Rapport hitjackis svp

Résolu/Fermé
celine391 Messages postés 12 Date d'inscription lundi 17 novembre 2008 Statut Membre Dernière intervention 28 septembre 2012 - 17 nov. 2008 à 18:49
 Utilisateur anonyme - 19 nov. 2008 à 15:44
Bonjour,
je fais appel a vous car j ai un gros probleme avec mon ordi.plus moyen de le mettre a jour,et il rame ,jusqu a reste bloque des que j ouvre deux pages.j ai tout essaye:change avast pour avg,ccleaner,spybot il ne veut meme plus me faire une restauration systeme!alors mon dernier recours c est vous et hitjackis si vous pouviez m aider!voila mon rapportLogfile of HijackThis v1.99.1
Scan saved at 18:31:26, on 17/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Autodata Limited Shared\Service\ADCDLicSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Tele2\Common\FSMA32.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Tele2\Common\FSMB32.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tele2\Common\FCH32.EXE
C:\Program Files\Tele2\Common\FAMEH32.EXE
C:\Program Files\Tele2\FSPC\fspc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Tele2\FSAUA\program\fsaua.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Tele2\FSAUA\program\fsus.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\2f92d48fd4dd6c3e29f57417ec6cf1d9\update\update.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\AGRSMMSG.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tele2\Common\FSM32.EXE
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Tele2\FSGUI\fsguidll.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/french
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Tele2\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [rdxjtpa] c:\documents and settings\compaq_propriétaire\local settings\application data\rdxjtpa.exe rdxjtpa
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.15\AMVConverter\grab.html
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.15\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Tele2\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Tele2\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Tele2\FSPC\fspcmsie.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\tele2\fsps\program\fslsp.dll
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://express.foto.com/Newuploader/ImageUploader4.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodata Limited License Service - Unknown owner - C:\Program Files\Fichiers communs\Autodata Limited Shared\Service\ADCDLicSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Tele2\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Tele2\Common\FSMA32.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\system32\wdfmgr.exe (file missing)
merci de votre aide

14 réponses

Utilisateur anonyme
17 nov. 2008 à 18:53
salut ton hijackthis est un peu vieux..........

ensuite tu es infectee par Navipromo donc pour commencer :


Fais un clic droit sur ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Fais un clic droit sur navilog1.zip et choisis "tout extraire"
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

Laisse-toi guider. Au menu principal, choisis 1 et valides.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le blocnote.
Le rapport est en outre sauvegardé à la racine du disque (C:\fixnavi.txt)
TUTO :: http://www.malekal.com/Adware.Magic_Control.php

0
celine391 Messages postés 12 Date d'inscription lundi 17 novembre 2008 Statut Membre Dernière intervention 28 septembre 2012
17 nov. 2008 à 19:27
merci.c est vrai mon hitjackis vieux lol mais ca faisait logtemps que j avais pas ete infectee.alors voila j ai fait ce que tu m as ditSearch Navipromo version 3.6.9 commencé le 17/11/2008 à 19:06:35,29

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Compaq_Propriétaire"

Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : NTFS

Recherche executé en mode normal

*** Recherche Programmes installés ***

Favorit

*** Recherche dossiers dans "C:\WINDOWS" ***


*** Recherche dossiers dans "C:\Program Files" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\amandine\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\AMANDI~1.ALE\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\celia\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\COMPAQ~2\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\INVIT~1.ALE\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\kime\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\seb\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\amandine\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\AMANDI~1.ALE\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\celia\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\INVIT~1.ALE\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\kime\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\seb\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\AMANDI~1.ALE\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\INVIT~1.ALE\menudm~1\progra~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\kime\menudm~1\progra~1" ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\WINDOWS\system32" *

* Recherche dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\amandine\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\AMANDI~1.ALE\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\celia\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\INVIT~1.ALE\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\kime\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\seb\locals~1\applic~1" *



*** Recherche fichiers ***



*** Recherche clés spécifiques dans le Registre ***

HKEY_CURRENT_USER\Software\Lanconfig trouvé !

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans "C:\WINDOWS\system32" :


* Dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" :

rdxjtpa.dat trouvé !
rdxjtpa_nav.dat trouvé !
rdxjtpa_navps.dat trouvé !

* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :


* Dans "C:\DOCUME~1\amandine\locals~1\applic~1" :


* Dans "C:\DOCUME~1\AMANDI~1.ALE\locals~1\applic~1" :


* Dans "C:\DOCUME~1\celia\locals~1\applic~1" :


* Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" :


* Dans "C:\DOCUME~1\INVIT~1.ALE\locals~1\applic~1" :


* Dans "C:\DOCUME~1\kime\locals~1\applic~1" :


* Dans "C:\DOCUME~1\seb\locals~1\applic~1" :


3)Recherche Certificats :

Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat Montorgueil absent !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche fichiers connus :



*** Analyse terminée le 17/11/2008 à 19:25:03,29 ***
0
celine391 Messages postés 12 Date d'inscription lundi 17 novembre 2008 Statut Membre Dernière intervention 28 septembre 2012
17 nov. 2008 à 21:20
alors docteur c est grave?lol
0
Utilisateur anonyme
18 nov. 2008 à 16:14
TRES grave......lol


Double cliques sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
Au menu principal, choisis 2 et valides.
(ne fais pas le choix 3 ou 4 sans notre avis/accord)

Le fix va t'informer qu'il va alors redémarrer ton PC
Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
Appuies sur une touche comme demandé.
(si ton Pc ne redémarre pas automatiquement, fais le toi même)
Au redémarrage de ton PC, choisis ta session habituelle.

Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***
Le bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver
Referme le bloc-notes. Ton bureau va réapparaitre

PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Celà te fera apparaitre ton bureau.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
celine391 Messages postés 12 Date d'inscription lundi 17 novembre 2008 Statut Membre Dernière intervention 28 septembre 2012
18 nov. 2008 à 16:35
bonjour,j espere que la visite est remboursee par la secu!lolvoila mon rapport:Clean Navipromo version 3.6.9 commencé le 18/11/2008 à 16:27:43,39

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Compaq_Propriétaire"

Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : NTFS

Mode suppression automatique
avec prise en charge résultats Catchme et GNS


Nettoyage exécuté au redémarrage de l'ordinateur


*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


*** Suppression avec sauvegardes résultats GenericNaviSearch ***

* Suppression dans "C:\WINDOWS\System32" *


* Suppression dans "C:\Documents and Settings\Compaq_PropriÚtaire\locals~1\applic~1" *


* Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\amandine\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\AMANDI~1.ALE\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\celia\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\INVIT~1.ALE\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\kime\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\seb\locals~1\applic~1" *


*** Suppression dossiers dans "C:\WINDOWS" ***


*** Suppression dossiers dans "C:\Program Files" ***


*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\Compaq_PropriÚtaire\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\amandine\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\AMANDI~1.ALE\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\celia\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\COMPAQ~2\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\INVIT~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\INVIT~1.ALE\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\kime\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\seb\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\Compaq_PropriÚtaire\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\amandine\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\AMANDI~1.ALE\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\celia\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\INVIT~1.ALE\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\kime\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\seb\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\Compaq_PropriÚtaire\menudm~1\progra~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\AMANDI~1.ALE\menudm~1\progra~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\INVIT~1.ALE\menudm~1\progra~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\kime\menudm~1\progra~1" ***



*** Suppression fichiers ***


*** Suppression fichiers temporaires ***

Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Compaq_Propriétaire\locals~1\Temp effectué !

