Votre question

Plain de pub qui s'ouvre SERWAB ? Comment s en débarrasser merci

Tags :
  • comment retirer
  • Sécurité
Dernière réponse : dans Sécurité et virus
26 Novembre 2006 18:40:39

Plein de fenêtre de Pub qui s ouvre au milieu de l'écran, souvent les mêmes MEETIC par exemple, j ai essayé de lire et de faire ce qui etait conseillé sur ce forum mais pas tout compris il y a des reste du Virus - Si qqun sait aussi comment retirer les centaines de msg VIAGRA que je reçoit sur ma massegerie wanadoo - Merci d avance pour mon sauveur

Autres pages sur : plain pub ouvre serwab debarrasser merci

a b 8 Sécurité
26 Novembre 2006 18:52:51

Bonjour,

- Télécharge Hijackthis de Merjin.
- Dézippe le dans un dossier ou sur ton bureau.
-- Clique Droit sur Hijackthis.exe :
-> Choisis "Renommer"
-> Tape Scanner.exe puis valide.

- Lance l'application
- Choisis l'option "Do a system scan and save a logfile"
-- Le Bloc-Notes s'ouvre :
-> Edition / Sélectionner Tout
-> Edition / Copier
- Colle le rapport ici.

AIDE : Aide sur Hijackthis (Malekal)

26 Novembre 2006 18:57:51

Logfile of HijackThis v1.99.1
Scan saved at 18:57:28, on 26/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\stephane dufour\Bureau\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Workflow] E:\install\Workflow.exe
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LiesBone] C:\DOCUME~1\STEPHA~1\APPLIC~1\WARNMI~1\SUPPORTTRUST.exe
O4 - Global Startup: Docteur Club Internet.lnk = C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Pinnacle Scheduler.lnk = ?
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Cont...
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://labo.nomatica.com/downloads/ImageUploader3.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

Contenus similaires
a b 8 Sécurité
26 Novembre 2006 19:04:21

Re,

Télécharge Lopxp.zip
Dézippe le sur le Bureau
Lance le fichier lopxp.bat
Un rapport sera généré, poste son contenu ici.
26 Novembre 2006 19:07:32

Rapport fait à 19:06:28.87 le 26/11/2006

Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D8E2-0891

R‚pertoire de C:\Documents and Settings\All Users\Application Data

23/06/2004 19:03 <REP> MSN Messenger 6.2.0137
11/08/2003 19:06 <REP> MSN6
11/08/2003 17:37 <REP> Symantec
11/08/2003 08:33 <REP> CyberLink
08/08/2003 21:47 <REP> QuickTime
05/08/2003 21:25 62 desktop.ini
05/08/2003 21:25 <REP> Microsoft
05/08/2003 21:25 <REP> .
05/08/2003 21:25 <REP> ..
1 fichier(s) 62 octets
8 R‚p(s) 19983159296 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D8E2-0891

R‚pertoire de C:\Documents and Settings\All Users.WINDOWS\Application Data

03/11/2006 15:43 3120 118300.34
28/10/2006 04:19 <REP> BasePlanAxisSpam
30/06/2006 01:53 <REP> Windows Genuine Advantage
28/05/2006 19:43 <REP> MotiveSysIDs
24/05/2006 18:05 <REP> Motive
05/01/2006 21:00 <REP> Adobe
09/10/2005 19:51 <REP> MSN6
14/07/2005 17:10 <REP> Micro Application
16/06/2005 19:54 <REP> CyberLink
19/12/2004 14:19 <REP> SBT
19/12/2004 10:50 <REP> Symantec
19/12/2004 00:55 62 desktop.ini
19/12/2004 00:55 <REP> Microsoft
19/12/2004 00:55 <REP> .
19/12/2004 00:55 <REP> ..
2 fichier(s) 3182 octets
13 R‚p(s) 19983155200 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D8E2-0891

R‚pertoire de C:\Documents and Settings\Default User\Application Data

05/08/2003 21:25 62 desktop.ini
05/08/2003 21:25 <REP> ..
05/08/2003 21:25 <REP> Microsoft
05/08/2003 21:25 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 19983155200 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D8E2-0891

R‚pertoire de C:\Documents and Settings\Default User.WINDOWS\Application Data

19/12/2004 00:55 62 desktop.ini
19/12/2004 00:55 <REP> ..
19/12/2004 00:55 <REP> Microsoft
19/12/2004 00:55 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 19983155200 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D8E2-0891

R‚pertoire de C:\Documents and Settings\pc\Application Data

23/06/2004 18:37 <REP> Sun
16/01/2004 20:58 <REP> Macromedia
24/11/2003 11:03 <REP> Kazaa Lite
24/10/2003 20:30 0 dm.ini
29/09/2003 06:19 <REP> Ahead
27/08/2003 22:49 <REP> Microsoft Web Folders
11/08/2003 19:55 <REP> Help
11/08/2003 19:06 <REP> MSN6
11/08/2003 17:38 <REP> Symantec
08/08/2003 21:35 <REP> Adobe
08/08/2003 21:35 <REP> InterTrust
05/08/2003 20:38 <REP> Identities
05/08/2003 20:38 62 desktop.ini
05/08/2003 20:38 <REP> Microsoft
05/08/2003 20:38 <REP> .
05/08/2003 20:38 <REP> ..
2 fichier(s) 62 octets
14 R‚p(s) 19983155200 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D8E2-0891

R‚pertoire de C:\Documents and Settings\stephane dufour\Application Data

28/10/2006 04:19 <REP> warnmixfork
28/10/2006 04:19 <REP> NetPumper
28/08/2006 19:39 <REP> EoRezo
19/08/2006 09:12 <REP> Mp3tag
03/07/2006 18:21 <REP> Help
31/10/2005 20:28 <REP> SlySoft
09/10/2005 19:51 <REP> MSN6
30/07/2005 14:17 <REP> InterTrust
14/07/2005 17:10 <REP> Micro Application
16/06/2005 20:04 <REP> Cyberlink
21/05/2005 00:01 <REP> Sun
08/05/2005 13:44 <REP> Azureus
09/01/2005 19:32 <REP> Real
05/01/2005 20:14 <REP> AdobeUM
05/01/2005 20:04 <REP> Adobe
05/01/2005 20:04 0 dm.ini
05/01/2005 20:04 1749 AdobeDLM.log
24/12/2004 09:10 <REP> Ahead
22/12/2004 08:28 <REP> Macromedia
19/12/2004 14:33 <REP> NeroVision
19/12/2004 14:15 <REP> Microsoft Web Folders
19/12/2004 10:50 <REP> Symantec
19/12/2004 01:21 <REP> Identities
19/12/2004 01:21 62 desktop.ini
19/12/2004 01:21 <REP> Microsoft
19/12/2004 01:21 <REP> .
19/12/2004 01:21 <REP> ..
3 fichier(s) 1811 octets
24 R‚p(s) 19983151104 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks

Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est D8E2-0891

R‚pertoire de C:\WINDOWS\Tasks

28/10/2006 04:19 296 AD22F40591A166D9.job
19/12/2004 01:05 6 SA.DAT
19/12/2004 01:03 65 desktop.ini
05/08/2003 20:30 <REP> ..
05/08/2003 20:30 <REP> .
3 fichier(s) 367 octets
2 R‚p(s) 19ÿ983ÿ151ÿ104 octets libres

******************************************
Recherche dans Program files

Le dossier C:\Program Files\C2Media n'existe pas

*************** Fin du rapport ****************


merci angeldark
a b 8 Sécurité
26 Novembre 2006 19:11:38

Les manipulations sont à faire sans interruption et dans l'ordre
Si tu ne comprends pas quelque chose, demande des explications avant de commencer.


Enregistre cette page pour avoir accès à la procédure en mode sans échec :
- Fichier
- Enregistrer Sous...
- Nom du fichier : Procédure
- Type : Page Web, complète
- Pour l'emplacement, chosis ton Bureau
- Clique maintenant sur Enregistrer

Télécharge:

Ccleaner
Installe le dans un répertoire dédié.
Lors de l'installation décoche: "Ajouter la Barre d'Outils Yahoo! Ccleaner"
AIDE : Tuto de Ccleaner

Clean.zip (de Malekal),
décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.

Redémarre en mode sans échec

Ferme TOUTES les fenêtres ouvertes (sauf Hijackthis)
et les logiciels de protection en temps réel (Antivirus, TeaTimer...)

- Lance Hijackthis ->Do a system scan only
->Coche les lignes ci-dessous :

O4 - HKCU\..\Run: [LiesBone] C:\DOCUME~1\STEPHA~1\APPLIC~1\WARNMI~1\SUPPORTTRUST.exe
O4 - Global Startup: Pinnacle Scheduler.lnk = ?

Clique sur Fix checked (en bas à gauche)

- Assure toi d'avoir accès aux dossiers/fichiers cachés
-> Démarrer
-> Panneau de configuration
-> Options des Dossiers, onglet Affichage :
. Clique sur Afficher les dossiers cachés
. Décoche Masquer les extensions des fichiers dont le type est connu
. Décoche Masquer les fichiers protégés du système d'exploitation


- Suppime ces fichiers et/ou dossiers s'ils existent encore :

C:\Documents and Settings\stephane dufour\Application Data\Warnmixfork\<- le dossier
C:\WINDOWS\Tasks\AD22F40591A166D9.job

-- Lance Ccleaner :
- Clique sur le bouton "Analyse"
- Clique maintenant sur le bouton "Lancer le Néttoyage".

- Clique sur l'onglet "Erreurs"
- Clique successivement sur "Chercher des erreurs" puis sur "Réparer les erreurs sélectionnées".

- Ouvre le dossier clean qui se trouve sur ton bureau, et double-clique sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laisse la ouverte.

Redémarre normalement.

- Poste un nouveau rapport Hijackthis.

- Le rapport clean : Poste de travail / double clic sur disque C / double-clic sur rapport_clean.txt et copier/coller le contenu ici C:\rapport_clean.txt

NB : Merci à Malekal pour ses tutos.
26 Novembre 2006 19:20:45

comment fait on pour redemarrer en mode sans echec
a b 8 Sécurité
26 Novembre 2006 19:21:26

Clique sur "Redémarre en mode sans échec"
26 Novembre 2006 19:25:08

C est là le probleme, je sais pas où c est et comment on y va sur ce clic - Merci
26 Novembre 2006 20:25:05

Un peu long désolé pas l habitude :

Logfile of HijackThis v1.99.1
Scan saved at 20:19:09, on 26/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\stephane dufour\Bureau\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Workflow] E:\install\Workflow.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Cont...
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://labo.nomatica.com/downloads/ImageUploader3.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

Pour clean.cmd : ca n a rien fait

Windows Registry Editor Version 5.00


[HKEY_CLASSES_ROOT\Acronis.PrivexShellExt]
@="CPrivexShellExt Object"

[HKEY_CLASSES_ROOT\Acronis.PrivexShellExt\CLSID]
@="{60CE0473-50F7-417B-A10F-6921827B9CA8}"

[HKEY_CLASSES_ROOT\Acronis.PrivexShellExt\CurVer]
@="Acronis.PrivexShellExt.1"


[HKEY_CLASSES_ROOT\Acronis.PrivexShellExt.1]
@="CPrivexShellExt Object"

[HKEY_CLASSES_ROOT\Acronis.PrivexShellExt.1\CLSID]
@="{60CE0473-50F7-417B-A10F-6921827B9CA8}"


[HKEY_CLASSES_ROOT\AU_ISC]
@="AU ISC Server Application"

[HKEY_CLASSES_ROOT\AU_ISC\CLSID]
@="{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}"

[HKEY_CLASSES_ROOT\AU_ISC\CurVer]
@="AU_ISC.1"


[HKEY_CLASSES_ROOT\AU_ISC.1]
@="AU ISC Server Application"

[HKEY_CLASSES_ROOT\AU_ISC.1\CLSID]
@="{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}"


[HKEY_CLASSES_ROOT\CDDBControl.CDDBControl2]
@="CDDBControl2 Class"

[HKEY_CLASSES_ROOT\CDDBControl.CDDBControl2\CLSID]
@="{69E9B473-22E6-471D-8683-84BD1E4BECE1}"


[HKEY_CLASSES_ROOT\CDDBControl.CDDBControl2.1]
@="CDDBControl2 Class"

[HKEY_CLASSES_ROOT\CDDBControl.CDDBControl2.1\CLSID]
@="{69E9B473-22E6-471D-8683-84BD1E4BECE1}"


