Virus methode préliminaire de désnfection

aliepeet Messages postés 31 Statut Membre -  
^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour,

Je viens sur ce site depuis longtps, j'ai beaucoup de problemes sur mon ordi,et je vais en prendre un autre en septembre, mais j'aimerais me débarasser de tous mes virus, spyware, trojans...et lorque je suis allée sur cette page:
http://www.commentcamarche.net/faq/sujet 3174 virus methode preliminaire de desinfection version fr
J'ai effectué toute la marche à suivre et je dois donc afficher le resultat des scans..Mais j'ai un peu peur de balancer çà sur le forum?Est-ce que je dois supprimer les logiciels utilisés pour ces tests?
Y a t il un risqueau niveau confidentialité?

Merci de me répondre!

Alieet

NB: ordi portable HP de 2005, systeme d'expl. = XP
Configuration: Windows XP
Internet Explorer 7.0

7 réponses

  1. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    Bonsoir

    C 'est tout ?
    http://www.commentcamarche.net/faq/sujet 3174 virus methode preliminaire de desinfection version fr

    Fait
    Cleaner
    AVG ► poste le rapport
    Hijacthis ► poste le rapport
    1
    1. aliepeet Messages postés 31 Statut Membre
       
      BONJOUR!

      Je t'envoie le rapport hijackthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 02:47:32, on 09/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\crypserv.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
      C:\WINDOWS\system32\hphmon05.exe
      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
      C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
      C:\Program Files\TF1Vision\TF1vision.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\VAV\vav.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
      C:\Documents and Settings\Internet et MSN\Local Settings\Temporary Internet Files\Content.IE5\7VHLSKV2\install_3968_MXw1fHx8fHx8fA_[1].exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.oracle.com/sun/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
      O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
      O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
      O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
      O4 - HKLM\..\Run: [e-TF1] C:\Program Files\TF1Vision\TF1vision.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [BM2596996e] Rundll32.exe "C:\WINDOWS\system32\monsqngu.dll",s
      O4 - HKLM\..\Run: [26a5aaf2] rundll32.exe "C:\WINDOWS\system32\gqmbkxfn.dll",b
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe
      O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
      O4 - HKCU\..\Run: [TheSpyBot] C:\Program Files\TheSpyBot\TheSpyBot.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\jnwnw64l.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
      O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} (InstallerObj Class) - http://www.m6video.fr/1click/install/files/installer2.cab
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104w.bay104.mail.live.com/mail/resources/MsnPUpld.cab
      O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{E84A4C7F-7E4C-4947-92C3-0B6DBFAEE94B}: NameServer = 194.49.160.1,195.154.209.1
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Sygate Personal Firewall (SmcService) - Unknown owner - C:\Program Files\Sygate\SPF\smc.exe (file missing)
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      0
    2. aliepeet Messages postés 31 Statut Membre
       
      suite de la réponse je te reposte le rapport ccleaner qui n'est pas passé en entier je crois...

      NETTOYAGE COMPLET - (32.520 secs)
      ------------------------------------------------------------------------------------------
      27,3MB supprimés.
      ------------------------------------------------------------------------------------------

      Détails des fichiers effacés
      ------------------------------------------------------------------------------------------
      Fichiers Temporaires d'Internet Explorer (fichiers 1514) 25,7MB
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@rad.msn[2].txt 680 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[7].txt 70 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@affiliates.nexpartner[2].txt 293 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@67.205.95[3].txt 438 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@vlaze[2].txt 434 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@85.17.166[3].txt 166 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@scanner.vav-scanner[3].txt 170 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@speedbit[2].txt 270 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@live[3].txt 514 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.dailymotion[1].txt 75 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adstronic[1].txt 125 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@64.22.123[2].txt 106 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@ads.react2media[3].txt 340 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@windowsmarketplace[3].txt 263 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@em.gad-network[3].txt 159 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@ads.vlaze[1].txt 105 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@fr.msn[2].txt 563 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@banner.cotedazurpalace[3].txt 290 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adnetserver[3].txt 332 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@85.12.43[3].txt 273 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@login.live[3].txt 181 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[8].txt 70 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@detoxitnow[1].txt 78 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@em.pc-on-internet[2].txt 75 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@google[3].txt 135 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[5].txt 98 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@msn[4].txt 345 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@thespybotpromo[2].txt 78 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@scanner.shredderscan[1].txt 253 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@web-mediaplayer[2].txt 279 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.smooki[1].txt 101 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@zune[3].txt 235 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.primecasino[2].txt 77 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@xiti[2].txt 107 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adtrgt[5].txt 1,23KB
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@sdv[1].txt 243 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@quantserve[3].txt 199 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@cotedazurpalace[3].txt 474 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.web-mediaplayer[2].txt 121 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@commentcamarche[4].txt 118 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.checkmystats.com[3].txt 226 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@83.149.75[1].txt 69 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@media6degrees[2].txt 121 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@85.12.43[2].txt 100 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@ooshop[1].txt 111 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@srv1.e-statistic[2].txt 87 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@c.live[1].txt 74 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@89.188.16[3].txt 69 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@splendor-casino[1].txt 78 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@dailymotion[2].txt 253 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@89.188.16[7].txt 69 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@rad.live[3].txt 700 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.windowslive[1].txt 82 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@software-traffic[3].txt 89 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@p.live[2].txt 104 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[6].txt 76 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@yahoo[3].txt 166 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@ad.zanox[1].txt 258 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@msn[3].txt 432 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@analytics.gameforge[5].txt 95 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@89.188.16[8].txt 67 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@google[2].txt 136 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@32vegas[1].txt 138 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@3suisses[2].txt 272 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@67.205.95[1].txt 312 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[1].txt 233 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[2].txt 98 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[3].txt 167 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[4].txt 76 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@83.149.75[2].txt 68 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@85.12.43[1].txt 101 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@85.17.166[1].txt 168 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@89.188.16[1].txt 69 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@89.188.16[2].txt 159 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@89.188.16[4].txt 163 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@89.188.16[5].txt 234 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@89.188.16[6].txt 261 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adnetserver[2].txt 329 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@ads.react2media[2].txt 398 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adtrgt[1].txt 945 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adtrgt[2].txt 945 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adtrgt[4].txt 906 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adultfriendfinder[1].txt 494 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@affiliates.digitalriver[2].txt 279 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@analytics.gameforge[1].txt 402 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@analytics.gameforge[2].txt 95 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@analytics.gameforge[4].txt 499 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@apmebf[1].txt 176 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@banner.32vegas[2].txt 228 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@banner.cotedazurpalace[2].txt 207 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@bitdefender.eptimum[1].txt 109 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@bitdefender[2].txt 135 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@bountycpa[1].txt 342 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@cc-dt[1].txt 109 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@commentcamarche[2].txt 119 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@commentcamarche[3].txt 119 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@cotedazurpalace[1].txt 114 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@crwdcntrl[2].txt 457 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@dailymotion[1].txt 269 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@eas.apm.emediate[2].txt 188 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@edt02[1].txt 516 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@element5[1].txt 89 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@em.gad-network[1].txt 226 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@em.pc-on-internet[1].txt 84 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@emjcd[1].txt 174 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@eurosport[1].txt 177 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@expedia[1].txt 292 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@fr.f1-live[4].txt 263 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@go.gratisnetwork[2].txt 84 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@google[1].txt 129 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@h.live[1].txt 69 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@imgfarm[1].txt 72 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@linksynergy[2].txt 109 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@live.f1-live[1].txt 268 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@live[1].txt 509 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@live[2].txt 512 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@login.live[2].txt 181 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@msn[1].txt 338 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@nbjmp[2].txt 359 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@netfinanceconsult[1].txt 108 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@offers.gratisnetwork[2].txt 412 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@p.live[1].txt 104 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@perfspot[1].txt 525 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@perfspot[2].txt 387 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@primecasino[1].txt 345 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@primecasino[2].txt 268 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@quantserve[2].txt 203 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@rad.live[2].txt 700 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@s2d6[2].txt 110 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@scanner.privacy-watcher[2].txt 177 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@scanner.shredderscan[2].txt 162 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@scanner.shredderscan[3].txt 256 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@scanner.vav-scanner[1].txt 260 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@sdv[2].txt 481 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@shareit[2].txt 88 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@software-traffic[1].txt 86 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@speedbit[1].txt 267 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@srv1.e-statistic[1].txt 173 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@tagheuer[1].txt 272 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@tf1[2].txt 359 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@thespybotpromo[1].txt 76 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@vip.f1-live[2].txt 204 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@vip.f1-live[3].txt 329 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@web-mediaplayer[1].txt 326 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@webfetti[1].txt 353 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@website[2].txt 632 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@windowsmarketplace[1].txt 262 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@windowsmarketplace[2].txt 263 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.checkmystats.com[2].txt 231 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.dailymotion[2].txt 132 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.engineseeker[2].txt 199 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.jackpotmadness[1].txt 124 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.primecasino[1].txt 79 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.primosearch[1].txt 138 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.rgjmp[1].txt 429 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.trendsecure[1].txt 153 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.web-mediaplayer[1].txt 129 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@xiti[1].txt 106 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@yahoo[2].txt 162 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@youtube[1].txt 347 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@zune[2].txt 235 bytes
      Marqué pour l'effacement: C:\Documents and Settings\Internet et MSN\Local Settings\Temporary Internet Files\Content.IE5\index.dat
      Marqué pour l'effacement: C:\Documents and Settings\Internet et MSN\Cookies\index.dat
      Marqué pour l'effacement: C:\Documents and Settings\Internet et MSN\Local Settings\Historique\History.IE5\desktop.ini
      Marqué pour l'effacement: C:\Documents and Settings\Internet et MSN\Local Settings\Historique\History.IE5\index.dat
      C:\Documents and Settings\Internet et MSN\Recent\BTS AS formation.lnk 357 bytes
      C:\Documents and Settings\Internet et MSN\Recent\Candidature BTS banque.lnk 542 bytes
      C:\Documents and Settings\Internet et MSN\Recent\CV.lnk 405 bytes
      C:\Documents and Settings\Internet et MSN\Recent\hijackthis scan.lnk 614 bytes
      C:\Documents and Settings\Internet et MSN\Recent\USB.lnk 312 bytes
      Poubelle vidée (4 fichiers) 1,50MB
      C:\WINDOWS\TEMP\Perflib_Perfdata_8c.dat 16,00KB
      C:\Documents and Settings\Internet et MSN\Local Settings\Temp\D653F3EC.TMP 127 bytes
      C:\WINDOWS\system32\wbem\Logs\FrameWork.log 780 bytes
      C:\WINDOWS\system32\wbem\Logs\wbemess.log 7,18KB
      C:\WINDOWS\system32\wbem\Logs\wmiprov.log 201 bytes
      C:\WINDOWS\0.log 0 bytes
      C:\WINDOWS\comsetup.log 2,26KB
      C:\WINDOWS\FaxSetup.log 6,63KB
      C:\WINDOWS\iis6.log 986 bytes
      C:\WINDOWS\imsins.log 1,85KB
      C:\WINDOWS\msgsocm.log 479 bytes
      C:\WINDOWS\ntdtcsetup.log 1,56KB
      C:\WINDOWS\ocgen.log 5,59KB
      C:\WINDOWS\ocmsn.log 469 bytes
      C:\WINDOWS\setupact.log 0 bytes
      C:\WINDOWS\setupapi.log 10,26KB
      C:\WINDOWS\setuperr.log 0 bytes
      C:\WINDOWS\tsoc.log 3,83KB
      C:\WINDOWS\WindowsUpdate.log 3,56KB
      C:\Documents and Settings\Internet et MSN\Application Data\Microsoft\Office\Recent\CV.lnk 377 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Microsoft\Office\Recent\Desktop.ini 95 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Microsoft\Office\Recent\index.dat 81 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Microsoft\Office\Recent\Mes documents.lnk 665 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Microsoft\Office\Recent\sexy nouvelle.lnk 805 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Microsoft\Office\Recent\USB.lnk 312 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Google\Local Search History\google%2Eweb.w 240 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Macromedia\Flash Player\#SharedObjects\T69PEYWD\www.dailymotion.com\flash\dmplayer\dmplayer-fr.swf\dmplayer.sol 89 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.dailymotion.com\settings.sol 89 bytes
      C:\Documents and Settings\Internet et MSN\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 442 bytes
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\logfile.txt 560 bytes
      ------------------------------------------------------------------------------------------
      ensuite le rapport hijackthis