*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

2)Recherche, création sauvegardes et suppression Heuristique :


* Dans "C:\WINDOWS\system32" *


* Dans "C:\Documents and Settings\Compaq_PropriÚtaire\locals~1\applic~1" *


rdxjtpa.dat trouvé !
Copie rdxjtpa.dat réalisée avec succès !
rdxjtpa.dat supprimé !

rdxjtpa_nav.dat trouvé !
Copie rdxjtpa_nav.dat réalisée avec succès !
rdxjtpa_nav.dat supprimé !

rdxjtpa_navps.dat trouvé !
Copie rdxjtpa_navps.dat réalisée avec succès !
rdxjtpa_navps.dat supprimé !


* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *


* Dans "C:\DOCUME~1\amandine\locals~1\applic~1" *


* Dans "C:\DOCUME~1\AMANDI~1.ALE\locals~1\applic~1" *


* Dans "C:\DOCUME~1\celia\locals~1\applic~1" *


* Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *


* Dans "C:\DOCUME~1\INVIT~1.ALE\locals~1\applic~1" *


* Dans "C:\DOCUME~1\kime\locals~1\applic~1" *


* Dans "C:\DOCUME~1\seb\locals~1\applic~1" *


*** Sauvegarde du Registre vers dossier Safebackup ***

sauvegarde du Registre réalisée avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok


*** Certificats ***

Certificat Egroup supprimé !
Certificat Electronic-Group supprimé !
Certificat Montorgueil absent !
Certificat OOO-Favorit supprimé !
Certificat Sunny-Day-Design-Ltdt absent !

*** Nettoyage terminé le 18/11/2008 à 16:30:55,60 ***

merki
0
Utilisateur anonyme
18 nov. 2008 à 20:14
Certificat Egroup supprimé !
Certificat Electronic-Group supprimé !
Certificat OOO-Favorit supprimé !

ca j'aime.......!!!!!!!!!!!!!!

maintenant pour virer les traces tu fais ceci :

suis bien les points forts en gras

1) Télécharge et installe Malwarebyte's Anti-Malware:

http://www.malwarebytes.org/mbam/program/mbam-setup.exe

A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK

Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.

Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK

Laisse les Mises à jour se télécharger

*** Referme le programme ***


2) Scan avec Malwarebyte's Anti-Malware

Lance Malwarebyte's Anti-Malware
Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
Suppression des éléments détectés >>>>
supprime ce qu'il a trouvé vide également les éléments de la quarantaineS'il t'es demandé de redémarrer >>> clique sur "Yes"

--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
_______________________________________________
0
celine391 Messages postés 12 Date d'inscription lundi 17 novembre 2008 Statut Membre Dernière intervention 28 septembre 2012
18 nov. 2008 à 22:37
voila le rapport:Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1410
Windows 5.1.2600 Service Pack 2

18/11/2008 22:29:21
mbam-log-2008-11-18 (22-29-21).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 174201
Temps écoulé: 1 hour(s), 3 minute(s), 9 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spoolms (Trojan.Downloader) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
0
Utilisateur anonyme
18 nov. 2008 à 22:52
et bien pour bien finir :

1)Telecharge :
-------------

https://www.clubic.com/telecharger-fiche262022-purera.html

coche tout a droite et "clean"

ensuite :
-----------

http://www.commentcamarche.net/telecharger/cleanafterme 34056612 avis opinions.php3

meme chose tu coches tout et "clean selected items"

2)

---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).


3/

---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse(Sauvegarde la base de registre).et regles les options pour qu'il demarre avec windows


4/

---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme

---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
https://www.vulgarisation-informatique.com/creer-point-restauration.php


stp poste tous les rapports delivrés....merci.....

si tu as deja Ccleaner ne tiens pas compte du N°3.....mais fais ce qu il est demande avec
(desole le canned est pour tout le mond
0
The following actions will be executed if you choose to clean the selected items:

Delete registry value: 'LangID' in HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
Delete registry value: 'C:\Program Files\IncrediMail\bin\IncMail.exe' in HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
Delete registry value: '@C:\WINDOWS\system32\SHELL32.dll,-9216' in HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\IM\img146.htm
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\IM\img147.htm
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\LSBurnWatcher.log
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\~DFD9B2.tmp
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\~DFDCA4.tmp
Delete folder: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temp\IM
Empty the Recycle Bin
Clean the clipboard
Clean event log: Application
Clean event log: Security
Clean event log: System
Uninstall USB Devices
Clean index.dat file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\28NZ6DKD\desktop.ini
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\6XFVJJOE\desktop.ini
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\A344RDZV\desktop.ini
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\T4VXR54W\desktop.ini
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\desktop.ini
Delete folder: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\28NZ6DKD
Delete folder: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\6XFVJJOE
Delete folder: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\A344RDZV
Delete folder: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\T4VXR54W
Clean index.dat file: C:\Documents and Settings\Compaq_Propriétaire\Cookies\index.dat
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@mystart.incredimail[2].txt
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Cookies\compaq_propriétaire@www.incredimail[1].txt
Clean index.dat file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Historique\History.IE5\index.dat
Clean index.dat file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Historique\History.IE5\MSHist012008111820081119\index.dat
Delete file: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Historique\History.IE5\MSHist012008111820081119\index.dat
Delete folder: C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Historique\History.IE5\MSHist012008111820081119


Number of files to delete: 13
Total size of files to delete: 66 KB
0
Utilisateur anonyme
18 nov. 2008 à 23:39
continue !!
0
Windows Registry Editor Version 5.00


[HKEY_CLASSES_ROOT\aAvgAPI.AvgBro]
@="AvgBro Object"

[HKEY_CLASSES_ROOT\aAvgAPI.AvgBro\Clsid]
@="{18B30EBF-6B58-425E-AC54-831C05D91B5A}"

[HKEY_CLASSES_ROOT\Connection Manager Profile]
@="Connection Manager Profile"

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell]

[HKEY_CLASSES_ROOT\EditVideo.Document]
@="DM Video Project File"

[HKEY_CLASSES_ROOT\EditVideo.Document\shell]

[HKEY_CLASSES_ROOT\F-Secure IE Shield COM button]
@="F-Secure IE Shield COM button"

[HKEY_CLASSES_ROOT\F-Secure IE Shield COM button\CLSID]
@="{0928F506-07E8-470C-979D-147C296D4879}"

[HKEY_CLASSES_ROOT\F-Secure IE Shield COM button\CurVer]
@="F-Secure IE Shield COM button.1"

[HKEY_CLASSES_ROOT\F-Secure IE Shield COM button.1]
@="F-Secure IE Shield COM button"

[HKEY_CLASSES_ROOT\F-Secure IE Shield COM button.1\CLSID]
@="{0928F506-07E8-470C-979D-147C296D4879}"

[HKEY_CLASSES_ROOT\GFLImageServices.GFLReader]
@="GFL Image Services"

[HKEY_CLASSES_ROOT\GFLImageServices.GFLReader\CLSID]
@="{FF5FCD00-2C20-49D8-84F6-888D2E2C95DA}"

[HKEY_CLASSES_ROOT\GFLImageServices.GFLReader\CurVer]
@="GFLImageServices.GFLReader.1"

