v_check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DC6Y_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DriveCleaner 2006 Free
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ErrorGuard
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ErrorSafe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ERS_check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ERScw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|fat.exe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Firewall
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MDRV_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MDRY_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MNI.UWFX5LP_0001_0614
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UAVIFR_0001_N105M2404
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERS_0001_NI57M1124
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSM_0001_N57M0112
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSM_0001_N68M1602
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_LP
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N68M0602
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N91M2107
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N91S2108
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_9999_N91S1912
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSY_0001_N68M0602
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UGA6PV_0001_N108M0207
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ni.usyp
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.USYP_0002_N91M1708
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.USYP_0003_N91M0908
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA6PV_0001_N91M2107
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA6PY_0001_N73M0604
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA7PV_0001_N91M0510
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA7PV_0001_N96M0206
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6V_0001_N76M1904
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6V_0001_N91M2208
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6Y_0001_N91M2208
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_0802
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_N57M1412
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX6_0001_N68M2301
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|PAS_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|rtasks
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Salestart
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6V_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6Y_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006 Free
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|udc6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|UERScw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uga6pcw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|usdr6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uwa6pcw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uwas6cw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|wa6pcw
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WA6PV_Check
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006 Free
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006 Scanner
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiVirusPro2006
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiVirus Pro 2007
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2006
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer2005

    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|fat.exe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|fat_reinstall
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|WinAntiSpyware 2006 Scanner

    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\ErrorSafe\esPCheck.dll
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\common files\winantivirus pro 2006\wapchk.dll
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\WinAntiSpyware 2006 Scanner\uwasffNT.exe
    RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\WINDOWS\system32\drivers\uwasfsd.sys

    RegDeleteKey HKCR\antiviruscom.avofficeprotect
    RegDeleteKey HKCR\antiviruscom.avofficeprotect.1
    RegDeleteKey HKCR\avexplorer.shellextension
    RegDeleteKey HKCR\avexplorer.shellextension.2
    RegDeleteKey HKCR\avexplorer.shellextension\curver
    RegDeleteKey HKCR\checkprod.checkproduct
    RegDeleteKey HKCR\CheckProduct2.CheckProduct
    RegDeleteKey HKCR\CheckProduct2.CheckProduct.1
    RegDeleteKey HKCR\ComCleanCor.AppCleane
    RegDeleteKey HKCR\ComCleanCor.AppCleane.1
    RegDeleteKey HKCR\ComCleanCor.CQuickScan
    RegDeleteKey HKCR\ComCleanCor.CQuickScan.1
    RegDeleteKey HKCR\ComCleanCor.FileCleane
    RegDeleteKey HKCR\ComCleanCor.InetCleane
    RegDeleteKey HKCR\ComCleanCor.InetCleane.1
    RegDeleteKey HKCR\ComCleanCor.RegCleane
    RegDeleteKey HKCR\ComCleanCor.RegCleane.1
    RegDeleteKey HKCR\ComCleanCor.SystemCleane
    RegDeleteKey HKCR\ComCleanCor.SystemCleane.1
    RegDeleteKey HKCR\ComCleanCore.FileClean.1
    RegDeleteKey HKCR\CompCleanCore.AppCleaner
    RegDeleteKey HKCR\CompCleanCore.AppCleaner.1
    RegDeleteKey HKCR\CompCleanCore.CCQuickScan
    RegDeleteKey HKCR\CompCleanCore.CCQuickScan.1
    RegDeleteKey HKCR\CompCleanCore.FileCleaner
    RegDeleteKey HKCR\CompCleanCore.FileCleaner.1
    RegDeleteKey HKCR\CompCleanCore.InetCleaner
    RegDeleteKey HKCR\CompCleanCore.InetCleaner.1
    RegDeleteKey HKCR\CompCleanCore.RegCleaner
    RegDeleteKey HKCR\CompCleanCore.RegCleaner.1
    RegDeleteKey HKCR\CompCleanCore.SystemCleaner
    RegDeleteKey HKCR\CompCleanCore.SystemCleaner.1
    RegDeleteKey HKCR\df_fixer.Fixer
    RegDeleteKey HKCR\df_fixer.Fixer.1
    RegDeleteKey HKCR\df_proxy.DriverManipulate
    RegDeleteKey HKCR\df_proxy.DriverManipulate.1
    RegDeleteKey HKCR\df_fix.Fix
    RegDeleteKey HKCR\df_fix.Fix.1
    RegDeleteKey HKCR\df_prx.DriverManipulat
    RegDeleteKey HKCR\df_prx.DriverManipulat.1
    RegDeleteKey HKCR\escompcleancore.esappcleaner
    RegDeleteKey HKCR\escompcleancore.esappcleaner.1
    RegDeleteKey HKCR\escompcleancore.esccquickscan
    RegDeleteKey HKCR\escompcleancore.esccquickscan.1
    RegDeleteKey HKCR\escompcleancore.esfilecleaner
    RegDeleteKey HKCR\escompcleancore.esfilecleaner.1
    RegDeleteKey HKCR\escompcleancore.esinetcleaner
    RegDeleteKey HKCR\escompcleancore.esinetcleaner.1
    RegDeleteKey HKCR\escompcleancore.esregcleaner
    RegDeleteKey HKCR\escompcleancore.esregcleaner.1
    RegDeleteKey HKCR\escompcleancore.essystemcleaner
    RegDeleteKey HKCR\escompcleancore.essystemcleaner.1
    RegDeleteKey HKCR\esdf_fixer.esfixer
    RegDeleteKey HKCR\esdf_fixer.esfixer.1
    RegDeleteKey HKCR\esdf_proxy.esdrivermanipulate
    RegDeleteKey HKCR\esdf_proxy.esdrivermanipulate.1
    RegDeleteKey HKCR\esffwraper.esffenginwraper
    RegDeleteKey HKCR\esffwraper.esffenginwraper.1
    RegDeleteKey HKCR\esfixcore.esmmfixcore
    RegDeleteKey HKCR\esfixcore.esmmfixcore.1
    RegDeleteKey HKCR\esmmfixctrl.escofixengine
    RegDeleteKey HKCR\esmmfixctrl.escofixengine.1
    RegDeleteKey HKCR\esspchck.esspchck
    RegDeleteKey HKCR\esspchck.esspchck.1
    RegDeleteKey HKCR\esspcheck.esspcheck
    RegDeleteKey HKCR\esspcheck.esspcheck.1
    RegDeleteKey HKCR\FFCom.FlFixer
    RegDeleteKey HKCR\FFWraper.FFEnginWraper
    RegDeleteKey HKCR\FFWrap.FEnginWrape
    RegDeleteKey HKCR\FFWrap.FEnginWrape.1
    RegDeleteKey HKCR\FFWraper.FFEnginWraper.1
    RegDeleteKey HKCR\FFxr_21.FFixr21
    RegDeleteKey HKCR\FixCor.MMFxCor
    RegDeleteKey HKCR\FixCor.MMFxCor.1
    RegDeleteKey HKCR\FixCore.MMFixCore
    RegDeleteKey HKCR\FixCore.MMFixCore.1
    RegDeleteKey HKCR\FlFxr3.FlFixer3
    RegDeleteKey HKCR\flfxr5.flfixer5
    RegDeleteKey HKCR\FlFxr15.FlFixer15
    RegDeleteKey HKCR\FWrape_r.FFEnginWrape_r
    RegDeleteKey HKCR\FWrape_r.FFEnginWrape_r.1
    RegDeleteKey HKCR\FWraper.FFEnginWraper
    RegDeleteKey HKCR\FWraper.FFEnginWraper.1
    RegDeleteKey HKCR\FxCor_e.MMFixCor_e.1
    RegDeleteKey HKCR\FxCor_e.MMFixCor_e
    RegDeleteKey HKCR\FxCore.MMFixCore
    RegDeleteKey HKCR\FxCore.MMFixCore.1
    RegDeleteKey HKCR\iefwbho.iefw
    RegDeleteKey HKCR\iefwbho.iefw.2
    RegDeleteKey HKCR\Install.Install
    RegDeleteKey HKCR\Install.Install.1
    RegDeleteKey HKCR\MMFixCtrl.CoFixEngine
    RegDeleteKey HKCR\MMFixCtrl.CoFixEngine.1
    RegDeleteKey HKCR\MMFx.CoFxEngin
    RegDeleteKey HKCR\MMFx.CoFxEngin.1
    RegDeleteKey HKCR\MMFxCtr_l.CoFixEngin_e
    RegDeleteKey HKCR\MMFxCtr_l.CoFixEngin_e.1
    RegDeleteKey HKCR\systemdoctor.free
    RegDeleteKey HKCR\UWFX6PCheck.UWFX6PCheck.2
    RegDeleteKey HKCR\UWFXCheck.UWFXCheck
    RegDeleteKey HKCR\UWFXCheck.UWFXCheck.1
    RegDeleteKey HKCR\wap6.pcheck
    RegDeleteKey HKCR\wap6.pcheck.1
    RegDeleteKey HKCR\winpgintegrator.ieintegrator
    RegDeleteKey HKCR\winpgintegrator.ieintegrator.1