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:31:39, on 10/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\crypserv.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
      C:\WINDOWS\system32\hphmon05.exe
      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
      C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
      C:\Program Files\TF1Vision\TF1vision.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.oracle.com/sun/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
      O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
      O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
      O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
      O4 - HKLM\..\Run: [e-TF1] C:\Program Files\TF1Vision\TF1vision.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [BM2596996e] Rundll32.exe "C:\WINDOWS\system32\monsqngu.dll",s
      O4 - HKLM\..\Run: [26a5aaf2] rundll32.exe "C:\WINDOWS\system32\dhffudxu.dll",b
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\jnwnw64l.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
      O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} - http://www.m6video.fr/1click/install/files/installer2.cab
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104w.bay104.mail.live.com/mail/resources/MsnPUpld.cab
      O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{E84A4C7F-7E4C-4947-92C3-0B6DBFAEE94B}: NameServer = 194.49.160.1,195.154.209.1
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Sygate Personal Firewall (SmcService) - Unknown owner - C:\Program Files\Sygate\SPF\smc.exe (file missing)
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      0
  2. hacked62 Messages postés 96 Statut Membre 5
     
    OUI

    avec les virus il y a toujour des rique de confidentialiter ....

    je te propose comme je le propose a tout lmonde efface tout c'est dob d'anti virus et telecharge

    "nod32" ou encore "avast" voila

    fait un scan avec 1 de c'est 2 anti virus et la tu sera plus trankille ....

    hacked
    0
    1. aliepeet Messages postés 31 Statut Membre
       
      J'ai déjà avast, mais j'ai quand même des virus, ou je ne sais quoi d'autre...L'ordi est ralenti, des pubs pr différents anti-virus apparaissent et stop le travail en cours en proposant des analyses, windows me dit que mes informations ne sont pas protégées..etc
      il a buggé deux fi c'est grâce aux restaurations que je l'ai sauvé...Là encore en écrivant, il y a plein de lettres qui ne passent pas quand je les tape!!Mais si je publie mes rapports de scans, quelqu'un peut m'aider?
      0
  3. Utilisateur anonyme
     
    salut

    oui on est là pour ça ^^ t'en fais pas

    bises
    0
    1. hacked62 Messages postés 96 Statut Membre 5
       
      FORMATAGE

      formate ton pc et la croi moi qui'il va reprendre un bon cou de jeune le monstre ;)

      je ne vois que cette solution les virus on du henvahir ton sys 32

      erff sale ....

      voial formate mais tout se que tu ve garder sur un dd exetrn ou une cle usb ou encore grave les ...

      c'est la meilleur sollution =)
      0
      1. aliepeet Messages postés 31 Statut Membre > hacked62 Messages postés 96 Statut Membre
         
        Bonjour tous!

        Je voulais savoir si je peux envoyer mes rapports de scan sur le forum pour que vous m'aidiez à comrendre ce qui ne va pas sur mon ordi??
        Avast n'arrête pas d'intervenir à propos de virus ou cheval de troie dans le dossier "Win 32", de plus, jai accepté de télécharger un module de l'antivirus vista 2008, depuis il y a une fentre qui n'arrête pas de s'ouvrir, il me dit qu'il y a une attaque detecté, propose un scan, et ue fois le scan finit, pour le supprimer, il fo bien évidement acheter une licence...Qd je vais dans ajout ou suppr de programme, je ne trouve pas l'antivirus vista, donc je ne peux pas le supprimer!!
        Quelqu'un peut m'aider?Sinon, il y a plein de lettres qui ne passent pas sur mon clavier...
        Et je narrive pas a activer adaware et ses mises à jour

        J'en ai marre!Les ordis sont censés nous simplifier la vie mais en fait c'est une vraie prise de tête!
        0
  4. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    salut

    Je voulais savoir si je peux envoyer mes rapports de scan sur le forum pour que vous m'aidiez à comrendre ce qui ne va pas sur mon ordi??

    Envoie els rapports STP

    0
    1. aliepeet Messages postés 31 Statut Membre
       
      coucou marie

      je les ai envoyé sur le forum

      merci
      bises
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    Copie les ici...

    Je ferme les autres
    0
    1. aliepeet Messages postés 31 Statut Membre
       
      ok voici:

      Bonjour,
      J'envois mes trois rapports comme indiqué dans la methode préliminaire:
      Windows Registry Editor Version 5.00


      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\HPQ\\Safety and Comfort Guide\\PchCabInstall.vbs"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\HPQ\\Safety and Comfort Guide\\ahpregw.cab"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\MSIMRT.DLL"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\DIMM.DLL"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\QTPlugin.OCX"=dword:000003e6

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\ndpsetup.ico"=dword:00000001­

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\msxml3a.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Documents and Settings\\All Users\\Application Data\\YAHOO\\YMP\\LabelLic.xml"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\System32\\NeroCheck.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\Aiff.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\DefConvertor.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\msa.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\Vqf.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\wav.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\DriveLocker.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\NeroCBUI.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeFileSrc.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeRender.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\ImagX7.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\apreg.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeAudio.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeAMR.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeVideo.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\Aac.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\aacenc32.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NDParser.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeQTDec.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\aacplus.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\AdvrCntr.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\NeroIPP.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\ogg.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\Templates\\Data.nct"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\LSTemplates\\Audio_Content.nct"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\covered-deu.nls"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\covered-jpn.nls"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\CoverEdCtrl.ocx"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\TwnLib20.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp-Deu.nls"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\WMPBurn\\WMPBurn.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp-Jpn.nls"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\mp3PP.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\mp3PRO.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\lame_enc.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.Vsa.Vb.CodeDOMProcessor.­tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\mscoree.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\mscorlib.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.Drawing.tlb"=dword:000­01000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.EnterpriseServices.tlb"­;=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.Vsa.tlb"=dword:0000­1000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.JScript.tlb"=dword:­00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.Windows.Forms.tlb"=dwo­rd:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Documents and Settings\\All Users\\Application Data\\Adobe\\Photoshop Album\\Catalogues\\My Catalog.psa"=dword:00000001

      [HKEY_CLASSES_ROOT\.7z]

      [HKEY_CLASSES_ROOT\.ace]

      [HKEY_CLASSES_ROOT\.arj]

      [HKEY_CLASSES_ROOT\.bz]

      [HKEY_CLASSES_ROOT\.bz2]

      [HKEY_CLASSES_ROOT\.ids]

      [HKEY_CLASSES_ROOT\.iso]

      [HKEY_CLASSES_ROOT\.lha]

      [HKEY_CLASSES_ROOT\.lzh]

      [HKEY_CLASSES_ROOT\.mst]

      [HKEY_CLASSES_ROOT\.taz]

      [HKEY_CLASSES_ROOT\.tbz]

      [HKEY_CLASSES_ROOT\.tbz2]

      [HKEY_CLASSES_ROOT\.uu]

      [HKEY_CLASSES_ROOT\.uue]

      [HKEY_CLASSES_ROOT\.vfo]

      [HKEY_CLASSES_ROOT\.vfs]

      [HKEY_CLASSES_ROOT\.xxe]