[HKEY_CLASSES_ROOT\GFLImageServices.GFLReader.1]
@="GFL Image Services"

[HKEY_CLASSES_ROOT\GFLImageServices.GFLReader.1\CLSID]
@="{FF5FCD00-2C20-49D8-84F6-888D2E2C95DA}"

[HKEY_CLASSES_ROOT\GFLLibraryBuilder.Builder]
@="GFL Library Builder"

[HKEY_CLASSES_ROOT\GFLLibraryBuilder.Builder\CLSID]
@="{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}"

[HKEY_CLASSES_ROOT\GFLLibraryBuilder.Builder\CurVer]
@="GFLLibraryBuilder.Builder.1"

[HKEY_CLASSES_ROOT\GFLLibraryBuilder.Builder.1]
@="GFL Library Builder"

[HKEY_CLASSES_ROOT\GFLLibraryBuilder.Builder.1\CLSID]
@="{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}"

[HKEY_CLASSES_ROOT\GoogleGadgetManifest]
@="Google Gadget Manifest"

[HKEY_CLASSES_ROOT\GoogleGadgetManifest\shell]

[HKEY_CLASSES_ROOT\Imagic30.Document]
@="Imagic30.Document"

[HKEY_CLASSES_ROOT\Imagic30.Document\shell]

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin]
@="ActiveXPlugin Object"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\CLSID]
@="{06DD38D3-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\CurVer]
@="Microsoft.ActiveXPlugin.1"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\NotInsertable]

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1]
@="ActiveXPlugin Object"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1\CLSID]
@="{06DD38D3-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1\NotInsertable]

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker]
@=""

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker\CLSID]
@="{111C85E9-BB62-4528-A806-F0BE908E02F0}"

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker\CurVer]
@="MSNMessenger.ContactsPicker.1"

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker.1]
@=""

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker.1\CLSID]
@="{111C85E9-BB62-4528-A806-F0BE908E02F0}"

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker.1\CurVer]
@="MSNMessenger.ContactsPicker"

[HKEY_CLASSES_ROOT\Shareaza.AVIPreviewer.1]
@="Partial AVI Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\Shareaza.AVIPreviewer.1\CLSID]
@="{394011F0-6D5C-42a3-96C6-24B9AD6B010C}"

[HKEY_CLASSES_ROOT\Shareaza.Collection]
@="Shareaza Collection File"

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell]

[HKEY_CLASSES_ROOT\Shareaza.DocReader]
@="Document Metadata Reader and Thumbnailer"

[HKEY_CLASSES_ROOT\Shareaza.DocReader\CLSID]
@="{E9F51B1E-DB0F-4EEE-9B36-46151994C715}"

[HKEY_CLASSES_ROOT\Shareaza.DocReader\CurVer]
@="Shareaza.DocReader.1"

[HKEY_CLASSES_ROOT\Shareaza.DocReader.1]
@="Document Metadata Reader and Thumbnailer"

[HKEY_CLASSES_ROOT\Shareaza.DocReader.1\CLSID]
@="{E9F51B1E-DB0F-4EEE-9B36-46151994C715}"

[HKEY_CLASSES_ROOT\Shareaza.MP3Previewer.1]
@="Partial MP3 Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\Shareaza.MP3Previewer.1\CLSID]
@="{BF00DBCC-90A2-4f46-8171-7D4F929D035F}"

[HKEY_CLASSES_ROOT\Shareaza.MPEGPreviewer.1]
@="Partial MPEG-1 Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\Shareaza.MPEGPreviewer.1\CLSID]
@="{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}"

[HKEY_CLASSES_ROOT\Shareaza.SimpleScope.1]
@="SimpleScopes Audio Visualisation for Shareaza"

[HKEY_CLASSES_ROOT\Shareaza.SimpleScope.1\CLSID]
@="{591A5CFF-3172-4020-A067-238542DDE9C2}"

[HKEY_CLASSES_ROOT\Shareaza.SoniqueVis.1]
@="Sonique Visualisation Wrapper"

[HKEY_CLASSES_ROOT\Shareaza.SoniqueVis.1\CLSID]
@="{D07E630D-A850-4f11-AD29-3D3848B67EFE}"

[HKEY_CLASSES_ROOT\Shareaza.WMPVis.1]
@="Windows Media Player Visualisation Wrapper"

[HKEY_CLASSES_ROOT\Shareaza.WMPVis.1\CLSID]
@="{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}"

[HKEY_CLASSES_ROOT\uTorrent]

[HKEY_CLASSES_ROOT\uTorrent\shell]
@="open"

[HKEY_CLASSES_ROOT\VIDEOCHAT.VideochatCtrl.1]
@="Videochat Pro Control"

[HKEY_CLASSES_ROOT\VIDEOCHAT.VideochatCtrl.1\CLSID]
@="{9DA66AFA-F784-426A-82F6-7DD754C1A039}"

[HKEY_CLASSES_ROOT\Applications\bittorrent.exe]

[HKEY_CLASSES_ROOT\Applications\bittorrent.exe\shell]
@="open"

[HKEY_CLASSES_ROOT\Applications\pptview.exe]

[HKEY_CLASSES_ROOT\Applications\pptview.exe\shell]
@="Show"

[HKEY_CLASSES_ROOT\Applications\soffice.exe]

[HKEY_CLASSES_ROOT\Applications\soffice.exe\shell]

[HKEY_CLASSES_ROOT\Applications\uTorrent.exe]

[HKEY_CLASSES_ROOT\Applications\uTorrent.exe\shell]
@="open"

[HKEY_CLASSES_ROOT\Applications\WinDVD.exe]

[HKEY_CLASSES_ROOT\Applications\WinDVD.exe\shell]
@="play"

[HKEY_CLASSES_ROOT\.dmv]
@="EditVideo.Document"

[HKEY_CLASSES_ROOT\.gmanifest]
@="GoogleGadgetManifest"
0
celine391 Messages postés 12 Date d'inscription lundi 17 novembre 2008 Statut Membre Dernière intervention 28 septembre 2012
18 nov. 2008 à 23:53
Windows Registry Editor Version 5.00


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"c:\\Program Files\\Fichiers communs\\Symantec Shared\\SNDSrvc.exe"=dword:80000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\unicows.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqaol08.exe"=dword:00000002

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\system32\\msxml3a.dll"=dword:00000001

[HKEY_CLASSES_ROOT\.eta]
@="Google Earth.etafile"

[HKEY_CLASSES_ROOT\.xlm]
@="ExcelViewer.Macrosheet"

[HKEY_CLASSES_ROOT\.xlw]
@="ExcelViewer.Workspace"

[HKEY_CLASSES_ROOT\SysmonLogManager.Snapin]

[HKEY_CLASSES_ROOT\WMPCD]

