Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

probleme avec magicControl.agent


binacalista
 Partager

Messages recommandés

bonjour a tous

J'ai été sur de nombreux forum pour trouver une solution a mon probleme mais rien n'y fait.

Depuis quelques semaines j'ai magicControl.agent qui s'affiche lorsque je fais tourner spybot et de plus des que j'ouvre une page via internet explorer j'ai des pubs qui s'ouvre en grand. Quelqu'un peut il m'aider a résoudre définitivement ce probleme sans avoir a reformater totalement mon pc?

j'ai pris hijackthis pour tenter de voir où était le probleme mais j'y comprends rien.

Quelqu'un peut il m'aider? :P

 

Logfile of HijackThis v1.99.1

Scan saved at 12:27:08, on 17/01/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe

C:\Program Files\Acer\eRecovery\Monitor.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\WINDOWS\System32\FTRTSVC.exe

C:\Program Files\Acer\Acer eMode Management\AspireService.exe

C:\Program Files\Acer\Acer eConsole\MediaSync.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\LVCOMSX.EXE

C:\Program Files\MessengerPlus! 3\MsgPlus.exe

C:\PROGRA~1\Wanadoo\TaskBarIcon.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\PROGRA~1\Wanadoo\ComComp.exe

C:\PROGRA~1\Wanadoo\Toaster.exe

C:\PROGRA~1\Wanadoo\Inactivity.exe

C:\PROGRA~1\Wanadoo\PollingModule.exe

C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\PROGRA~1\Wanadoo\Watch.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\eMule\emule.exe

C:\DOCUME~1\NAT&SA~1\LOCALS~1\Temp\ICEOWS\ViewUpd\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

O4 - HKLM\..\Run: [LaunchApp] Alaunch

O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"

O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe

O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe

O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe

O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)

O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)

O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1135069124750

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} - http://scripts.downloadv3.com/binaries/IA/...svc32_FR_XP.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Lien vers le commentaire
Partager sur d’autres sites

salut binacalista et bienvenue sur le forum :P

 

Peut tu ouvrir hijackthis =>"Open the Misc Tools Section"=>"Open Uninstall Manager" et poster le rapport ici?

 

Puis tu cliques sur "Back" et tu coches la ligne suivante:

O16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} - http://scripts.downloadv3.com/binaries/IA/...svc32_FR_XP.cab

-Ferme tous les programmes et clique sur "Fix Checked"

 

A ceci j'ajoute un scan en ligne:

 

-Faire un scan en ligne ici et coller le rapport.

Panda si tu n'y arrive pas : tutorial

 

-Deux remarques :

 

C:\Program Files\eMule\emule.exe => contraire à la charte du forum! principale source d'infection sur un pc!!

 

C:\DOCUME~1\NAT&SA~1\LOCALS~1\Temp\ICEOWS\ViewUpd\HijackThis.exe => désinstalle hijackthis et réinstalle le dans C:\Program Files par exemple(pas dans un répertoire temporaire, sinon tu ne bénéficieras pas des sauvegardes)

Modifié par charles ingals
Lien vers le commentaire
Partager sur d’autres sites

merci pour ta réponse charles ingalls ! voici le rapport

Acer eConsole

Acer eMode Management

Ad-Aware SE Personal

Adobe Reader 7.0

Athlon 64 Processor Driver

ATI Display Driver

avast! Antivirus

Colour Options 1.3 (beta) for The Sims 2

Correctif Windows XP - KB867282

Correctif Windows XP - KB873339

Correctif Windows XP - KB885250

Correctif Windows XP - KB885835

Correctif Windows XP - KB885836

Correctif Windows XP - KB885884

Correctif Windows XP - KB886185

Correctif Windows XP - KB887472

Correctif Windows XP - KB887742

Correctif Windows XP - KB888113

Correctif Windows XP - KB888302

Correctif Windows XP - KB890047

Correctif Windows XP - KB890175

Correctif Windows XP - KB890859

Correctif Windows XP - KB890923

Correctif Windows XP - KB891781

Correctif Windows XP - KB893086

ENPC PersoTEST

EPSON Attach To Email

EPSON Copy Utility 3

EPSON Easy Photo Print

EPSON File Manager

EPSON Image Clip Palette

EPSON Logiciel imprimante

EPSON Scan

EPSON Scan Assistant

EPSON Web-To-Page

ESDX3800 Guide d'utilisation

HijackThis 1.99.1

Iceows V4.20b

J2SE Runtime Environment 5.0 Update 2

J2SE Runtime Environment 5.0 Update 6

JVTorrent 1.1

Language pack for Ad-Aware SE

Lecteur Windows Media 10

Les Sims 2

Livebox

Macromedia Flash Player 8

Macromedia Shockwave Player

Madskin

Messenger Plus! 3

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1 French Language Pack

Microsoft .NET Framework 1.1 Hotfix (KB886903)

Microsoft Office XP Professional avec FrontPage

Microsoft Works

Mise à jour de sécurité pour Windows XP (KB890046)

Mise à jour de sécurité pour Windows XP (KB893066)

Mise à jour de sécurité pour Windows XP (KB893756)

Mise à jour de sécurité pour Windows XP (KB896358)

Mise à jour de sécurité pour Windows XP (KB896422)

Mise à jour de sécurité pour Windows XP (KB896423)

Mise à jour de sécurité pour Windows XP (KB896424)

Mise à jour de sécurité pour Windows XP (KB896428)

Mise à jour de sécurité pour Windows XP (KB896688)

Mise à jour de sécurité pour Windows XP (KB899587)

Mise à jour de sécurité pour Windows XP (KB899591)

Mise à jour de sécurité pour Windows XP (KB900725)

Mise à jour de sécurité pour Windows XP (KB901017)

Mise à jour de sécurité pour Windows XP (KB901214)

Mise à jour de sécurité pour Windows XP (KB902400)

Mise à jour de sécurité pour Windows XP (KB904706)

Mise à jour de sécurité pour Windows XP (KB905414)

Mise à jour de sécurité pour Windows XP (KB905749)

Mise à jour de sécurité pour Windows XP (KB905915)

Mise à jour de sécurité pour Windows XP (KB908519)

Mise à jour de sécurité pour Windows XP (KB912919)

Mise à jour pour Windows XP (KB894391)

Mise à jour pour Windows XP (KB896727)

Mise à jour pour Windows XP (KB898461)

Mise à jour pour Windows XP (KB910437)

Mozilla Firefox (1.5)

MSN Messenger 7.5

Music Transfer pavit Edition

NTI Backup NOW! 4

NTI CD & DVD-Maker

NTI HomeVideo-Maker

NVIDIA Drivers

NvMixer

Outil de connexion Wanadoo

PIF DESIGNER

PowerDVD

Programme de gestion Camera de Logitech®

RealPlayer

SLD Codec Pack

Spybot - Search & Destroy 1.4

VideoLAN VLC media player 0.8.4a

Windows Genuine Advantage v1.3.0254.0

Windows Installer 3.1 (KB893803)

Windows Media Format Runtime

ZoneAlarm

 

 

j'ai essayé de faire un scan en ligne mais mon antivirus n'a pas accepté l'acces a panda en m'avertissant qu'il yavait un vers.

De plus aucun antivirus na réussi a me détecter magiccontrol.agent. seul spybot le détecte.

MagicControl.Agent: Réglages utilisateur (Clé du registre, nothing done)

HKEY_USERS\S-1-5-21-2011925375-3653460283-2877552486-1006\Software\LanConfig

 

 

j'ai désinstallé emule, de toute facon je l'utilisais plus depuis bien longtemps.

Jai refais tourner spybot et il me le trouve toujours...tu sais quoi faire?

Lien vers le commentaire
Partager sur d’autres sites

Salut binacalista

 

On va traquer "MagicControl.Agent" dans la base de registre et l'éliminer!

 

Fais ceci stp:

 

Télécharge RegSearch.exe (Registry Search de Bobbi Flekman) -> http://www.bleepingcomputer.com/files/misc/regsearch.zip

- dézippe dans un répertoire dédié tel que C:\Program Files

- double clique sur RegSearch.exe

- copie colle LanConfig dans la première ligne de la zone de recherche

- rien dans la deuxième ligne de la zone de recherche

- clique sur OK

- après recherche, le bloc-notes ouvre une fenêtre "RegSearch.txt" avec toutes les instances trouvées

- le fichier est en outre sauvegardé dans le même répertoire que celui de RegSearch

- copie-colle le contenu de la fenêtre dans un post, ici

- ferme le bloc-notes

- ferme RegSearch par Cancel

 

Fais de même pour mslagent et SA

 

Poste le rapport. De plus , je te demanderai ceci=>

 

Télécharge silentrunners sur le bureau:

 

http://www.silentrunners.org/Silent%20Runners.zip

 

Dézippe le fichier dans un dossier . double clique sur le fichier "silentrunners.vbs" :une fenêtre va s'ouvrir ,clique sur "oui" . Poste le rapport qui a été généré.

Lien vers le commentaire
Partager sur d’autres sites

REGEDIT4

 

; Registry Search by Bobbi Flekman © 2005

; Version: 1.0.2.4

 

; Results at 17/01/2006 23:36:01 for strings:

; 'lanconfig '

; Strings excluded from search:

; (None)

; Search in:

; Registry Keys Registry Values Registry Data

; HKEY_LOCAL_MACHINE HKEY_USERS

 

 

; End Of The Log...

 

REGEDIT4

 

; Registry Search by Bobbi Flekman © 2005

; Version: 1.0.2.4

 

; Results at 17/01/2006 23:38:50 for strings:

; 'mslagent'

; Strings excluded from search:

; (None)

; Search in:

; Registry Keys Registry Values Registry Data

; HKEY_LOCAL_MACHINE HKEY_USERS

 

 

; End Of The Log...

 

 

REGEDIT4

 

; Registry Search by Bobbi Flekman © 2005

; Version: 1.0.2.4

 

; Results at 17/01/2006 23:42:20 for strings:

; 'sa'

; Strings excluded from search:

; (None)

; Search in:

; Registry Keys Registry Values Registry Data

; HKEY_LOCAL_MACHINE HKEY_USERS

 

 

[HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\7]

"Identifier"="ISA"

 

[HKEY_LOCAL_MACHINE\SAM]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\acer\AspireEMode]

"DisableLaunchKey"=dword:00000000

 

[HKEY_LOCAL_MACHINE\SOFTWARE\acer\MediaServerService]

"AlwaysAllow"=dword:00000000

 

[HKEY_LOCAL_MACHINE\SOFTWARE\acer\MediaServerService]

"DefaultAccessAllow"=dword:00000001

 

[HKEY_LOCAL_MACHINE\SOFTWARE\C07ft5Y]

@="SafeDisc RefCount"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ADE]

"ZAMailSafeExt"="zl0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ADP]

"ZAMailSafeExt"="zl1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asa]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asx]

"ZAMailSafeExt"="zlz"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.BAS]

"ZAMailSafeExt"="zl2"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat]

"ZAMailSafeExt"="zl3"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.chm]

"ZAMailSafeExt"="zl4"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd]

"ZAMailSafeExt"="zl5"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.com]

"ZAMailSafeExt"="zl6"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cpl]

"ZAMailSafeExt"="zl7"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.crt]

"ZAMailSafeExt"="zl8"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.DBX]

"ZAMailSafeExt"="zm0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.disabled]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.disabled]

@="SpybotSD.DisabledFile"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dll]

"ZAMailSafeExt"="zmb"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.eml]

@="Microsoft Internet Mail Message"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.eml]

"Content Type"="message/rfc822"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.eml]

"ZAMailSafeExt"="zmc"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe]

"ZAMailSafeExt"="zl9"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hlp]

"ZAMailSafeExt"="zla"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hta]

"ZAMailSafeExt"="zlb"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf]

"ZAMailSafeExt"="zlc"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ins]

"ZAMailSafeExt"="zld"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.isp]

"ZAMailSafeExt"="zle"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.js]

"ZAMailSafeExt"="z0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.JSE]

"ZAMailSafeExt"="zlf"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lnk]

"ZAMailSafeExt"="zlg"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.MDA]

"ZAMailSafeExt"="zm1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mdb]

"ZAMailSafeExt"="zlh"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.MDE]

"ZAMailSafeExt"="zli"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.MDZ]

"ZAMailSafeExt"="zm2"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mht]

"Content Type"="message/rfc822"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mht]

"ZAMailSafeExt"="zm8"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mhtml]

"Content Type"="message/rfc822"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msc]

"ZAMailSafeExt"="zlj"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msi]

"ZAMailSafeExt"="zlk"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msp]

"ZAMailSafeExt"="zll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.MST]

"ZAMailSafeExt"="zlm"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.NCH]

"ZAMailSafeExt"="zm3"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.nws]

@="Microsoft Internet News Message"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.nws]

"Content Type"="message/rfc822"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ocx]

"ZAMailSafeExt"="zmd"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.PCD]

"ZAMailSafeExt"="zln"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pif]

"ZAMailSafeExt"="zlo"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.prf]

"ZAMailSafeExt"="zm4"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.qds]

@="SavedDsQuery"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar]

"ZAMailSafeExt"="zma"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg]

"ZAMailSafeExt"="zlp"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sam]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sam\AmiProDocument]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sam\AmiProDocument\ShellNew]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sam\AmiProDocument\ShellNew]

"FileName"="amipro.sam"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.scf]

"ZAMailSafeExt"="zm5"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.scr]

"ZAMailSafeExt"="zlq"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sct]

"ZAMailSafeExt"="zlr"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.shb]

"ZAMailSafeExt"="zm6"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.shs]

"ZAMailSafeExt"="zls"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sys]

"ZAMailSafeExt"="zme"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.url]

"ZAMailSafeExt"="zlt"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.VB]

"ZAMailSafeExt"="z1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.VBE]

"ZAMailSafeExt"="zlu"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.vbs]

"ZAMailSafeExt"="zlv"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wms]

"ZAMailSafeExt"="zm7"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wsc]

"ZAMailSafeExt"="zlw"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.WSF]

"ZAMailSafeExt"="zlx"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.WSH]

"ZAMailSafeExt"="zly"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.z0]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.z1]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip]

"ZAMailSafeExt"="zm9"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl0]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl1]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl2]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl3]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl4]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl5]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl6]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl7]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl8]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zl9]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zla]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlb]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlc]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zld]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zle]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlf]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlg]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlh]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zli]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlj]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlk]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zll]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlm]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zln]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlo]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlp]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlq]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlr]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zls]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlt]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlu]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlv]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlw]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlx]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zly]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zlz]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm0]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm1]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm2]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm3]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm4]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm5]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm6]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm7]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm8]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zm9]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zma]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zmb]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zmc]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zmd]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zme]

@="ZAMailSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Character.2\DefaultIcon]

@="C:\\WINDOWS\\msagent\\agentdpv.dll,-201"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Character2.2\DefaultIcon]

@="C:\\WINDOWS\\msagent\\agentdp2.dll,-201"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Preview.2\DefaultIcon]

@="C:\\WINDOWS\\msagent\\agentdp2.dll,-201"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIFFFile\shell\open]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIFFFile\shell\play]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\OSA.EXE]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASFFile\shell\open]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASFFile\shell\play]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASXFile\shell\open]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASXFile\shell\play]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AUFile\shell\open]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AUFile\shell\play]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoDiscovery.EmailAssociations]

@="Associations de messagerie"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoDiscovery.EmailAssociations.1]

@="Associations de messagerie"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoDiscovery.Mail]

@="Découverte automatique de messagerie Windows"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AutoDiscovery.Mail.1]

@="Découverte automatique de messagerie Windows"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AVIFile\shell\open]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AVIFile\shell\play]

"LegacyDisable"=""

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ATSCComponentType]

@="Classe type de composant ATSC de modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ATSCComponentType.1]

@="Classe type de composant ATSC de modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Component]

@="Classe composant modèle de réglage BDA (sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Component.1]

@="Classe composant modèle de réglage BDA (sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ComponentType]

@="Classe de type composant modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ComponentType.1]

@="Classe de type composant modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ComponentTypes]

@="Collection des types composant de modèle de réglage BDA (types sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.ComponentTypes.1]

@="Collection des types composant de modèle de réglage BDA (types sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants]

@="Regroupement des composants de modèle de réglage BDA (sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants\CurVer]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants\CurVer]

@="BDATuner.Composants.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants.1]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants.1]

@="Regroupement des composants de modèle de réglage BDA (sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.Composants.1\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.DVBSLocator]

@="Recherche de satellite DVB de modèle de réglage BDA"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.DVBSLocator.1]

@="Recherche de satellite DVB de modèle de réglage BDA"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.DVBSTuningSpace]

@="Espace de réglage DVB-Satellite du modèle de réglage BDA"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.DVBSTuningSpace.1]

@="Espace de réglage DVB-Satellite du modèle de réglage BDA"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.LanguageComponentType]

@="Classe type de composant langue du modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.LanguageComponentType.1]

@="Classe type de composant langue du modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.MPEG2Component]

@="Classe composant MPEG2 de modèle de réglage BDA (sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.MPEG2Component.1]

@="Classe composant MPEG2 de modèle de réglage BDA (sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.MPEG2ComponentType]

@="Classe type de composant MPEG2 de modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BDATuner.MPEG2ComponentType.1]

@="Classe type de composant MPEG2 de modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CatSrv.RegDBCompensator]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CatSrv.RegDBCompensator]

@="RegDBCompensator Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CatSrv.RegDBCompensator\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Catsrv.RegDBCompensator.1]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Catsrv.RegDBCompensator.1]

@="RegDBCompensator Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Catsrv.RegDBCompensator.1\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage]

@="CdoCalendarMessage Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage\CurVer]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage\CurVer]

@="CDO.CalendarMessage.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage.1]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage.1]

@="CdoCalendarMessage Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.CalendarMessage.1\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message]

@="CDOMessage Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message\CurVer]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message\CurVer]

@="CDO.Message.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message.1]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message.1]

@="CDOMessage Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CDO.Message.1\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.CertMgrSaferWindowsExtensionObject.1]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.CertMgrSaferWindowsExtensionObject.1]

@="Objet SAFER Windows 1.0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.CertMgrSaferWindowsExtensionObject.1\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.SaferWindowsAboutObject.1]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.SaferWindowsAboutObject.1]

@="Objet SAFER Windows 1.0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CERTMGR.SaferWindowsAboutObject.1\CLSID]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msado15.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000061B-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0000061E-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000621-0000-0010-8000-00AA006D2EA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadox.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C101D-0000-0000-C000-000000000046}]

@="Microsoft Windows Installer Message RPC"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C101D-0000-0000-C000-000000000046}\ProgId]

@="WindowsInstaller.Message"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{008FD5DD-6DBB-48e3-991B-2D3ED658516A}]

@="Découverte automatique de messagerie Windows"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}]

@="Saisie semi-automatique Microsoft"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00BB2764-6A77-11D0-A535-00C04FD7D062}]

@="Liste de saisie semi-automatique de l'historique Microsoft"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}]

@="Conteneur de la liste de saisie semi-automatique multiple Microsoft"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}]

@="Liste de saisie semi-automatique du dossier Shell Microsoft"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04F34B7F-0241-455A-9DCD-25471E111409}]

@="SAFRemoteDesktopManager Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04F34B7F-0241-455A-9DCD-25471E111409}\InprocServer32]

@="C:\\WINDOWS\\system32\\safrdm.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04F34B7F-0241-455A-9DCD-25471E111409}\ProgID]

@="ISAFrdm.SAFRemoteDesktopManager.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04F34B7F-0241-455A-9DCD-25471E111409}\VersionIndependentProgID]

@="ISAFrdm.SAFRemoteDesktopManager"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{055CB2D7-2969-45CD-914B-76890722F112}]

@="Classe composant MPEG2 de modèle de réglage BDA (sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0655E396-25D0-11D3-9C26-00C04F8EF87C}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0655E396-25D0-11D3-9C26-00C04F8EF87C}\ProgID]

@="SAPI.SpLexicon.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0655E396-25D0-11D3-9C26-00C04F8EF87C}\VersionIndependentProgID]

@="SAPI.SpLexicon"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{079AA557-4A18-424A-8EEE-E39F0A8D41B9}]

@="SAX XML Reader"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{079AA557-4A18-424A-8EEE-E39F0A8D41B9}\ProgID]

@="Msxml2.SAXXMLReader"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{079AA557-4A18-424A-8EEE-E39F0A8D41B9}\VersionIndependentProgID]

@="Msxml2.SAXXMLReader"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{33FACFE0-A9BE-11D0-A520-00A0D10129C0}]

"FriendlyName"="SAMI (CC) Parser"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{7F1232EE-44D7-4494-AB8B-CC61B10E21A5}]

"FriendlyName"="WMT Sample Information Filter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{C1F400A0-3F08-11D3-9F0B-006008039E37}]

"FriendlyName"="SampleGrabber"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08CD963F-7A3E-4F5C-9BD8-D692BB043C5B}]

@="TF_MSAAControl"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0944D16C-D0F4-4389-982A-A085595A9EB3}\verb\2]

@="&Save Skin,0,2"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DAD5531-BF31-43AC-A513-1F8926BBF5EC}]

@="SafeWia Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DAD5531-BF31-43AC-A513-1F8926BBF5EC}\ProgID]

@="SafeWia.Script.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DAD5531-BF31-43AC-A513-1F8926BBF5EC}\VersionIndependentProgID]

@="SafeWia.Script"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}]

@="Microsoft.JScript.JSAuthor"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}\InprocServer32]

"Class"="Microsoft.JScript.JSAuthor"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}\InprocServer32\7.0.5000.0]

"Class"="Microsoft.JScript.JSAuthor"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}\ProgId]

@="Microsoft.JScript.JSAuthor"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F92030A-CBFD-4AB8-A164-FF5985547FF6}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\SAPI.DLL"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F92030A-CBFD-4AB8-A164-FF5985547FF6}\ProgID]

@="SAPI.SpTextSelectionInformation.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F92030A-CBFD-4AB8-A164-FF5985547FF6}\VersionIndependentProgID]

@="SAPI.SpTextSelectionInformation"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FA9F4D5-A173-11D1-AA62-00C04FA34D72}\InprocServer32]

@="C:\\WINDOWS\\msagent\\agentsr.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FF15AA1-2F93-11d1-83B0-00C04FBD7C09}]

@="CLSID_CCommNewsAcctImport"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{101A8FB9-F1B9-11d1-9A56-00C04FA309D4}]

@="CLSID_MessageStore"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12D73610-A1C9-11D3-BC90-00C04F72DF9F}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12D73610-A1C9-11D3-BC90-00C04F72DF9F}\ProgID]

@="SAPI.SpITNProcessor.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12D73610-A1C9-11D3-BC90-00C04F72DF9F}\VersionIndependentProgID]

@="SAPI.SpITNProcessor"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13709620-C279-11CE-A49E-444553540000}]

@="Service d'automatisation de l'interface"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{143A62C8-C33B-11D1-84FE-00C04FA34A14}\InprocServer32]

@="C:\\WINDOWS\\msagent\\agentpsh.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1443904B-34E4-40F6-B30F-6BEB81267B80}]

@="Cicero SAPI Layer Speech UI Server"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{152A1E9D-352F-4F25-87F6-0A18312D9F45}\ProgID]

@="MS.WinCE.WorksAB"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17869501-36C8-11d1-83B7-00C04FBD7C09}]

@="CLSID_CNExpressAcctImport"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{193B4137-0480-11D1-97DA-00C04FB9618A}]

@="Microsoft DTC Transaction Unmarshaller (private, internal)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2AFB92-0B5E-4A30-B5CC-353DB4F9E150}]

@="SpSapiServer Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2AFB92-0B5E-4A30-B5CC-353DB4F9E150}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2E3B3F-490A-4f4c-8C76-D94F59FE6400}]

@="Microsoft.Vsa.Vb.CodeDOM.Location"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2E3B3F-490A-4f4c-8C76-D94F59FE6400}\InprocServer32]

"Class"="Microsoft.Vsa.Vb.CodeDOM.Location"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2E3B3F-490A-4f4c-8C76-D94F59FE6400}\InprocServer32]

"Assembly"="Microsoft.Vsa.Vb.CodeDOMProcessor, Version=7.0.5000.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B2E3B3F-490A-4f4c-8C76-D94F59FE6400}\ProgId]

@="Microsoft.Vsa.Vb.CodeDOM.Location"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BE49F30-0E1B-11D3-9D8E-00C04F72D980}]

@="Classe type de composant langue du modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1DF7D126-4050-47F0-A7CF-4C4CA9241333}]

@="Recherche de satellite DVB de modèle de réglage BDA"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}]

@="System.Security.Cryptography.DSASignatureDeformatter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}\InprocServer32]

"Class"="System.Security.Cryptography.DSASignatureDeformatter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}\InprocServer32\1.0.5000.0]

"Class"="System.Security.Cryptography.DSASignatureDeformatter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}\ProgId]

@="System.Security.Cryptography.DSASignatureDeformatter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F823A6A-863F-11D1-A484-00C04FB93753}]

@="Composant logiciel enfichable d'extension des modèles de certificats d'Autorité de certification"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F823A6A-863F-11D1-A484-00C04FB93753}\ProgID]

@="Snapin.PolicySettingsAbout.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F823A6A-863F-11D1-A484-00C04FB93753}\VersionIndependentProgID]

@="Snapin.PolicySettingsAbout"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{228136B0-8BD3-11D0-B4EF-00A0C9138CA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadomd.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{228136B8-8BD3-11D0-B4EF-00A0C9138CA4}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\ado\\msadomd.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22E24591-49D0-11D2-BB50-006008320064}\InprocServer32]

@="C:\\WINDOWS\\system32\\msadds32.ax"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{233A9692-667E-11d1-9DFB-006097D50408}]

@="Outlook Express Message List"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{233A9692-667E-11d1-9DFB-006097D50408}\ProgID]

@="OutlookExpress.MessageList.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{233A9692-667E-11d1-9DFB-006097D50408}\VersionIndependentProgID]

@="OutlookExpress.MessageList"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24800CD0-0F4E-4df7-9F69-3C6903C89224}\ProgID]

@="VsaVbRT.7.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24800CD0-0F4E-4df7-9F69-3C6903C89224}\Server]

@="VsaVb7rt.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24800CD0-0F4E-4df7-9F69-3C6903C89224}\VersionIndependentProgID]

@="VsaVbRT"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{248FCFB3-5914-AF2C-CCBA-9BB5E3C749D5}]

@="TF_MSAAControl"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24EEC005-3938-3C71-821D-7F68FD850B2D}]

@="System.Runtime.Remoting.Messaging.RemotingSurrogateSelector"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24EEC005-3938-3C71-821D-7F68FD850B2D}\InprocServer32]

"Class"="System.Runtime.Remoting.Messaging.RemotingSurrogateSelector"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24EEC005-3938-3C71-821D-7F68FD850B2D}\InprocServer32\1.0.5000.0]

"Class"="System.Runtime.Remoting.Messaging.RemotingSurrogateSelector"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24EEC005-3938-3C71-821D-7F68FD850B2D}\ProgId]

@="System.Runtime.Remoting.Messaging.RemotingSurrogateSelector"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25642426-028D-4474-977B-111BB114FE3E}\InProcServer32]

@="C:\\WINDOWS\\system32\\msaatext.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27016870-8E02-11D1-924E-00C04FBBBFB3}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\msadc\\msdarem.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{280A7B65-8F00-438F-989B-8EAF9E438A71}]

@="Objet SAFER Windows 1.0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{280A7B65-8F00-438F-989B-8EAF9E438A71}\ProgID]

@="CERTMGR.SaferWindowsAboutObject.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{280A7B65-8F00-438F-989B-8EAF9E438A71}\VersionIndependentProgID]

@="CERTMGR.SaferWindowsAboutObject.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2AFA62E2-5548-11D1-A6E1-006097C4E476}]

@="ppDSApp Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D12DD17-6C4E-456E-A953-D210E3C64176}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}]

@="DHTML Edit Control Safe for Scripting for IE5"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\ProgID]

@="DHTMLSafe.DHTMLSafe.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D360201-FFF5-11d1-8D03-00A0C959BC0A}\VersionIndependentProgID]

@="DHTMLSafe.DHTMLSafe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}]

@="System.Runtime.InteropServices.SafeArrayTypeMismatchException"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}\InprocServer32]

"Class"="System.Runtime.InteropServices.SafeArrayTypeMismatchException"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}\InprocServer32\1.0.5000.0]

"Class"="System.Runtime.InteropServices.SafeArrayTypeMismatchException"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}\ProgId]

@="System.Runtime.InteropServices.SafeArrayTypeMismatchException"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f819-98b5-11cf-bb82-00aa00bdce0b}]

@="HtmlDlgSafeHelper Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f819-98b5-11cf-bb82-00aa00bdce0b}\ProgID]

@="HtmlDlgSafeHelper.HtmlDlgSafeHelper.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3050f819-98b5-11cf-bb82-00aa00bdce0b}\VersionIndependentProgID]

@="HtmlDlgSafeHelper.HtmlDlgSafeHelper"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3124C396-FB13-4836-A6AD-1317F1713688}]

@="SAX XML Reader 3.0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3124C396-FB13-4836-A6AD-1317F1713688}\ProgID]

@="Msxml2.SAXXMLReader.3.0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3124C396-FB13-4836-A6AD-1317F1713688}\VersionIndependentProgID]

@="Msxml2.SAXXMLReader"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33102459-4B30-11d2-A6DC-00C04F79E7C8}]

@="CLSID_CNavNewsAcctImport"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33FACFE0-A9BE-11D0-A520-00A0D10129C0}]

@="SAMI (CC) Reader"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3449A1C8-C56C-11D0-AD72-00C04FC29863}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\msadc\\msadds.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{364D8E0B-67CB-4547-9948-9E7F1B1743ED}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737A-DD75-11D2-966A-00C04F79487A}\ProgID]

@="PKMSA.AddStartAddress.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737A-DD75-11D2-966A-00C04F79487A}\VersionIndependentProgID]

@="PKMSA.AddStartAddress"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737B-DD75-11D2-966A-00C04F79487A}\ProgID]

@="PKMSA.StartAddressCommands.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737B-DD75-11D2-966A-00C04F79487A}\VersionIndependentProgID]

@="PKMSA.StartAddressCommands"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737C-DD75-11D2-966A-00C04F79487A}\ProgID]

@="PKMSA.CatalogCommands.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3753737C-DD75-11D2-966A-00C04F79487A}\VersionIndependentProgID]

@="PKMSA.CatalogCommands"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3918D75F-0ACB-41F2-B733-92AA15BCECF6}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3918D75F-0ACB-41F2-B733-92AA15BCECF6}\ProgID]

@="SAPI.SpObjectTokenEnum.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3918D75F-0ACB-41F2-B733-92AA15BCECF6}\VersionIndependentProgID]

@="SAPI.SpObjectTokenEnum"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F8D76B-0928-11D1-97DF-00C04FB9618A}]

@="Microsoft DTC Transaction"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BC4F3A1-652A-11D1-B4D4-00C04FC2DB8D}\ProgID]

@="Microsoft.ISAdm.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BC4F3A1-652A-11D1-B4D4-00C04FC2DB8D}\VersionIndependentProgID]

@="Microsoft.ISAdm"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BEE4890-4FE9-4A37-8C1E-5E7E12791C1F}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BEE4890-4FE9-4A37-8C1E-5E7E12791C1F}\ProgID]

@="Sapi.SpSharedRecognizer.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3BEE4890-4FE9-4A37-8C1E-5E7E12791C1F}\VersionIndependentProgID]

@="Sapi.SpSharedRecognizer"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E784A01-F3AE-4DC0-9354-9526B9370EBA}]

@="SAXAttributes 3.0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E784A01-F3AE-4DC0-9354-9526B9370EBA}\ProgID]

@="Msxml2.SAXAttributes.3.0"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E784A01-F3AE-4DC0-9354-9526B9370EBA}\VersionIndependentProgID]

@="Msxml2.SAXAttributes"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F276EB4-70EE-11D1-8A0F-00C04FB93753}]

@="Composant logiciel enfichable d'extension des modèles de certificats d'Autorité de certification"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3f454f0e-42ae-4d7c-8ea3-328250d6e272}]

@="Automatisation du menu de contexte"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3FF292B6-B204-11CF-8D23-00AA005FFE58}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\msadc\\msadce.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{418008F3-CF67-4668-9628-10DC52BE1D08}]

@="Classe type de composant MPEG2 de modèle de réglage BDA (type sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41B89B6B-9399-11D2-9623-00C04F8EE628}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41B89B6B-9399-11D2-9623-00C04F8EE628}\ProgID]

@="Sapi.SpInprocRecognizer.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41B89B6B-9399-11D2-9623-00C04F8EE628}\VersionIndependentProgID]

@="Sapi.SpInprocRecognizer"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{455F24E9-7396-4A16-9715-7C0FDBE3EFE3}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{455F24E9-7396-4A16-9715-7C0FDBE3EFE3}\ProgID]

@="SAPI.SpNullPhoneConverter.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{455F24E9-7396-4A16-9715-7C0FDBE3EFE3}\VersionIndependentProgID]

@="SAPI.SpNullPhoneConverter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47206204-5ECA-11D2-960F-00C04F8EE628}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47206204-5ECA-11D2-960F-00C04F8EE628}\ProgID]

@="SAPI.SpSharedRecoContext.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47206204-5ECA-11D2-960F-00C04F8EE628}\VersionIndependentProgID]

@="SAPI.SpSharedRecoContext"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BAC124B-78C8-11D1-B9A8-00C04FD97575}\InprocServer32]

@="C:\\WINDOWS\\msagent\\agentmpx.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}]

@="System.Runtime.InteropServices.SafeArrayRankMismatchException"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}\InprocServer32]

"Class"="System.Runtime.InteropServices.SafeArrayRankMismatchException"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}\InprocServer32\1.0.5000.0]

"Class"="System.Runtime.InteropServices.SafeArrayRankMismatchException"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}\ProgId]

@="System.Runtime.InteropServices.SafeArrayRankMismatchException"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C6F940C-3CFE-11D2-9EE7-00C04F797396}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\sapi.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}]

@="System.Security.Cryptography.RSAOAEPKeyExchangeDeformatter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}\InprocServer32]

"Class"="System.Security.Cryptography.RSAOAEPKeyExchangeDeformatter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}\InprocServer32\1.0.5000.0]

"Class"="System.Security.Cryptography.RSAOAEPKeyExchangeDeformatter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}\ProgId]

@="System.Security.Cryptography.RSAOAEPKeyExchangeDeformatter"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DD441AD-526D-4A77-9F1B-9841ED802FB0}]

@="SAXAttributes"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DD441AD-526D-4A77-9F1B-9841ED802FB0}\ProgID]

@="Msxml2.SAXAttributes"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4DD441AD-526D-4A77-9F1B-9841ED802FB0}\VersionIndependentProgID]

@="Msxml2.SAXAttributes"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F878398-E58A-11D3-BEE9-00C04FA0D6BA}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

@="Safe For Scripting"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F878398-E58A-11D3-BEE9-00C04FA0D6BA}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

@="Safe For Initialization"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52656BD4-ED0A-11D2-B7F4-00C04F72DAF0}]

@="WksABImport Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52656BD4-ED0A-11D2-B7F4-00C04F72DAF0}\InprocServer32]

@="C:\\Program Files\\Microsoft Works\\WKSABIMP.DLL"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52656BD4-ED0A-11D2-B7F4-00C04F72DAF0}\ProgID]

@="Wksabimp.WksABImport.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52656BD4-ED0A-11D2-B7F4-00C04F72DAF0}\VersionIndependentProgID]

@="Wksabimp.WksABImport"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53BCE0BA-C112-11D2-BA1A-00C04F72DABA}]

@="Wks5WizPageSample Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53BCE0BA-C112-11D2-BA1A-00C04F72DABA}\ProgID]

@="Sample.Wks5WizPageSample.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53BCE0BA-C112-11D2-BA1A-00C04F72DABA}\VersionIndependentProgID]

@="Sample.Wks5WizPageSample"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5440837F-4BFF-4AE5-A1B1-7722ECC6332A}\InprocServer32]

@="C:\\WINDOWS\\system32\\msaatext.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5440837F-4BFF-4AE5-A1B1-7722ECC6332A}\ProgID]

@="MSAAText.AccStore.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5440837F-4BFF-4AE5-A1B1-7722ECC6332A}\VersionIndependentProgID]