      [HKEY_CLASSES_ROOT\ATLPlugin.ATL3DShapeSphere=]

      [HKEY_CLASSES_ROOT\FMObex.Semc.FMObjectProperties=]

      [HKEY_CLASSES_ROOT\FMObexServer.Sony]

      [HKEY_CLASSES_ROOT\ObexAuthenticationServiceDll.Sony]

      [HKEY_CLASSES_ROOT\ObexOperationDll.Sony]

      [HKEY_CLASSES_ROOT\OISbmpfile]

      [HKEY_CLASSES_ROOT\OISemffile]

      [HKEY_CLASSES_ROOT\OISgiffile]

      [HKEY_CLASSES_ROOT\OISpngfile]

      [HKEY_CLASSES_ROOT\OIStiffile]

      [HKEY_CLASSES_ROOT\OISwmffile]

      [HKEY_CLASSES_ROOT\PclePlayout.PlayoutFactoryHAL=]

      [HKEY_CLASSES_ROOT\s]

      [HKEY_CLASSES_ROOT\WMPCD]

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithLis­t]

      [HKEY_CLASSES_ROOT\acrobat\DefaultIcon]

      [HKEY_CLASSES_ROOT\AcroExch.Lang\DefaultIcon]

      [HKEY_CLASSES_ROOT\ADCS]

      [HKEY_CLASSES_ROOT\ADCS\CLSID]

      [HKEY_CLASSES_ROOT\ATLPlugin.ATL3DPage_d2.1]

      [HKEY_CLASSES_ROOT\ATLPlugin.ATL3DPage_d2.1\CLSID]

      [HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost]

      [HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost\CLSID]

      [HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost.2]

      [HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost.2\CLSID]

      [HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...]

      [HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...\command]

      [HKEY_CLASSES_ROOT\dcsfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\dip_auto_file\DefaultIcon]

      [HKEY_CLASSES_ROOT\dip_auto_file\shell\open]

      [HKEY_CLASSES_ROOT\dip_auto_file\shell\open\command]

      [HKEY_CLASSES_ROOT\DirectAnimation.PathControl]

      [HKEY_CLASSES_ROOT\DirectAnimation.PathControl\CLSID]

      [HKEY_CLASSES_ROOT\DirectAnimation.Sequence]

      [HKEY_CLASSES_ROOT\DirectAnimation.Sequence\CLSID]

      [HKEY_CLASSES_ROOT\DirectAnimation.SequencerControl]

      [HKEY_CLASSES_ROOT\DirectAnimation.SequencerControl\CLSID]

      [HKEY_CLASSES_ROOT\DirectAnimation.SpriteControl]

      [HKEY_CLASSES_ROOT\DirectAnimation.SpriteControl\CLSID]

      [HKEY_CLASSES_ROOT\DirectAnimation.StructuredGraphicsControl]

      [HKEY_CLASSES_ROOT\DirectAnimation.StructuredGraphicsControl\CLSID]

      [HKEY_CLASSES_ROOT\Dossier deJascPaintShopPhotoAlbum5\shell\BurnCD]

      [HKEY_CLASSES_ROOT\Dossier deJascPaintShopPhotoAlbum5\shell\BurnCD\command]

      [HKEY_CLASSES_ROOT\ecsfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\ed2k\DefaultIcon]

      [HKEY_CLASSES_ROOT\ed2k\shell\open]

      [HKEY_CLASSES_ROOT\ed2k\shell\open\command]

      [HKEY_CLASSES_ROOT\eMule\DefaultIcon]

      [HKEY_CLASSES_ROOT\eMule\shell\open]

      [HKEY_CLASSES_ROOT\eMule\shell\open\command]

      [HKEY_CLASSES_ROOT\fcsfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMARC]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMARC\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMAREA]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMAREA\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMCIRCLE]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMCIRCLE\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMCOORDSYSTEM]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMCOORDSYSTEM\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMLAYER]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMLAYER\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMLINE]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMLINE\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMOBJECT]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMOBJECT\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOINT]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOINT\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYARC]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYARC\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYGON]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYGON\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYLINE]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYLINE\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYPOLYGON]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYPOLYGON\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYPOLYLINE]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPOLYPOLYLINE\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPTXY]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMPTXY\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMTEXT]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMTEXT\CLSID]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMWINRECT]

      [HKEY_CLASSES_ROOT\GEOVIEW.BMWINRECT\CLSID]

      [HKEY_CLASSES_ROOT\Google Earth.etafile\DefaultIcon]

      [HKEY_CLASSES_ROOT\Google Earth.etafile\shell\open]

      [HKEY_CLASSES_ROOT\Google Earth.etafile\shell\open\command]

      [HKEY_CLASSES_ROOT\Google Earth.kmlfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\Google Earth.kmlfile\shell\open]

      [HKEY_CLASSES_ROOT\Google Earth.kmlfile\shell\open\command]

      [HKEY_CLASSES_ROOT\Google Earth.kmzfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\Google Earth.kmzfile\shell\open]

      [HKEY_CLASSES_ROOT\Google Earth.kmzfile\shell\open\command]

      [HKEY_CLASSES_ROOT\MailFileAtt]

      [HKEY_CLASSES_ROOT\MailFileAtt\CLSID]

      [HKEY_CLASSES_ROOT\mapifvbx.object]

      [HKEY_CLASSES_ROOT\mapifvbx.object\Clsid]

      [HKEY_CLASSES_ROOT\mapifvbx.object.1]

      [HKEY_CLASSES_ROOT\mapifvbx.object.1\Clsid]

      [HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin]

      [HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\CLSID]

      [HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\CurVer]

      [HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\NotInsertable]

      [HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1]

      [HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1\CLSID]

      [HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1\NotInsertable]

      [HKEY_CLASSES_ROOT\MMJB.MMZ\DefaultIcon]

      [HKEY_CLASSES_ROOT\msbackupfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\msbackupfile\shell\Open]

      [HKEY_CLASSES_ROOT\msbackupfile\shell\Open\Command]

      [HKEY_CLASSES_ROOT\mvd_auto_file\DefaultIcon]

      [HKEY_CLASSES_ROOT\mvd_auto_file\shell\open]

      [HKEY_CLASSES_ROOT\mvd_auto_file\shell\open\command]

      [HKEY_CLASSES_ROOT\NBBACKUPType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NBBACKUPType\shell\open]

      [HKEY_CLASSES_ROOT\NBBACKUPType\shell\open\command]

      [HKEY_CLASSES_ROOT\NBCOMPRESSType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NBCOMPRESSType\shell\open]

      [HKEY_CLASSES_ROOT\NBCOMPRESSType\shell\open\command]

      [HKEY_CLASSES_ROOT\NBJOBType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NBJOBType\shell\open]

      [HKEY_CLASSES_ROOT\NBJOBType\shell\open\command]

      [HKEY_CLASSES_ROOT\ncsfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Document\DefaultIcon]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\Application]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\command]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\ddeexec]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Document\shell\open\ddeexec\Application]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Template\DefaultIcon]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\command]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\ddeexec]

      [HKEY_CLASSES_ROOT\Nero Cover Designer.Template\shell\open\ddeexec\Application]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_CDAudio]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_CDAudio\command]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_DataDisc]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_DataDisc\command]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_LaunchNeroStartSmart]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_LaunchNeroStartSmart\comm­and]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_AudioToNeroDigital]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_AudioToNeroDigital\command]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_CopyCD]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_CopyCD\command]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_RipCD]

      [HKEY_CLASSES_ROOT\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_RipCD\command]

      [HKEY_CLASSES_ROOT\NeroAACType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroAACType\shell\open]

      [HKEY_CLASSES_ROOT\NeroAACType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroAACType\shell\print]

      [HKEY_CLASSES_ROOT\NeroAACType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroAACType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroAACType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroAudioType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroAudioType\shell\open]

      [HKEY_CLASSES_ROOT\NeroAudioType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroAudioType\shell\print]

      [HKEY_CLASSES_ROOT\NeroAudioType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroAudioType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroAudioType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroCDCoverType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open]

      [HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroCDCoverType\shell\open\ddeexec]

      [HKEY_CLASSES_ROOT\NeroCDExtraType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroCDExtraType\shell\open]

      [HKEY_CLASSES_ROOT\NeroCDExtraType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroCDExtraType\shell\print]

      [HKEY_CLASSES_ROOT\NeroCDExtraType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroCDExtraType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroCDExtraType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroCDROMBootType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroCDROMBootType\shell\open]

      [HKEY_CLASSES_ROOT\NeroCDROMBootType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroCDROMBootType\shell\print]

      [HKEY_CLASSES_ROOT\NeroCDROMBootType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroCDROMBootType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroCDROMBootType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroCDROMEFIBootType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroCDROMEFIBootType\shell\open]

      [HKEY_CLASSES_ROOT\NeroCDROMEFIBootType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroCDROMEFIBootType\shell\print]

      [HKEY_CLASSES_ROOT\NeroCDROMEFIBootType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroCDROMEFIBootType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroCDROMEFIBootType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroCDROMHybridType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroCDROMHybridType\shell\open]

      [HKEY_CLASSES_ROOT\NeroCDROMHybridType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroCDROMHybridType\shell\print]

      [HKEY_CLASSES_ROOT\NeroCDROMHybridType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroCDROMHybridType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroCDROMHybridType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroCDROMType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroCDROMType\shell\open]

      [HKEY_CLASSES_ROOT\NeroCDROMType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroCDROMType\shell\print]

      [HKEY_CLASSES_ROOT\NeroCDROMType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroCDROMType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroCDROMType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroCopyType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroCopyType\shell\open]

      [HKEY_CLASSES_ROOT\NeroCopyType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroCopyType\shell\print]

      [HKEY_CLASSES_ROOT\NeroCopyType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroCopyType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroCopyType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroCueSheetType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroCueSheetType\shell\open]