    RegDeleteKey HKCR\AppID\{25A3C995-10C8-474B-A167-99460AB4AB2B}
    RegDeleteKey HKCR\AppID\{287A2BAD-6590-4EFF-9BBC-494385664A73}
    RegDeleteKey HKCR\AppID\{290B5B73-4963-4BA1-9D2D-07CB566CB7FA}
    RegDeleteKey HKCR\AppID\{367a86a5-d048-4785-86be-4e2706aafdd9}
    RegDeleteKey HKCR\AppID\{3C132D19-6103-4fc3-8326-34E13EE9E2C0}
    RegDeleteKey HKCR\AppID\{4f5e5d72-c915-4f3b-908b-527d064b0faa}
    RegDeleteKey HKCR\AppID\{8C65AEF6-E413-4314-815B-82717A3F1603}
    RegDeleteKey HKCR\AppID\{AAB0BA34-6D48-425f-B4B4-98F158CB61F1}
    RegDeleteKey HKCR\AppID\{DED71DE6-0575-4556-8311-A506B116A1A9}
    RegDeleteKey HKCR\AppID\{E8928E69-C050-42A9-8884-94DE85E888A2}
    RegDeleteKey HKCR\AppID\{E11FF09D-39AF-4613-86AD-F3217E576571}
    RegDeleteKey HKCR\AppID\CheckProduct2.DLL
    RegDeleteKey HKCR\AppID\compcln.dll
    RegDeleteKey HKCR\AppID\compclr.dll
    RegDeleteKey HKCR\AppID\FFWrapr.DLL
    RegDeleteKey HKCR\AppID\FFWraper.DLL
    RegDeleteKey HKCR\AppID\FixCore.DLL
    RegDeleteKey HKCR\AppID\FxCr.DLL
    RegDeleteKey HKCR\AppID\MFix.DLL
    RegDeleteKey HKCR\AppID\MMFixCtrl.DLL
    RegDeleteKey HKCR\AppID\winpgi.dll appid

    RegDeleteKey HKCR\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
    RegDeleteKey HKCR\CLSID\{0ba379c6-0efd-4a28-932c-d20469052fd9}
    RegDeleteKey HKCR\CLSID\{0bc09fc7-473d-4f9c-b49b-f4e3e244b47a}
    RegDeleteKey HKCR\CLSID\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
    RegDeleteKey HKCR\CLSID\{151a44b0-fc2d-4a02-bbbc-6b372f2f659c}
    RegDeleteKey HKCR\CLSID\{1640de0e-75e4-4a83-b5d1-2492bc7eba8f}
    RegDeleteKey HKCR\CLSID\{196c80cb-20a7-4cf9-9c98-9322fb1e35fb}
    RegDeleteKey HKCR\CLSID\{1ac5c88a-dea7-462b-a232-04af5ca42e7e}
    RegDeleteKey HKCR\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
    RegDeleteKey HKCR\CLSID\{205FF73B-CA67-11D5-99DD-444553540006}
    RegDeleteKey HKCR\CLSID\{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
    RegDeleteKey HKCR\CLSID\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
    RegDeleteKey HKCR\CLSID\{356af2e9-8874-4c60-a3d8-0cb516c9e747}
    RegDeleteKey HKCR\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
    RegDeleteKey HKCR\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
    RegDeleteKey HKCR\CLSID\{5284ac2a-ef00-4750-9b82-b5b907d26536}
    RegDeleteKey HKCR\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
    RegDeleteKey HKCR\CLSID\{53ABACCB-434C-4756-A02B-8C2A3F29FB7D}
    RegDeleteKey HKCR\CLSID\{5A1C8180-2A52-470c-938C-BFB4E63AA32D}
    RegDeleteKey HKCR\CLSID\{5e19dee2-8d2f-4a9c-a66d-76bbeedd15cb}
    RegDeleteKey HKCR\CLSID\{647b8364-79e0-48e2-a4ca-233abada0c2d}
    RegDeleteKey HKCR\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
    RegDeleteKey HKCR\CLSID\{6F85DDE5-A2DE-4217-A05D-0A7CD3C04DC2}
    RegDeleteKey HKCR\CLSID\{723d54c7-7483-4eb8-8eed-ce5b2aea534d}
    RegDeleteKey HKCR\CLSID\{72D597C4-2312-4116-BED4-4F9A2B2F710E}
    RegDeleteKey HKCR\CLSID\{77ca442a-0c72-492b-804a-82611e558142}
    RegDeleteKey HKCR\CLSID\{7e73c9db-69fb-4580-8e8e-194b34a2306c}
    RegDeleteKey HKCR\CLSID\{7F208C01-1FB1-4BC8-B918-82E287B0BB79}
    RegDeleteKey HKCR\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
    RegDeleteKey HKCR\CLSID\{861D5757-3A7E-4c46-966E-8CD53A0D0013}
    RegDeleteKey HKCR\CLSID\{8E3A1531-F462-4628-ADD8-D32984637641}
    RegDeleteKey HKCR\CLSID\{965a8d33-ae18-4c17-8011-fe42d81e0758}
    RegDeleteKey HKCR\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
    RegDeleteKey HKCR\CLSID\{9e87077c-380c-407d-8dab-eedad95c0a5d}
    RegDeleteKey HKCR\CLSID\{9F3D2A3C-D537-482b-A91B-44EE29F09C4B}
    RegDeleteKey HKCR\CLSID\{A99498D2-56E1-4e27-AC88-2328C6A87C7C}
    RegDeleteKey HKCR\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
    RegDeleteKey HKCR\CLSID\{ABC72615-4FB0-4689-AED9-AA6B89CEBC2C}
    RegDeleteKey HKCR\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
    RegDeleteKey HKCR\CLSID\{B296F12B-48A9-45fb-A860-4B98707B47AE}
    RegDeleteKey HKCR\CLSID\{b2a3156e-3332-4b47-af5a-5b121503514f}
    RegDeleteKey HKCR\CLSID\{B36E6241-4D02-41FF-A16D-9B57E67D7B15}
    RegDeleteKey HKCR\CLSID\{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
    RegDeleteKey HKCR\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
    RegDeleteKey HKCR\CLSID\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
    RegDeleteKey HKCR\CLSID\{B8CA1E6C-87E2-4435-9E56-8B791EC459D8}
    RegDeleteKey HKCR\CLSID\{c033567c-68fe-419b-bcc4-135db7faf8eb}
    RegDeleteKey HKCR\CLSID\{C08FA317-C152-4fea-AC0B-2EA68D2B1C84}
    RegDeleteKey HKCR\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
    RegDeleteKey HKCR\CLSID\{C427B3E3-28DC-4001-9590-D99B6776119B}
    RegDeleteKey HKCR\CLSID\{c85a4afd-ff76-4661-b76a-3e9bb2ce2dab}
    RegDeleteKey HKCR\CLSID\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
    RegDeleteKey HKCR\CLSID\{ccaabcdd-7c16-4215-b12e-150bfb994cf0}
    RegDeleteKey HKCR\CLSID\{D4EA0C00-3BC8-4B26-8D2E-C5512B07A211}
    RegDeleteKey HKCR\CLSID\{e73e3959-fb15-44d7-acb9-3a75377006fc}
    RegDeleteKey HKCR\CLSID\{EAB5DB02-08F5-4e7d-81F9-75B9462FAAE3}
    RegDeleteKey HKCR\CLSID\{ef130e77-0a34-4365-bfb7-218fd3ddcd5f}
    RegDeleteKey HKCR\CLSID\{F0ED6398-E5F8-4ef8-BAB9-FE9BBCE7EF3E}
    RegDeleteKey HKCR\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
    RegDeleteKey HKCR\CLSID\{f63e3b76-f82f-46eb-851c-8c0a221686bb}
    RegDeleteKey HKCR\CLSID\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