[HKEY_CLASSES_ROOT\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.01]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.01\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BUP]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BUP\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cmi]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cmi\OpenWithList]
"a"="firefox.exe"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FTS]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FTS\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IDF]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IDF\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IFO]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IFO\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl\OpenWithProgids]
"iTunes.itl"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itms]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itms\OpenWithProgids]
"iTunes.itms"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mtx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mtx\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mxmf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mxmf\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ndb]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ndb\OpenWithList]
"a"="firefox.exe"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nds]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nds\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odf3]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odf3\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odf4]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odf4\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OLD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OLD\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pf\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php\OpenWithList]
"a"="firefox.exe"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm\OpenWithProgids]
"PowerPointViewer.TemplateMacroEnabled.12"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx\OpenWithProgids]
"PowerPointViewer.Template.12"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm\OpenWithProgids]
"PowerPointViewer.SlideShowMacroEnabled.12"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\OpenWithProgids]
"PowerPointViewer.SlideShow.12"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm\OpenWithProgids]
"PowerPointViewer.ShowMacroEnabled.12"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx\OpenWithProgids]
"PowerPointViewer.Show.12"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pvm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pvm\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram\OpenWithList]
"a"="iexplore.exe"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm\OpenWithList]
"a"="iexplore.exe"
"MRUList"="ba"
"b"="firefox.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sav]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sav\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sqm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sqm\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.STH]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.STH\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.STP]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.STP\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tdf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tdf\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent]
"Application"=""

[HKEY_CLASSES_ROOT\acrobat\DefaultIcon]
@="C:\\Program Files\\Adobe\\Reader 8.0\\Acrobat\\AcroRd32.exe"

[HKEY_CLASSES_ROOT\ADCS]
@="Conteneur de classe Annuaire"

[HKEY_CLASSES_ROOT\ADCS\CLSID]
@="{89E30300-764D-11d0-B282-00A0C90F56FC}"

[HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost]

[HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost\CLSID]
@="{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}"

[HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost.2]
@="Microsoft COM+ Runtime Meta Data"

[HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost.2\CLSID]
@="{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}"

[HKEY_CLASSES_ROOT\Connection Manager Profile\DefaultIcon]
@="C:\\WINDOWS\\system32\\CMMGR32.EXE,1"

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open]

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open\command]
@="C:\\WINDOWS\\system32\\CMMGR32.EXE \"%1\""

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...]

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...\command]
@="C:\\WINDOWS\\system32\\CMMGR32.EXE /settings \"%1\""

[HKEY_CLASSES_ROOT\DirectAnimation.PathControl]
@="Microsoft DirectAnimation Path"

[HKEY_CLASSES_ROOT\DirectAnimation.PathControl\CLSID]
@="{D7A7D7C3-D47F-11D0-89D3-00A0C90833E6}"

[HKEY_CLASSES_ROOT\DirectAnimation.Sequence]
@="Microsoft DirectAnimation Sequence"

[HKEY_CLASSES_ROOT\DirectAnimation.Sequence\CLSID]
@="{4F241DB1-EE9F-11D0-9824-006097C99E51}"

[HKEY_CLASSES_ROOT\DirectAnimation.SequencerControl]
@="Microsoft DirectAnimation Sequencer"

[HKEY_CLASSES_ROOT\DirectAnimation.SequencerControl\CLSID]
@="{B0A6BAE2-AAF0-11D0-A152-00A0C908DB96}"

[HKEY_CLASSES_ROOT\DirectAnimation.SpriteControl]
@="Microsoft DirectAnimation Sprite"

[HKEY_CLASSES_ROOT\DirectAnimation.SpriteControl\CLSID]
@="{FD179533-D86E-11D0-89D6-00A0C90833E6}"

[HKEY_CLASSES_ROOT\DirectAnimation.StructuredGraphicsControl]
@="Microsoft DirectAnimation Structured Graphics"

[HKEY_CLASSES_ROOT\DirectAnimation.StructuredGraphicsControl\CLSID]
@="{369303C2-D7AC-11D0-89D5-00A0C90833E6}"

[HKEY_CLASSES_ROOT\EditVideo.Document\shell\open]

[HKEY_CLASSES_ROOT\EditVideo.Document\shell\open\command]
@="C:\\PROGRA~1\\Samsung\\DIGIMA~1\\DIGIMA~1.EXE \"%1\""

[HKEY_CLASSES_ROOT\F-Secure.License\DefaultIcon]
@="C:\\Program Files\\Tele2\\FSGUI\\fstnbins.dll,0"

[HKEY_CLASSES_ROOT\gnutella1\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-128"

[HKEY_CLASSES_ROOT\gnutella1\shell\open]

[HKEY_CLASSES_ROOT\gnutella1\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%L\""

[HKEY_CLASSES_ROOT\gnutella1\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\gnutella1\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\gnutella1\shell\open\ddeexec\Topic]
@="URL"

[HKEY_CLASSES_ROOT\gnutella2\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-128"

[HKEY_CLASSES_ROOT\gnutella2\shell\open]

[HKEY_CLASSES_ROOT\gnutella2\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%L\""

[HKEY_CLASSES_ROOT\gnutella2\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\gnutella2\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\gnutella2\shell\open\ddeexec\Topic]
@="URL"

[HKEY_CLASSES_ROOT\GoogleGadget\DefaultIcon]
@="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\",0"

[HKEY_CLASSES_ROOT\GoogleGadget\shell\open]
@="&Open with Google Desktop"

[HKEY_CLASSES_ROOT\GoogleGadget\shell\open\command]
@="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /display /load \"%1\""

[HKEY_CLASSES_ROOT\GoogleGadgetManifest\DefaultIcon]
@="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\",0"

[HKEY_CLASSES_ROOT\GoogleGadgetManifest\shell\open]

[HKEY_CLASSES_ROOT\GoogleGadgetManifest\shell\open\command]
@="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /display /load \"%1\""

[HKEY_CLASSES_ROOT\Imagic30.Document\shell\open]

[HKEY_CLASSES_ROOT\Imagic30.Document\shell\open\command]
@="C:\\PROGRA~1\\Samsung\\DIGIMA~1\\DIGIMA~1.EXE \"%1\""

[HKEY_CLASSES_ROOT\Imagic30.Document\shell\open\ddeexec]
@="[open(\"%1\")]"

[HKEY_CLASSES_ROOT\Modeler.Runtime.1]
@="Modeler Applicaiton"

[HKEY_CLASSES_ROOT\Modeler.Runtime.1\CLSID]
@="{21D22AC1-A4A0-D334-6338-D17E051AD71C}"

[HKEY_CLASSES_ROOT\msbackupfile\DefaultIcon]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,00,74,00,\
62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,00,2c,00,31,00,30,\
00,00,00

[HKEY_CLASSES_ROOT\msbackupfile\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\msbackupfile\shell\Open\Command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,00,74,00,\
62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,00,00,00

[HKEY_CLASSES_ROOT\Shareaza.Collection\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-244"

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open]

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%1\""

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\Shareaza.Collection\shell\open\ddeexec\Topic]
@="COLLECTION"

[HKEY_CLASSES_ROOT\Shareaza.SkinInfoExtractor.1]
@="Shareaza Skin Metadata Extractor"

[HKEY_CLASSES_ROOT\Shareaza.SkinInfoExtractor.1\CLSID]
@="{0EEDB912-C5FA-486F-8334-57288578C627}"

[HKEY_CLASSES_ROOT\Sms_object.SMS]
@="SMS Class"

[HKEY_CLASSES_ROOT\Sms_object.SMS\CLSID]
@="{46E1BF8E-AA99-4749-AA37-E18A20629B2E5}"

[HKEY_CLASSES_ROOT\Sms_object.SMS\CurVer]
@="Sms_object.SMS.1"

[HKEY_CLASSES_ROOT\SymWriter.pdb]
@="Pdb based SymWriter"