      [HKEY_CLASSES_ROOT\NeroCueSheetType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroCueSheetType\shell\print]

      [HKEY_CLASSES_ROOT\NeroCueSheetType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroCueSheetType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroCueSheetType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroDVDVideoType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroDVDVideoType\shell\open]

      [HKEY_CLASSES_ROOT\NeroDVDVideoType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroDVDVideoType\shell\print]

      [HKEY_CLASSES_ROOT\NeroDVDVideoType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroDVDVideoType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroDVDVideoType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroErrorType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroErrorType\shell\open]

      [HKEY_CLASSES_ROOT\NeroErrorType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroErrorType\shell\print]

      [HKEY_CLASSES_ROOT\NeroErrorType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroErrorType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroErrorType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroHDBackupType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroHDBackupType\shell\open]

      [HKEY_CLASSES_ROOT\NeroHDBackupType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroHDBackupType\shell\print]

      [HKEY_CLASSES_ROOT\NeroHDBackupType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroHDBackupType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroHDBackupType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroHDBVideoType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroHDBVideoType\shell\open]

      [HKEY_CLASSES_ROOT\NeroHDBVideoType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroHDBVideoType\shell\print]

      [HKEY_CLASSES_ROOT\NeroHDBVideoType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroHDBVideoType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroHDBVideoType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroHFSType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroHFSType\shell\open]

      [HKEY_CLASSES_ROOT\NeroHFSType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroHFSType\shell\print]

      [HKEY_CLASSES_ROOT\NeroHFSType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroHFSType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroHFSType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroImageType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroImageType\shell\open]

      [HKEY_CLASSES_ROOT\NeroImageType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroImageType\shell\print]

      [HKEY_CLASSES_ROOT\NeroImageType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroImageType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroImageType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NerominiDVDType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NerominiDVDType\shell\open]

      [HKEY_CLASSES_ROOT\NerominiDVDType\shell\open\command]

      [HKEY_CLASSES_ROOT\NerominiDVDType\shell\print]

      [HKEY_CLASSES_ROOT\NerominiDVDType\shell\print\command]

      [HKEY_CLASSES_ROOT\NerominiDVDType\shell\printto]

      [HKEY_CLASSES_ROOT\NerominiDVDType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroMixedModeType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroMixedModeType\shell\open]

      [HKEY_CLASSES_ROOT\NeroMixedModeType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroMixedModeType\shell\print]

      [HKEY_CLASSES_ROOT\NeroMixedModeType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroMixedModeType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroMixedModeType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroMP3Type\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroMP3Type\shell\open]

      [HKEY_CLASSES_ROOT\NeroMP3Type\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroMP3Type\shell\print]

      [HKEY_CLASSES_ROOT\NeroMP3Type\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroMP3Type\shell\printto]

      [HKEY_CLASSES_ROOT\NeroMP3Type\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroSuperVideoType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroSuperVideoType\shell\open]

      [HKEY_CLASSES_ROOT\NeroSuperVideoType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroUDFISOType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroUDFISOType\shell\open]

      [HKEY_CLASSES_ROOT\NeroUDFISOType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroUDFISOType\shell\print]

      [HKEY_CLASSES_ROOT\NeroUDFISOType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroUDFISOType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroUDFISOType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroUDFType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroUDFType\shell\open]

      [HKEY_CLASSES_ROOT\NeroUDFType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroUDFType\shell\print]

      [HKEY_CLASSES_ROOT\NeroUDFType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroUDFType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroUDFType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroVideoType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroVideoType\shell\open]

      [HKEY_CLASSES_ROOT\NeroVideoType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroVideoType\shell\print]

      [HKEY_CLASSES_ROOT\NeroVideoType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroVideoType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroVideoType\shell\printto\command]

      [HKEY_CLASSES_ROOT\NeroWMAType\DefaultIcon]

      [HKEY_CLASSES_ROOT\NeroWMAType\shell\open]

      [HKEY_CLASSES_ROOT\NeroWMAType\shell\open\command]

      [HKEY_CLASSES_ROOT\NeroWMAType\shell\print]

      [HKEY_CLASSES_ROOT\NeroWMAType\shell\print\command]

      [HKEY_CLASSES_ROOT\NeroWMAType\shell\printto]

      [HKEY_CLASSES_ROOT\NeroWMAType\shell\printto\command]

      [HKEY_CLASSES_ROOT\ProgressLog.ProgressLogCtrl]

      [HKEY_CLASSES_ROOT\ProgressLog.ProgressLogCtrl\CLSID]

      [HKEY_CLASSES_ROOT\ProgressLog.ProgressLogCtrl\CurVer]

      [HKEY_CLASSES_ROOT\ProgressLog.ProgressLogCtrl.1]

      [HKEY_CLASSES_ROOT\ProgressLog.ProgressLogCtrl.1\CLSID]

      [HKEY_CLASSES_ROOT\QuickTime.3g2\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.3g2\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.3g2\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.3gp\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.3gp\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.3gp\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.3gp2\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.3gp2\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.3gp2\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.3gpp\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.3gpp\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.3gpp\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.aac\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.aac\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.aac\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.AC3\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.AC3\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.AC3\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.adts\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.adts\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.adts\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.aif\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.aif\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.aif\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.aifc\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.aifc\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.aifc\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.aiff\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.aiff\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.aiff\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.amc\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.amc\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.amc\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.AMR\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.AMR\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.AMR\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.au\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.au\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.au\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.avi\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.avi\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.avi\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.bwf\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.bwf\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.bwf\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.caf\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.caf\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.caf\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.cdda\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.cdda\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.cdda\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.cel\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.cel\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.cel\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.dif\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.dif\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.dif\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.dv\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.dv\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.dv\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.flc\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.flc\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.flc\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.fli\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.fli\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.fli\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.gif\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.gif\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.gif\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.gsm\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.gsm\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.gsm\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.kar\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.kar\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.kar\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m15\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m15\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m15\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m1a\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m1a\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m1a\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m1s\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m1s\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m1s\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m1v\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m1v\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m1v\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m3u\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m3u\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m3u\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m3url\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m3url\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m3url\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m4a\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m4a\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m4a\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m4b\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m4b\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m4b\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m4p\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m4p\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m4p\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m4v\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m4v\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m4v\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.m75\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.m75\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.m75\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mid\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mid\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mid\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.midi\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.midi\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.midi\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mov\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mov\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mov\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mp2\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mp2\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mp2\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mp3\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mp3\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mp3\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mp4\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mp4\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mp4\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mpa\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mpa\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mpa\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mpeg\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mpeg\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mpeg\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mpg\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mpg\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mpg\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mpm\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mpm\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mpm\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mpv\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mpv\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mpv\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.mqv\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.mqv\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.mqv\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.qcp\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.qcp\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.qcp\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.qht\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.qht\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.qht\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.qhtm\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.qhtm\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.qhtm\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.qt\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.qt\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.qt\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.qtl\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.qtl\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.qtl\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.rts\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.rts\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.rts\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.rtsp\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.rtsp\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.rtsp\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.sd2\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.sd2\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.sd2\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.sdp\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.sdp\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.sdp\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.sdv\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.sdv\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.sdv\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.smf\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.smf\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.smf\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.smi\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.smi\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.smi\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.smil\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.smil\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.smil\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.sml\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.sml\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.sml\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.snd\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.snd\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.snd\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.swa\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.swa\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.swa\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.ulw\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.ulw\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.ulw\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.vfw\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.vfw\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.vfw\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTime.wav\DefaultIcon]

      [HKEY_CLASSES_ROOT\QuickTime.wav\shell\open]

      [HKEY_CLASSES_ROOT\QuickTime.wav\shell\open\command]

      [HKEY_CLASSES_ROOT\QuickTimePlayerAddition\DefaultIcon]

      [HKEY_CLASSES_ROOT\Studio.Document\DefaultIcon]

      [HKEY_CLASSES_ROOT\Studio.Document\shell\open]

      [HKEY_CLASSES_ROOT\Studio.Document\shell\open\command]

      [HKEY_CLASSES_ROOT\SymWriter.pdb]

      [HKEY_CLASSES_ROOT\SymWriter.pdb\CLSID]

      [HKEY_CLASSES_ROOT\tcsfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeAACNero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeAACNero\shell\open]

      [HKEY_CLASSES_ROOT\TypeAACNero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeAACNero\shell\print]

      [HKEY_CLASSES_ROOT\TypeAACNero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeAACNero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeAACNero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeAmorceCRROMNero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeAmorceCRROMNero\shell\open]

      [HKEY_CLASSES_ROOT\TypeAmorceCRROMNero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeAmorceCRROMNero\shell\print]

      [HKEY_CLASSES_ROOT\TypeAmorceCRROMNero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeAmorceCRROMNero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeAmorceCRROMNero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeCDROMNero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeCDROMNero\shell\open]

      [HKEY_CLASSES_ROOT\TypeCDROMNero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeCDROMNero\shell\print]

      [HKEY_CLASSES_ROOT\TypeCDROMNero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeCDROMNero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeCDROMNero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeErreurNero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeErreurNero\shell\open]

      [HKEY_CLASSES_ROOT\TypeErreurNero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeErreurNero\shell\print]

      [HKEY_CLASSES_ROOT\TypeErreurNero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeErreurNero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeErreurNero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeImageNero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeImageNero\shell\open]

      [HKEY_CLASSES_ROOT\TypeImageNero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeImageNero\shell\print]

      [HKEY_CLASSES_ROOT\TypeImageNero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeImageNero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeImageNero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeModeMixteNero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeModeMixteNero\shell\open]

      [HKEY_CLASSES_ROOT\TypeModeMixteNero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeModeMixteNero\shell\print]

      [HKEY_CLASSES_ROOT\TypeModeMixteNero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeModeMixteNero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeModeMixteNero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeMP3Nero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeMP3Nero\shell\open]