@="MSAAText.AccStore"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}]

@="System.Security.AllowPartiallyTrustedCallersAttribute"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}\InprocServer32]

"Class"="System.Security.AllowPartiallyTrustedCallersAttribute"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}\InprocServer32\1.0.5000.0]

"Class"="System.Security.AllowPartiallyTrustedCallersAttribute"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}\ProgId]

@="System.Security.AllowPartiallyTrustedCallersAttribute"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58ECEE30-E715-11CF-B0E3-00AA003F000F}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\System\\msadc\\msadce.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59DC47A8-116C-11D3-9D8E-00C04F72D980}]

@="Classe composant modèle de réglage BDA (sous-flux de diffusion)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5A7B63E0-F9BC-11D2-BBE5-00C04F86AE3B}]

@="À propos du composant logiciel enfichable de Internet Explorer"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B18AB61-091D-11D1-97DF-00C04FB9618A}]

@="Microsoft DTC Transaction Manager"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5cb66670-d3d4-11cf-acab-00a024a55aef}]

@="Composant Contexte de transaction étendu COM+"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5cb66670-d3d4-11cf-acab-00a024a55aef}\ProgID]

@="TxCTx.TransactionContextEx"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5cb66670-d3d4-11cf-acab-00a024a55aef}\VersionIndependentProgID]

@="TxCTx.TransactionContextEx"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D6179C8-17EC-11D1-9AA9-00C04FD8FE93}]

@="Composant logiciel enfichable Microsoft MMC Utilisateurs et groupes locaux"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D6179D2-17EC-11D1-9AA9-00C04FD8FE93}]

@="À propos du fournisseur du Composant logiciel enfichable Microsoft MMC Utilisateurs et groupes locaux"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D9DD151-65F4-11CE-900D-00AA00445589}]

@="Microsoft DTC Transaction Manager Proxy (private, internal)"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5DF2DE42-DC7A-5A02-BE2E-E47138107925}]

@="Composant logiciel enfichable Microsoft MMC Utilisateurs et groupes locaux"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5EA6F67B-7713-45F3-B535-0E03DD637345}]

@="SAFRemoteDesktopServerHost Class"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5EA6F67B-7713-45F3-B535-0E03DD637345}\ProgID]

@="RDSHost.SAFRemoteDesktopServerHost.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5EA6F67B-7713-45F3-B535-0E03DD637345}\VersionIndependentProgID]

@="RDSHost.SAFRemoteDesktopServerHost"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F889CE8-3B09-4CFF-B70A-83730CC00627}\InprocServer32]

@="C:\\WINDOWS\\system32\\safrcdlg.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F889CE8-3B09-4CFF-B70A-83730CC00627}\ProgID]

@="SAFRCFileDlg.FileOpen.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F889CE8-3B09-4CFF-B70A-83730CC00627}\VersionIndependentProgID]

@="SAFRCFileDlg.FileOpen"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FB7EF7D-DFF4-468a-B6B7-2FCBD188F994}\InprocServer32]

@="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Speech\\SAPI.DLL"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FB7EF7D-DFF4-468a-B6B7-2FCBD188F994}\ProgID]

@="SAPI.SpMemoryStream.1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FB7EF7D-DFF4-468a-B6B7-2FCBD188F994}\VersionIndependentProgID]

@="SAPI.SpMemoryStream"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6089A37E-EB8A-482D-BD6F-F9F46904D16D}\InprocServer32]

@="C:\\WINDOWS\\system32\\msaatext.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{622D47B6-CEEC-4DE1-8056-B6D16F29BC97}]

@="Microsoft WBEM Rpc Message Sender"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6572EE16-5FE5-4331-BB6D-76A49C56E423}\InprocServer32]

@="C:\\WINDOWS\\system32\\msaatext.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}]

@="System.FlagsAttribute"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}\InprocServer32]

"Class"="System.FlagsAttribute"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}\InprocServer32\1.0.5000.0]

"Class"="System.FlagsAttribute"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}\ProgId]

@="System.FlagsAttribute"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67331D85-BE17-42f6-8D3F-47B8E8B26637}]

@="Objet d'automatisation OOBE de l'Assistant Migration"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673DFE75-9F93-304F-ABA8-D2A86BA87D7C}]

@="System.Security.Cryptography.DSACryptoServiceProvider"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673DFE75-9F93-304F-ABA8-D2A86BA87D7C}\InprocServer32]

"Class"="System.Security.Cryptography.DSACryptoServiceProvider"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes&

Lien vers le commentaire
Partager sur d’autres sites

"Silent Runners.vbs", revision 43, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by "{++}"

 

 

Startup items buried in registry:

---------------------------------

 

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}

"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

"WOOKIT" = "C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=" [empty string]

"MessengerPlus3" = ""C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart" ["Patchou"]

"msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]

 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}

"LaunchApp" = "Alaunch" ["Acer Inc."]

"NVMixerTray" = ""C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"" ["NVIDIA Corporation"]

"eRecoveryService" = "C:\Program Files\Acer\eRecovery\Monitor.exe" ["acer Inc."]

"ntiMUI" = "C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [null data]

"(Default)" = (empty string)

"RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]

"IMJPMIG8.1" = ""C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" [MS]

"MSPY2002" = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC" [null data]

"PHIME2002ASync" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" [MS]

"PHIME2002A" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName" [MS]

"AspireService" = "C:\Program Files\Acer\Acer eMode Management\AspireService.exe" ["Acer Inc."]

"MediaSync" = "C:\Program Files\Acer\Acer eConsole\MediaSync.exe" ["Acer Inc."]

"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" ["Sun Microsystems, Inc."]

"WOOWATCH" = "C:\PROGRA~1\Wanadoo\Watch.exe" ["France Télécom R&D"]

"WOOTASKBARICON" = "C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe" ["France Télécom R&D"]

"avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]

"LVCOMSX" = "C:\WINDOWS\system32\LVCOMSX.EXE" ["Logitech Inc."]

"MessengerPlus3" = ""C:\Program Files\MessengerPlus! 3\MsgPlus.exe"" ["Patchou"]

"EPSON Stylus DX3800 Series" = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"" ["SEIKO EPSON CORPORATION"]

"TkBellExe" = ""C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]

"Zone Labs Client" = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" ["Zone Labs, LLC"]

"lbecovx" = "c:\windows\system32\lbecovx.exe lbecovx" [null data]

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]

{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)

-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = "SSVHelper Class" [from CLSID]

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]

{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}\(Default) = "EpsonToolBandKicker Class" [from CLSID]

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll" ["SEIKO EPSON CORPORATION"]

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"

-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"

-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

"{FEB7DAE0-E111-11D0-BFD7-444553540000}" = "ICEOWS"

-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"]

"{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"

-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]

"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]

"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]

"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"

-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]

"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"

-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]

 

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\

INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

 

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

ICEOWS\(Default) = "{FEB7DAE0-E111-11D0-BFD7-444553540000}"

-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"]

 

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

ICEOWS\(Default) = "{FEB7DAE0-E111-11D0-BFD7-444553540000}"

-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"]

 

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

 

 

Active Desktop and Wallpaper:

-----------------------------

 

Active Desktop is disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

 

HKCU\Control Panel\Desktop\

"Wallpaper" = "C:\Documents and Settings\Nat & Sab\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

 

 

Startup items in "Nat & Sab" & "All Users" startup folders:

-----------------------------------------------------------

 

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage

"Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]

"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]

 

 

Enabled Scheduled Tasks:

------------------------

 

"XoftSpy" -> launches: "C:\Program Files\XoftSpy\XoftSpy.exe -t" [file not found]

 

 

Winsock2 Service Provider DLLs:

-------------------------------

 

Namespace Service Providers

 

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

 

Transport Service Providers

 

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

 

 

Toolbars, Explorer Bars, Extensions:

------------------------------------

 

Toolbars

 

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\

"{EE5D279F-081B-4404-994D-C6B60AAEBA6D}" = "EPSON Web-To-Page" [from CLSID]

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll" ["SEIKO EPSON CORPORATION"]

 

HKLM\Software\Microsoft\Internet Explorer\Toolbar\

"{EE5D279F-081B-4404-994D-C6B60AAEBA6D}" = "EPSON Web-To-Page" [from CLSID]

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll" ["SEIKO EPSON CORPORATION"]

 

Extensions (Tools menu items, main toolbar menu buttons)

 

HKCU\Software\Microsoft\Internet Explorer\Extensions\

{1462651F-F4BA-4C76-A001-C4284D0FE16E}\

"ButtonText" = "Wanadoo"

"Exec" = "http://www.wanadoo.fr" [file not found]

 

HKLM\Software\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\

"MenuText" = "Console Java (Sun)"

"CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"

-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."]

 

{FB5F1910-F110-11D2-BB9E-00C04F795683}\

"ButtonText" = "Messager Wanadoo"

"MenuText" = "Messager Wanadoo"

"Exec" = "C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe" [file not found]

 

 

Miscellaneous IE Hijack Points

------------------------------

 

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

 

Added lines (compared with English-language version):

[strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/"

 

Missing lines (compared with English-language version):

[strings]: 1 line

 

HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\

"{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = "Search Class" [from CLSID]

-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\SEARCH~1.DLL" [empty string]

 

 

Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------

 

Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]

avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]

avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]

avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]

avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]

France Telecom Routing Table Service, FTRTSVC, "C:\WINDOWS\System32\FTRTSVC.exe" ["France Telecom"]

TrueVector Internet Monitor, vsmon, "C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service" ["Zone Labs, LLC"]

Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]

 

 

Print Monitors:

---------------

 

HKLM\System\CurrentControlSet\Control\Print\Monitors\

EPSON Stylus DX3800 Series 2KMonitor5E\Driver = "E_FLMACE.DLL" ["SEIKO EPSON CORPORATION"]

Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]

 

 

----------

+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

launch it from a command prompt or a shortcut with the -all parameter.

+ To search all directories of local fixed drives for DESKTOP.INI

DLL launch points and all Registry CLSIDs for dormant Explorer Bars,

use the -supp parameter or answer "No" at the first message box.

---------- (total run time: 18 seconds, including 6 seconds for message boxes)

 

 

silent runners fonctionne bien mais pour SA il est tellement long que ca ne marche pas meme en voulant le couper en plusieurs parties

au faite merci pour ton aide :P

Lien vers le commentaire
Partager sur d’autres sites

de rien :P

 

J'aimerai que tu fasses deux choses:

 

1)-Chercher ce fichier :(en gras)

 

c:\windows\system32\lbecovx.exe

 

Ce fichier étant peut être caché, fais ceci pour tout afficher=>

 

Démarrer, Poste de travail ou autre dossier, Menu Outils, Option des dossiers, onglet Affichage :

Activer la case : Afficher les fichiers et dossiers cachés

Désactiver la case : Masquer les extensions des fichiers dont le type est connu

Désactiver la case : Masquer les fichiers protégés du système d'exploitation

Puis Appliquer

 

-Puis tu vas soumettre ce fichier à un scan en ligne(c'est rapide!)=>

 

1- Jotti: http://virusscan.jotti.org/de/

2- http://www.virustotal.com/flash/index_en.html

communiquer les 2 rapports.

 

2)-On va créer un fichier reg pour te débarrasser de la clé découverte par Spybot:

 

Créé un fichier Bloc Notes avec le texte qui se trouve dans l'espace "code" ci-dessous (copie/colle, sans le mot "Code"=>Attention pas de ligne vierge avant REGEDIT4 ) :

 

REGEDIT4

[-HKEY_USERS\S-1-5-21-2011925375-3653460283-2877552486-1006\Software\LanConfig]

 

-Enregistrer ce fichier dans : Bureau

-Nom du fichier : remove.reg

-Type : tous les fichiers

-cliquer sur Enregistrer

-quitter le Bloc Notes

 

-Redémarre en mode sans échec.

 

-Clique sur le fichier remove.reg pour qu'il s'exécute.Un message te demandera la fusion,accepte.Elimine le fichier reg.

 

-Redémarre en mode normal, et refais un scan avec Spybot pour voir si il détecte toujours cette daube!

 

Pour finir on fera un scan evec Ewido :P

Modifié par charles ingals
Lien vers le commentaire
Partager sur d’autres sites

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

 Partager

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...