

binacalista
Membres-
Compteur de contenus
27 -
Inscription
-
Dernière visite
Tout ce qui a été posté par binacalista
-
Bonjour, jespere que quelqu'un pourra m'aider a retirer ce bidule, je sais pas où j'ai pu l'attraper et avast me le détecte mais il n'arrive pas a me le retirer. Quelqu'un peut maider? voici mon rapport Hijackthis Logfile of HijackThis v1.99.1 Scan saved at 14:23:03, on 29/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Acer\Acer eMode Management\AspireService.exe C:\Program Files\Acer\eRecovery\Monitor.exe C:\Program Files\Acer\Acer eConsole\MediaSync.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800" O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1135069124750 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
-
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
bonsoir charles et bien je n'ai qu'une seule chose a te dire : MERCI merci pour ta gentillesse, ta patience et surtout pour ton aide. J'ai suivi tous tes conseils a la lettre et tout se passe bien. Donc une fois de plus Merci -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
Coucou J'ai fais tout ce que tu m'as dis et il est vrai qu'il est plus rapide au démarrage et pleins de choses ont disparu dont wanadoo mais cela ne mempeche pas de me connecter alors que je pensais que c ca ki faisait la connexion ! merci merci -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
Un grand merci a QC001 et bien sur Charles Ingals !!! J'ai résolu aussi le probleme des images cétait rien de grave. A TOUS LES DEUX !!!! last question but not least comment optimiser le systeme? Apres je cesse de vous harceler promis juré mais pas cracher car je suis une lady -
Bonsoir, Mon probleme est a la fois tres simple et tres étrange. Apres avoir eu quelques problemes avec un malware et réussi a le retirer, j'ai constaté que des que je mettais une photo ou une image sur le bureau pour la visualiser, je ne pouvais pas l'ouvrir avec l'appercu des images et des télécopies windows.ca semble vouloir s'ouvrir mais se bloque et ca se referme automatiquement. Si je mets cette meme image dans mes documents ou dans un dossier, elle s'ouvre. Comment faire pour que cela fonctionne aussi sur le bureau comme avant? Bon bah on vient de me trouver une solution c'était rien de grave. Merci quand meme
-
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
Bon bah voila tout est fait et tout est propre ! merci non un grand merci a vous deux pour l'autre probleme je vais faire ce que tu mas dis et je verrai si quelqu'un peut m'aider mais bon ca semble pas tres grave, je px visualiser partout sauf sur le bureau. Merci encore. Au faite tu penses que j'ai pu chopper tout cela où? parcontre tu mas dis cela "Si tu veux on fixera quelque lignes sur ton rapport: certains logiciels se lancent au démarrage,c'est inutile et ca bouffe des ressources pour rien!" que voulais tu dire? -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
non cest bien la le problème je n'ai pas supprimé ce fichier et il est bien présent. Je viens de vérifier. -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
ah bah cest gentil, jai tout fais merci beaucoup. Je viens de remarquer que lorsque j'enregistre ou mets une image ou photo sur le bureau et l'ouvre pour la visualiser, l'appercu des images et des télécopies windows n'arrive pas a s'ouvrir mais si je déplace la photo ou l'image dans un fichier là elle s'ouvre. C'est normal? -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
comment je fais pour effacer " Supprime le fichier fixme.reg que tu avais créé au début." ? Logfile of HijackThis v1.99.1 Scan saved at 21:57:35, on 18/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\Program Files\Acer\eRecovery\Monitor.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Acer\Acer eMode Management\AspireService.exe C:\Program Files\Acer\Acer eConsole\MediaSync.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\PROGRA~1\Wanadoo\TaskBarIcon.exe C:\WINDOWS\System32\FTRTSVC.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\PROGRA~1\Wanadoo\ComComp.exe C:\PROGRA~1\Wanadoo\Toaster.exe C:\PROGRA~1\Wanadoo\Inactivity.exe C:\PROGRA~1\Wanadoo\PollingModule.exe C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\Wanadoo\Watch.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Nat & Sab\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM= O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU) O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1135069124750 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Bon je suppose que le fichier fixme.reg était sur le bureau et comme jefface au fur et a mesure il é parti depuis bien longtemps. Voila mon rapport. Spybot quand a lui ne détecte plus rien et je n'ai plus de pages qui saffiche des que jouvre ou navigue sur internet explorer. Donc déjà merciiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii mais euh....et pour mon probleme sur le bureau? les photos qui ne souvre pas? -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
coucou bon bah voila mon rapport ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Wednesday, January 18, 2006 18:32:12 Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 18/01/2006 Kaspersky Anti-Virus database records: 171721 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ G:\ H:\ I:\ J:\ Scan Statistics: Total number of scanned objects: 49067 Number of viruses found: 2 Number of infected objects: 14 Number of suspicious objects: 0 Duration of the scan process: 1227 sec Infected Object Name - Virus Name C:\!KillBox\lbecovx.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\Documents and Settings\Nat & Sab\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-729f21ed.zip/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.w C:\Documents and Settings\Nat & Sab\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-729f21ed.zip Infected: Trojan-Downloader.Java.OpenStream.w C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000027.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000054.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000185.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000270.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000281.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000316.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000354.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000388.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP1\A0000452.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\System Volume Information\_restore{0F563069-B249-4BA2-B95F-31CB7CB72A54}\RP2\A0000485.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.m C:\WINDOWS\system32\msclock32.dll Infected: not-a-virus:AdWare.Win32.NaviPromo.m Scan process completed. -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
daccord merci cest en train de tourner parcontre je viens de remarquer que je ne px plus ouvrir des photos ou image lorsqu'elles sont sur le bureau c normal? -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
je viens de vérifier je pense que j'ai déjà un probleme de résolu qui était les pubs et pages qui souvraient des que j'utilisais internet explorer ! quand a magiccontrol,spybot me le détecte toujours Merci à toi quand meme car tu as réussi a me résoudre déjà la moitié de mon probleme sinon le pc va plus vite, il redémarre ou séteind plus rapidement..coincidence?...je pense pas -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
Bonjour QC001 Alors jai bien fais ce que tu mas demandé et au lieu de trouver lbecovx.exe jai trouvé lbecovx.dat ainsi que lbecovx_nav.dat et lbecovx_navps.dat donc je me suis pas posée 10 000 questions jai effacé les trois lol voici le rapport demandé Logfile of HijackThis v1.99.1 Scan saved at 16:55:58, on 18/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Acer\eRecovery\Monitor.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Acer\Acer eMode Management\AspireService.exe C:\Program Files\Acer\Acer eConsole\MediaSync.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\PROGRA~1\Wanadoo\TaskBarIcon.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\System32\FTRTSVC.exe C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\PROGRA~1\Wanadoo\ComComp.exe C:\PROGRA~1\Wanadoo\Toaster.exe C:\PROGRA~1\Wanadoo\Inactivity.exe C:\PROGRA~1\Wanadoo\PollingModule.exe C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\Wanadoo\Watch.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\cmd.exe C:\Documents and Settings\Nat & Sab\Bureau\HijackThis.exe C:\WINDOWS\system32\ping.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM= O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1135069124750 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe doesn't exist HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iexplore.exe doesn't exist HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx doesn't exist HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run doesn't exist HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run doesn't exist HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe ----------------------- ----------------------- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers] [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido] @="{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Fichiers hors connexion] @="{750fdf0e-2a26-11d1-a3ea-080036587f03}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ICEOWS] @="{FEB7DAE0-E111-11D0-BFD7-444553540000}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With] @="{09799AFB-AD67-11d1-ABCD-00C04FC30936}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu] @="{A470F8CF-A1E8-4f65-8335-227475AA5C46}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}] @="Épingle du menu Démarrer" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LaunchApp"="Alaunch" "NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\"" "eRecoveryService"="C:\\Program Files\\Acer\\eRecovery\\Monitor.exe" "ntiMUI"="C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\ntiMUI.exe" @="" "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32" "MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC" "PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC" "PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName" "AspireService"="C:\\Program Files\\Acer\\Acer eMode Management\\AspireService.exe" "MediaSync"="C:\\Program Files\\Acer\\Acer eConsole\\MediaSync.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe" "WOOWATCH"="C:\\PROGRA~1\\Wanadoo\\Watch.exe" "WOOTASKBARICON"="C:\\PROGRA~1\\Wanadoo\\GestMaj.exe TaskBarIcon.exe" "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE" "MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\"" "EPSON Stylus DX3800 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIACE.EXE /P26 \"EPSON Stylus DX3800 Series\" /O6 \"USB001\" /M \"Stylus DX3800\"" "TkBellExe"="\"C:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe\" -osboot" "Zone Labs Client"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe" "WOOKIT"="C:\\PROGRA~1\\Wanadoo\\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=" "MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart" "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce] Scheduled Tasks Folder Contents * C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\SA.DAT C:\WINDOWS\Tasks\XoftSpy.job -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
oui jai bien suivi tes manipulations et dailleurs jai recommencer encore pour voir et non le fichier n'apparait pas du tout c louche... -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