      [HKEY_CLASSES_ROOT\TypeMP3Nero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeMP3Nero\shell\print]

      [HKEY_CLASSES_ROOT\TypeMP3Nero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeMP3Nero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeMP3Nero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeUDFISONero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeUDFISONero\shell\open]

      [HKEY_CLASSES_ROOT\TypeUDFISONero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeUDFISONero\shell\print]

      [HKEY_CLASSES_ROOT\TypeUDFISONero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeUDFISONero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeUDFISONero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeUDFNero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeUDFNero\shell\open]

      [HKEY_CLASSES_ROOT\TypeUDFNero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeUDFNero\shell\print]

      [HKEY_CLASSES_ROOT\TypeUDFNero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeUDFNero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeUDFNero\shell\printto\command]

      [HKEY_CLASSES_ROOT\TypeWMANero\DefaultIcon]

      [HKEY_CLASSES_ROOT\TypeWMANero\shell\open]

      [HKEY_CLASSES_ROOT\TypeWMANero\shell\open\command]

      [HKEY_CLASSES_ROOT\TypeWMANero\shell\print]

      [HKEY_CLASSES_ROOT\TypeWMANero\shell\print\command]

      [HKEY_CLASSES_ROOT\TypeWMANero\shell\printto]

      [HKEY_CLASSES_ROOT\TypeWMANero\shell\printto\command]

      [HKEY_CLASSES_ROOT\urn:content-classes:catalog\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:catalog-settings\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:contentclassdef\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:exchange55startaddress\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:exchangestartaddress\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:filestartaddress\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:management\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:notesstartaddress\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:remoteworkspacestartaddress\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:webstartaddress\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:wizard/addcontentclass\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:wizard/addsearchcontentlocation\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:workspace-settings\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:workspaceconfiguration\DefaultIcon]

      [HKEY_CLASSES_ROOT\urn:content-classes:workspacestartaddress\DefaultIcon]

      [HKEY_CLASSES_ROOT\VDLX.Document\shell\open]

      [HKEY_CLASSES_ROOT\VDLX.Document\shell\open\command]

      [HKEY_CLASSES_ROOT\VDLX.Document\shell\open\ddeexec]

      [HKEY_CLASSES_ROOT\Wallpaper.WallpaperManager]

      [HKEY_CLASSES_ROOT\Wallpaper.WallpaperManager\CLSID]

      [HKEY_CLASSES_ROOT\Wallpaper.WallpaperManager\CurVer]

      [HKEY_CLASSES_ROOT\Wallpaper.WallpaperManager.1]

      [HKEY_CLASSES_ROOT\Wallpaper.WallpaperManager.1\CLSID]

      [HKEY_CLASSES_ROOT\wcsfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\YPager.Messenger]

      [HKEY_CLASSES_ROOT\YPager.Messenger\CLSID]

      [HKEY_CLASSES_ROOT\YPager.Messenger\CurVer]

      [HKEY_CLASSES_ROOT\zapfile\DefaultIcon]

      [HKEY_CLASSES_ROOT\CLSID\{0083AA80-357D-11D4-876E-CA5F65139036}]

      [HKEY_CLASSES_ROOT\CLSID\{0083AA80-357D-11D4-876E-CA5F65139036}\InprocServer32]
      "ThreadingModel"="Both"

      [HKEY_CLASSES_ROOT\CLSID\{00E1F738-1122-47D4-8B13-5F9229E839FF}]

      [HKEY_CLASSES_ROOT\CLSID\{00E1F738-1122-47D4-8B13-5F9229E839FF}\InprocServer32]

      [HKEY_CLASSES_ROOT\CLSID\{00E1F738-1122-47D4-8B13-5F9229E839FF}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{00E1F738-1122-47D4-8B13-5F9229E839FF}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{00E1F738-1122-47D4-8B13-5F9229E839FF}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{00E1F738-1122-47D4-8B13-5F9229E839FF}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{0302A95D-FC12-47E9-8413-B453AE137785}]
      "AppID"="{ED512BE6-6629-4FB4-953D-D0C353847163}"

      [HKEY_CLASSES_ROOT\CLSID\{0302A95D-FC12-47E9-8413-B453AE137785}\InprocServer32]
      "ThreadingModel"="apartment"

      [HKEY_CLASSES_ROOT\CLSID\{0302A95D-FC12-47E9-8413-B453AE137785}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{0302A95D-FC12-47E9-8413-B453AE137785}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{0302A95D-FC12-47E9-8413-B453AE137785}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{0302A95D-FC12-47E9-8413-B453AE137785}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{041287C6-DD49-11D3-AB88-00A024B5DE6F}]
      "AppID"="{041287C4-DD49-11D3-AB88-00A024B5DE6F}"

      [HKEY_CLASSES_ROOT\CLSID\{041287C6-DD49-11D3-AB88-00A024B5DE6F}\LocalServer32]

      [HKEY_CLASSES_ROOT\CLSID\{041287C6-DD49-11D3-AB88-00A024B5DE6F}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{041287C6-DD49-11D3-AB88-00A024B5DE6F}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{041287C6-DD49-11D3-AB88-00A024B5DE6F}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{041287C6-DD49-11D3-AB88-00A024B5DE6F}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{041287CB-DD49-11D3-AB88-00A024B5DE6F}]
      "AppID"="{041287C4-DD49-11D3-AB88-00A024B5DE6F}"

      [HKEY_CLASSES_ROOT\CLSID\{041287CB-DD49-11D3-AB88-00A024B5DE6F}\LocalServer32]

      [HKEY_CLASSES_ROOT\CLSID\{041287CB-DD49-11D3-AB88-00A024B5DE6F}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{041287CB-DD49-11D3-AB88-00A024B5DE6F}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{041287CB-DD49-11D3-AB88-00A024B5DE6F}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{041287CB-DD49-11D3-AB88-00A024B5DE6F}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}]

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}\Control]

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}\InprocServer32]
      "ThreadingModel"="Apartment"

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}\MiscStatus]

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}\MiscStatus\1]

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}\ToolboxBitmap32]

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{070655DC-6AD9-4BB3-A7F9-78359689FBD7}\Version]

      [HKEY_CLASSES_ROOT\CLSID\{0724F708-270F-4E80-85A6-F4472D5126CC}]

      [HKEY_CLASSES_ROOT\CLSID\{0724F708-270F-4E80-85A6-F4472D5126CC}\InprocServer32]
      "ThreadingModel"="Both"

      [HKEY_CLASSES_ROOT\CLSID\{0b1511cd-37ee-4f0a-9647-cb2785b68a29}]

      [HKEY_CLASSES_ROOT\CLSID\{0b1511cd-37ee-4f0a-9647-cb2785b68a29}\InprocServer32]
      "ThreadingModel"="Apartment"

      [HKEY_CLASSES_ROOT\CLSID\{0b1511cd-37ee-4f0a-9647-cb2785b68a29}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{0b1511cd-37ee-4f0a-9647-cb2785b68a29}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{0b1511cd-37ee-4f0a-9647-cb2785b68a29}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{0b1511cd-37ee-4f0a-9647-cb2785b68a29}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}]

      [HKEY_CLASSES_ROOT\CLSID\{0B785C4A-8E74-4db2-87A7-2D5BF9C6E55C}\InprocServer32]

      [HKEY_CLASSES_ROOT\CLSID\{0E654C56-D988-472B-9D03-BA6CCC9E7EAF}]

      [HKEY_CLASSES_ROOT\CLSID\{0E654C56-D988-472B-9D03-BA6CCC9E7EAF}\InprocServer32]
      "ThreadingModel"="Both"

      [HKEY_CLASSES_ROOT\CLSID\{0edcdb7d-cd9e-44e6-9e9a-adbaa85540e8}]

      [HKEY_CLASSES_ROOT\CLSID\{0edcdb7d-cd9e-44e6-9e9a-adbaa85540e8}\InprocServer32]
      "ThreadingModel"="Apartment"

      [HKEY_CLASSES_ROOT\CLSID\{0edcdb7d-cd9e-44e6-9e9a-adbaa85540e8}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{0edcdb7d-cd9e-44e6-9e9a-adbaa85540e8}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{0edcdb7d-cd9e-44e6-9e9a-adbaa85540e8}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{0edcdb7d-cd9e-44e6-9e9a-adbaa85540e8}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{138130AF-A79B-45D5-B4AA-87697457BA87}]

      [HKEY_CLASSES_ROOT\CLSID\{138130AF-A79B-45D5-B4AA-87697457BA87}\InprocServer32]
      "ThreadingModel"="Both"

      [HKEY_CLASSES_ROOT\CLSID\{14AF36A0-23BD-48E4-8B37-517C24B09FC9}]

      [HKEY_CLASSES_ROOT\CLSID\{14AF36A0-23BD-48E4-8B37-517C24B09FC9}\InprocServer32]
      "ThreadingModel"="Both"

      [HKEY_CLASSES_ROOT\CLSID\{1588A1C4-D709-4F78-8C3F-E1EEBFDE98B8}]

      [HKEY_CLASSES_ROOT\CLSID\{1588A1C4-D709-4F78-8C3F-E1EEBFDE98B8}\InprocServer32]

      [HKEY_CLASSES_ROOT\CLSID\{1796A329-04C1-4C07-B28E-E4A807935C06}]
      "AppID"="{46A99B9C-4AC8-4EE9-AF7D-D02816CEC314}"

      [HKEY_CLASSES_ROOT\CLSID\{1796A329-04C1-4C07-B28E-E4A807935C06}\LocalServer32]