    RegDeleteKey HKCR\Interface\{08C71FB1-1E66-4D22-9F32-4C045A451306}
    RegDeleteKey HKCR\Interface\{02946fd1-2d99-46e6-a790-3a089714edd9}
    RegDeleteKey HKCR\Interface\{0b9a27eb-125f-4f3e-a35c-2769c47a1442}
    RegDeleteKey HKCR\Interface\{1CE1C25B-F8B4-4974-99D2-5D4AE96B9900}
    RegDeleteKey HKCR\Interface\{35096C29-3507-4ABE-B6D8-C7CC881BE020}
    RegDeleteKey HKCR\Interface\{38F743A2-210F-49DE-9B79-DCD501CED284}
    RegDeleteKey HKCR\Interface\{3EEC290D-FC13-4C83-803D-4802651EEB61}
    RegDeleteKey HKCR\Interface\{41A5BBF6-3C9D-4CF9-9A99-32DD37CC290B}
    RegDeleteKey HKCR\Interface\{4E4F38D9-8736-41AE-B192-E829AE194398}
    RegDeleteKey HKCR\Interface\{4F79D1C5-24F9-4E59-8022-604D4B41D5CA}
    RegDeleteKey HKCR\Interface\{66484903-09F4-4330-927D-1F6C214221AC}
    RegDeleteKey HKCR\Interface\{7FA14AD6-D8E5-465F-9BD1-A37E26C1A74F}
    RegDeleteKey HKCR\Interface\{9E984934-CD94-4763-9DBC-618E483D4B7F}
    RegDeleteKey HKCR\Interface\{B115BD8E-B008-46F4-B8B6-3405EB325C3C}
    RegDeleteKey HKCR\Interface\{B9DFCF32-B679-4CAD-B7FC-518A48CE3922}
    RegDeleteKey HKCR\Interface\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
    RegDeleteKey HKCR\Interface\{CBEEF194-EBC5-4758-9B51-AC34FC135E70}
    RegDeleteKey HKCR\Interface\{CD3604CC-2B95-43EE-AFC9-E7444C21BE1C}
    RegDeleteKey HKCR\Interface\{D21040FE-0A57-4FAB-8ED2-F0E653E55809}
    RegDeleteKey HKCR\Interface\{D7A2488E-53E4-4EDD-AEAA-F24778BEB100}
    RegDeleteKey HKCR\Interface\{D7A6DF8D-B6CF-4C27-8E99-ECA2CE370EA7}
    RegDeleteKey HKCR\Interface\{e18b69d0-7e9e-4c6e-bdd8-879a1fff7123}
    RegDeleteKey HKCR\Interface\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
    RegDeleteKey HKCR\Interface\{F6C1582E-B11C-4724-B8F6-240457EF1D2A}
    RegDeleteKey HKCR\Interface\{FB787D5E-0C7C-4BAB-B45D-20325FB886DB}
    RegDeleteKey HKCR\Interface\{24F3E817-2C07-4CB5-975D-F23FCFAEDE51}
    RegDeleteKey HKCR\Interface\{3BB63444-FD94-4C31-9D6F-0DA76CB11D70}
    RegDeleteKey HKCR\Interface\{3C2656F4-8601-42B6-BDC3-DEC901E21C80}
    RegDeleteKey HKCR\Interface\{471D3AEF-F18C-4626-A7DB-320732ACC763}
    RegDeleteKey HKCR\Interface\{490E59CC-F6D5-4987-BBC8-E1A6D599C3F8}
    RegDeleteKey HKCR\Interface\{68A7506D-DF03-4DF0-BE96-02BCB918EA7D}
    RegDeleteKey HKCR\Interface\{74ECF6F4-62C5-48BA-945E-B20A97239A5E}
    RegDeleteKey HKCR\Interface\{7A66E632-E262-4986-A936-CC636282F138}
    RegDeleteKey HKCR\Interface\{7D9DFDB3-5135-4279-B365-3CEEA4AC1EAC}
    RegDeleteKey HKCR\Interface\{7F208C01-1FB1-4BC8-B918-82E287B0BB79}
    RegDeleteKey HKCR\Interface\{7f4e63c9-f30c-4424-9baf-b6896f5f56c4}
    RegDeleteKey HKCR\Interface\{81A7D75C-9768-41C3-AE0F-8B108D802B62}
    RegDeleteKey HKCR\Interface\{86786BEC-544D-473F-8D93-8E7AC0685361}
    RegDeleteKey HKCR\Interface\{92B92664-32D6-4FCE-B2CE-C8519BAEFC4E}
    RegDeleteKey HKCR\Interface\{94dbdb63-5f05-4c51-8b14-de0ca12ef4ca}
    RegDeleteKey HKCR\Interface\{B0725565-2694-43EC-B1AB-0245762C9860}
    RegDeleteKey HKCR\Interface\{B26CA1F6-2D46-49AE-9897-9C5B7CCAB9FB}
    RegDeleteKey HKCR\Interface\{B36E6241-4D02-41FF-A16D-9B57E67D7B15}
    RegDeleteKey HKCR\Interface\{CADCB2CC-0B7E-45B1-A689-A0AD9CE5932D}
    RegDeleteKey HKCR\Interface\{D3390AE7-6F1D-464F-8921-AF9A85EED316}
    RegDeleteKey HKCR\Interface\{D4EA0C00-3BC8-4B26-8D2E-C5512B07A211}
    RegDeleteKey HKCR\Interface\{DB064061-95F1-4BAF-BEC9-F70792E01094}
    RegDeleteKey HKCR\Interface\{F3067DE7-3DBA-4DF8-9FA0-6B0200BAA324}
    RegDeleteKey HKCR\Interface\{f5ac8b35-5b15-4e8f-8046-43858973b495}
    RegDeleteKey HKCR\Interface\{FE899520-E9F9-4CD9-AABB-E9074815CF50}

    RegDeleteKey HKCR\TypeLib\{04392304-5221-4022-9300-be4128fb25b2}
    RegDeleteKey HKCR\TypeLib\{0E9F6AC0-A21A-4591-910F-E2C6F3CA094C}
    RegDeleteKey HKCR\TypeLib\{1234890a-5e6e-4867-8136-ca6f1456b235}
    RegDeleteKey HKCR\TypeLib\{1b197c22-561f-455f-8511-35b1a45c5c9f}
    RegDeleteKey HKCR\TypeLib\{17E55F3A-20AB-4668-A75F-DC96377AE16C}
    RegDeleteKey HKCR\TypeLib\(205FF72E-CA67-11D5-99DD-444553540006)
    RegDeleteKey HKCR\TypeLib\{248FDD41-4E0A-4138-9086-6CF5D6FA8179}
    RegDeleteKey HKCR\TypeLib\{25BAE2A9-DF54-4927-AF6F-9963146D11D8}
    RegDeleteKey HKCR\TypeLib\{2bc32ef8-bb73-4099-bb2e-0f2951b3e276}
    RegDeleteKey HKCR\TypeLib\{30ED49A5-CA6C-4918-B5F3-5E6818C91D8B}
    RegDeleteKey HKCR\TypeLib\{367a86a5-d048-4785-86be-4e2706aafdd9}
    RegDeleteKey HKCR\TypeLib\{371EFE75-C183-4D0C-B8CD-2DFAFEEB34D7}
    RegDeleteKey HKCR\TypeLib\{49f9ffb5-514d-4b69-b31d-2ae5a7d30ae6}
    RegDeleteKey HKCR\TypeLib\{4DCEEA42-794D-4855-9ECC-20DCF5F4FEA7}
    RegDeleteKey HKCR\TypeLib\{5F638503-4F2E-48F8-9210-9865AF4AD020}
    RegDeleteKey HKCR\TypeLib\{68bc55e9-4d3e-4c89-89ac-7559763c98b8}
    RegDeleteKey HKCR\TypeLib\{692ca430-32c8-470d-ba1f-7e15e21e7043}
    RegDeleteKey HKCR\TypeLib\{6A077841-5016-42C8-92C8-F2D6B865BCD1}
    RegDeleteKey HKCR\TypeLib\{6bd7e052-306e-497a-ad23-601bc6bfc305}
    RegDeleteKey HKCR\TypeLib\{6F9DB588-66C5-4904-A2C7-423961358E8C}
    RegDeleteKey HKCR\TypeLib\{732b6533-7f78-4c47-9c01-2979ba0829b9}
    RegDeleteKey HKCR\TypeLib\{77dc6558-60e0-4644-a3df-b31f29d113bd}
    RegDeleteKey HKCR\TypeLib\{7eacf70b-302f-4049-ac68-2d62eb43e473}
    RegDeleteKey HKCR\TypeLib\{8D67C4E4-AAD6-46A1-812F-D7D21BBB4624}
    RegDeleteKey HKCR\TypeLib\{9dd86cf2-8ac0-4fe0-b55a-601a302b5fd8}
    RegDeleteKey HKCR\TypeLib\{a73973ab-95a6-4abe-a046-de3bab2be448}
    RegDeleteKey HKCR\TypeLib\{AD70AC89-F460-4E7E-B5A5-7EAF7E207736}
    RegDeleteKey HKCR\TypeLib\{B6625280-8CD8-4632-97C0-83CEC12A49A3}
    RegDeleteKey HKCR\TypeLib\{D49C1A5F-26CF-482E-81EE-1D4C9B057BD2}
    RegDeleteKey HKCR\TypeLib\{F458ADAE-D53B-4859-B99F-9FA127791278}
    RegDeleteKey HKCR\TypeLib\{FC76A5B8-DB35-4F3E-8B9A-BF0EEA098D64}