[HKEY_CLASSES_ROOT\CDDBControlWinamp.CddbDisc]
@="CddbDisc Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp.CddbDisc\CLSID]
@="{c2e21ac1-675c-4cae-ba0c-98d25a5e5b84}"

[HKEY_CLASSES_ROOT\CDDBControlWinamp.CddbDisc\CurVer]
@="CDDBControlWinamp5.CddbDisc.1"


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCacheManager]
@="CddbCacheManager Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCacheManager\CLSID]
@="{efe52f1e-1427-4ce9-acfe-0e050e498e63}"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCacheManager\CurVer]
@="CDDBControlWinamp5.CddbCacheManager.1"


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCacheManager.1]
@="CddbCacheManager Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCacheManager.1\CLSID]
@="{efe52f1e-1427-4ce9-acfe-0e050e498e63}"


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCredit]
@="CddbCredit Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCredit\CLSID]
@="{bfe639ee-762e-46c4-ae7c-3c34ccc317ff}"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCredit\CurVer]
@="CDDBControlWinamp5.CddbCredit.1"


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCredit.1]
@="CddbCredit Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbCredit.1\CLSID]
@="{bfe639ee-762e-46c4-ae7c-3c34ccc317ff}"


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbDisc.1]
@="CddbDisc Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbDisc.1\CLSID]
@="{c2e21ac1-675c-4cae-ba0c-98d25a5e5b84}"


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbFullName.1]
@="CddbFullName Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CddbFullName.1\CLSID]
@="{f1110c60-736a-4d58-8e2a-4935dfcf9ac7}"


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CDDBWinamp5Control]
@="CDDBWinamp5Control Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CDDBWinamp5Control\CLSID]
@="{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CDDBWinamp5Control\CurVer]
@="CDDBControlWinamp5.CDDBWinamp5Control.1"


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CDDBWinamp5Control.1]
@="CDDBWinamp5Control Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CDDBWinamp5Control.1\CLSID]
@="{f2e9891e-0ce2-40bc-a6df-ed87c817b83d}"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.CDDBWinamp5Control.1\Insertable]


[HKEY_CLASSES_ROOT\CDDBControlWinamp5.FullName]
@="CddbFullName Class"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.FullName\CLSID]
@="{f1110c60-736a-4d58-8e2a-4935dfcf9ac7}"

[HKEY_CLASSES_ROOT\CDDBControlWinamp5.FullName\CurVer]
@="CDDBControlWinamp5.CddbFullName.1"


[HKEY_CLASSES_ROOT\CDDBUIControlWinamp5.CddbWinamp5UI]
@="CddbWinamp5UI Class"

[HKEY_CLASSES_ROOT\CDDBUIControlWinamp5.CddbWinamp5UI\CLSID]
@="{0dabacb1-1a16-4082-a610-3d0b3a2a94fc}"

[HKEY_CLASSES_ROOT\CDDBUIControlWinamp5.CddbWinamp5UI\CurVer]
@="CDDBUIControlWinamp5.CddbWinamp5UI.1"


[HKEY_CLASSES_ROOT\CDDBUIControlWinamp5.CddbWinamp5UI.1]
@="CddbWinamp5UI Class"

[HKEY_CLASSES_ROOT\CDDBUIControlWinamp5.CddbWinamp5UI.1\CLSID]
@="{0dabacb1-1a16-4082-a610-3d0b3a2a94fc}"


[HKEY_CLASSES_ROOT\ChilkatXml.ChilkatXml]
@="ChilkatXml Class"

[HKEY_CLASSES_ROOT\ChilkatXml.ChilkatXml\CLSID]
@="{CE2E4226-494A-4DB2-9B45-7C8586CC01A3}"

[HKEY_CLASSES_ROOT\ChilkatXml.ChilkatXml\CurVer]
@="ChilkatXml.ChilkatXml.1"


[HKEY_CLASSES_ROOT\ChilkatXml.ChilkatXml.1]
@="ChilkatXml Class"

[HKEY_CLASSES_ROOT\ChilkatXml.ChilkatXml.1\CLSID]
@="{CE2E4226-494A-4DB2-9B45-7C8586CC01A3}"


[HKEY_CLASSES_ROOT\ChilkatXml.XmlFactory]
@="XmlFactory Class"

[HKEY_CLASSES_ROOT\ChilkatXml.XmlFactory\CLSID]
@="{7FAB24D9-F81A-49A3-A0E9-A3198DEDF454}"

[HKEY_CLASSES_ROOT\ChilkatXml.XmlFactory\CurVer]
@="ChilkatXml.XmlFactory.1"


[HKEY_CLASSES_ROOT\ChilkatXml.XmlFactory.1]
@="XmlFactory Class"

[HKEY_CLASSES_ROOT\ChilkatXml.XmlFactory.1\CLSID]
@="{7FAB24D9-F81A-49A3-A0E9-A3198DEDF454}"

[HKEY_CLASSES_ROOT\ChilkatXml.XmlFactory.1\Insertable]


[HKEY_CLASSES_ROOT\Connection Manager Profile]
@="Connection Manager Profile"

[HKEY_CLASSES_ROOT\Connection Manager Profile\shell]


[HKEY_CLASSES_ROOT\hex_auto_file]
@=""

[HKEY_CLASSES_ROOT\hex_auto_file\shell]


[HKEY_CLASSES_ROOT\IncrediAnimation.AnimationPlayer]
@="AnimationPlayer Class"

[HKEY_CLASSES_ROOT\IncrediAnimation.AnimationPlayer\CLSID]
@="{B5534644-E461-11D3-BBB2-0050DA276194}"

[HKEY_CLASSES_ROOT\IncrediAnimation.AnimationPlayer\CurVer]
@="IncrediAnimation.AnimationPlayer.1"


[HKEY_CLASSES_ROOT\IncrediAnimation.AnimationPlayer.1]
@="AnimationPlayer Class"

[HKEY_CLASSES_ROOT\IncrediAnimation.AnimationPlayer.1\CLSID]
@="{B5534644-E461-11D3-BBB2-0050DA276194}"


[HKEY_CLASSES_ROOT\IncrediApp.ImTray]
@="ImTray Class"

[HKEY_CLASSES_ROOT\IncrediApp.ImTray\CLSID]
@="{F2F6A7B0-0E74-49BF-ABDF-8A0778554472}"

[HKEY_CLASSES_ROOT\IncrediApp.ImTray\CurVer]
@="IncrediApp.ImTray.1"