      [HKEY_CLASSES_ROOT\CLSID\{1796A329-04C1-4C07-B28E-E4A807935C06}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1796A329-04C1-4C07-B28E-E4A807935C06}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{1796A329-04C1-4C07-B28E-E4A807935C06}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{1796A329-04C1-4C07-B28E-E4A807935C06}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1810360D-0FC7-474B-ABC1-84E96BF51D2F}]
      "AppID"="{EADB5B4B-D99B-4B18-9BCA-108EAAE88F24}"

      [HKEY_CLASSES_ROOT\CLSID\{1810360D-0FC7-474B-ABC1-84E96BF51D2F}\LocalServer32]

      [HKEY_CLASSES_ROOT\CLSID\{1810360D-0FC7-474B-ABC1-84E96BF51D2F}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{190B0C37-E066-11D3-AB88-00A024B5DE6F}]
      "AppID"="{041287C4-DD49-11D3-AB88-00A024B5DE6F}"

      [HKEY_CLASSES_ROOT\CLSID\{190B0C37-E066-11D3-AB88-00A024B5DE6F}\LocalServer32]

      [HKEY_CLASSES_ROOT\CLSID\{190B0C37-E066-11D3-AB88-00A024B5DE6F}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{190B0C37-E066-11D3-AB88-00A024B5DE6F}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{190B0C37-E066-11D3-AB88-00A024B5DE6F}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{190B0C37-E066-11D3-AB88-00A024B5DE6F}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}]
      "AppID"="{46A99B9C-4AC8-4EE9-AF7D-D02816CEC314}"

      [HKEY_CLASSES_ROOT\CLSID\{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}\LocalServer32]

      [HKEY_CLASSES_ROOT\CLSID\{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{1A239250-B650-4B63-B4CF-7FCC4DC07DC6}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}]
      "AppID"="{46A99B9C-4AC8-4EE9-AF7D-D02816CEC314}"

      [HKEY_CLASSES_ROOT\CLSID\{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}\LocalServer32]

      [HKEY_CLASSES_ROOT\CLSID\{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{1AEDB68D-18A7-4CA9-B41B-3CE7E59FAB24}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1C508980-77FB-411F-93CB-83E3B5392394}]

      [HKEY_CLASSES_ROOT\CLSID\{1C508980-77FB-411F-93CB-83E3B5392394}\InprocServer32]

      [HKEY_CLASSES_ROOT\CLSID\{1C508980-77FB-411F-93CB-83E3B5392394}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1C508980-77FB-411F-93CB-83E3B5392394}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{1C508980-77FB-411F-93CB-83E3B5392394}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{1C508980-77FB-411F-93CB-83E3B5392394}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1c613f47-70c5-4551-a264-f7254139854c}]

      [HKEY_CLASSES_ROOT\CLSID\{1c613f47-70c5-4551-a264-f7254139854c}\InprocServer32]
      "ThreadingModel"="Apartment"

      [HKEY_CLASSES_ROOT\CLSID\{1c613f47-70c5-4551-a264-f7254139854c}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1c613f47-70c5-4551-a264-f7254139854c}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{1c613f47-70c5-4551-a264-f7254139854c}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{1c613f47-70c5-4551-a264-f7254139854c}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{1E404D48-670A-4085-A6A0-D195793DDD33}]

      [HKEY_CLASSES_ROOT\CLSID\{1E404D48-670A-4085-A6A0-D195793DDD33}\InProcServer32]
      "ThreadingModel"="Both"

      [HKEY_CLASSES_ROOT\CLSID\{2018C303-E3F2-4455-AA1A-773F84F10902}]
      "AppID"="{5DF1991D-0670-4D2C-9321-E9E650969320}"

      [HKEY_CLASSES_ROOT\CLSID\{2018C303-E3F2-4455-AA1A-773F84F10902}\InprocServer32]
      "ThreadingModel"="Apartment"

      [HKEY_CLASSES_ROOT\CLSID\{2018C303-E3F2-4455-AA1A-773F84F10902}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{2018C303-E3F2-4455-AA1A-773F84F10902}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{2018C303-E3F2-4455-AA1A-773F84F10902}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{2018C303-E3F2-4455-AA1A-773F84F10902}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{2293107A-87F9-4BE1-858E-FF1D96956D82}]

      [HKEY_CLASSES_ROOT\CLSID\{2293107A-87F9-4BE1-858E-FF1D96956D82}\InprocServer32]

      [HKEY_CLASSES_ROOT\CLSID\{2447902A-29D9-4101-8C63-55D46C78CBC5}]

      [HKEY_CLASSES_ROOT\CLSID\{2447902A-29D9-4101-8C63-55D46C78CBC5}\InprocServer32]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\Control]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\InprocServer32]
      "ThreadingModel"="Apartment"

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\MiscStatus]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\MiscStatus\1]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\ToolboxBitmap32]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\Version]

      [HKEY_CLASSES_ROOT\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{26897554-A4D8-4973-B229-1179A879460D}]

      [HKEY_CLASSES_ROOT\CLSID\{26897554-A4D8-4973-B229-1179A879460D}\InProcServer32]
      "ThreadingModel"="Both"

      [HKEY_CLASSES_ROOT\CLSID\{283AEB67-7D7B-4771-9B70-634CE1CBDA82}]

      [HKEY_CLASSES_ROOT\CLSID\{283AEB67-7D7B-4771-9B70-634CE1CBDA82}\InprocServer32]

      [HKEY_CLASSES_ROOT\CLSID\{283AEB67-7D7B-4771-9B70-634CE1CBDA82}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{283AEB67-7D7B-4771-9B70-634CE1CBDA82}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{283AEB67-7D7B-4771-9B70-634CE1CBDA82}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{283AEB67-7D7B-4771-9B70-634CE1CBDA82}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\CLSID\{292AE934-4F49-40bb-9E7E-6F6398ED9C31}]

      [HKEY
      0
  7. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    AVG l'as tu paramétré de manière à mettre en quarantaine ?
    tout est "ignoré"

    Recommence le scan et poste le nouveau rapport stp mais avant assure toi de :

    fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.

    Puis sur l'onglet Paramètres,
    sous : "Comment réagir "clique sur Actions recommandées. Sélectionne Quarantaine.

    Reviens à l'onglet Analyse. Clique sur Analyse complète du système.

    A la fin du scan, choisis l'option 3

    "Appliquer toutes les actions " en bas.

    Clique sur "Enregistrer le rapport".

    Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

    Poste le.

    reposte également un nouveau rapport hijackthis
    0
    1. aliepeet Messages postés 31 Statut Membre
       
      Désoléé du délais...

      Alors en premier lieu, voici 2 registres ccleaner;


      Windows Registry Editor Version 5.00


      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\Downloaded Program Files\\installer2.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\HPQ\\Safety and Comfort Guide\\PchCabInstall.vbs"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\HPQ\\Safety and Comfort Guide\\ahpregw.cab"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\MSIMRT.DLL"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\DIMM.DLL"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\QTPlugin.OCX"=dword:000003e6

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\ndpsetup.ico"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\msxml3a.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Documents and Settings\\All Users\\Application Data\\YAHOO\\YMP\\LabelLic.xml"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\System32\\NeroCheck.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\Aiff.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\DefConvertor.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\msa.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\Vqf.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\wav.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\DriveLocker.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\NeroCBUI.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeFileSrc.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeRender.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\ImagX7.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\apreg.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeAudio.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeAMR.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeVideo.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\Aac.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\aacenc32.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NDParser.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\NeQTDec.ax"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\DSFilter\\aacplus.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\AdvrCntr.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\Lib\\NeroIPP.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\ogg.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\Templates\\Data.nct"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\LSTemplates\\Audio_Content.nct"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\covered-deu.nls"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\covered-jpn.nls"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\CoverEdCtrl.ocx"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\WINDOWS\\system32\\TwnLib20.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\CoverDesigner\\CoverDes.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp-Deu.nls"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\WMPBurn\\WMPBurn.exe"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp-Jpn.nls"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\mp3PP.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\mp3PRO.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Program Files\\Fichiers communs\\Ahead\\AudioPlugins\\lame_enc.dll"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\mscoree.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\mscorlib.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.Drawing.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.EnterpriseServices.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.Vsa.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.JScript.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "c:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.Windows.Forms.tlb"=dword:00001000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
      "C:\\Documents and Settings\\All Users\\Application Data\\Adobe\\Photoshop Album\\Catalogues\\My Catalog.psa"=dword:00000001

      [HKEY_CLASSES_ROOT\.7z]

      [HKEY_CLASSES_ROOT\.ace]

      [HKEY_CLASSES_ROOT\.arj]

      [HKEY_CLASSES_ROOT\.bz]

      [HKEY_CLASSES_ROOT\.bz2]

      [HKEY_CLASSES_ROOT\.ids]

      [HKEY_CLASSES_ROOT\.iso]

      [HKEY_CLASSES_ROOT\.lha]

      [HKEY_CLASSES_ROOT\.lzh]

      [HKEY_CLASSES_ROOT\.mst]

      [HKEY_CLASSES_ROOT\.taz]

      [HKEY_CLASSES_ROOT\.tbz]

      [HKEY_CLASSES_ROOT\.tbz2]

      [HKEY_CLASSES_ROOT\.uu]

      [HKEY_CLASSES_ROOT\.uue]

      [HKEY_CLASSES_ROOT\.vfo]

      [HKEY_CLASSES_ROOT\.vfs]

      [HKEY_CLASSES_ROOT\.xxe]

      [HKEY_CLASSES_ROOT\ATLPlugin.ATL3DShapeSphere=]

      [HKEY_CLASSES_ROOT\FMObex.Semc.FMObjectProperties=]

      [HKEY_CLASSES_ROOT\FMObexServer.Sony]

      [HKEY_CLASSES_ROOT\ObexAuthenticationServiceDll.Sony]

      [HKEY_CLASSES_ROOT\ObexOperationDll.Sony]

      [HKEY_CLASSES_ROOT\OISbmpfile]