    RegDeleteKey HKCU\Software\ErrorGuard
    RegDeleteKey HKCU\Software\errorsafe
    RegDeleteKey HKCU\Software\error safe free
    RegDeleteKey HKCU\Software\sysprotect free
    RegDeleteKey HKCU\Software\SystemDoctor 2006 Free
    RegDeleteKey HKCU\Software\WinAntiSpyware 2006 Scanner
    RegDeleteKey HKCU\Software\WinAntiVirus Pro 2006
    RegDeleteKey HKCU\Software\WinFixer 2005
    RegDeleteKey HKCU\Software\WinSoftware

    RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{205ff73b-ca67-11d5-99dd-444553540006}
    RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}

    RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\SystemDoctor 2006 Unregistered

    RegDeleteKey HKLM\Software\DriveCleaner 2006 Free
    RegDeleteKey HKLM\Software\ErrorSafe
    RegDeleteKey HKLM\Software\Error Safe Free
    RegDeleteKey HKLM\Software\sysprotect
    RegDeleteKey HKLM\Software\SystemDoctor 2006 Free
    RegDeleteKey HKLM\Software\WinAntiSpyware 2006 Scanner
    RegDeleteKey HKLM\Software\winantivirus pro 2006
    RegDeleteKey HKLM\Software\WinSoftware

    RegDeleteKey HKLM\Software\Classes\checkprod.checkproduct
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.AppCleaner
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.CCQuickScan
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.CCQuickScan.1
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.FileCleaner
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.FileCleaner.1
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.InetCleaner\CLSID
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.InetCleaner.1
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.RegCleaner
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.RegCleaner.1
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.SystemCleaner
    RegDeleteKey HKLM\Software\Classes\ComCleanCore.SystemCleaner.1
    RegDeleteKey HKLM\Software\Classes\df_fixr.Fixer
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESAppCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESAppCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESCCQuickScan
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESCCQuickScan.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESFileCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESFileCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESInetCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESInetCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESRegCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESRegCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESSystemCleaner
    RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESSystemCleaner.1
    RegDeleteKey HKLM\Software\Classes\ESdf_fixer.ESFixer
    RegDeleteKey HKLM\Software\Classes\ESdf_fixer.ESFixer.1
    RegDeleteKey HKLM\Software\Classes\ESdf_proxy.ESDriverManipulate
    RegDeleteKey HKLM\Software\Classes\ESdf_proxy.ESDriverManipulate.1
    RegDeleteKey HKLM\Software\Classes\ESFFWraper.ESFFEnginWraper
    RegDeleteKey HKLM\Software\Classes\ESFFWraper.ESFFEnginWraper.1
    RegDeleteKey HKLM\Software\Classes\ESFixCore.ESMMFixCore
    RegDeleteKey HKLM\Software\Classes\ESFixCore.ESMMFixCore.1
    RegDeleteKey HKLM\Software\Classes\ESMMFixCtrl.ESCoFixEngine
    RegDeleteKey HKLM\Software\Classes\ESMMFixCtrl.ESCoFixEngine.1
    RegDeleteKey HKLM\Software\Classes\ESSPCheck.ESSPCheck
    RegDeleteKey HKLM\Software\Classes\ESSPCheck.ESSPCheck.1
    RegDeleteKey HKLM\Software\Classes\FFWraper.FFEnginWrapr
    RegDeleteKey HKLM\Software\Classes\FixCor.MMFixCore
    RegDeleteKey HKLM\Software\Classes\FlFxr5.FlFixer5
    RegDeleteKey HKLM\Software\Classes\FlFxr10.FlFixer10
    RegDeleteKey HKLM\Software\Classes\MMFixCtrl.CoFixEngin2
    RegDeleteKey HKLM\Software\Classes\SystemDoctor.Free
    RegDeleteKey HKLM\Software\Classes\UDCPChk.UDCPChk
    RegDeleteKey HKLM\Software\Classes\UDCPChk.UDCPChk.1
    RegDeleteKey HKLM\Software\Classes\UDCShell
    RegDeleteKey HKLM\Software\Classes\UWAS6.UWAS6
    RegDeleteKey HKLM\Software\Classes\uwasfsd.CreationNotifier
    RegDeleteKey HKLM\Software\Classes\uwasfsd.CreationNotifier.1
    RegDeleteKey HKLM\Software\Classes\uwashellext.ShellHook
    RegDeleteKey HKLM\Software\Classes\uwashellext.ShellHook.1
    RegDeleteKey HKLM\Software\Classes\uwashellext.WASContextMenu
    RegDeleteKey HKLM\Software\Classes\uwashellext.WASContextMenu.1
    RegDeleteKey HKLM\Software\Classes\wasfsd.CreationNotifier
    RegDeleteKey HKLM\Software\Classes\wasfsd.CreationNotifier.1
    RegDeleteKey HKLM\Software\Classes\washellext.WASContextMenu
    RegDeleteKey HKLM\Software\Classes\washellext.WASContextMenu.1
    RegDeleteKey HKLM\Software\Classes\WASPChk.WASPChk

    RegDeleteKey HKLM\Software\Classes\*\shellex\ContextMenuHandlers\UDCShell

    RegDeleteKey HKLM\Software\Classes\AppID\{1C02CE6B-CC12-4ea1-B2D8-113F611F25C2}
    RegDeleteKey HKLM\Software\Classes\AppID\{4f5e5d72-c915-4f3b-908b-527d064b0faa}
    RegDeleteKey HKLM\Software\Classes\AppID\{8A1E94DA-725D-4f64-B110-DB3F73ADB6F7}
    RegDeleteKey HKLM\Software\Classes\AppID\{E7E155EE-EEF2-46af-99B7-65F1269DC3CF}
    RegDeleteKey HKLM\Software\Classes\AppID\{EE10A303-0C60-4acb-A033-95A790FA4DCD}
    RegDeleteKey HKLM\Software\Classes\AppID\checkproduct2_1.dll

