Détournement de mes autorisation de droit administrateur

J'avais bien compris tout cela,et c'est pourquoi je vous ai orienté vers Ntrights.


En fait, il fait à, peu prés ,comme les 2 logiciels qui vous ont été conseillé dans la chambre à côté, mais moins facilement.

  chtilo a dit :
Je ne peux plus faire mes Màj j'ai fait comme je fais d'habitude je veux dire changement de réglage de XP Antispy et XPSafe mais rien à faire. Je peut poster l'écran d'erreur si il faut j'avais pas pensé tout suite.


ensuite suppression de ces deux clés





Je pense que ça vient de là. As tu réessayer Zeb Restore pour rétablir Win Update.


Pocèdes tu un programme appelé "Orvell Monitoring Network" ?


Tu m'as pas répondu. Après une recherche, j'ai trouvé quez ce programme possède un processus svdhost.exe .

Il peut servire pour surveiller se que les utilisateurs font sur l'ordi.

Peut être est il utilisé par quelqu'un qui est rentré sur ton ordi vi à un troyen. Si non, cela doit être un utilisateur.






Cet outils me donne accès au même chose que GPEDIT si j'ai bien compris, et j'ai été sur gpedit mais il n'y a rien de touché du moins ça a l'air.


Car si c'est la même chose j'ai accès a gpedit mais le problème c'est que je ne comprend pas trop cette zone, je n'y suis pas alèse.


Je pars poster un message sur l'autre topic que j'ai ouvert, j'ai une idée pour essayer de résoudre tout ça mais j'ai besoin d'avis.


Merci à vous de m'aider et de me consacré du temp.



  chtilo a dit :
Cet outils me donne accès au même chose que GPEDIT


On doit pas parler du même programme: la pub de ce logicielle dit:


"What does your employees see on their screen?


Orvell Monitoring is the award winning network monitoring and supervision solution that your network needs! "


perso, j'appelles ça un outil d'espionage. Je doute que cela face comme gpedit.

Si tu pouvais m'expliquer comment tu t'en sert (sur cette page).






Posté(e) (modifié)

On a du ecrire notre message en même temp , je répondai à Pear qui me proposait l'outils NTright. Je lisait du coup ton message mais les lignes était lié au logiciels que tu parle mais si on n'a pas ce logiciels alors on est infecté voici ma source parmi d'autre.


Il y a aussi des explication sur microsoft qui parle d'une faille de sécurité avec certain logiciels qui permette l'execution de code malicieux qui peuvent altéré les droit et bien d'autre chose, voir ici mais ça date mais j'ai installer Office 2003 y a pas longtemp.


As tu lu mon post sur l'autre topic mon dernier message


Qu'en pense tu ?




PS: Oui j'ai essayé ZebRestore mais rien par contre je suis en train de me dire pour les Màj je peu réécrire les clé, mais est ce que l'emplacement d'où je les ai effacer est le bon a l'origine.


merci, amicalement

Modifié par chtilo

Bonjours à tous et merci de m'aider,


Bon pas de changement a part que je me demande si les clés que j'ai effacer il faudrait que je les remette en place , non ?


Pour mes droit après recherche sur le forum Sécu il y a un outil qui peut regarder dans le registre c'est WinPFind3U.exe mais par contre vaut connaitre la bête pour savoir corriger et même l'analyser ça pas l'air simple donc voilà pour le moment.


Si quelqu'un Peut m'aider , merci à tous du coup de main.




Voici le scan fais avec Winpfind3u.exe après avoir lu le topic qui traite d'un problème presque similaire si quelqu'un peut me le traduire je le remercie et aussi toute les personne qui m'aide depuis le début de mon topic et ceux a venir.


WinPFind3 logfile created on: 2007-09-05 19:12:40

WinPFind3U by OldTimer - Version 1.0.42 Folder = U:\Télécharger\WinPFind3u\

Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)

Internet Explorer (Version = 7.0.5730.11)


1023.48 Mb Total Physical Memory | 549.73 Mb Available Physical Memory | 53.71% Memory free

2.40 Gb Paging File | 2.01 Gb Available in Paging File | 83.77% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072;


%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 58.59 Gb Total Space | 49.46 Gb Free Space | 84.40% Space Free

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded


Computer Name: LO-516AA449945E

Current User Name: Loickos

Logged in as Administrator.

Current Boot Mode: Normal



[Processes - Non-Microsoft Only]

a2service.exe -> %ProgramFiles%\a-squared Free\a2service.exe -> Emsi Software GmbH [Ver = | Size = 217208 bytes | Modified Date = 2007-08-19 21:30:02 | Attr = ]

ati2evxx.exe -> %System32%\ati2evxx.exe -> ATI Technologies Inc. [Ver = | Size = 380928 bytes | Modified Date = 2005-08-04 05:02:58 | Attr = ]

ati2evxx.exe -> %System32%\ati2evxx.exe -> ATI Technologies Inc. [Ver = | Size = 380928 bytes | Modified Date = 2005-08-04 05:02:58 | Attr = ]

avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 2007-06-11 11:25:42 | Attr = ]

cledx.exe -> %ProgramFiles%\SyncroSoft\POS\H2O\cledx.exe -> Team H2O [Ver = v0.3.1412 | Size = 307200 bytes | Modified Date = 2007-12-11 04:59:40 | Attr = ]

dsa.exe -> %ProgramFiles%\Privacyware\Dynamic Security Agent\DSA.exe -> Privacyware [Ver = 1, 0, 8, 8 | Size = 2347008 bytes | Modified Date = 2006-08-08 19:01:24 | Attr = ]

firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> Mozilla Corporation [Ver = 2007072518 | Size = 7644520 bytes | Modified Date = 2007-07-31 07:35:16 | Attr = ]

guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 2007-05-30 14:31:10 | Attr = ]

jusched.exe -> %ProgramFiles%\Java\jre1.6.0_02\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = | Size = 132496 bytes | Modified Date = 2007-07-12 04:00:36 | Attr = ]

nod32krn.exe -> %ProgramFiles%\ESET\nod32krn.exe -> Eset [Ver = 2, 70, 39 | Size = 552064 bytes | Modified Date = 2007-08-18 10:29:28 | Attr = ]

nod32kui.exe -> %ProgramFiles%\ESET\nod32kui.exe -> Eset [Ver = 2, 70, 39 | Size = 949376 bytes | Modified Date = 2007-08-18 10:29:28 | Attr = ]

ooccag.exe -> %ProgramFiles%\OO Software\CleverCache\ooccag.exe -> O&O Software GmbH [Ver = | Size = 391952 bytes | Modified Date = 2007-01-28 15:08:26 | Attr = ]

ooccctrl.exe -> %ProgramFiles%\OO Software\CleverCache\ooccctrl.exe -> O&O Software GmbH [Ver = | Size = 1911568 bytes | Modified Date = 2007-01-28 15:08:36 | Attr = ]

oodag.exe -> %System32%\oodag.exe -> O&O Software GmbH [Ver = 10.0.1670 | Size = 1049856 bytes | Modified Date = 2007-06-28 23:02:08 | Attr = ]

pwrisovm.exe -> %ProgramFiles%\PowerISO\PWRISOVM.EXE -> PowerISO Computing, Inc. [Ver = 3, 7, 0, 0 | Size = 200704 bytes | Modified Date = 2007-04-09 14:23:12 | Attr = ]

regprot.exe -> %SystemDrive%\RegProt\regprot.exe -> [Ver = | Size = 19614 bytes | Modified Date = 2001-09-13 06:54:22 | Attr = ]

robotaskbaricon.exe -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe -> Siber Systems [Ver = 6-9-5 | Size = 160568 bytes | Modified Date = 2007-08-30 11:06:32 | Attr = ]

soundman.exe -> %SystemRoot%\SOUNDMAN.EXE -> Realtek Semiconductor Corp. [Ver = | Size = 77824 bytes | Modified Date = 2005-04-15 05:01:46 | Attr = ]