c'est bon jai réussi a toruver il fallait que je m'inscrive sur le site afin dacceder a ton téléchargement. Voila ce kil me dit : Logfile of HijackThis v1.99.1 Scan saved at 14:15:28, on 18/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\WINDOWS\System32\FTRTSVC.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\Program Files\Acer\eRecovery\Monitor.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Acer\Acer eMode Management\AspireService.exe C:\Program Files\Acer\Acer eConsole\MediaSync.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\PROGRA~1\Wanadoo\TaskBarIcon.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\windows\system32\lbecovx.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe C:\PROGRA~1\Wanadoo\ComComp.exe C:\PROGRA~1\Wanadoo\Toaster.exe C:\PROGRA~1\Wanadoo\Inactivity.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\PROGRA~1\Wanadoo\PollingModule.exe C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\Wanadoo\Watch.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\cmd.exe C:\Documents and Settings\Nat & Sab\Bureau\HijackThis.exe C:\WINDOWS\system32\ping.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [lbecovx] c:\windows\system32\lbecovx.exe lbecovx O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM= O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1135069124750 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe doesn't exist HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iexplore.exe doesn't exist HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx doesn't exist HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run doesn't exist HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run doesn't exist HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe ----------------------- ----------------------- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx] [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers] [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido] @="{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Fichiers hors connexion] @="{750fdf0e-2a26-11d1-a3ea-080036587f03}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ICEOWS] @="{FEB7DAE0-E111-11D0-BFD7-444553540000}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With] @="{09799AFB-AD67-11d1-ABCD-00C04FC30936}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu] @="{A470F8CF-A1E8-4f65-8335-227475AA5C46}" [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}] @="Épingle du menu Démarrer" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LaunchApp"="Alaunch" "NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\"" "eRecoveryService"="C:\\Program Files\\Acer\\eRecovery\\Monitor.exe" "ntiMUI"="C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\ntiMUI.exe" @="" "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32" "MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC" "PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC" "PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName" "AspireService"="C:\\Program Files\\Acer\\Acer eMode Management\\AspireService.exe" "MediaSync"="C:\\Program Files\\Acer\\Acer eConsole\\MediaSync.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe" "WOOWATCH"="C:\\PROGRA~1\\Wanadoo\\Watch.exe" "WOOTASKBARICON"="C:\\PROGRA~1\\Wanadoo\\GestMaj.exe TaskBarIcon.exe" "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE" "MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\"" "EPSON Stylus DX3800 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIACE.EXE /P26 \"EPSON Stylus DX3800 Series\" /O6 \"USB001\" /M \"Stylus DX3800\"" "TkBellExe"="\"C:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe\" -osboot" "Zone Labs Client"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe" "lbecovx"="c:\\windows\\system32\\lbecovx.exe lbecovx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe" "WOOKIT"="C:\\PROGRA~1\\Wanadoo\\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=" "MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart" "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce] Scheduled Tasks Folder Contents * C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\SA.DAT C:\WINDOWS\Tasks\XoftSpy.job -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
je ne trouve pas HijackThis! + Extra sur ton lien mais parcontre jai HijackThis sur mon pc , ca suffit? -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
Bon bah euh...non il est tjrs la ! spybot le détecte de nouveau. Semblerait qu'il réapparaisse apres démarrage. Pourquoi? comment? je n'en sais rien et ca commence vraiment a ménerver j'attends tes suggestions lol -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
Bonjour CHarles lol alors pour le fichier reg jai effectivement utiliser le fichier en mode sans échec sinon je viens de suivre tes consignes mais parcontre " Quand jv16 a terminé la recherche,vas dans le menu "sélectionner" choisis "sélectionner tout" puis va en bas à droite et supprime.Tu peux virer toutes les entrées en vert." pour ca en faite jai fé tout selectionner et supprimer et il ma supprimer tout autant les entrées vertes que les entrées rouges donc jespere que ce nest pas grave... je vais redémarrer et te dis de suite si ca marche ou non -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
--------------------------------------------------------- ewido anti-malware - Rapport de scan --------------------------------------------------------- + Créé le: 02:33:11, 18/01/2006 + Somme de contrôle: FBEB82A3 + Résultats du scan: Pas de fichiers infectés trouvés! ::Fin du rapport Jai effectivement fait tourner spybot en mode sans echec et il ma de nouveau trouver magiccontrol.agent parcontre ewido ne me trouve rien du tout. Il se fait tard, je vais me coucher. J'espere te revoir demain lol et peut etre trouverons nous une solution mais bien sur je te remercie pour ton aide et de m'avoir donner un peu de ton temps. -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
oui tout a fait un cube vert et cela ma demander si je voulais ajouter les infos contenus sur / bureau/remove.regau registre et jai dis oui et il ma redis que cela était inscrit au registre. -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
euh ca ressemblait a une image de...euh...de clé de registre je crois bien. voici le rapport de spybot et de regsearch --- Search result list --- MagicControl.Agent: Réglages utilisateur (Clé du registre, nothing done) HKEY_USERS\S-1-5-21-2011925375-3653460283-2877552486-1006\Software\LanConfig --- Spybot - Search & Destroy version: 1.4 (build: 20050523) --- 2005-05-31 blindman.exe (1.0.0.1) 2005-05-31 SpybotSD.exe (1.4.0.3) 2005-05-31 TeaTimer.exe (1.4.0.2) 2006-01-06 unins000.exe (51.41.0.0) 2005-05-31 Update.exe (1.4.0.0) 2004-10-04 advcheck.dll (1.0.1.0) 2005-05-31 aports.dll (2.1.0.0) 2005-05-31 borlndmm.dll (7.0.4.453) 2005-05-31 delphimm.dll (7.0.4.453) 2005-05-31 SDHelper.dll (1.4.0.0) 2005-05-31 Tools.dll (2.0.0.2) 2005-05-31 UnzDll.dll (1.73.1.1) 2005-05-31 ZipDll.dll (1.73.2.0) 2005-12-30 Includes\Cookies.sbi (*) 2005-12-30 Includes\Dialer.sbi (*) 2005-12-30 Includes\Hijackers.sbi (*) 2005-12-30 Includes\Keyloggers.sbi (*) 2005-12-30 Includes\Malware.sbi (*) 2005-12-30 Includes\PUPS.sbi (*) 2005-12-30 Includes\Revision.sbi (*) 2005-12-30 Includes\Security.sbi (*) 2005-12-30 Includes\Spybots.sbi (*) 2005-02-17 Includes\Tracks.uti 2005-12-30 Includes\Trojans.sbi (*) --- System information --- Windows XP (Build: 2600) Service Pack 2 / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB886903) / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) / Windows XP / SP3: Correctif Windows XP - KB867282 / Windows XP / SP3: Correctif Windows XP - KB873339 / Windows XP / SP3: Correctif Windows XP - KB885250 / Windows XP / SP3: Correctif Windows XP - KB885835 / Windows XP / SP3: Correctif Windows XP - KB885836 / Windows XP / SP3: Correctif Windows XP - KB885884 / Windows XP / SP3: Correctif Windows XP - KB886185 / Windows XP / SP3: Correctif Windows XP - KB887472 / Windows XP / SP3: Correctif Windows XP - KB887742 / Windows XP / SP3: Correctif Windows XP - KB888113 / Windows XP / SP3: Correctif Windows XP - KB888302 / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB890046) / Windows XP / SP3: Correctif Windows XP - KB890047 / Windows XP / SP3: Correctif Windows XP - KB890175 / Windows XP / SP3: Correctif Windows XP - KB890859 / Windows XP / SP3: Correctif Windows XP - KB890923 / Windows XP / SP3: Correctif Windows XP - KB891781 / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB893066) / Windows XP / SP3: Correctif Windows XP - KB893086 / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB893756) / Windows XP / SP3: Windows Installer 3.1 (KB893803) / Windows XP / SP3: Mise à jour pour Windows XP (KB894391) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896358) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896422) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896423) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896424) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896428) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896688) / Windows XP / SP3: Mise à jour pour Windows XP (KB896727) / Windows XP / SP3: Mise à jour pour Windows XP (KB898461) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB899587) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB899591) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB900725) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB901017) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB901214) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB902400) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB904706) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB905414) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB905749) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB905915) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB908519) / Windows XP / SP3: Mise à jour pour Windows XP (KB910437) / Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB912919) --- Startup entries list --- Located: HK_LM:Run, command: file: Located: HK_LM:Run, AspireService command: C:\Program Files\Acer\Acer eMode Management\AspireService.exe file: C:\Program Files\Acer\Acer eMode Management\AspireService.exe size: 114688 MD5: 57a8e5e6863fd77538a2cf6151e32da8 Located: HK_LM:Run, avast! command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe size: 98352 MD5: 0a9883be214c4f7a65b6dff129f37b6e Located: HK_LM:Run, EPSON Stylus DX3800 Series command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800" file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE size: 98304 MD5: b9297016cbc59d2d5631cc982479cc96 Located: HK_LM:Run, eRecoveryService command: C:\Program Files\Acer\eRecovery\Monitor.exe file: C:\Program Files\Acer\eRecovery\Monitor.exe size: 352256 MD5: 6d03048ef846508b3d2ea61adaa518ec Located: HK_LM:Run, IMJPMIG8.1 command: "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 file: C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE size: 208952 MD5: 7bbe4cf421aecc7f0226edd75f12079f Located: HK_LM:Run, LaunchApp command: Alaunch file: C:\WINDOWS\Alaunch.exe size: 520192 MD5: c7f4958a99983e2e4b435be798081dd8 Located: HK_LM:Run, LVCOMSX command: C:\WINDOWS\system32\LVCOMSX.EXE file: C:\WINDOWS\system32\LVCOMSX.EXE size: 221184 MD5: 5ba8a7da5d0573f7923e02b260aad2f1 Located: HK_LM:Run, MediaSync command: C:\Program Files\Acer\Acer eConsole\MediaSync.exe file: C:\Program Files\Acer\Acer eConsole\MediaSync.exe size: 425984 MD5: 65cb183cb14a048ecea5330994307ae0 Located: HK_LM:Run, MessengerPlus3 command: "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" file: C:\Program Files\MessengerPlus! 3\MsgPlus.exe size: 190024 MD5: f5f3a19013808113b1f3dada4379606a Located: HK_LM:Run, MSPY2002 command: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC file: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe size: 59392 MD5: 1b17e09c1223f6d17336d2dd7a1af4f4 Located: HK_LM:Run, ntiMUI command: C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe file: C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe size: 45056 MD5: 27ecdc43b2e41a865092cc31263358f2 Located: HK_LM:Run, NVMixerTray command: "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" file: C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe size: 131072 MD5: 9a41cd3bef74884c2c9e1269b8a6a566 Located: HK_LM:Run, PHIME2002A command: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName file: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE size: 455168 MD5: 024dc0f68df5fd6ae9dd82dfbaf479d6 Located: HK_LM:Run, PHIME2002ASync command: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC file: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE size: 455168 MD5: 024dc0f68df5fd6ae9dd82dfbaf479d6 Located: HK_LM:Run, RemoteControl command: "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" file: C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe size: 32768 MD5: 7a011702c0aa86ad79efa86e66f411dc Located: HK_LM:Run, SunJavaUpdateSched command: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe file: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe size: 36975 MD5: 61a3a9d5d98bf0331df5b716144a8100 Located: HK_LM:Run, TkBellExe command: "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot file: C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe size: 180269 MD5: 006220ee86eb71c5884f415eaa9e8058 Located: HK_LM:Run, WOOTASKBARICON command: C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe file: C:\PROGRA~1\Wanadoo\GestMaj.exe size: 32768 MD5: 8d6f2c724cfc608872ede3cc4a7b49b9 Located: HK_LM:Run, WOOWATCH command: C:\PROGRA~1\Wanadoo\Watch.exe file: C:\PROGRA~1\Wanadoo\Watch.exe size: 20480 MD5: 9a29592cd135f6262c429152f7a8dd4a Located: HK_LM:Run, Zone Labs Client command: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe size: 755472 MD5: e85c5dc2659f562c496e839649aa7200 Located: HK_LM:Run, Zone Labs Client command: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe size: 755472 MD5: e85c5dc2659f562c496e839649aa7200 Located: HK_CU:Run, CTFMON.EXE command: C:\WINDOWS\system32\ctfmon.exe file: C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5584247b568c2e53934873f4b655fe6a Located: HK_CU:Run, MessengerPlus3 command: "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart file: C:\Program Files\MessengerPlus! 