    RegDeleteKey HKLM\Software\Classes\CLSID\{_CLSID_WAShellExecuteCheck}
    RegDeleteKey HKLM\Software\Classes\CLSID\{05324ED1-05C0-4e3a-A34F-98BFC64426F5}
    RegDeleteKey HKLM\Software\Classes\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
    RegDeleteKey HKLM\Software\Classes\CLSID\{0D7DE254-2FBD-4C09-9077-3DC4A2DEBE9D}
    RegDeleteKey HKLM\Software\Classes\CLSID\{1230649B-B980-44A5-B259-9B09EBEA6331}
    RegDeleteKey HKLM\Software\Classes\CLSID\{1236DE55-EDED-4675-AF10-BA15EDDB4D7A}
    RegDeleteKey HKLM\Software\Classes\CLSID\{184B0A26-4C9C-4757-ABF5-4B6AF71F9A45}
    RegDeleteKey HKLM\Software\Classes\CLSID\{18A41B20-E519-47a1-B545-FFC200730E9B}
    RegDeleteKey HKLM\Software\Classes\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
    RegDeleteKey HKLM\Software\Classes\CLSID\{2178F3FB-2560-458f-BDEE-631E2FE0DFE4}
    RegDeleteKey HKLM\Software\Classes\CLSID\{22024DC7-D190-44ec-9D49-AEE5F244A466}
    RegDeleteKey HKLM\Software\Classes\CLSID\{250D1063-5414-4fb0-86D5-AABB7A5D7DA7}
    RegDeleteKey HKLM\Software\Classes\CLSID\{2B334C22-40CA-438f-913A-61A8105C4CCD}
    RegDeleteKey HKLM\Software\Classes\CLSID\{2BF3C5AD-F9EC-49d8-8568-D7DFFC77108B}
    RegDeleteKey HKLM\Software\Classes\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
    RegDeleteKey HKLM\Software\Classes\CLSID\{43DB73EB-4C90-4418-B6AD-10DB22016908}
    RegDeleteKey HKLM\Software\Classes\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
    RegDeleteKey HKLM\Software\Classes\CLSID\{4AA76F27-81BC-4C3F-9F24-CB99349C8CC9}
    RegDeleteKey HKLM\Software\Classes\CLSID\{4F4E2384-42AD-4fe4-B966-B6D50C7BF90A}
    RegDeleteKey HKLM\Software\Classes\CLSID\{5284AC2A-EF00-4750-9B82-B5B907D26536}
    RegDeleteKey HKLM\Software\Classes\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
    RegDeleteKey HKLM\Software\Classes\CLSID\{59399E33-FB54-48AB-8AE4-AE108B36DAB4}
    RegDeleteKey HKLM\Software\Classes\CLSID\{5D178DBE-C867-417f-8A4E-D5DEFA4CD4E7}
    RegDeleteKey HKLM\Software\Classes\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
    RegDeleteKey HKLM\Software\Classes\CLSID\{6AE7418B-229F-4A2C-AE1B-D5962888F02D}
    RegDeleteKey HKLM\Software\Classes\CLSID\{6C8416A2-2408-4f4d-8D26-EC9A07E8DC98}
    RegDeleteKey HKLM\Software\Classes\CLSID\{7D435027-F646-4bf9-B2C5-0EF4940D5CA2}
    RegDeleteKey HKLM\Software\Classes\CLSID\{7EC618F2-C506-4221-9F56-792B92BF762E}
    RegDeleteKey HKLM\Software\Classes\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
    RegDeleteKey HKLM\Software\Classes\CLSID\{8DAE9202-0019-4D30-A5D2-AAF02D4DDC37}
    RegDeleteKey HKLM\Software\Classes\CLSID\{9C102B96-4845-4756-991E-4F9294965536}
    RegDeleteKey HKLM\Software\Classes\CLSID\{9CB12DAD-32C7-4f34-9758-C9FDD26D4D22}
    RegDeleteKey HKLM\Software\Classes\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
    RegDeleteKey HKLM\Software\Classes\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
    RegDeleteKey HKLM\Software\Classes\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B11}
    RegDeleteKey HKLM\Software\Classes\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B22}
    RegDeleteKey HKLM\Software\Classes\CLSID\{AE84FF0C-BABD-4D91-92A1-AF75D2D02E6D}
    RegDeleteKey HKLM\Software\Classes\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
    RegDeleteKey HKLM\Software\Classes\CLSID\{b2a3156e-3332-4b47-af5a-5b121503514f}
    RegDeleteKey HKLM\Software\Classes\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C1EA2421-BC9A-4546-943C-126F9D818EFB}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C3E2988E-1433-469d-BFC1-4080D131FE1A}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C4C4786C-9861-46d2-BB63-AC782AB07046}
    RegDeleteKey HKLM\Software\Classes\CLSID\{C833A552-F5AF-4a7b-87B3-6EBDE0DB3B43}
    RegDeleteKey HKLM\Software\Classes\CLSID\{CF080118-CDA5-429d-A8BD-EC7ECA74663F}
    RegDeleteKey HKLM\Software\Classes\CLSID\{D3377825-230D-4a12-805C-132557FA1A8B}
    RegDeleteKey HKLM\Software\Classes\CLSID\{D7136B99-FC27-4DC1-8497-5444D49B426A}
    RegDeleteKey HKLM\Software\Classes\CLSID\{DD45A464-7763-43EE-A756-5F2C93B0CF5E}
    RegDeleteKey HKLM\Software\Classes\CLSID\{E4A3F67D-5237-43fa-B3F2-41C37C1204B9}
    RegDeleteKey HKLM\Software\Classes\CLSID\{E78EA05B-B6A7-4dc4-879D-444DCD224CB4}
    RegDeleteKey HKLM\Software\Classes\CLSID\{EDF78E1B-31A2-4c6e-AD40-0AFCD0D55263}
    RegDeleteKey HKLM\Software\Classes\CLSID\{ef130e77-0a34-4365-bfb7-218fd3ddcd5f}
    RegDeleteKey HKLM\Software\Classes\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
    RegDeleteKey HKLM\Software\Classes\CLSID\{F5AB293C-2E21-4441-9AD8-B3646EB26DF5}
    RegDeleteKey HKLM\Software\Classes\CLSID\{FDA9BFC7-4ECD-43a0-AC1E-2E7DDE0C81B0}
    RegDeleteKey HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\{7EC618F2-C506-4221-9F56-792B92BF762E}

    RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ExplorerUWAS
    RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ExplorerWAS
    RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\UDCShell

    RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\ExplorerUWAS
    RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\ExplorerWAS
    RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\UDCShell

    RegDeleteKey HKLM\Software\Classes\Interface\{02946FD1-2D99-46E6-A790-3A089714EDD9}
    RegDeleteKey HKLM\Software\Classes\Interface\{0D146B7F-FA35-465D-B716-BCBC1F9A92D3}
    RegDeleteKey HKLM\Software\Classes\Interface\{12813770-461E-4A9F-8C5B-C227A8E9FBE8}
    RegDeleteKey HKLM\Software\Classes\Interface\{1562D24E-F5BF-4BB4-AF4C-BBB610B62638}
    RegDeleteKey HKLM\Software\Classes\Interface\{1BEA1806-F5C7-4696-B0A0-26CFD6A958DD}
    RegDeleteKey HKLM\Software\Classes\Interface\{258E07A2-FF65-493B-B6BD-421A1F2992A3}
    RegDeleteKey HKLM\Software\Classes\Interface\{2A1647E8-3EC2-49FE-B632-E12D765FA0CC}
    RegDeleteKey HKLM\Software\Classes\Interface\{2DECFCC9-D910-4BAC-94B8-FC006827A60F}
    RegDeleteKey HKLM\Software\Classes\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
    RegDeleteKey HKLM\Software\Classes\Interface\{4AA76F27-81BC-4C3F-9F24-CB99349C8CC9}
    RegDeleteKey HKLM\Software\Classes\Interface\{4B6A7638-0999-4924-93B7-C5738E1BAEE1}
    RegDeleteKey HKLM\Software\Classes\Interface\{5585C185-B318-4072-A00D-8385F443AE07}
    RegDeleteKey HKLM\Software\Classes\Interface\{59399E33-FB54-48AB-8AE4-AE108B36DAB4}
    RegDeleteKey HKLM\Software\Classes\Interface\{622423BD-B825-4989-BA65-86D0B990D328}
    RegDeleteKey HKLM\Software\Classes\Interface\{6813BFFD-BE81-4613-B4E6-AA7ED0DA8659}
    RegDeleteKey HKLM\Software\Classes\Interface\{7516C86C-2F3D-4724-BD4E-1608F1BDAE12}
    RegDeleteKey HKLM\Software\Classes\Interface\{7CA36000-3320-49D1-BAD1-4C5169D4084A}
    RegDeleteKey HKLM\Software\Classes\Interface\{7E7A1949-5C0C-45F3-A106-34FE038493EF}
    RegDeleteKey HKLM\Software\Classes\Interface\{8DAE9202-0019-4D30-A5D2-AAF02D4DDC37}
    RegDeleteKey HKLM\Software\Classes\Interface\{8E0A02C1-974F-4379-BFD3-69FFB9E0659D}
    RegDeleteKey HKLM\Software\Classes\Interface\{9793B356-4337-44AC-9A22-DF6A7930602C}
    RegDeleteKey HKLM\Software\Classes\Interface\{A1DDDD67-64B2-4CAB-BE0B-E34F3F12AED0}
    RegDeleteKey HKLM\Software\Classes\Interface\{A22FBA1E-CAAF-4E45-8EFF-4A821AF03E69}
    RegDeleteKey HKLM\Software\Classes\Interface\{A56B6D30-FDE0-42A9-BE6B-18B5D3F2F519}
    RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95411}
    RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95422}
    RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-D8E8-4DF1-A3EA-D0AA72F42611}
    RegDeleteKey HKLM\Software\Classes\Interface\{A0E2E5AB-C02F-489B-BD7B-58C329F774F3}
    RegDeleteKey HKLM\Software\Classes\Interface\{A6E398B2-A288-4D76-B0D0-8F153D14B66E}
    RegDeleteKey HKLM\Software\Classes\Interface\{A92616B1-2E82-4052-B579-0A40C2304380}
    RegDeleteKey HKLM\Software\Classes\Interface\{B22EE952-9A58-4495-AE78-C0146FA1A3C7}
    RegDeleteKey HKLM\Software\Classes\Interface\{C1EA2421-BC9A-4546-943C-126F9D818EFB}
    RegDeleteKey HKLM\Software\Classes\Interface\{C3896A1E-8ECD-490B-8A1C-39FE9F7D64A1}
    RegDeleteKey HKLM\Software\Classes\Interface\{C88B2356-A6FE-41EC-B0FB-41F2C82C867E}
    RegDeleteKey HKLM\Software\Classes\Interface\{CF5C9FCE-C963-49E5-A3A4-0A81FFFE1E55}
    RegDeleteKey HKLM\Software\Classes\Interface\{D090E12D-B79C-4B82-A76C-0E3BBE73C9EF}
    RegDeleteKey HKLM\Software\Classes\Interface\{D7136B99-FC27-4DC1-8497-5444D49B426A}
    RegDeleteKey HKLM\Software\Classes\Interface\{D80A56D7-451C-41CF-9A74-1447E0887B97}
    RegDeleteKey HKLM\Software\Classes\Interface\{DE3C77B8-7378-4A4C-B6F8-4A008B4A6009}
    RegDeleteKey HKLM\Software\Classes\Interface\{E0110779-5F79-4685-9C96-9D99EFD30CA2}
    RegDeleteKey HKLM\Software\Classes\Interface\{E7CCBD19-2EEA-4B6A-B9BE-E8A68613809C}
    RegDeleteKey HKLM\Software\Classes\Interface\{E95F8133-A554-4C0C-9B9A-EEEE3B82CEDE}
    RegDeleteKey HKLM\Software\Classes\Interface\{EA0F107F-2BF6-44A0-96C4-A99B74AFBC4A}
    RegDeleteKey HKLM\Software\Classes\Interface\{F18701B3-185D-42FD-A55E-F47FDAC8F362}
    RegDeleteKey HKLM\Software\Classes\Interface\{F709F572-86F5-47C8-AFCF-3CEBC468FADB}
    RegDeleteKey HKLM\Software\Classes\Interface\{F97E5B38-4887-444A-86F5-91C18331500B}
    RegDeleteKey HKLM\Software\Classes\Interface\{F9AC5167-2C13-4607-B924-81C1C2251C84}
    RegDeleteKey HKLM\Software\Classes\Interface\{FB752175-36D8-4792-9302CFB8018C0DEC}