      [HKEY_CLASSES_ROOT\OISemffile]

      [HKEY_CLASSES_ROOT\OISgiffile]

      [HKEY_CLASSES_ROOT\OISpngfile]

      [HKEY_CLASSES_ROOT\OIStiffile]

      [HKEY_CLASSES_ROOT\OISwmffile]

      [HKEY_CLASSES_ROOT\PclePlayout.PlayoutFactoryHAL=]

      [HKEY_CLASSES_ROOT\s]

      [HKEY_CLASSES_ROOT\WMPCD]

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithList]

      [HKEY_CLASSES_ROOT\LimeWire\DefaultIcon]

      [HKEY_CLASSES_ROOT\LimeWire\shell\open]

      [HKEY_CLASSES_ROOT\LimeWire\shell\open\command]

      [HKEY_CLASSES_ROOT\magnet\DefaultIcon]

      [HKEY_CLASSES_ROOT\magnet\shell\open]

      [HKEY_CLASSES_ROOT\magnet\shell\open\command]

      [HKEY_CLASSES_ROOT\MMJB.MMZ\DefaultIcon]

      [HKEY_CLASSES_ROOT\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}]
      "AppID"="{6E1E6AB9-6DCF-44C0-9D49-B51AFE8C027F}"

      [HKEY_CLASSES_ROOT\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\InprocServer32]
      "ThreadingModel"="Apartment"

      [HKEY_CLASSES_ROOT\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ProgID]

      [HKEY_CLASSES_ROOT\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\Programmable]

      [HKEY_CLASSES_ROOT\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\TypeLib]

      [HKEY_CLASSES_ROOT\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\VersionIndependentProgID]

      [HKEY_CLASSES_ROOT\Applications\moviemk.exe]

      [HKEY_CLASSES_ROOT\Applications\moviemk.exe\shell]
      "FriendlyCache"="Movie Maker"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
      "nwindcs9.hlp"="C:\\Program Files\\Microsoft Office\\Office\\Samples\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
      "nwindcs9.cnt"="C:\\Program Files\\Microsoft Office\\Office\\Samples\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
      "nwind9.hlp"="C:\\Program Files\\Microsoft Office\\Office\\Samples\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
      "nwind9.cnt"="C:\\Program Files\\Microsoft Office\\Office\\Samples\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
      "nmplace.hlp"="C:\\Program Files\\Microsoft Office\\Office\\1036\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
      "sbcmpss.hlp"="C:\\Program Files\\Microsoft Office\\Office\\1036\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
      "snapview.hlp"="C:\\Program Files\\Microsoft Office\\Office\\1036\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
      "scanpst.hlp"="C:\\Program Files\\Fichiers communs\\SYSTEM\\MSMAPI\\1036\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help]
      "artgalry.chm"="C:\\Program Files\\Microsoft Office\\Office\\1036\\"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\"="1"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\ActiveX\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\Microsoft .NET Framework 2.0\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Documents and Settings\\All Users\\Application Data\\SmartSound Software Inc\\Encoding\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Adobe\\Reader 8.0\\Setup Files\\{AC76BA86-7AD7-1036-7B44-A81000000003}\\"="1"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\WINDOWS\\Installer\\{AC76BA86-7AD7-1036-7B44-A81000000003}\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\skins\\"="1"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\skins\\SlipStream\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\skins\\SlipStream\\theme\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\WINDOWS\\winsxs\\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\WINDOWS\\winsxs\\Policies\\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Adobe\\Reader 8.0\\Update\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Sygate\\SPF\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Sygate\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Sygate\\SPF\\Help\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Sygate\\SPF\\Install\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Program Files\\Sygate\\SPF\\Netport\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
      "C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Sygate Personal Firewall\\"=""

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Deewoo Network Manager]
      "DisplayName"="Deewoo Network Manager removal"
      "UninstallString"="C:\\WINDOWS\\system32\\ocntokdm.exe -UPop"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 2.0]
      "DisplayIcon"="C:\\WINDOWS\\system32\\msiexec.exe"
      "DisplayName"="Microsoft .NET Framework 2.0"
      "UninstallString"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\Microsoft .NET Framework 2.0\\install.exe"
      "VersionMinor"="0"
      "VersionMajor"="2"
      "Publisher"="Microsoft Corporation"
      "InstallLocation"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\"
      "UninstallPath"="C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\Microsoft .NET Framework 2.0\\install.exe"
      "URLUpdateInfo"="https://visualstudio.microsoft.com/"
      "HelpLink"="https://support.microsoft.com/ph/8291"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\SudoPlanet]
      "DisplayName"="SudoPlanet"
      "UninstallString"="C:\\Program Files\\SudoPlanet\\uninst.exe"
      "UninstallString2"="\"C:\\Program Files\\SudoPlanet\\uninst.exe\" /S"
      "DisplayIcon"="C:\\Program Files\\SudoPlanet\\SudoPlanet.exe"
      "DisplayVersion"="1.0"
      "URLInfoAbout"="http://www.sudoplanet.com/"
      "Publisher"="OOO «Favorit»"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Adobe Acrobat 4.0]
      "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,50,6d,00,00,00,00,00,a6,e6,e0,\
      7b,53,3d,c5,01,05,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
      61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,41,00,64,00,6f,00,62,\
      00,65,00,5c,00,41,00,63,00,72,00,6f,00,62,00,61,00,74,00,20,00,34,00,2e,00,\
      30,00,5c,00,52,00,65,00,61,00,64,00,65,00,72,00,5c,00,41,00,63,00,72,00,6f,\
      00,52,00,64,00,33,00,32,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,a0,71,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917283.T1_1ToU93_1]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
      00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922770.T1_1ToU168_1]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
      00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LiveReg]
      "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,e0,2d,00,00,00,00,00,ff,ff,ff,\
      ff,ff,ff,ff,ff,02,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
      61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,46,00,69,00,63,00,68,\
      00,69,00,65,00,72,00,73,00,20,00,63,00,6f,00,6d,00,6d,00,75,00,6e,00,73,00,\
      5c,00,53,00,79,00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,\
      00,72,00,65,00,64,00,5c,00,4c,00,69,00,76,00,65,00,52,00,65,00,67,00,5c,00,\
      49,00,72,00,61,00,4c,00,72,00,53,00,68,00,6c,00,2e,00,65,00,78,00,65,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LiveUpdate]
      "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,d0,51,00,00,00,00,00,ff,ff,ff,\
      ff,ff,ff,ff,ff,02,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
      61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
      00,6e,00,74,00,65,00,63,00,5c,00,4c,00,69,00,76,00,65,00,55,00,70,00,64,00,\
      61,00,74,00,65,00,5c,00,41,00,4c,00,55,00,4e,00,4f,00,54,00,49,00,46,00,59,\
      00,2e,00,45,00,58,00,45,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,74,2f,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3877C2CD-F137-4144-BDB2-0A811492F920}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
      00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3E439F9C-CCF8-4AB8-8AE1-063F2042A78B}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
      00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{7882C030-705A-45FF-A705-DC6089DC51BF}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,04,eb,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{9D4251DB-E86C-4A9B-BAEA-C9726BD7282B}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
      00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A394E835-C8D6-4B4B-884B-D2709059F3BE}]
      "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,70,01,00,00,00,00,00,88,05,d7,\
      4b,35,c3,c8,01,02,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
      61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4e,00,65,00,74,00,77,\
      00,6f,00,72,00,6b,00,20,00,4d,00,6f,00,6e,00,69,00,74,00,6f,00,72,00,5c,00,\
      6e,00,65,00,74,00,6d,00,6f,00,6e,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AC76BA86-7AD7-0000-2550-7A8C40000000}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
      00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AC76BA86-7AD7-1036-7B44-A00000000001}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,d8,48,03,00,00,00,00,00,00,00,\
      00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AC76BA86-7AD7-1036-7B44-A70900000002}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,70,ca,04,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C6F1E87D-F3E1-4874-97EC-F87DAB6D6878}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
      00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CBBF4242-B809-3664-7ACA-18ED4EA7126F}]
      "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}]
      "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,d8,1d,00,00,00,00,00,72,65,63,\
      27,03,4a,c7,01,00,00,00,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
      57,00,53,00,5c,00,49,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,65,00,72,00,5c,\
      00,7b,00,46,00,36,00,33,00,32,00,36,00,42,00,36,00,30,00,2d,00,31,00,42,00,\
      31,00,44,00,2d,00,34,00,41,00,42,00,46,00,2d,00,42,00,46,00,43,00,44,00,2d,\
      00,37,00,42,00,37,00,34,00,30,00,34,00,46,00,34,00,34,00,34,00,31,00,31,00,\
      7d,00,5c,00,4d,00,73,00,62,00,6c,00,49,00,63,00,6f,00,2e,00,45,00,78,00,65,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
      00,00,00,00,00,00,00,00
      "Changed"=dword:00000000

      [HKEY_CURRENT_USER\Software\AntiVirus]

      [HKEY_LOCAL_MACHINE\Software\Mozilla]

      [HKEY_LOCAL_MACHINE\Software\MusicNet]

      [HKEY_LOCAL_MACHINE\Software\RealNetworks]

      [HKEY_LOCAL_MACHINE\Software\Sonic]

      [HKEY_LOCAL_MACHINE\Software\Symantec]