[HKEY_CLASSES_ROOT\SymWriter.pdb\CLSID]
@="{520DC67A-752E-11D3-8D56-00C04F680B2B}"

[HKEY_CLASSES_ROOT\uhc\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-128"

[HKEY_CLASSES_ROOT\uhc\shell\open]

[HKEY_CLASSES_ROOT\uhc\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%L\""

[HKEY_CLASSES_ROOT\uhc\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\uhc\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\uhc\shell\open\ddeexec\Topic]
@="URL"

[HKEY_CLASSES_ROOT\ukhl\DefaultIcon]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\",-128"

[HKEY_CLASSES_ROOT\ukhl\shell\open]

[HKEY_CLASSES_ROOT\ukhl\shell\open\command]
@="\"C:\\Program Files\\Shareaza\\Shareaza.exe\" \"%L\""

[HKEY_CLASSES_ROOT\ukhl\shell\open\ddeexec]
@="%1"

[HKEY_CLASSES_ROOT\ukhl\shell\open\ddeexec\Application]
@="Shareaza"

[HKEY_CLASSES_ROOT\ukhl\shell\open\ddeexec\Topic]
@="URL"

[HKEY_CLASSES_ROOT\uTorrent\shell\open]

[HKEY_CLASSES_ROOT\uTorrent\shell\open\command]
@="\"C:\\Program Files\\uTorrent\\uTorrent.exe\" \"%1\""

[HKEY_CLASSES_ROOT\weflirt\DefaultIcon]
@="C:\\Program Files\\Weflirt\\weflirt.exe,0"

[HKEY_CLASSES_ROOT\weflirt\shell\open]

[HKEY_CLASSES_ROOT\weflirt\shell\open\command]
@="\"C:\\Program Files\\Weflirt\\weflirt.exe\" \"%1\""

[HKEY_CLASSES_ROOT\zapfile\DefaultIcon]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,70,00,\
70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,32,00,31,00,38,\
00,00,00

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}]
@="ActiveXPlugin Object"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Control]

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\InprocServer32]
@="C:\\WINDOWS\\system32\\plugin.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\ProgID]
@="Microsoft.ActiveXPlugin.1"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\ToolboxBitmap32]
@="C:\\WINDOWS\\system32\\plugin.ocx, 1"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\TypeLib]
@="{06DD38D0-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\VersionIndependentProgID]
@="Microsoft.ActiveXPlugin"

[HKEY_CLASSES_ROOT\CLSID\{0928F506-07E8-470C-979D-147C296D4879}]
@="F-Secure IE Shield COM button"

[HKEY_CLASSES_ROOT\CLSID\{0928F506-07E8-470C-979D-147C296D4879}\InprocServer32]
@="C:\\Program Files\\Tele2\\Anti-Spyware\\ieshield.dll"

[HKEY_CLASSES_ROOT\CLSID\{0928F506-07E8-470C-979D-147C296D4879}\ProgID]
@="F-Secure IE Shield COM button.1"

[HKEY_CLASSES_ROOT\CLSID\{0928F506-07E8-470C-979D-147C296D4879}\VersionIndependentProgID]
@="F-Secure IE Shield COM button"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}]

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\InprocServer32]
@="\"C:\\PROGRA~1\\MSNMES~1\\msgsc.dll\""
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\LocalServer32]
@="\"C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe\""
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\ProgID]
@="MSNMessenger.ContactsPicker"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\Programmable]
@=""

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\VersionIndependentProgID]
@="MSNMessenger.ContactsPicker.1"

[HKEY_CLASSES_ROOT\CLSID\{18B30EBF-6B58-425E-AC54-831C05D91B5A}]
@="AvgBro Object"

[HKEY_CLASSES_ROOT\CLSID\{18B30EBF-6B58-425E-AC54-831C05D91B5A}\LocalServer32]
@="C:\\PROGRA~1\\AVG\\AVG8\\aAvgApi.exe"

[HKEY_CLASSES_ROOT\CLSID\{18B30EBF-6B58-425E-AC54-831C05D91B5A}\ProgID]
@="aAvgAPI.AvgBro"

[HKEY_CLASSES_ROOT\CLSID\{18B30EBF-6B58-425E-AC54-831C05D91B5A}\TypeLib]
@="{3E536428-8E1A-4A2C-8463-4A8F74763C30}"

[HKEY_CLASSES_ROOT\CLSID\{18B30EBF-6B58-425E-AC54-831C05D91B5A}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}]
@="Partial AVI Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}\ProgID]
@="Shareaza.AVIPreviewer.1"

[HKEY_CLASSES_ROOT\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}\VersionIndependentProgID]
@="Shareaza.AVIPreviewer"

[HKEY_CLASSES_ROOT\CLSID\{3f9491f6-6195-405c-bd50-01cbbbaf8f70}]

[HKEY_CLASSES_ROOT\CLSID\{3f9491f6-6195-405c-bd50-01cbbbaf8f70}\InprocServer32]
@="C:\\Program Files\\LG PC Suite\\LG Phone Manager\\MP4video.ax"

[HKEY_CLASSES_ROOT\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}]
@="SimpleScopes Audio Visualisation for Shareaza"

[HKEY_CLASSES_ROOT\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}\ProgID]
@="Shareaza.SimpleScope.1"

[HKEY_CLASSES_ROOT\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}\VersionIndependentProgID]
@="Shareaza.SimpleScope"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}]
@="GFL Library Builder"
"AppID"="{F74AD137-A43F-46FD-A1FE-6532C3FC3E88}"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\GFLLibraryBuilder.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}\ProgID]
@="GFLLibraryBuilder.Builder.1"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}\TypeLib]
@="{7B8046FF-0D3A-4D85-9424-7DFCCD1BCA45}"

[HKEY_CLASSES_ROOT\CLSID\{6C9E61BE-E58F-4AE1-A304-6FF1D183804C}\VersionIndependentProgID]
@="GFLLibraryBuilder.Builder"

[HKEY_CLASSES_ROOT\CLSID\{92110F7B-4B7B-41F6-8D2A-D411DF3F9FD6}]
@="Videochat Pro Property Page"

[HKEY_CLASSES_ROOT\CLSID\{92110F7B-4B7B-41F6-8D2A-D411DF3F9FD6}\InprocServer32]
@="C:\\PROGRA~1\\Weflirt\\VIDEOC~1.OCX"

[HKEY_CLASSES_ROOT\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}]
@="Partial MPEG-1 Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}\ProgID]
@="Shareaza.MPEGPreviewer.1"

[HKEY_CLASSES_ROOT\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}\VersionIndependentProgID]
@="Shareaza.MPEGPreviewer"

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}]
@="Videochat Pro Control"

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}\Control]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}\InprocServer32]
@="C:\\PROGRA~1\\Weflirt\\VIDEOC~1.OCX"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}\ProgID]
@="VIDEOCHAT.VideochatCtrl.1"

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}\ToolboxBitmap32]
@="C:\\PROGRA~1\\Weflirt\\VIDEOC~1.OCX, 1"

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}\TypeLib]
@="{F9D8E1C3-CDFE-4136-ABF0-36FF5BCA7F83}"

[HKEY_CLASSES_ROOT\CLSID\{9DA66AFA-F784-426A-82F6-7DD754C1A039}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}]
@="Shareaza Skin Metadata Extractor"

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\SkinScanSKS.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\ProgID]
@="Shareaza.SkinInfoExtractor.1"