    RegDeleteKey HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\UDCShell

    RegDeleteKey HKLM\Software\Classes\SYSTEM\ControlSet003\Services\wasfsd

    RegDeleteKey HKLM\Software\Classes\TypeLib\{03A78DBD-AA12-4DB4-AB2C-564460D385DC}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{09AF1CF9-825C-4017-A7DC-088C68770F31}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{0A89FF7F-1A12-42D9-ACCB-4217112DC7E0}
    RegDeleteKey HKLM\software\classes\typelib\{1234890a-5e6e-4867-8136-ca6f1456b235}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{12398A44-7DFC-4C46-BD8F-41259D169A0D}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{16DEEE6B-AEFC-4BA6-9F32-57BBE6783A7C}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{21C724D0-B91A-4F35-99E7-55D325F00B20}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{223CEDCA-738B-4C4D-B8AE-C68B68C90A4A}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{5940CA88-8F1A-4A74-89E4-B3407E5E7348}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{61C1FC79-7120-4824-A563-D4D11D80BAFB}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{68BC55E9-4D3E-4C89-89AC-7559763C98B8}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{692CA430-32C8-470D-BA1F-7E15E21E7043}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{7eacf70b-302f-4049-ac68-2d62eb43e473}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{8ECC09E1-634B-42AC-8BE7-E6EDBB53C90E}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{A8C9AD38-7708-4BEB-A20C-B79614B4F120}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37411}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37422}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{B869788C-35DF-4104-BACB-8FDB83AFFFFD}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{BD9421BB-9F96-4272-802F-49BEC746056E}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{F874A0AE-66E8-426B-A3F5-6BA6958DCDBA}
    RegDeleteKey HKLM\Software\Classes\TypeLib\{FB42F450-C8B1-4799-99F1-87FA9CA92AB9}

    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\errorguard.exe

    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{205ff73b-ca67-11d5-99dd-444553540006}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6AE7418B-229F-4A2C-AE1B-D5962888F02D}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8C65AEF6-E413-4314-815B-82717A3F1603}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3B4C621-6024-410B-9F0F-22CBD6981F5E}

    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Error Guard
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ERS_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ersu_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UDC6_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USDR6_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USDR6V_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\usyp_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UWFX_5_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UWinFX6_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\wa6p_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WAS_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WFX5_is1
    RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinAntiSpyware 2006 Scanner_is1

    RegDeleteKey HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sscan.sys
    RegDeleteKey HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\sscan.sys

    RegDeleteKey HKLM\SYSTEM\ControlSet001\Services\FOPN
    RegDeleteKey HKLM\SYSTEM\ControlSet001\Services\uwasfsd
    RegDeleteKey HKLM\SYSTEM\ControlSet002\Services\FOPN

    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\df_km.sys
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ersd.sys
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sscan.sys

    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\df_kmd.sys
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ersd.sys
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sscan.sys

    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ERSD
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\enum\root\legacy_erssdd

    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\df_kmd
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\ersd
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\erssdd
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\FOPN
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\FWSvc
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\uwasfsd
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\vspf
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk
    RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\wasfsd

    RegDeleteKey HKUS\Software\DriveCleaner 2006 Free

    # 4 - ActiveX

    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006}
    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
    RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}|Compatibility Flags|1024
    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{205FF73B-CA67-11D5-99DD-444553540006}|Compatibility Flags|1024
    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}|Compatibility Flags|1024
    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}|Compatibility Flags|1024
    RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{F919FBD3-A96B-4679-AF26-F551439BB5FD}|Compatibility Flags|1024

    # 5 - Fichiers

    DllUnregister C:\Program Files\DriveCleaner 2006 Free\UDCPChk.dll|1
    DllUnregister C:\Program Files\DriveCleaner 2006 Free\UDCShell.dll|1
    DllUnregister C:\Program Files\ErrorSafe\df_fixer.dll|1
    DllUnregister C:\Program Files\ErrorSafe\df_proxy.dll|1
    DllUnregister C:\Program Files\ErrorSafe\ecc.dll|1
    DllUnregister C:\Program Files\ErrorSafe\esSPCheck.dll|1
    DllUnregister C:\Program Files\ErrorSafe\FFWraper.dll|1
    DllUnregister C:\Program Files\ErrorSafe\FixCore.dll|1
    DllUnregister C:\Program Files\ErrorSafe\FiFxr5.dll|1
    DllUnregister C:\Program Files\ErrorSafe\FTRec.dll|1
    DllUnregister C:\Program Files\ErrorSafe\MMFix.dll|1
    DllUnregister C:\Program Files\ErrorSafe\StrRes.dll|1
    DllUnregister C:\Program Files\SysProtect\compclr.dll|1
    DllUnregister C:\Program Files\SysProtect\df_fixer.dll|1
    DllUnregister C:\Program Files\SysProtect\df_proxy.dll|1
    DllUnregister C:\Program Files\SysProtect\FFWrapr.dll|1
    DllUnregister C:\Program Files\SysProtect\flfxr10.dll|1
    DllUnregister C:\Program Files\SysProtect\FTRec.dll|1
    DllUnregister C:\Program Files\SysProtect\FxCore.dll|1
    DllUnregister C:\Program Files\SysProtect\MMFx.dll|1
    DllUnregister C:\Program Files\SysProtect\StrRes.dll|1
    DllUnregister C:\Program Files\SystemDoctor 2006 Free\order.dll|1
    DllUnregister C:\Program Files\VirusGarde\Addons\popupg.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006\AsAgents.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006\shellext.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\AsAgents.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\shellext.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\uwas6chk.dll|1
    DllUnregister C:\Program Files\WinAntiSpyware 2006 Scanner\was6chk.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\avkernel.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\IEFWBHO.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\libfn.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\rpt.dll|1
    DllUnregister C:\Program Files\WinAntiVirus Pro 2006\winpgi.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\compcln.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\df_fixer.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\df_proxy.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\ffCom.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\FFWraper.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\FileTypeRecognizer.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\FixCore.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\MMFix.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\OEDrop.dll|1
    DllUnregister C:\Program Files\WinFixer 2005\StrRes.dll|1
    DllUnregister C:\Program Files\Common Files\Companion Wizard\WapCHK.dll|1
    DllUnregister C:\Program Files\Common Files\WinAntiSpyware 2006\was6chk.dll|1
    DllUnregister C:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll|1
    DllUnregister C:\Program Files\Common Files\WinSoftware\CrXML.dll|1
    DllUnregister C:\Program Files\Common Files\WinSoftware\PCheck.dll|1
    DllUnregister C:\Program Files\Fichiers communs\WinFixer 2005\uwappchk.dll|1
    DllUnregister C:\WINDOWS\system32\SpOrder.dll|1
    DllUnregister C:\WINDOWS\syst32.dll|1