3\MsgPlus.exe size: 190024 MD5: f5f3a19013808113b1f3dada4379606a Located: HK_CU:Run, msnmsgr command: "C:\Program Files\MSN Messenger\msnmsgr.exe" /background file: C:\Program Files\MSN Messenger\msnmsgr.exe size: 7094272 MD5: bcd239cb30b5356a019fd81e45d6636b Located: HK_CU:Run, WOOKIT command: C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM= file: C:\PROGRA~1\Wanadoo\Shell.exe size: 122880 MD5: 2bd5e1e68614dbc6b320597856ed6ea7 Located: Démarrage (tous utilisateurs), Adobe Reader Speed Launch.lnk command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe size: 29696 MD5: deb88aef013dd1eefb462d7cad642166 Located: Démarrage (tous utilisateurs), Microsoft Office.lnk command: C:\Program Files\Microsoft Office\Office10\OSA.EXE file: C:\Program Files\Microsoft Office\Office10\OSA.EXE size: 83360 MD5: 5bc65464354a9fd3beaa28e18839734a Located: System.ini, AtiExtEvent command: Ati2evxx.dll file: Ati2evxx.dll Located: System.ini, crypt32chain command: crypt32.dll file: crypt32.dll Located: System.ini, cryptnet command: cryptnet.dll file: cryptnet.dll Located: System.ini, cscdll command: cscdll.dll file: cscdll.dll Located: System.ini, ScCertProp command: wlnotify.dll file: wlnotify.dll Located: System.ini, Schedule command: wlnotify.dll file: wlnotify.dll Located: System.ini, sclgntfy command: sclgntfy.dll file: sclgntfy.dll Located: System.ini, SensLogn command: WlNotify.dll file: WlNotify.dll Located: System.ini, termsrv command: wlnotify.dll file: wlnotify.dll Located: System.ini, wlballoon command: wlnotify.dll file: wlnotify.dll --- Browser helper object list --- {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class) BHO name: CLSID name: SSVHelper Class Path: C:\Program Files\Java\jre1.5.0_06\bin\ Long name: ssv.dll Short name: Date (created): 10/11/2005 13:03:56 Date (last access): 18/01/2006 01:21:24 Date (last write): 10/11/2005 13:22:10 Filesize: 184423 Attributes: archive MD5: F01726F7CA8538FDD4663C9DB8FEAEDC CRC32: 0111B892 Version: 5.0.60.5 {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class) BHO name: CLSID name: EpsonToolBandKicker Class Path: C:\Program Files\EPSON\EPSON Web-To-Page\ Long name: EPSON Web-To-Page.dll Short name: EPSONW~1.DLL Date (created): 13/12/2005 18:13:58 Date (last access): 18/01/2006 01:21:26 Date (last write): 21/02/2005 21:50:34 Filesize: 368640 Attributes: archive MD5: 01319CF4030B3740BA8261E7024ACAD1 CRC32: D484DB79 Version: 1.1.0.0 --- ActiveX list --- {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) DPF name: CLSID name: InstallerBehaviorFactory Class Installer: C:\WINDOWS\Downloaded Program Files\MsnInstC.inf Codebase: https://signup.msn.com/pages/MsnInstC.cab Path: C:\WINDOWS\Downloaded Program Files\ Long name: MsnInstC.dll {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) DPF name: CLSID name: ActiveScan Installer Class Installer: C:\WINDOWS\Downloaded Program Files\asinst.inf Codebase: http://acs.pandasoftware.com/activescan/as5free/asinst.cab description: classification: Open for discussion known filename: ASINST.DLL info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\Downloaded Program Files\ Long name: asinst.dll Short name: Date (created): 19/12/2005 13:35:32 Date (last access): 18/01/2006 00:58:56 Date (last write): 19/12/2005 13:35:32 Filesize: 135168 Attributes: archive MD5: 20C07B231040B49AFCE82397BFC35F9C CRC32: 9301377D Version: 58.4.0.0 {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) DPF name: Java Runtime Environment 1.5.0 CLSID name: Java Plug-in 1.5.0_06 Installer: Codebase: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab Path: C:\Program Files\Java\jre1.5.0_06\bin\ Long name: NPJPI150_06.dll Short name: NPJPI1~1.DLL Date (created): 10/11/2005 13:03:56 Date (last access): 18/01/2006 01:27:00 Date (last write): 10/11/2005 13:22:10 Filesize: 69746 Attributes: archive MD5: D2CF6BB5E9020E6707B62575F8083954 CRC32: 7F39DC54 Version: 5.0.60.5 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) DPF name: Java Runtime Environment 1.5.0 CLSID name: Java Plug-in 1.5.0_06 Installer: Codebase: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab Path: C:\Program Files\Java\jre1.5.0_06\bin\ Long name: NPJPI150_06.dll Short name: NPJPI1~1.DLL Date (created): 10/11/2005 13:03:56 Date (last access): 18/01/2006 01:27:00 Date (last write): 10/11/2005 13:22:10 Filesize: 69746 Attributes: archive MD5: D2CF6BB5E9020E6707B62575F8083954 CRC32: 7F39DC54 Version: 5.0.60.5 --- Process list --- PID: 0 ( 0) [system] PID: 588 ( 4) \SystemRoot\System32\smss.exe PID: 652 ( 588) \??\C:\WINDOWS\system32\csrss.exe PID: 692 ( 588) \??\C:\WINDOWS\system32\winlogon.exe PID: 736 ( 692) C:\WINDOWS\system32\services.exe size: 108544 MD5: 732E0B1ABAACE15D80EC19056B0A2AF9 PID: 748 ( 692) C:\WINDOWS\system32\lsass.exe size: 13312 MD5: 9F3744A5C6F49291A7A685040A013399 PID: 888 ( 736) C:\WINDOWS\system32\Ati2evxx.exe size: 360448 MD5: 6633CBF0D658440F0962D90E5BD20DDE PID: 916 ( 736) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 1BD6C2F707A275CB7C16FD99FE0F31CA PID: 1004 ( 736) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 1BD6C2F707A275CB7C16FD99FE0F31CA PID: 1100 ( 736) C:\WINDOWS\System32\svchost.exe size: 14336 MD5: 1BD6C2F707A275CB7C16FD99FE0F31CA PID: 1168 ( 736) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 1BD6C2F707A275CB7C16FD99FE0F31CA PID: 1356 ( 736) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 1BD6C2F707A275CB7C16FD99FE0F31CA PID: 1492 ( 736) C:\WINDOWS\system32\spoolsv.exe size: 57856 MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F PID: 1652 ( 736) C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe size: 53248 MD5: 435D862E96FE19612093177CF6618F4E PID: 1668 ( 736) C:\Program Files\Alwil Software\Avast4\ashServ.exe size: 98352 MD5: C8C0AEE5D0585457FF6E318E8BB9289D PID: 1712 ( 736) C:\WINDOWS\System32\FTRTSVC.exe size: 40960 MD5: D1261099E03EEE90976EA19002995B89 PID: 1776 ( 736) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 1BD6C2F707A275CB7C16FD99FE0F31CA PID: 1816 ( 736) C:\WINDOWS\system32\wdfmgr.exe size: 38912 MD5: C81B8635DEE0D3EF5F64B3DD643023A5 PID: 1880 ( 736) C:\WINDOWS\system32\ZoneLabs\vsmon.exe size: 1693448 MD5: 7E9C8F0BF97910E04A078799837BB6F2 PID: 1176 ( 736) C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe size: 241712 MD5: 8C50FFD2642FD97DAC0009280A438570 PID: 1200 ( 736) C:\Program Files\Alwil Software\Avast4\ashWebSv.exe size: 360496 MD5: EB51923A762779247C776A551C546898 PID: 1460 ( 736) C:\WINDOWS\System32\alg.exe size: 44544 MD5: 2FE681D10C5FC343DBBC0610B8DD4D24 PID: 1772 ( 692) C:\WINDOWS\system32\Ati2evxx.exe size: 360448 MD5: 6633CBF0D658440F0962D90E5BD20DDE PID: 2184 (2124) C:\WINDOWS\Explorer.EXE size: 1036288 MD5: 4C33E5B9A6197B6ED215F6CFBA0A2DAA PID: 2592 (2184) C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe size: 131072 MD5: 9A41CD3BEF74884C2C9E1269B8A6A566 PID: 2632 (2184) C:\Program Files\Acer\eRecovery\Monitor.exe size: 352256 MD5: 6D03048EF846508B3D2EA61ADAA518EC PID: 2656 (2184) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe size: 32768 MD5: 7A011702C0AA86AD79EFA86E66F411DC PID: 2764 (2184) C:\Program Files\Acer\Acer eMode Management\AspireService.exe size: 114688 MD5: 57A8E5E6863FD77538A2CF6151E32DA8 PID: 2772 (2184) C:\Program Files\Acer\Acer eConsole\MediaSync.exe size: 425984 MD5: 65CB183CB14A048ECEA5330994307AE0 PID: 2784 (2184) C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe size: 36975 MD5: 61A3A9D5D98BF0331DF5B716144A8100 PID: 2836 (2184) C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe size: 98352 MD5: 0A9883BE214C4F7A65B6DFF129F37B6E PID: 2868 (2184) C:\WINDOWS\system32\LVCOMSX.EXE size: 221184 MD5: 5BA8A7DA5D0573F7923E02B260AAD2F1 PID: 2892 (2800) C:\PROGRA~1\Wanadoo\TaskBarIcon.exe size: 61440 MD5: F9710A77123CC3FD09D062F2AF33E473 PID: 2904 (2184) C:\Program Files\MessengerPlus! 3\MsgPlus.exe size: 190024 MD5: F5F3A19013808113B1F3DADA4379606A PID: 2964 (2184) C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE size: 98304 MD5: B9297016CBC59D2D5631CC982479CC96 PID: 3024 (2184) C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe size: 180269 MD5: 006220EE86EB71C5884F415EAA9E8058 PID: 3040 (2184) C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe size: 755472 MD5: E85C5DC2659F562C496E839649AA7200 PID: 3104 (2184) C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5584247B568C2E53934873F4B655FE6A PID: 3772 (3376) C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe size: 802816 MD5: 3413F188DDC03149E02EC683CC8CF72B PID: 4024 (3772) C:\PROGRA~1\Wanadoo\ComComp.exe size: 245760 MD5: B61E01BE313E30D37AC2D74C86D9E719 PID: 4064 (3772) C:\PROGRA~1\Wanadoo\Toaster.exe size: 69632 MD5: C2D1BD2B433571ECEC29924ACE5D7C62 PID: 4072 (3772) C:\PROGRA~1\Wanadoo\Inactivity.exe size: 32768 MD5: 5F6DBF75D05462EED92B42376E89D9FE PID: 4080 (3772) C:\PROGRA~1\Wanadoo\PollingModule.exe size: 69632 MD5: EDF02F58940FD56C12357D150F5397C0 PID: 1548 ( 916) C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE size: 45056 MD5: 68E404DB5525373FE0554ED2607F0C82 PID: 1272 (4024) C:\PROGRA~1\Wanadoo\Watch.exe size: 20480 MD5: 9A29592CD135F6262C429152F7A8DD4A PID: 2056 (3536) C:\Program Files\MSN Messenger\msnmsgr.exe size: 7094272 MD5: BCD239CB30B5356A019FD81E45D6636B PID: 2352 (2184) C:\Program Files\Mozilla Firefox\firefox.exe size: 7162979 MD5: F375D4684A1F72D279A7CFA7A5DE1A9C PID: 3916 ( 736) C:\WINDOWS\System32\svchost.exe size: 14336 MD5: 1BD6C2F707A275CB7C16FD99FE0F31CA PID: 2484 ( 736) C:\Program Files\ewido anti-malware\ewidoguard.exe size: 151616 MD5: 34A50717AD686900F078F5208F8E908E PID: 208 ( 736) C:\Program Files\ewido anti-malware\ewidoctrl.exe size: 13888 MD5: 26830B750372AB1BF29C95DEEBEB802F PID: 3340 (2184) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe size: 4393096 MD5: 09CA174A605B480318731E691DC98539 PID: 4 ( 0) system --- Browser start & search pages list --- Spybot - Search & Destroy browser pages report, 18/01/2006 01:27:31 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page C:\WINDOWS\system32\blank.htm HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page http://www.msn.com HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page C:\WINDOWS\system32\blank.htm HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page http://www.msn.com HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm --- Winsock Layered Service Provider list --- --- Uninstall list --- Ad-Aware SE Personal 1.06 (Ad-Aware SE Personal) uninstall cmd: C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG publisher: Lavasoft help link: http://www.lavasoft.com (AddressBook) ATI Display Driver 8.121-050322a-022142C-ATI (ATI Display Driver) uninstall cmd: rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean avast! Antivirus 4.6 (avast!) version (major): 4 version (minor): 6 install location: C:\PROGRA~1\ALWILS~1\Avast4 install source: C:\PROGRA~1\ALWILS~1\Avast4\setup uninstall cmd: rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup publisher: Alwil Software help link: http://www.avast.com (Branding) (Connection Manager) (DirectAnimation) (DirectDrawEx) (DXM_Runtime) ENPC PersoTEST (ENPC PersoTEST) uninstall cmd: C:\PROGRA~1\ENPC_P~1\UNWISE.EXE C:\PROGRA~1\ENPC_P~1\INSTALL.LOG EPSON Logiciel imprimante (EPSON Printer and Utilities) uninstall cmd: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R EPSON Scan (EPSON Scanner) uninstall cmd: C:\Program Files\epson\escndv\setup\setup.exe /r ESDX3800 Guide d'utilisation (ESDX3800 Guide d'utilisation) install location: C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G uninstall cmd: C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G\DOCUNINS.EXE Outil de connexion Wanadoo (EspaceWanadoo.exe) uninstall cmd: C:\PROGRA~1\Wanadoo\MessageDesinstallation.exe Wanadoo ewido anti-malware (ewidoantimalware) install location: C:\Program Files\ewido anti-malware uninstall cmd: C:\Program Files\ewido anti-malware\Uninstall.exe publisher: ewido networks help link: http://www.ewido.net (Fontcore) Iceows V4.20b (ICEOWS) uninstall cmd: C:\Program Files\ICEOWS\Setup.exe /uninstall (ICW) (IE40) (IE4Data) (IE5BAKEX) (IEData) (InstallShield Uninstall Information) NTI CD & DVD-Maker 7 (InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}) version: 117440512 version (major): 7 estimated size: 188829 install date: 20050623 install location: C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ install source: C:\ACERNB\INSTALL\CDM703905R1\ uninstall cmd: C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7 publisher: NewTech Infosystems comments: Vos remarques contact: Service support clientèle help link: http://www.votresociété.com/aide help telephone: +1-555-555-4505 EPSON Attach To Email 1.01.0000 (InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) version: 16842752 version (major): 1 version (minor): 1 estimated size: 1108 install date: 20051213 install location: C:\Program Files\EPSON\Creativity Suite\Attach To Email\ install source: E:\COMMON\CreativitySuite\AttachToEmail\ uninstall cmd: C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG publisher: SEIKO EPSON comments: Attach To Email - Email support app help link: http://www.epson.com/ NTI Backup NOW! 4 4 (InstallShield_{385979FE-DC4F-4140-8EAD-A59625000D72}) version: 67108864 version (major): 4 estimated size: 129594 install date: 20050623 install location: C:\Program Files\NewTech Infosystems\NTI Backup NOW! 4\ install source: C:\ACERNB\INSTALL\CDM703905R1\BUN\ uninstall cmd: C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{385979FE-DC4F-4140-8EAD-A59625000D72} /l1036 BUN4 publisher: NewTech Infosystems comments: Your Comments contact: Technical Support help link: www.ntius.com help telephone: 1-949-421-0712 readme: Readme.txt Music Transfer pavit Edition 1.0.1 (InstallShield_{786DC36B-AB55-4C3A-9FBA-73D14263BE40}) version: 16777217 version (major): 1 estimated size: 8636 install date: 20051213 install location: C:\Program Files\AIWA\Music Transfer pavit Edition\ install source: E:\Setup\ uninstall cmd: C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{786DC36B-AB55-4C3A-9FBA-73D14263BE40} /l1036 publisher: Sony Corporation help link: http://www.aiwa.com/ JVTorrent 1.1 1.1 (JVTorrent) uninstall cmd: C:\Program Files\JVTorrent\uninst.exe publisher: JeuxVideo.com Correctif Windows XP - KB867282 20050127.090417 (KB867282) uninstall cmd: C:\WINDOWS\$NtUninstallKB867282$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=867282 Correctif Windows XP - KB873339 20041117.092459 (KB873339) uninstall cmd: C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=873339 (KB884016) Correctif Windows XP - KB885250 20050118.202711 (KB885250) uninstall cmd: C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=885250 Correctif Windows XP - KB885835 20041027.181713 (KB885835) uninstall cmd: C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=885835 Correctif Windows XP - KB885836 20041028.173203 (KB885836) uninstall cmd: C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=885836 Correctif Windows XP - KB885884 20040924.025457 (KB885884) uninstall cmd: C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=885884 Correctif Windows XP - KB886185 20041021.090540 (KB886185) uninstall cmd: C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=886185 Correctif Windows XP - KB887472 20041014.162858 (KB887472) uninstall cmd: C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=887472 Correctif Windows XP - KB887742 20041103.095002 (KB887742) uninstall cmd: C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=887742 Correctif Windows XP - KB888113 20041116.131036 (KB888113) uninstall cmd: C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=888113 Correctif Windows XP - KB888302 20041207.111426 (KB888302) uninstall cmd: C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=888302 Mise à jour de sécurité pour Windows XP (KB890046) 1 (KB890046) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=890046 Correctif Windows XP - KB890047 20041221.124506 (KB890047) uninstall cmd: C:\WINDOWS\$NtUninstallKB890047$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=890047 Correctif Windows XP - KB890175 20041201.233338 (KB890175) uninstall cmd: C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=890175 Correctif Windows XP - KB890859 1 (KB890859) install date: 20050623 uninstall cmd: "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=890859 Correctif Windows XP - KB890923 1 (KB890923) install date: 20050623 uninstall cmd: "C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=890923 Correctif Windows XP - KB891781 20050110.165439 (KB891781) uninstall cmd: C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=891781 Mise à jour de sécurité pour Windows XP (KB893066) 2 (KB893066) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=893066 Correctif Windows XP - KB893086 1 (KB893086) install date: 20050623 uninstall cmd: "C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=893086 Mise à jour de sécurité pour Windows XP (KB893756) 1 (KB893756) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=893756 (KB893803) Windows Installer 3.1 (KB893803) 3.1 (KB893803v2) uninstall cmd: "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://go.microsoft.com/fwlink/?LinkId=42467 Mise à jour pour Windows XP (KB894391) 1 (KB894391) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=894391 Mise à jour de sécurité pour Windows XP (KB896358) 1 (KB896358) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=896358 Mise à jour de sécurité pour Windows XP (KB896422) 1 (KB896422) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=896422 Mise à jour de sécurité pour Windows XP (KB896423) 1 (KB896423) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=896423 Mise à jour de sécurité pour Windows XP (KB896424) 1 (KB896424) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=896424 Mise à jour de sécurité pour Windows XP (KB896428) 1 (KB896428) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=896428 Mise à jour de sécurité pour Windows XP (KB896688) 1 (KB896688) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB896688$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=896688 Mise à jour pour Windows XP (KB896727) 1 (KB896727) install date: 20060103 uninstall cmd: "C:\WINDOWS\$NtUninstallKB896727$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=896727 Mise à jour pour Windows XP (KB898461) 1 (KB898461) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=898461 Mise à jour de sécurité pour Windows XP (KB899587) 1 (KB899587) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=899587 Mise à jour de sécurité pour Windows XP (KB899591) 1 (KB899591) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=899591 Mise à jour de sécurité pour Windows XP (KB900725) 1 (KB900725) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=900725 Mise à jour de sécurité pour Windows XP (KB901017) 1 (KB901017) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=901017 Mise à jour de sécurité pour Windows XP (KB901214) 1 (KB901214) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=901214 Mise à jour de sécurité pour Windows XP (KB902400) 1 (KB902400) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=902400 Mise à jour de sécurité pour Windows XP (KB904706) 1 (KB904706) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=904706 Mise à jour de sécurité pour Windows XP (KB905414) 1 (KB905414) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=905414 Mise à jour de sécurité pour Windows XP (KB905749) 1 (KB905749) install date: 20051213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=905749 Mise à jour de sécurité pour Windows XP (KB905915) 1 (KB905915) install date: 20051214 uninstall cmd: "C:\WINDOWS\$NtUninstallKB905915$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=905915 Mise à jour de sécurité pour Windows XP (KB908519) 1 (KB908519) install date: 20060114 uninstall cmd: "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=908519 Mise à jour pour Windows XP (KB910437) 1 (KB910437) install date: 20051214 uninstall cmd: "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=910437 Mise à jour de sécurité pour Windows XP (KB912919) 1 (KB912919) install date: 20060106 uninstall cmd: "C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=912919 Language pack for Ad-Aware SE (Language pack for Ad-Aware SE) uninstall cmd: C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\Langs\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\Langs\INSTALL.LOG publisher: Lavasoft help link: http://www.lavasoft.de Microsoft .NET Framework 1.1 Hotfix (KB886903) (M886903) uninstall cmd: "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M886903\M886903Uninstall.msp" Macromedia Shockwave Player 10.1.0.11 (Macromedia Shockwave Player) uninstall cmd: C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log publisher: Macromedia, Inc. help link: http://www.macromedia.com/fr/support/shockwave Madskin (Madskin) uninstall cmd: C:\Program Files\MSN Messenger\uninstallMadskin.exe publisher: Mad Skinning help link: http://www.mad-skinning.net Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033)) uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm (MobileOptionPack) Mozilla Firefox (1.5) 1.5 (fr) (Mozilla Firefox (1.5)) install location: C:\Program Files\Mozilla Firefox uninstall cmd: C:\WINDOWS\UninstallFirefox.exe /ua "1.5 (fr)" publisher: Mozilla (MPlayer2) Messenger Plus! 3 (MsgPlus! Plugin) uninstall cmd: "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove (MSI30-Beta1) (MSI30-Beta2) (MSI30-KB884016) (MSI30-RC1) (MSI30-RC2) (MSI30a-KB884016) (MSI31-Beta) (MSI31-RC1) Colour Options 1.3 (beta) for The Sims 2 1.3 (beta) (MTS2_ColourOptions_is1) uninstall cmd: C:\WINDOWS\unins000.exe (NetMeeting) NVIDIA Drivers (NVIDIA Drivers) uninstall cmd: C:\WINDOWS\system32\NVUNINST.EXE UninstallGUI (OutlookExpress) (PCHealth) uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Programme de gestion Camera de Logitech® (QcDrv) install location: C:\Program Files\Fichiers communs\Logitech\QCDRV install source: E:\Drivers\Bin\ uninstall cmd: "C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT (RealJukebox 1.0) uninstall cmd: C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 RealPlayer (RealPlayer 6.0) uninstall cmd: C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 (SchedulingAgent) (Shockwave) Macromedia Flash Player 8 8 (ShockwaveFlash) uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5 publisher: Macromedia help link: http://www.macromedia.com/go/flashplayer_support/ SLD Codec Pack (SLD Codec Pack) uninstall cmd: C:\Program Files\SLD Codec Pack\uninstall.exe Spybot - Search & Destroy 1.4 1.4 (Spybot - Search & Destroy_is1) install location: C:\Program Files\Spybot - Search & Destroy\ uninstall cmd: "C:\Program Files\Spybot - Search & Destroy\unins000.exe" publisher: Safer Networking Limited VideoLAN VLC media player 0.8.4a 0.8.4a (VLC media player) uninstall cmd: C:\Program Files\VideoLAN\VLC\uninstall.exe publisher: VideoLAN Team Windows Media Format Runtime (Windows Media Format Runtime) uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Lecteur Windows Media 10 (Windows Media Player) uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall ZoneAlarm 6.1.737.000 (ZoneAlarm) uninstall cmd: C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe publisher: Zone Labs, Inc help link: C:\Program Files\Zone Labs\ZoneAlarm\Aide\zaclients.chm NTI CD & DVD-Maker 7 ({1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}) version: 117440512 version (major): 7 estimated size: 188829 install date: 20050623 install location: C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ install source: C:\ACERNB\INSTALL\CDM703905R1\ publisher: NewTech Infosystems comments: Vos remarques contact: Service support clientèle help link: http://www.votresociété.com/aide help telephone: +1-555-555-4505 Livebox ({17342E3B-0818-4A6F-BFF8-99476605ADD6}) uninstall cmd: RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe" -l0x40c EPSON Attach To Email 1.01.0000 ({20C45B32-5AB6-46A4-94EF-58950CAF05E5}) version: 16842752 version (major): 1 version (minor): 1 estimated size: 1108 install date: 20051213 install location: C:\Program Files\EPSON\Creativity Suite\Attach To Email\ install source: E:\COMMON\CreativitySuite\AttachToEmail\ publisher: SEIKO EPSON comments: Attach To Email - Email support app help link: http://www.epson.com/ EPSON Scan Assistant 1.02.00 ({2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) version: 16908288 install location: C:\Program Files\EPSON\Creativity Suite\Scan Assistant uninstall cmd: RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u EPSON Image Clip Palette 1.02.00 ({314F6D08-A8B7-11D8-8446-0050BA1D384D}) version: 16908288 install location: C:\Program Files\EPSON\Creativity Suite\Image Clip Palette uninstall cmd: RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u J2SE Runtime Environment 5.0 Update 2 1.5.0.20 ({3248F0A8-6813-11D6-A77B-00B0D0150020}) version: 17104896 version (major): 1 version (minor): 5 estimated size: 147041 install date: 20051023 install source: C:\Documents and Settings\Propriétaire\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}\ uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020} publisher: Sun Microsystems, Inc. contact: http://java.com help link: http://java.com readme: C:\Program Files\Java\jre1.5.0_02\README.txt J2SE Runtime Environment 5.0 Update 6 1.5.0.60 ({3248F0A8-6813-11D6-A77B-00B0D0150060}) version: 17104896 version (major): 1 version (minor): 5 estimated size: 148501 install date: 20051215 install source: http://jdl.sun.com/webapps/download/GetFil.../windows-i586// uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060} publisher: Sun Microsystems, Inc. contact: http://java.com help link: http://java.com readme: C:\Program Files\Java\jre1.5.0_06\README.txt WebFldrs XP 9.50.7523 ({350C940c-3D7C-4EE8-BAA9-00BCB3D54227}) version: 154279267 version (major): 9 version (minor): 50 estimated size: 2656 install date: 20051023 install source: C:\WINDOWS\system32\ publisher: Microsoft Corporation help link: http://www.microsoft.com/windows NTI Backup NOW! 4 4 ({385979FE-DC4F-4140-8EAD-A59625000D72}) version: 67108864 version (major): 4 estimated size: 129594 install date: 20050623 install location: C:\Program Files\NewTech Infosystems\NTI Backup NOW! 4\ install source: C:\ACERNB\INSTALL\CDM703905R1\BUN\ publisher: NewTech Infosystems comments: Your Comments contact: Technical Support help link: www.ntius.com help telephone: 1-949-421-0712 readme: Readme.txt EPSON Easy Photo Print 1.1.0.0 ({5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}) version: 16842752 install location: C:\Program Files\EPSON\Creativity Suite\Easy Photo Print uninstall cmd: RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST Windows Genuine Advantage v1.3.0254.0 1.3.0254.0 ({63569CE9-FA00-469C-AF5C-E5D4D93ACF91}) version: 16974078 version (major): 1 version (minor): 3 estimated size: 519 install date: 20051214 install source: C:\DOCUME~1\NAT&SA~1\LOCALS~1\Temp\IXP000.TMP\ uninstall cmd: MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91} publisher: Microsoft comments: Your Comments contact: Customer Support Department help link: http://www.microsoft.com/genuine/downloads...idate.aspx/help help telephone: 1-425.882.8080 Acer eMode Management 2.0.17.0 ({65CDEC30-4BF4-48FB-8059-9FC480E4E94F}) version: 33554449 install location: C:\Program Files\Acer\Acer eMode Management uninstall cmd: RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{65CDEC30-4BF4-48FB-8059-9FC480E4E94F}\setup.exe" -l0x40c EPSON Copy Utility 3 3.1.5.0 ({67EDD823-135A-4D59-87BD-950616D6E857}) version: 50397189 install location: C:\Program Files\EPSON\Creativity Suite uninstall cmd: RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall PowerDVD ({6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) uninstall cmd: RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall Les Sims 2 ({6E7DD182-9FC6-4651-0095-2E666CC6AF35}) uninstall cmd: C:\Program Files\EA GAMES\Les Sims 2\EAUninstall.exe Music Transfer pavit Edition 1.0.1 ({786DC36B-AB55-4C3A-9FBA-73D14263BE40}) version: 16777217 version (major): 1 estimated size: 8636 install date: 20051213 install location: C:\Program Files\AIWA\Music Transfer pavit Edition\ install source: E:\Setup\ publisher: Sony Corporation help link: http://www.aiwa.com/ EPSON Web-To-Page ({7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}) install location: C:\Program Files\EPSON\EPSON Web-To-Page uninstall cmd: RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything Microsoft Office XP Professional avec FrontPage 10.0.4330.0 ({9028040C-6000-11D3-8CFE-0050048383C9}) version: 167776490 version (major): 10 estimated size: 150281 install date: 20051219 install location: INSTALLLOCATION install source: E:\ uninstall cmd: MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9} publisher: Microsoft Corporation help link: http://www.microsoft.com/support readme: C:\Program Files\Microsoft Office\Office10\1036\OFREAD10.HTM Microsoft .NET Framework 1.1 French Language Pack 1.1.4322 ({9A394342-4A68-4EBA-85A6-55B559F4E700}) version: 16847074 version (major): 1 version (minor): 1 estimated size: 3238 install date: 20050623 install source: C:\DOCUME~1\PROPRI~1\LOCALS~1\ -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
jai fais tout ce que tu mas dis et spybot me le détecte toujours -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
jai beau regarder je ne trouves pas ceci : lbecovx.exe -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
"Silent Runners.vbs", revision 43, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS] "WOOKIT" = "C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=" [empty string] "MessengerPlus3" = ""C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart" ["Patchou"] "msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "LaunchApp" = "Alaunch" ["Acer Inc."] "NVMixerTray" = ""C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"" ["NVIDIA Corporation"] "eRecoveryService" = "C:\Program Files\Acer\eRecovery\Monitor.exe" ["acer Inc."] "ntiMUI" = "C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [null data] "(Default)" = (empty string) "RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."] "IMJPMIG8.1" = ""C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" [MS] "MSPY2002" = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC" [null data] "PHIME2002ASync" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" [MS] "PHIME2002A" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName" [MS] "AspireService" = "C:\Program Files\Acer\Acer eMode Management\AspireService.exe" ["Acer Inc."] "MediaSync" = "C:\Program Files\Acer\Acer eConsole\MediaSync.exe" ["Acer Inc."] "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" ["Sun Microsystems, Inc."] "WOOWATCH" = "C:\PROGRA~1\Wanadoo\Watch.exe" ["France Télécom R&D"] "WOOTASKBARICON" = "C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe" ["France Télécom R&D"] "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data] "LVCOMSX" = "C:\WINDOWS\system32\LVCOMSX.EXE" ["Logitech Inc."] "MessengerPlus3" = ""C:\Program Files\MessengerPlus! 3\MsgPlus.exe"" ["Patchou"] "EPSON Stylus DX3800 Series" = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"" ["SEIKO EPSON CORPORATION"] "TkBellExe" = ""C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."] "Zone Labs Client" = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" ["Zone Labs, LLC"] "lbecovx" = "c:\windows\system32\lbecovx.exe lbecovx" [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"] {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided) -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = "SSVHelper Class" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."] {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}\(Default) = "EpsonToolBandKicker Class" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll" ["SEIKO EPSON CORPORATION"] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration" -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found] "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."] "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] "{FEB7DAE0-E111-11D0-BFD7-444553540000}" = "ICEOWS" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"] "{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS] "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."] "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS] "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS] "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."] HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] ICEOWS\(Default) = "{FEB7DAE0-E111-11D0-BFD7-444553540000}" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ ICEOWS\(Default) = "{FEB7DAE0-E111-11D0-BFD7-444553540000}" -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] Active Desktop and Wallpaper: ----------------------------- Active Desktop is disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Documents and Settings\Nat & Sab\Local Settings\Application Data\Microsoft\Wallpaper1.bmp" Startup items in "Nat & Sab" & "All Users" startup folders: ----------------------------------------------------------- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage "Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"] "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS] Enabled Scheduled Tasks: ------------------------ "XoftSpy" -> launches: "C:\Program Files\XoftSpy\XoftSpy.exe -t" [file not found] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ "{EE5D279F-081B-4404-994D-C6B60AAEBA6D}" = "EPSON Web-To-Page" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll" ["SEIKO EPSON CORPORATION"] HKLM\Software\Microsoft\Internet Explorer\Toolbar\ "{EE5D279F-081B-4404-994D-C6B60AAEBA6D}" = "EPSON Web-To-Page" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll" ["SEIKO EPSON CORPORATION"] Extensions (Tools menu items, main toolbar menu buttons) HKCU\Software\Microsoft\Internet Explorer\Extensions\ {1462651F-F4BA-4C76-A001-C4284D0FE16E}\ "ButtonText" = "Wanadoo" "Exec" = "http://www.wanadoo.fr" [file not found] HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ "MenuText" = "Console Java (Sun)" "CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}" -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."] {FB5F1910-F110-11D2-BB9E-00C04F795683}\ "ButtonText" = "Messager Wanadoo" "MenuText" = "Messager Wanadoo" "Exec" = "C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe" [file not found] Miscellaneous IE Hijack Points ------------------------------ C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings") Added lines (compared with English-language version): [strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/" Missing lines (compared with English-language version): [strings]: 1 line HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\ "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = "Search Class" [from CLSID] -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\SEARCH~1.DLL" [empty string] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."] avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data] avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data] avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"] avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"] France Telecom Routing Table Service, FTRTSVC, "C:\WINDOWS\System32\FTRTSVC.exe" ["France Telecom"] TrueVector Internet Monitor, vsmon, "C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service" ["Zone Labs, LLC"] Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ EPSON Stylus DX3800 Series 2KMonitor5E\Driver = "E_FLMACE.DLL" ["SEIKO EPSON CORPORATION"] Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS] ---------- + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points and all Registry CLSIDs for dormant Explorer Bars, use the -supp parameter or answer "No" at the first message box. ---------- (total run time: 18 seconds, including 6 seconds for message boxes) silent runners fonctionne bien mais pour SA il est tellement long que ca ne marche pas meme en voulant le couper en plusieurs parties au faite merci pour ton aide -
probleme avec magicControl.agent
binacalista a répondu à un(e) sujet de binacalista dans Analyses et éradication malwares