[HKEY_CLASSES_ROOT\IncrediApp.ImTray.1]
@="ImTray Class"

[HKEY_CLASSES_ROOT\IncrediApp.ImTray.1\CLSID]
@="{F2F6A7B0-0E74-49BF-ABDF-8A0778554472}"


[HKEY_CLASSES_ROOT\IncrediComUtils.AppSync]
@="AppSync Class"

[HKEY_CLASSES_ROOT\IncrediComUtils.AppSync\CLSID]
@="{A7256361-EC20-4E5B-B824-A692515700BD}"

[HKEY_CLASSES_ROOT\IncrediComUtils.AppSync\CurVer]
@="IncrediComUtils.AppSync.1"


[HKEY_CLASSES_ROOT\IncrediComUtils.AppSync.1]
@="AppSync Class"

[HKEY_CLASSES_ROOT\IncrediComUtils.AppSync.1\CLSID]
@="{A7256361-EC20-4E5B-B824-A692515700BD}"


[HKEY_CLASSES_ROOT\IncrediComUtils.ComFactory]
@="ComFactory Class"

[HKEY_CLASSES_ROOT\IncrediComUtils.ComFactory\CLSID]
@="{EEBF0065-B9C2-44ef-9E34-0E51BE01937F}"

[HKEY_CLASSES_ROOT\IncrediComUtils.ComFactory\CurVer]
@="IncrediComUtils.ComFactory.1"


[HKEY_CLASSES_ROOT\IncrediComUtils.ComFactory.1]
@="ComFactory Class"

[HKEY_CLASSES_ROOT\IncrediComUtils.ComFactory.1\CLSID]
@="{EEBF0065-B9C2-44ef-9E34-0E51BE01937F}"


[HKEY_CLASSES_ROOT\IncrediComUtils.Connection]
@="Connection Class"

[HKEY_CLASSES_ROOT\IncrediComUtils.Connection\CLSID]
@="{77969C47-EBE5-486F-8730-F48B84284D88}"

[HKEY_CLASSES_ROOT\IncrediComUtils.Connection\CurVer]
@="IncrediComUtils.Connection.1"


[HKEY_CLASSES_ROOT\IncrediComUtils.Connection.1]
@="Connection Class"

[HKEY_CLASSES_ROOT\IncrediComUtils.Connection.1\CLSID]
@="{77969C47-EBE5-486F-8730-F48B84284D88}"


[HKEY_CLASSES_ROOT\IncrediComUtils.XmlParser]
@="XmlParser Class"

[HKEY_CLASSES_ROOT\IncrediComUtils.XmlParser\CLSID]
@="{6D587C7F-27A0-4416-A90D-FB337F9B406C}"

[HKEY_CLASSES_ROOT\IncrediComUtils.XmlParser\CurVer]
@="IncrediComUtils.XmlParser.1"


[HKEY_CLASSES_ROOT\IncrediComUtils.XmlParser.1]
@="XmlParser Class"

[HKEY_CLASSES_ROOT\IncrediComUtils.XmlParser.1\CLSID]
@="{6D587C7F-27A0-4416-A90D-FB337F9B406C}"


[HKEY_CLASSES_ROOT\IncrediFeatures.CommonSettings]
@="CommonSettings Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.CommonSettings\CLSID]
@="{CBF9925D-3C19-4F33-9DE4-446978645EBB}"

[HKEY_CLASSES_ROOT\IncrediFeatures.CommonSettings\CurVer]
@="IncrediFeatures.CommonSettings.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.CommonSettings.1]
@="CommonSettings Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.CommonSettings.1\CLSID]
@="{CBF9925D-3C19-4F33-9DE4-446978645EBB}"


[HKEY_CLASSES_ROOT\IncrediFeatures.EmoticonCenter]
@="EmoticonCenter Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.EmoticonCenter\CLSID]
@="{D0B6B45D-7BAF-4993-8EC2-F165BA440CD4}"

[HKEY_CLASSES_ROOT\IncrediFeatures.EmoticonCenter\CurVer]
@="IncrediFeatures.EmoticonCenter.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.EmoticonCenter.1]
@="EmoticonCenter Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.EmoticonCenter.1\CLSID]
@="{D0B6B45D-7BAF-4993-8EC2-F165BA440CD4}"


[HKEY_CLASSES_ROOT\IncrediFeatures.IMMessage]
@="IMMessage Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.IMMessage\CLSID]
@="{07D03588-7B5E-11D5-8784-0050DA2761C4}"

[HKEY_CLASSES_ROOT\IncrediFeatures.IMMessage\CurVer]
@="IncrediFeatures.IMMessage.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.IMMessage.1]
@="IMMessage Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.IMMessage.1\CLSID]
@="{07D03588-7B5E-11D5-8784-0050DA2761C4}"


[HKEY_CLASSES_ROOT\IncrediFeatures.LicenceManager]
@="LicenceManager Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.LicenceManager\CLSID]
@="{5862A1C2-7676-45AA-8C7D-2F803754D007}"

[HKEY_CLASSES_ROOT\IncrediFeatures.LicenceManager\CurVer]
@="IncrediFeatures.LicenceManager.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.LicenceManager.1]
@="LicenceManager Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.LicenceManager.1\CLSID]
@="{5862A1C2-7676-45AA-8C7D-2F803754D007}"


[HKEY_CLASSES_ROOT\IncrediFeatures.MultiSignature]
@="MultiSignature Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.MultiSignature\CLSID]
@="{328CC455-1F5E-4F1A-A6B7-A888AA9C0289}"

[HKEY_CLASSES_ROOT\IncrediFeatures.MultiSignature\CurVer]
@="IncrediFeatures.MultiSignature.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.MultiSignature.1]
@="MultiSignature Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.MultiSignature.1\CLSID]
@="{328CC455-1F5E-4F1A-A6B7-A888AA9C0289}"


[HKEY_CLASSES_ROOT\IncrediFeatures.ProfileManager]
@="ProfileManager Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.ProfileManager\CLSID]
@="{96D04D6A-7B1E-48A9-BEA6-99F9FE8341C7}"

[HKEY_CLASSES_ROOT\IncrediFeatures.ProfileManager\CurVer]
@="IncrediFeatures.ProfileManager.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.ProfileManager.1]
@="ProfileManager Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.ProfileManager.1\CLSID]
@="{96D04D6A-7B1E-48A9-BEA6-99F9FE8341C7}"