    FileDelete C:\Documents and Settings\All Users\Bureau\WinAntiVirus*.lnk
    FileDelete C:\Documents and Settings\Maëlle\Application Data\*drivecleaner*.exe
    FileDelete C:\Documents and Settings\Maëlle\Application Data\*errorsafe*.exe
    FileDelete C:\Documents and Settings\Maëlle\Application Data\*winantispyware*.exe
    FileDelete C:\Documents and Settings\Maëlle\Application Data\*winantivirus*.exe
    FileDelete C:\Documents and Settings\Maëlle\Application Data\install_fr*.exe
    FileDelete C:\Documents and Settings\Maëlle\Application Data\Microsoft\Internet Explorer\Quick Launch\SystemDoctor*.lnk
    FileDelete C:\Documents and Settings\Maëlle\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiSpyware*.lnk
    FileDelete C:\Documents and Settings\Maëlle\Bureau\*drivecleaner*.exe
    FileDelete C:\Documents and Settings\Maëlle\Bureau\DriveCleaner 2006 Free.lnk
    FileDelete C:\Documents and Settings\Maëlle\Bureau\ErrorGuard.lnk
    FileDelete C:\Documents and Settings\Maëlle\Bureau\ErrorSafe.lnk
    FileDelete C:\Documents and Settings\Maëlle\Bureau\ErrorSafe*.exe
    FileDelete C:\Documents and Settings\Maëlle\Bureau\SystemDoctor*.lnk
    FileDelete C:\Documents and Settings\Maëlle\Bureau\WinAntiSpyware*.lnk
    FileDelete C:\Documents and Settings\Maëlle\Bureau\WinFixer*.exe
    FileDelete C:\Documents and Settings\Maëlle\Bureau\WinFixer*.lnk
    FileDelete C:\Documents and Settings\Maëlle\Mes documents\*drivecleaner*.exe
    FileDelete C:\Documents and Settings\Maëlle\Mes documents\*SystemDoctor*.exe
    FileDelete C:\Documents and Settings\Maëlle\Mes documents\*WinAntiVirusPro*.exe
    FileDelete C:\Program Files\*drivecleaner*.exe
    FileDelete C:\Program Files\*WinAntiVirusPro*.exe
    FileDelete C:\Program Files\Common Files\Companion Wizard\compwiz.exe
    FileDelete C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
    FileDelete C:\Program Files\Common Files\Companion Wizard\WapCHK{*}.dll
    FileDelete C:\WINDOWS\46241234110.exe
    FileDelete C:\WINDOWS\service32.exe
    FileDelete C:\WINDOWS\syst32.dll
    FileDelete C:\WINDOWS\Downloaded Program Files\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.1\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.2\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.3\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.4\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.5\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.6\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.7\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.8\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.9\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.10\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.11\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.12\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.13\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.14\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.15\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.16\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Downloaded Program Files\CONFLICT.17\U*_*_*NetInstaller.exe
    FileDelete C:\WINDOWS\Prefetch\*winantispyware*.pf
    FileDelete C:\WINDOWS\system32\av.cpl
    FileDelete C:\WINDOWS\system32\df_kme.exe
    FileDelete C:\WINDOWS\system32\SpOrder.dll
    FileDelete C:\WINDOWS\system32\stera.exe
    FileDelete C:\WINDOWS\system32\stera.?o?
    FileDelete C:\WINDOWS\system32\drivers\ApiMon.sys
    FileDelete C:\WINDOWS\system32\drivers\df_kmd.sys
    FileDelete C:\WINDOWS\system32\drivers\ersd.sys
    FileDelete C:\WINDOWS\system32\drivers\erssdd.sys
    FileDelete C:\WINDOWS\system32\drivers\fopn.sys
    FileDelete C:\WINDOWS\system32\drivers\sscan.sys
    FileDelete C:\WINDOWS\system32\drivers\uwasfsd.sys
    FileDelete C:\WINDOWS\system32\drivers\vspf_hk5.sys
    FileDelete C:\WINDOWS\system32\drivers\vspf5.sys
    FileDelete C:\WINDOWS\system32\drivers\wasfsd.sys
    FileDelete C:\WINDOWS\system32\drivers\WFF.sys
    FileDelete C:\systemdoctor*.exe

    # 6 - Repertoires

    FolderDelete C:\Documents and Settings\Maëlle\Application Data\DriveCleaner Free
    FolderDelete C:\Documents and Settings\Maëlle\Application Data\systemdoctor 2006 free
    FolderDelete C:\Documents and Settings\Maëlle\Application Data\VirusGarde
    FolderDelete C:\Documents and Settings\Maëlle\Application Data\WinAntiVirus Pro 2006
    FolderDelete C:\Documents and Settings\Maëlle\Application Data\WinAntiVirus Pro 2007
    FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Corp
    FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006
    FolderDelete C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\DriveCleaner 2006 Free
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ErrorSafe
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\SystemDoctor 2006 Unregistered Version
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiSpyware 2006
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiSpyware 2006 Scanner
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinAntiVirus Pro 2006
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinFixer 2005
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\WinAntiVirus Pro 2007
    FolderDelete C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\SysProtect
    FolderDelete C:\Program Files\DriveCleaner 2006 Free
    FolderDelete C:\Program Files\erroguard
    FolderDelete C:\Program Files\Error Safe
    FolderDelete C:\Program Files\Error Safe Free
    FolderDelete C:\Program Files\ErrorSafe
    FolderDelete C:\Program Files\errorsafe free
    FolderDelete C:\Program Files\SysProtect Free
    FolderDelete C:\Program Files\SystemDoctor 2006
    FolderDelete C:\Program Files\SystemDoctor 2006 Free
    FolderDelete C:\Program Files\VirusGarde
    FolderDelete C:\Program Files\WinAntiSpyware 2006
    FolderDelete C:\Program Files\WinAntiSpyware 2006 Free
    FolderDelete C:\Program Files\WinAntiSpyware 2006 Scanner
    FolderDelete C:\Program Files\WinAntiVirus 2005
    FolderDelete C:\Program Files\WinAntiVirus Pro 2006
    FolderDelete C:\Program Files\WinAntiVirus Pro 2007
    FolderDelete C:\Program Files\WinFixer 2005
    FolderDelete C:\Program Files\WinPopupGuard 2005
    FolderDelete C:\Program Files\Archivos comunes\DriveCleaner 2006
    FolderDelete C:\Program Files\Archivos comunes\DriveCleaner 2006 Free
    FolderDelete C:\Program Files\Archivos comunes\DriveCleaner Free
    FolderDelete C:\Program Files\Archivos comunes\Error Safe
    FolderDelete C:\Program Files\Archivos comunes\erroguard
    FolderDelete C:\Program Files\Archivos comunes\errorguard
    FolderDelete C:\Program Files\Archivos comunes\ErrorSafe
    FolderDelete C:\Program Files\Archivos comunes\SystemDoctor
    FolderDelete C:\Program Files\Archivos comunes\SystemDoctor 2006
    FolderDelete C:\Program Files\Archivos comunes\WinAntiSpyware 2006
    FolderDelete C:\Program Files\Archivos comunes\WinAntiVirus Pro 2006
    FolderDelete C:\Program Files\Archivos comunes\WinAntiVirus Pro 2007
    FolderDelete C:\Program Files\Archivos comunes\WinFixer 2005
    FolderDelete C:\Program Files\Archivos comunes\WinSoftware
    FolderDelete C:\Program Files\Common Files\DriveCleaner 2006 Free
    FolderDelete C:\Program Files\Common Files\erroguard
    FolderDelete C:\Program Files\Common Files\errorguard
    FolderDelete C:\Program Files\Common Files\ErrorSafe
    FolderDelete C:\Program Files\Common Files\SysProtect
    FolderDelete C:\Program Files\Common Files\SystemDoctor 2006
    FolderDelete C:\Program Files\Common Files\WinAntiSpyware 2006
    FolderDelete C:\Program Files\Common Files\WinAntiVirus Pro 2006
    FolderDelete C:\Program Files\Common Files\WinFixer 2005
    FolderDelete C:\Program Files\Common Files\WinSoftware
    FolderDelete C:\Program Files\Fichiers communs\DriveCleaner 2006
    FolderDelete C:\Program Files\Fichiers communs\DriveCleaner 2006 Free
    FolderDelete C:\Program Files\Fichiers communs\DriveCleaner Free
    FolderDelete C:\Program Files\Fichiers communs\Error Safe
    FolderDelete C:\Program Files\Fichiers communs\erroguard
    FolderDelete C:\Program Files\Fichiers communs\errorguard
    FolderDelete C:\Program Files\Fichiers communs\ErrorSafe
    FolderDelete C:\Program Files\Fichiers communs\ProtectionAssuree
    FolderDelete C:\Program Files\Fichiers communs\SystemDoctor
    FolderDelete C:\Program Files\Fichiers communs\SystemDoctor 2006
    FolderDelete C:\Program Files\Fichiers communs\WinAntiSpyware 2006
    FolderDelete C:\Program Files\Fichiers communs\WinAntiVirus Pro 2006
    FolderDelete C:\Program Files\Fichiers communs\WinAntivirus Pro 2007
    FolderDelete C:\Program Files\Fichiers communs\WinFixer 2005
    FolderDelete C:\Program Files\Fichiers communs\WinFixer 2005
    FolderDelete C:\Program Files\Fichiers communs\WinSoftware
    FolderDelete C:\UWA7PV
    FolderDelete C:\WinAntiVirus Pro 2006

