Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)

re

pour zone alarme c'est normal la societe c'est check point qui regroupe plusieurs autres E Trust Ez Antivirus ,zone labs etc

à+

mais je pense pas que faire virer nod et za pour installer panda soit tres sympa au niveau commercial un peu agressif comme decision

ex je te colle un faux positif pour te prouver que je suis le seul à eradiquer et pousse toi de la que je mis mette

surtout que le pare feux n'a pas un rapport direct avec l'infection

voila mon impression

à+

Modifié par pitcat

Posté(e)

Bonjour tout le monde !

 

Et c'est là que j'ai trouvé deux clefs de registre bizarre, j'ai décidé de les supprimer : une clef s'appelle mailskinner et l'autre ncxbeib. J'ai supprimer à l'aide de Regcleaner la seule clef "mailskinner" et la deuxième a été automatiquement enlevé avec.

 

Merci cubitus pour le conseil on va faire une recherche dessus alors !

 

Mais avant j'attend le rapport sur mslagent et navmpc

 

A plus !

Posté(e)

Re

 

Je poste pour Pioukaya

 

Bonjour à tous!

Régis,voici les rapports que tu m'as demandés:

REGEDIT4

 

; Registry Search 2.0 by Bobbi Flekman © 2005

; Version: 2.0.0.1

 

; Results at 13/04/2006 14:23:37 for strings:

; 'mslagent'

; 'navmpc'

; Strings excluded from search:

; (None)

; Search in:

; Registry Keys Registry Values Registry Data

; HKEY_LOCAL_MACHINE HKEY_USERS

 

 

; End Of The Log...

 

Logfile of HijackThis v1.99.1

Scan saved at 14:26:12, on 13/04/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\ewido anti-malware\ewidoctrl.exe

C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wdfmgr.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RunDll32.exe

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\a-squared\a2guard.exe

C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\Trend Micro\Internet Security\tmproxy.exe

C:\Program Files\Trend Micro\Internet Security\PccPfw.exe

C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe

C:\Program Files\Trend Micro\Internet Security\PCClient.EXE

C:\Program Files\Trend Micro\Internet Security\PCCGUIDE.EXE

C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\HJT\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cegetel.net/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cegetel.net/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.cegetel.net/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"

O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"

O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Desktop\V5.1\moffice.exe

O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Labtec\Desktop\V5.1\kbdap32a.exe

O4 - HKLM\..\Run: [WinPatrol] d:\winpatrol.exe

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"

O4 - HKCU\..\Run: [a-squared Antispam Guard] C:\PROGRAM FILES\A-SQUARED ANTI-SPAM\A2AntiSpamGUARD.exe

O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1127582898512

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{B26C4E16-1C2E-491A-926C-E3664210738B}: NameServer = 217.19.192.132 217.19.192.131

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe

O23 - Service: Trend Micro Personal Firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\PccPfw.exe

O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe

O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\tmproxy.exe

 

 

Incident Statut Analyse

 

Adware:adware/navipromo No Désinfecté Registre Windows

Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\Cathy\Cookies\cathy@weborama[1].txt

Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\Virginie\Cookies\virginie@xiti[1].txt

Que penses-tu de regcleaner? Cubi semble avoir régler son problème...

A+++

 

A plus !

Posté(e) (modifié)

Re

 

Bon vu les rapports et ce que nous a indiqué cubitus on va continuer ainsi

 

- double clique sur RegSearch.exe

- copie colle l'entrée en rouge dans la ligne de la zone de recherche:

 

mailskinner

ncxbeib

 

- rien dans la ligne "Enter string to exclude from results"

- clique sur OK

- après recherche, le bloc-notes ouvre une fenêtre "RegSearch.txt" avec toutes les instances trouvées

- le fichier est en outre sauvegardé dans le même répertoire que celui de RegSearch

- copie-colle le contenu de la fenêtre dans un post, ici

- ferme le bloc-notes

- ferme RegSearch par Cancel.

 

A plus !

Modifié par regis56
Posté(e)

Alors je voulais préciser le deuxième fichier c'est "ncxbeib" ou "ncxdeib"

 

J'ai un doute là.

 

Par contre le fait de supprimer l'entrée "mailskinner" m'a automatiquement enlevé le deuxième "ncxdeib"

 

Je teste depuis 17 h 00 et toujours pas de soucis.

 

 

Cubi

Posté(e)

Très-très intéressant Cubitus !! :P

 

Si on peut trouver cette clé de MailSkinner, ben on pourra l'ajouter au script de Metallica et plus de soucis !

 

L'autre est aléatoire par contre, et dans notre cas c'était nplxmiea notre fameux processus caché.

 

Voyons voir pour MailSkinner...

Posté(e)

Très-très intéressant Cubitus !! :P

 

Si on peut trouver cette clé de MailSkinner, ben on pourra l'ajouter au script de Metallica et plus de soucis !

 

L'autre est aléatoire par contre, et dans notre cas c'était nplxmiea notre fameux processus caché.

 

Voyons voir pour MailSkinner...

 

Bonjour à tous!

REGEDIT4

 

; Registry Search 2.0 by Bobbi Flekman © 2005

; Version: 2.0.0.1

 

; Results at 14/04/2006 12:11:46 for strings:

; 'mailskinner'

; 'ncxbeib'

; 'ncxdeib'

; Strings excluded from search:

; (None)

; Search in:

; Registry Keys Registry Values Registry Data

; HKEY_LOCAL_MACHINE HKEY_USERS

 

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{180B4EE9-1795-4429-9651-F17A6515726D}\InprocServer32]

@="C:\\Program Files\\MailSkinner\\OLSkinner.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0A089E22-5736-4092-B3F8-3F0D5F345482}]

@="IEGEmailSkinnerAddin"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5BAD7FAE-81F0-4439-8C1A-3E8907998047}\1.0\0\win32]

@="C:\\Program Files\\MailSkinner\\OLSkinner.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5BAD7FAE-81F0-4439-8C1A-3E8907998047}\1.0\HELPDIR]

@="C:\\Program Files\\MailSkinner\\"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]

"C:\\Program Files\\MailSkinner\\"="1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\0EE7C7FA5DD015874E6A0148620078DF]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\OLSkinner.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\2209460BBD44E161AEE9F6D7E842A099]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\emo.bmp"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\5C11A4CE946BF72D1CCAB19755A044F8]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\MailSkinner.exe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\69FAC78908145BC59233C718E2E36D2B]

"96FF640DA68D6C24EAF73B276C0844D6"="01:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\MailSkinner"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\9595E8AD562999D604AC8F36057234F6]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\95D365E637BDA42123E749A8DE273DB8]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\SOFTWARE LICENSE.rtf"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\A357C5B45C3210974019540F8C5F9D69]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\banner.jpg"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\A36D4CBB3C1BEA8BD51491C18B0EBF2A]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\anim_0.gif"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\CE167B94B4F39F146CEEF1045E0631E2]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\OESkinner.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\E7218F21850F091BA39DC85BECE2E36D]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\icon1.ico"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\FA93D872BF86A2B8DF7B3EA90F7E3F26]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\anim_help.gif"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Products\96FF640DA68D6C24EAF73B276C0844D6\InstallProperties]

"DisplayName"="MailSkinner"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D046FF69-D86A-42C6-AE7F-B372C680446D}]

"DisplayName"="MailSkinner"

 

[HKEY_USERS\S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\Installer\Products\96FF640DA68D6C24EAF73B276C0844D6]

"ProductName"="MailSkinner"

 

; End Of The Log...

 

Merci et à +

Posté(e) (modifié)

Bonjour pioukaya !

 

Ha c'est très interressant ca !!

 

Peut tu faire ceci

 

Faire démarrer/panneau de configuration/ajout-supression de programmes

Regarder dans la liste si présent

MailSkinner (désinstaller)

 

Si tu ne trouve pas mailskinner dans la liste fais ceci

Démarrer /tous mes programmes / mailskinner /désinstaller

 

Sinon fais ceci

C:\Program Files\MailSkinner\<= supprime le dossier !

 

puis passe un coup de easycleaner registre seulement

 

Et refais un regsearch avec MailSkinner et nplxmiea

 

 

A plus !

Modifié par regis56
Posté(e)

Bonjour pioukaya !

 

Ha c'est très interressant ca !!

 

Peut tu faire ceci

 

Faire démarrer/panneau de configuration/ajout-supression de programmes

Regarder dans la liste si présent

MailSkinner (désinstaller)

 

Si tu ne trouve pas mailskinner dans la liste fais ceci

Démarrer /tous mes programmes / mailskinner /désinstaller

 

Sinon fais ceci

C:\Program Files\MailSkinner\<= supprime le dossier !

 

puis passe un coup de easycleaner registre seulement

 

Et refais un regsearch avec MailSkinner et nplxmiea

A plus !

 

Bonjour Régis

Root Registry key Modified String value File/path reference

HKEY_CURRENT_USER Software\BillP Studios\WinPatrol\Run 09/04/2006 11:10:10 d:\winpatrol.exe 1

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\BillP Studios\WinPatrol\Run 09/04/2006 11:10:10 d:\winpatrol.exe 1

HKEY_LOCAL_MACHINE Software\Samsung\Samsung PC Studio\ImageEditor 29/11/2005 18:23:48 AppPathName C:\bureau\\ImageEditor.exe

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{F5346614-B7C4-4E94-826A-E2363155233D} 15/04/2006 06:30:06 InstallSource C:\DOCUME~1\Cathy\LOCALS~1\Temp\bye33C.tmp\Disk1\

HKEY_CURRENT_USER Software\Microsoft\Installer\Products\96FF640DA68D6C24EAF73B276C0844D6\SourceList\Net 15/04/2006 06:40:49 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\Installer\Products\96FF640DA68D6C24EAF73B276C0844D6\SourceList\Net 15/04/2006 06:40:49 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Classes\Installer\Patches\4E443A98B45AE5C479DB40B0B4033011\SourceList\Net 26/10/2005 18:33:31 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Classes\Installer\Patches\4E443A98B45AE5C479DB40B0B4033042\SourceList\Net 10/02/2006 09:00:41 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\9EC9653600AFC964FAC55E4D9DA3FC19\SourceList\Net 24/09/2005 17:46:34 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Classes\Installer\Products\E1C3DFABCE30AD11FBDB0060B5DB0C5B\SourceList\Net 25/09/2005 10:57:07 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EC9653600AFC964FAC55E4D9DA3FC19\InstallProperties 24/09/2005 17:46:34 InstallSource C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E1C3DFABCE30AD11FBDB0060B5DB0C5B\InstallProperties 10/02/2006 09:00:41 InstallSource C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Products\96FF640DA68D6C24EAF73B276C0844D6\InstallProperties 15/04/2006 06:40:49 InstallSource C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{63569CE9-FA00-469C-AF5C-E5D4D93ACF91} 24/09/2005 17:46:34 InstallSource C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{BAFD3C1E-03EC-11DA-BFBD-00065BBDC0B5} 10/02/2006 09:00:41 InstallSource C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\{D046FF69-D86A-42C6-AE7F-B372C680446D} 15/04/2006 06:40:49 InstallSource C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\

HKEY_LOCAL_MACHINE Software\Microsoft\Advanced INF Setup\IE5SETUP 16/10/2005 15:24:23 InstallINFFile C:\DOCUME~1\Cathy\LOCALS~1\Temp\IXP000.TMP\IESetup.inf

HKEY_LOCAL_MACHINE Software\Classes\Installer\Patches\8E768F6B290FE5C4D727CA0775BDFE54\SourceList\Net 19/10/2005 14:16:09 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\pft22.tmp\

HKEY_LOCAL_MACHINE Software\Classes\Installer\Patches\821752B295B088A4FAFDEB215E5F9B0A\SourceList\Net 18/02/2006 17:18:57 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\pft5.tmp\

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{D645B4A2-2BAA-4C2B-AD5E-D6AB75A2D673}\1.0\HELPDIR 23/12/2005 18:04:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\PPT8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{D645B4A2-2BAA-4C2B-AD5E-D6AB75A2D673}\1.0\0\win32 23/12/2005 18:04:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\PPT8.0\ShockwaveFlashObjects.exd

HKEY_CURRENT_USER Software\KillBox 04/04/2006 07:00:07 LastPath C:\DOCUME~1\Cathy\LOCALS~1\Temp\QZTEMP

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\KillBox 04/04/2006 07:00:07 LastPath C:\DOCUME~1\Cathy\LOCALS~1\Temp\QZTEMP

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis 31/03/2006 10:06:40 DisplayIcon C:\DOCUME~1\Cathy\LOCALS~1\Temp\QZTEMP\HijackThis.exe

HKEY_CURRENT_USER Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 0 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb0.tmp

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 0 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb0.tmp

HKEY_CURRENT_USER Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb1.tmp

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 1 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb1.tmp

HKEY_CURRENT_USER Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 2 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb2.tmp

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 2 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb2.tmp

HKEY_CURRENT_USER Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 3 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb3.tmp

HKEY_CURRENT_USER Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 4 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb3.tmp

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 3 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb3.tmp

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 4 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb3.tmp

HKEY_CURRENT_USER Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 5 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb4.tmp

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 5 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb4.tmp

HKEY_CURRENT_USER Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 6 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb5.tmp

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 6 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb5.tmp

HKEY_CURRENT_USER Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 7 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb6.tmp

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source 28/12/2005 12:50:26 7 C:\DOCUME~1\Cathy\LOCALS~1\Temp\setb6.tmp

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{1C8FBDD8-F97C-460E-B993-35D55C452482}\2.0\HELPDIR 25/03/2006 14:33:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{3EE0CE84-3E20-491A-A89A-D2965A83EBB9}\1.0\HELPDIR 25/03/2006 14:33:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{48A8E6BD-5985-4EEA-A684-AB8747320775}\1.0\HELPDIR 23/03/2006 09:44:53 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{750778F1-6F35-4EA3-A36C-EB9383DC49A9}\2.0\HELPDIR 19/02/2006 11:01:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{7AF0F2F3-2C2B-40EB-BA8E-880679A88853}\2.0\HELPDIR 19/02/2006 18:28:32 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{7D2F621F-097E-48EF-94EB-3860C118817A}\1.0\HELPDIR 19/02/2006 11:01:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{7F3C641C-7F7D-40C2-BC94-1304214F8CE4}\1.0\HELPDIR 20/03/2006 15:42:21 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{829D3D86-E7CA-43D3-9A3B-026B2B88F593}\1.0\HELPDIR 23/03/2006 08:35:10 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{8D6049ED-E13A-4D7A-AD7D-C6D978EC9C15}\2.0\HELPDIR 19/02/2006 14:14:33 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{97919616-B2AD-4096-9EE2-FC79B82AADDC}\2.0\HELPDIR 23/03/2006 08:35:10 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{9BA23A1C-4B81-4850-BEAC-DD119E5ACDF3}\2.0\HELPDIR 20/03/2006 15:42:21 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{B3539B99-FE65-49CD-8660-1B04A34B88C3}\1.0\HELPDIR 19/02/2006 18:28:32 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{C53F85E6-0512-44EF-B33E-91BF2D97A6C8}\1.0\HELPDIR 19/02/2006 14:14:33 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{C79829AB-7630-413D-83D1-80DD1604D6D6}\2.0\HELPDIR 13/10/2005 11:11:32 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{CF5A16E9-4420-4722-8812-2FEA61BA66B6}\2.0\HELPDIR 23/03/2006 09:44:53 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{E6C7F501-E0AA-4A0F-9A89-FDF955397F77}\2.0\HELPDIR 28/03/2006 15:21:55 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{EDB08B35-189A-4ED0-BFA2-745432E62B53}\1.0\HELPDIR 13/10/2005 11:11:32 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{FBF35D0D-89E2-4660-8D52-8D9A18068970}\2.0\HELPDIR 26/03/2006 07:39:45 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{FCCE7C36-9783-4508-B574-CCA45630A3CD}\1.0\HELPDIR 26/03/2006 07:39:46 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{FE5E018A-7730-4630-AA7F-6B69F77EEFC3}\1.0\HELPDIR 28/03/2006 15:21:56 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{1C8FBDD8-F97C-460E-B993-35D55C452482}\2.0\0\win32 25/03/2006 14:33:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{750778F1-6F35-4EA3-A36C-EB9383DC49A9}\2.0\0\win32 19/02/2006 11:01:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{7AF0F2F3-2C2B-40EB-BA8E-880679A88853}\2.0\0\win32 19/02/2006 18:28:32 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{8D6049ED-E13A-4D7A-AD7D-C6D978EC9C15}\2.0\0\win32 19/02/2006 14:14:33 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{97919616-B2AD-4096-9EE2-FC79B82AADDC}\2.0\0\win32 23/03/2006 08:35:10 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{9BA23A1C-4B81-4850-BEAC-DD119E5ACDF3}\2.0\0\win32 20/03/2006 15:42:21 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{C79829AB-7630-413D-83D1-80DD1604D6D6}\2.0\0\win32 13/10/2005 11:11:32 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{CF5A16E9-4420-4722-8812-2FEA61BA66B6}\2.0\0\win32 23/03/2006 09:44:53 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{E6C7F501-E0AA-4A0F-9A89-FDF955397F77}\2.0\0\win32 28/03/2006 15:21:55 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{FBF35D0D-89E2-4660-8D52-8D9A18068970}\2.0\0\win32 26/03/2006 07:39:45 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{3EE0CE84-3E20-491A-A89A-D2965A83EBB9}\1.0\0\win32 25/03/2006 14:33:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{48A8E6BD-5985-4EEA-A684-AB8747320775}\1.0\0\win32 23/03/2006 09:44:53 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{7D2F621F-097E-48EF-94EB-3860C118817A}\1.0\0\win32 19/02/2006 11:01:34 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{7F3C641C-7F7D-40C2-BC94-1304214F8CE4}\1.0\0\win32 20/03/2006 15:42:21 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{829D3D86-E7CA-43D3-9A3B-026B2B88F593}\1.0\0\win32 23/03/2006 08:35:10 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{B3539B99-FE65-49CD-8660-1B04A34B88C3}\1.0\0\win32 19/02/2006 18:28:32 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{C53F85E6-0512-44EF-B33E-91BF2D97A6C8}\1.0\0\win32 19/02/2006 14:14:33 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{EDB08B35-189A-4ED0-BFA2-745432E62B53}\1.0\0\win32 13/10/2005 11:11:32 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{FCCE7C36-9783-4508-B574-CCA45630A3CD}\1.0\0\win32 26/03/2006 07:39:46 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{FE5E018A-7730-4630-AA7F-6B69F77EEFC3}\1.0\0\win32 28/03/2006 15:21:56 C:\DOCUME~1\Cathy\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{0F5104E4-9E2F-47AB-977B-7ACECA4BD51F}\2.0\HELPDIR 11/04/2006 16:49:26 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{1EABC331-CB7E-45C7-861A-28CFDAB5213C}\2.0\HELPDIR 28/03/2006 18:07:36 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{4B9A11B1-4539-42D4-B057-A4333853ECC5}\1.0\HELPDIR 05/11/2005 06:42:44 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{621222B7-3BDD-42E2-95B9-B664C5AB61ED}\1.0\HELPDIR 11/12/2005 11:20:40 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{6CBF78F1-D56C-41A0-8A88-28B08B4B08C8}\2.0\HELPDIR 18/02/2006 12:01:31 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{89C17A00-6E5B-49DF-A23E-7CB70494E6C2}\2.0\HELPDIR 08/02/2006 14:43:13 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{8CF96D82-C3A5-4D12-BA8C-E318785DC740}\2.0\HELPDIR 11/04/2006 07:58:07 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{8F9F6414-06B4-4E5F-AA1C-5E5B93E47E22}\2.0\HELPDIR 05/11/2005 06:42:46 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{BDB72507-41C2-49F9-BE09-01B678B8E77E}\2.0\HELPDIR 08/04/2006 19:41:56 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{D618E00E-C05D-46F7-9192-0BE9EBA84661}\2.0\HELPDIR 16/03/2006 10:04:48 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{F5FB0028-7D1E-4708-98BB-72EE5B0A2403}\2.0\HELPDIR 14/04/2006 19:52:48 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{FDB7A726-77C3-45DB-A1CF-E6831FF8DCCD}\1.0\HELPDIR 23/10/2005 17:04:08 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{621222B7-3BDD-42E2-95B9-B664C5AB61ED}\1.0\0\win32 11/12/2005 11:20:40 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\InlineMultimedia.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{FDB7A726-77C3-45DB-A1CF-E6831FF8DCCD}\1.0\0\win32 23/10/2005 17:04:08 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MARQUEELib.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{0F5104E4-9E2F-47AB-977B-7ACECA4BD51F}\2.0\0\win32 11/04/2006 16:49:26 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{1EABC331-CB7E-45C7-861A-28CFDAB5213C}\2.0\0\win32 28/03/2006 18:07:36 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{6CBF78F1-D56C-41A0-8A88-28B08B4B08C8}\2.0\0\win32 18/02/2006 12:01:31 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{89C17A00-6E5B-49DF-A23E-7CB70494E6C2}\2.0\0\win32 08/02/2006 14:43:13 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{8CF96D82-C3A5-4D12-BA8C-E318785DC740}\2.0\0\win32 11/04/2006 07:58:07 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{8F9F6414-06B4-4E5F-AA1C-5E5B93E47E22}\2.0\0\win32 05/11/2005 06:42:46 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{BDB72507-41C2-49F9-BE09-01B678B8E77E}\2.0\0\win32 08/04/2006 19:41:56 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{D618E00E-C05D-46F7-9192-0BE9EBA84661}\2.0\0\win32 16/03/2006 10:04:48 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{F5FB0028-7D1E-4708-98BB-72EE5B0A2403}\2.0\0\win32 14/04/2006 19:52:48 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{4B9A11B1-4539-42D4-B057-A4333853ECC5}\1.0\0\win32 05/11/2005 06:42:44 C:\DOCUME~1\Cathy\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd

HKEY_LOCAL_MACHINE Software\Microsoft\Advanced INF Setup\ZzZzZzZz 24/09/2005 20:50:33 InstallCabFile C:\DOCUME~1\Cathy\LOCALS~1\Temp\~dxmcab~\strmanim.cab

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{0654AF63-F841-48B1-A8AF-743054A25BD8}\2.0\HELPDIR 14/03/2006 21:10:14 C:\DOCUME~1\Virginie\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{632F4260-47C2-4A06-B42B-2403DFB32143}\2.0\HELPDIR 19/10/2005 18:37:32 C:\DOCUME~1\Virginie\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{9CA94441-D1D4-43BB-8AEC-3851F0E009E7}\1.0\HELPDIR 14/03/2006 21:10:14 C:\DOCUME~1\Virginie\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{AD9E6E44-E0D3-4736-AFE6-DC1A9E77BF49}\1.0\HELPDIR 19/10/2005 18:37:33 C:\DOCUME~1\Virginie\LOCALS~1\Temp\VBE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{0654AF63-F841-48B1-A8AF-743054A25BD8}\2.0\0\win32 14/03/2006 21:10:14 C:\DOCUME~1\Virginie\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{632F4260-47C2-4A06-B42B-2403DFB32143}\2.0\0\win32 19/10/2005 18:37:32 C:\DOCUME~1\Virginie\LOCALS~1\Temp\VBE\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{9CA94441-D1D4-43BB-8AEC-3851F0E009E7}\1.0\0\win32 14/03/2006 21:10:14 C:\DOCUME~1\Virginie\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{AD9E6E44-E0D3-4736-AFE6-DC1A9E77BF49}\1.0\0\win32 19/10/2005 18:37:33 C:\DOCUME~1\Virginie\LOCALS~1\Temp\VBE\RefEdit.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{1C412D0C-1ACD-4C25-9F1B-2F9CAC902430}\2.0\HELPDIR 20/10/2005 18:45:33 C:\DOCUME~1\Virginie\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{3C56EC27-F22A-410F-9B28-E6BA6486F5F3}\1.0\HELPDIR 20/10/2005 18:45:32 C:\DOCUME~1\Virginie\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{5CA29A4A-C47F-473F-9282-8DC8D9F37E60}\2.0\HELPDIR 02/04/2006 19:45:31 C:\DOCUME~1\Virginie\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{D75FDB5B-3798-4392-9B7B-03281060DEB4}\1.0\HELPDIR 02/04/2006 19:45:30 C:\DOCUME~1\Virginie\LOCALS~1\Temp\Word8.0

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{1C412D0C-1ACD-4C25-9F1B-2F9CAC902430}\2.0\0\win32 20/10/2005 18:45:33 C:\DOCUME~1\Virginie\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{5CA29A4A-C47F-473F-9282-8DC8D9F37E60}\2.0\0\win32 02/04/2006 19:45:31 C:\DOCUME~1\Virginie\LOCALS~1\Temp\Word8.0\MSForms.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{3C56EC27-F22A-410F-9B28-E6BA6486F5F3}\1.0\0\win32 20/10/2005 18:45:32 C:\DOCUME~1\Virginie\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{D75FDB5B-3798-4392-9B7B-03281060DEB4}\1.0\0\win32 02/04/2006 19:45:30 C:\DOCUME~1\Virginie\LOCALS~1\Temp\Word8.0\ShockwaveFlashObjects.exd

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}\InprocServer32 24/09/2005 18:07:49 C:\PROGRA~1\MESSEN~1\rtcimsp.dll

HKEY_LOCAL_MACHINE Software\Screensavers.com\Installer\Tokens 11/03/2006 20:00:37 COMET C:\PROGRA~1\SCREEN~1.COM

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{3E18E990-2533-11D4-8A2B-0090271D4F88}\3.0\0\win32 18/01/2006 20:08:17 C:\PROGRA~1\Yahoo!\Common\messmod.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}\InprocServer32 18/01/2006 20:08:17 C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}\LocalServer32 18/01/2006 20:07:42 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{E5D12C41-7B4F-11D3-B5C9-0050045C3C96}\1.0\0\win32 18/01/2006 20:07:40 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

HKEY_LOCAL_MACHINE Software\Microsoft\Java VM 24/09/2005 18:05:14 LibsDirectory C:\WINDOWS\java\lib

HKEY_LOCAL_MACHINE Software\Microsoft\Advanced INF Setup\IEEX 16/10/2005 15:24:20 InstallINFFile C:\WINDOWS\msdownld.tmp\ASCB9946.tmp\IEEX\ieexinst.inf

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Active Setup Temp Folders 30/09/2005 05:30:23 Folder C:\WINDOWS\msdownld.tmp|?:\msdownld.tmp

HKEY_LOCAL_MACHINE Software\Microsoft\Windows NT\CurrentVersion\SeCEdit 24/09/2005 19:16:51 TemplateUsed C:\WINDOWS\SEC10C2.tmp

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1643_x-ww_bf702e2b 24/09/2005 18:07:24 Codebase C:\WINDOWS\ServicePackFiles\i386/comctl.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1643_x-ww_bf702e2b\Codebases\U_KB893086 24/09/2005 18:07:24 URL C:\WINDOWS\ServicePackFiles\i386/comctl.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_eb84b25e 24/09/2005 19:12:47 Codebase C:\WINDOWS\ServicePackFiles\i386/comctl.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_eb84b25e\Codebases\U_Service Pack 2 24/09/2005 19:12:47 URL C:\WINDOWS\ServicePackFiles\i386/comctl.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1643_x-ww_7c3a9bc6 24/09/2005 18:07:24 Codebase C:\WINDOWS\ServicePackFiles\i386/controls.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1643_x-ww_7c3a9bc6\Codebases\U_KB893086 24/09/2005 18:07:24 URL C:\WINDOWS\ServicePackFiles\i386/controls.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9 24/09/2005 19:12:47 Codebase C:\WINDOWS\ServicePackFiles\i386/controls.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\Codebases\U_Service Pack 2 24/09/2005 19:12:47 URL C:\WINDOWS\ServicePackFiles\i386/controls.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281 24/09/2005 19:12:46 Codebase C:\WINDOWS\ServicePackFiles\i386/default.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281\Codebases\U_Service Pack 2 24/09/2005 19:12:46 URL C:\WINDOWS\ServicePackFiles\i386/default.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_0e037a8a 24/09/2005 19:12:46 Codebase C:\WINDOWS\ServicePackFiles\i386/default.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_0e037a8a\Codebases\U_Service Pack 2 24/09/2005 19:12:46 URL C:\WINDOWS\ServicePackFiles\i386/default.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7 24/09/2005 19:12:46 Codebase C:\WINDOWS\ServicePackFiles\i386/dxmrtp.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\Codebases\U_Service Pack 2 24/09/2005 19:12:46 URL C:\WINDOWS\ServicePackFiles\i386/dxmrtp.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_cf59288d 24/09/2005 19:12:47 Codebase C:\WINDOWS\ServicePackFiles\i386/dxmrtp.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_cf59288d\Codebases\U_Service Pack 2 24/09/2005 19:12:47 URL C:\WINDOWS\ServicePackFiles\i386/dxmrtp.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82 24/09/2005 19:12:45 Codebase C:\WINDOWS\ServicePackFiles\i386/gdiplus.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\Codebases\U_Service Pack 2 24/09/2005 19:12:45 URL C:\WINDOWS\ServicePackFiles\i386/gdiplus.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_5ff735e2 24/09/2005 19:12:45 Codebase C:\WINDOWS\ServicePackFiles\i386/gdiplus.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_5ff735e2\Codebases\U_Service Pack 2 24/09/2005 19:12:45 URL C:\WINDOWS\ServicePackFiles\i386/gdiplus.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9 24/09/2005 19:12:47 Codebase C:\WINDOWS\ServicePackFiles\i386/mswincrt.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\Codebases\U_Service Pack 2 24/09/2005 19:12:47 URL C:\WINDOWS\ServicePackFiles\i386/mswincrt.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_cf5111a1 24/09/2005 19:12:47 Codebase C:\WINDOWS\ServicePackFiles\i386/mswincrt.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_cf5111a1\Codebases\U_Service Pack 2 24/09/2005 19:12:47 URL C:\WINDOWS\ServicePackFiles\i386/mswincrt.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95 24/09/2005 19:12:46 Codebase C:\WINDOWS\ServicePackFiles\i386/rtcdll.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\Codebases\U_Service Pack 2 24/09/2005 19:12:46 URL C:\WINDOWS\ServicePackFiles\i386/rtcdll.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_5.2.2.3_x-ww_5f924d7b 24/09/2005 19:12:47 Codebase C:\WINDOWS\ServicePackFiles\i386/rtcdll.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_5.2.2.3_x-ww_5f924d7b\Codebases\U_Service Pack 2 24/09/2005 19:12:47 URL C:\WINDOWS\ServicePackFiles\i386/rtcdll.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_fr_457ebf3d 24/09/2005 19:12:47 Codebase C:\WINDOWS\ServicePackFiles\i386/rtcres.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\SideBySide\Installations\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_fr_457ebf3d\Codebases\U_Service Pack 2 24/09/2005 19:12:47 URL C:\WINDOWS\ServicePackFiles\i386/rtcres.man

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Setup 12/04/2006 11:54:38 ServicePackCachePath c:\windows\ServicePackFiles\ServicePackCache

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD42-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD43-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD44-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD45-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD46-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD47-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD48-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD49-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD4A-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD4B-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD4C-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD4D-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{DC47DD4E-E06B-44be-8BD4-B0C5F5892F72}\InprocServer32 22/01/2006 14:42:01 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{DC47DD40-E06B-44BE-8BD4-B0C5F5892F72}\1.0\0\win32 02/12/2005 19:07:07 C:\WINDOWS\system32\actskn45.ocx

HKEY_LOCAL_MACHINE Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllCreateIndirectData\{D0BA83B0-DB49-11D2-B886-00C04F866F52} 24/09/2005 16:57:44 Dll C:\WINDOWS\System32\asfsipc.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D0BA83B0-DB49-11D2-B886-00C04F866F52} 24/09/2005 16:57:44 Dll C:\WINDOWS\System32\asfsipc.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllIsMyFileType\{D0BA83B0-DB49-11D2-B886-00C04F866F52} 24/09/2005 16:57:44 Dll C:\WINDOWS\System32\asfsipc.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D0BA83B0-DB49-11D2-B886-00C04F866F52} 24/09/2005 16:57:44 Dll C:\WINDOWS\System32\asfsipc.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllRemoveSignedDataMsg\{D0BA83B0-DB49-11D2-B886-00C04F866F52} 24/09/2005 16:57:44 Dll C:\WINDOWS\System32\asfsipc.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D0BA83B0-DB49-11D2-B886-00C04F866F52} 24/09/2005 16:57:44 Dll C:\WINDOWS\System32\asfsipc.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe 24/09/2005 19:13:43 C:\WINDOWS\System32\cmmgr32.exe

HKEY_LOCAL_MACHINE Software\BillP Studios\WinPatrol\Sysfiles\HOSTS 09/04/2006 11:09:08 Location C:\WINDOWS\system32\drivers\etc\HOSTS

HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\MPlayer2\Groups\Video\DVR-MS 04/12/2005 12:17:07 RequiredFile C:\WINDOWS\system32\enable.dvd

HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\WMPlayer\Groups\Video\DVD 12/04/2006 11:55:48 RequiredFile C:\WINDOWS\system32\enable.dvd

HKEY_LOCAL_MACHINE Software\Microsoft\Multimedia\WMPlayer\Groups\Video\DVR-MS 12/04/2006 11:55:48 RequiredFile C:\WINDOWS\system32\enable.dvd

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\InprocServer32 24/09/2005 16:57:31 C:\WINDOWS\System32\plugin.ocx

HKEY_LOCAL_MACHINE Software\Classes\TypeLib\{06DD38D0-D187-11CF-A80D-00C04FD74AD8}\1.0\0\win32 24/09/2005 16:57:31 C:\WINDOWS\System32\plugin.ocx

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{CC2C83A6-9BE4-11D0-98E7-00C04FC2CAF5}\InprocServer32 24/09/2005 16:57:37 SystemDB C:\WINDOWS\System32\system.mdw

HKEY_LOCAL_MACHINE Software\Microsoft\Windows Media Device Manager 28/12/2005 12:49:44 Log.Filename C:\WINDOWS\system32\Wmdm.log

HKEY_LOCAL_MACHINE Software\Microsoft\IMAPI\StashInfo 24/09/2005 17:06:40 StashPath C:\WINDOWS\Temp\StashIMAPI.bin

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\App Paths\easyrencontre.exe 01/12/2005 11:57:58 D:\easyrencontre\easyrencontre.exe

HKEY_CURRENT_USER Software\NoAdware4 02/04/2006 06:26:03 path D:\NoAdware4

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\NoAdware4 02/04/2006 06:26:03 path D:\NoAdware4

HKEY_CURRENT_USER Software\NoAdware4 02/04/2006 06:26:03 lfp D:\NoAdware4\logs

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\NoAdware4 02/04/2006 06:26:03 lfp D:\NoAdware4\logs

HKEY_CURRENT_USER Software\NoAdware4 02/04/2006 06:26:03 rfp D:\NoAdware4\noadware4_033006.na

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\NoAdware4 02/04/2006 06:26:03 rfp D:\NoAdware4\noadware4_033006.na

HKEY_CURRENT_USER Software\NoAdware4 02/04/2006 06:26:03 xpath D:\NoAdware4\xblk.na

HKEY_USERS S-1-5-21-1220945662-602609370-839522115-1003\Software\NoAdware4 02/04/2006 06:26:03 xpath D:\NoAdware4\xblk.na

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{4956C5F5-D9A8-4CBB-8994-F53CF55CFDF5}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\ImageServices.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{5E6309F2-9971-4683-9445-F548E81BEC07}\InprocServer32 18/12/2005 18:44:20 D:\Shareaza\Plugins\ImageServices.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{D427C22F-23FB-4E51-A8B8-70F2036ED3BA}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\ImageServices.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{17BF74FD-69AF-4BD5-A982-EA6DE6F3449C}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\MediaPlayer.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{394011F0-6D5C-42a3-96C6-24B9AD6B010C}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\MediaPlayer.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{591A5CFF-3172-4020-A067-238542DDE9C2}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\MediaPlayer.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{9AA8DF47-B8FE-47da-AB1A-2DAA0DA0B646}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\MediaPlayer.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{BF00DBCC-90A2-4f46-8171-7D4F929D035F}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\MediaPlayer.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{C3B7B25C-6B8B-481A-BC48-59F9A6F7B69A}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\MediaPlayer.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{D07E630D-A850-4f11-AD29-3D3848B67EFE}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\MediaPlayer.dll

HKEY_LOCAL_MACHINE Software\Classes\CLSID\{A4F1E383-B493-4580-8DB6-5CC89CBAAC53}\InprocServer32 18/12/2005 18:44:21 D:\Shareaza\Plugins\SkinScanSKS.dll

HKEY_LOCAL_MACHINE Software\Microsoft\Windows\CurrentVersion\Run 13/04/2006 15:07:23 WinPatrol d:\winpatrol.exe

HKEY_USERS .DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache 22/01/2006 14:07:43 D:\LimeWire\LimeWire.exe LimeWire

HKEY_USERS S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache 22/01/2006 14:07:43 D:\LimeWire\LimeWire.exe LimeWire

 

Dois-je supprimer???

 

REGEDIT4

 

; Registry Search 2.0 by Bobbi Flekman © 2005

; Version: 2.0.0.1

 

; Results at 15/04/2006 08:49:39 for strings:

; 'mailskinner'

; 'nplxmiea'

; Strings excluded from search:

; (None)

; Search in:

; Registry Keys Registry Values Registry Data

; HKEY_LOCAL_MACHINE HKEY_USERS

 

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{180B4EE9-1795-4429-9651-F17A6515726D}\InprocServer32]

@="C:\\Program Files\\MailSkinner\\OLSkinner.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0A089E22-5736-4092-B3F8-3F0D5F345482}]

@="IEGEmailSkinnerAddin"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5BAD7FAE-81F0-4439-8C1A-3E8907998047}\1.0\0\win32]

@="C:\\Program Files\\MailSkinner\\OLSkinner.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5BAD7FAE-81F0-4439-8C1A-3E8907998047}\1.0\HELPDIR]

@="C:\\Program Files\\MailSkinner\\"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]

"C:\\Program Files\\MailSkinner\\"="1"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\0EE7C7FA5DD015874E6A0148620078DF]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\OLSkinner.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\2209460BBD44E161AEE9F6D7E842A099]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\emo.bmp"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\5C11A4CE946BF72D1CCAB19755A044F8]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\MailSkinner.exe"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\69FAC78908145BC59233C718E2E36D2B]

"96FF640DA68D6C24EAF73B276C0844D6"="01:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\MailSkinner"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\9595E8AD562999D604AC8F36057234F6]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\95D365E637BDA42123E749A8DE273DB8]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\SOFTWARE LICENSE.rtf"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\A357C5B45C3210974019540F8C5F9D69]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\banner.jpg"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\A36D4CBB3C1BEA8BD51491C18B0EBF2A]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\anim_0.gif"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\CE167B94B4F39F146CEEF1045E0631E2]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\OESkinner.dll"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\E7218F21850F091BA39DC85BECE2E36D]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\icon1.ico"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Components\FA93D872BF86A2B8DF7B3EA90F7E3F26]

"96FF640DA68D6C24EAF73B276C0844D6"="C:\\Program Files\\MailSkinner\\anim_help.gif"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1220945662-602609370-839522115-1003\Products\96FF640DA68D6C24EAF73B276C0844D6\InstallProperties]

"DisplayName"="MailSkinner"

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D046FF69-D86A-42C6-AE7F-B372C680446D}]

"DisplayName"="MailSkinner"

 

[HKEY_USERS\S-1-5-21-1220945662-602609370-839522115-1003\Software\Microsoft\Installer\Products\96FF640DA68D6C24EAF73B276C0844D6]

"ProductName"="MailSkinner"

 

; End Of The Log...

 

 

A+++

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...