[HKEY_CLASSES_ROOT\IncrediFeatures.Signature]
@="Signature Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.Signature\CLSID]
@="{DA12A268-0ACB-11D4-859D-0050DA2761C4}"

[HKEY_CLASSES_ROOT\IncrediFeatures.Signature\CurVer]
@="IncrediFeatures.Signature.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.Signature.1]
@="Signature Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.Signature.1\CLSID]
@="{DA12A268-0ACB-11D4-859D-0050DA2761C4}"


[HKEY_CLASSES_ROOT\IncrediFeatures.Sound]
@="Sound Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.Sound\CLSID]
@="{0710C793-2117-11D5-B75D-005004C0C6BA}"

[HKEY_CLASSES_ROOT\IncrediFeatures.Sound\CurVer]
@="IncrediFeatures.Sound.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.Sound.1]
@="Sound Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.Sound.1\CLSID]
@="{0710C793-2117-11D5-B75D-005004C0C6BA}"


[HKEY_CLASSES_ROOT\IncrediFeatures.Spelling]
@="Spelling Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.Spelling\CLSID]
@="{84566316-EC70-11D5-881D-0050DA2761C4}"

[HKEY_CLASSES_ROOT\IncrediFeatures.Spelling\CurVer]
@="IncrediFeatures.Spelling.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.Spelling.1]
@="Spelling Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.Spelling.1\CLSID]
@="{84566316-EC70-11D5-881D-0050DA2761C4}"


[HKEY_CLASSES_ROOT\IncrediFeatures.StyleBox]
@="StyleBox Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.StyleBox\CLSID]
@="{C7681ACB-27AD-4025-8F53-643549159658}"

[HKEY_CLASSES_ROOT\IncrediFeatures.StyleBox\CurVer]
@="IncrediFeatures.StyleBox.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.StyleBox.1]
@="StyleBox Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.StyleBox.1\CLSID]
@="{C7681ACB-27AD-4025-8F53-643549159658}"


[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageTAF]
@="TypeMessageTAF Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageTAF\CLSID]
@="{FEBD6230-F4F6-4E79-89CD-4BEBDC4A96AE}"

[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageTAF\CurVer]
@="IncrediFeatures.TypeMessageTAF.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageTAF.1]
@="TypeMessageTAF Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageTAF.1\CLSID]
@="{FEBD6230-F4F6-4E79-89CD-4BEBDC4A96AE}"


[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageVIP]
@="TypeMessageVIP Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageVIP\CLSID]
@="{47B10849-77FA-463b-8973-10241FF9DB37}"

[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageVIP\CurVer]
@="IncrediFeatures.TypeMessageVIP.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageVIP.1]
@="TypeMessageVIP Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.TypeMessageVIP.1\CLSID]
@="{47B10849-77FA-463b-8973-10241FF9DB37}"


[HKEY_CLASSES_ROOT\IncrediFeatures.WebViewer]
@="WebViewer Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.WebViewer\CLSID]
@="{4EAA7268-FC1E-47C6-87EF-8915475CBC88}"

[HKEY_CLASSES_ROOT\IncrediFeatures.WebViewer\CurVer]
@="IncrediFeatures.WebViewer.1"


[HKEY_CLASSES_ROOT\IncrediFeatures.WebViewer.1]
@="WebViewer Class"

[HKEY_CLASSES_ROOT\IncrediFeatures.WebViewer.1\CLSID]
@="{4EAA7268-FC1E-47C6-87EF-8915475CBC88}"


[HKEY_CLASSES_ROOT\IncrediMail.Kernel]
@="Kernel Class"

[HKEY_CLASSES_ROOT\IncrediMail.Kernel\CLSID]
@="{E9BC70A8-D70C-11D3-BBAE-0050DA276194}"

[HKEY_CLASSES_ROOT\IncrediMail.Kernel\CurVer]
@="IncrediMail.Kernel.1"


[HKEY_CLASSES_ROOT\IncrediMail.Kernel.1]
@="Kernel Class"

[HKEY_CLASSES_ROOT\IncrediMail.Kernel.1\CLSID]
@="{E9BC70A8-D70C-11D3-BBAE-0050DA276194}"


[HKEY_CLASSES_ROOT\IncrediMessage]
@="IncrediMail Internet Mail Message"

[HKEY_CLASSES_ROOT\IncrediMessage\shell]


[HKEY_CLASSES_ROOT\IncrediNotifier.CoNotifierPlayer]
@="CoNotifierPlayer Class"

[HKEY_CLASSES_ROOT\IncrediNotifier.CoNotifierPlayer\CLSID]
@="{181C43E6-AF9E-46EA-A51E-2D63B975A15D}"

[HKEY_CLASSES_ROOT\IncrediNotifier.CoNotifierPlayer\CurVer]
@="IncrediNotifier.CoNotifierPlayer.1"


[HKEY_CLASSES_ROOT\IncrediNotifier.CoNotifierPlayer.1]
@="CoNotifierPlayer Class"

[HKEY_CLASSES_ROOT\IncrediNotifier.CoNotifierPlayer.1\CLSID]
@="{181C43E6-AF9E-46EA-A51E-2D63B975A15D}"


[HKEY_CLASSES_ROOT\IncrediNotifier.Notifier]
@="Notifier Class"

[HKEY_CLASSES_ROOT\IncrediNotifier.Notifier\CLSID]
@="{80BCA063-A0D1-4F29-888C-6B67C392F5DA}"

[HKEY_CLASSES_ROOT\IncrediNotifier.Notifier\CurVer]
@="IncrediNotifier.Notifier.1"


[HKEY_CLASSES_ROOT\IncrediNotifier.Notifier.1]
@="Notifier Class"

[HKEY_CLASSES_ROOT\IncrediNotifier.Notifier.1\CLSID]
@="{80BCA063-A0D1-4F29-888C-6B67C392F5DA}"


[HKEY_CLASSES_ROOT\IncrediNotify.NotifierManager]
@="NotifierManager Class"

[HKEY_CLASSES_ROOT\IncrediNotify.NotifierManager\CLSID]
@="{B385A628-C100-11D3-BB95-0050DA276194}"

[HKEY_CLASSES_ROOT\IncrediNotify.NotifierManager\CurVer]
@="IncrediNotify.NotifierManager.1"


[HKEY_CLASSES_ROOT\IncrediNotify.NotifierManager.1]
@="NotifierManager Class"