REGEDIT4 ; Registry Search by Bobbi Flekman © 2005 ; Version: 1.0.2.4 ; Results at 17/01/2006 23:36:01 for strings: ; 'lanconfig ' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS ; End Of The Log... REGEDIT4 ; Registry Search by Bobbi Flekman © 2005 ; Version: 1.0.2.4 ; Results at 17/01/2006 23:38:50 for strings: ; 'mslagent' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS ; End Of The Log... REGEDIT4 ; Registry Search by Bobbi Flekman © 2005 ; Version: 1.0.2.4 ; Results at 17/01/2006 23:42:20 for strings: ; 'sa' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\7] "Identifier"="ISA" [HKEY_LOCAL_MACHINE\SAM] [HKEY_LOCAL_MACHINE\SOFTWARE\acer\AspireEMode] "DisableLaunchKey"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\acer\MediaServerService] "AlwaysAllow"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\acer\MediaServerService] "DefaultAccessAllow"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\C07ft5Y] @="SafeDisc RefCount" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ADE] "ZAMailSafeExt"="zl0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ADP] "ZAMailSafeExt"="zl1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asa] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asx] "ZAMailSafeExt"="zlz" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.BAS] "ZAMailSafeExt"="zl2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat] "ZAMailSafeExt"="zl3" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.chm] "ZAMailSafeExt"="zl4" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd] "ZAMailSafeExt"="zl5" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.com] "ZAMailSafeExt"="zl6" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cpl] "ZAMailSafeExt"="zl7" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.crt] "ZAMailSafeExt"="zl8" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.DBX] "ZAMailSafeExt"="zm0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.disabled] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.disabled] @="SpybotSD.DisabledFile" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dll] "ZAMailSafeExt"="zmb" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.eml] @="Microsoft Internet Mail Message" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.eml] "Content Type"="message/rfc822" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.eml] "ZAMailSafeExt"="zmc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe] "ZAMailSafeExt"="zl9" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hlp] "ZAMailSafeExt"="zla" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hta] "ZAMailSafeExt"="zlb" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf] "ZAMailSafeExt"="zlc" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ins] "ZAMailSafeExt"="zld" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.isp] "ZAMailSafeExt"="zle" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.js] "ZAMailSafeExt"="z0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.JSE] "ZAMailSafeExt"="zlf" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lnk] "ZAMailSafeExt"="zlg" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.MDA] "ZAMailSafeExt"="zm1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mdb] "ZAMailSafeExt"="zlh" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.MDE] "ZAMailSafeExt"="zli" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.MDZ] "ZAMailSafeExt"="zm2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mht] "Content Type"="message/rfc822" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mht] "ZAMailSafeExt"="zm8" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mhtml] "Content Type"="message/rfc822" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msc] "ZAMailSafeExt"="zlj" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msi] "ZAMailSafeExt"="zlk" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msp] "ZAMailSafeExt"="zll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.MST] "ZAMailSafeExt"="zlm" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.NCH] "ZAMailSafeExt"="zm3" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.nws] @="Microsoft Internet News Message" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.nws] "Content Type"="message/rfc822" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ocx] "ZAMailSafeExt"="zmd" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.PCD] "ZAMailSafeExt"="zln" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pif] "ZAMailSafeExt"="zlo" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.prf] "ZAMailSafeExt"="zm4" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.qds] @="SavedDsQuery" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar] "ZAMailSafeExt"="zma" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg] "ZAMailSafeExt"="zlp" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sam] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sam\AmiProDocument] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sam\AmiProDocument\ShellNew] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sam\AmiProDocument\ShellNew] "FileName"="amipro.sam" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.scf] "ZAMailSafeExt"="zm5" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.scr] "ZAMailSafeExt"="zlq" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sct] "ZAMailSafeExt"="zlr" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.shb] "ZAMailSafeExt"="zm6" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.shs] "ZAMailSafeExt"="zls" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sys] "ZAMailSafeExt"="zme" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.url] "ZAMailSafeExt"="zlt" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.VB] "ZAMailSafeExt"="z1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.VBE] "ZAMailSafeExt"="zlu" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.vbs] "ZAMailSafeExt"="zlv" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wms] "ZAMailSafeExt"="zm7" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wsc] "ZAMailSafeExt"="zlw" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.WSF] "ZAMailSafeExt"="zlx" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.WSH] "ZAMailSafeExt"="zly" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.z0] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.z1] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip] "ZAMailSafeExt"="zm9" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl0] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl1] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl2] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl3] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl4] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl5] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl6] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl7] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl8] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl9] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zla] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlb] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlc] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zld] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zle] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlf] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlg] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlh] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zli] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlj] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlk] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zll] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlm] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zln] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlo] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlp] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlq] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlr] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zls] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlt] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlu] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlv] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlw] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlx] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zly] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlz] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm0] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm1] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm2] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm3] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm4] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm5] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm6] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm7] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm8] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm9] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zma] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zmb] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zmc] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zmd] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zme] @="ZAMailSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Character.2\DefaultIcon] @="C:\\WINDOWS\\msagent\\agentdpv.dll,-201" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Character2.2\DefaultIcon] @="C:\\WINDOWS\\msagent\\agentdp2.dll,-201" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Preview.2\DefaultIcon] @="C:\\WINDOWS\\msagent\\agentdp2.dll,-201" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIFFFile\shell\open] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIFFFile\shell\play] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\OSA.EXE] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASFFile\shell\open] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASFFile\shell\play] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASXFile\shell\open] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASXFile\shell\play] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AUFile\shell\open] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AUFile\shell\play] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoDiscovery.EmailAssociations] @="Associations de messagerie" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoDiscovery.EmailAssociations.1] @="Associations de messagerie" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoDiscovery.Mail] @="Découverte automatique de messagerie Windows" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoDiscovery.Mail.1] @="Découverte automatique de messagerie Windows" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AVIFile\shell\open] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AVIFile\shell\play] "LegacyDisable"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ATSCComponentType] @="Classe type de composant ATSC de modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ATSCComponentType.1] @="Classe type de composant ATSC de modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Component] @="Classe composant modèle de réglage BDA (sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Component.1] @="Classe composant modèle de réglage BDA (sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ComponentType] @="Classe de type composant modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ComponentType.1] @="Classe de type composant modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ComponentTypes] @="Collection des types composant de modèle de réglage BDA (types sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ComponentTypes.1] @="Collection des types composant de modèle de réglage BDA (types sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants] @="Regroupement des composants de modèle de réglage BDA (sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants\CurVer] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants\CurVer] @="BDATuner.Composants.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants.1] @="Regroupement des composants de modèle de réglage BDA (sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants.1\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.DVBSLocator] @="Recherche de satellite DVB de modèle de réglage BDA" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.DVBSLocator.1] @="Recherche de satellite DVB de modèle de réglage BDA" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.DVBSTuningSpace] @="Espace de réglage DVB-Satellite du modèle de réglage BDA" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.DVBSTuningSpace.1] @="Espace de réglage DVB-Satellite du modèle de réglage BDA" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.LanguageComponentType] @="Classe type de composant langue du modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.LanguageComponentType.1] @="Classe type de composant langue du modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.MPEG2Component] @="Classe composant MPEG2 de modèle de réglage BDA (sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.MPEG2Component.1] @="Classe composant MPEG2 de modèle de réglage BDA (sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.MPEG2ComponentType] @="Classe type de composant MPEG2 de modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.MPEG2ComponentType.1] @="Classe type de composant MPEG2 de modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CatSrv.RegDBCompensator] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CatSrv.RegDBCompensator] @="RegDBCompensator Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CatSrv.RegDBCompensator\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Catsrv.RegDBCompensator.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Catsrv.RegDBCompensator.1] @="RegDBCompensator Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Catsrv.RegDBCompensator.1\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage] @="CdoCalendarMessage Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage\CurVer] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage\CurVer] @="CDO.CalendarMessage.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage.1] @="CdoCalendarMessage Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage.1\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message] @="CDOMessage Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message\CurVer] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message\CurVer] @="CDO.Message.