      [HKEY_LOCAL_MACHINE\Software\Trad-FR]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Antivirus"="C:\\Program Files\\VAV\\vav.exe"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "lhgngmflfg"="c:\\windows\\system32\\lhgngmflfg.exe lhgngmflfg"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "LSA Shellu"="C:\\Documents and Settings\\carriou\\lsass.exe"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Antivirus"="C:\\Program Files\\VAV\\vav.exe"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "TheSpyBot"="C:\\Program Files\\TheSpyBot\\TheSpyBot.exe"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Program Files\\VAV\\vav.exe"="Vista Antivirus 2008"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Documents and Settings\\Internet et MSN\\Local Settings\\Temporary Internet Files\\Content.IE5\\7VHLSKV2\\install_3968_MXw1fHx8fHx8fA_[1].exe"="install_3968_MXw1fHx8fHx8fA_[1]"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Program Files\\TheSpyBot\\TheSpyBot.exe"="TheSpyBot"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Program Files\\TheSpyBot\\Uninstall.exe"="Uninstall"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Documents and Settings\\Internet et MSN\\Local Settings\\Temporary Internet Files\\Content.IE5\\V8N5ZC2C\\avgas-setup-7.5.1.43[1].exe"="avgas-setup-7.5.1.43[1]"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Documents and Settings\\Internet et MSN\\Local Settings\\Temporary Internet Files\\Content.IE5\\WIXPGHZD\\HJTInstall[1].exe"="HijackThis"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Documents and Settings\\Internet et MSN\\Local Settings\\Temporary Internet Files\\Content.IE5\\ASMOO9I1\\wmp11-windowsxp-x86-FR-FR[1].exe"="wmp11-windowsxp-x86-FR-FR[1]"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Documents and Settings\\Internet et MSN\\Local Settings\\Temporary Internet Files\\Content.IE5\\45CM4FV4\\Lavasoft_Adaware_multi[1].exe"="Ad-Aware"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
      "C:\\Documents and Settings\\Internet et MSN\\Local Settings\\Temporary Internet Files\\Content.IE5\\NJUFVJNJ\\ccsetup208[1].exe"="CCleaner Installer"

      et le deuxieme

      Windows Registry Editor Version 5.00


      [HKEY_CLASSES_ROOT\Installer.InstallerObj]

      [HKEY_CLASSES_ROOT\Installer.InstallerObj\CLSID]

      [HKEY_CLASSES_ROOT\Installer.InstallerObj\CurVer]

      [HKEY_CLASSES_ROOT\Installer.InstallerObj.2]

      [HKEY_CLASSES_ROOT\Installer.InstallerObj.2\CLSID]

      et le rapport ccleaner

      NETTOYAGE COMPLET - (32.520 secs)
      ------------------------------------------------------------------------------------------
      27,3MB supprimés.
      ------------------------------------------------------------------------------------------

      Détails des fichiers effacés
      ------------------------------------------------------------------------------------------
      Fichiers Temporaires d'Internet Explorer (fichiers 1514) 25,7MB
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@rad.msn[2].txt 680 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[7].txt 70 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@affiliates.nexpartner[2].txt 293 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@67.205.95[3].txt 438 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@vlaze[2].txt 434 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@85.17.166[3].txt 166 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@scanner.vav-scanner[3].txt 170 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@speedbit[2].txt 270 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@live[3].txt 514 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@www.dailymotion[1].txt 75 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adstronic[1].txt 125 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@64.22.123[2].txt 106 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@ads.react2media[3].txt 340 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@windowsmarketplace[3].txt 263 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@em.gad-network[3].txt 159 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@ads.vlaze[1].txt 105 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@fr.msn[2].txt 563 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@banner.cotedazurpalace[3].txt 290 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@adnetserver[3].txt 332 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@85.12.43[3].txt 273 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@login.live[3].txt 181 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@82.98.235[8].txt 70 bytes
      C:\Documents and Settings\Internet et MSN\Cookies\internet_et_msn@detoxit
      0
    2. aliepeet Messages postés 31 Statut Membre
       
      et enfin mon dernier scan sur bitdefender

      BitDefender Online Scanner



      Scan report generated at: Mon, Jun 09, 2008 - 02:30:19





      Scan path: C:\;D:\;







      Statistics

      Time
      01:59:42

      Files
      252723

      Folders
      6612

      Boot Sectors
      2

      Archives
      8958

      Packed Files
      21117




      Results

      Identified Viruses
      16

      Infected Files
      22

      Suspect Files
      0

      Warnings
      0

      Disinfected
      0

      Deleted Files
      21




      Engines Info

      Virus Definitions
      1256958

      Engine build
      AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

      Scan plugins
      16

      Archive plugins
      42

      Unpack plugins
      7

      E-mail plugins
      6

      System plugins
      5




      Scan Settings

      First Action
      Disinfect

      Second Action
      Delete

      Heuristics
      Yes

      Enable Warnings
      Yes

      Scanned Extensions
      *;

      Exclude Extensions


      Scan Emails
      Yes

      Scan Archives
      Yes

      Scan Packed
      Yes

      Scan Files
      Yes

      Scan Boot
      Yes




      Scanned File
      Status

      C:\Documents and Settings\carriou\Application Data\Sun\Java\Deployment\cache\6.0\34\6df4ce22-29a2a78c=>NewURLClassLoader.class
      Infected with: Java.Trojan.Exploit.Bytverify

      C:\Documents and Settings\carriou\Application Data\Sun\Java\Deployment\cache\6.0\34\6df4ce22-29a2a78c=>NewURLClassLoader.class
      Disinfection failed

      C:\Documents and Settings\carriou\Application Data\Sun\Java\Deployment\cache\6.0\34\6df4ce22-29a2a78c=>NewURLClassLoader.class
      Deleted

      C:\Documents and Settings\carriou\Application Data\Sun\Java\Deployment\cache\6.0\34\6df4ce22-29a2a78c
      Updated

      C:\Documents and Settings\carriou\Local Settings\Temp\jar_cache11746.tmp=>NewURLClassLoader.class
      Infected with: Java.Trojan.Exploit.Bytverify

      C:\Documents and Settings\carriou\Local Settings\Temp\jar_cache11746.tmp=>NewURLClassLoader.class
      Disinfection failed

      C:\Documents and Settings\carriou\Local Settings\Temp\jar_cache11746.tmp=>NewURLClassLoader.class
      Deleted

      C:\Documents and Settings\carriou\Local Settings\Temp\jar_cache11746.tmp
      Updated

      C:\Program Files\VAV\vav.exe
      Infected with: GenPack:Trojan.FakeAV.I

      C:\Program Files\VAV\vav.exe
      Disinfection failed

      C:\Program Files\VAV\vav.exe
      Delete failed

      C:\smss.exe
      Infected with: Dropped:Trojan.Downloader.VB.VPG

      C:\smss.exe
      Disinfection failed

      C:\smss.exe
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167809.dll
      Detected with: Adware.BHO.WRG

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167809.dll
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167833.exe=>(NSIS 2g)=>bzip2_solid_nsis0002
      Detected with: Adware.BHO.WRG

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167833.exe=>(NSIS 2g)=>bzip2_solid_nsis0002
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167833.exe=>(NSIS 2g)
      Update failed

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167834.exe
      Infected with: Trojan.Generic.271296

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167834.exe
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167835.exe
      Detected with: Adware.PlayMp3z.A

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167835.exe
      Disinfection failed

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP489\A0167835.exe
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194002.exe
      Detected with: Adware.BHO.WRH

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194002.exe
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194003.dll
      Detected with: Adware.BHO.WRG

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194003.dll
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194013.exe
      Detected with: Adware.BHO.WRH

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194013.exe
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194050.exe
      Infected with: Trojan.Downloader.Matcash.J

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194050.exe
      Disinfection failed

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194050.exe
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194051.dll
      Infected with: MemScan:Trojan.Vundo.ENL

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194051.dll
      Disinfection failed

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194051.dll
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194052.dll
      Detected with: Adware.CommAd.A

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194052.dll
      Disinfection failed

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194052.dll
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194053.exe
      Infected with: Trojan.Generic.107114

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194053.exe
      Disinfection failed

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP491\A0194053.exe
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP495\A0195208.exe
      Infected with: Trojan.Generic.278812

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP495\A0195208.exe
      Deleted

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP495\A0195210.exe
      Infected with: Dropped:Trojan.Downloader.VB.VPG

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP495\A0195210.exe
      Disinfection failed

      C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP495\A0195210.exe
      Deleted

      C:\WINDOWS\Downloaded Program Files\installer2.dll
      Detected with: Adware.Clickmedia.A

      C:\WINDOWS\Downloaded Program Files\installer2.dll
      Deleted

      C:\WINDOWS\system32\gside.exe=>(NSIS o)=>bzip2_solid_nsis0002
      Detected with: Adware.BHO.WRG

      C:\WINDOWS\system32\gside.exe=>(NSIS o)=>bzip2_solid_nsis0002
      Deleted

      C:\WINDOWS\system32\gside.exe=>(NSIS o)
      Update failed

      C:\WINDOWS\system32\pac.txt
      Infected with: Trojan.Downloader.VB.VPG

      C:\WINDOWS\system32\pac.txt
      Deleted

      C:\WINDOWS\system32\yayxxuus.dll
      Infected with: Trojan.Vundo.ERD

      C:\WINDOWS\system32\yayxxuus.dll
      Deleted

      C:\WINDOWS\uninstall_nmon.vbs
      Infected with: Trojan.Small.WY

      C:\WINDOWS\uninstall_nmon.vbs
      Deleted

      Voilà, esperons que ceci éclairera ta lanterne, moi j'y comprends rien!! lol Merci beaucoup en tout cas!!
      0
  8. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    Salut

    Fais un clic droit sur ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Fais un clic droit sur navilog1.zip et choisis "tout extraire"
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    TUTO :: http://www.malekal.com/Adware.Magic_Control.php

    Télécharge SmitfraudFix
    Utilitaire de S!Ri: Moe et balltrap34
    http://siri.urz.free.fr/Fix/SmitfraudFix.php
    et télécharge SmitfraudFix.exe.

    Regarde le tuto

    Exécute le en choisissant l’option 1,
    il va générer un rapport
    Copie/colle le sur le poste stp.

    Bon courage
    A++

    0