[HKEY_CLASSES_ROOT\IncrediNotify.NotifierManager.1\CLSID]
@="{B385A628-C100-11D3-BB95-0050DA276194}"


[HKEY_CLASSES_ROOT\IncrediService.RegInfo]
@="RegInfo Class"

[HKEY_CLASSES_ROOT\IncrediService.RegInfo\CLSID]
@="{F648D80F-2409-4EDA-847D-8E820B03451F}"

[HKEY_CLASSES_ROOT\IncrediService.RegInfo\CurVer]
@="IncrediService.RegInfo.1"


[HKEY_CLASSES_ROOT\IncrediService.RegInfo.1]
@="RegInfo Class"

[HKEY_CLASSES_ROOT\IncrediService.RegInfo.1\CLSID]
@="{F648D80F-2409-4EDA-847D-8E820B03451F}"


[HKEY_CLASSES_ROOT\IncrediService.Registration]
@="Registration Class"

[HKEY_CLASSES_ROOT\IncrediService.Registration\CLSID]
@="{C0CF353A-F029-11D3-857F-005004BE235E}"

[HKEY_CLASSES_ROOT\IncrediService.Registration\CurVer]
@="IncrediService.Registration.1"


[HKEY_CLASSES_ROOT\IncrediService.Registration.1]
@="Registration Class"

[HKEY_CLASSES_ROOT\IncrediService.Registration.1\CLSID]
@="{C0CF353A-F029-11D3-857F-005004BE235E}"


[HKEY_CLASSES_ROOT\IncrediService.Service]
@="Service Class"

[HKEY_CLASSES_ROOT\IncrediService.Service\CLSID]
@="{55B613D4-E613-11D3-857A-005004BE235E}"

[HKEY_CLASSES_ROOT\IncrediService.Service\CurVer]
@="IncrediService.Service.1"


[HKEY_CLASSES_ROOT\IncrediService.Service.1]
@="Service Class"

[HKEY_CLASSES_ROOT\IncrediService.Service.1\CLSID]
@="{55B613D4-E613-11D3-857A-005004BE235E}"


[HKEY_CLASSES_ROOT\IncrediShellExt.IMMenuShellExt]
@="IMMenuShellExt Class"

[HKEY_CLASSES_ROOT\IncrediShellExt.IMMenuShellExt\CLSID]
@="{F8984111-38B6-11D5-8725-0050DA2761C4}"

[HKEY_CLASSES_ROOT\IncrediShellExt.IMMenuShellExt\CurVer]
@="IncrediShellExt.IMMenuShellExt.1"


[HKEY_CLASSES_ROOT\IncrediShellExt.IMMenuShellExt.1]
@="IMMenuShellExt Class"

[HKEY_CLASSES_ROOT\IncrediShellExt.IMMenuShellExt.1\CLSID]
@="{F8984111-38B6-11D5-8725-0050DA2761C4}"


[HKEY_CLASSES_ROOT\IncrediTools.ContentPlugProtocol]
@="ContentPlugProtocol Class"

[HKEY_CLASSES_ROOT\IncrediTools.ContentPlugProtocol\CLSID]
@="{8BACC255-A3CF-4e27-BAF1-D531B1AE02FD}"

[HKEY_CLASSES_ROOT\IncrediTools.ContentPlugProtocol\CurVer]
@="IncrediTools.ContentPlugProtocol.1"


[HKEY_CLASSES_ROOT\IncrediTools.ContentPlugProtocol.1]
@="ContentPlugProtocol Class"

[HKEY_CLASSES_ROOT\IncrediTools.ContentPlugProtocol.1\CLSID]
@="{8BACC255-A3CF-4e27-BAF1-D531B1AE02FD}"


[HKEY_CLASSES_ROOT\IncrediTools.Magic]
@="Magic Class"

[HKEY_CLASSES_ROOT\IncrediTools.Magic\CLSID]
@="{B84092B9-8658-11D5-8793-0050DA2761C4}"

[HKEY_CLASSES_ROOT\IncrediTools.Magic\CurVer]
@="IncrediTools.Magic.1"


[HKEY_CLASSES_ROOT\IncrediTools.Magic.1]
@="Magic Class"

[HKEY_CLASSES_ROOT\IncrediTools.Magic.1\CLSID]
@="{B84092B9-8658-11D5-8793-0050DA2761C4}"


[HKEY_CLASSES_ROOT\IncrediTools.SoundManager]
@="SoundManager Class"

[HKEY_CLASSES_ROOT\IncrediTools.SoundManager\CLSID]
@="{0B9A0840-1EC3-11D5-B75C-005004C0C6BA}"

[HKEY_CLASSES_ROOT\IncrediTools.SoundManager\CurVer]
@="IncrediTools.SoundManager.1"


[HKEY_CLASSES_ROOT\IncrediTools.SoundManager.1]
@="SoundManager Class"

[HKEY_CLASSES_ROOT\IncrediTools.SoundManager.1\CLSID]
@="{0B9A0840-1EC3-11D5-B75C-005004C0C6BA}"


[HKEY_CLASSES_ROOT\IncrediTools.ThumbnailCreator]
@="ThumbnailCreator Class"

[HKEY_CLASSES_ROOT\IncrediTools.ThumbnailCreator\CLSID]
@="{140BBD3E-C68E-4077-B7EC-D4DC46242EF5}"

[HKEY_CLASSES_ROOT\IncrediTools.ThumbnailCreator\CurVer]
@="IncrediTools.ThumbnailCreator.1"


[HKEY_CLASSES_ROOT\IncrediTools.ThumbnailCreator.1]
@="ThumbnailCreator Class"

[HKEY_CLASSES_ROOT\IncrediTools.ThumbnailCreator.1\CLSID]
@="{140BBD3E-C68E-4077-B7EC-D4DC46242EF5}"


[HKEY_CLASSES_ROOT\Messenger.MessengerApp]
@="Messenger Application"

[HKEY_CLASSES_ROOT\Messenger.MessengerApp\CLSID]
@="{FB7199AB-79BF-11d2-8D94-0000F875C541}"

[HKEY_CLASSES_ROOT\Messenger.MessengerApp\CurVer]
@="Messenger.MessengerApp.1"


[HKEY_CLASSES_ROOT\Messenger.MessengerApp.1]
@="Messenger Application"