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message.1] @="CDOMessage Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message.1\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.CertMgrSaferWindowsExtensionObject.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.CertMgrSaferWindowsExtensionObject.1] @="Objet SAFER Windows 1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.CertMgrSaferWindowsExtensionObject.1\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.SaferWindowsAboutObject.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.SaferWindowsAboutObject.1] @="Objet SAFER Windows 1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.SaferWindowsAboutObject.1\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000061B-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000061E-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000621-0000-0010-8000-00AA006D2EA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C101D-0000-0000-C000-000000000046}] @="Microsoft Windows Installer Message RPC" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C101D-0000-0000-C000-000000000046}\ProgId] @="WindowsInstaller.Message" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{008FD5DD-6DBB-48e3-991B-2D3ED658516A}] @="Découverte automatique de messagerie Windows" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}] @="Saisie semi-automatique Microsoft" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00BB2764-6A77-11D0-A535-00C04FD7D062}] @="Liste de saisie semi-automatique de l'historique Microsoft" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}] @="Conteneur de la liste de saisie semi-automatique multiple Microsoft" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}] @="Liste de saisie semi-automatique du dossier Shell Microsoft" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04F34B7F-0241-455A-9DCD-25471E111409}] @="SAFRemoteDesktopManager Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04F34B7F-0241-455A-9DCD-25471E111409}\InprocServer32] @="C:\\WINDOWS\\system32\\safrdm.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04F34B7F-0241-455A-9DCD-25471E111409}\ProgID] @="ISAFrdm.SAFRemoteDesktopManager.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04F34B7F-0241-455A-9DCD-25471E111409}\VersionIndependentProgID] @="ISAFrdm.SAFRemoteDesktopManager" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{055CB2D7-2969-45CD-914B-76890722F112}] @="Classe composant MPEG2 de modèle de réglage BDA (sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0655E396-25D0-11D3-9C26-00C04F8EF87C}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0655E396-25D0-11D3-9C26-00C04F8EF87C}\ProgID] @="SAPI.SpLexicon.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0655E396-25D0-11D3-9C26-00C04F8EF87C}\VersionIndependentProgID] @="SAPI.SpLexicon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{079AA557-4A18-424A-8EEE-E39F0A8D41B9}] @="SAX XML Reader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{079AA557-4A18-424A-8EEE-E39F0A8D41B9}\ProgID] @="Msxml2.SAXXMLReader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{079AA557-4A18-424A-8EEE-E39F0A8D41B9}\VersionIndependentProgID] @="Msxml2.SAXXMLReader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{33FACFE0-A9BE-11D0-A520-00A0D10129C0}] "FriendlyName"="SAMI (CC) Parser" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{7F1232EE-44D7-4494-AB8B-CC61B10E21A5}] "FriendlyName"="WMT Sample Information Filter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{C1F400A0-3F08-11D3-9F0B-006008039E37}] "FriendlyName"="SampleGrabber" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08CD963F-7A3E-4F5C-9BD8-D692BB043C5B}] @="TF_MSAAControl" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0944D16C-D0F4-4389-982A-A085595A9EB3}\verb\2] @="&Save Skin,0,2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DAD5531-BF31-43AC-A513-1F8926BBF5EC}] @="SafeWia Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DAD5531-BF31-43AC-A513-1F8926BBF5EC}\ProgID] @="SafeWia.Script.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DAD5531-BF31-43AC-A513-1F8926BBF5EC}\VersionIndependentProgID] @="SafeWia.Script" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}] @="Microsoft.JScript.JSAuthor" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}\InprocServer32] "Class"="Microsoft.JScript.JSAuthor" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}\InprocServer32\7.0.5000.0] "Class"="Microsoft.JScript.JSAuthor" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}\ProgId] @="Microsoft.JScript.JSAuthor" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F92030A-CBFD-4AB8-A164-FF5985547FF6}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\SAPI.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F92030A-CBFD-4AB8-A164-FF5985547FF6}\ProgID] @="SAPI.SpTextSelectionInformation.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F92030A-CBFD-4AB8-A164-FF5985547FF6}\VersionIndependentProgID] @="SAPI.SpTextSelectionInformation" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FA9F4D5-A173-11D1-AA62-00C04FA34D72}\InprocServer32] @="C:\\WINDOWS\\msagent\\agentsr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FF15AA1-2F93-11d1-83B0-00C04FBD7C09}] @="CLSID_CCommNewsAcctImport" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{101A8FB9-F1B9-11d1-9A56-00C04FA309D4}] @="CLSID_MessageStore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12D73610-A1C9-11D3-BC90-00C04F72DF9F}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12D73610-A1C9-11D3-BC90-00C04F72DF9F}\ProgID] @="SAPI.SpITNProcessor.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12D73610-A1C9-11D3-BC90-00C04F72DF9F}\VersionIndependentProgID] @="SAPI.SpITNProcessor" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13709620-C279-11CE-A49E-444553540000}] @="Service d'automatisation de l'interface" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{143A62C8-C33B-11D1-84FE-00C04FA34A14}\InprocServer32] @="C:\\WINDOWS\\msagent\\agentpsh.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1443904B-34E4-40F6-B30F-6BEB81267B80}] @="Cicero SAPI Layer Speech UI Server" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{152A1E9D-352F-4F25-87F6-0A18312D9F45}\ProgID] @="MS.WinCE.WorksAB" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17869501-36C8-11d1-83B7-00C04FBD7C09}] @="CLSID_CNExpressAcctImport" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{193B4137-0480-11D1-97DA-00C04FB9618A}] @="Microsoft DTC Transaction Unmarshaller (private, internal)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2AFB92-0B5E-4A30-B5CC-353DB4F9E150}] @="SpSapiServer Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2AFB92-0B5E-4A30-B5CC-353DB4F9E150}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2E3B3F-490A-4f4c-8C76-D94F59FE6400}] @="Microsoft.Vsa.Vb.CodeDOM.Location" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2E3B3F-490A-4f4c-8C76-D94F59FE6400}\InprocServer32] "Class"="Microsoft.Vsa.Vb.CodeDOM.Location" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2E3B3F-490A-4f4c-8C76-D94F59FE6400}\InprocServer32] "Assembly"="Microsoft.Vsa.Vb.CodeDOMProcessor, Version=7.0.5000.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2E3B3F-490A-4f4c-8C76-D94F59FE6400}\ProgId] @="Microsoft.Vsa.Vb.CodeDOM.Location" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BE49F30-0E1B-11D3-9D8E-00C04F72D980}] @="Classe type de composant langue du modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1DF7D126-4050-47F0-A7CF-4C4CA9241333}] @="Recherche de satellite DVB de modèle de réglage BDA" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}] @="System.Security.Cryptography.DSASignatureDeformatter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}\InprocServer32] "Class"="System.Security.Cryptography.DSASignatureDeformatter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}\InprocServer32\1.0.5000.0] "Class"="System.Security.Cryptography.DSASignatureDeformatter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}\ProgId] @="System.Security.Cryptography.DSASignatureDeformatter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F823A6A-863F-11D1-A484-00C04FB93753}] @="Composant logiciel enfichable d'extension des modèles de certificats d'Autorité de certification" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F823A6A-863F-11D1-A484-00C04FB93753}\ProgID] @="Snapin.PolicySettingsAbout.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F823A6A-863F-11D1-A484-00C04FB93753}\VersionIndependentProgID] @="Snapin.PolicySettingsAbout" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{228136B0-8BD3-11D0-B4EF-00A0C9138CA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadomd.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{228136B8-8BD3-11D0-B4EF-00A0C9138CA4}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\ado\\msadomd.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22E24591-49D0-11D2-BB50-006008320064}\InprocServer32] @="C:\\WINDOWS\\system32\\msadds32.ax" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{233A9692-667E-11d1-9DFB-006097D50408}] @="Outlook Express Message List" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{233A9692-667E-11d1-9DFB-006097D50408}\ProgID] @="OutlookExpress.MessageList.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{233A9692-667E-11d1-9DFB-006097D50408}\VersionIndependentProgID] @="OutlookExpress.MessageList" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24800CD0-0F4E-4df7-9F69-3C6903C89224}\ProgID] @="VsaVbRT.7.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24800CD0-0F4E-4df7-9F69-3C6903C89224}\Server] @="VsaVb7rt.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24800CD0-0F4E-4df7-9F69-3C6903C89224}\VersionIndependentProgID] @="VsaVbRT" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{248FCFB3-5914-AF2C-CCBA-9BB5E3C749D5}] @="TF_MSAAControl" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24EEC005-3938-3C71-821D-7F68FD850B2D}] @="System.Runtime.Remoting.Messaging.RemotingSurrogateSelector" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24EEC005-3938-3C71-821D-7F68FD850B2D}\InprocServer32] "Class"="System.Runtime.Remoting.Messaging.RemotingSurrogateSelector" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24EEC005-3938-3C71-821D-7F68FD850B2D}\InprocServer32\1.0.5000.0] "Class"="System.Runtime.Remoting.Messaging.RemotingSurrogateSelector" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24EEC005-3938-3C71-821D-7F68FD850B2D}\ProgId] @="System.Runtime.Remoting.Messaging.RemotingSurrogateSelector" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25642426-028D-4474-977B-111BB114FE3E}\InProcServer32] @="C:\\WINDOWS\\system32\\msaatext.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27016870-8E02-11D1-924E-00C04FBBBFB3}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\msadc\\msdarem.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{280A7B65-8F00-438F-989B-8EAF9E438A71}] @="Objet SAFER Windows 1.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{280A7B65-8F00-438F-989B-8EAF9E438A71}\ProgID] @="CERTMGR.SaferWindowsAboutObject.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{280A7B65-8F00-438F-989B-8EAF9E438A71}\VersionIndependentProgID] @="CERTMGR.SaferWindowsAboutObject.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2AFA62E2-5548-11D1-A6E1-006097C4E476}] @="ppDSApp Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D12DD17-6C4E-456E-A953-D210E3C64176}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}] @="DHTML Edit Control Safe for Scripting for IE5" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\ProgID] @="DHTMLSafe.DHTMLSafe.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\VersionIndependentProgID] @="DHTMLSafe.DHTMLSafe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}] @="System.Runtime.InteropServices.SafeArrayTypeMismatchException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}\InprocServer32] "Class"="System.Runtime.InteropServices.SafeArrayTypeMismatchException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}\InprocServer32\1.0.5000.0] "Class"="System.Runtime.InteropServices.SafeArrayTypeMismatchException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}\ProgId] @="System.Runtime.InteropServices.SafeArrayTypeMismatchException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f819-98b5-11cf-bb82-00aa00bdce0b}] @="HtmlDlgSafeHelper Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f819-98b5-11cf-bb82-00aa00bdce0b}\ProgID] @="HtmlDlgSafeHelper.HtmlDlgSafeHelper.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f819-98b5-11cf-bb82-00aa00bdce0b}\VersionIndependentProgID] @="HtmlDlgSafeHelper.HtmlDlgSafeHelper" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3124C396-FB13-4836-A6AD-1317F1713688}] @="SAX XML Reader 3.