Votre question

envahie par des fenêtres intempestives

Tags :
  • Fenêtre intempestive
  • Sécurité
Dernière réponse : dans Sécurité et virus
26 Février 2007 11:21:24

Bonjours, :hello: 
Je suis nouvelle et je n’y connais pas grand chose
En informatique.mais depuis quelque temps je reçois plein de publicité é « x » qui s’affiche sans raisons, cela m’embête car j’ai dés enfants, j’ai bien le blocage contrôle parentale mais c’est très embêtant ! Comment fait pour sans débarrasser ??Merci d’avance pour toute aide.
up

Autres pages sur : envahie fenetres intempestives

26 Février 2007 11:35:43

Bonjour,

Poste un rapport HijackThis

Télécharge le, puis met le dans un dossier dédié (exemple : ..\Bureau\Hijackthis\Hijackthis.exe ).

Renomme-le en Scanner.exe (clic droit sur le fichier HijackThis et choisis renommer).

Ensuite, lance le (double clic sur Scanner.exe ensuite tu l’exécutes) appuie sur Do a system scan a save a logfile, le bloc note va alors s’ouvrir, tu copies et tu colles le rapport ici dans ta prochaine réponse.

Aide : N'hésite pas à consulter l'aide HiJackThis
26 Février 2007 13:51:30

Voilà excuse moi j’ai mis beaucoup de temps à te répondre mais j’étais un peut beaucoup perdu. Je me suis déconnecter par erreur et j’ai eu beaucoup de mal à te retrouver pour t’envoyer le rapport le voici donc merci pour ton aide

Ps : il faut m’explique dans les moindres détails car je comprends vite, mais il faut m’expliquer longtemps

Logfile of HijackThis v1.99.1
Scan saved at 13:25:32, on 26/02/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\DriveCleaner Free\udcsdr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32prodsrvs.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\elodie\Mes documents\elodie.zitte\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?product=ssearch&src_id... (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Starware - {F7C7AA47-BCA6-451D-8DBC-C10A8F75C8C7} - C:\Program Files\Starware\bin\Starware.dll
O3 - Toolbar: Starware - {9839B3B7-3F99-4498-884D-6CFCCD251AB1} - C:\Program Files\Starware\bin\Starware.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SDR6V_Check] "C:\Program Files\Fichiers communs\DriveCleaner Free\udcsdr.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [CursorXP] C:\themeGold55\CursorXP\CursorXP.exe -s
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\System32\prodsrvs.exe /res
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?a44db9d7804f4ac0a2bbd744420aaa44
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?a44db9d7804f4ac0a2bbd744420aaa44
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr
O16 - DPF: Interface Chat Wanadoo - http://chat4.x-echo.com/version8/Applet/wchatsign.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.drivecleaner.com/installdrivecleanerstart_fr...
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab312...
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2508b8c209c524056218/netzip...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photos.orange.fr/al/presentation/pc/resources/ac...
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (HbtInstObj) - http://installs.hotbar.com/installs/hbtools/programs/hb...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {AA59202C-5E41-48FC-AF7D-324F5FD6A9F1} - http://scripts.dlv4.com/binaries/egaccess4/egaccess4_10...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game10.zylom.servicesalacarte.orange.fr/activex/...
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://player.virtools.com/downloads/player/Install2.5/...
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://wanadoofr.oberon-media.com/online2/diner_dash/Di...
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9336BF6-47C2-4468-BC4A-CC99640D6A51}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Securitoo Control Parental (OPTENET_FILTER) - Securitoo - C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe

moi j'ai mis b
Contenus similaires
26 Février 2007 13:58:45

Re,

Télécharge Blacklight (de F-Secure); clique sur "I ACCEPT" au bas de la page. Sauvegarde le sur ton Bureau.

Double-clique blbeta.exe et accepte la licence; clique Scan puis Next

Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

Copie et colle le contenu de ce rapport dans ta prochaine réponse. NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport, car des fichiers légitimes peuvent être présents, tel wbemtest.exe

Tu peux consulter le tutorial de F-Secure BlackLight : (merci à Malekal)

http://www.malekal.com/tutorial_f-secure_BlackLight.htm...
26 Février 2007 14:38:59

voilà le contenu du raport:



02/26/07 14:32:14 [Info]: BlackLight Engine 1.0.55 initialized
02/26/07 14:32:14 [Info]: OS: 5.1 build 2600 (Service Pack 1)
02/26/07 14:32:15 [Note]: 7019 4
02/26/07 14:32:15 [Note]: 7005 0
02/26/07 14:32:28 [Note]: 7006 0
02/26/07 14:32:28 [Note]: 7011 1480
02/26/07 14:32:29 [Note]: 7026 0
02/26/07 14:32:29 [Note]: 7026 0
02/26/07 14:32:29 [Note]: 7024 3
02/26/07 14:32:29 [Info]: Hidden process: C:\windows\system32\bcjxgescao.exe
02/26/07 14:32:36 [Note]: FSRAW library version 1.7.1021
02/26/07 14:34:16 [Info]: Hidden file: c:\WINDOWS\system32\bcjxgescao.dat
02/26/07 14:34:16 [Note]: 10002 1
02/26/07 14:34:16 [Info]: Hidden file: C:\windows\system32\bcjxgescao.exe
02/26/07 14:34:16 [Note]: 10002 1
02/26/07 14:34:16 [Info]: Hidden file: c:\WINDOWS\system32\bcjxgescao_nav.dat
02/26/07 14:34:16 [Note]: 10002 1
02/26/07 14:34:16 [Info]: Hidden file: c:\WINDOWS\system32\bcjxgescao_navps.dat
02/26/07 14:34:16 [Note]: 10002 1
02/26/07 14:35:14 [Note]: 2000 1012
26 Février 2007 14:41:33

Re,

La procédure est longue et en partie en mode sans échec. Attention, tu n'as pas accès à Internet dans ce mode, enregistre cette page Web (clique sur fichier/enregistrer sous/choisis « Bureau ») ou imprime ce que tu as à faire.

Télécharge Brute Force Uninstaller (de Merijn).
Créé un nouveau dossier directement sur le C:\ et nomme-le BFU. Décompresse le fichier téléchargé dans ce nouveau dossier (C:\BFU)

FAIS UN CLIC-DROIT ICI et choisis "Enregistrer la cible sous..." afin de télécharger EGDACCESS.bfu (de Metallica). Sauvegarde dans le dossier créé (C:\BFU). **Note : si tu utlises Internet Explorer; lors de la sauvegarde, assure-toi que le champs "Type :" affiche "Tous les fichiers". Tu dois maintenant avoir deux fichiers dans le dossier C:\BFU : EGDACCESS.bfu et BFU.exe (très important).

Télécharge Navipromo.zip et décompresse-le sur ton bureau.

Redémarre en mode Sans Échec
(au démarrage, tapote immédiatement la touche F8), puis tu verras un écran avec choix de démarrages :
choisis Mode sans échec avec les flèches du clavier, puis valide avec Entrée.
Choisis ton compte usuel (et non Administrateur).

Si tu n’arrives vraiment pas à redémarrer en mode sans échec je te propose ce lien :

Redémarrer en mode sans échec

- Lance le fichier Navipromo.bat qui se trouve dans le dossier Navipromo, sur ton bureau.

Lance le fichier Navipromo.bat qui se trouve sur ton bureau dans le dossier Navipromo.
Sélectionne d'abord l'option "Vérifications", et patiente quelques minutes. Lorsqu'il a terminé, ferme le rapport qui s'est ouvert.
Sélectionne ensuite l'option "Recherche et suppression automatique" en tapant sur la touche R.
S'il trouve quelque chose, tu verras défiler des lignes dans la fenêtre de commande et au bout de quelques instants, il faudra que tu appuies sur une touche pour que le nettoyage soit lancé.

Démarre le "Brute Force Uninstaller" en double-cliquant BFU.exe (du dossier C:\BFU)

- Clique sur le petit dossier jaune, à la droite de la boîte Scriptline to execute, et double-clique sur :

EGDACCESS.bfu

- Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\EGDACCESS.bfu

Clique sur Execute et laisse-le faire son travail.

Attendre que Complete script execution apparaîsse et clique sur OK.
Clique Exit pour fermer le programme BFU.

Redemarre normalement

Poste le contenu du fichier Navipromo.txt qui se trouve dans Poste de travail > disque C:\Navipromo.txt
Le rapport EGDACCESS.bfu qui ce trouve ici : C:\egd.txt
Un nouveau rapport Hijackthis.
26 Février 2007 15:19:45

ALORS ATTEND JE SUIS ENCORE A:

**Note : si tu utlises Internet Explorer; lors de la sauvegarde, assure-toi que le champs "Type :" affiche "Tous les fichiers". Tu dois maintenant avoir deux fichiers dans le dossier C:\BFU : EGDACCESS.bfu et BFU.exe (très important).
ET DANS LE DOC;IL Y A 2 TRUC.