[HKEY_CLASSES_ROOT\Messenger.MessengerApp.1\CLSID]
@="{FB7199AB-79BF-11d2-8D94-0000F875C541}"


[HKEY_CLASSES_ROOT\Messenger.MsgrSessionManager]
@="Messenger MsgrSession Manager"

[HKEY_CLASSES_ROOT\Messenger.MsgrSessionManager\CLSID]
@="{E3A3B1D9-5675-43c0-BF04-37BE11939FB7}"

[HKEY_CLASSES_ROOT\Messenger.MsgrSessionManager\CurVer]
@="Messenger.MsgrSessionManager.1"


[HKEY_CLASSES_ROOT\Messenger.MsgrSessionManager.1]
@="Messenger.MsgrSessionManager"

[HKEY_CLASSES_ROOT\Messenger.MsgrSessionManager.1\CLSID]
@="{E3A3B1D9-5675-43c0-BF04-37BE11939FB7}"


[HKEY_CLASSES_ROOT\Messenger.UIAutomation]
@="Messenger Object"

[HKEY_CLASSES_ROOT\Messenger.UIAutomation\CLSID]
@="{B69003B3-C55E-4b48-836C-BC5946FC3B28}"

[HKEY_CLASSES_ROOT\Messenger.UIAutomation\CurVer]
@="Messenger.UIAutomation.1"


[HKEY_CLASSES_ROOT\Messenger.UIAutomation.1]
@="Messenger.UIAutomation"

[HKEY_CLASSES_ROOT\Messenger.UIAutomation.1\CLSID]
@="{B69003B3-C55E-4b48-836C-BC5946FC3B28}"


[HKEY_CLASSES_ROOT\MessengerPrivate.MessengerPriv]
@="Messenger Private Object"

[HKEY_CLASSES_ROOT\MessengerPrivate.MessengerPriv\CLSID]
@="{AB1D8565-40E9-4616-984D-98465687E82C}"

[HKEY_CLASSES_ROOT\MessengerPrivate.MessengerPriv\CurVer]
@="MessengerPrivate.MessengerPriv.1"


[HKEY_CLASSES_ROOT\MessengerPrivate.MessengerPriv.1]
@="MessengerPrivate.MessengerPriv"

[HKEY_CLASSES_ROOT\MessengerPrivate.MessengerPriv.1\CLSID]
@="{AB1D8565-40E9-4616-984D-98465687E82C}"


[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin]
@="ActiveXPlugin Object"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\CLSID]
@="{06DD38D3-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\CurVer]
@="Microsoft.ActiveXPlugin.1"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\NotInsertable]


[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1]
@="ActiveXPlugin Object"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1\CLSID]
@="{06DD38D3-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1\NotInsertable]


[HKEY_CLASSES_ROOT\Motive.MCCAddon]
@="MCCAddonObj Class"

[HKEY_CLASSES_ROOT\Motive.MCCAddon\CLSID]
@="{D49547E8-E9C5-4a15-A719-FF88ED9B86F1}"

[HKEY_CLASSES_ROOT\Motive.MCCAddon\CurVer]
@="Motive.MCCAddon.1"


[HKEY_CLASSES_ROOT\Motive.MCCAddon.1]
@="MCCAddonObj Class"

[HKEY_CLASSES_ROOT\Motive.MCCAddon.1\CLSID]
@="{D49547E8-E9C5-4a15-A719-FF88ED9B86F1}"


[HKEY_CLASSES_ROOT\ppifile]
@="Fichier de configuration du Passeport Microsoft"

[HKEY_CLASSES_ROOT\ppifile\shell]


[HKEY_CLASSES_ROOT\SpyDoctor.EMClient]
@="EMClient SD Object"

[HKEY_CLASSES_ROOT\SpyDoctor.EMClient\Clsid]
@="{C7976BEB-AB1E-46F7-8CCD-D4C9CD83BF49}"


[HKEY_CLASSES_ROOT\Applications\RealPlay.exe]
@=""

[HKEY_CLASSES_ROOT\Applications\RealPlay.exe\DefaultIcon]
@="C:\\Program Files\\Real\\RealPlayer\\realplay.exe,0"

[HKEY_CLASSES_ROOT\Applications\RealPlay.exe\shell]

[HKEY_CLASSES_ROOT\Applications\RealPlay.exe\SupportedTypes]
@=""
".mp3"=""
".m3u"=""
".cda"=""
".wav"=""
".mpg"=""
".mpeg"=""
".mpv"=""
".mps"=""
".m2v"=""
".m1v"=""
".mpe"=""
".mpa"=""
".avi"=""
".mp4"=""
".m4e"=""
".rt"=""
".rnx"=""
".rmp"=""
".rms"=""
".rjs"=""
".ra"=""
".rax"=""
".rm"=""
".rmvb"=""
".rp"=""
".ram"=""
".rmm"=""
".rsml"=""
".rv"=""
".rvx"=""
".rmj"=""
".rjt"=""
".rmx"=""
".wma"=""
".wmv"=""
".wax"=""
".asx"=""
".asf"=""
".wm"=""
".wmx"=""
".wvx"=""
".mov"=""
".qt"=""
".aac"=""
".m4a"=""
".m4p"=""
".mp2"=""
".mp1"=""
".mpga"=""
".pls"=""
".xpl"=""
".smi"=""
".smil"=""
".ssm"=""
".sdp"=""
".au"=""
".aif"=""
".aiff"=""
".mid"=""
".midi"=""
".rmi"=""
".acp"=""
".lmsff"=""
".lqt"=""
".lavs"=""
".lar"=""
".la1"=""
".rpl"=""
".3gp"=""
".amr"=""
".awb"=""
".3g2"=""
".rpm"=""


[HKEY_CLASSES_ROOT\Applications\RegCloneDVD.exe]

[HKEY_CLASSES_ROOT\Applications\RegCloneDVD.exe\shell]


[HKEY_CLASSES_ROOT\Applications\rnxproc.exe]

[HKEY_CLASSES_ROOT\Applications\rnxproc.exe\shell]


[HKEY_CLASSES_ROOT\Applications\winzip32.exe]