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3124C396-FB13-4836-A6AD-1317F1713688}\ProgID] @="Msxml2.SAXXMLReader.3.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3124C396-FB13-4836-A6AD-1317F1713688}\VersionIndependentProgID] @="Msxml2.SAXXMLReader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33102459-4B30-11d2-A6DC-00C04F79E7C8}] @="CLSID_CNavNewsAcctImport" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33FACFE0-A9BE-11D0-A520-00A0D10129C0}] @="SAMI (CC) Reader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3449A1C8-C56C-11D0-AD72-00C04FC29863}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\msadc\\msadds.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{364D8E0B-67CB-4547-9948-9E7F1B1743ED}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737A-DD75-11D2-966A-00C04F79487A}\ProgID] @="PKMSA.AddStartAddress.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737A-DD75-11D2-966A-00C04F79487A}\VersionIndependentProgID] @="PKMSA.AddStartAddress" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737B-DD75-11D2-966A-00C04F79487A}\ProgID] @="PKMSA.StartAddressCommands.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737B-DD75-11D2-966A-00C04F79487A}\VersionIndependentProgID] @="PKMSA.StartAddressCommands" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737C-DD75-11D2-966A-00C04F79487A}\ProgID] @="PKMSA.CatalogCommands.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737C-DD75-11D2-966A-00C04F79487A}\VersionIndependentProgID] @="PKMSA.CatalogCommands" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3918D75F-0ACB-41F2-B733-92AA15BCECF6}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3918D75F-0ACB-41F2-B733-92AA15BCECF6}\ProgID] @="SAPI.SpObjectTokenEnum.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3918D75F-0ACB-41F2-B733-92AA15BCECF6}\VersionIndependentProgID] @="SAPI.SpObjectTokenEnum" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F8D76B-0928-11D1-97DF-00C04FB9618A}] @="Microsoft DTC Transaction" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BC4F3A1-652A-11D1-B4D4-00C04FC2DB8D}\ProgID] @="Microsoft.ISAdm.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BC4F3A1-652A-11D1-B4D4-00C04FC2DB8D}\VersionIndependentProgID] @="Microsoft.ISAdm" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BEE4890-4FE9-4A37-8C1E-5E7E12791C1F}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BEE4890-4FE9-4A37-8C1E-5E7E12791C1F}\ProgID] @="Sapi.SpSharedRecognizer.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BEE4890-4FE9-4A37-8C1E-5E7E12791C1F}\VersionIndependentProgID] @="Sapi.SpSharedRecognizer" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E784A01-F3AE-4DC0-9354-9526B9370EBA}] @="SAXAttributes 3.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E784A01-F3AE-4DC0-9354-9526B9370EBA}\ProgID] @="Msxml2.SAXAttributes.3.0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E784A01-F3AE-4DC0-9354-9526B9370EBA}\VersionIndependentProgID] @="Msxml2.SAXAttributes" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F276EB4-70EE-11D1-8A0F-00C04FB93753}] @="Composant logiciel enfichable d'extension des modèles de certificats d'Autorité de certification" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f454f0e-42ae-4d7c-8ea3-328250d6e272}] @="Automatisation du menu de contexte" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3FF292B6-B204-11CF-8D23-00AA005FFE58}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\msadc\\msadce.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{418008F3-CF67-4668-9628-10DC52BE1D08}] @="Classe type de composant MPEG2 de modèle de réglage BDA (type sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41B89B6B-9399-11D2-9623-00C04F8EE628}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41B89B6B-9399-11D2-9623-00C04F8EE628}\ProgID] @="Sapi.SpInprocRecognizer.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41B89B6B-9399-11D2-9623-00C04F8EE628}\VersionIndependentProgID] @="Sapi.SpInprocRecognizer" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{455F24E9-7396-4A16-9715-7C0FDBE3EFE3}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{455F24E9-7396-4A16-9715-7C0FDBE3EFE3}\ProgID] @="SAPI.SpNullPhoneConverter.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{455F24E9-7396-4A16-9715-7C0FDBE3EFE3}\VersionIndependentProgID] @="SAPI.SpNullPhoneConverter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47206204-5ECA-11D2-960F-00C04F8EE628}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47206204-5ECA-11D2-960F-00C04F8EE628}\ProgID] @="SAPI.SpSharedRecoContext.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47206204-5ECA-11D2-960F-00C04F8EE628}\VersionIndependentProgID] @="SAPI.SpSharedRecoContext" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BAC124B-78C8-11D1-B9A8-00C04FD97575}\InprocServer32] @="C:\\WINDOWS\\msagent\\agentmpx.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}] @="System.Runtime.InteropServices.SafeArrayRankMismatchException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}\InprocServer32] "Class"="System.Runtime.InteropServices.SafeArrayRankMismatchException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}\InprocServer32\1.0.5000.0] "Class"="System.Runtime.InteropServices.SafeArrayRankMismatchException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}\ProgId] @="System.Runtime.InteropServices.SafeArrayRankMismatchException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C6F940C-3CFE-11D2-9EE7-00C04F797396}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}] @="System.Security.Cryptography.RSAOAEPKeyExchangeDeformatter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}\InprocServer32] "Class"="System.Security.Cryptography.RSAOAEPKeyExchangeDeformatter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}\InprocServer32\1.0.5000.0] "Class"="System.Security.Cryptography.RSAOAEPKeyExchangeDeformatter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}\ProgId] @="System.Security.Cryptography.RSAOAEPKeyExchangeDeformatter" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DD441AD-526D-4A77-9F1B-9841ED802FB0}] @="SAXAttributes" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DD441AD-526D-4A77-9F1B-9841ED802FB0}\ProgID] @="Msxml2.SAXAttributes" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DD441AD-526D-4A77-9F1B-9841ED802FB0}\VersionIndependentProgID] @="Msxml2.SAXAttributes" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F878398-E58A-11D3-BEE9-00C04FA0D6BA}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}] @="Safe For Scripting" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F878398-E58A-11D3-BEE9-00C04FA0D6BA}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}] @="Safe For Initialization" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52656BD4-ED0A-11D2-B7F4-00C04F72DAF0}] @="WksABImport Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52656BD4-ED0A-11D2-B7F4-00C04F72DAF0}\InprocServer32] @="C:\\Program Files\\Microsoft Works\\WKSABIMP.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52656BD4-ED0A-11D2-B7F4-00C04F72DAF0}\ProgID] @="Wksabimp.WksABImport.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52656BD4-ED0A-11D2-B7F4-00C04F72DAF0}\VersionIndependentProgID] @="Wksabimp.WksABImport" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53BCE0BA-C112-11D2-BA1A-00C04F72DABA}] @="Wks5WizPageSample Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53BCE0BA-C112-11D2-BA1A-00C04F72DABA}\ProgID] @="Sample.Wks5WizPageSample.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53BCE0BA-C112-11D2-BA1A-00C04F72DABA}\VersionIndependentProgID] @="Sample.Wks5WizPageSample" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5440837F-4BFF-4AE5-A1B1-7722ECC6332A}\InprocServer32] @="C:\\WINDOWS\\system32\\msaatext.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5440837F-4BFF-4AE5-A1B1-7722ECC6332A}\ProgID] @="MSAAText.AccStore.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5440837F-4BFF-4AE5-A1B1-7722ECC6332A}\VersionIndependentProgID] @="MSAAText.AccStore" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}] @="System.Security.AllowPartiallyTrustedCallersAttribute" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}\InprocServer32] "Class"="System.Security.AllowPartiallyTrustedCallersAttribute" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}\InprocServer32\1.0.5000.0] "Class"="System.Security.AllowPartiallyTrustedCallersAttribute" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}\ProgId] @="System.Security.AllowPartiallyTrustedCallersAttribute" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58ECEE30-E715-11CF-B0E3-00AA003F000F}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\System\\msadc\\msadce.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59DC47A8-116C-11D3-9D8E-00C04F72D980}] @="Classe composant modèle de réglage BDA (sous-flux de diffusion)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5A7B63E0-F9BC-11D2-BBE5-00C04F86AE3B}] @="À propos du composant logiciel enfichable de Internet Explorer" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B18AB61-091D-11D1-97DF-00C04FB9618A}] @="Microsoft DTC Transaction Manager" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5cb66670-d3d4-11cf-acab-00a024a55aef}] @="Composant Contexte de transaction étendu COM+" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5cb66670-d3d4-11cf-acab-00a024a55aef}\ProgID] @="TxCTx.TransactionContextEx" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5cb66670-d3d4-11cf-acab-00a024a55aef}\VersionIndependentProgID] @="TxCTx.TransactionContextEx" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D6179C8-17EC-11D1-9AA9-00C04FD8FE93}] @="Composant logiciel enfichable Microsoft MMC Utilisateurs et groupes locaux" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D6179D2-17EC-11D1-9AA9-00C04FD8FE93}] @="À propos du fournisseur du Composant logiciel enfichable Microsoft MMC Utilisateurs et groupes locaux" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D9DD151-65F4-11CE-900D-00AA00445589}] @="Microsoft DTC Transaction Manager Proxy (private, internal)" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5DF2DE42-DC7A-5A02-BE2E-E47138107925}] @="Composant logiciel enfichable Microsoft MMC Utilisateurs et groupes locaux" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5EA6F67B-7713-45F3-B535-0E03DD637345}] @="SAFRemoteDesktopServerHost Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5EA6F67B-7713-45F3-B535-0E03DD637345}\ProgID] @="RDSHost.SAFRemoteDesktopServerHost.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5EA6F67B-7713-45F3-B535-0E03DD637345}\VersionIndependentProgID] @="RDSHost.SAFRemoteDesktopServerHost" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F889CE8-3B09-4CFF-B70A-83730CC00627}\InprocServer32] @="C:\\WINDOWS\\system32\\safrcdlg.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F889CE8-3B09-4CFF-B70A-83730CC00627}\ProgID] @="SAFRCFileDlg.FileOpen.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F889CE8-3B09-4CFF-B70A-83730CC00627}\VersionIndependentProgID] @="SAFRCFileDlg.FileOpen" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FB7EF7D-DFF4-468a-B6B7-2FCBD188F994}\InprocServer32] @="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\SAPI.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FB7EF7D-DFF4-468a-B6B7-2FCBD188F994}\ProgID] @="SAPI.SpMemoryStream.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FB7EF7D-DFF4-468a-B6B7-2FCBD188F994}\VersionIndependentProgID] @="SAPI.SpMemoryStream" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6089A37E-EB8A-482D-BD6F-F9F46904D16D}\InprocServer32] @="C:\\WINDOWS\\system32\\msaatext.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{622D47B6-CEEC-4DE1-8056-B6D16F29BC97}] @="Microsoft WBEM Rpc Message Sender" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6572EE16-5FE5-4331-BB6D-76A49C56E423}\InprocServer32] @="C:\\WINDOWS\\system32\\msaatext.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}] @="System.FlagsAttribute" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}\InprocServer32] "Class"="System.FlagsAttribute" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}\InprocServer32\1.0.5000.0] "Class"="System.FlagsAttribute" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}\ProgId] @="System.FlagsAttribute" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67331D85-BE17-42f6-8D3F-47B8E8B26637}] @="Objet d'automatisation OOBE de l'Assistant Migration" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673DFE75-9F93-304F-ABA8-D2A86BA87D7C}] @="System.Security.Cryptography.DSACryptoServiceProvider" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673DFE75-9F93-304F-ABA8-D2A86BA87D7C}\InprocServer32] "Class"="System.Security.Cryptography.DSACryptoServiceProvider" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes&