

Pascal62
Membres-
Compteur de contenus
35 -
Inscription
-
Dernière visite
Tout ce qui a été posté par Pascal62
-
Démarrage hyper lent – Analyse HijackThis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
toujours aussi longue au demarrage ! -
Démarrage hyper lent – Analyse HijackThis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
ca y ets c'est fait, rapport : Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Version de la base de données: v2012.06.03.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 giraudeau :: GIRAUDEAU-VAIO [administrateur] 03/06/2012 16:23:34 mbam-log-2012-06-03 (16-23-34).txt Type d'examen: Examen complet Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM Options d'examen désactivées: P2P Elément(s) analysé(s): 336162 Temps écoulé: 57 minute(s), 46 seconde(s) Processus mémoire détecté(s): 0 (Aucun élément nuisible détecté) Module(s) mémoire détecté(s): 0 (Aucun élément nuisible détecté) Clé(s) du Registre détectée(s): 0 (Aucun élément nuisible détecté) Valeur(s) du Registre détectée(s): 0 (Aucun élément nuisible détecté) Elément(s) de données du Registre détecté(s): 0 (Aucun élément nuisible détecté) Dossier(s) détecté(s): 0 (Aucun élément nuisible détecté) Fichier(s) détecté(s): 2 C:\Users\giraudeau\Downloads\AudioPerformerSetup.exe (PUP.BundleInstaller.IB) -> Mis en quarantaine et supprimé avec succès. C:\Users\giraudeau\Downloads\SoftonicDownloader_pour_hijackthis.exe (PUP.ToolbarDownloader) -> Mis en quarantaine et supprimé avec succès. (fin) -
Démarrage hyper lent – Analyse HijackThis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
premier rapport SFT : Lien CJoint.com BFdqmipcJ9l -
Démarrage hyper lent – Analyse HijackThis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Désolé pour les temps d'attente , mais ya du monde chez moi alors faut que je jongle. voici le rapport si je me suis pas encore planté : Rapport de ZHPFix 1.2.06 par Nicolas Coolman, Update du 17/05/2012 Fichier d'export Registre : Run by giraudeau at 03/06/2012 14:09:30 Windows 7 Business Edition, 64-bit Service Pack 1 (Build 7601) Web site : ZHPFix Fix de rapport Web site : Blog de NicolasCoolman - ZebHelpProcess - Skyrock.com ========== Valeur(s) du Registre ========== ABSENT AppInit: ta Manager.) - C:\Program Files (x86)\SEARCH~1\Datamngr\x64\datamngr.dll [MD5.03F853FCB8535930BDCBFE2A160AB669] [APT] [softwareUpdateTaskMachineCore] (.Boxore OU..) -- C:\Program Files (x86)\Software\Update\S- DTX broker.) -- C:\Program Files (x86)\Searchcore Toolbar\Datamngr\ToolBar\dtUser.exe O87 - FAEL: "{1C6F607D-9919-4C15-9AE3-6CFE61E7FCB6}" | In - Private - P6 - TRUE | .(.Visicom Media Inc. - DTX broker.) -- C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\ToolBar\dtUser.exe O87 - FAEL: "{5D120B93-35BB-4CD1-8713-6565E6C4254A}" | In - Private - P17 - TRUE | .(.Visicom Media Inc. - DTX broker.) -- C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\ToolBar\dtUser.exe [HKLM\Software\WOW6432Node\Classes\AppID\BearShare.exe] [HKLM\Software\WOW6432Node\Classes\CLSID\{31F8B21E-8674-4589-A37F-31A4D4B55CC5}] [HKLM\Software\WOW6432Node\Classes\AppID\{756C097C-6BDB-45de-A8F1-83E01AB86BA4}] [HKLM\Software\WOW6432Node\BearShare ========== Fichier(s) ========== ABSENT File: c:\program files (x86)\search~1\datamngr\x64\datamngr.dller.) -- c:\program files (x86)\searchcore toolbar\datamngr\toolbar\dtuser.exe o87 - fael: "{1c6f607d-9919-4c15-9ae3-6cfe61e7fcb6}" | in - private - p6 - true | .(.visicom media inc. - dtx broker.) -- c:\program files (x86)\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe o87 - fael: "{5d120b93-35bb-4cd1-8713-6565e6c4254a}" | in - private - p17 - true | .(.visicom media inc. - dtx broker.) -- c:\program files (x86)\bearshare applications\mediabar\datamngr\toolbar\dtuser.exe [hklm\software\wow6432node\classes\appid\bearshare.exe] [hklm\software\wow6432node\classes\clsid\{31f8b21e-8674-4589-a37f-31a4d4b55cc5}] [hklm\software\wow6432node\classes\appid\{756c097c-6bdb-45de-a8f1-83e01ab86ba4}] [hklm\software\wow6432node\bearshare ========== Autre ========== NON TRAITE MediabarTb] firewallrazemptytempemptyflash ========== Récapitulatif ========== 1 : Valeur(s) du Registre 1 : Fichier(s) 1 : Autre End of clean in 00mn 01s ========== Chemin de fichier rapport ========== C:\ZHP\ZHPFix[R1].txt - 03/06/2012 14:09:30 [2498] -
Démarrage hyper lent – Analyse HijackThis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Désolé pour l'erreur, je me suis bien planté. Bon je vais essayer d'assurer plus Voici le lien du rapport de ZHPDiag. -
Démarrage hyper lent – Analyse HijackThis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Entendu ! Voici le rapport AdwCleaner. -
Démarrage hyper lent – Analyse HijackThis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour et merci, Voici ce rapport : # AdwCleaner v1.608 - Rapport créé le 03/06/2012 à 12:31:01 # Mis à jour le 27/05/2012 par Xplode # Système d'exploitation : Windows 7 Professional Service Pack 1 (64 bits) # Nom d'utilisateur : giraudeau - GIRAUDEAU-VAIO # Exécuté depuis : C:\Users\giraudeau\Desktop\adwcleaner.exe # Option [suppression] ***** [services] ***** ***** [Fichiers / Dossiers] ***** Supprimé au redémarrage : C:\ProgramData\boost_interprocess ***** [Registre] ***** ***** [Registre - GUID] ***** ***** [Navigateurs] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Le registre ne contient aucune entrée illégitime. -\\ Google Chrome v19.0.1084.52 Fichier : C:\Users\giraudeau\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Le fichier ne contient aucune entrée illégitime. ************************* AdwCleaner[R1].txt - [12618 octets] - [03/06/2012 12:20:11] AdwCleaner[s1].txt - [9859 octets] - [03/06/2012 12:21:00] AdwCleaner[s2].txt - [967 octets] - [03/06/2012 12:31:01] ########## EOF - C:\AdwCleaner[s2].txt - [1094 octets] ########## -
Démarrage hyper lent – Analyse HijackThis
Pascal62 a posté un sujet dans Analyses et éradication malwares
Bonjour à tous, Je viens vers vous pour connaître votre analyse de mon fichier Logfile HijackThis. Merci d'avance. -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour Ogu voici le dernier rapport Hijackthis avec kles suppressions effectives Que dois je nettoyer d'autre ? merci d'avance avec le rapport c'est mieux Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:51:35, on 11/04/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Acer\eRecovery\Monitor.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\keyhook.exe C:\Program Files\Arcade\PCMService.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\tppaldr.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe c:\program files\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\mcafee.com\mps\mscifapp.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MICROS~4\rapimgr.exe C:\WINDOWS\system32\sistray.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pctools.com/fr/spyware-doctor/p...ef/google_pack/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file) O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [siS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoreflex.com/tools/ImageUplo...geUploader3.cab O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 9939 bytes -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour oGu, Oui j'ai fais la toolbar Google mais s'il en reste des morceaux, je suis pour tout virer. Et pour ce qui est de la sécurisation je suis partant.. Par contre avant de demarrer cela je voudrai m'occuper de McAfee pour le virer car j'ai pus de mise à jour. Merci encore -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bon voilà on avance, Le rapport OTMOVIE : C:\Program Files\Logitech\Desktop Messenger\8876480\Program moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Install moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Plugins moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Program\EN moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Program moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Misc\Temp moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Misc moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\2608 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\fde moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\fdb moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\fd8\a9a3f17 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\fd8\a9a3ef0 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\fd8\a9a3e36 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\fd8\a9a3e54 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\fd8\a9a3e53 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\fd8 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\LowIntegrity moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\GenFlash\1 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\GenFlash moved successfully. Folder move failed. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data scheduled to be moved on reboot. Folder move failed. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE scheduled to be moved on reboot. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Misc\Temp moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Misc moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\LowIntegrity moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\a20 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\34e1\a9a3f17 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\34e1\a9a3ef0 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\34e1\a9a3e54 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\34e1\a9a3e53 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\34e1\a9a3e36 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\34e1 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\6023 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\34de\Upstream moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\34de moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\GenFlash\1 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data\GenFlash moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU\Data moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOU moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Misc\Temp moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Misc moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\LowIntegrity moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\7f30 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\5da6\a9a3f17 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\5da6\a9a3ef0 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\5da6\a9a3e54 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\5da6\a9a3e53 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\5da6\a9a3e36 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\5da6 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\2fd2 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\6270\Upstream moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\6270 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\GenFlash\1 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data\GenFlash moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU\Data moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOU moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Misc\Backup moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Misc\Temp moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Misc moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\6deb moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73\10685e1c moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73\10685d92\LDM Release Multi moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73\10685d92 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73\a9a3f17 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73\a9a3ef0 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73\a9a3e54 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73\a9a3e53 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73\a9a3e36 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\5a73 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\4463 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\4460\a9acb42 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\4460\Upstream moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\4460 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\LowIntegrity moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\GenFlash\1 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data\GenFlash moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE\Data moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOUTE moved successfully. Folder move failed. C:\Program Files\Logitech\Desktop Messenger\8876480\Users scheduled to be moved on reboot. C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash\1 moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data moved successfully. C:\Program Files\Logitech\Desktop Messenger\8876480\InitData moved successfully. Folder move failed. C:\Program Files\Logitech\Desktop Messenger\8876480 scheduled to be moved on reboot. Folder move failed. C:\Program Files\Logitech\Desktop Messenger scheduled to be moved on reboot. C:\Program Files\Yahoo!\Common moved successfully. C:\Program Files\Yahoo!\Companion\Data moved successfully. Folder move failed. C:\Program Files\Yahoo!\Companion\Installs\cpn scheduled to be moved on reboot. Folder move failed. C:\Program Files\Yahoo!\Companion\Installs scheduled to be moved on reboot. Folder move failed. C:\Program Files\Yahoo!\Companion scheduled to be moved on reboot. Folder move failed. C:\Program Files\Yahoo! scheduled to be moved on reboot. OTMoveIt2 by OldTimer - Version 1.0.21 log created on 04042008_214703 Le rapport Hijackthis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:23:37, on 04/04/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\keyhook.exe C:\Program Files\Arcade\PCMService.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Acer\eRecovery\Monitor.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\tppaldr.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe c:\program files\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\mcafee.com\mps\mscifapp.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\MICROS~4\rapimgr.exe C:\WINDOWS\system32\sistray.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pctools.com/fr/spyware-doctor/p...ef/google_pack/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file) O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [siS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoreflex.com/tools/ImageUplo...geUploader3.cab O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 10587 bytes Voici Merci -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour Bon voici la suite des problèmes : Le logitech desktop messenger, n'est pas présent dans ajout suppression de programmes, via le pânneau de config. La tolbar de Yahoo non plus Quant au logiciel aswclear ... le lien ne fonctionne pas. @ Plus -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour! Merci pour ton aide au niiveau du foncetionnement cela va mieux! parc ontre je ne paux pas desinstaller McAfee, je n'y arrive pas ! Dés que j'ai progressé , je t'envoie un nouveau Rapport Bye! -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour! fichier supprimé et nouveau rapport : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:32:00, on 01/04/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\keyhook.exe C:\Program Files\Arcade\PCMService.exe C:\Program Files\Acer\eRecovery\Monitor.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\tppaldr.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe c:\program files\mcafee.com\agent\mcagent.exe C:\PROGRA~1\mcafee.com\mps\mscifapp.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MICROS~4\rapimgr.exe C:\WINDOWS\system32\sistray.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pctools.com/fr/spyware-doctor/p...ef/google_pack/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file) O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [siS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoreflex.com/tools/ImageUplo...geUploader3.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 12162 bytes -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
En effet il n'y figure pas, et je remets de suite les options que je viens de changer ...dans options... Merci -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Le résultat ne me donne que ça ! OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03302008_152508 -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Le voici le dernier Hijackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:28:56, on 30/03/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\McAfee\Common Framework\FrameworkService.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\keyhook.exe C:\Program Files\Arcade\PCMService.exe C:\Program Files\Acer\eRecovery\Monitor.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\tppaldr.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\mcafee.com\mps\mscifapp.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\MICROS~4\rapimgr.exe C:\WINDOWS\system32\sistray.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pctools.com/fr/spyware-doctor/p...ef/google_pack/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file) O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [siS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [zcwzxkjch] c:\windows\system32\zcwzxkjch.exe zcwzxkjch O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoreflex.com/tools/ImageUplo...geUploader3.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 12209 bytes -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour! le dernier Navilog le voici : Search Navipromo version 3.5.1 commencé le 30/03/2008 à 9:41:30,31 !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!! !!! Postez ce rapport sur le forum pour le faire analyser !!! !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!! Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "LOULOUTE" Mise à jour le 23.03.2008 à 22h00 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 7.0.5730.11 Système de fichiers : FAT32 Executé en mode normal *** Recherche Programmes installés *** *** Recherche dossiers dans C:\WINDOWS *** *** Recherche dossiers dans C:\Program Files *** *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 *** *** Recherche dossiers dans "C:\Documents and Settings\LOULOUTE\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\LOULOUTE\menud+~1\progra~1" *** *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUD?~1\PROGRA~1 *** *** Recherche avec Catchme-rootkit/stealth malware detector par gmer *** pour + d'infos : http://www.gmer.net Aucun Fichier trouvé *** Recherche avec GenericNaviSearch *** !!! Tous ces résultats peuvent révéler des fichiers légitimes !!! !!! A vérifier impérativement avant toute suppression manuelle !!! * Recherche dans C:\WINDOWS\system32 * * Recherche dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" * * Recherche dans "C:\docume~1\LOUTE\locals~1\applic~1" * * Recherche dans "C:\docume~1\LOU\locals~1\applic~1" * * Recherche dans "C:\docume~1\LOU.LOU_LOUTE\locals~1\applic~1" * * Recherche dans "C:\docume~1\Administrateur\locals~1\applic~1" * *** Recherche fichiers *** *** Recherche clés spécifiques dans le Registre *** *** Module de Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Recherche nouveaux fichiers Instant Access : 2)Recherche Heuristique : * Dans C:\WINDOWS\system32 : * Dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" : * Dans "C:\docume~1\LOUTE\locals~1\applic~1" : * Dans "C:\docume~1\LOU\locals~1\applic~1" : * Dans "C:\docume~1\LOU.LOU_LOUTE\locals~1\applic~1" : * Dans "C:\docume~1\Administrateur\locals~1\applic~1" : 3)Recherche Certificats : Certificat Egroup absent ! Certificat Electronic-Group absent ! Certificat OOO-Favorit absent ! Certificat Sunny-Day-Design-Ltd absent ! 4)Recherche fichiers connus : *** Analyse terminée le 30/03/2008 à 9:42:45,39 *** -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
bonsoir! Ewido n'a pas trouvé les fichiers que tu citais ...ex "HKEYLOCA...." Rapport MALWAREBYTES : Malwarebytes' Anti-Malware 1.09 Version de la base de données: 560 Type de recherche: Examen complet (C:\|D:\|E:\|F:\|) Eléments examinés: 96665 Temps écoulé: 15 minute(s), 39 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 5 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 0 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): HKEY_CLASSES_ROOT\Interface\{6c51f7e9-8542-4f25-a30f-2060157752e1} (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{9d573d0e-663c-435f-bf31-2c4497373c41} (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{b1e68d42-02c4-465b-8368-5ed9b732e22d} (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{90a52f08-64ac-4dc6-9d7d-4516670275d3} (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{90a52f08-64ac-4dc6-9d7d-4516670275d3} (Trojan.Downloader) -> Quarantined and deleted successfully. Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): (Aucun élément nuisible détecté) Rapport Blacklight : 03/28/08 19:14:21 [info]: BlackLight Engine 1.0.67 initialized 03/28/08 19:14:21 [info]: OS: 5.1 build 2600 (Service Pack 2) 03/28/08 19:14:21 [Note]: 7019 4 03/28/08 19:14:21 [Note]: 7005 0 03/28/08 19:14:31 [Note]: 7006 0 03/28/08 19:14:31 [Note]: 7011 1660 03/28/08 19:14:31 [Note]: 7026 0 03/28/08 19:14:31 [Note]: 7026 0 03/28/08 19:14:33 [Note]: FSRAW library version 1.7.1024 03/28/08 19:15:27 [Note]: 2000 1012 03/28/08 19:16:15 [Note]: 7007 0 Et enfin le HIJACKTHIS Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:20:52, on 28/03/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\keyhook.exe C:\Program Files\Arcade\PCMService.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\tppaldr.exe C:\Program Files\Acer\eRecovery\Monitor.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\WINDOWS\system32\sistray.exe C:\PROGRA~1\MICROS~4\rapimgr.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pctools.com/fr/spyware-doctor/p...ef/google_pack/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file) O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [siS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [zcwzxkjch] c:\windows\system32\zcwzxkjch.exe zcwzxkjch O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoreflex.com/tools/ImageUplo...geUploader3.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 12203 bytes Merci -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
le voici : Clean Navipromo version 3.5.1 commencé le 27/03/2008 à 22:09:32,71 Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "LOULOUTE" Actual User Account : "LOULOUTE" Mise à jour le 23.03.2008 à 22h00 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 7.0.5730.11 Système de fichiers : FAT32 Mode suppression automatique avec prise en charge résultats Catchme et GNS *** Creation backups fichiers trouvés par Catchme *** Copie vers "C:\Program Files\navilog1\Backupnavi" Copie C:\WINDOWS\system32\zcwzxkjch_nav.dat 425984 bytes réalisée avec succès ! Copie C:\WINDOWS\system32\zcwzxkjch.exe 393216 bytes réalisée avec succès ! Copie C:\WINDOWS\system32\zcwzxkjch.dat 32768 bytes réalisée avec succès ! Copie C:\WINDOWS\system32\zcwzxkjch_navps.dat 32768 bytes réalisée avec succès ! *** Suppression des fichiers trouvés avec Catchme *** ** 2ème passage avec résultats Catchme ** * Dans C:\WINDOWS\system32 * zcwzxkjch.exe trouvé ! Copie zcwzxkjch.exe réalisée avec succès ! zcwzxkjch.exe supprimé ! zcwzxkjch.dat trouvé ! Copie zcwzxkjch.dat réalisée avec succès ! zcwzxkjch.dat supprimé ! zcwzxkjch_nav.dat trouvé ! Copie zcwzxkjch_nav.dat réalisée avec succès ! zcwzxkjch_nav.dat supprimé ! zcwzxkjch_navps.dat trouvé ! Copie zcwzxkjch_navps.dat réalisée avec succès ! zcwzxkjch_navps.dat supprimé ! * Dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" * *** Suppression avec sauvegardes résultats GenericNaviSearch *** * Suppression dans C:\WINDOWS\System32 * * Suppression dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" * * Suppression dans "C:\docume~1\LOUTE\locals~1\applic~1" * * Suppression dans "C:\docume~1\LOU\locals~1\applic~1" * * Suppression dans "C:\docume~1\LOU.LOU_LOUTE\locals~1\applic~1" * * Suppression dans "C:\docume~1\Administrateur\locals~1\applic~1" * *** Suppression dossiers dans C:\WINDOWS *** *** Suppression dossiers dans C:\Program Files *** C:\Program Files\WebMediaPlayer ...suppression... C:\Program Files\WebMediaPlayer supprimé ! *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 *** *** Suppression dossiers dans "C:\Documents and Settings\LOULOUTE\applic~1" *** *** Suppression dossiers dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" *** *** Suppression dossiers dans "C:\Documents and Settings\LOULOUTE\menud+~1\progra~1" *** *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUD?~1\PROGRA~1 *** ...\WebMediaPlayer ...suppression... ...\WebMediaPlayer supprimé ! *** Suppression fichiers *** C:\DOCUME~1\ALLUSE~1\BUREAU\WebMediaPlayer.lnk supprimé ! C:\WINDOWS\pack.epk supprimé ! C:\WINDOWS\system32\nvs2.inf supprimé ! *** Suppression fichiers temporaires *** Nettoyage contenu C:\WINDOWS\Temp effectué ! Nettoyage contenu C:\Documents and Settings\LOULOUTE\locals~1\Temp effectué ! *** Traitement Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Suppression avec sauvegardes nouveaux fichiers Instant Access : 2)Recherche, création sauvegardes et suppression Heuristique : * Dans C:\WINDOWS\system32 * iffhsp.dat trouvé ! Copie iffhsp.dat réalisée avec succès ! iffhsp.dat supprimé ! iffhsp_navps.dat trouvé ! Copie iffhsp_navps.dat réalisée avec succès ! iffhsp_navps.dat supprimé ! * Dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" * * Dans "C:\docume~1\LOUTE\locals~1\applic~1" * * Dans "C:\docume~1\LOU\locals~1\applic~1" * * Dans "C:\docume~1\LOU.LOU_LOUTE\locals~1\applic~1" * * Dans "C:\docume~1\Administrateur\locals~1\applic~1" * *** Sauvegarde du Registre vers dossier Backupnavi *** sauvegarde du Registre réalisée avec succès ! *** Nettoyage Registre *** Nettoyage Registre Ok *** Certificats *** Certificat Egroup supprimé ! Certificat Electronic-Group supprimé ! Certificat OOO-Favorit supprimé ! Certificat Sunny-Day-Design-Ltdt absent ! *** Nettoyage terminé le 27/03/2008 à 22:12:34,42 *** -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonsoir bon voici le résultat de Navilog Search Navipromo version 3.5.1 commencé le 27/03/2008 à 20:40:10,90 !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!! !!! Postez ce rapport sur le forum pour le faire analyser !!! !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!! Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "LOULOUTE" Mise à jour le 23.03.2008 à 22h00 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 7.0.5730.11 Système de fichiers : FAT32 Executé en mode normal *** Recherche Programmes installés *** WebMediaPlayer *** Recherche dossiers dans C:\WINDOWS *** *** Recherche dossiers dans C:\Program Files *** C:\Program Files\WebMediaPlayer trouvé ! *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 *** *** Recherche dossiers dans "C:\Documents and Settings\LOULOUTE\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\LOULOUTE\menud+~1\progra~1" *** *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUD?~1\PROGRA~1 *** ...\WebMediaPlayer trouvé ! *** Recherche avec Catchme-rootkit/stealth malware detector par gmer *** pour + d'infos : http://www.gmer.net Fichier(s) caché(s) : C:\WINDOWS\system32\zcwzxkjch_nav.dat 425984 bytes C:\WINDOWS\system32\zcwzxkjch.exe 393216 bytes C:\WINDOWS\system32\zcwzxkjch.dat 32768 bytes C:\WINDOWS\system32\zcwzxkjch_navps.dat 32768 bytes *** Recherche avec GenericNaviSearch *** !!! Tous ces résultats peuvent révéler des fichiers légitimes !!! !!! A vérifier impérativement avant toute suppression manuelle !!! * Recherche dans C:\WINDOWS\system32 * Fichiers suspects : C:\WINDOWS\system32\zcwzxkjch.exe trouvé ! * Recherche dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" * * Recherche dans "C:\docume~1\LOUTE\locals~1\applic~1" * * Recherche dans "C:\docume~1\LOU\locals~1\applic~1" * * Recherche dans "C:\docume~1\LOU.LOU_LOUTE\locals~1\applic~1" * * Recherche dans "C:\docume~1\Administrateur\locals~1\applic~1" * *** Recherche fichiers *** C:\DOCUME~1\ALLUSE~1\BUREAU\WebMediaPlayer.lnk trouvé ! C:\WINDOWS\pack.epk trouvé ! C:\WINDOWS\system32\nvs2.inf trouvé ! *** Recherche clés spécifiques dans le Registre *** HKEY_CURRENT_USER\Software\Lanconfig trouvé ! *** Module de Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Recherche nouveaux fichiers Instant Access : 2)Recherche Heuristique : * Dans C:\WINDOWS\system32 : iffhsp.dat trouvé ! zcwzxkjch.dat trouvé ! iffhsp_navps.dat trouvé ! zcwzxkjch_navps.dat trouvé ! * Dans "C:\Documents and Settings\LOULOUTE\locals~1\applic~1" : * Dans "C:\docume~1\LOUTE\locals~1\applic~1" : * Dans "C:\docume~1\LOU\locals~1\applic~1" : * Dans "C:\docume~1\LOU.LOU_LOUTE\locals~1\applic~1" : * Dans "C:\docume~1\Administrateur\locals~1\applic~1" : 3)Recherche Certificats : Certificat Egroup trouvé ! Certificat Electronic-Group trouvé ! Certificat OOO-Favorit trouvé ! Certificat Sunny-Day-Design-Ltd absent ! 4)Recherche fichiers connus : *** Analyse terminée le 27/03/2008 à 20:42:03,90 *** -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour! voici mon dernier avec Kapersky : ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Monday, March 24, 2008 10:49:14 PM Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version : 5.0.83.0 Dernière mise à jour de la base antivirus Kaspersky : 24/03/2008 Enregistrements dans la base antivirus Kaspersky : 593625 ------------------------------------------------------------------------------- Paramètres d'analyse: Analyser avec la base antivirus suivante: standard Analyser les archives: vrai Analyser les bases de messagerie: vrai Cible de l'analyse - Poste de travail: C:\ D:\ E:\ F:\ Statistiques de l'analyse: Total d'objets analysés: 75599 Nombre de virus trouvés: 9 Nombre d'objets infectés: 25 / 0 Nombre d'objets suspects: 0 Durée de l'analyse: 01:40:24 Nom de l'objet infecté / Nom du virus / Dernière action C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré C:\WINDOWS\system32\drivers\sptd.sys L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré C:\WINDOWS\system32\CatRoot2\edbtmp.log L'objet est verrouillé ignoré C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré C:\WINDOWS\Temp\Perflib_Perfdata_644.dat L'objet est verrouillé ignoré C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd000.log L'objet est verrouillé ignoré C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\PrdMgr_LOU_LOUTE.log L'objet est verrouillé ignoré C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\Agent_LOU_LOUTE.log L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\ntuser.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\ntuser.dat L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Temp\WCESLog.log L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Temp\Acr6760.tmp L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Temp\Acr67B0.tmp L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Temp\Acr6767.tmp L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Mes documents\Downloads\_PANTHEON_ anglais test SVCD (Album).zip/Setup.exe Infecté : Trojan-Dropper.Win32.Agent.dkn ignoré C:\Documents and Settings\LOULOUTE\Mes documents\Downloads\_PANTHEON_ anglais test SVCD (Album).zip ZIP: infecté - 1 ignoré C:\Documents and Settings\LOULOUTE\Bureau\LOU2\Mes documents\Downloads\----- mypal ----- 2007.zip/Setup.exe Infecté : not-virus:Hoax.Win32.Agent.o ignoré C:\Documents and Settings\LOULOUTE\Bureau\LOU2\Mes documents\Downloads\----- mypal ----- 2007.zip ZIP: infecté - 1 ignoré C:\Documents and Settings\LOULOUTE\Bureau\Web-MediaPlayer_setup.exe Infecté : Trojan-Dropper.Win32.Agent.dtk ignoré C:\Documents and Settings\LOULOUTE\Cookies\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\Application Data\$_hpcst$.hpc L'objet est verrouillé ignoré C:\Documents and Settings\LOULOUTE\ntuser.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\chandir.idx L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\D0000000.FCS L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\chandir.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\inuse.txt L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\main.log L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\storydb.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\storydb.idx L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\chn.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\chn.idx L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs_die.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs_die.idx L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs_dnd.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs_dnd.idx L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs_ext.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs_ext.idx L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs_rcv.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs_rcv.idx L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs.dat L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\prs.idx L'objet est verrouillé ignoré C:\Program Files\Logitech\Desktop Messenger\8876480\Users\LOULOUTE\Data\L0000008.FCS L'objet est verrouillé ignoré C:\Program Files\Alwil Software\Avast4\DATA\INTEG\avast.int L'objet est verrouillé ignoré C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db L'objet est verrouillé ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP207\A0053975.exe Infecté : Trojan-Dropper.Win32.Agent.dkn ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP211\A0059355.exe Infecté : Trojan-Downloader.Win32.Agent.fct ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP211\A0059356.exe Infecté : Trojan-Downloader.Win32.Agent.fjg ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP221\A0063586.exe Infecté : Trojan-Downloader.Win32.Agent.dwe ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0067377.sys Infecté : Trojan-Downloader.Win32.Bagle.lm ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0067405.sys Infecté : Trojan-Downloader.Win32.Bagle.lm ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0067433.sys Infecté : Trojan-Downloader.Win32.Bagle.lm ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0068432.sys Infecté : Trojan-Downloader.Win32.Bagle.lm ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0068459.exe Infecté : Email-Worm.Win32.Bagle.of ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0068460.exe Infecté : Email-Worm.Win32.Bagle.of ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0069436.sys Infecté : Trojan-Downloader.Win32.Bagle.lm ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0069438.exe Infecté : Email-Worm.Win32.Bagle.of ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0069439.exe Infecté : Email-Worm.Win32.Bagle.of ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0069572.sys Infecté : Trojan-Downloader.Win32.Bagle.lm ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0069674.exe Infecté : Email-Worm.Win32.Bagle.of ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP234\A0069675.exe Infecté : Email-Worm.Win32.Bagle.of ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP235\A0070194.exe Infecté : Email-Worm.Win32.Bagle.of ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP235\A0070200.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP235\A0070201.exe Infecté : Email-Worm.Win32.Bagle.of ignoré C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP237\change.log L'objet est verrouillé ignoré C:\_OTMoveIt\MovedFiles\03222008_143526\Documents and Settings\LOULOUTE\Application Data\WinButler\WinBuninstaller.exe Infecté : Trojan-Downloader.Win32.Agent.dwe ignoré Analyse terminée. Merci -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
OK je fais ça merci et bon voyage -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bonjour ! Voici avec bien des difficultés les seuls rapports que j'ai pu avoir. le dernier concernant Kapersky en mode sans échec n'a pas été possible car il me dit que la mise à jour n'est pas récente alors il ne se passe plus rien. les rapports obtenus sont: CCcleaner Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\FileCDDefault\\resFileCD.dll"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\Default\\resCdmkr.dll"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Fichiers communs\\NewTech Infosystems\\LiveUpdate\\Default\\ResLiveUpdtEN.dll"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\DFDefault\\resNDVD9To5.dll"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Fichiers communs\\Microsoft Shared\\VBA\\VEENOB3.HLP"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Fichiers communs\\Microsoft Shared\\VBA\\VBA332.DLL"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Fichiers communs\\Microsoft Shared\\VBA\\MSO97RT.DLL"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Fichiers communs\\Microsoft Shared\\VBA\\VBEEXT1.OLB"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Fichiers communs\\Microsoft Shared\\VBA\\VBE.DLL"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\system32\\pxwma.dll"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\system32\\pxinsi64.exe"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\system32\\pxcpyi64.exe"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.Windows.Forms.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.EnterpriseServices.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.JScript.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.Vsa.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.Drawing.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\mscoree.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\mscorlib.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\System.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\WINDOWS\\Microsoft.NET\\Framework\\v1.0.3705\\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb"=dword:00001000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\de.locale\\compasstop.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\de.locale\\license.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\de.locale\\releasenotes.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\de.locale\\ring_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\de.locale\\ring_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\de.locale\\ring_norm.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\de.locale\\ring_n_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\de.locale\\ring_n_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\en.locale\\compasstop.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\en.locale\\license.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\en.locale\\releasenotes.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\en.locale\\ring_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\en.locale\\ring_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\en.locale\\ring_norm.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\en.locale\\ring_n_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\en.locale\\ring_n_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\es.locale\\compasstop.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\es.locale\\license.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\es.locale\\releasenotes.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\es.locale\\ring_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\es.locale\\ring_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\es.locale\\ring_norm.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\es.locale\\ring_n_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\es.locale\\ring_n_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\fr.locale\\compasstop.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\fr.locale\\license.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\fr.locale\\releasenotes.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\fr.locale\\ring_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\fr.locale\\ring_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\fr.locale\\ring_norm.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\fr.locale\\ring_n_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\fr.locale\\ring_n_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\it.locale\\compasstop.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\it.locale\\license.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\it.locale\\releasenotes.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\it.locale\\ring_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\it.locale\\ring_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\it.locale\\ring_norm.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\it.locale\\ring_n_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\it.locale\\ring_n_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\compasstop.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\license.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\licensepro.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\releasenotes.txt"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\ring_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\ring_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\ring_norm.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\ring_n_active.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\ja.locale\\ring_n_hover.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon0.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon1.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon10.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon11.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon12.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon13.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon14.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon15.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon16.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon17.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon18.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon19.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon2.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon20.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon21.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon22.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon23.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon24.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon25.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon26.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon27.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon28.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon29.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon3.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon30.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon31.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon32.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon33.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon34.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon35.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon36.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon37.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon38.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon39.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon4.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon40.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon41.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon42.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon43.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon44.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon45.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon46.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon47.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon48.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon49.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon5.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon50.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon51.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon52.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon53.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon54.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon55.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon56.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon57.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon58.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon59.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon6.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon60.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon61.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon62.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon63.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon7.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon8.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal2\\icon9.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon0.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon0l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon1.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon10.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon10l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon11.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon11l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon12.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon12l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon13.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon13l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon14.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon14l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon15.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon15l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon16.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon16l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon17.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon17l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon18.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon19.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon1l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon2.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon20.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon21.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon22.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon23.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon24.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon24l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon25.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon25l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon26.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon27.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon28.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon29.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon2l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon3.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon30.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon31.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon32.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon33.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon34.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon35.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon36.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon37.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon38.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon39.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon3l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon4.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon40.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon41.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon42.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon43.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon44.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon45.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon46.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon47.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon48.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon49.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon4l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon5.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon50.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon51.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon52.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon53.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon54.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon55.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon56.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon57.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon58.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon59.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon5l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon6.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon60.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon61.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon62.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon63.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon6l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon7.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon7l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon8.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon8l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon9.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal3\\icon9l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon0.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon1.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon10.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon11.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon12.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon13.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon14.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon15.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon16.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon17.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon18.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon19.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon2.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon20.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon21.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon22.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon23.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon24.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon25.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon26.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon27.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon28.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon29.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon3.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon30.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon31.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon32.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon33.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon34.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon35.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon36.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon37.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon38.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon39.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon4.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon40.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon41.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon42.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon43.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon44.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon45.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon46.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon47.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon48.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon49.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon5.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon50.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon51.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon52.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon53.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon54.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon55.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon56.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon57.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon58.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon59.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon6.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon60.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon61.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon62.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon63.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon7.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon8.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal4\\icon9.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon0.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon0l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon1.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon10.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon11.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon12.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon13.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon14.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon15.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon16.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon16l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon17.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon17l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon18.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon18l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon19.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon19l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon1l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon2.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon20.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon20l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon21.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon21l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon22.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon22l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon23.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon23l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon24.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon24l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon25.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon25l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon26.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon26l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon27.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon27l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon28.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon28l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon29.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon29l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon3.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon30.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon30l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon31.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon31l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon32.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon32l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon33.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon33l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon34.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon34l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon35.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon35l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon36.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon36l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon37.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon37l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon38.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon38l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon39.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon39l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon4.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon40.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon40l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon41.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon41l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon42.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon42l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon43.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon43l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon44.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon44l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon45.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon45l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon46.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon46l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon47.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon47l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon48.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon48l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon49.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon49l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon5.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon50.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon50l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon51.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon51l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon52.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon52l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon53.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon53l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon54.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon54l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon55.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon55l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon56.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon56l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon57.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon57l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon58.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon58l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon59.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon59l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon6.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon60.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon60l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon61.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon61l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon62.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon62l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon63.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon63l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon7.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon8.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon8l.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon9.png"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls] "C:\\Program Files\\Google\\Google Earth\\res\\pal5\\icon9l.png"=dword:00000001 [HKEY_CLASSES_ROOT\.b4s] [HKEY_CLASSES_ROOT\.bpl] [HKEY_CLASSES_ROOT\.pls] [HKEY_CLASSES_ROOT\.wpz] [HKEY_CLASSES_ROOT\idcfile] @="" [HKEY_CLASSES_ROOT\PocketPC] [HKEY_CLASSES_ROOT\SysmonLogManager.Snapin] [HKEY_CLASSES_ROOT\WMPCD] [HKEY_CLASSES_ROOT\{] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k] @="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2] @="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc] @="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nds] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nds\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx] @="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sav] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sav\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp\OpenWithList] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm] @="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithList] [HKEY_CLASSES_ROOT\ADCS] @="Conteneur de classe Annuaire" [HKEY_CLASSES_ROOT\ADCS\CLSID] @="{89E30300-764D-11d0-B282-00A0C90F56FC}" [HKEY_CLASSES_ROOT\bwpfile\shell\open] [HKEY_CLASSES_ROOT\bwpfile\shell\open\command] @="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\8.1.1.50-8876480SL\\Program\\PrvCnt.exe \"%1\"" [HKEY_CLASSES_ROOT\callto\DefaultIcon] @="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\",0" [HKEY_CLASSES_ROOT\callto\shell\open] [HKEY_CLASSES_ROOT\callto\shell\open\command] @="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" \"/callto:\"%l\"\"" [HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost] [HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost\CLSID] @="{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}" [HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost.2] @="Microsoft COM+ Runtime Meta Data" [HKEY_CLASSES_ROOT\ComPlusMetaData.MsCorHost.2\CLSID] @="{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}" [HKEY_CLASSES_ROOT\Connection Manager Profile\DefaultIcon] @="C:\\WINDOWS\\system32\\CMMGR32.EXE,1" [HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open] [HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open\command] @="C:\\WINDOWS\\system32\\CMMGR32.EXE \"%1\"" [HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...] [HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...\command] @="C:\\WINDOWS\\system32\\CMMGR32.EXE /settings \"%1\"" [HKEY_CLASSES_ROOT\DirectAnimation.PathControl] @="Microsoft DirectAnimation Path" [HKEY_CLASSES_ROOT\DirectAnimation.PathControl\CLSID] @="{D7A7D7C3-D47F-11D0-89D3-00A0C90833E6}" [HKEY_CLASSES_ROOT\DirectAnimation.Sequence] @="Microsoft DirectAnimation Sequence" [HKEY_CLASSES_ROOT\DirectAnimation.Sequence\CLSID] @="{4F241DB1-EE9F-11D0-9824-006097C99E51}" [HKEY_CLASSES_ROOT\DirectAnimation.SequencerControl] @="Microsoft DirectAnimation Sequencer" [HKEY_CLASSES_ROOT\DirectAnimation.SequencerControl\CLSID] @="{B0A6BAE2-AAF0-11D0-A152-00A0C908DB96}" [HKEY_CLASSES_ROOT\DirectAnimation.SpriteControl] @="Microsoft DirectAnimation Sprite" [HKEY_CLASSES_ROOT\DirectAnimation.SpriteControl\CLSID] @="{FD179533-D86E-11D0-89D6-00A0C90833E6}" [HKEY_CLASSES_ROOT\DirectAnimation.StructuredGraphicsControl] @="Microsoft DirectAnimation Structured Graphics" [HKEY_CLASSES_ROOT\DirectAnimation.StructuredGraphicsControl\CLSID] @="{369303C2-D7AC-11D0-89D5-00A0C90833E6}" [HKEY_CLASSES_ROOT\maxtv\shell\open] [HKEY_CLASSES_ROOT\maxtv\shell\open\command] @="C:\\Program Files\\MaxTV\\maxtv.exe -%1-" [HKEY_CLASSES_ROOT\msbackupfile\DefaultIcon] @=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,00,74,00,\ 62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,00,2c,00,31,00,30,\ 00,00,00 [HKEY_CLASSES_ROOT\msbackupfile\shell\Open] @="&Ouvrir" [HKEY_CLASSES_ROOT\msbackupfile\shell\Open\Command] @=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6e,00,74,00,\ 62,00,61,00,63,00,6b,00,75,00,70,00,2e,00,65,00,78,00,65,00,00,00 [HKEY_CLASSES_ROOT\Msxml2.XSLPatternFactory] @="XSL Pattern Factory" [HKEY_CLASSES_ROOT\Msxml2.XSLPatternFactory\CLSID] @="%CLSID_XSLPatternFactory" [HKEY_CLASSES_ROOT\Msxml2.XSLPatternFactory\CurVer] @="Msxml2.XSLPatternFactory.4.0" [HKEY_CLASSES_ROOT\RavenShieldMap\shell\open] [HKEY_CLASSES_ROOT\RavenShieldMap\shell\open\command] @="\"C:\\Program Files\\Red Storm Entertainment\\RavenShield\\systemUnrealEd.exe\" \"%1\"" [HKEY_CLASSES_ROOT\SymWriter.pdb] @="Pdb based SymWriter" [HKEY_CLASSES_ROOT\SymWriter.pdb\CLSID] @="{520DC67A-752E-11D3-8D56-00C04F680B2B}" [HKEY_CLASSES_ROOT\vanBasco.MIDI\DefaultIcon] @="C:\\Program Files\\vanBasco's Karaoke Player\\vmidi.exe,1" [HKEY_CLASSES_ROOT\vanBasco.MIDI\shell\open] @="&Open" [HKEY_CLASSES_ROOT\vanBasco.MIDI\shell\open\command] @="\"C:\\Program Files\\vanBasco's Karaoke Player\\vmidi.exe\"" [HKEY_CLASSES_ROOT\vanBasco.MIDI\shell\open\ddeexec] @="[load(\"%1\")]" [HKEY_CLASSES_ROOT\vanBasco.MIDI\shell\play] @="&Play" [HKEY_CLASSES_ROOT\vanBasco.MIDI\shell\play\command] @="\"C:\\Program Files\\vanBasco's Karaoke Player\\vmidi.exe\"" [HKEY_CLASSES_ROOT\vanBasco.MIDI\shell\play\ddeexec] @="[load(\"%1\")][play]" [HKEY_CLASSES_ROOT\zapfile\DefaultIcon] @=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\ 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,70,00,\ 70,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,32,00,31,00,38,\ 00,00,00 [HKEY_CLASSES_ROOT\CLSID\{04C3AD62-C14C-44E9-9550-96E07ADDABE7}] @="PSCookieDetectedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{04C3AD62-C14C-44E9-9550-96E07ADDABE7}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{04C3AD62-C14C-44E9-9550-96E07ADDABE7}\ProgID] @="MpsEventHandler.PSCookieDetectedEvent.1" [HKEY_CLASSES_ROOT\CLSID\{04C3AD62-C14C-44E9-9550-96E07ADDABE7}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{04C3AD62-C14C-44E9-9550-96E07ADDABE7}\VersionIndependentProgID] @="MpsEventHandler.PSCookieDetectedEventHa" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}] @="ActiveXPlugin Object" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Control] [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories] [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}] [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}] [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\InprocServer32] @="C:\\WINDOWS\\system32\\plugin.ocx" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\MiscStatus] @="0" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\MiscStatus\1] @="131473" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\ProgID] @="Microsoft.ActiveXPlugin.1" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\ToolboxBitmap32] @="C:\\WINDOWS\\system32\\plugin.ocx, 1" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\TypeLib] @="{06DD38D0-D187-11CF-A80D-00C04FD74AD8}" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\VersionIndependentProgID] @="Microsoft.ActiveXPlugin" [HKEY_CLASSES_ROOT\CLSID\{09DBB645-8A30-4141-9ABE-826C1BBDFB10}] @="UserEvents Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{09DBB645-8A30-4141-9ABE-826C1BBDFB10}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{09DBB645-8A30-4141-9ABE-826C1BBDFB10}\ProgID] @="MpsEventHandler.UserEvents.1" [HKEY_CLASSES_ROOT\CLSID\{09DBB645-8A30-4141-9ABE-826C1BBDFB10}\TypeLib] @="{}" [HKEY_CLASSES_ROOT\CLSID\{09DBB645-8A30-4141-9ABE-826C1BBDFB10}\VersionIndependentProgID] @="MpsEventHandler.UserEvents" [HKEY_CLASSES_ROOT\CLSID\{0A8E9E0A-10F6-4BB4-A076-D89D1C446CFF}] [HKEY_CLASSES_ROOT\CLSID\{0A8E9E0A-10F6-4BB4-A076-D89D1C446CFF}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" [HKEY_CLASSES_ROOT\CLSID\{0C146D72-9229-49D8-B2C9-D805EF5C69A9}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{0C146D72-9229-49D8-B2C9-D805EF5C69A9}\InProcServer32] @="c:\\PROGRA~1\\mcafee\\VIRUSS~1\\mcodsps.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{0D81DFEC-5610-4A2B-9B57-FC33D21366F0}] [HKEY_CLASSES_ROOT\CLSID\{0D81DFEC-5610-4A2B-9B57-FC33D21366F0}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{0D81DFEC-5610-4A2B-9B57-FC33D21366F0}\ProgID] @="MSNMessenger.MsgrSessionManager" [HKEY_CLASSES_ROOT\CLSID\{0D81DFEC-5610-4A2B-9B57-FC33D21366F0}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{0D81DFEC-5610-4A2B-9B57-FC33D21366F0}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{0D81DFEC-5610-4A2B-9B57-FC33D21366F0}\VersionIndependentProgID] @="MSNMessenger.MsgrSessionManager.1" [HKEY_CLASSES_ROOT\CLSID\{0dabacb1-1a16-4082-a610-3d0b3a2a94fc}] @="CddbWinamp5UI Class" [HKEY_CLASSES_ROOT\CLSID\{0dabacb1-1a16-4082-a610-3d0b3a2a94fc}\InprocServer32] @="C:\\Program Files\\Winamp\\Plugins\\cddbuiwinamp.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{0dabacb1-1a16-4082-a610-3d0b3a2a94fc}\ProgID] @="CDDBUIControlWinamp5.CddbWinamp5UI.1" [HKEY_CLASSES_ROOT\CLSID\{0dabacb1-1a16-4082-a610-3d0b3a2a94fc}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{0dabacb1-1a16-4082-a610-3d0b3a2a94fc}\TypeLib] @="{70891d64-b465-4e35-bbfa-6772bb37c966}" [HKEY_CLASSES_ROOT\CLSID\{0dabacb1-1a16-4082-a610-3d0b3a2a94fc}\VersionIndependentProgID] @="CDDBUIControlWinamp5.CddbWinamp5UI" [HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}] [HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\InprocServer32] @="\"C:\\PROGRA~1\\MSNMES~1\\msgsc.dll\"" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\LocalServer32] @="\"C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe\"" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\ProgID] @="MSNMessenger.ContactsPicker" [HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\Programmable] @="" [HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\VersionIndependentProgID] @="MSNMessenger.ContactsPicker.1" [HKEY_CLASSES_ROOT\CLSID\{11BF9882-396B-4B8C-87D3-B5E7812080CC}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{11BF9882-396B-4B8C-87D3-B5E7812080CC}\InProcServer32] @="c:\\PROGRA~1\\FICHIE~1\\mcafee\\redirsvc\\redirps.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{11C534D6-2D12-419F-B2D5-210100C8495F}] @="PSImageBlockedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{11C534D6-2D12-419F-B2D5-210100C8495F}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{11C534D6-2D12-419F-B2D5-210100C8495F}\ProgID] @="MpsEventHandler.PSImageBlockedEventHa.1" [HKEY_CLASSES_ROOT\CLSID\{11C534D6-2D12-419F-B2D5-210100C8495F}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{11C534D6-2D12-419F-B2D5-210100C8495F}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{11C534D6-2D12-419F-B2D5-210100C8495F}\VersionIndependentProgID] @="MpsEventHandler.PSImageBlockedEventHand" [HKEY_CLASSES_ROOT\CLSID\{17BE27FE-0B6C-4234-B487-FFC6E3DCA2D6}] [HKEY_CLASSES_ROOT\CLSID\{17BE27FE-0B6C-4234-B487-FFC6E3DCA2D6}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{17BE27FE-0B6C-4234-B487-FFC6E3DCA2D6}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{1B02BDDF-F6D2-4B36-ABBA-AD49EBC876A5}] [HKEY_CLASSES_ROOT\CLSID\{1B02BDDF-F6D2-4B36-ABBA-AD49EBC876A5}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" [HKEY_CLASSES_ROOT\CLSID\{2B05BC74-FFC7-4792-85CF-DA6E17950480}] @="ElevatedHelperClass Class" "AppID"="{73E3EA38-DBAA-414F-AE10-9CB33B6E9FDF}" "LocalizedString"="@C:\\Program Files\\Softwin\\BitDefender10\\bdelev.dll,-1000" [HKEY_CLASSES_ROOT\CLSID\{2B05BC74-FFC7-4792-85CF-DA6E17950480}\Elevation] "Enabled"=dword:00000001 [HKEY_CLASSES_ROOT\CLSID\{2B05BC74-FFC7-4792-85CF-DA6E17950480}\InprocServer32] @="C:\\Program Files\\Softwin\\BitDefender10\\bdelev.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{2B05BC74-FFC7-4792-85CF-DA6E17950480}\ProgID] @="BDElevatedHelper.ElevatedHelperClass.1" [HKEY_CLASSES_ROOT\CLSID\{2B05BC74-FFC7-4792-85CF-DA6E17950480}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{2B05BC74-FFC7-4792-85CF-DA6E17950480}\TypeLib] @="{48E8254D-A519-402B-AB11-7DFDD5CE0E74}" [HKEY_CLASSES_ROOT\CLSID\{2B05BC74-FFC7-4792-85CF-DA6E17950480}\VersionIndependentProgID] @="BDElevatedHelper.ElevatedHelperClass" [HKEY_CLASSES_ROOT\CLSID\{323C0F99-820A-4E0B-B714-57942C6D9678}] [HKEY_CLASSES_ROOT\CLSID\{323C0F99-820A-4E0B-B714-57942C6D9678}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{323C0F99-820A-4E0B-B714-57942C6D9678}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{323C0F99-820A-4E0B-B714-57942C6D9678}\ProgID] @="MSNMessengerPrivate.MessengerPriv" [HKEY_CLASSES_ROOT\CLSID\{323C0F99-820A-4E0B-B714-57942C6D9678}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{323C0F99-820A-4E0B-B714-57942C6D9678}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{323C0F99-820A-4E0B-B714-57942C6D9678}\VersionIndependentProgID] @="MSNMessengerPrivate.MessengerPriv.1" [HKEY_CLASSES_ROOT\CLSID\{395D2485-540E-4111-B9C7-CE3FC4E9AFE2}] @="PSSignOutEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{395D2485-540E-4111-B9C7-CE3FC4E9AFE2}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{395D2485-540E-4111-B9C7-CE3FC4E9AFE2}\ProgID] @="MpsEventHandler.PSSignOutEventHandler.1" [HKEY_CLASSES_ROOT\CLSID\{395D2485-540E-4111-B9C7-CE3FC4E9AFE2}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{395D2485-540E-4111-B9C7-CE3FC4E9AFE2}\VersionIndependentProgID] @="MpsEventHandler.PSSignOutEventHandler" [HKEY_CLASSES_ROOT\CLSID\{4F07F79F-087F-42CF-8B36-7A88D06088E9}] [HKEY_CLASSES_ROOT\CLSID\{4F07F79F-087F-42CF-8B36-7A88D06088E9}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{4F07F79F-087F-42CF-8B36-7A88D06088E9}\ProgID] @="MSNMessenger.HotmailControl" [HKEY_CLASSES_ROOT\CLSID\{4F07F79F-087F-42CF-8B36-7A88D06088E9}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{4F07F79F-087F-42CF-8B36-7A88D06088E9}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{4F07F79F-087F-42CF-8B36-7A88D06088E9}\VersionIndependentProgID] @="MSNMessenger.HotmailControl.1" [HKEY_CLASSES_ROOT\CLSID\{575774BF-73CA-4DCC-88E4-48D04E930F91}] @="PSAdBlockedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{575774BF-73CA-4DCC-88E4-48D04E930F91}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{575774BF-73CA-4DCC-88E4-48D04E930F91}\ProgID] @="MpsEventHandler.PSAdBlockedEventHandl.1" [HKEY_CLASSES_ROOT\CLSID\{575774BF-73CA-4DCC-88E4-48D04E930F91}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{575774BF-73CA-4DCC-88E4-48D04E930F91}\VersionIndependentProgID] @="MpsEventHandler.PSAdBlockedEventHandler" [HKEY_CLASSES_ROOT\CLSID\{5C90092E-A90F-40F3-8155-49F087A3B752}] @="PSSignInEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{5C90092E-A90F-40F3-8155-49F087A3B752}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{5C90092E-A90F-40F3-8155-49F087A3B752}\ProgID] @="MpsEventHandler.PSSignInEventHandler.1" [HKEY_CLASSES_ROOT\CLSID\{5C90092E-A90F-40F3-8155-49F087A3B752}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{5C90092E-A90F-40F3-8155-49F087A3B752}\VersionIndependentProgID] @="MpsEventHandler.PSSignInEventHandler" [HKEY_CLASSES_ROOT\CLSID\{63D7FB68-6898-4380-9EBC-BDAB6F5705F4}] @="SubscriptionEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{63D7FB68-6898-4380-9EBC-BDAB6F5705F4}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{63D7FB68-6898-4380-9EBC-BDAB6F5705F4}\ProgID] @="MpsEventHandler.SubscriptionEventHand.1" [HKEY_CLASSES_ROOT\CLSID\{63D7FB68-6898-4380-9EBC-BDAB6F5705F4}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{63D7FB68-6898-4380-9EBC-BDAB6F5705F4}\VersionIndependentProgID] @="MpsEventHandler.SubscriptionEventHandler" [HKEY_CLASSES_ROOT\CLSID\{683C7EA1-3A4B-4764-A8E6-768C4F38BBA6}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{683C7EA1-3A4B-4764-A8E6-768C4F38BBA6}\InProcServer32] @="c:\\PROGRA~1\\mcafee\\msc\\mcmispps.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{69E9B473-22E6-471D-8683-84BD1E4BECE1}] @="CDDBControl2 Class" [HKEY_CLASSES_ROOT\CLSID\{69E9B473-22E6-471D-8683-84BD1E4BECE1}\InprocServer32] @="C:\\Program Files\\Winamp\\Plugins\\cddbcontrolwinamp.dll" "ThreadingModel"="both" [HKEY_CLASSES_ROOT\CLSID\{69E9B473-22E6-471D-8683-84BD1E4BECE1}\ProgID] @="CDDBControl.CDDBControl2.1" [HKEY_CLASSES_ROOT\CLSID\{69E9B473-22E6-471D-8683-84BD1E4BECE1}\VersionIndependentProgID] @="CDDBControl.CDDBControl2" [HKEY_CLASSES_ROOT\CLSID\{6FBF8DD5-9E03-4AF5-B779-FEBEF6754712}] [HKEY_CLASSES_ROOT\CLSID\{6FBF8DD5-9E03-4AF5-B779-FEBEF6754712}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{6FBF8DD5-9E03-4AF5-B779-FEBEF6754712}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{6FBF8DD5-9E03-4AF5-B779-FEBEF6754712}\ProgID] @="MSNMessenger.ToastManager" [HKEY_CLASSES_ROOT\CLSID\{6FBF8DD5-9E03-4AF5-B779-FEBEF6754712}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{6FBF8DD5-9E03-4AF5-B779-FEBEF6754712}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{6FBF8DD5-9E03-4AF5-B779-FEBEF6754712}\VersionIndependentProgID] @="MSNMessenger.ToastManager.1" [HKEY_CLASSES_ROOT\CLSID\{7F72DD4F-F9DB-40B1-A248-1F77F3C3B132}] [HKEY_CLASSES_ROOT\CLSID\{7F72DD4F-F9DB-40B1-A248-1F77F3C3B132}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{7F72DD4F-F9DB-40B1-A248-1F77F3C3B132}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{8025781B-7405-42F4-B6FC-C1FB826A11F2}] @="VideoCD Property Page" [HKEY_CLASSES_ROOT\CLSID\{8025781B-7405-42F4-B6FC-C1FB826A11F2}\InprocServer32] @="C:\\WINDOWS\\system32\\htvcdsvcd.ax" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{80274203-490D-40FF-95A0-917F5EB5A3BF}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{80274203-490D-40FF-95A0-917F5EB5A3BF}\InProcServer32] @="c:\\PROGRA~1\\FICHIE~1\\mcafee\\mna\\MCNASV~1.DLL" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{825F2E3B-565A-4195-AA90-D535F6E31D36}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{825F2E3B-565A-4195-AA90-D535F6E31D36}\InProcServer32] @="c:\\PROGRA~1\\FICHIE~1\\mcafee\\HACKER~1\\hwapips.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{828030A1-22C1-4009-854F-8E305202313F}] [HKEY_CLASSES_ROOT\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGRAP~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ProgID] @="IMAPP.IMAPP.1" [HKEY_CLASSES_ROOT\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\VersionIndependentProgID] @="IMAPP.IMAPP" [HKEY_CLASSES_ROOT\CLSID\{83748E14-8F60-4AB3-8A81-7CECBE2B1CBE}] @="MpsMISPImpl Class" "AppID"="{267BBEBC-C05C-489E-823B-026E6EA456BE}" [HKEY_CLASSES_ROOT\CLSID\{83748E14-8F60-4AB3-8A81-7CECBE2B1CBE}\InprocServer32] @="c:\\PROGRA~1\\mcafee\\mps\\mpsmisp.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{83748E14-8F60-4AB3-8A81-7CECBE2B1CBE}\ProgID] @="MpsMISP.MpsMISPImpl.1" [HKEY_CLASSES_ROOT\CLSID\{83748E14-8F60-4AB3-8A81-7CECBE2B1CBE}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{83748E14-8F60-4AB3-8A81-7CECBE2B1CBE}\TypeLib] @="{EAD6E826-2F75-4030-92E4-7064B727E1A2}" [HKEY_CLASSES_ROOT\CLSID\{83748E14-8F60-4AB3-8A81-7CECBE2B1CBE}\VersionIndependentProgID] @="MpsMISP.MpsMISPImpl" [HKEY_CLASSES_ROOT\CLSID\{884C860E-C24E-4E3D-9A4D-77A32707C6A6}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{884C860E-C24E-4E3D-9A4D-77A32707C6A6}\InProcServer32] @="c:\\PROGRA~1\\mcafee\\msc\\mcnmcsps.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{94478404-6236-40C4-8850-DF09CE6D95BC}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{94478404-6236-40C4-8850-DF09CE6D95BC}\InProcServer32] @="c:\\PROGRA~1\\mcafee\\VIRUSS~1\\mcvsps.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}] @="MpsConfig Class" "AppID"="{267BBEBC-C05C-489E-823B-026E6EA456BE}" [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\Control] [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\Implemented Categories] [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}] [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}] [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\InprocServer32] @="c:\\PROGRA~1\\mcafee\\mps\\mpsmisp.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\ProgID] @="MpsMISP.MpsConfig.1" [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\ToolboxBitmap32] @="c:\\PROGRA~1\\mcafee\\mps\\mpsmisp.dll, 102" [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\TypeLib] @="{EAD6E826-2F75-4030-92E4-7064B727E1A2}" [HKEY_CLASSES_ROOT\CLSID\{94807D76-62F1-4C85-B794-D0B29E29DAAE}\VersionIndependentProgID] @="MpsMISP.MpsConfig" [HKEY_CLASSES_ROOT\CLSID\{94F5EA4D-7E59-4388-9B8D-151501CF480B}] @="McAfee Proxy Service" "AppID"="{70AE37AD-5507-4fe0-9691-563A55D71F18}" [HKEY_CLASSES_ROOT\CLSID\{94F5EA4D-7E59-4388-9B8D-151501CF480B}\LocalServer32] @="C:\\PROGRA~1\\FICHIE~1\\mcafee\\mcproxy\\mcproxy.exe" [HKEY_CLASSES_ROOT\CLSID\{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}] "AppID"="{7178B45D-568D-4024-95FC-BC564C34542E}" @="MSN USNSVC" [HKEY_CLASSES_ROOT\CLSID\{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\usnsvc.exe" [HKEY_CLASSES_ROOT\CLSID\{98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1}\ProgID] @="Microsoft.MSN.MCC.USNJSVC.1" [HKEY_CLASSES_ROOT\CLSID\{99E69691-3266-4EA2-97FF-DFC40CF90DDC}] @="MpsLogger Class" "AppID"="{267BBEBC-C05C-489E-823B-026E6EA456BE}" [HKEY_CLASSES_ROOT\CLSID\{99E69691-3266-4EA2-97FF-DFC40CF90DDC}\InprocServer32] @="c:\\PROGRA~1\\mcafee\\mps\\mpsmisp.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{99E69691-3266-4EA2-97FF-DFC40CF90DDC}\ProgID] @="MpsMISP.MpsLogger.1" [HKEY_CLASSES_ROOT\CLSID\{99E69691-3266-4EA2-97FF-DFC40CF90DDC}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{99E69691-3266-4EA2-97FF-DFC40CF90DDC}\TypeLib] @="{EAD6E826-2F75-4030-92E4-7064B727E1A2}" [HKEY_CLASSES_ROOT\CLSID\{99E69691-3266-4EA2-97FF-DFC40CF90DDC}\VersionIndependentProgID] @="MpsMISP.MpsLogger" [HKEY_CLASSES_ROOT\CLSID\{AB92D412-E57E-473b-B9A2-3BAE647D9C8C}] @="McReportLog Class" "AppID"="{DEFCCD2D-5B05-4841-A53E-C46AF9A2BDD5}" [HKEY_CLASSES_ROOT\CLSID\{AB92D412-E57E-473b-B9A2-3BAE647D9C8C}\LocalServer32] @="\"c:\\program files\\mcafee\\msc\\mclogsrv.exe\"" [HKEY_CLASSES_ROOT\CLSID\{AD97990E-D79A-4CC0-BCA1-341ED2F1C24E}] @="PSPopupBlockedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{AD97990E-D79A-4CC0-BCA1-341ED2F1C24E}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{AD97990E-D79A-4CC0-BCA1-341ED2F1C24E}\ProgID] @="MpsEventHandler.PSPopupBlockedEventHa.1" [HKEY_CLASSES_ROOT\CLSID\{AD97990E-D79A-4CC0-BCA1-341ED2F1C24E}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{AD97990E-D79A-4CC0-BCA1-341ED2F1C24E}\VersionIndependentProgID] @="MpsEventHandler.PSPopupBlockedEventHand" [HKEY_CLASSES_ROOT\CLSID\{AE9F578D-E062-499F-BA30-1ACEFA76F34E}] @="PSAccessDeniedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{AE9F578D-E062-499F-BA30-1ACEFA76F34E}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{AE9F578D-E062-499F-BA30-1ACEFA76F34E}\ProgID] @="MpsEventHandler.PSAccessDeniedEventHa.1" [HKEY_CLASSES_ROOT\CLSID\{AE9F578D-E062-499F-BA30-1ACEFA76F34E}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{AE9F578D-E062-499F-BA30-1ACEFA76F34E}\VersionIndependentProgID] @="MpsEventHandler.PSAccessDeniedEventHand" [HKEY_CLASSES_ROOT\CLSID\{B1E52F24-060D-45F5-8697-991F8D7AC83B}] @="PSPIIDetectedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{B1E52F24-060D-45F5-8697-991F8D7AC83B}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{B1E52F24-060D-45F5-8697-991F8D7AC83B}\ProgID] @="MpsEventHandler.PSPIIDetectedEventHan.1" [HKEY_CLASSES_ROOT\CLSID\{B1E52F24-060D-45F5-8697-991F8D7AC83B}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{B1E52F24-060D-45F5-8697-991F8D7AC83B}\VersionIndependentProgID] @="MpsEventHandler.PSPIIDetectedEventHandl" [HKEY_CLASSES_ROOT\CLSID\{B2C86B23-DE6A-4B0E-A4C2-0EF039A0392A}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{B2C86B23-DE6A-4B0E-A4C2-0EF039A0392A}\InProcServer32] @="c:\\PROGRA~1\\FICHIE~1\\mcafee\\core\\mccoreps.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{B5BAD031-12CB-465E-82D6-11B5C536BCD9}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{B5BAD031-12CB-465E-82D6-11B5C536BCD9}\InProcServer32] @="c:\\PROGRA~1\\mcafee\\msc\\mcshllps.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{BD28FB5B-B2D0-4BA8-9755-618B29A95785}] @="UserHelper Class" "AppID"="{267BBEBC-C05C-489E-823B-026E6EA456BE}" [HKEY_CLASSES_ROOT\CLSID\{BD28FB5B-B2D0-4BA8-9755-618B29A95785}\InprocServer32] @="c:\\PROGRA~1\\mcafee\\mps\\mpsmisp.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{BD28FB5B-B2D0-4BA8-9755-618B29A95785}\ProgID] @="MpsMISP.UserHelper.1" [HKEY_CLASSES_ROOT\CLSID\{BD28FB5B-B2D0-4BA8-9755-618B29A95785}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{BD28FB5B-B2D0-4BA8-9755-618B29A95785}\TypeLib] @="{EAD6E826-2F75-4030-92E4-7064B727E1A2}" [HKEY_CLASSES_ROOT\CLSID\{BD28FB5B-B2D0-4BA8-9755-618B29A95785}\VersionIndependentProgID] @="MpsMISP.UserHelper" [HKEY_CLASSES_ROOT\CLSID\{bfe639ee-762e-46c4-ae7c-3c34ccc317ff}] @="CddbCredit Class" [HKEY_CLASSES_ROOT\CLSID\{bfe639ee-762e-46c4-ae7c-3c34ccc317ff}\InprocServer32] @="C:\\Program Files\\Winamp\\Plugins\\cddbcontrolwinamp.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{bfe639ee-762e-46c4-ae7c-3c34ccc317ff}\ProgID] @="CDDBControlWinamp5.CddbCredit.1" [HKEY_CLASSES_ROOT\CLSID\{bfe639ee-762e-46c4-ae7c-3c34ccc317ff}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{bfe639ee-762e-46c4-ae7c-3c34ccc317ff}\TypeLib] @="{092c84ce-ce92-439f-9c12-997beea855d2}" [HKEY_CLASSES_ROOT\CLSID\{bfe639ee-762e-46c4-ae7c-3c34ccc317ff}\VersionIndependentProgID] @="CDDBControlWinamp5.CddbCredit" [HKEY_CLASSES_ROOT\CLSID\{C05729E9-54C0-4846-8A7A-B5FE2742862C}] @="PSSignInRequiredEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{C05729E9-54C0-4846-8A7A-B5FE2742862C}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{C05729E9-54C0-4846-8A7A-B5FE2742862C}\ProgID] @="MpsEventHandler.PSSignInRequiredEvent.1" [HKEY_CLASSES_ROOT\CLSID\{C05729E9-54C0-4846-8A7A-B5FE2742862C}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{C05729E9-54C0-4846-8A7A-B5FE2742862C}\VersionIndependentProgID] @="MpsEventHandler.PSSignInRequiredEventHa" [HKEY_CLASSES_ROOT\CLSID\{c2e21ac1-675c-4cae-ba0c-98d25a5e5b84}] @="CddbDisc Class" [HKEY_CLASSES_ROOT\CLSID\{c2e21ac1-675c-4cae-ba0c-98d25a5e5b84}\InprocServer32] @="C:\\Program Files\\Winamp\\Plugins\\cddbcontrolwinamp.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{c2e21ac1-675c-4cae-ba0c-98d25a5e5b84}\ProgID] @="CDDBControlWinamp5.CddbDisc.1" [HKEY_CLASSES_ROOT\CLSID\{c2e21ac1-675c-4cae-ba0c-98d25a5e5b84}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{c2e21ac1-675c-4cae-ba0c-98d25a5e5b84}\TypeLib] @="{092c84ce-ce92-439f-9c12-997beea855d2}" [HKEY_CLASSES_ROOT\CLSID\{c2e21ac1-675c-4cae-ba0c-98d25a5e5b84}\VersionIndependentProgID] @="CDDBControlWinamp5.CddbDisc" [HKEY_CLASSES_ROOT\CLSID\{C5F86999-8022-476E-89A2-58D07DC5A5F8}] @="PSUrlVisitedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{C5F86999-8022-476E-89A2-58D07DC5A5F8}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{C5F86999-8022-476E-89A2-58D07DC5A5F8}\ProgID] @="MpsEventHandler.PSUrlVisitedEventHand.1" [HKEY_CLASSES_ROOT\CLSID\{C5F86999-8022-476E-89A2-58D07DC5A5F8}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{C5F86999-8022-476E-89A2-58D07DC5A5F8}\VersionIndependentProgID] @="MpsEventHandler.PSUrlVisitedEventHandle" [HKEY_CLASSES_ROOT\CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53}] @="CPub Object" "AppID"="" [HKEY_CLASSES_ROOT\CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53}\InprocServer32] @="c:\\PROGRA~1\\mcafee\\mps\\mcpopup.dll" "ThreadingModel"="apartment" [HKEY_CLASSES_ROOT\CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53}\ProgID] @="McAfee.PopupBlocker.1" [HKEY_CLASSES_ROOT\CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53}\TypeLib] @="{90A52F08-64AC-4DC6-9D7D-4516670275D3}" [HKEY_CLASSES_ROOT\CLSID\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53}\VersionIndependentProgID] @="McAfee.PopupBlocker" [HKEY_CLASSES_ROOT\CLSID\{C78AA488-7868-4005-914C-F74678B49CFF}] @="PSCookieBlockedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{C78AA488-7868-4005-914C-F74678B49CFF}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{C78AA488-7868-4005-914C-F74678B49CFF}\ProgID] @="MpsEventHandler.PSCookieBlockedEventH.1" [HKEY_CLASSES_ROOT\CLSID\{C78AA488-7868-4005-914C-F74678B49CFF}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{C78AA488-7868-4005-914C-F74678B49CFF}\VersionIndependentProgID] @="MpsEventHandler.PSCookieBlockedEventHan" [HKEY_CLASSES_ROOT\CLSID\{C9109C64-0A3B-4CDF-A60A-5ECCD659D44E}] @="PSKeywordBlockedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{C9109C64-0A3B-4CDF-A60A-5ECCD659D44E}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{C9109C64-0A3B-4CDF-A60A-5ECCD659D44E}\ProgID] @="MpsEventHandler.PSKeywordDetec.1" [HKEY_CLASSES_ROOT\CLSID\{C9109C64-0A3B-4CDF-A60A-5ECCD659D44E}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{C9109C64-0A3B-4CDF-A60A-5ECCD659D44E}\VersionIndependentProgID] @="MpsEventHandler.PSKeywordDetecti" [HKEY_CLASSES_ROOT\CLSID\{C9738C6A-123E-4CD7-95F6-923C5E8B3658}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{C9738C6A-123E-4CD7-95F6-923C5E8B3658}\InProcServer32] @="C:\\Program Files\\Softwin\\BitDefender10\\bdelev.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}] @="Java Plug-in 1.6.0_04" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\InprocServer32] @="C:\\Program Files\\Java\\jre1.6.0_05\\bin\\ssv.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}] @="Java Plug-in 1.6.0_04" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}\InprocServer32] @="C:\\Program Files\\Java\\jre1.6.0_05\\bin\\ssv.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}] @="Java Plug-in 1.6.0_04" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}\InprocServer32] @="C:\\Program Files\\Java\\jre1.6.0_05\\bin\\ssv.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}] @="Java Plug-in 1.6.0_05" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\InprocServer32] @="C:\\Program Files\\Java\\jre1.6.0_05\\bin\\ssv.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}] @="Java Plug-in 1.6.0_05" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}\InprocServer32] @="C:\\Program Files\\Java\\jre1.6.0_05\\bin\\ssv.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}] @="Java Plug-in 1.6.0_05" [HKEY_CLASSES_ROOT\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}\InprocServer32] @="C:\\Program Files\\Java\\jre1.6.0_05\\bin\\ssv.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{CDC11E15-A6D9-43D2-9518-F043287D32B1}] @="PSWebBugBlockedEventHandler Class" "AppID"="{4825782D-C87D-4B1F-8659-E807325CA99E}" [HKEY_CLASSES_ROOT\CLSID\{CDC11E15-A6D9-43D2-9518-F043287D32B1}\LocalServer32] @="\"C:\\Program Files\\McAfee\\MPS\\mpsevh.exe\"" [HKEY_CLASSES_ROOT\CLSID\{CDC11E15-A6D9-43D2-9518-F043287D32B1}\ProgID] @="MpsEventHandler.PSWebBugBlockedEventH.1" [HKEY_CLASSES_ROOT\CLSID\{CDC11E15-A6D9-43D2-9518-F043287D32B1}\TypeLib] @="{38CAF31C-7235-44E1-9E9A-4FA92717E522}" [HKEY_CLASSES_ROOT\CLSID\{CDC11E15-A6D9-43D2-9518-F043287D32B1}\VersionIndependentProgID] @="MpsEventHandler.PSWebBugBlockedEventHan" [HKEY_CLASSES_ROOT\CLSID\{D360501E-DC73-4de6-A61C-21925AED7835}] @="CWindowEventHandler Object" "AppID"="" [HKEY_CLASSES_ROOT\CLSID\{D360501E-DC73-4de6-A61C-21925AED7835}\InprocServer32] @="c:\\PROGRA~1\\mcafee\\mps\\mcpopup.dll" "ThreadingModel"="apartment" [HKEY_CLASSES_ROOT\CLSID\{D360501E-DC73-4de6-A61C-21925AED7835}\ProgID] @="McAfee.PubWindowEventHandler.1" [HKEY_CLASSES_ROOT\CLSID\{D360501E-DC73-4de6-A61C-21925AED7835}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{D360501E-DC73-4de6-A61C-21925AED7835}\TypeLib] @="{90A52F08-64AC-4DC6-9D7D-4516670275D3}" [HKEY_CLASSES_ROOT\CLSID\{D360501E-DC73-4de6-A61C-21925AED7835}\VersionIndependentProgID] @="McAfee.PubWindowEventHandler" [HKEY_CLASSES_ROOT\CLSID\{D74C0C0E-14F3-402C-9379-3E2BD0BF5D06}] "AppID"="{D74C0C0E-14F3-402C-9379-3E2BD0BF5D07}" @="WL Hardware Device Manager" [HKEY_CLASSES_ROOT\CLSID\{D74C0C0E-14F3-402C-9379-3E2BD0BF5D06}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\DEVICE~1\\msgrdvmn.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{D74C0C0E-14F3-402C-9379-3E2BD0BF5D06}\ProgID] @="MSN.V2SDeviceHandler.1" [HKEY_CLASSES_ROOT\CLSID\{D74C0C0E-14F3-402C-9379-3E2BD0BF5D06}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{D74C0C0E-14F3-402C-9379-3E2BD0BF5D06}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{D74C0C0E-14F3-402C-9379-3E2BD0BF5D06}\VersionIndependentProgID] @="MSN.V2SDeviceHandler" [HKEY_CLASSES_ROOT\CLSID\{DDA1154C-204B-41D7-BFE7-7907C6BA9D56}] @="McReportRecentEvent Class" "AppID"="{DEFCCD2D-5B05-4841-A53E-C46AF9A2BDD5}" [HKEY_CLASSES_ROOT\CLSID\{DDA1154C-204B-41D7-BFE7-7907C6BA9D56}\LocalServer32] @="\"c:\\program files\\mcafee\\msc\\mclogsrv.exe\"" [HKEY_CLASSES_ROOT\CLSID\{E13AAC70-70AE-4988-808C-B267F2C20E79}] [HKEY_CLASSES_ROOT\CLSID\{E13AAC70-70AE-4988-808C-B267F2C20E79}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{E13AAC70-70AE-4988-808C-B267F2C20E79}\ProgID] @="MSNMessenger.P4QuickLaunch" [HKEY_CLASSES_ROOT\CLSID\{E13AAC70-70AE-4988-808C-B267F2C20E79}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{E13AAC70-70AE-4988-808C-B267F2C20E79}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{E13AAC70-70AE-4988-808C-B267F2C20E79}\VersionIndependentProgID] @="MSNMessenger.P4QuickLaunch.1" [HKEY_CLASSES_ROOT\CLSID\{E1771B7F-98BE-407F-BA67-AA16ADA5D0C5}] [HKEY_CLASSES_ROOT\CLSID\{E1771B7F-98BE-407F-BA67-AA16ADA5D0C5}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{E1771B7F-98BE-407F-BA67-AA16ADA5D0C5}\ProgID] @="MSNMessenger.Hotmail2Control" [HKEY_CLASSES_ROOT\CLSID\{E1771B7F-98BE-407F-BA67-AA16ADA5D0C5}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{E1771B7F-98BE-407F-BA67-AA16ADA5D0C5}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{E1771B7F-98BE-407F-BA67-AA16ADA5D0C5}\VersionIndependentProgID] @="MSNMessenger.Hotmail2Control.1" [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}] @="VideoLAN VLC ActiveX Plugin" [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\Control] [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\Implemented Categories] [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\Implemented Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}] [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}] [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}] [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}] [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\InprocServer32] @="C:\\Program Files\\MaxSoftware\\axvlc.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\MiscStatus] [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\MiscStatus\1] @="131473" [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\ProgID] @="VideoLAN.VLCPlugin.1" [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\ToolboxBitmap32] @="C:\\Program Files\\MaxSoftware\\axvlc.dll,1" [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\TypeLib] @="{DF2BBE39-40A8-433B-A279-073F48DA94B6}" [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\VersionIndependentProgID] @="VideoLAN.VLCPlugin" [HKEY_CLASSES_ROOT\CLSID\{EB045914-CB36-4731-82D6-0BA9644E264B}] @="PSFactoryBuffer" [HKEY_CLASSES_ROOT\CLSID\{EB045914-CB36-4731-82D6-0BA9644E264B}\InProcServer32] @="c:\\PROGRA~1\\mcafee\\msc\\mcnmcsps.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{efe52f1e-1427-4ce9-acfe-0e050e498e63}] @="CddbCacheManager Class" [HKEY_CLASSES_ROOT\CLSID\{efe52f1e-1427-4ce9-acfe-0e050e498e63}\InprocServer32] @="C:\\Program Files\\Winamp\\Plugins\\cddbcontrolwinamp.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{efe52f1e-1427-4ce9-acfe-0e050e498e63}\ProgID] @="CDDBControlWinamp5.CddbCacheManager.1" [HKEY_CLASSES_ROOT\CLSID\{efe52f1e-1427-4ce9-acfe-0e050e498e63}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{efe52f1e-1427-4ce9-acfe-0e050e498e63}\TypeLib] @="{092c84ce-ce92-439f-9c12-997beea855d2}" [HKEY_CLASSES_ROOT\CLSID\{efe52f1e-1427-4ce9-acfe-0e050e498e63}\VersionIndependentProgID] @="CDDBControlWinamp5.CddbCacheManager" [HKEY_CLASSES_ROOT\CLSID\{F06608C7-1874-4EEA-B3B2-DF99EBB144B8}] [HKEY_CLASSES_ROOT\CLSID\{F06608C7-1874-4EEA-B3B2-DF99EBB144B8}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{F06608C7-1874-4EEA-B3B2-DF99EBB144B8}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{F06608C7-1874-4EEA-B3B2-DF99EBB144B8}\ProgID] @="MSNMessenger.MessengerContentInstaller" [HKEY_CLASSES_ROOT\CLSID\{F06608C7-1874-4EEA-B3B2-DF99EBB144B8}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{F06608C7-1874-4EEA-B3B2-DF99EBB144B8}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{F06608C7-1874-4EEA-B3B2-DF99EBB144B8}\VersionIndependentProgID] @="MSNMessenger.MessengerContentInstaller.1" [HKEY_CLASSES_ROOT\CLSID\{f1110c60-736a-4d58-8e2a-4935dfcf9ac7}] @="CddbFullName Class" [HKEY_CLASSES_ROOT\CLSID\{f1110c60-736a-4d58-8e2a-4935dfcf9ac7}\InprocServer32] @="C:\\Program Files\\Winamp\\Plugins\\cddbcontrolwinamp.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{f1110c60-736a-4d58-8e2a-4935dfcf9ac7}\ProgID] @="CDDBControlWinamp5.CddbFullName.1" [HKEY_CLASSES_ROOT\CLSID\{f1110c60-736a-4d58-8e2a-4935dfcf9ac7}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{f1110c60-736a-4d58-8e2a-4935dfcf9ac7}\TypeLib] @="{092c84ce-ce92-439f-9c12-997beea855d2}" [HKEY_CLASSES_ROOT\CLSID\{f1110c60-736a-4d58-8e2a-4935dfcf9ac7}\VersionIndependentProgID] @="CDDBControlWinamp5.CddbFullName" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}] @="CDDBWinamp5Control Class" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\Control] [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\InprocServer32] @="C:\\Program Files\\Winamp\\Plugins\\cddbcontrolwinamp.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\Insertable] [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\MiscStatus] @="0" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\MiscStatus\1] @="135569" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\ProgID] @="CDDBControlWinamp5.CDDBWinamp5Control.1" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\ToolboxBitmap32] @="C:\\Program Files\\Winamp\\Plugins\\cddbcontrolwinamp.dll, 104" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\TypeLib] @="{092c84ce-ce92-439f-9c12-997beea855d2}" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}\VersionIndependentProgID] @="CDDBControlWinamp5.CDDBWinamp5Control" [HKEY_CLASSES_ROOT\CLSID\{F4C30BB5-D7FC-4D60-9D49-7C6B67C3592D}] [HKEY_CLASSES_ROOT\CLSID\{F4C30BB5-D7FC-4D60-9D49-7C6B67C3592D}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{F4C30BB5-D7FC-4D60-9D49-7C6B67C3592D}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{F4C30BB5-D7FC-4D60-9D49-7C6B67C3592D}\ProgID] @="MSNMessenger.MessengerApp" [HKEY_CLASSES_ROOT\CLSID\{F4C30BB5-D7FC-4D60-9D49-7C6B67C3592D}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{F4C30BB5-D7FC-4D60-9D49-7C6B67C3592D}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{F4C30BB5-D7FC-4D60-9D49-7C6B67C3592D}\VersionIndependentProgID] @="MSNMessenger.MessengerApp.1" [HKEY_CLASSES_ROOT\CLSID\{F5F545A6-39C4-40B5-814D-B45040A89FB5}] [HKEY_CLASSES_ROOT\CLSID\{F5F545A6-39C4-40B5-814D-B45040A89FB5}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{F5F545A6-39C4-40B5-814D-B45040A89FB5}\LocalServer32] @="C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{F5F545A6-39C4-40B5-814D-B45040A89FB5}\ProgID] @="MSNMessenger.MsgrObject" [HKEY_CLASSES_ROOT\CLSID\{F5F545A6-39C4-40B5-814D-B45040A89FB5}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{F5F545A6-39C4-40B5-814D-B45040A89FB5}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{F5F545A6-39C4-40B5-814D-B45040A89FB5}\VersionIndependentProgID] @="MSNMessenger.MsgrObject.1" [HKEY_CLASSES_ROOT\CLSID\{F81CD990-910B-4bbf-9CB3-6A77F3D697B3}] @="" [HKEY_CLASSES_ROOT\CLSID\{F81CD990-910B-4bbf-9CB3-6A77F3D697B3}\InprocServer32] @="C:\\PROGRA~1\\MSNMES~1\\MSGSC8~1.DLL" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{F81CD990-910B-4bbf-9CB3-6A77F3D697B3}\LocalServer32] @="C:\\Program Files\\MSN Messenger\\msnmsgr.exe" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{F81CD990-910B-4bbf-9CB3-6A77F3D697B3}\ProgID] @="MSNMessenger.UIAutomation" [HKEY_CLASSES_ROOT\CLSID\{F81CD990-910B-4bbf-9CB3-6A77F3D697B3}\Programmable] @="" [HKEY_CLASSES_ROOT\CLSID\{F81CD990-910B-4bbf-9CB3-6A77F3D697B3}\TypeLib] @="" [HKEY_CLASSES_ROOT\CLSID\{F81CD990-910B-4bbf-9CB3-6A77F3D697B3}\Version] @="1.0" [HKEY_CLASSES_ROOT\CLSID\{F81CD990-910B-4bbf-9CB3-6A77F3D697B3}\VersionIndependentProgID] @="MSNMessenger.UIAutomation.1" [HKEY_CLASSES_ROOT\CLSID\{F9668ADA-FC6B-47F4-8381-DE861DBA5115}] @="CDocEventHandler Object" "AppID"="" [HKEY_CLASSES_ROOT\CLSID\{F9668ADA-FC6B-47F4-8381-DE861DBA5115}\InprocServer32] @="c:\\PROGRA~1\\mcafee\\mps\\mcpopup.dll" "ThreadingModel"="apartment" [HKEY_CLASSES_ROOT\CLSID\{F9668ADA-FC6B-47F4-8381-DE861DBA5115}\ProgID] @="McAfee.PubDocEventHandler.1" [HKEY_CLASSES_ROOT\CLSID\{F9668ADA-FC6B-47F4-8381-DE861DBA5115}\Programmable] [HKEY_CLASSES_ROOT\CLSID\{F9668ADA-FC6B-47F4-8381-DE861DBA5115}\TypeLib] @="{90A52F08-64AC-4DC6-9D7D-4516670275D3}" [HKEY_CLASSES_ROOT\CLSID\{F9668ADA-FC6B-47F4-8381-DE861DBA5115}\VersionIndependentProgID] @="McAfee.PubDocEventHandler" [HKEY_CLASSES_ROOT\Applications\FIREFOX.EXE\shell\open] [HKEY_CLASSES_ROOT\Applications\FIREFOX.EXE\shell\open\command] @="C:\\PROGRA~1\\MOZILL~1\\FIREFOX.EXE -requestPending -osint -url \"%1\"" [HKEY_CLASSES_ROOT\Applications\FIREFOX.EXE\shell\open\ddeexec] @="\"%1\",,0,0,,,," "NoActivateHandler"="" [HKEY_CLASSES_ROOT\Applications\FIREFOX.EXE\shell\open\ddeexec\Application] @="Firefox" [HKEY_CLASSES_ROOT\Applications\FIREFOX.EXE\shell\open\ddeexec\Topic] @="WWW_OpenURL" [HKEY_CLASSES_ROOT\Applications\moviemk.exe] [HKEY_CLASSES_ROOT\Applications\moviemk.exe\shell] "FriendlyCache"="Movie Maker" [HKEY_CLASSES_ROOT\Applications\vmidi.exe\shell\open] @="&Open" [HKEY_CLASSES_ROOT\Applications\vmidi.exe\shell\open\command] @="\"C:\\Program Files\\vanBasco's Karaoke Player\\vmidi.exe\"" [HKEY_CLASSES_ROOT\Applications\vmidi.exe\shell\open\ddeexec] @="[load(\"%1\")]" [HKEY_CLASSES_ROOT\Applications\vmidi.exe\shell\play] @="&Play" [HKEY_CLASSES_ROOT\Applications\vmidi.exe\shell\play\command] @="\"C:\\Program Files\\vanBasco's Karaoke Player\\vmidi.exe\"" [HKEY_CLASSES_ROOT\Applications\vmidi.exe\shell\play\ddeexec] @="[load(\"%1\")][play]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe] @="C:\\WINDOWS\\system32\\cmmgr32.exe" "Path"="C:\\WINDOWS\\system32" "CmstpExtensionDll"="C:\\WINDOWS\\system32\\cmcfg32.dll" "CMInternalVersion"="1.2" "CmNative"=dword:00000001 "ProfilesUpgraded"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\ldm.exe] "Path"="C:\\Program Files\\Logitech\\Desktop Messenger" @="C:\\Program Files\\Logitech\\Desktop Messenger\\ldm.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\Net Blitz II.exe] @="C:\\Documents and Settings\\LOUTE\\Mes documents\\Mes jeux\\Echecs _2\\Net Blitz II\\Net Blitz II.exe" "Path"="c:\\documents and settings\\loute\\mes documents\\mes jeux\\echecs _2\\net blitz ii" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\PL-2303 DriverInstaller.exe] "Path"="C:\\WINDOWS\\" @="C:\\WINDOWS\\PL-2303 DriverInstaller.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\QuickCam.exe] @="C:\\Program Files\\Logitech\\Video\\QuickCam.exe" "Path"="C:\\Program Files\\Logitech\\Video" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\VMidi.exe] @="C:\\Program Files\\vanBasco's Karaoke Player\\VMidi.exe" "Path"="C:\\Program Files\\vanBasco's Karaoke Player" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\YourApp.exe] "Path"="C:\\Program Files\\Gemtek 11Mbps WMonitor" @="C:\\Program Files\\Gemtek 11Mbps WMonitor\\YourApp.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "en.hlp"="C:\\WINDOWS\\ime\\Shared\\imepad" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "EQNEDT32.cnt"="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Equation\\" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "nwind9.cnt"="C:\\Program Files\\Microsoft Office\\Office10\\Samples\\" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "nwind9.hlp"="C:\\Program Files\\Microsoft Office\\Office10\\Samples\\" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "nwindcs9.cnt"="C:\\Program Files\\Microsoft Office\\Office10\\Samples\\" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "nwindcs9.hlp"="C:\\Program Files\\Microsoft Office\\Office10\\Samples\\" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "fpmmcglo.hlp"="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Web Server Extensions\\50\\bin\\1036\\" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "VEENOB3.HLP"="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\VBA" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help] "VEENOB3.CNT"="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\VBA" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help] "CHTPADEN.CHM"="Folder:IMEPADEN.CHM" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\FileCDDefault\\"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\Default\\"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\Fichiers communs\\NewTech Infosystems\\LiveUpdate\\Default\\"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\JCMDefault\\"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\WEDefault\\"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\DFDefault\\"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\NewTech Infosystems\\NTI Backup NOW! 4\\Default\\"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\WINDOWS\\winsxs\\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\\"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\McAfee Wireless Security\\"="1" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\Microsoft Games\\Age of Empires III\\"="1" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Program Files\\Microsoft Games\\"="1" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\TchecMeet] "DisplayName"="TchecMeet" "UninstallString"="C:\\Documents and Settings\\LOUTE\\Mes documents\\Uninstal.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows Mobile Device Handbook] "DisplayName"="Manuel de l'appareil Windows Mobile®" "DisplayVersion"="1.0" "Publisher"="Microsoft Corporation" "RegisterPath"="Software\\Microsoft\\Windows Mobile Getting Started Disc\\Device Handbook" "ProductName"="Manuel de l'appareil Windows Mobile®" "UninstallString"="C:\\Program Files\\Windows Mobile Device Handbook\\Windows Mobile Device Handbook\\Bin\\DHUninstall.exe" "DHBWindowTitle"="Manuel de l'appareil Windows Mobile®" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Dofus 1.20.0] "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,80,08,25,00,00,00,00,00,f0,3a,\ 92,f6,09,c8,01,01,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\ 61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,44,00,6f,00,66,00,75,\ 00,73,00,5c,00,44,00,6f,00,66,00,75,00,73,00,2e,00,65,00,78,00,65,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB917283.T1_1ToU93_1] "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\ 00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB922770.T1_1ToU168_1] "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\ 00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LimeWire] "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,80,61,01,00,00,00,00,00,70,79,\ 4b,5b,d4,c6,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\ 61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4c,00,69,00,6d,00,65,\ 00,57,00,69,00,72,00,65,00,5c,00,4c,00,69,00,6d,00,65,00,57,00,69,00,72,00,\ 65,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\M928366] "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\ 00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MaxTV Online2006] "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,00,75,01,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (3.0b1)] "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,80,a6,01,00,00,00,00,00,d8,9b,\ 39,b7,3a,c8,01,10,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\ 61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,6f,00,7a,00,69,\ 00,6c,00,6c,00,61,00,20,00,46,00,69,00,72,00,65,00,66,00,6f,00,78,00,20,00,\ 33,00,20,00,42,00,65,00,74,00,61,00,20,00,31,00,5c,00,66,00,69,00,72,00,65,\ 00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (3.0b2)] "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,80,a6,01,00,00,00,00,00,d8,90,\ 36,25,44,c8,01,2a,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\ 61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,6f,00,7a,00,69,\ 00,6c,00,6c,00,61,00,20,00,46,00,69,00,72,00,65,00,66,00,6f,00,78,00,20,00,\ 33,00,20,00,42,00,65,00,74,00,61,00,20,00,31,00,5c,00,66,00,69,00,72,00,65,\ 00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp] "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,00,de,02,00,00,00,00,00,f0,d2,\ 40,5c,f5,c6,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\ 61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,57,00,69,00,6e,00,61,\ 00,6d,00,70,00,5c,00,77,00,69,00,6e,00,61,00,6d,00,70,00,61,00,2e,00,65,00,\ 78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{0496D9E8-224B-4AFA-8F37-23B98D52F1EB}] "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}] "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,80,63,03,00,00,00,00,00,70,71,\ 02,ab,b6,c7,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\ 61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,47,00,6f,00,6f,00,67,\ 00,6c,00,65,00,5c,00,47,00,6f,00,6f,00,67,00,6c,00,65,00,20,00,45,00,61,00,\ 72,00,74,00,68,00,5c,00,67,00,6f,00,6f,00,67,00,6c,00,65,00,65,00,61,00,72,\ 00,74,00,68,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}] "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,ac,77,02,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{E22885AB-B503-46E2-8437-73BBC6BC5487}] "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,74,cd,01,00,00,00,00,00,f0,d2,\ 40,5c,f5,c6,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\ 61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,65,00,73,00,73,\ 00,65,00,6e,00,67,00,65,00,72,00,5c,00,6d,00,73,00,6d,00,73,00,67,00,73,00,\ 2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{F9FFD19E-B9BA-4C0C-B088-A385F9E9A15B}] "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,24,d8,03,00,00,00,00,00,58,90,\ 97,ff,1f,c8,01,08,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\ 61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,6f,00,66,00,74,\ 00,77,00,69,00,6e,00,5c,00,42,00,69,00,74,00,44,00,65,00,66,00,65,00,6e,00,\ 64,00,65,00,72,00,31,00,30,00,5c,00,62,00,64,00,6d,00,63,00,6f,00,6e,00,2e,\ 00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_CURRENT_USER\Software\3ivx] [HKEY_CURRENT_USER\Software\epk_extr] EWIDO: __________________________________________________ ewido anti-spyware online scanner http://www.ewido.net __________________________________________________ Name: TrackingCookie.Tradedoubler Path: C:\Documents and Settings\LOULOUTE\Cookies\louloute@tradedoubler[1].txt Risk: Medium Name: TrackingCookie.Serving-sys Path: C:\Documents and Settings\LOULOUTE\Cookies\louloute@serving-sys[2].txt Risk: Medium Name: TrackingCookie.Serving-sys Path: C:\Documents and Settings\LOULOUTE\Cookies\louloute@bs.serving-sys[2].txt Risk: Medium Name: TrackingCookie.Doubleclick Path: C:\Documents and Settings\LOULOUTE\Cookies\louloute@doubleclick[1].txt Risk: Medium Name: TrackingCookie.Adviva Path: C:\Documents and Settings\LOULOUTE\Cookies\louloute@adviva[2].txt Risk: Medium Name: TrackingCookie.Smartadserver Path: C:\Documents and Settings\LOULOUTE\Cookies\louloute@smartadserver[2].txt Risk: Medium Name: TrackingCookie.Webtrends Path: C:\Documents and Settings\LOULOUTE\Cookies\louloute@m.webtrends[1].txt Risk: Medium Name: TrackingCookie.Bluestreak Path: C:\Documents and Settings\LOULOUTE\Cookies\louloute@bluestreak[2].txt Risk: Medium Name: TrackingCookie.Skype Path: C:\WINDOWS\system32\config\systemprofile\Cookies\system@skype[1].txt Risk: Medium Name: TrackingCookie.Smartadserver Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@smartadserver[1].txt Risk: Medium Name: TrackingCookie.Doubleclick Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@doubleclick[1].txt Risk: Medium Name: TrackingCookie.Serving-sys Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@serving-sys[2].txt Risk: Medium Name: TrackingCookie.Mediaplex Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@mediaplex[1].txt Risk: Medium Name: TrackingCookie.Estat Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@estat[1].txt Risk: Medium Name: TrackingCookie.Hitbox Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@hitbox[2].txt Risk: Medium Name: TrackingCookie.Tradedoubler Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@tradedoubler[1].txt Risk: Medium Name: TrackingCookie.Hitbox Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@ehg-telecomitalia.hitbox[2].txt Risk: Medium Name: TrackingCookie.Serving-sys Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@bs.serving-sys[1].txt Risk: Medium Name: TrackingCookie.Atdmt Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@atdmt[2].txt Risk: Medium Name: TrackingCookie.Casinotropez Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@www.casinotropez[1].txt Risk: Medium Name: TrackingCookie.Webtrends Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@m.webtrends[2].txt Risk: Medium Name: TrackingCookie.2o7 Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@2o7[2].txt Risk: Medium Name: TrackingCookie.Bluestreak Path: C:\Documents and Settings\LOU.LOU_LOUTE\Cookies\lou@bluestreak[1].txt Risk: Medium Name: Dropper.Agent.dkn Path: C:\Documents and Settings\LOULOUTE\Mes documents\Downloads\_PANTHEON_ anglais test SVCD (Album).zip/Setup.exe Risk: High Name: Dropper.Agent.dkn Path: C:\Documents and Settings\LOULOUTE\Mes documents\Downloads\(Better Version) dofus 1 21 by TNT [Mix].zip/Setup.exe Risk: High Name: Dropper.Agent.dkn Path: C:\Documents and Settings\LOULOUTE\Mes documents\Downloads\www.torrent.to dofus 1 21 by DONE (Full).zip/Setup.exe Risk: High Name: Not-A-Virus.Hoax.Win32.Agent.o Path: C:\Documents and Settings\LOULOUTE\Bureau\LOU2\Mes documents\Downloads\----- mypal ----- 2007.zip/Setup.exe Risk: Low Name: Dropper.Agent.dtk Path: C:\Documents and Settings\LOULOUTE\Bureau\Web-MediaPlayer_setup.exe Risk: High Name: Dropper.Agent.dkn Path: C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP207\A0053975.exe Risk: High Name: Downloader.Agent.fct Path: C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP211\A0059355.exe Risk: High Name: Downloader.Agent.dwc Path: C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP211\A0059356.exe Risk: High Name: Downloader.Agent.dwe Path: C:\System Volume Information\_restore{0E53C2D2-603D-4B01-84F6-6DE602018BFB}\RP221\A0063586.exe Risk: High Name: Downloader.Agent.dwe Path: C:\_OTMoveIt\MovedFiles\03222008_143526\Documents and Settings\LOULOUTE\Application Data\WinButler\WinBuninstaller.exe Risk: High [HKEY_LOCAL_MACHINE\Software\lameme] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ExtraFilmHemmaAgent"="\"C:\\Program Files\\WistitiSoft\\Agent.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WLanCfg.exe"="C:\\Program Files\\Gemtek 11Mbps WMonitor\\WLanCfg.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.2\\Apps\\apdproxy.exe\"" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\IrfanView] "Order"=hex:08,00,00,00,02,00,00,00,f2,04,00,00,01,00,00,00,09,00,00,00,88,\ 00,00,00,00,00,00,00,7a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,68,00,\ 32,00,24,02,00,00,58,37,10,86,20,00,41,42,4f,55,54,49,7e,31,2e,4c,4e,4b,00,\ 00,3e,00,03,00,04,00,ef,be,58,37,10,86,5a,37,00,b0,14,00,00,00,41,00,62,00,\ 6f,00,75,00,74,00,20,00,49,00,72,00,66,00,61,00,6e,00,56,00,69,00,65,00,77,\ 00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,\ 1c,00,00,00,00,00,00,00,00,00,90,00,00,00,01,00,00,00,82,00,00,00,41,75,67,\ 4d,02,00,00,00,01,00,00,00,70,00,32,00,3a,02,00,00,58,37,10,86,20,00,41,56,\ 41,49,4c,41,7e,32,2e,4c,4e,4b,00,00,46,00,03,00,04,00,ef,be,58,37,10,86,5a,\ 37,00,b0,14,00,00,00,41,00,76,00,61,00,69,00,6c,00,61,00,62,00,6c,00,65,00,\ 20,00,4c,00,61,00,6e,00,67,00,75,00,61,00,67,00,65,00,73,00,2e,00,6c,00,6e,\ 00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,\ 00,00,00,00,8c,00,00,00,02,00,00,00,7e,00,00,00,41,75,67,4d,02,00,00,00,01,\ 00,00,00,6c,00,32,00,30,02,00,00,58,37,10,86,20,00,41,56,41,49,4c,41,7e,31,\ 2e,4c,4e,4b,00,00,42,00,03,00,04,00,ef,be,58,37,10,86,5a,37,00,b0,14,00,00,\ 00,41,00,76,00,61,00,69,00,6c,00,61,00,62,00,6c,00,65,00,20,00,50,00,6c,00,\ 75,00,67,00,49,00,6e,00,73,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,\ 00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,92,00,00,00,03,00,\ 00,00,84,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,72,00,32,00,30,02,00,\ 00,58,37,10,86,20,00,43,4f,4d,4d,41,4e,7e,31,2e,4c,4e,4b,00,00,48,00,03,00,\ 04,00,ef,be,58,37,10,86,5a,37,00,b0,14,00,00,00,43,00,6f,00,6d,00,6d,00,61,\ 00,6e,00,64,00,20,00,6c,00,69,00,6e,00,65,00,20,00,4f,00,70,00,74,00,69,00,\ 6f,00,6e,00,73,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,\ be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,86,00,00,00,04,00,00,00,78,00,\ 00,00,41,75,67,4d,02,00,00,00,01,00,00,00,66,00,32,00,2b,02,00,00,58,37,10,\ 86,20,00,49,52,46,41,4e,56,7e,31,2e,4c,4e,4b,00,00,3c,00,03,00,04,00,ef,be,\ 58,37,10,86,5a,37,00,b0,14,00,00,00,49,00,72,00,66,00,61,00,6e,00,56,00,69,\ 00,65,00,77,00,20,00,34,00,2e,00,31,00,30,00,2e,00,6c,00,6e,00,6b,00,00,00,\ 1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,96,\ 00,00,00,05,00,00,00,88,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,76,00,\ 32,00,9f,05,00,00,58,37,10,86,20,00,49,52,46,41,4e,56,7e,32,2e,4c,4e,4b,00,\ 00,4c,00,03,00,04,00,ef,be,58,37,10,86,5a,37,00,b0,14,00,00,00,49,00,72,00,\ 66,00,61,00,6e,00,56,00,69,00,65,00,77,00,20,00,2d,00,20,00,54,00,68,00,75,\ 00,6d,00,62,00,6e,00,61,00,69,00,6c,00,73,00,2e,00,6c,00,6e,00,6b,00,00,00,\ 1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,86,\ 00,00,00,06,00,00,00,78,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,66,00,\ 32,00,2b,02,00,00,58,37,10,86,20,00,49,52,46,41,4e,56,7e,33,2e,4c,4e,4b,00,\ 00,3c,00,03,00,04,00,ef,be,58,37,10,86,5a,37,00,b0,14,00,00,00,49,00,72,00,\ 66,00,61,00,6e,00,56,00,69,00,65,00,77,00,20,00,48,00,65,00,6c,00,70,00,2e,\ 00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,\ 00,00,00,00,00,00,00,00,90,00,00,00,07,00,00,00,82,00,00,00,41,75,67,4d,02,\ 00,00,00,01,00,00,00,70,00,32,00,3f,02,00,00,58,37,10,86,20,00,55,4e,49,4e,\ 53,54,7e,31,2e,4c,4e,4b,00,00,46,00,03,00,04,00,ef,be,58,37,10,86,5a,37,00,\ b0,14,00,00,00,55,00,6e,00,69,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,20,00,\ 49,00,72,00,66,00,61,00,6e,00,56,00,69,00,65,00,77,00,2e,00,6c,00,6e,00,6b,\ 00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,\ 00,00,7e,00,00,00,08,00,00,00,70,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,\ 00,5e,00,32,00,30,02,00,00,58,37,10,86,20,00,57,48,41,54,27,53,7e,31,2e,4c,\ 4e,4b,00,00,34,00,03,00,04,00,ef,be,58,37,10,86,5a,37,00,b0,14,00,00,00,57,\ 00,68,00,61,00,74,00,27,00,73,00,20,00,4e,00,65,00,77,00,2e,00,6c,00,6e,00,\ 6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,\ 00,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Microsoft Games] "Order"=hex:08,00,00,00,02,00,00,00,8e,00,00,00,01,00,00,00,01,00,00,00,82,\ 00,00,00,00,00,00,00,74,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,62,00,\ 31,00,00,00,00,00,04,37,1b,49,10,00,41,47,45,4f,46,45,7e,31,00,00,3c,00,03,\ 00,04,00,ef,be,04,37,1b,49,03,37,00,b0,14,00,00,00,41,00,67,00,65,00,20,00,\ 6f,00,66,00,20,00,45,00,6d,00,70,00,69,00,72,00,65,00,73,00,20,00,49,00,49,\ 00,49,00,00,00,18,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,18,00,00,00,00,00,\ 00,00,00,00 Et Malawrebytes : Malwarebytes' Anti-Malware 1.09 Version de la base de données: 521 Type de recherche: Examen complet (C:\|D:\|) Eléments examinés: 101497 Temps écoulé: 21 minute(s), 37 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 7 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 4 Fichier(s) infecté(s): 6 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): HKEY_CLASSES_ROOT\Interface\{6c51f7e9-8542-4f25-a30f-2060157752e1} (Trojan.Downloader) -> No action taken. HKEY_CLASSES_ROOT\Interface\{9d573d0e-663c-435f-bf31-2c4497373c41} (Trojan.Downloader) -> No action taken. HKEY_CLASSES_ROOT\Interface\{b1e68d42-02c4-465b-8368-5ed9b732e22d} (Trojan.Downloader) -> No action taken. HKEY_CLASSES_ROOT\Typelib\{90a52f08-64ac-4dc6-9d7d-4516670275d3} (Trojan.Downloader) -> No action taken. HKEY_CLASSES_ROOT\AppID\{90a52f08-64ac-4dc6-9d7d-4516670275d3} (Trojan.Downloader) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webmediaplayer (Adware.EGDAccess) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WebMediaPlayer.exe (Adware.EGDAccess) -> No action taken. Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> No action taken. C:\Program Files\WebMediaPlayer\resources (Adware.EGDAccess) -> No action taken. C:\Program Files\WebMediaPlayer\skins (Adware.EGDAccess) -> No action taken. C:\Program Files\WebMediaPlayer\updates (Adware.EGDAccess) -> No action taken. Fichier(s) infecté(s): C:\Program Files\WebMediaPlayer\uninst.exe (Adware.EGDAccess) -> No action taken. C:\Program Files\WebMediaPlayer\sqlite3.dll (Adware.EGDAccess) -> No action taken. C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Adware.EGDAccess) -> No action taken. C:\WINDOWS\system32\iffhsp_navps.dat (Adware.EGDAccess) -> No action taken. C:\WINDOWS\system32\nvs2.inf (Adware.EGDAccess) -> No action taken. C:\Documents and Settings\All Users\Bureau\WebMediaPlayer.lnk (Adware.EGDAccess) -> No action taken. Voilà tout ce que j'ai pour l'instant. Merci -
impossible de telecharger Hitjackthis
Pascal62 a répondu à un(e) sujet de Pascal62 dans Analyses et éradication malwares
Bon c'est en cours, je fais tout ça puis te donne des news plus tard car je dois m'absenter , merci pour ton aide!