supercopier2.exe -> %ProgramFiles%\SuperCopier2\SuperCopier2.exe -> SFX TEAM [Ver = | Size = 1052672 bytes | Modified Date = 2006-07-07 18:45:00 | Attr = ]

totalcmd.exe -> %SystemDrive%\totalcmd\TOTALCMD.EXE -> C. Ghisler & Co. [Ver = 7.01 | Size = 1071560 bytes | Modified Date = 2007-06-24 17:18:04 | Attr = ]

trayit!.exe -> U:\Optimisation & Diagnostic\Tray It\TrayIt!.exe -> Igor Nys [Ver = 4, 6, 5, 5 | Size = 204800 bytes | Modified Date = 2007-07-18 15:57:00 | Attr = ]

vsmon.exe -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 75568 bytes | Modified Date = 2007-03-09 00:01:58 | Attr = ]

washersvc.exe -> %ProgramFiles%\Webroot\Washer\WasherSvc.exe -> Webroot Software, Inc. [Ver = 6,5,0,1093 | Size = 388936 bytes | Modified Date = 2007-08-09 13:56:26 | Attr = ]

winpfind3u.exe -> U:\Télécharger\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = | Size = 322560 bytes | Modified Date = 2007-09-04 10:47:26 | Attr = ]

zlclient.exe -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 919280 bytes | Modified Date = 2007-03-09 00:02:00 | Attr = ]


[Win32 Services - Non-Microsoft Only]

(a2free) a-squared Free Service [Win32_Own | Auto | Running] -> %ProgramFiles%\a-squared Free\a2service.exe -> Emsi Software GmbH [Ver = | Size = 217208 bytes | Modified Date = 2007-08-19 21:30:02 | Attr = ]

(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %System32%\ati2evxx.exe -> ATI Technologies Inc. [Ver = | Size = 380928 bytes | Modified Date = 2005-08-04 05:02:58 | Attr = ]

(ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> %System32%\ati2sgag.exe -> [Ver = 5.13.0024 | Size = 516096 bytes | Modified Date = 2005-08-05 21:05:00 | Attr = ]

(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 2007-05-30 14:31:10 | Attr = ]

(dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 225280 bytes | Modified Date = 2004-08-19 23:09:52 | Attr = ]

(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 2007-07-23 23:33:14 | Attr = ]

(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> -> File not found

(NBService) NBService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Nero\Nero 7\Nero BackItUp\NBService.exe -> Nero AG [Ver = 2, 10, 3, 2 | Size = 800040 bytes | Modified Date = 2007-06-29 19:16:56 | Attr = ]

(NMIndexingService) NMIndexingService [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Ahead\Lib\NMIndexingService.exe -> Nero AG [Ver = 2,0,16,0 | Size = 279848 bytes | Modified Date = 2007-06-27 19:04:00 | Attr = ]

(NOD32krn) NOD32 Kernel Service [Win32_Own | Auto | Running] -> %ProgramFiles%\ESET\nod32krn.exe -> Eset [Ver = 2, 70, 39 | Size = 552064 bytes | Modified Date = 2007-08-18 10:29:28 | Attr = ]

(O&O Defrag) O&O Defrag [Win32_Own | Auto | Running] -> %System32%\oodag.exe -> O&O Software GmbH [Ver = 10.0.1670 | Size = 1049856 bytes | Modified Date = 2007-06-28 23:02:08 | Attr = ]

(OOCleverCacheAgent) O&O CleverCache Agent [Win32_Own | Auto | Running] -> %ProgramFiles%\OO Software\CleverCache\ooccag.exe -> O&O Software GmbH [Ver = | Size = 391952 bytes | Modified Date = 2007-01-28 15:08:26 | Attr = ]

(PFNet) Privacyware network service [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Privacyware\Dynamic Security Agent\pfsvc.exe -> PWI, Inc. [Ver = 5, 0, 8, 8 | Size = 319488 bytes | Modified Date = 2006-08-08 17:23:26 | Attr = ]

(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Running] -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 75568 bytes | Modified Date = 2007-03-09 00:01:58 | Attr = ]

(wwEngineSvc) Window Washer Engine [Win32_Own | Auto | Running] -> %ProgramFiles%\Webroot\Washer\WasherSvc.exe -> Webroot Software, Inc. [Ver = 6,5,0,1093 | Size = 388936 bytes | Modified Date = 2007-08-09 13:56:26 | Attr = ]


[Registry - Non-Microsoft Only]

< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->

!AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 2007-06-11 11:25:42 | Attr = ]

ATICCC -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLI.exe -> ATI Technologies Inc. [Ver = 1.2.2044.224 | Size = 61440 bytes | Modified Date = 2005-08-06 01:07:30 | Attr = ]

DSA -> %ProgramFiles%\Privacyware\Dynamic Security Agent\DSA.exe -> Privacyware [Ver = 1, 0, 8, 8 | Size = 2347008 bytes | Modified Date = 2006-08-08 19:01:24 | Attr = ]

H2O -> %ProgramFiles%\SyncroSoft\POS\H2O\cledx.exe -> Team H2O [Ver = v0.3.1412 | Size = 307200 bytes | Modified Date = 2007-12-11 04:59:40 | Attr = ]

NeroFilterCheck -> %CommonProgramFiles%\Ahead\Lib\NeroCheck.exe -> Nero AG [Ver = 1, 0, 0, 6 | Size = 153136 bytes | Modified Date = 2007-03-01 15:57:24 | Attr = ]

nod32kui -> %ProgramFiles%\ESET\nod32kui.exe -> Eset [Ver = 2, 70, 39 | Size = 949376 bytes | Modified Date = 2007-08-18 10:29:28 | Attr = ]

ooccctrl.exe -> %ProgramFiles%\OO Software\CleverCache\ooccctrl.exe -> O&O Software GmbH [Ver = | Size = 1911568 bytes | Modified Date = 2007-01-28 15:08:36 | Attr = ]

OSSelectorReinstall -> %CommonProgramFiles%\Acronis\Partition Suite\oss_reinstall.exe -> [Ver = | Size = 1281425 bytes | Modified Date = 2006-05-31 11:20:56 | Attr = ]

PWRISOVM.EXE -> %ProgramFiles%\PowerISO\PWRISOVM.EXE -> PowerISO Computing, Inc. [Ver = 3, 7, 0, 0 | Size = 200704 bytes | Modified Date = 2007-04-09 14:23:12 | Attr = ]

RegProt -> %SystemDrive%\RegProt\regprot.exe -> [Ver = | Size = 19614 bytes | Modified Date = 2001-09-13 06:54:22 | Attr = ]

SoundMan -> %SystemRoot%\SOUNDMAN.EXE -> Realtek Semiconductor Corp. [Ver = | Size = 77824 bytes | Modified Date = 2005-04-15 05:01:46 | Attr = ]

SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_02\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = | Size = 132496 bytes | Modified Date = 2007-07-12 04:00:36 | Attr = ]

ZoneAlarm Client -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 7.0.337.000 | Size = 919280 bytes | Modified Date = 2007-03-09 00:02:00 | Attr = ]

< RunOnce [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->

MRUBlaster -> %ProgramFiles%\MRU-Blaster\indexcleaner.exe -> [Ver = 1.00.0002 | Size = 32768 bytes | Modified Date = 2003-01-05 13:20:20 | Attr = ]

< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->

RoboForm -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe -> Siber Systems [Ver = 6-9-5 | Size = 160568 bytes | Modified Date = 2007-08-30 11:06:32 | Attr = ]

SuperCopier2.exe -> %ProgramFiles%\SuperCopier2\SuperCopier2.exe -> SFX TEAM [Ver = | Size = 1052672 bytes | Modified Date = 2006-07-07 18:45:00 | Attr = ]

swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 2007-07-27 12:54:44 | Attr = ]

< Common Startup > -> C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage ->

%AllUsersStartup%\Barre d'état système d'ATI CATALYST.lnk -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLI.exe -> ATI Technologies Inc. [Ver = 1.2.2044.224 | Size = 61440 bytes | Modified Date = 2005-08-06 01:07:30 | Attr = ]

< User Startup > -> C:\Documents and Settings\Loickos\Menu Démarrer\Programmes\Démarrage ->

%UserStartup%\ERUNT AutoBackup.lnk -> %ProgramFiles%\ERUNT\AUTOBACK.EXE -> [Ver = | Size = 36864 bytes | Modified Date = 2005-03-06 15:26:48 | Attr = ]

%UserStartup%\MRU-Blaster Silent Clean.lnk -> %ProgramFiles%\MRU-Blaster\mrublaster.exe -> [Ver = 1.05.0009 | Size = 1216512 bytes | Modified Date = 2004-03-28 15:07:48 | Attr = ]

%UserStartup%\TrayIt!.lnk -> U:\Optimisation & Diagnostic\Tray It\TrayIt!.exe -> Igor Nys [Ver = 4, 6, 5, 5 | Size = 204800 bytes | Modified Date = 2007-07-18 15:57:00 | Attr = ]

< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->

{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 2007-05-30 14:29:58 | Attr = ]

{81559C35-8464-49F7-BB0E-07A383BEF910} [HKLM] -> %ProgramFiles%\SpywareGuard\spywareguard.dll [spywareGuard] -> [Ver = 2.02 | Size = 126976 bytes | Modified Date = 2003-08-02 23:20:58 | Attr = R ]

< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->

< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->

AtiExtEvent -> %System32%\ati2evxx.dll -> ATI Technologies Inc. [Ver = | Size = 46080 bytes | Modified Date = 2005-08-04 05:04:18 | Attr = ]

< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoDriveAutoRun -> 67108863 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoDriveTypeAutoRun -> 255 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoRecentDocsMenu -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoFavoritesMenu -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoSMMyDocs -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoSMMyPictures -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoStartMenuMyMusic -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoRecentDocsHistory -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoRecentDocsNetHood -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoSMHelp -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoRun -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoInstrumentation -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoSimpleStartMenu -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\RUN\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\\NoFileSharing -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\\NoPrintSharing -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\dontdisplaylastusername -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\shutdownwithoutlogon -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\undockwithoutlogon -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\legalnoticecaption -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\legalnoticetext -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\UNINSTALL\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WINDOWSUPDATE\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WinOldApp\ -> ->

< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\\DisableWindowsUpdate -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoDriveTypeAutoRun -> 145 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoWindowsUpdate -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoRecentDocsMenu -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoFavoritesMenu -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoSMMyDocs -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoSMMyPictures -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoStartMenuMyMusic -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoRecentDocsHistory -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\ClearRecentDocsOnExit -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoRecentDocsNetHood -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoSMHelp -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoRun -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoUserNameInStartMenu -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoInstrumentation -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoStartMenuPinnedList -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\ForceStartMenuLogoff -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\\NoSharedDocuments -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\DISALLOWCPL\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\DISALLOWRUN\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\RESTRICTCPL\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\RESTRICTRUN\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\EXPLORER\RUN\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\\NoFileSharing -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\\NoFileSharingControl -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\\NoPrintSharing -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 1 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\UNINSTALL\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WINDOWSUPDATE\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WINDOWSUPDATE\\DisableWindowsUpdateAccess -> 1 ->

< HOSTS File > (8430625 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->

< Internet Explorer Settings > -> ->

HKLM: Default_Page_URL -> ->

HKLM: Main\\Default_Search_URL ->;ar=iesearch ->

HKLM: Local Page -> C:\windows\system32\blank.htm ->

HKLM: Search Bar ->{SUB_RFC1766}/srchasst/srchcust.htm ->

HKLM: Search Page ->;ar=iesearch ->

HKLM: Start Page ->}&ar=home ->

HKLM: CustomizeSearch ->{SUB_RFC1766}/srchasst/srchcust.htm ->

HKLM: Search\\Default_Search_URL ->;ar=iesearch ->

HKLM: SearchAssistant ->{SUB_RFC1766}/srchasst/srchasst.htm ->

HKCU: Default_Search_URL ->;ar=iesearch ->

HKCU: Local Page -> C:\windows\system32\blank.htm ->

HKCU: Search Page ->;ar=iesearch ->

HKCU: Start Page -> ->

HKCU: ProxyEnable -> 0 ->

< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [ - ] -> ->

< Trusted Sites > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

* [http] -> ->

* [https] -> -> [http] -> -> [http] -> ->

< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->

{2E03C0FD-4C48-43A7-9A54-00240C70FF16} [HKLM] -> %System32%\BhoECart.dll [ECarteBleueBrowserHelper Class] -> Orbiscom Ltd. All rights reserved. [Ver = 2, 2, 1, 3, 94 | Size = 69632 bytes | Modified Date = 2003-05-14 14:41:30 | Attr = ]

{4A368E80-174F-4872-96B5-0B27DDD11DB2} [HKLM] -> %ProgramFiles%\SpywareGuard\dlprotect.dll [spywareGuardDLBLOCK.CBrowserHelper] -> [Ver = 2.02 | Size = 192512 bytes | Modified Date = 2003-08-02 23:24:02 | Attr = R ]

{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 2005-05-31 01:04:00 | Attr = ]

{724d43a9-0d85-11d4-9908-00400523e39a} [HKLM] -> %ProgramFiles%\Siber Systems\AI RoboForm\roboform.dll [Reg Data - Value does not exist] -> Siber Systems [Ver = 6-9-5 | Size = 5645104 bytes | Modified Date = 2007-08-30 11:06:32 | Attr = ]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_02\bin\ssv.dll [sSVHelper Class] -> Sun Microsystems, Inc. [Ver = | Size = 501136 bytes | Modified Date = 2007-07-12 04:00:36 | Attr = ]

{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\googletoolbar2.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 2007-07-23 23:33:12 | Attr = R ]

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [Google Toolbar Notifier BHO] -> Google Inc. [Ver = 2, 0, 301, 7164 | Size = 325048 bytes | Modified Date = 2007-07-27 12:54:44 | Attr = ]

< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->

{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar2.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 2007-07-23 23:33:12 | Attr = R ]

{724d43a0-0d85-11d4-9908-00400523e39a} [HKLM] -> %ProgramFiles%\Siber Systems\AI RoboForm\roboform.dll [&RoboForm] -> Siber Systems [Ver = 6-9-5 | Size = 5645104 bytes | Modified Date = 2007-08-30 11:06:32 | Attr = ]

< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->

WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar2.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 2007-07-23 23:33:12 | Attr = R ]

WebBrowser\\{724D43A0-0D85-11D4-9908-00400523E39A} [HKLM] -> %ProgramFiles%\Siber Systems\AI RoboForm\roboform.dll [&RoboForm] -> Siber Systems [Ver = 6-9-5 | Size = 5645104 bytes | Modified Date = 2007-08-30 11:06:32 | Attr = ]

< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_02\bin\npjpi160_02.dll [MenuText: Console Java (Sun)] -> Sun Microsystems, Inc. [Ver = | Size = 132496 bytes | Modified Date = 2007-07-12 04:00:36 | Attr = ]

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.6.0_02\bin\ssv.dll [MenuText: Console Java (Sun)] -> Sun Microsystems, Inc. [Ver = | Size = 501136 bytes | Modified Date = 2007-07-12 04:00:36 | Attr = ]

{320AF880-6646-11D3-ABEE-C5DBF3571F46} -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComFillForms.htm [buttonText: Remplir] -> File not found

{320AF880-6646-11D3-ABEE-C5DBF3571F49} -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComSavePass.htm [buttonText: Enregistrer] -> File not found

{724d43aa-0d85-11d4-9908-00400523e39a} -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComShowToolbar.htm [buttonText: Barre RoboForm] -> File not found

{92780B25-18CC-41C8-B9BE-3C9C571A8263} -> Reg Data - Value does not exist [buttonText: Recherche] -> File not found

< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->

Barre RoboForm -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComShowToolbar.htm -> File not found

E&xporter vers Microsoft Excel -> -> File not found

Enregistrer le formulaire -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComSavePass.htm -> File not found

Personnaliser le menu -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.htm -> File not found

Remplir le formulaire -> %ProgramFiles%\Siber Systems\AI RoboForm\RoboFormComFillForms.htm -> File not found

< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform ->

sv1 -> ->

< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->

{022C77D4-E660-4630-8947-94654E82A62B} -> () ->

< Winsock2 Catalogs [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ ->

Protocol_Catalog9\Catalog_Entries0000000001 -> %System32%\imon.dll -> Eset [Ver = 2, 70, 39 | Size = 298104 bytes | Modified Date = 2007-08-18 10:29:30 | Attr = ]

Protocol_Catalog9\Catalog_Entries0000000002 -> %System32%\imon.dll -> Eset [Ver = 2, 70, 39 | Size = 298104 bytes | Modified Date = 2007-08-18 10:29:30 | Attr = ]

Protocol_Catalog9\Catalog_Entries0000000003 -> %System32%\imon.dll -> Eset [Ver = 2, 70, 39 | Size = 298104 bytes | Modified Date = 2007-08-18 10:29:30 | Attr = ]

Protocol_Catalog9\Catalog_Entries0000000004 -> %System32%\imon.dll -> Eset [Ver = 2, 70, 39 | Size = 298104 bytes | Modified Date = 2007-08-18 10:29:30 | Attr = ]

Protocol_Catalog9\Catalog_Entries0000000005 -> %System32%\imon.dll -> Eset [Ver = 2, 70, 39 | Size = 298104 bytes | Modified Date = 2007-08-18 10:29:30 | Attr = ]

Protocol_Catalog9\Catalog_Entries0000000017 -> %System32%\imon.dll -> Eset [Ver = 2, 70, 39 | Size = 298104 bytes | Modified Date = 2007-08-18 10:29:30 | Attr = ]

< Default Protocols [HKLM] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->

about -> 4 = Restricted sites (Not a Default Protocol) ->

about: -> 4 = Restricted sites (Not a Default Protocol) ->

mhtml -> 4 = Restricted sites (Not a Default Protocol) ->

< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->

ipp -> Reg Data - Key not found -> File not found

msdaipp -> Reg Data - Key not found -> File not found

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->

{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -> CKAVWebScan Object - CodeBase = ->

{6414512B-B978-451D-A0D8-FCFDF33E833C} -> - CodeBase = ->

{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_02 - CodeBase = ->

{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = ->

{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_02 - CodeBase = ->

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_02 - CodeBase = ->

{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = ->



[Registry - Additional Scans - Non-Microsoft Only]

< Security Settings > -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\\DisableMonitoring -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\system32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Service de transfert intelligent en arrière-plan ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> RpcSs; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Transfère des données entre les clients et les serveurs en tâche de fond. Si le service BITS est désactivé, les fonctionnalités telles que Windows Update ne fonctionneront pas correctement. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\FailureActions ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 3 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> C:\WINDOWS\system32\qmgr.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> Root\LEGACY_BITS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Internet Connection Sharing ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 4 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Group -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 197 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 0 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions -> 0 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\135:TCP -> 135:TCP:*:Enabled:DCOM(135) ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> Root\LEGACY_SHAREDACCESS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %systemroot%\system32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Mises à jour automatiques ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Autorise le téléchargement et l'installation des mises à jour de Windows. Si ce service est désactivé, cet ordinateur ne pourra pas utiliser la fonctionnalité Mises à jour automatiques, ni accéder au site Web Windows Update. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Group -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 4 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\system32\wuauserv.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> Root\LEGACY_WUAUSERV00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->

< Software Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\ ->


HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Conferencing\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\\NoUpdateCheck -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\\PreventAutoRun -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\\PreventRun -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\\Disabled -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\\PreventBackgroundDownload -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\\PreventAutoUpdate -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\MRT\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\MRT\\DontReportInfectionInformation -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\10.0\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\10.0\Common\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\10.0\Common\\DWNeverUpload -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\10.0\Common\\DWNoExternalURL -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\10.0\Common\\DWNoFileCollection -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\10.0\Common\\DWNoSecondLevelCollection -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\11.0\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\11.0\Common\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\11.0\Common\\DWNoExternalURL -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\11.0\Common\\DWNoFileCollection -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\11.0\Common\\DWNoSecondLevelCollection -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\9.0\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\9.0\Common\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\9.0\Common\\DWNeverUpload -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\9.0\Common\\DWNoExternalURL -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\9.0\Common\\DWNoFileCollection -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Office\9.0\Common\\DWNoSecondLevelCollection -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\PCHealth\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\PCHealth\ErrorReporting\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\PCHealth\ErrorReporting\DW\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\PCHealth\ErrorReporting\DW\\DWNeverUpload -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\\EnableAdminTSRemote -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\\DisableMSI -> 2 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\\AlwaysInstallElevated -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Psched\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Psched\\NonBestEffortLimit -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\ -> ->


HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\TransparentEnabled -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\DefaultLevel -> 262144 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\AuthenticodeEnabled -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\PolicyScope -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\FriendlyName -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemData -> ^«0O•zI‰j

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemSize -> ; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\FriendlyName -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemData -> g°Ô‹4:?Ó¼éÜdgó” ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemSize -> ; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\FriendlyName -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemData -> 2xÜþøÈ“ÜŠ°Ý„} ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemSize -> –; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\FriendlyName -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemData -> ½š*ÛBëØV%Mø/g ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemSize -> å; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\Description -> Stop the download of this file ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\FriendlyName -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\HashAlg -> 32771 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemData -> 8k_„ìöiÓk•j"À€ ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemSize -> r; ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\Description -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\SaferFlags -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\ItemData -> %HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK* ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\LastModified -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\\ElevateNonAdmins -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\AU\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\AU\\AUOptions -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\AU\\AutoInstallMinorUpdates -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\AU\\NoAutoUpdate -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\Terminal Services\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsMediaPlayer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsMediaPlayer\\DisableAutoUpdate -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsMediaPlayer\\PreventCodecDownload -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsMediaPlayer\\DisableMRU -> 1 ->

< Software Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\policies\ ->

HKEY_CURRENT_USER\Software\Policies\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\\NoBrowserOptions -> 0 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Messenger\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Messenger\Client\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Messenger\Client\\PreventAutoRun -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Messenger\Client\\PreventRun -> 0 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\Common\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\Common\\DWNeverUpload -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\Common\\DWNoExternalURL -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\Common\\DWNoFileCollection -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\Common\\DWNoSecondLevelCollection -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\Outlook\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\Outlook\InstantMessaging\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\10.0\Outlook\InstantMessaging\\ForceDisableIM -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\11.0\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\11.0\Common\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\11.0\Common\\DWNeverUpload -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\11.0\Common\\DWNoExternalURL -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\11.0\Common\\DWNoFileCollection -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\11.0\Common\\DWNoSecondLevelCollection -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\9.0\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\9.0\Common\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\9.0\Common\\DWNeverUpload -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\9.0\Common\\DWNoExternalURL -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\9.0\Common\\DWNoFileCollection -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\9.0\Common\\DWNoSecondLevelCollection -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\PCHealth\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\PCHealth\ErrorReporting\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\PCHealth\ErrorReporting\DW\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\PCHealth\ErrorReporting\DW\\DWNeverUpload -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\AppCompat\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsMediaPlayer\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsMediaPlayer\\PreventCodecDownload -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsMediaPlayer\\NoCodecDownload -> 1 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsMediaPlayer\\PreventMusicFileMetadataRetrieval -> 0 ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsMediaPlayer\\PreventCDDVDMetadataRetrieval -> 0 ->

< Uninstall List > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->

{083F79E4-6FE9-46FB-A6C6-4F8862742947} -> ATI HYDRAVISION ->

{15095BF3-A3D7-4DDF-B193-3A496881E003} -> Microsoft .NET Framework 3.0 ->

{2300EE96-0A41-4FAB-BD03-989EC44577A0} -> Partition Suite ->

{2318C2B1-4965-11d4-9B18-009027A5CD4F} -> Google Toolbar for Internet Explorer ->

{3248F0A8-6813-11D6-A77B-00B0D0160010} -> Java SE Runtime Environment 6 Update 1 ->

{3248F0A8-6813-11D6-A77B-00B0D0160020} -> Java 6 Update 2 ->

{350C940c-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP ->

{491DD792-AD81-429C-9EB4-86DD3D22E333} -> Windows Communication Foundation ->

{4D3B509A-82E2-4E8B-9D90-C880A2131C73} -> Dynamic Security Agent 1.0 ->

{534802E0-761E-47F4-BD27-061BC8F976AE} -> O&O SafeErase ->

{53480330-E1D1-41CA-B8F8-7F78644F7F50} -> O&O Defrag Professional Edition ->

{53480390-0EC4-429E-BBEE-78E19EEB03BD} -> O&O CleverCache ->

{56C049BE-79E9-4502-BEA7-9754A3E60F9B} -> neroxml ->

{5A710547-B58E-488B-828D-CA9A25A0533C} -> MSXML 6.0 Parser (KB927977) ->

{620797B0-A022-4B57-A95E-DD7DD0321028} -> ProxyWay Extra ->

{6901DD22-527A-41EF-9059-E81FEDE9E494} -> Windows Presentation Foundation Language Pack (FRA) ->

{69B9A8B6-75C7-4B0C-A530-129C3C0768C8} -> Personal Translator 2008 Professional English French ->

{7131646D-CD3C-40F4-97B9-CD9E4E6262EF} -> Microsoft .NET Framework 2.0 ->

{7D1B85BD-AA07-48B8-808D-67A4067FC6BD} -> Windows Workflow Foundation ->

{86EC42B5-346E-4BAB-948D-58E021EA4BD1} -> ATI Catalyst Control Center ->

{9011040C-6000-11D3-8CFE-0150048383C9} -> Microsoft Office Professional Edition 2003 ->

{B168C59D-5FCF-4EEC-B464-BFA7A8266150} -> Windows Communication Foundation Language Pack - FRA ->

{B84C141C-9A13-44BE-9A69-301D7B11D836} -> Windows Workflow Foundation FR Language Pack ->

{BAF78226-3200-4DB4-BE33-4D922A799840} -> Windows Presentation Foundation ->

{C151CE54-E7EA-4804-854B-F515368B0798} -> Athlon 64 Processor Driver ->

{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} -> Microsoft .NET Framework 1.1 ->

{CF097717-F174-4144-954A-FBC4BF301036} -> Nero 7 Premium ->

{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1 -> NOD32 FiX ->

{DBEA1034-5882-4A88-8033-81C4EF0CFA29} -> Google Toolbar for Internet Explorer ->

{E3C080B0-23F5-49AF-89F8-8E8DBC89E659} -> Microsoft .NET Framework 3.0 French Language Pack ->

{F196AC50-7C95-42E1-9947-BDAB18BF3C8C} -> Microsoft .NET Framework 2.0 Language Pack - FRA ->

{F7338FA3-DAB5-49B2-900D-0AFB5760C166} -> PC Probe II ->

{FB08F381-6533-4108-B7DD-039E11FBC27E} -> Realtek AC'97 Audio ->

97149975-b4b1-4d2b-b9fe-7ba413d0efeb_is1 -> SummerProperties 1.2 ->

Adobe Flash Player Plugin -> Adobe Flash Player Plugin ->

Adobe® Photoshop® Album Edition Découverte 3.2 -> Adobe® Photoshop® Album Edition Découverte 3.2 ->

AI RoboForm -> AI RoboForm (All Users) ->

All ATI Software -> ATI - Utilitaire de désinstallation du logiciel ->

a-squared Free_is1 -> a-squared Free 3.0 ->

AsusUpdate -> AsusUpdate ->

ATI Display Driver -> ATI Display Driver ->

AVGantiRootkit -> AVG Anti-Rootkit Free ->

AVGAntiSpyware75 -> AVG Anti-Spyware 7.5 ->

AxCrypt -> AxCrypt (Désinstaller uniquement) ->

CCleaner -> CCleaner (remove only) ->

dBpoweramp [Arrange Audio] Codec -> dBpoweramp [Arrange Audio] Codec ->

dBpoweramp [Multi Encoder] Codec -> dBpoweramp [Multi Encoder] Codec ->

dBpoweramp [ReplayGain] Codec -> dBpoweramp [ReplayGain] Codec ->

dBpoweramp AAC Encoder -> dBpoweramp AAC Encoder ->

dBpowerAMP CD Writer -> dBpowerAMP CD Writer ->

dBPowerAMP Dalet codec R2 -> dBPowerAMP Dalet codec R2 ->

dBpoweramp DirectShow Decoder -> dBpoweramp DirectShow Decoder ->

dBpoweramp DSP Effects -> dBpoweramp DSP Effects ->

dBpoweramp FLAC Codec -> dBpoweramp FLAC Codec ->

dBpoweramp m4a Codec -> dBpoweramp m4a Codec ->

dBpoweramp m4a Utilities -> dBpoweramp m4a Utilities ->

dBpoweramp Midi Decoder -> dBpoweramp Midi Decoder ->

dBpoweramp Monkeys Audio Codec -> dBpoweramp Monkeys Audio Codec ->

dBpoweramp Musepack Codec -> dBpoweramp Musepack Codec ->

dBpoweramp Music Converter -> dBpoweramp Music Converter ->

dBpoweramp Ogg Vorbis Codec -> dBpoweramp Ogg Vorbis Codec ->

dBpowerAMP Rename Extension -> dBpowerAMP Rename Extension ->

dBpowerAMP Tag From Filename -> dBpowerAMP Tag From Filename ->

dBpowerAMP Update ID Tag -> dBpowerAMP Update ID Tag ->

dBpoweramp WavPack Codec -> dBpoweramp WavPack Codec ->

dBpoweramp Windows Media Audio 10 Codec -> dBpoweramp Windows Media Audio 10 Codec ->

DFX for Winamp -> DFX 8 for Winamp ->

e-Carte Bleue Banque Populaire -> e-Carte Bleue Banque Populaire ->

ERUNT_is1 -> ERUNT 1.1h ->

EVEREST Ultimate Edition_is1 -> EVEREST Ultimate Edition v4.00 ->

Foxit Reader -> Foxit Reader ->

HijackThis -> HijackThis 1.99.1 ->

Hijackthis Version Française_is1 -> Hijackthis Version Française ->

IDNMitigationAPIs -> Microsoft Internationalized Domain Names Mitigation APIs ->

ie7 -> Windows Internet Explorer 7 ->

InstallShield_{69B9A8B6-75C7-4B0C-A530-129C3C0768C8} -> Personal Translator 2008 Professional English French ->

iZotope Ozone 1.0 for Winamp2 and Winamp3_is1 -> iZotope Ozone 1.0 for Winamp2 and Winamp3 ->

jv16 PowerTools_is1 -> jv16 PowerTools 2007 ->

Kaspersky Online Scanner -> Kaspersky Online Scanner ->

KB892130 -> Windows Genuine Advantage Validation Tool (KB892130) ->

KB920342 -> Mise à jour pour Windows XP (KB920342) ->

KB921503 -> Mise à jour de sécurité pour Windows XP (KB921503) ->

KB923789 -> Mise à jour de sécurité pour Windows XP (KB923789) ->

KB929969 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969) ->

KB933566-IE7 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566) ->

KB936021 -> Mise à jour de sécurité pour Windows XP (KB936021) ->

KB936782_WMP9 -> Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782) ->

KB937143-IE7 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143) ->

KB938127-IE7 -> Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127) ->

KB938828 -> Mise à jour pour Windows XP (KB938828) ->

KB938829 -> Mise à jour de sécurité pour Windows XP (KB938829) ->

L'Assistant DartyBox -> L'Assistant DartyBox ->

Microsoft .NET Framework 2.0 -> Microsoft .NET Framework 2.0 ->

Microsoft .NET Framework 2.0 Language Pack - FRA -> Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA ->

Microsoft .NET Framework 3.0 -> Microsoft .NET Framework 3.0 ->

Microsoft .NET Framework 3.0 French Language Pack -> Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0 ->

MRU-Blaster_is1 -> MRU-Blaster v1.5 (Database 3/28/2004) ->

NLSDownlevelMapping -> Microsoft National Language Support Downlevel APIs ->

NOD32 -> NOD32 Antivirus System ->

NTREGOPT_is1 -> NTREGOPT 1.1h ->

NVIDIA Drivers -> NVIDIA Drivers ->

PowerISO -> PowerISO ->

Privoxy -> Privoxy 3.0.6 ->

Random Password Generator-PRO -> Random Password Generator-PRO ->

RegScanner -> RegScanner ->

Revo Uninstaller -> Revo Uninstaller 1.34 ->

ShockwaveFlash -> Adobe Flash Player 9 ActiveX ->

SpeedFan -> SpeedFan (remove only) ->

Spybot - Search & Destroy_is1 -> Spybot - Search & Destroy 1.4 ->

SpywareBlaster_is1 -> SpywareBlaster v3.5.1 ->

SpywareGuard_is1 -> SpywareGuard v2.2 ->

Steinberg Nuendo v3.2.0.1128 -> Steinberg Nuendo v3.2.0.1128 ->

SuperCopier2 -> SuperCopier2 ->

SyncroSoft Emu -> SyncroSoft Emu (Remove only) ->

Syncrosoft's License Control -> Le Centre de Contrôle de Licences de Syncrosoft ->

The KMPlayer FR_is1 -> The KMPlayer v2.9.3.1340 FR ->

Tor -> Tor ->

Totalcmd -> Total Commander (Remove or Repair) ->

Uninstall -> Uninstall ->

Vidalia -> Vidalia 0.0.13 ->

WGA -> Windows Genuine Advantage Validation Tool (KB892130) ->

WIC -> Windows Imaging Component ->

Winamp -> Winamp (remove only) ->

Window Washer -> Window Washer ->

Windows Media Format Runtime -> Windows Media Format 11 runtime ->

WinRAR archiver -> Archiveur WinRAR ->

WMFDist11 -> Windows Media Format 11 runtime ->

xp-AntiSpy -> xp-AntiSpy 3.96-5 ->

XpsEPSC -> XML Paper Specification Shared Components Pack 1.0 ->

XPSEPSCLP -> XML Paper Specification Shared Components Language Pack 1.0 ->

ZoneAlarm Pro -> ZoneAlarm Pro ->


[Files/Folders - Created Within 60 days]

AUTOEXEC.BAT -> %SystemDrive%\AUTOEXEC.BAT -> [Ver = | Size = 0 bytes | Created Date = 2007-07-23 21:06:30 | Attr = ]

Bases -> %SystemDrive%\Bases -> [Folder | Created Date = 2007-09-01 17:43:59 | Attr = ]

boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 212 bytes | Created Date = 2007-07-23 22:51:41 | Attr = HS]

ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 2007-09-05 00:41:15 | Attr = ]

Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Created Date = 2007-08-05 17:30:24 | Attr = ]

CONFIG.SYS -> %SystemDrive%\CONFIG.SYS -> [Ver = | Size = 0 bytes | Created Date = 2007-07-23 21:06:30 | Attr = ]

CWShredder -> %SystemDrive%\CWShredder -> [Folder | Created Date = 2007-08-20 20:58:05 | Attr = ]

Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Created Date = 2007-07-23 22:52:26 | Attr = ]

Downloads -> %SystemDrive%\Downloads -> [Folder | Created Date = 2007-09-01 17:43:59 | Attr = ]

HijackThis-fr -> %SystemDrive%\HijackThis-fr -> [Folder | Created Date = 2007-08-03 06:06:39 | Attr = ]

IO.SYS -> %SystemDrive%\IO.SYS -> [Ver = | Size = 0 bytes | Created Date = 2007-07-23 21:06:30 | Attr = RHS]

Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Created Date = 2007-09-01 17:42:46 | Attr = ]

MSDOS.SYS -> %SystemDrive%\MSDOS.SYS -> [Ver = | Size = 0 bytes | Created Date = 2007-07-23 21:06:30 | Attr = RHS]

Program Files -> %ProgramFiles% -> [Folder | Created Date = 2007-07-23 22:53:16 | Attr = R ]

qoobox -> %SystemDrive%\qoobox -> [Folder | Created Date = 2007-09-05 00:41:59 | Attr = ]

RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Created Date = 2007-07-23 22:08:27 | Attr = HS]

RegProt -> %SystemDrive%\RegProt -> [Folder | Created Date = 2007-08-30 08:11:48 | Attr = ]

Rustbfix -> %SystemDrive%\Rustbfix -> [Folder | Created Date = 2007-08-23 15:17:03 | Attr = ]

SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 2007-09-05 01:09:46 | Attr = ]

Smitfraudfix -> %SystemDrive%\Smitfraudfix -> [Folder | Created Date = 2007-08-20 18:05:18 | Attr = ]

System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Created Date = 1782-11-30 03:04:26 | Attr = HS]

totalcmd -> %SystemDrive%\totalcmd -> [Folder | Created Date = 2007-08-18 09:50:23 | Attr = ]

treeinfo.wc -> %SystemDrive%\treeinfo.wc -> [Ver = | Size = 196893 bytes | Created Date = 2007-08-19 20:15:51 | Attr = H ]

WINDOWS -> %SystemRoot% -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Created Date = 2007-07-23 22:47:32 | Attr = H ]

$NtServicePackUninstallIDNMitigationAPIs$ -> %SystemRoot%\$NtServicePackUninstallIDNMitigationAPIs$ -> [Folder | Created Date = 2007-07-23 23:10:12 | Attr = H ]

$NtServicePackUninstallNLSDownlevelMapping$ -> %SystemRoot%\$NtServicePackUninstallNLSDownlevelMapping$ -> [Folder | Created Date = 2007-07-23 23:10:02 | Attr = H ]

$NtUninstallKB920342$ -> %SystemRoot%\$NtUninstallKB920342$ -> [Folder | Created Date = 2007-08-20 13:18:29 | Attr = H ]

$NtUninstallKB921503$ -> %SystemRoot%\$NtUninstallKB921503$ -> [Folder | Created Date = 2007-08-20 13:25:25 | Attr = H ]

$NtUninstallKB936021$ -> %SystemRoot%\$NtUninstallKB936021$ -> [Folder | Created Date = 2007-08-20 13:26:16 | Attr = H ]

$NtUninstallKB936782_WMP9$ -> %SystemRoot%\$NtUninstallKB936782_WMP9$ -> [Folder | Created Date = 2007-08-20 13:26:06 | Attr = H ]

$NtUninstallKB938828$ -> %SystemRoot%\$NtUninstallKB938828$ -> [Folder | Created Date = 2007-08-20 13:24:32 | Attr = H ]

$NtUninstallKB938829$ -> %SystemRoot%\$NtUninstallKB938829$ -> [Folder | Created Date = 2007-08-20 13:25:31 | Attr = H ]

$NtUninstallWIC$ -> %SystemRoot%\$NtUninstallWIC$ -> [Folder | Created Date = 2007-08-20 13:18:41 | Attr = H ]

$NtUninstallWMFDist11$ -> %SystemRoot%\$NtUninstallWMFDist11$ -> [Folder | Created Date = 2007-08-07 00:20:39 | Attr = H ]

$NtUninstallXPSEPSCLP$ -> %SystemRoot%\$NtUninstallXPSEPSCLP$ -> [Folder | Created Date = 2007-08-20 13:24:14 | Attr = H ]

addins -> %SystemRoot%\addins -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

ALCFDRTM.EXE -> %SystemRoot%\ALCFDRTM.EXE -> Realtek Semiconductor Corp. [Ver = 1.01 | Size = 60416 bytes | Created Date = 2007-07-26 15:19:39 | Attr = ]

ALCFDRTM.VER -> %SystemRoot%\ALCFDRTM.VER -> Realtek Semiconductor Corp. [Ver = 1.01 | Size = 60416 bytes | Created Date = 2007-07-26 15:19:39 | Attr = ]

alcrmv.exe -> %SystemRoot%\alcrmv.exe -> Realtek Semiconductor Corp. [Ver = 1, 9, 0, 1 | Size = 200704 bytes | Created Date = 2007-07-23 21:35:43 | Attr = ]

alcupd.exe -> %SystemRoot%\alcupd.exe -> Realtek Semiconductor Corp. [Ver = 2, 0, 0, 1 | Size = 294912 bytes | Created Date = 2007-07-23 21:35:43 | Attr = ]

AppPatch -> %SystemRoot%\AppPatch -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

ARJ.PIF -> %SystemRoot%\ARJ.PIF -> [Ver = | Size = 545 bytes | Created Date = 2007-08-18 09:50:23 | Attr = ]

Ascd_tmp.ini -> %SystemRoot%\Ascd_tmp.ini -> [Ver = | Size = 5733 bytes | Created Date = 2007-07-23 21:28:23 | Attr = ]

assembly -> %SystemRoot%\assembly -> [Folder | Created Date = 2007-07-23 21:44:24 | Attr = R S]

avrack.ini -> %SystemRoot%\avrack.ini -> [Ver = | Size = 164 bytes | Created Date = 2007-07-23 21:35:55 | Attr = ]

BissHM.ini -> %SystemRoot%\BissHM.ini -> [Ver = | Size = 251 bytes | Created Date = 2007-07-26 18:28:24 | Attr = ]

bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Created Date = 2007-07-23 21:08:16 | Attr = S]

Bulles de savon.bmp -> %SystemRoot%\Bulles de savon.bmp -> [Ver = | Size = 65978 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Created Date = 2007-09-05 00:41:26 | Attr = ]

CMDLIC.DLL -> %SystemRoot%\CMDLIC.DLL -> COMODO [Ver = | Size = 208896 bytes | Created Date = 2007-08-03 06:34:25 | Attr = ]

Config -> %SystemRoot%\Config -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

Connection Wizard -> %SystemRoot%\Connection Wizard -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

control.ini -> %SystemRoot%\control.ini -> [Ver = | Size = 0 bytes | Created Date = 2007-07-23 21:06:30 | Attr = ]

Cursors -> %SystemRoot%\Cursors -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

Debug -> %SystemRoot%\Debug -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

desktop.ini -> %SystemRoot%\desktop.ini -> [Ver = | Size = 2 bytes | Created Date = 2007-07-23 21:04:55 | Attr = ]

Downloaded Installations -> %SystemRoot%\Downloaded Installations -> [Folder | Created Date = 2007-07-23 21:30:52 | Attr = ]

Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Created Date = 2007-07-23 21:05:33 | Attr = S]

Driver Cache -> %SystemRoot%\Driver Cache -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

ehome -> %SystemRoot%\ehome -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

ERDNT -> %SystemRoot%\ERDNT -> [Folder | Created Date = 2007-09-05 00:42:28 | Attr = ]

Fonts -> %SystemRoot%\Fonts -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = R S]

gmer.dll -> %SystemRoot%\gmer.dll -> [Ver = 1, 0, 13, 12551 | Size = 585791 bytes | Created Date = 2007-08-23 20:29:25 | Attr = ]

gmer.exe -> %SystemRoot%\gmer.exe -> [Ver = 1, 0, 13, 12551 | Size = 581632 bytes | Created Date = 2007-08-23 20:29:25 | Attr = ]

gmer.ini -> %SystemRoot%\gmer.ini -> [Ver = | Size = 297 bytes | Created Date = 2007-08-23 20:29:26 | Attr = ]

gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [Ver = | Size = 80 bytes | Created Date = 2007-08-23 20:29:25 | Attr = ]

Granit vert.bmp -> %SystemRoot%\Granit vert.bmp -> [Ver = | Size = 26582 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

Help -> %SystemRoot%\Help -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

ie7 -> %SystemRoot%\ie7 -> [Folder | Created Date = 2007-07-23 23:10:20 | Attr = H ]

ie7updates -> %SystemRoot%\ie7updates -> [Folder | Created Date = 2007-07-25 12:24:40 | Attr = ]

ime -> %SystemRoot%\ime -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

inf -> %SystemRoot%\inf -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = H ]

Installer -> %SystemRoot%\Installer -> [Folder | Created Date = 2007-07-23 22:53:19 | Attr = HS]

Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Created Date = 2007-08-28 07:30:34 | Attr = ]

IsUninst.exe -> %SystemRoot%\IsUninst.exe -> InstallShield Software Corporation [Ver = 5, 51, 138, 0 | Size = 306688 bytes | Created Date = 2007-07-23 21:38:25 | Attr = ]

java -> %SystemRoot%\java -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

Jour de pêche.bmp -> %SystemRoot%\Jour de pêche.bmp -> [Ver = | Size = 17336 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

LHA.PIF -> %SystemRoot%\LHA.PIF -> [Ver = | Size = 545 bytes | Created Date = 2007-08-18 09:50:23 | Attr = ]

Media -> %SystemRoot%\Media -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

Microsoft.NET -> %SystemRoot%\Microsoft.NET -> [Folder | Created Date = 2007-07-23 21:44:24 | Attr = ]

mozver.dat -> %SystemRoot%\mozver.dat -> [Ver = | Size = 1595 bytes | Created Date = 2007-07-24 22:47:08 | Attr = ]

msagent -> %SystemRoot%\msagent -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

msapps -> %SystemRoot%\msapps -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

mui -> %SystemRoot%\mui -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

Mur de Santa Fe.bmp -> %SystemRoot%\Mur de Santa Fe.bmp -> [Ver = | Size = 65832 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [Ver = | Size = 69 bytes | Created Date = 2007-08-29 06:44:19 | Attr = ]

network diagnostic -> %SystemRoot%\network diagnostic -> [Folder | Created Date = 2007-07-23 23:09:17 | Attr = ]

nircmd.exe -> %SystemRoot%\nircmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 2007-09-05 00:41:26 | Attr = ]

NOCLOSE.PIF -> %SystemRoot%\NOCLOSE.PIF -> [Ver = | Size = 545 bytes | Created Date = 2007-08-18 09:50:23 | Attr = ]

ODBC.INI -> %SystemRoot%\ODBC.INI -> [Ver = | Size = 385 bytes | Created Date = 2007-08-05 20:11:26 | Attr = ]

ODBCINST.INI -> %SystemRoot%\ODBCINST.INI -> [Ver = | Size = 4205 bytes | Created Date = 2007-07-23 22:53:18 | Attr = ]

Offline Web Pages -> %SystemRoot%\Offline Web Pages -> [Folder | Created Date = 2007-07-23 21:05:33 | Attr = R ]

pchealth -> %SystemRoot%\pchealth -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

PeerNet -> %SystemRoot%\PeerNet -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

pestpatrol5.INI -> %SystemRoot%\pestpatrol5.INI -> [Ver = | Size = 0 bytes | Created Date = 2007-07-28 12:25:33 | Attr = ]

PIF -> %SystemRoot%\PIF -> [Folder | Created Date = 2007-08-14 22:47:46 | Attr = H ]

PKUNZIP.PIF -> %SystemRoot%\PKUNZIP.PIF -> [Ver = | Size = 545 bytes | Created Date = 2007-08-18 09:50:23 | Attr = ]

PKZIP.PIF -> %SystemRoot%\PKZIP.PIF -> [Ver = | Size = 545 bytes | Created Date = 2007-08-18 09:50:23 | Attr = ]

Plume.bmp -> %SystemRoot%\Plume.bmp -> [Ver = | Size = 16730 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

Prefetch -> %SystemRoot%\Prefetch -> [Folder | Created Date = 2007-07-23 21:09:14 | Attr = ]

Provisioning -> %SystemRoot%\Provisioning -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

pss -> %SystemRoot%\pss -> [Folder | Created Date = 2007-08-01 16:55:31 | Attr = ]

RAR.PIF -> %SystemRoot%\RAR.PIF -> [Ver = | Size = 545 bytes | Created Date = 2007-08-18 09:50:23 | Attr = ]

RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Created Date = 2007-07-31 09:56:21 | Attr = ]

Registration -> %SystemRoot%\Registration -> [Folder | Created Date = 2007-07-23 21:03:54 | Attr = ]

repair -> %SystemRoot%\repair -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

Resources -> %SystemRoot%\Resources -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

Rhododendron.bmp -> %SystemRoot%\Rhododendron.bmp -> [Ver = | Size = 17362 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

Rivière Sumida.bmp -> %SystemRoot%\Rivière Sumida.bmp -> [Ver = | Size = 26680 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

Rosace bleue 16.bmp -> %SystemRoot%\Rosace bleue 16.bmp -> [Ver = | Size = 1272 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

RtlExUpd.dll -> %SystemRoot%\RtlExUpd.dll -> Realtek Semiconductor Corp. [Ver = 1, 0, 0, 1 | Size = 192512 bytes | Created Date = 2007-07-23 21:35:37 | Attr = ]

RtlRack.ini -> %SystemRoot%\RtlRack.ini -> [Ver = | Size = 169 bytes | Created Date = 2007-07-27 23:52:54 | Attr = ]

security -> %SystemRoot%\security -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

SHELLNEW -> %SystemRoot%\SHELLNEW -> [Folder | Created Date = 2007-08-05 13:32:43 | Attr = ]

SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Created Date = 2007-07-23 21:09:15 | Attr = ]

SOUNDMAN.EXE -> %SystemRoot%\SOUNDMAN.EXE -> Realtek Semiconductor Corp. [Ver = | Size = 77824 bytes | Created Date = 2007-07-23 21:35:53 | Attr = ]

srchasst -> %SystemRoot%\srchasst -> [Folder | Created Date = 2007-07-23 21:04:45 | Attr = ]

SummerProperties.dll -> %SystemRoot%\SummerProperties.dll -> [Ver = 1, 2, 0, 0 | Size = 86016 bytes | Created Date = 2007-07-25 09:21:17 | Attr = ]

Sun -> %SystemRoot%\Sun -> [Folder | Created Date = 2007-07-23 22:42:19 | Attr = ]

SxsCaPendDel -> %SystemRoot%\SxsCaPendDel -> [Folder | Created Date = 2007-08-08 12:08:29 | Attr = ]

system -> %SystemRoot%\system -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

system32 -> %System32% -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

Tasks -> %SystemRoot%\Tasks -> [Folder | Created Date = 2007-07-23 21:04:48 | Attr = S]

Tasse à café.bmp -> %SystemRoot%\Tasse à café.bmp -> [Ver = | Size = 17062 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

Temp -> %SystemRoot%\Temp -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

twain_32 -> %SystemRoot%\twain_32 -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

UC.PIF -> %SystemRoot%\UC.PIF -> [Ver = | Size = 545 bytes | Created Date = 2007-08-18 09:50:23 | Attr = ]

UNBOC.EXE -> %SystemRoot%\UNBOC.EXE -> COMODO [Ver = 4.24.001 | Size = 241904 bytes | Created Date = 2007-08-03 06:34:26 | Attr = ]

unins000.dat -> %SystemRoot%\unins000.dat -> [Ver = | Size = 964 bytes | Created Date = 2007-08-21 15:08:50 | Attr = ]

uninst.exe -> %SystemRoot%\uninst.exe -> InstallShield Corporation, Inc. [Ver = 2.20.924.0 | Size = 299520 bytes | Created Date = 2007-08-07 22:47:40 | Attr = ]

Unwash6.exe -> %SystemRoot%\Unwash6.exe -> Webroot Software, Inc. [Ver = | Size = 69960 bytes | Created Date = 2007-08-28 06:26:21 | Attr = ]

vb.ini -> %SystemRoot%\vb.ini -> [Ver = | Size = 36 bytes | Created Date = 2007-07-23 21:03:58 | Attr = ]

vbaddin.ini -> %SystemRoot%\vbaddin.ini -> [Ver = | Size = 37 bytes | Created Date = 2007-07-23 21:03:58 | Attr = ]

Vent de prairie.bmp -> %SystemRoot%\Vent de prairie.bmp -> [Ver = | Size = 65954 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

WBEM -> %SystemRoot%\WBEM -> [Folder | Created Date = 2007-07-23 23:10:30 | Attr = ]

wcx_ftp.ini -> %SystemRoot%\wcx_ftp.ini -> [Ver = | Size = 135 bytes | Created Date = 2007-08-18 10:03:52 | Attr = ]

Web -> %SystemRoot%\Web -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = R ]

wincmd.ini -> %SystemRoot%\wincmd.ini -> [Ver = | Size = 4618 bytes | Created Date = 2007-08-18 09:50:23 | Attr = ]

WindowsShell.Manifest -> %SystemRoot%\WindowsShell.Manifest -> [Ver = | Size = 749 bytes | Created Date = 2007-07-23 21:05:28 | Attr = RH ]

winnt.bmp -> %SystemRoot%\winnt.bmp -> [Ver = | Size = 49102 bytes | Created Date = 2007-07-23 21:04:55 | Attr = HS]

winnt256.bmp -> %SystemRoot%\winnt256.bmp -> [Ver = | Size = 49102 bytes | Created Date = 2007-07-23 21:04:55 | Attr = HS]

WinSxS -> %SystemRoot%\WinSxS -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Created Date = 2007-07-23 21:06:21 | Attr = ]

WORDPAD.INI -> %SystemRoot%\WORDPAD.INI -> [Ver = | Size = 754 bytes | Created Date = 2007-07-25 15:21:41 | Attr = ]

Zapotec.bmp -> %SystemRoot%\Zapotec.bmp -> [Ver = | Size = 9522 bytes | Created Date = 2007-07-23 21:03:32 | Attr = ]

zipinst.exe -> %SystemRoot%\zipinst.exe -> NirSoft [Ver = 1.21 | Size = 39424 bytes | Created Date = 2007-09-04 18:07:47 | Attr = ]

desktop.ini -> %SystemRoot%\tasks\desktop.ini -> [Ver = | Size = 65 bytes | Created Date = 2007-07-23 21:04:48 | Attr = RH ]

SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Created Date = 2007-07-23 21:09:14 | Attr = H ]

$winnt$.inf -> %System32%\$winnt$.inf -> [Ver = | Size = 261 bytes | Created Date = 2007-07-23 22:51:38 | Attr = ]

1025 -> %System32%\1025 -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

1028 -> %System32%\1028 -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

1031 -> %System32%\1031 -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

1033 -> %System32%\1033 -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

1036 -> %System32%\1036 -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

1037 -> %System32%\1037 -> [Folder | Created Date = 2007-07-23 22:49:00 | Attr = ]

< End of report >



Merci par avance je signale que j'ai SafeXP et XP AntiSpy .






Là, je ne vois pas comment t'aider. Si j'ai une idéee je te préviens.

Normalement si tu réactive les maj avec, zeb restore, ça rajoute les clefs.


Que se passe t'il quand tu te vas sur le site de Microsoft pour faire les màj?







4soir Xeti,


ZebRestore n'as rien changer pas mieux après.


Sinon, j'ai formater le recour ultime pour que sa s'arrête, mais bon le formatage c'est pas trop bien passé donc je repars pour un autre sujet.


Voilà les news, mais je remercie tout ceux qui m'ont apporter leur aide et de leur temps, merci.