BUF.exe
BUF.Brut force Uninstaller
Soeperman entreprises Ltd
et
egdaccess.buf
ficher BUH
48.ko

es ce que c'est ce qu'il faut qu'il y est dans le doc??
26 Février 2007 15:37:38

Oui continue :) 
26 Février 2007 16:23:01

;) Bon voilà sa y est c'est fait j'ai eu peur de faire des fautes de manipulation mais je crois avoir réussi. Alors voilà le rapport deNavipromo.txt:

Rapport Navipromo.bat 0.72 effectué le lun. 26/02/2007 à 15:53:13,45
L'opération se déroule en mode sans échec sous le compte "elodie"

## Vérifications supplémentaires

Note : cette section est expérimentale, aucun fichier ne sera supprimé. Si des fichiers sont trouvés à l'aide de cette méthode, ils ne seront pas nécessairement dangereux.

* Navipromo

C:\WINDOWS\System32

bcjxgescao.exe
bcjxgescao_navps.dat
bcjxgescao.dat
bcjxgescao.dat

* Trojan Nebula



* Trojan Vundo


-------------

Rapport Navipromo.bat 0.71 effectué le lun. 26/02/2007 à 15:54:07,59
L'opération se déroule en mode sans échec sous le compte "elodie"

** Recherche...

1/ bcjxgescao trouvé, recherche de bcjxgescao*
C:\WINDOWS\system32\bcjxgescao.dat
C:\WINDOWS\system32\bcjxgescao.exe
C:\WINDOWS\system32\bcjxgescao_nav.dat
C:\WINDOWS\system32\bcjxgescao_navps.dat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
bcjxgescao REG_SZ c:\windows\system32\bcjxgescao.exe bcjxgescao

------------------
Fin du rapport de recherche
Adware Navipromo trouvé 1 fois avec cette méthode

################################################

** Nettoyage...

1/ Déplacement de bcjxgescao* vers C:\Navipromo\Backups...
C:\WINDOWS\System32\bcjxgescao* déplacé avec succès !

------------------
* Suppression clés et valeurs de registre
1 entrées de registre netttoyées


* Backups :

C:\Navipromo\Backups\ARPCache.reg
C:\Navipromo\Backups\bcjxgescao.dat
C:\Navipromo\Backups\bcjxgescao.exe
C:\Navipromo\Backups\bcjxgescao_nav.dat
C:\Navipromo\Backups\bcjxgescao_navps.dat
C:\Navipromo\Backups\HKCURun.reg
C:\Navipromo\Backups\HKLMRun.reg
C:\Navipromo\Backups\pack.epk
C:\Navipromo\Backups\Uninstall.reg

Ajout d'extension .off aux backups

## Fin du rapport de Suppression

et celui deEGDACCESS.buf:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"Lexmark X1100 Series"="\"C:\\Program Files\\Lexmark X1100 Series\\lxbkbmgr.exe\""
"CnxDslTaskBar"="\"C:\\Program Files\\ZTE Corporation\\ZXDSL852\\CnxDslTb.exe\" \"ZTE Corporation\\ZXDSL852\""
"WOOWATCH"="C:\\PROGRA~1\\Wanadoo\\Watch.exe"
"WOOTASKBARICON"="C:\\PROGRA~1\\Wanadoo\\GestMaj.exe TaskBarIcon.exe"
"LVCOMSX"="C:\\WINDOWS\\System32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"Synchronization Manager"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,\
00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,\
32,00,5c,00,6d,00,6f,00,62,00,73,00,79,00,6e,00,63,00,2e,00,65,00,78,00,65,\
00,20,00,2f,00,6c,00,6f,00,67,00,6f,00,6e,00,00,00
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"KernelFaultCheck"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,\
00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,\
5c,00,64,00,75,00,6d,00,70,00,72,00,65,00,70,00,20,00,30,00,20,00,2d,00,6b,\
00,00,00
"SDR6V_Check"="\"C:\\Program Files\\Fichiers communs\\DriveCleaner Free\\udcsdr.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

26 Février 2007 16:25:42

Re,

Tu as fait du bon boulot ;) 

Supprime ce dosssier :

C:\Navipromo\Backups

La procédure est longue et en partie en mode sans échec. Attention, tu n'as pas accès à Internet dans ce mode, enregistre cette page Web (clique sur fichier/enregistrer sous/choisis « Bureau ») ou imprime ce que tu as à faire.

1/ Télécharge la version d'évaluation d'AVG Anti-Spyware 7.5

Installe-le sur ton bureau

- Démarre AVG Anti-Spyware 7.5 avec l'icône qui se trouve sur ton Bureau.
Clique sur Mise à jour.
Sous Mise à jour manuelle clique sur Commencer la mise à jour et attend la fin de cette mise à jour puis ferme le programme.

2/ Télécharge Ccleaner

Installe le dans un répertoire dédié (attention à l'installation pense à décocher l'installation de Yahoo toolbar).

3/ Redémarre en mode Sans Échec
(au démarrage, tapote immédiatement la touche F8), puis tu verras un écran avec choix de démarrages :
choisis Mode sans échec avec les flèches du clavier, puis valide avec Entrée.
Choisis ton compte usuel (et non Administrateur).

Si tu n’arrives vraiment pas à redémarrer en mode sans échec je te propose ce lien :

Redémarrer en mode sans échec

4/ Lance Ccleaner

Puis clique sur le bouton « Analyse » ensuite bouton « Lancer le Nettoyage ». Ensuite fait de même sur le bouton « Erreurs » puis « chercher des erreurs » et « réparer les erreurs sélectionnées ».

5/ Lance AVG Anti-Spyware 7.5 et clique sur Analyse et ensuite clique sur Analyse complète du système.
A la fin du scan il affichera une liste des fichiers détectés.
Clique sur le bouton Appliquer toutes les actions.
Clique sur Enregistrer le rapport, puis Enregistrer le rapport sous, je te conseille de le mettre sur ton bureau.

6/ Redémarre en mode normal.
Poste le rapport AVG Anti-Spyware 7.5 dans ta prochaine réponse et poste un nouveau rapport HijackThis.
26 Février 2007 16:30:05

petite précision: qu'est-ce qu' un répertoire dédié (attention à l'installation pense à décocher l'installation de Yahoo toolbar).
26 Février 2007 16:46:44

Re,

C'est à dire dans son propre dossier quand tu l'installeras met le directement sur C:
26 Février 2007 19:22:52

re,
es ceci le rapport que tu ma demandé? je commence a etre un peut perdu

Windows Registry Editor Version 5.00


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\CoverDesigner\\covered-deu.nls"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Ahead\\Nero BackItUp\\BackItUp-Deu.nls"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\WINDOWS\\System32\\pxwma.dll"=dword:00000001

[HKEY_CLASSES_ROOT\.eta]
@="Google Earth.etafile"


[HKEY_CLASSES_ROOT\.kml]
@="Google Earth.kmlfile"


[HKEY_CLASSES_ROOT\.kmz]
@="Google Earth.kmzfile"


[HKEY_CLASSES_ROOT\.VOB]


[HKEY_CLASSES_ROOT\OWS Collaboration Objects]
@=""


[HKEY_CLASSES_ROOT\PCFriendly.PCFriendly]


[HKEY_CLASSES_ROOT\SysmonLogManager.Snapin]


[HKEY_CLASSES_ROOT\WMPCD]


[HKEY_CLASSES_ROOT\{]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\OpenWithList]
"a"="WOOBrowser.exe"
"MRUList"="a"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.008041325987235726]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.008041325987235726\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.013256626085709655]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.013256626085709655\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.08217962750937269]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.08217962750937269\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.14679553246335408]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.14679553246335408\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.230]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.230\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.256]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.256\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.26354762967797596]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.26354762967797596\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.4039209087493816]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.4039209087493816\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.9225785952965325]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.9225785952965325\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.9784590071043828]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.9784590071043828\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abm\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.am]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.am\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr\OpenWithProgids]
"RealPlayer.AMR.10"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asg\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.awb]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.awb\OpenWithProgids]
"RealPlayer.AMR_WB.10"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bak]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bak\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bfu]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bfu\OpenWithList]
"a"="WOOBrowser.exe"
"MRUList"="ba"
"b"="BFU.exe"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bik]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bik\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMK]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMK\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cache]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cache\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ccd]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ccd\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cfg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cfg\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cnc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cnc\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cnk]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cnk\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue\OpenWithList]
"a"="daemon.exe"
"MRUList"="a"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\OpenWithList]
"a"="ACDSee6.exe"
"MRUList"="ba"
"b"="shimgvw.dll"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.divx\OpenWithProgids]
"RealPlayer.DIVX.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dsp\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exeold]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exeold\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gba]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gba\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gifmaman]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gifmaman\OpenWithList]
"a"="WOOBrowser.exe"
"MRUList"="a"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gifreine]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gifreine\OpenWithList]
"a"="WOOBrowser.exe"
"MRUList"="a"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icw\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.in]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.in\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iso]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iso\OpenWithList]
"a"="WinISO.exe"
"MRUList"="a"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iso\OpenWithProgids]
"WinISO"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j00]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j00\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.layout]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.layout\OpenWithList]
"a"="bsplay.exe"
"MRUList"="a"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mds]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mds\OpenWithList]
"a"="daemon.exe"
"MRUList"="a"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpga]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OLD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OLD\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.package]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.package\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php%3Fid%3D40886%26type%3D2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php%3Fid%3D40886%26type%3D2\OpenWithList]
"a"="WOOBrowser.exe"
"MRUList"="a"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PRO]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PRO\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PSF]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PSF\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram\OpenWithProgids]
"RealPlayer.RAM.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rax]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rax\OpenWithProgids]
"RealPlayer.RAX.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rjs]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rjt]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmj]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmj\OpenWithProgids]
"RealJukebox.RMJ.1"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmm]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmm\OpenWithProgids]
"RealPlayer.RAM.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rms]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rms\OpenWithProgids]
"RealPlayer.RMS.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmx]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmx\OpenWithProgids]
"RealJukebox.RMX.1"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rnx]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rp]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsml]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsml\OpenWithProgids]
"RealPlayer.RSML.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rt]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rv]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rvx]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rvx\OpenWithProgids]
"RealPlayer.RVX.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sav]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sav\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.set]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.set\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sg0]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sg0\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sg1]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sg1\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi\OpenWithProgids]
"RealPlayer.SMIL.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil]
"Application"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil\OpenWithProgids]
"RealPlayer.SMIL.6"=hex(0):


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ssm]
"Application"=""


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sxw\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ver]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ver\OpenWithList]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithList]


[HKEY_CLASSES_ROOT\3ivx.m4a\shell\Open]
@="&Open"

[HKEY_CLASSES_ROOT\3ivx.m4a\shell\Open\Command]
@="\"C:\\Program Files\\Windows Media Player\\mplayer2.exe\" \"%1\""


[HKEY_CLASSES_ROOT\3ivx.mp4\shell\Open]
@="&Open"

[HKEY_CLASSES_ROOT\3ivx.mp4\shell\Open\Command]
@="\"C:\\Program Files\\Windows Media Player\\mplayer2.exe\" \"%1\""


[HKEY_CLASSES_ROOT\acrobat\DefaultIcon]
@="C:\\Program Files\\Adobe\\Acrobat 7.0\\Acrobat\\AcroRd32.exe"


[HKEY_CLASSES_ROOT\ActMsg.Session]
@="Active Messaging Session Object"

[HKEY_CLASSES_ROOT\ActMsg.Session\CLSID]
@="{3FA7DEB3-6438-101B-ACC1-00AA00423326}"


[HKEY_CLASSES_ROOT\acwfile\DefaultIcon]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,63,00,\
63,00,77,00,69,00,7a,00,2e,00,65,00,78,00,65,00,2c,00,30,00,00,00


[HKEY_CLASSES_ROOT\acwfile\shell\open]

[HKEY_CLASSES_ROOT\acwfile\shell\open\command]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,63,00,\
63,00,77,00,69,00,7a,00,2e,00,65,00,78,00,65,00,20,00,25,00,31,00,00,00


[HKEY_CLASSES_ROOT\ADCS]
@="Conteneur de classe Annuaire"

[HKEY_CLASSES_ROOT\ADCS\CLSID]
@="{89E30300-764D-11d0-B282-00A0C90F56FC}"


[HKEY_CLASSES_ROOT\bin_auto_file\shell\open]

[HKEY_CLASSES_ROOT\bin_auto_file\shell\open\command]
@="\"C:\\Program Files\\WinISO\\WinISO.exe\" \"%1\""


[HKEY_CLASSES_ROOT\Cartes Fichier\DefaultIcon]
@="C:\\DOCUME~1\\elodie\\LOCALS~1\\Temp\\Rar$EX01.266\\Visiten.exe,1"


[HKEY_CLASSES_ROOT\Cartes Fichier\shell\open]

[HKEY_CLASSES_ROOT\Cartes Fichier\shell\open\command]
@="C:\\DOCUME~1\\elodie\\LOCALS~1\\Temp\\Rar$EX01.266\\Visiten.exe \"%1\""


[HKEY_CLASSES_ROOT\Cartes Fichier\shell\print]

[HKEY_CLASSES_ROOT\Cartes Fichier\shell\print\command]
@="C:\\DOCUME~1\\elodie\\LOCALS~1\\Temp\\Rar$EX01.266\\Visiten.exe /p \"%1\""


[HKEY_CLASSES_ROOT\Cartes Fichier\shell\printto]

[HKEY_CLASSES_ROOT\Cartes Fichier\shell\printto\command]
@="C:\\DOCUME~1\\elodie\\LOCALS~1\\Temp\\Rar$EX01.266\\Visiten.exe /pt \"%1\" \"%2\" \"%3\" \"%4\""


[HKEY_CLASSES_ROOT\Connection Manager Profile\DefaultIcon]
@="C:\\WINDOWS\\System32\\CMMGR32.EXE,1"


[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open]

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open\command]
@="C:\\WINDOWS\\System32\\CMMGR32.EXE \"%1\""


[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...]

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...\command]
@="C:\\WINDOWS\\System32\\CMMGR32.EXE /settings \"%1\""


[HKEY_CLASSES_ROOT\GSALaunch.Document\shell\launch]
@="&Launch GameSpy Arcade"

[HKEY_CLASSES_ROOT\GSALaunch.Document\shell\launch\command]
@="C:\\PROGRA~1\\GAMESP~1\\GSAPak.exe -launch \"%1\""


[HKEY_CLASSES_ROOT\GSASkin.Document\DefaultIcon]
@="C:\\PROGRA~1\\GAMESP~1\\GSAPak.exe,-133"


[HKEY_CLASSES_ROOT\GSASkin.Document\shell\install]
@="&Install Arcade Skin!"

[HKEY_CLASSES_ROOT\GSASkin.Document\shell\install\command]
@="C:\\PROGRA~1\\GAMESP~1\\GSAPak.exe \"%1\""


[HKEY_CLASSES_ROOT\GSASkin.Document\shell\open]

[HKEY_CLASSES_ROOT\GSASkin.Document\shell\open\command]
@="C:\\PROGRA~1\\GAMESP~1\\GSAPak.exe \"%1\""


[HKEY_CLASSES_ROOT\MAFairePart.Carte\DefaultIcon]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\draw7019.exe,0"


[HKEY_CLASSES_ROOT\MAFairePart.Carte\shell\open]

[HKEY_CLASSES_ROOT\MAFairePart.Carte\shell\open\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\draw7019.exe \"%1\""


[HKEY_CLASSES_ROOT\MAFairePart.Carte\shell\print]

[HKEY_CLASSES_ROOT\MAFairePart.Carte\shell\print\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\draw7019.exe /p \"%1\""


[HKEY_CLASSES_ROOT\MAFairePart.Carte\shell\printto]

[HKEY_CLASSES_ROOT\MAFairePart.Carte\shell\printto\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\draw7019.exe /pt \"%1\" \"%2\" \"%3\" \"%4\""


[HKEY_CLASSES_ROOT\MailFileAtt]
@=""

[HKEY_CLASSES_ROOT\MailFileAtt\CLSID]
@="{00020D05-0000-0000-C000-000000000046}"


[HKEY_CLASSES_ROOT\MAKitCDDVDEditionClassic.Kit\DefaultIcon]
@="C:\\PROGRA~1\\MICROA~1\\KITCD-~1\\draw4359.exe,0"


[HKEY_CLASSES_ROOT\MAKitCDDVDEditionClassic.Kit\shell\open]

[HKEY_CLASSES_ROOT\MAKitCDDVDEditionClassic.Kit\shell\open\command]
@="C:\\PROGRA~1\\MICROA~1\\KITCD-~1\\draw4359.exe \"%1\""


[HKEY_CLASSES_ROOT\MAKitCDDVDEditionClassic.Kit\shell\print]

[HKEY_CLASSES_ROOT\MAKitCDDVDEditionClassic.Kit\shell\print\command]
@="C:\\PROGRA~1\\MICROA~1\\KITCD-~1\\draw4359.exe /p \"%1\""


[HKEY_CLASSES_ROOT\MAKitCDDVDEditionClassic.Kit\shell\printto]

[HKEY_CLASSES_ROOT\MAKitCDDVDEditionClassic.Kit\shell\printto\command]
@="C:\\PROGRA~1\\MICROA~1\\KITCD-~1\\draw4359.exe /pt \"%1\" \"%2\" \"%3\" \"%4\""


[HKEY_CLASSES_ROOT\mapifvbx.object]
@="MAPIForm object"

[HKEY_CLASSES_ROOT\mapifvbx.object\Clsid]
@="{41116C00-8B90-101B-96CD-00AA003B14FC}"


[HKEY_CLASSES_ROOT\mapifvbx.object.1]
@="MAPIForm object (V 1.0)"

[HKEY_CLASSES_ROOT\mapifvbx.object.1\Clsid]
@="{41116C00-8B90-101B-96CD-00AA003B14FC}"


[HKEY_CLASSES_ROOT\Plenoptic.Plenoptic]
@="Plenoptic Class"

[HKEY_CLASSES_ROOT\Plenoptic.Plenoptic\CLSID]
@="{607C27E9-AB27-11d3-A116-A0EA50C10801}"

[HKEY_CLASSES_ROOT\Plenoptic.Plenoptic\CurVer]
@="Plenoptic.Plenoptic.1"


[HKEY_CLASSES_ROOT\Plenoptic.Plenoptic.1]
@="Plenoptic Class"

[HKEY_CLASSES_ROOT\Plenoptic.Plenoptic.1\CLSID]
@="{607C27E9-AB27-11d3-A116-A0EA50C10801}"


[HKEY_CLASSES_ROOT\ScrapPerso.Document\DefaultIcon]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\SCRAPP~1.EXE,1"


[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\open]

[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\open\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\SCRAPP~1.EXE /dde"

[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\open\ddeexec]
@="[open(\"%1\")]"


[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\print]

[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\print\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\SCRAPP~1.EXE /dde"

[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\print\ddeexec]
@="[print(\"%1\")]"


[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\printto]

[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\printto\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\SCRAPP~1.EXE /dde"

[HKEY_CLASSES_ROOT\ScrapPerso.Document\shell\printto\ddeexec]
@="[printto(\"%1\",\"%2\",\"%3\",\"%4\")]"


[HKEY_CLASSES_ROOT\vnd.ms.radio\shell\open]

[HKEY_CLASSES_ROOT\vnd.ms.radio\shell\open\command]
@="\"C:\\Program Files\\Windows Media Player\\mplayer2.exe\" \"%L\""


[HKEY_CLASSES_ROOT\WBEMComConnection]
@="WBEM Connection"

[HKEY_CLASSES_ROOT\WBEMComConnection\CLSID]
@="SOFTWARE\\CLASSES\\WBEMComConnection"


[HKEY_CLASSES_ROOT\WBEMComLocator]
@="WBEM Locator"

[HKEY_CLASSES_ROOT\WBEMComLocator\CLSID]
@="SOFTWARE\\CLASSES\\WBEMComLocator"


[HKEY_CLASSES_ROOT\WMDMPDAExplorer.WMDMPDAExplorer]
@="WMDM PDA Explorer for WMP 7.0"

[HKEY_CLASSES_ROOT\WMDMPDAExplorer.WMDMPDAExplorer\CLSID]
@="{939438A9-CF0F-44d8-9140-599736F0D3A2}"

[HKEY_CLASSES_ROOT\WMDMPDAExplorer.WMDMPDAExplorer\CurVer]
@="WMDMPDAExplorer.WMDMPDAExplorer.1"


[HKEY_CLASSES_ROOT\WMDMPDAExplorer.WMDMPDAExplorer.1]
@="WMDM PDA Explorer for WMP 7.0"

[HKEY_CLASSES_ROOT\WMDMPDAExplorer.WMDMPDAExplorer.1\CLSID]
@="{939438A9-CF0F-44d8-9140-599736F0D3A2}"


[HKEY_CLASSES_ROOT\CLSID\{07F46615-1857-40CF-9AA9-872C9858E769}]
@="PSFactoryBuffer"

[HKEY_CLASSES_ROOT\CLSID\{07F46615-1857-40CF-9AA9-872C9858E769}\InProcServer32]
@="C:\\Program Files\\Google\\Google Earth\\earthps.dll"
"ThreadingModel"="Both"


[HKEY_CLASSES_ROOT\CLSID\{085BBE3D-39F4-4B73-ABD8-B64C65496888}]
@="PSFactoryBuffer"

[HKEY_CLASSES_ROOT\CLSID\{085BBE3D-39F4-4B73-ABD8-B64C65496888}\InProcServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\SyncEngineAppps.dll"
"ThreadingModel"="Both"


[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}]

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\InprocServer32]
@="\"C:\\PROGRA~1\\MSNMES~1\\msgsc.dll\""
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\LocalServer32]
@="\"C:\\PROGRA~1\\MSNMES~1\\msnmsgr.exe\""
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\ProgID]
@="MSNMessenger.ContactsPicker"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\Programmable]
@=""

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{111C85E9-BB62-4528-A806-F0BE908E02F0}\VersionIndependentProgID]
@="MSNMessenger.ContactsPicker.1"


[HKEY_CLASSES_ROOT\CLSID\{279AD714-3F53-49FA-904E-E5DF5A2AC123}]
@="OutlookExtension.Adapter"

[HKEY_CLASSES_ROOT\CLSID\{279AD714-3F53-49FA-904E-E5DF5A2AC123}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{279AD714-3F53-49FA-904E-E5DF5A2AC123}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}]

[HKEY_CLASSES_ROOT\CLSID\{279AD714-3F53-49FA-904E-E5DF5A2AC123}\InprocServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\OutlookExtension.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{279AD714-3F53-49FA-904E-E5DF5A2AC123}\ProgID]
@="OutlookExtension.Adapter"

[HKEY_CLASSES_ROOT\CLSID\{279AD714-3F53-49FA-904E-E5DF5A2AC123}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{279AD714-3F53-49FA-904E-E5DF5A2AC123}\TypeLib]
@="{254A2B92-CC22-490C-A494-F67B4E065E63}"

[HKEY_CLASSES_ROOT\CLSID\{279AD714-3F53-49FA-904E-E5DF5A2AC123}\VERSION]
@="1.0"


[HKEY_CLASSES_ROOT\CLSID\{36034C71-E550-4E16-B2C8-8B6665B1590B}]
@="Obex Session Class"

[HKEY_CLASSES_ROOT\CLSID\{36034C71-E550-4E16-B2C8-8B6665B1590B}\InprocServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\ObexTransport.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{36034C71-E550-4E16-B2C8-8B6665B1590B}\ProgID]
@="ObexTransport.ObexSession.SEMC.1"

[HKEY_CLASSES_ROOT\CLSID\{36034C71-E550-4E16-B2C8-8B6665B1590B}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{36034C71-E550-4E16-B2C8-8B6665B1590B}\TypeLib]
@="{905F030D-5B90-46EB-B845-8C3F8A7772DC}"

[HKEY_CLASSES_ROOT\CLSID\{36034C71-E550-4E16-B2C8-8B6665B1590B}\VersionIndependentProgID]
@="ObexTransport.ObexSession.SEMC"


[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}]
@="Implements DocHostUIHandler"

[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32]
@="C:\\PROGRA~1\\DISNEY~1\\DISNEY~1\\atlantis.exe"

[HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID]
@="atlantis.DocHostUIHandler"


[HKEY_CLASSES_ROOT\CLSID\{4C904A4A-714C-78C5-2E3E-A690F6FB6765}]
@="PSFactoryBuffer"
"WOkUXCwDoaoJx"="iEgnSzqKRlk{VVBaS@fQH@hdREoHb~Flh|wADFoD\\QnaVOwkxTpR{Mk_DrFecKWOC~]a_]pK^pHoJ\\CXXv`{WPNKfEWWp"

[HKEY_CLASSES_ROOT\CLSID\{4C904A4A-714C-78C5-2E3E-A690F6FB6765}\InProcServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\SyncEngineAppps.dll"
"ThreadingModel"="Both"


[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}]
@="DbConf Control"

[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}\Control]
@=""

[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}\InprocServer32]
@="C:\\PROGRA~1\\SONYER~1\\Mobile\\SYNCST~1\\DbConf.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}\ProgID]
@="DBCONF.DbConfCtrl.SEMC.1"

[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}\ToolboxBitmap32]
@="C:\\PROGRA~1\\SONYER~1\\Mobile\\SYNCST~1\\DbConf.ocx, 1"

[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}\TypeLib]
@="{DB8E1350-A9EC-446E-91F8-99FE969FAFFE}"

[HKEY_CLASSES_ROOT\CLSID\{51BA5D82-D09E-4ABB-BF04-EE75966DB45A}\Version]
@="1.0"


[HKEY_CLASSES_ROOT\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}]
@="RealDownload Express InfoWindow Class"

[HKEY_CLASSES_ROOT\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}\InprocServer32]
@="C:\\DOCUME~1\\elodie\\LOCALS~1\\Temp\\InfoWindow.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}\ProgID]
@="RealDownloadExpress.InfoWindow.1"

[HKEY_CLASSES_ROOT\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}\TypeLib]
@="{7AF322C5-AB43-11D4-A00B-0050DA18DE71}"

[HKEY_CLASSES_ROOT\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}\VersionIndependentProgID]
@="RealDownloadExpress.InfoWindow"


[HKEY_CLASSES_ROOT\CLSID\{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}]
@="KHViewExtents Class"
"AppID"="{7E7898C9-8E34-4314-9670-771BC5343D0E}"

[HKEY_CLASSES_ROOT\CLSID\{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}\ProgID]
@="Keyhole.KHViewExtents.1"

[HKEY_CLASSES_ROOT\CLSID\{63E6BE14-A742-4EEA-8AF3-0EC39F10F850}\VersionIndependentProgID]
@="Keyhole.KHViewExtents"


[HKEY_CLASSES_ROOT\CLSID\{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}]
@="CameraInfoGE Class"
"AppID"="{46A99B9C-4AC8-4EE9-AF7D-D02816CEC314}"

[HKEY_CLASSES_ROOT\CLSID\{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}\ProgID]
@="GoogleEarth.CameraInfoGE.1"

[HKEY_CLASSES_ROOT\CLSID\{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}\TypeLib]
@="{3476FAB2-687F-4EA6-9AC2-88D72DC7D7FC}"

[HKEY_CLASSES_ROOT\CLSID\{645EEE5A-BD51-4C05-A6AF-6F2CF8950AAB}\VersionIndependentProgID]
@="GoogleEarth.CameraInfoGE"


[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}]
@="Web Assistant"
"AppID"=""

[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}\Implemented Categories\{00021493-0000-0000-C000-000000000046}]

[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}\InprocServer32]
@="C:\\Program Files\\HbTools\\Bin\\4.7.7.0\\HbtHostIE.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}\Instance]
"CLSID"="{4D5C8C2A-D075-11D0-B416-00C04FB90376}"

[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}\Instance\InitPropertyBag]
"Url"="http://hotbar.com"

[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}\ProgID]
@="HbTools.HbtTravelCompareBar.1"

[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}\TypeLib]
@="{45397063-D7D0-47C2-9508-26487608A298}"

[HKEY_CLASSES_ROOT\CLSID\{66B90ADB-0BE3-40AE-8680-84A6F0577CA0}\VersionIndependentProgID]
@="HbTools.HbtTravelCompareBar"


[HKEY_CLASSES_ROOT\CLSID\{74CC49F7-EB32-4A08-B204-948962A6E3DB}]
@="H&otbar"

[HKEY_CLASSES_ROOT\CLSID\{74CC49F7-EB32-4A08-B204-948962A6E3DB}\InprocServer32]
@="C:\\Program Files\\HbTools\\Bin\\4.8.2.0\\HbtHostIE.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{74CC49F7-EB32-4A08-B204-948962A6E3DB}\ProgID]
@="HbtHostIE.Bho.1"

[HKEY_CLASSES_ROOT\CLSID\{74CC49F7-EB32-4A08-B204-948962A6E3DB}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{74CC49F7-EB32-4A08-B204-948962A6E3DB}\TypeLib]
@="{45397063-D7D0-47C2-9508-26487608A298}"

[HKEY_CLASSES_ROOT\CLSID\{74CC49F7-EB32-4A08-B204-948962A6E3DB}\VersionIndependentProgID]
@="HbtHostIE.Bho"


[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}]
@="Hotbar Information Window"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Control]

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Implemented Categories\{00021494-0000-0000-C000-000000000046}]

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\InprocServer32]
@="C:\\Program Files\\HbTools\\Bin\\4.8.2.0\\HbtHostIE.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Instance]
"CLSID"="{4D5C8C2A-D075-11D0-B416-00C04FB90376}"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Instance\InitPropertyBag]
"Url"="http://hotbar.com"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\ProgID]
@="HbTools.HbtCommBand.1"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\ToolboxBitmap32]
@="C:\\Program Files\\HbTools\\Bin\\4.8.2.0\\HbtHostIE.dll, 507"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\TypeLib]
@="{45397063-D7D0-47C2-9508-26487608A298}"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\VersionIndependentProgID]
@="HbTools.HbtCommBand"


[HKEY_CLASSES_ROOT\CLSID\{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}]
@="ApplicationGE Class"
"AppID"="{46A99B9C-4AC8-4EE9-AF7D-D02816CEC314}"

[HKEY_CLASSES_ROOT\CLSID\{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}\ProgID]
@="GoogleEarth.ApplicationGE.1"

[HKEY_CLASSES_ROOT\CLSID\{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}\TypeLib]
@="{3476FAB2-687F-4EA6-9AC2-88D72DC7D7FC}"

[HKEY_CLASSES_ROOT\CLSID\{8097D7E9-DB9E-4AEF-9B28-61D82A1DF784}\VersionIndependentProgID]
@="GoogleEarth.ApplicationGE"


[HKEY_CLASSES_ROOT\CLSID\{8202B02B-086E-44C0-B991-9A78AD95376E}]
@="Device Customisation Factory Class"

[HKEY_CLASSES_ROOT\CLSID\{8202B02B-086E-44C0-B991-9A78AD95376E}\InprocServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\DeviceCustomisation.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{8202B02B-086E-44C0-B991-9A78AD95376E}\ProgID]
@="Teleca.TSS.SyncStation.DeviceCustomisationFactory.SEMC.1"

[HKEY_CLASSES_ROOT\CLSID\{8202B02B-086E-44C0-B991-9A78AD95376E}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{8202B02B-086E-44C0-B991-9A78AD95376E}\TypeLib]
@="{1844683D-0402-4D35-90C5-84AFB767C92E}"

[HKEY_CLASSES_ROOT\CLSID\{8202B02B-086E-44C0-B991-9A78AD95376E}\VersionIndependentProgID]
@="Teleca.TSS.SyncStation.DeviceCustomisationFactory.SEMC"


[HKEY_CLASSES_ROOT\CLSID\{8C875948-9C60-4381-9248-0DF180542D53}]
@="HbtInstObj"

[HKEY_CLASSES_ROOT\CLSID\{8C875948-9C60-4381-9248-0DF180542D53}\InprocServer32]
@="C:\\Program Files\\HbTools\\Bin\\4.8.2.0\\HbtInstIE.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{8C875948-9C60-4381-9248-0DF180542D53}\ProgID]
@="HbtInstIE.HbInstObj.1"

[HKEY_CLASSES_ROOT\CLSID\{8C875948-9C60-4381-9248-0DF180542D53}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{8C875948-9C60-4381-9248-0DF180542D53}\TypeLib]
@="{4CF5A3C1-07A2-4336-9B54-6870452EBDE1}"

[HKEY_CLASSES_ROOT\CLSID\{8C875948-9C60-4381-9248-0DF180542D53}\VersionIndependentProgID]
@="HbtInstIE.HbInstObj"


[HKEY_CLASSES_ROOT\CLSID\{9059C329-4661-49B2-9984-8753C45DB7B9}]
@="FeatureCollectionGE Class"
"AppID"="{46A99B9C-4AC8-4EE9-AF7D-D02816CEC314}"

[HKEY_CLASSES_ROOT\CLSID\{9059C329-4661-49B2-9984-8753C45DB7B9}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{9059C329-4661-49B2-9984-8753C45DB7B9}\ProgID]
@="GoogleEarth.FeatureCollectionGE.1"

[HKEY_CLASSES_ROOT\CLSID\{9059C329-4661-49B2-9984-8753C45DB7B9}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{9059C329-4661-49B2-9984-8753C45DB7B9}\TypeLib]
@="{3476FAB2-687F-4EA6-9AC2-88D72DC7D7FC}"

[HKEY_CLASSES_ROOT\CLSID\{9059C329-4661-49B2-9984-8753C45DB7B9}\VersionIndependentProgID]
@="GoogleEarth.FeatureCollectionGE"


[HKEY_CLASSES_ROOT\CLSID\{92547B06-0007-4820-B76A-C84E402CA709}]
@="PSFactoryBuffer"

[HKEY_CLASSES_ROOT\CLSID\{92547B06-0007-4820-B76A-C84E402CA709}\InProcServer32]
@="C:\\Program Files\\Google\\Google Earth\\earthps.dll"
"ThreadingModel"="Both"


[HKEY_CLASSES_ROOT\CLSID\{98764E83-0130-44CD-A637-0B08C0BE6AB2}]
@="All Device Customisation Class"

[HKEY_CLASSES_ROOT\CLSID\{98764E83-0130-44CD-A637-0B08C0BE6AB2}\InprocServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\DeviceCustomisation.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{98764E83-0130-44CD-A637-0B08C0BE6AB2}\ProgID]
@="DeviceCustomisation.AllDeviceCustomisation.SEMC.1"

[HKEY_CLASSES_ROOT\CLSID\{98764E83-0130-44CD-A637-0B08C0BE6AB2}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{98764E83-0130-44CD-A637-0B08C0BE6AB2}\TypeLib]
@="{1844683D-0402-4D35-90C5-84AFB767C92E}"

[HKEY_CLASSES_ROOT\CLSID\{98764E83-0130-44CD-A637-0B08C0BE6AB2}\VersionIndependentProgID]
@="DeviceCustomisation.AllDeviceCustomisation.SEMC"


[HKEY_CLASSES_ROOT\CLSID\{9E66A2FA-680E-45CD-AC92-0CD87A1A72A7}]
@="OutlookPimAdaption Class"

[HKEY_CLASSES_ROOT\CLSID\{9E66A2FA-680E-45CD-AC92-0CD87A1A72A7}\InprocServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\OutlookPim.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{9E66A2FA-680E-45CD-AC92-0CD87A1A72A7}\ProgID]
@="Outlook.OutlookPimAdaption.SEMC.1"

[HKEY_CLASSES_ROOT\CLSID\{9E66A2FA-680E-45CD-AC92-0CD87A1A72A7}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{9E66A2FA-680E-45CD-AC92-0CD87A1A72A7}\TypeLib]
@="{5E8E47F1-B107-49EC-A819-E4EF9FE5A733}"

[HKEY_CLASSES_ROOT\CLSID\{9E66A2FA-680E-45CD-AC92-0CD87A1A72A7}\VersionIndependentProgID]
@="Outlook.OutlookPimAdaption.SEMC"


[HKEY_CLASSES_ROOT\CLSID\{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}]
@="KHViewInfo Class"
"AppID"="{7E7898C9-8E34-4314-9670-771BC5343D0E}"

[HKEY_CLASSES_ROOT\CLSID\{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}\ProgID]
@="Keyhole.KHViewInfo.1"

[HKEY_CLASSES_ROOT\CLSID\{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}\TypeLib]
@="{3476FAB2-687F-4EA6-9AC2-88D72DC7D7FC}"

[HKEY_CLASSES_ROOT\CLSID\{A2D4475B-C9AA-48E2-A029-1DB829DACF7B}\VersionIndependentProgID]
@="Keyhole.KHViewInfo"


[HKEY_CLASSES_ROOT\CLSID\{AD6BF5C0-7B88-11D5-A5DE-444553540000}]
@="BMPCapture"

[HKEY_CLASSES_ROOT\CLSID\{AD6BF5C0-7B88-11D5-A5DE-444553540000}\InprocServer32]
@="C:\\Program Files\\Sony Corporation\\Picture Package\\Picture Package Applications\\BMPCapture.ax"
"ThreadingModel"="Both"


[HKEY_CLASSES_ROOT\CLSID\{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}]
@="KHInterface Class"
"AppID"="{7E7898C9-8E34-4314-9670-771BC5343D0E}"

[HKEY_CLASSES_ROOT\CLSID\{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}\ProgID]
@="Keyhole.KHInterface.1"

[HKEY_CLASSES_ROOT\CLSID\{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}\TypeLib]
@="{3476FAB2-687F-4EA6-9AC2-88D72DC7D7FC}"

[HKEY_CLASSES_ROOT\CLSID\{AFD07A5E-3E20-4D77-825C-2F6D1A50BE5B}\VersionIndependentProgID]
@="Keyhole.KHInterface"


[HKEY_CLASSES_ROOT\CLSID\{B100C7CF-A032-47DA-B850-75E821A0826E}]
@="DbConf Property Page"

[HKEY_CLASSES_ROOT\CLSID\{B100C7CF-A032-47DA-B850-75E821A0826E}\InprocServer32]
@="C:\\PROGRA~1\\SONYER~1\\Mobile\\SYNCST~1\\DbConf.ocx"


[HKEY_CLASSES_ROOT\CLSID\{B153D707-447A-4538-913E-6146B3FDEE02}]
@="KHFeature Class"
"AppID"="{7E7898C9-8E34-4314-9670-771BC5343D0E}"

[HKEY_CLASSES_ROOT\CLSID\{B153D707-447A-4538-913E-6146B3FDEE02}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{B153D707-447A-4538-913E-6146B3FDEE02}\ProgID]
@="Keyhole.KHFeature.1"

[HKEY_CLASSES_ROOT\CLSID\{B153D707-447A-4538-913E-6146B3FDEE02}\VersionIndependentProgID]
@="Keyhole.KHFeature"


[HKEY_CLASSES_ROOT\CLSID\{BF16DE10-E096-4D85-ADC3-7CA8D23A2BCF}]
@="SyncProgressDialog Class"
"AppID"=""

[HKEY_CLASSES_ROOT\CLSID\{BF16DE10-E096-4D85-ADC3-7CA8D23A2BCF}\InprocServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\Progress.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{BF16DE10-E096-4D85-ADC3-7CA8D23A2BCF}\ProgID]
@="TelecaSyncMLProgressDialog.SyncProgressDialog.SEMC.1"

[HKEY_CLASSES_ROOT\CLSID\{BF16DE10-E096-4D85-ADC3-7CA8D23A2BCF}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{BF16DE10-E096-4D85-ADC3-7CA8D23A2BCF}\TypeLib]
@="543D4CDA-4C8F-47C2-BDFA-093688B1E693"

[HKEY_CLASSES_ROOT\CLSID\{BF16DE10-E096-4D85-ADC3-7CA8D23A2BCF}\VersionIndependentProgID]
@="TelecaSyncMLProgressDialog.SyncProgressDialog.SEMC"


[HKEY_CLASSES_ROOT\CLSID\{CBD4FB70-F00B-4963-B249-4B056E6A981A}]
@="FeatureGE Class"
"AppID"="{46A99B9C-4AC8-4EE9-AF7D-D02816CEC314}"

[HKEY_CLASSES_ROOT\CLSID\{CBD4FB70-F00B-4963-B249-4B056E6A981A}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{CBD4FB70-F00B-4963-B249-4B056E6A981A}\ProgID]
@="GoogleEarth.FeatureGE.1"

[HKEY_CLASSES_ROOT\CLSID\{CBD4FB70-F00B-4963-B249-4B056E6A981A}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{CBD4FB70-F00B-4963-B249-4B056E6A981A}\TypeLib]
@="{3476FAB2-687F-4EA6-9AC2-88D72DC7D7FC}"

[HKEY_CLASSES_ROOT\CLSID\{CBD4FB70-F00B-4963-B249-4B056E6A981A}\VersionIndependentProgID]
@="GoogleEarth.FeatureGE"


[HKEY_CLASSES_ROOT\CLSID\{D5396561-8356-4253-836C-AAD32CA1DCF9}]
@="WABPimAdaption Class"

[HKEY_CLASSES_ROOT\CLSID\{D5396561-8356-4253-836C-AAD32CA1DCF9}\InprocServer32]
@="C:\\Program Files\\Sony Ericsson\\Mobile\\Sync Station\\WABPim.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{D5396561-8356-4253-836C-AAD32CA1DCF9}\ProgID]
@="WABPim.WABPimAdaption.SEMC.1"

[HKEY_CLASSES_ROOT\CLSID\{D5396561-8356-4253-836C-AAD32CA1DCF9}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{D5396561-8356-4253-836C-AAD32CA1DCF9}\TypeLib]
@="{E2092540-2B9C-47CD-AE7F-546CE05C26B3}"

[HKEY_CLASSES_ROOT\CLSID\{D5396561-8356-4253-836C-AAD32CA1DCF9}\VersionIndependentProgID]
@="WABPim.WABPimAdaption.SEMC"


[HKEY_CLASSES_ROOT\CLSID\{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}]
@="ViewExtentsGE Class"
"AppID"="{46A99B9C-4AC8-4EE9-AF7D-D02816CEC314}"

[HKEY_CLASSES_ROOT\CLSID\{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}\LocalServer32]
@="C:\\Program Files\\Google\\Google Earth\\googleearth.exe"

[HKEY_CLASSES_ROOT\CLSID\{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}\ProgID]
@="GoogleEarth.ViewExtentsGE.1"

[HKEY_CLASSES_ROOT\CLSID\{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}\TypeLib]
@="{3476FAB2-687F-4EA6-9AC2-88D72DC7D7FC}"

[HKEY_CLASSES_ROOT\CLSID\{D93BF052-FC68-4DB6-A4F8-A4DC9BEEB1C0}\VersionIndependentProgID]
@="GoogleEarth.ViewExtentsGE"


[HKEY_CLASSES_ROOT\CLSID\{ED8525EA-2BFC-4440-BD8A-20EFB9D5E541}]
@="HbtMain"

[HKEY_CLASSES_ROOT\CLSID\{ED8525EA-2BFC-4440-BD8A-20EFB9D5E541}\InprocServer32]
@="C:\\Program Files\\HbTools\\Bin\\4.8.2.0\\HbtHostIE.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{ED8525EA-2BFC-4440-BD8A-20EFB9D5E541}\ProgID]
@="HbtTools.HbMain.1"

[HKEY_CLASSES_ROOT\CLSID\{ED8525EA-2BFC-4440-BD8A-20EFB9D5E541}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{ED8525EA-2BFC-4440-BD8A-20EFB9D5E541}\TypeLib]
@="{45397063-D7D0-47C2-9508-26487608A298}"

[HKEY_CLASSES_ROOT\CLSID\{ED8525EA-2BFC-4440-BD8A-20EFB9D5E541}\VersionIndependentProgID]
@="HbtTools.HbMain"


[HKEY_CLASSES_ROOT\Applications\draw7019.exe\shell\open]

[HKEY_CLASSES_ROOT\Applications\draw7019.exe\shell\open\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\draw7019.exe \"%1\""


[HKEY_CLASSES_ROOT\Applications\draw7019.exe\shell\print]

[HKEY_CLASSES_ROOT\Applications\draw7019.exe\shell\print\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\draw7019.exe /p \"%1\""


[HKEY_CLASSES_ROOT\Applications\draw7019.exe\shell\printto]

[HKEY_CLASSES_ROOT\Applications\draw7019.exe\shell\printto\command]
@="C:\\PROGRA~1\\MICROA~1\\FAIRE-~1\\draw7019.exe /pt \"%1\" \"%2\" \"%3\" \"%4\""


[HKEY_CLASSES_ROOT\Applications\RealPlay.exe\shell\open]

[HKEY_CLASSES_ROOT\Applications\RealPlay.exe\shell\open\command]
@="\"C:\\Program Files\\Real\\RealPlayer\\realplay.exe\" \"%1\""


[HKEY_CLASSES_ROOT\Applications\WinISO.exe\shell\open]

[HKEY_CLASSES_ROOT\Applications\WinISO.exe\shell\open\command]
@="\"C:\\Program Files\\WinISO\\WinISO.exe\" \"%1\""


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\AngelsvsDevils.exe]
"Path"="C:\\WINDOWS\\"
@="C:\\WINDOWS\\AngelsvsDevils.exe"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe]
@="C:\\WINDOWS\\System32\\cmmgr32.exe"
"Path"="C:\\WINDOWS\\System32"
"CmstpExtensionDll"="C:\\WINDOWS\\System32\\cmcfg32.dll"
"CMInternalVersion"="1.2"
"CmNative"=dword:00000001


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\DevDetect.exe]
@="C:\\Program Files\\Fichiers communs\\ACD Systems\\EN\\DevDetect.exe"
"Path"=""


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\HijackThis.exe]
@="C:\\Documents and Settings\\elodie\\Mes documents\\elodie.zitte\\hijackthis.exe"
"Path"="C:\\Documents and Settings\\elodie\\Mes documents\\elodie.zitte"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\HydraVision]
"Path"="C:\\Program Files\\ATI Technologies\\ATI HydraVision"
@="C:\\Program Files\\ATI Technologies\\ATI HydraVision\\HydraVision"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\IMxBackUP.exe]
@="C:\\Program Files\\PIXELA\\ImageMixer\\IMxBackUP.exe"
"Path"="C:\\Program Files\\PIXELA\\ImageMixer"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\optproxy.exe]
"Path"="C:\\Program Files\\Securitoo\\Controle Parental"
@="C:\\Program Files\\Securitoo\\Controle Parental\\optproxy.exe"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\QuickCam.exe]
@="C:\\Program Files\\Logitech\\Video\\QuickCam.exe"
"Path"="C:\\Program Files\\Logitech\\Video"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\setup.exe]
"RunAsOnNonAdminInstall"=dword:00000001
"BlockOnTSNonInstallMode"=dword:00000001
"Path"="C:\\Program Files\\ATI Technologies\\ATI Control Panel"
@="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\setup.exe"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
"nwindcs9.hlp"="C:\\Program Files\\Microsoft Office\\Office\\Samples\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
"nwindcs9.cnt"="C:\\Program Files\\Microsoft Office\\Office\\Samples\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
"nwind9.hlp"="C:\\Program Files\\Microsoft Office\\Office\\Samples\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
"nwind9.cnt"="C:\\Program Files\\Microsoft Office\\Office\\Samples\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Help]
"nmplace.hlp"="C:\\Program Files\\Microsoft Office\\Office\\1036\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help]
"AM_LHA.chm"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help]
"PX_Prints_Gifts.chm"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help]
"msjro.chm"="C:\\Program Files\\Fichiers communs\\System\\Ado\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help]
"dao360.chm"="C:\\Program Files\\Fichiers communs\\Microsoft Shared\\DAO\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help]
"jetsql40.chm"="C:\\Program Files\\Microsoft Office\\Office\\1036\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help]
"jetdef40.chm"="C:\\Program Files\\Microsoft Office\\Office\\1036\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\HTML Help]
"artgalry.chm"="C:\\Program Files\\Microsoft Office\\Office\\1036\\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\WinSxS\\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\WinSxS\\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\WINDOWS\\winsxs\\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\\"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\HbToolsOutlookTools]
"DisplayName"="Hotbar Outlook Tools"
"DisplayIcon"="C:\\Program Files\\HbTools\\Bin\\HbtUninst.exe"
"UninstallString"="\"C:\\Program Files\\HbTools\\Bin\\HbtUninst.exe\" Outlook"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\HbToolsWebTools]
"DisplayName"="Hotbar Browser, Weather and Wowpapers Tools"
"DisplayIcon"="C:\\Program Files\\HbTools\\Bin\\HbtUninst.exe"
"UninstallString"="\"C:\\Program Files\\HbTools\\Bin\\HbtUninst.exe\" Web"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis]
"DisplayName"="HijackThis 1.99.1"
"UninstallString"="C:\\DOCUME~1\\elodie\\Bureau\\scanner.exe\\HijackThis.exe /uninstall"
"DisplayIcon"="C:\\DOCUME~1\\elodie\\Bureau\\scanner.exe\\HijackThis.exe"
"DisplayVersion"="1.99.1"
"Publisher"="Soeperman Enterprises Ltd."
"URLInfoAbout"="http://www.spywareinfo.com/~merijn/"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ad-aware 6 Personal]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,90,1c,00,00,00,00,00,ae,55,14,\
f3,0b,d1,c5,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4c,00,61,00,76,00,61,\
00,73,00,6f,00,66,00,74,00,5c,00,41,00,64,00,2d,00,61,00,77,00,61,00,72,00,\
65,00,20,00,36,00,5c,00,41,00,64,00,2d,00,61,00,77,00,61,00,72,00,65,00,2e,\
00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\InstallShield_{54C0D94A-F467-4ABC-9D02-6E58748668D4}]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,10,17,02,00,00,00,00,7e,13,31,\
d7,9a,c6,c6,01,0d,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,69,00,54,00,75,00,6e,\
00,65,00,73,00,5c,00,69,00,54,00,75,00,6e,00,65,00,73,00,2e,00,65,00,78,00,\
65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,40,77,04,00,00,00,00,4c,c1,ae,\
ae,97,c6,c6,01,07,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,51,00,75,00,69,00,63,\
00,6b,00,54,00,69,00,6d,00,65,00,5c,00,71,00,74,00,74,00,61,00,73,00,6b,00,\
2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Instant Access]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,00,e0,14,00,00,00,00,00,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\QuickTime]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,60,2b,00,00,00,00,00,2c,b0,65,\
e4,9a,21,c6,01,05,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,51,00,75,00,69,00,63,\
00,6b,00,54,00,69,00,6d,00,65,00,5c,00,71,00,74,00,74,00,61,00,73,00,6b,00,\
2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Swarm]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,80,70,04,00,00,00,00,d2,c1,29,\
b3,4a,a4,c6,01,06,00,00,00,43,00,3a,00,5c,00,47,00,61,00,6d,00,65,00,73,00,\
5c,00,53,00,77,00,61,00,72,00,6d,00,5c,00,53,00,77,00,61,00,72,00,6d,00,2e,\
00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\TipTop Deluxe 1.1]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,40,3c,00,00,00,00,00,c0,ab,2a,\
ee,7b,82,c6,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,50,00,6f,00,70,00,43,\
00,61,00,70,00,20,00,47,00,61,00,6d,00,65,00,73,00,5c,00,54,00,69,00,70,00,\
54,00,6f,00,70,00,20,00,44,00,65,00,6c,00,75,00,78,00,65,00,5c,00,54,00,69,\
00,70,00,54,00,6f,00,70,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WebMediaPlayer]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,40,14,00,00,00,00,00,56,b0,e2,\
90,17,50,c7,01,00,00,00,00,44,00,3a,00,5c,00,57,00,65,00,62,00,4d,00,65,00,\
64,00,69,00,61,00,50,00,6c,00,61,00,79,00,65,00,72,00,5c,00,57,00,65,00,62,\
00,4d,00,65,00,64,00,69,00,61,00,50,00,6c,00,61,00,79,00,65,00,72,00,2e,00,\
65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinISO_is1]
"SlowInfoCache"=hex:28
26 Février 2007 19:25:06

attend je crois que c'est celui là :

---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 18:29:11 26/02/2007

+ Résultat de l'analyse:



C:\Program Files\HbTools\bin\4.7.7.0\HbtAds.dll -> Adware.HotBar : Ignoré.
C:\Program Files\HbTools\bin\4.7.7.0\HbtCoreSrv.dll -> Adware.HotBar : Ignoré.
C:\Program Files\HbTools\bin\4.7.7.0\HbtHostOE.dll -> Adware.Hotbar : Ignoré.
C:\Program Files\HbTools\bin\4.7.7.0\HbtInstIE.dll -> Adware.HotBar : Ignoré.
C:\Program Files\HbTools\bin\4.7.7.0\HbtToolbar.dll -> Adware.HotBar : Ignoré.
C:\Program Files\HbTools\bin\4.7.7.0\HbtWallpaper.dll -> Adware.HotBar : Ignoré.
C:\Program Files\HbTools\bin\4.8.2.0\HbtCoreSrv.dll -> Adware.HotBar : Ignoré.
C:\Program Files\HbTools\bin\4.8.2.0\HbtGuard.exe -> Adware.HotBar : Ignoré.
C:\Program Files\HbTools\bin\4.8.2.0\HbtHostOL.dll -> Adware.HotBar : Ignoré.
C:\Program Files\HbTools\bin\4.8.2.0\HbtSrv.exe -> Adware.HotBar : Ignoré.
C:\Program Files\Hotbar -> Adware.HotBar : Ignoré.
C:\WINDOWS\Downloaded Program Files\HbInstIE.dll -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\AppID\WeatherOnTray.EXE -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbCoreSrv.DynamicProp -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbCoreSrv.DynamicProp.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbCoreSrv.DynamicProp\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbCoreSrv.DynamicProp\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbTools.HbtTravelCompareBar -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbTools.HbtTravelCompareBar.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbTools.HbtTravelCompareBar\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbTools.HbtTravelCompareBar\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtCoreSrv.HbtCoreServices -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtCoreSrv.HbtCoreServices.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtCoreSrv.HbtCoreServices\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtCoreSrv.HbtCoreServices\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtCoreSrv.LfgAx -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtCoreSrv.LfgAx.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtCoreSrv.LfgAx\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtCoreSrv.LfgAx\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostIE.Bho -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostIE.Bho.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostIE.Bho\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostIE.Bho\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostOL.HbtMailAnim -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostOL.HbtMailAnim.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostOL.HbtMailAnim\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostOL.HbtMailAnim\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostOL.HbtWebmailSend -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostOL.HbtWebmailSend.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostOL.HbtWebmailSend\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtHostOL.HbtWebmailSend\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtToolbar.HbtHtmlMenuUI -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtToolbar.HbtHtmlMenuUI.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtToolbar.HbtHtmlMenuUI\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtToolbar.HbtHtmlMenuUI\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtToolbar.HbtToolbarCtl -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtToolbar.HbtToolbarCtl.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtToolbar.HbtToolbarCtl\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtToolbar.HbtToolbarCtl\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtTools.HbMain -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtTools.HbMain.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtTools.HbMain\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\HbtTools.HbMain\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\Wallpaper.WallpaperManager -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\Wallpaper.WallpaperManager.1 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\Wallpaper.WallpaperManager\CLSID -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\Classes\Wallpaper.WallpaperManager\CurVer -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HbTools -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HbTools\Install -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HbTools\MachineInfo -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HbTools\Mail -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HbTools\PI -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HbTools\PI\3.2 -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HbTools\Updates -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HbTools\Upgrade -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HostOI -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HostOI\Mail -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HostOI\Updates -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HostOI\options -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HostOL -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HostOL\Mail -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\HostOL\Updates -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\Hotbar -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\Hotbar\Install -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\Install -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\Install\CmpMap -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\Install\Icons -> Adware.HotBar : Ignoré.
HKLM\SOFTWARE\HbTools\Install\Links -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Common -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Common\Time -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Common\Updates -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\EUI -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\HtmlPPP -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\ImagesHistory -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Install -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Local -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\MachineInfo -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\PI -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\PI\3.2 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\keren -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\nobbar -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\salespartion -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg860 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg861 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg887 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg888 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg889 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg910 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg914 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg915 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg940 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg941 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg942 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg943 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg946 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg947 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg948 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg955 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg956 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Sample\Hist\sg957 -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\UserInfo -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\Weather -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\dynamic -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\links -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\mail -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\options -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HbTools\updates -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HostOI -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HostOI\Updates -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\HostOI\links -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time\HostIE -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time\HostIE\Updates -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time\HostOE -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time\HostOE\Updates -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time\HostOI -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time\HostOI\Updates -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time\HostOL -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\Time\HostOL\Updates -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\hostol -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\hostol\Mail -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\hostol\Updates -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\hostol\links -> Adware.HotBar : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\HbTools\hostol\soho -> Adware.HotBar : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\U00066A36.exe -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\416_button_1b_def.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\416_button_1b_def.pinkcorners.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\416_button_1b_over.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\416_button_1b_over.pinkcorners.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\416_button_8b_def.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\416_button_8b_over.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\417_button_1b_def.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\417_button_1b_over.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\417_button_8b_def.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\417_button_8b_over.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\FindIt.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\FindItHot.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\Highlight.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\HighlightHot.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\PopupBlocker.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\PopupBlockerHot.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\blocker.cur -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\brand.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\findithotxp.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\finditxp.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\highlighthotxp.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\highlightxp.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\logo.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\logoxp.bmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\popupblockerhotxp.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\buttons\popupblockerxp.png -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\contexts -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\contexts\error.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\contexts\related.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\All Users\Application Data\Starware\contexts\travel.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\BrowserSearch -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ErrorSearch -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Layouts -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Manager -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\PopupBlocker -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Recipes -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Recipes\RecipesOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Recipes\RecipesOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Reference -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Reference\ReferenceOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Reference\ReferenceOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\SearchMatch -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\SearchMatch\searchMatchPages -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Tem118.tmp -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Toolbar -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ToolbarLogo -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ToolbarSearch -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Ignoré.
C:\Documents and Settings\elodie\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Ignoré.
C:\Program Files\Starware -> Adware.Starware : Ignoré.
C:\Program Files\Starware\StarwareConfig.xml -> Adware.Starware : Ignoré.
C:\Program Files\Starware\StarwareUninstall.exe -> Adware.Starware : Ignoré.
C:\Program Files\Starware\bin -> Adware.Starware : Ignoré.
C:\Program Files\Starware\bin\Starware.dll -> Adware.Starware : Ignoré.
C:\Program Files\Starware\brand.bmp -> Adware.Starware : Ignoré.
C:\Program Files\Starware\icons -> Adware.Starware : Ignoré.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Starware -> Adware.Starware : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\Starware -> Adware.Starware : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\Starware\Options -> Adware.Starware : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\Starware\OriginalAutoSearch -> Adware.Starware : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\Starware\OriginalSearchAssistant -> Adware.Starware : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\Starware\OriginalURLSearchHooks -> Adware.Starware : Ignoré.
HKU\S-1-5-21-746137067-1284227242-682003330-1003\Software\Starware\SearchAssistant -> Adware.Starware : Ignoré.
HKLM\SOFTWARE\SystemDoctor 2006 Free -> Adware.Systemdoctor : Ignoré.
C:\Program Files\Fichiers communs\DriveCleaner Free\udcsdr.exe -> Adware.WinFixer : Ignoré.
C:\WINDOWS\Downloaded Program Files\USDR6V_0001_D18M3107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Ignoré.
C:\WINDOWS\Downloaded Program Files\UDC6V_0001_D19M0709NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : Ignoré.


Fin du rapport

26 Février 2007 19:30:19

et puis voilà le nouveaux rapport HijackThis/

Logfile of HijackThis v1.99.1
Scan saved at 19:29:50, on 26/02/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Documents and Settings\elodie\Mes documents\elodie.zitte\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?product=ssearch&src_id... (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Starware - {F7C7AA47-BCA6-451D-8DBC-C10A8F75C8C7} - C:\Program Files\Starware\bin\Starware.dll
O3 - Toolbar: Starware - {9839B3B7-3F99-4498-884D-6CFCCD251AB1} - C:\Program Files\Starware\bin\Starware.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [CursorXP] C:\themeGold55\CursorXP\CursorXP.exe -s
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?a44db9d7804f4ac0a2bbd744420aaa44
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?a44db9d7804f4ac0a2bbd744420aaa44
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr
O16 - DPF: Interface Chat Wanadoo - http://chat4.x-echo.com/version8/Applet/wchatsign.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.drivecleaner.com/installdrivecleanerstart_fr...
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab312...
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2508b8c209c524056218/netzip...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photos.orange.fr/al/presentation/pc/resources/ac...
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.hotbar.com/installs/hbtools/programs/hb...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDown...
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game10.zylom.servicesalacarte.orange.fr/activex/...
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://player.virtools.com/downloads/player/Install2.5/...
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://wanadoofr.oberon-media.com/online2/diner_dash/Di...
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9336BF6-47C2-4468-BC4A-CC99640D6A51}: NameServer = 80.10.246.130 80.10.246.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Securitoo Control Parental (OPTENET_FILTER) - Securitoo - C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe

28 Février 2007 13:39:24

UP
Alors es-ce que le sujet et réapparut ?
Tom's guide dans le monde
  • Allemagne
  • Italie
  • Irlande
  • Royaume Uni
  • Etats Unis
Suivre Tom's Guide
Inscrivez-vous à la Newsletter
  • ajouter à twitter
  • ajouter à facebook
  • ajouter un flux RSS