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\VersionIndependentProgID]
@="Shareaza.SkinInfoExtractor"

[HKEY_CLASSES_ROOT\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}]
@="Partial MP3 Preview Filter for Shareaza"

[HKEY_CLASSES_ROOT\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}\ProgID]
@="Shareaza.MP3Previewer.1"

[HKEY_CLASSES_ROOT\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}\VersionIndependentProgID]
@="Shareaza.MP3Previewer"

[HKEY_CLASSES_ROOT\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}]
@="Windows Media Player Visualisation Wrapper"

[HKEY_CLASSES_ROOT\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}\ProgID]
@="Shareaza.WMPVis.1"

[HKEY_CLASSES_ROOT\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}\VersionIndependentProgID]
@="Shareaza.WMPVis"

[HKEY_CLASSES_ROOT\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}]
@="Sonique Visualisation Wrapper"

[HKEY_CLASSES_ROOT\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\MediaPlayer.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}\ProgID]
@="Shareaza.SoniqueVis.1"

[HKEY_CLASSES_ROOT\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}\VersionIndependentProgID]
@="Shareaza.SoniqueVis"

[HKEY_CLASSES_ROOT\CLSID\{E3FB4BFE-1979-11D2-B362-00104B08CC22}]
@="AmvSource Std."

[HKEY_CLASSES_ROOT\CLSID\{E3FB4BFE-1979-11D2-B362-00104B08CC22}\InprocServer32]
@="C:\\Program Files\\MP3 Player Utilities 4.15\\AMVConverter\\amv.ax"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}]
@="Document Metadata Reader and Thumbnailer"
"AppID"="{BEC42E3F-4B6B-49A3-A099-EB3D6752AA02}"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\DocumentReader.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}\ProgID]
@="Shareaza.DocReader.1"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}\TypeLib]
@="{607C3F69-850D-4413-A81A-CF1C849BF387}"

[HKEY_CLASSES_ROOT\CLSID\{E9F51B1E-DB0F-4EEE-9B36-46151994C715}\VersionIndependentProgID]
@="Shareaza.DocReader"

[HKEY_CLASSES_ROOT\CLSID\{FF5FCD00-2C20-49D8-84F6-888D2E2C95DA}]
@="GFL Image Services"
"AppID"="{4DD7500D-4ACC-4833-AB1D-887C59199DC5}"

[HKEY_CLASSES_ROOT\CLSID\{FF5FCD00-2C20-49D8-84F6-888D2E2C95DA}\InprocServer32]
@="C:\\Program Files\\Shareaza\\Plugins\\GFLImageServices.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{FF5FCD00-2C20-49D8-84F6-888D2E2C95DA}\ProgID]
@="GFLImageServices.GFLReader.1"

[HKEY_CLASSES_ROOT\CLSID\{FF5FCD00-2C20-49D8-84F6-888D2E2C95DA}\TypeLib]
@="{FCCC9C8C-45EF-4EB4-8AB1-5235585A631D}"

[HKEY_CLASSES_ROOT\CLSID\{FF5FCD00-2C20-49D8-84F6-888D2E2C95DA}\VersionIndependentProgID]
@="GFLImageServices.GFLReader"

[HKEY_CLASSES_ROOT\Interface\{076D42C0-28A0-11D1-B2FA-006097C9B3E0}]
@="DSpriteCollection"

[HKEY_CLASSES_ROOT\Interface\{076D42C0-28A0-11D1-B2FA-006097C9B3E0}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{076D42C0-28A0-11D1-B2FA-006097C9B3E0}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{076D42C0-28A0-11D1-B2FA-006097C9B3E0}\TypeLib]
@="DGlobalState"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{0BD7D3C0-9E6D-11D1-B31C-006097C9B3E0}]

[HKEY_CLASSES_ROOT\Interface\{0BD7D3C0-9E6D-11D1-B31C-006097C9B3E0}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{0BD7D3C0-9E6D-11D1-B31C-006097C9B3E0}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{0BD7D3C0-9E6D-11D1-B31C-006097C9B3E0}\TypeLib]
@="DTextureFillProcedure"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{2A56DD10-E476-11D1-AD0B-006097D2DE49}]
@="DGradFillProc"

[HKEY_CLASSES_ROOT\Interface\{2A56DD10-E476-11D1-AD0B-006097D2DE49}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{2A56DD10-E476-11D1-AD0B-006097D2DE49}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{2A56DD10-E476-11D1-AD0B-006097D2DE49}\TypeLib]
@="DColorCutOutProc"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{2B59C2E0-B34A-11D1-ACF3-006097D2DE49}]

[HKEY_CLASSES_ROOT\Interface\{2B59C2E0-B34A-11D1-ACF3-006097D2DE49}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{2B59C2E0-B34A-11D1-ACF3-006097D2DE49}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{2B59C2E0-B34A-11D1-ACF3-006097D2DE49}\TypeLib]
@="DPictureFillProcedure"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}]
@="ISearch"

[HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}\TypeLib]
"Version"="1.0"
@="{47A7A4B0-2723-41BA-865E-EBBB7081A602}"

[HKEY_CLASSES_ROOT\Interface\{3AB12302-DE0C-11D1-8728-00AA00A42C71}]
@="DShadowProc"

[HKEY_CLASSES_ROOT\Interface\{3AB12302-DE0C-11D1-8728-00AA00A42C71}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{3AB12302-DE0C-11D1-8728-00AA00A42C71}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{3AB12302-DE0C-11D1-8728-00AA00A42C71}\TypeLib]
@="DSingleTextProc"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{46F56D93-AF23-11D1-8010-00600896C25C}]
@="DMultiTextProc"

[HKEY_CLASSES_ROOT\Interface\{46F56D93-AF23-11D1-8010-00600896C25C}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{46F56D93-AF23-11D1-8010-00600896C25C}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{46F56D93-AF23-11D1-8010-00600896C25C}\TypeLib]
@="IVGPaintProc"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{492655B1-9E90-11D1-9DE2-006097D2DF69}]

[HKEY_CLASSES_ROOT\Interface\{492655B1-9E90-11D1-9DE2-006097D2DF69}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{492655B1-9E90-11D1-9DE2-006097D2DF69}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{492655B1-9E90-11D1-9DE2-006097D2DF69}\TypeLib]
@="DColorTwistProc"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{4C1B71D2-6CDB-11D1-B315-006097C9B3E0}]

[HKEY_CLASSES_ROOT\Interface\{4C1B71D2-6CDB-11D1-B315-006097C9B3E0}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{4C1B71D2-6CDB-11D1-B315-006097C9B3E0}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{4C1B71D2-6CDB-11D1-B315-006097C9B3E0}\TypeLib]
@="DLineFormat"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{55D922A3-6A97-11D1-9DD9-006097D2DF69}]
@="DShapeNodes"

[HKEY_CLASSES_ROOT\Interface\{55D922A3-6A97-11D1-9DD9-006097D2DF69}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{55D922A3-6A97-11D1-9DD9-006097D2DF69}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{55D922A3-6A97-11D1-9DD9-006097D2DF69}\TypeLib]
@="IInitShapeProc"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{584FD990-921E-11D1-ACE9-006097D2DE49}]