    # 7 - Nettoyage

    Filedelete %USERPROFILE%\Cookies\*@*drivecleaner*.txt
    Filedelete %USERPROFILE%\Cookies\*@*errorsafe*.txt
    Filedelete %USERPROFILE%\Cookies\*@*systemdoctor*.txt
    Filedelete %USERPROFILE%\Cookies\*@*WinAntiSpyware*.txt
    Filedelete %USERPROFILE%\Cookies\*@*winantivirus*.txt
    Filedelete %USERPROFILE%\Cookies\*@*winfixer*.txt
    Filedelete %USERPROFILE%\Cookies\*@*yieldmanager*.txt

    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drivecleanr.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\systemdoctor.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\win-anti-virus-pro.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispy.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantiviruspro.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfirewall.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer2006.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winnanny.com|*|4
    RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winsoftware.com|*|4

    RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drivecleanr.com|*|4
    RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domain
    0
  9. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    refais hijack stp
    @+
    0
  10. malou35000 Messages postés 9 Statut Membre
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:32:20, on 15/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\Wanadoo\CnxMon.exe
    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
    C:\Program Files\Eraser\Eraser.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\bgsvcgen.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Documents and Settings\Maëlle\Mes documents\eMule0.48a\eMule0.48a\emule.exe
    C:\BFU\BFU.exe
    C:\BFU\BFU.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
    O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [mav_startupmon] "C:\Program Files\Fichiers communs\WinAntiVirus Pro 2007\mav_startupmon.exe"
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AutoTBar] C:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
    O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"
    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - S-1-5-18 Startup: AutoTBar.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: AutoTBar.exe (User 'Default user')
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
    O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by117fd.bay117.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
    O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Program Files\Canon\DIAS\CnxDIAS.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    0
  11. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    * Redémarre l'ordinateur en mode sans échec
    (tapoter F8 au boot pour obtenir le menu de démarrage ou http://service1.symantec.com/

    * Double clique sur smitfraudfix.cmd

    * Sélectionne 2 pour supprimer les fichiers responsables de l'infection.

    A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

    A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

    * Redémarre en mode normal et poste le rapport ici

    N.B.: Cette étape élimine les fichiers infectieux détectés à l'étape #1
    Attention que l'option 2 de l'outil supprime le fond d'écran !

    reposte un nouveau rapport hijackthis à l'issu stp
    0
    1. malou35000 Messages postés 9 Statut Membre
       
      SmitFraudFix v2.304

      Rapport fait à 21:53:50,23, 15/03/2008
      Executé à partir de C:\Documents and Settings\Ma‰lle\Bureau\SmitfraudFix\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode sans echec

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus


      »»»»»»»»»»»»»»»»»»»»»»»» hosts


      127.0.0.1 localhost

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

      S!Ri's WS2Fix: LSP not Found.


      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

      GenericRenosFix by S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés


      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{43651CE2-9894-4B3B-B02A-1409AB6D0632}: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{43651CE2-9894-4B3B-B02A-1409AB6D0632}: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{2DC2A048-1EE1-40AC-A1D9-B65D560D0160}: DhcpNameServer=193.54.111.8 10.75.2.221
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{43651CE2-9894-4B3B-B02A-1409AB6D0632}: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=193.54.111.8 10.75.2.221
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.122 82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121


      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires


      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]


      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      Nettoyage terminé.

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
  12. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Télécharge:
    http://www.commentcamarche.net/telecharger/telecharger 218 avg anti spyware
    = Installer
    = Le lancer
    = Clic : Mise à jour
    ------
    = Redémarre en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
    Attention, pas d’accès à internet dans ce mode. Enregistre ou imprime les consignes.

    Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
    Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel
    -------
    = Dans ANALYSE ( en forme de loupe )
    ==> Paramètres ==> sous COMMENT REAGIR==>clic sur Actions recommandées ==>Quarantaine
    ==> Clic : Analyse complète du système
    En fin de scan ( qui est assez long)
    ==> Clic Appliquer toutes les actions <== ceci Très important
    ==> Clic Sauvegarder rapport puis Enregistrer sous et choisir bureau
    -------
    En mode normal
    colle le rapport

    ensuite fait un scan en ligne

    avec bitdefender et colle le rapport

    https://www.bitdefender.com/toolbox/

    un tuto
    http://pageperso.aol.fr/rginformatique/mapage/defender.htm
    + un nouveau rapport hijack
    @+
    0
  13. malou35000
     
    [16/03/2008 12:06:23] Error: [CProcessInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ProcessInformation.cpp, 274
    [16/03/2008 12:06:23] Error: [CConnectionInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ConnectionInformation.cpp, 227
    [16/03/2008 12:14:26] Error: failed to connect to server, Value: 00000002, Position: .\Client.cpp, 26
    [16/03/2008 12:14:30] Error: failed to connect to server, Value: 00000002, Position: .\Client.cpp, 26
    [16/03/2008 12:14:30] Error: IPC connect to service failed, Position: .\main.cpp, 258
    [16/03/2008 12:15:03] Error: [CProcessInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ProcessInformation.cpp, 274
    [16/03/2008 12:15:03] Error: [CProcessInformation]: Module32First failed, Value: 00000012, Position: .\ProcessInformation.cpp, 291
    [16/03/2008 12:15:03] Error: [CConnectionInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ConnectionInformation.cpp, 227
    [16/03/2008 12:15:10] Error: failed to connect to server, Value: 00002741, Position: .\DownloadHttp.cpp, 265
    [16/03/2008 12:18:03] Error: failed to connect to server, Value: 00000002, Position: .\Client.cpp, 26
    [16/03/2008 12:21:30] Error: failed to connect to server, Value: 00000002, Position: .\Client.cpp, 26
    [16/03/2008 12:22:04] Error: [CProcessInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ProcessInformation.cpp, 274
    [16/03/2008 12:22:04] Error: [CConnectionInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ConnectionInformation.cpp, 227
    [16/03/2008 12:27:46] Error: failed to connect to server, Value: 00000002, Position: .\Client.cpp, 26
    [16/03/2008 12:28:15] Error: [CProcessInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ProcessInformation.cpp, 274
    [16/03/2008 12:28:15] Error: [CConnectionInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ConnectionInformation.cpp, 227
    [16/03/2008 12:28:25] Error: Shell_NotifyIcon failed, Value: 000005B4, Position: .\Tray.cpp, 229
    [16/03/2008 12:28:50] Error: failed to connect to server, Value: 00002741, Position: .\DownloadHttp.cpp, 265
    [16/03/2008 12:35:01] Error: failed to connect to driver, Value: 00000002, Position: .\SelfProtection.cpp, 23
    [16/03/2008 12:36:15] Error: failed to connect to server, Value: 000000E7, Position: .\Client.cpp, 26
    [16/03/2008 12:36:15] Error: IPC connect to service failed, Position: .\main.cpp, 258
    [16/03/2008 12:36:46] Error: failed to connect to driver, Value: 00000002, Position: .\SelfProtection.cpp, 23
    [16/03/2008 12:36:47] Error: [CProcessInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ProcessInformation.cpp, 274
    [16/03/2008 12:36:59] Error: failed to connect to driver, Value: 00000002, Position: .\SelfProtection.cpp, 23
    [16/03/2008 12:37:29] Error: failed to create socket, Value: 00002742, Position: .\DownloadHttp.cpp, 212
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 000005AA, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] Error: Cannot open config key, Value: 00000013, Position: .\config.cpp, 56
    [16/03/2008 12:58:23] [16/03/2008 13:33:40] Error: [CProcessInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ProcessInformation.cpp, 274
    [16/03/2008 13:33:40] Error: [CConnectionInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ConnectionInformation.cpp, 227
    [16/03/2008 13:48:20] Error: failed to connect to server, Value: 00000002, Position: .\Client.cpp, 26
    [16/03/2008 13:48:46] Error: [CProcessInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ProcessInformation.cpp, 274
    [16/03/2008 13:48:47] Error: [CConnectionInformation]: Creating snapshot for module enumeration failed., Value: 00000008, Position: .\ConnectionInformation.cpp, 227
    0
  14. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonjour ce ci n'est ne le rapport de avg ni de bitdefender
    @+
    0