[HKEY_CLASSES_ROOT\Interface\{584FD990-921E-11D1-ACE9-006097D2DE49}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{584FD990-921E-11D1-ACE9-006097D2DE49}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{584FD990-921E-11D1-ACE9-006097D2DE49}\TypeLib]
@="IShapeNodesProc"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{70A03D21-2EBE-11D1-B2FA-006097C9B3E0}]
@="DAffineProc"

[HKEY_CLASSES_ROOT\Interface\{70A03D21-2EBE-11D1-B2FA-006097C9B3E0}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{70A03D21-2EBE-11D1-B2FA-006097C9B3E0}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{70A03D21-2EBE-11D1-B2FA-006097C9B3E0}\TypeLib]
@="DSpriteRange"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{8349ABC0-F10C-11D1-831B-00C04F990E86}]
@="DAutoshapeProc"

[HKEY_CLASSES_ROOT\Interface\{8349ABC0-F10C-11D1-831B-00C04F990E86}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{8349ABC0-F10C-11D1-831B-00C04F990E86}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{8349ABC0-F10C-11D1-831B-00C04F990E86}\TypeLib]
@="DEffectCollection"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{9C682D00-E9FF-11D1-AD0D-006097D2DE49}]
@="DCropProcedure"

[HKEY_CLASSES_ROOT\Interface\{9C682D00-E9FF-11D1-AD0D-006097D2DE49}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{9C682D00-E9FF-11D1-AD0D-006097D2DE49}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{9C682D00-E9FF-11D1-AD0D-006097D2DE49}\TypeLib]
@="DComposition"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{A81A7A17-1FFB-11D1-94C5-00609778EA69}]
@="DSprite"

[HKEY_CLASSES_ROOT\Interface\{A81A7A17-1FFB-11D1-94C5-00609778EA69}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{A81A7A17-1FFB-11D1-94C5-00609778EA69}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{A81A7A17-1FFB-11D1-94C5-00609778EA69}\TypeLib]
@="DDecoSettings"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{B88068B1-A4B7-11D1-9DE2-006097D2DF69}]

[HKEY_CLASSES_ROOT\Interface\{B88068B1-A4B7-11D1-9DE2-006097D2DF69}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{B88068B1-A4B7-11D1-9DE2-006097D2DF69}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{B88068B1-A4B7-11D1-9DE2-006097D2DF69}\TypeLib]
@="IFadeProc"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{BB3F355F-A1A5-11D1-B31C-006097C9B3E0}]

[HKEY_CLASSES_ROOT\Interface\{BB3F355F-A1A5-11D1-B31C-006097C9B3E0}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{BB3F355F-A1A5-11D1-B31C-006097C9B3E0}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{BB3F355F-A1A5-11D1-B31C-006097C9B3E0}\TypeLib]
@="DReplaceObject"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{BD11DFC8-E511-11D1-A658-00C04FBBBCB1}]

[HKEY_CLASSES_ROOT\Interface\{BD11DFC8-E511-11D1-A658-00C04FBBBCB1}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{BD11DFC8-E511-11D1-A658-00C04FBBBCB1}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{BD11DFC8-E511-11D1-A658-00C04FBBBCB1}\TypeLib]
@="ILineFormatProcedure"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{C286F1F1-98D7-11D1-9DE1-006097D2DF69}]

[HKEY_CLASSES_ROOT\Interface\{C286F1F1-98D7-11D1-9DE1-006097D2DF69}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{C286F1F1-98D7-11D1-9DE1-006097D2DF69}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{C286F1F1-98D7-11D1-9DE1-006097D2DF69}\TypeLib]
@="DLinePlain"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Interface\{DA368BE2-977B-11D1-BFE2-006097D2DF4E}]
@="IThreeDProc"

[HKEY_CLASSES_ROOT\Interface\{DA368BE2-977B-11D1-BFE2-006097D2DF4E}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{DA368BE2-977B-11D1-BFE2-006097D2DF4E}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{DA368BE2-977B-11D1-BFE2-006097D2DF4E}\TypeLib]
@="IPSPlugInProc"
"Version"="1.0"

[HKEY_CLASSES_ROOT\Applications\bittorrent.exe\shell\open]

[HKEY_CLASSES_ROOT\Applications\bittorrent.exe\shell\open\command]
@="\"C:\\Program Files\\BitTorrent\\bittorrent.exe\" \"%1\""

[HKEY_CLASSES_ROOT\Applications\moviemk.exe]

[HKEY_CLASSES_ROOT\Applications\moviemk.exe\shell]
"FriendlyCache"="Movie Maker"

[HKEY_CLASSES_ROOT\Applications\OpenOffice.org 2.2\shell\edit]

[HKEY_CLASSES_ROOT\Applications\OpenOffice.org 2.2\shell\edit\command]
@="\"C:\\Program Files\\OpenOffice.org 2.2\\program\\soffice.exe\" -o \"%1\""

[HKEY_CLASSES_ROOT\Applications\pptview.exe\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\Applications\pptview.exe\shell\Print\command]
@="C:\\Program Files\\Microsoft Office\\Office12\\pptview.exe /p \"%1\""

[HKEY_CLASSES_ROOT\Applications\pptview.exe\shell\Show]
@="A&fficher"

[HKEY_CLASSES_ROOT\Applications\pptview.exe\shell\Show\command]
@="C:\\Program Files\\Microsoft Office\\Office12\\pptview.exe \"%1\""

[HKEY_CLASSES_ROOT\Applications\soffice.exe\shell\edit]

[HKEY_CLASSES_ROOT\Applications\soffice.exe\shell\edit\command]
@="\"C:\\Program Files\\OpenOffice.org 2.2\\program\\soffice.exe\" -o \"%1\""

[HKEY_CLASSES_ROOT\Applications\uTorrent.exe\shell\open]

[HKEY_CLASSES_ROOT\Applications\uTorrent.exe\shell\open\command]
@="\"C:\\Program Files\\uTorrent\\uTorrent.exe\" \"%1\""

[HKEY_CLASSES_ROOT\Applications\WinDVD.exe\shell\open]
@=""

[HKEY_CLASSES_ROOT\Applications\WinDVD.exe\shell\open\command]
@="\"C:\\Program Files\\InterVideo\\WinDVD\\WinDVD.exe\" %1"

[HKEY_CLASSES_ROOT\Applications\WinDVD.exe\shell\play]
@="&Visionner avec WinDVD"

[HKEY_CLASSES_ROOT\Applications\WinDVD.exe\shell\play\command]
@="\"C:\\Program Files\\InterVideo\\WinDVD\\WinDVD.exe\" %1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe]
@="C:\\WINDOWS\\system32\\cmmgr32.exe"
"Path"="C:\\WINDOWS\\system32"
"CmstpExtensionDll"="C:\\WINDOWS\\system32\\cmcfg32.dll"
"CMInternalVersion"="1.2"
"CmNative"=dword:00000001
"ProfilesUpgraded"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe]
@="C:\\Documents and Settings\\Compaq_Propriétaire\\Bureau\\ComboFix.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\EasyStudio.exe]
"Path"="C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\"
@="C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\EasyStudio.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\HijackThis.exe]
@="C:\\Program Files\\Hijackthis Version Française\\hijackthis.exe"
"Path"="C:\\Program Files\\Hijackthis Version Française"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\ORUN32.EXE]
"Path"="C:\\WINDOWS\\"
@="C:\\WINDOWS\\ORUN32.EXE"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\setup.exe]
"RunAsOnNonAdminInstall"=dword:00000001
"BlockOnTSNonInstallMode"=dword:00000001
@="C:\\Program Files\\TRUST 120 SPACEC@M\\Setup.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\yourapp.Exe]
"Path"="C:\\Program Files\\HP\\Non Driver CIO Components"
@="C:\\Program Files\\HP\\Non Driver CIO Components\\yourapp.Exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\plug_ins\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\ActiveX\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\plug_ins\\Annotations\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\Propriétaire\\Application Data\\Microsoft\\Internet Explorer\\Lancement rapide\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Easy Internet signup\\FrontEnd\\"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Easy Internet signup\\FrontEnd\\fr\\offer_templates\\"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Easy Internet signup\\FrontEnd\\fr\\"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Easy Internet signup\\FrontEnd\\fr\\offer_templates\\compaq\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"c:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"c:\\Program Files\\Norton Internet Security\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\Sync ML Desktop Server\\German\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\Sync ML Desktop Server\\Italian\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\Sync ML Desktop Server\\French\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\Sync ML Desktop Server\\Spanish\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\Sync ML Desktop Server\\Portuguese\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\Sync ML Desktop Server\\Dutch\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\Sync ML Desktop Server\\Swedish\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Samsung\\Samsung PC Studio 2.1\\Sync ML Desktop Server\\Greek\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\PCHEALTH\\ERRORREP\\QHEADLES\\"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\PCHEALTH\\ERRORREP\\QSIGNOFF\\"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Adobe\\Security Update\\"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\avast!]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,00,b0,07,00,00,00,00,50,14,9d,\
f0,8b,48,c9,01,02,00,00,00,43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,\
41,00,7e,00,31,00,5c,00,41,00,4c,00,57,00,49,00,4c,00,53,00,7e,00,31,00,5c,\
00,41,00,76,00,61,00,73,00,74,00,34,00,5c,00,61,00,73,00,68,00,50,00,6f,00,\
70,00,57,00,7a,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\HijackThis]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,20,1d,00,00,00,00,00,28,85,e3,\
bc,11,f5,c7,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,48,00,69,00,6a,00,61,\
00,63,00,6b,00,74,00,68,00,69,00,73,00,20,00,56,00,65,00,72,00,73,00,69,00,\
6f,00,6e,00,20,00,46,00,72,00,61,00,6e,00,e7,00,61,00,69,00,73,00,65,00,5c,\
00,56,00,45,00,52,00,53,00,49,00,4f,00,4e,00,20,00,54,00,52,00,41,00,44,00,\
55,00,49,00,54,00,45,00,20,00,4f,00,52,00,49,00,47,00,49,00,4e,00,41,00,4c,\
00,45,00,2e,00,45,00,58,00,45,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LiveReg]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,b0,1c,00,00,00,00,00,f6,81,89,\
05,15,f0,c4,01,02,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,46,00,69,00,63,00,68,\
00,69,00,65,00,72,00,73,00,20,00,63,00,6f,00,6d,00,6d,00,75,00,6e,00,73,00,\
5c,00,53,00,79,00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,\
00,72,00,65,00,64,00,5c,00,4c,00,69,00,76,00,65,00,52,00,65,00,67,00,5c,00,\
73,00,79,00,6d,00,63,00,73,00,75,00,62,00,2e,00,65,00,78,00,65,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LiveUpdate]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,90,71,00,00,00,00,00,a0,21,9a,\
3a,f7,99,c7,01,02,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,79,00,6d,00,61,\
00,6e,00,74,00,65,00,63,00,5c,00,4c,00,69,00,76,00,65,00,55,00,70,00,64,00,\
61,00,74,00,65,00,5c,00,4c,00,75,00,43,00,6f,00,6d,00,53,00,65,00,72,00,76,\
00,65,00,72,00,5f,00,32,00,5f,00,35,00,2e,00,45,00,58,00,45,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (2.0.0.12)]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,a0,69,01,00,00,00,00,34,c3,67,\
48,34,73,c8,01,0c,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,6f,00,7a,00,69,\
00,6c,00,6c,00,61,00,20,00,46,00,69,00,72,00,65,00,66,00,6f,00,78,00,5c,00,\
66,00,69,00,72,00,65,00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (2.0.0.13)]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,00,43,01,00,00,00,00,b2,d0,0b,\
36,cc,90,c8,01,55,01,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,6f,00,7a,00,69,\
00,6c,00,6c,00,61,00,20,00,46,00,69,00,72,00,65,00,66,00,6f,00,78,00,5c,00,\
65,00,78,00,74,00,65,00,6e,00,73,00,69,00,6f,00,6e,00,73,00,5c,00,74,00,61,\
00,6c,00,6b,00,62,00,61,00,63,00,6b,00,40,00,6d,00,6f,00,7a,00,69,00,6c,00,\
6c,00,61,00,2e,00,6f,00,72,00,67,00,5c,00,63,00,6f,00,6d,00,70,00,6f,00,6e,\
00,65,00,6e,00,74,00,73,00,5c,00,74,00,61,00,6c,00,6b,00,62,00,61,00,63,00,\
6b,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (2.0
0
celine391 Messages postés 12 Date d'inscription lundi 17 novembre 2008 Statut Membre Dernière intervention 28 septembre 2012
18 nov. 2008 à 23:55
[ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\HijackThis.exe: trouvé !
C:\Combofix.txt: trouvé !
C:\hijackthis.log: trouvé !
C:\fixnavi.txt: trouvé !
C:\cleannavi.txt: trouvé !
C:\MsnFix: trouvé !
C:\Qoobox: trouvé !
C:\Documents and Settings\All Users\Documents\Mes images\mes images\hijackthis.log: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Navilog1.exe: trouvé !
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\hijackthis.log: trouvé !
C:\Program Files\Navilog1: trouvé !
C:\Program Files\Hijackthis Version Française\hijackthis.log: trouvé !
C:\Program Files\Navilog1\Navilog1.bat: trouvé !
C:\QooBox\Quarantine\C\Combofix: trouvé !
C:\WINDOWS\msnfix.txt: trouvé !

---------------------------------
-->- Suppression:

C:\HijackThis.exe: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Navilog1.exe: supprimé !
C:\Program Files\Navilog1\Navilog1.bat: supprimé !
C:\Combofix.txt: supprimé !
C:\hijackthis.log: supprimé !
C:\fixnavi.txt: supprimé !
C:\cleannavi.txt: supprimé !
C:\Documents and Settings\All Users\Documents\Mes images\mes images\hijackthis.log: supprimé !
C:\Documents and Settings\Compaq_Propriétaire\Mes documents\hijackthis.log: supprimé !
C:\Program Files\Hijackthis Version Française\hijackthis.log: supprimé !
C:\WINDOWS\msnfix.txt: supprimé !
C:\MsnFix: supprimé !
C:\Qoobox: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
C:\Program Files\Navilog1: supprimé !
je ne sais meme plus si il manque un rapport lol
0
Utilisateur anonyme
19 nov. 2008 à 00:04
lol..............non mais je pense que c est bon la................;
0
celine391 Messages postés 12 Date d'inscription lundi 17 novembre 2008 Statut Membre Dernière intervention 28 septembre 2012
19 nov. 2008 à 09:12
alors merci de ton aide et j espere pas a bientot mdr!
0
Utilisateur anonyme
19 nov. 2008 à 15:44
c est cool.......................
0