[HKEY_CLASSES_ROOT\Applications\winzip32.exe\shell]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\HijackThis.exe]
@="C:\\Documents and Settings\\stephane dufour\\Bureau\\hijackthis.exe"
"Path"="C:\\Documents and Settings\\stephane dufour\\Bureau"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\HijackThis]
"DisplayName"="HijackThis 1.99.1"
"UninstallString"="C:\\Documents and Settings\\stephane dufour\\Bureau\\HijackThis.exe /uninstall"
"DisplayIcon"="C:\\Documents and Settings\\stephane dufour\\Bureau\\HijackThis.exe"
"DisplayVersion"="1.99.1"
"Publisher"="Soeperman Enterprises Ltd."
"URLInfoAbout"="http://www.spywareinfo.com/~merijn/"


[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\stephane dufour\\Local Settings\\Temporary Internet Files\\Content.IE5\\BTXLRMGY\\ccsetup135[1].exe"="CCleaner Installer"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\STEPHA~1\\LOCALS~1\\Temp\\YCOMP_~1.EXE"="Yahoo! Toolbar"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\STEPHA~1\\LOCALS~1\\Temp\\Répertoire temporaire 1 pour clean.zip\\clean\\clean.cmd"="clean"

Je sais pas si c ça Ca m a l air tres long comme rapport

Merci



a b 8 Sécurité
26 Novembre 2006 20:27:04

D'autres problèmes ?
26 Novembre 2006 20:32:21

Non à part ma messagerie wanadoo où je reçois plein de msg viagra - Mais là je crois que c parce que j ai trop laissé mon adresse mail trainer - Si je suis debarrasser de SERWAB je tiens à t adresser un très grand merci et la prochaine fois je tacherai de ne pas installer d antivirus gratuit qui cache des virus comme serwab --encore merci
a b 8 Sécurité
26 Novembre 2006 20:42:00

De rien.

Dénonce ton infection (SERWAB) pour faire condamner les auteurs, ça serait sympa.
Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être le plus nombreux possibles, alors rends compte de ton infection.
AIDE : Comment rapporter son infection sur Malware-Complaints ?

Consulte cette page pour éviter que ces problèmes ne réapparaissent pas.
28 Novembre 2006 11:12:11

Salut,

Pourrais t egalement m'aider stp. Je n'en peut plus :

Voici mon rapport:

Logfile of HijackThis v1.99.1
Scan saved at 11:05:56, on 28/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Foxmail\Foxmail.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\M\Bureau\hijack\Scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Foxmail] "C:\Program Files\Foxmail\Foxmail.exe" -min
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://www.flyordie.com/pub/dl/msjavx86.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall...
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst....
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.pixdiscount.fr/clients/ImageUploader3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EAEBD28-5C6A-4BD8-8EF2-D312B22AF42A}: NameServer = 193.252.19.3,192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EAEBD28-5C6A-4BD8-8EF2-D312B22AF42A}: NameServer = 193.252.19.3,192.168.1.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
28 Novembre 2006 11:16:22


Voici mon rapport LOPXP:

Rapport fait à 11:15:01,39 le 28/11/2006

Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est A0A2-927E

R‚pertoire de C:\Documents and Settings\All Users\Application Data

23/11/2006 10:09 <REP> Windows Genuine Advantage
14/10/2006 13:56 <REP> Spybot - Search & Destroy
27/07/2006 09:15 <REP> Apple Computer
02/02/2006 14:47 <REP> DVD Shrink
24/06/2005 10:29 <REP> Ahead
23/06/2005 10:13 <REP> CyberLink
25/05/2005 10:52 <REP> River Past G2
16/02/2005 11:18 <REP> Macrovision
16/02/2005 11:13 <REP> Adobe
07/01/2005 11:06 <REP> QuickTime
16/12/2004 16:50 <REP> Symantec
16/12/2004 15:30 62 desktop.ini
16/12/2004 15:30 <REP> Microsoft
16/12/2004 15:30 <REP> .
16/12/2004 15:30 <REP> ..
1 fichier(s) 62 octets
14 R‚p(s) 15834906624 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est A0A2-927E

R‚pertoire de C:\Documents and Settings\Default User\Application Data

16/12/2004 15:30 62 desktop.ini
16/12/2004 15:30 <REP> ..
16/12/2004 15:30 <REP> Microsoft
16/12/2004 15:30 <REP> .
1 fichier(s) 62 octets
3 R‚p(s) 15834906624 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est A0A2-927E

R‚pertoire de C:\Documents and Settings\M\Application Data

13/09/2006 10:38 <REP> Printer Info Cache
13/09/2006 10:38 <REP> Image Zone Express
07/09/2006 13:00 <REP> MySpace
27/07/2006 09:17 <REP> Apple Computer
16/03/2006 14:56 81920 0000096C_VTS_1.IFO
16/03/2006 14:56 12288 0000096C_VTS_0.IFO
18/11/2005 15:02 <REP> Sun
18/10/2005 14:21 <REP> SendPix
01/10/2005 16:31 <REP> Microgaming
20/09/2005 13:09 <REP> Google
29/07/2005 10:59 <REP> CopyToDvd
27/07/2005 08:55 <REP> Lavasoft
24/06/2005 10:40 <REP> Ahead
23/06/2005 10:58 <REP> CyberLink
25/05/2005 14:51 <REP> PVC
25/05/2005 13:21 <REP> River Past G2
16/02/2005 18:28 <REP> XnView
16/02/2005 14:12 <REP> AdobeAUM
16/02/2005 11:19 <REP> AdobeUM
02/02/2005 15:03 <REP> Corel
12/01/2005 09:42 <REP> Yahoo! Messenger
08/01/2005 14:33 <REP> Real
06/01/2005 13:57 <REP> Leadertech
20/12/2004 17:08 <REP> Help
17/12/2004 10:36 <REP> Visicom Media
17/12/2004 10:34 <REP> Macromedia
16/12/2004 16:50 <REP> Symantec
16/12/2004 16:26 <REP> Adobe
16/12/2004 15:49 <REP> Identities
16/12/2004 15:48 62 desktop.ini
16/12/2004 15:48 <REP> Microsoft
16/12/2004 15:48 <REP> ..
16/12/2004 15:48 <REP> .
3 fichier(s) 94270 octets
30 R‚p(s) 15834906624 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks

Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est A0A2-927E

R‚pertoire de C:\WINDOWS\Tasks

16/12/2004 15:41 6 SA.DAT
16/12/2004 15:39 65 desktop.ini
16/12/2004 15:39 <REP> ..
16/12/2004 15:39 <REP> .
2 fichier(s) 71 octets
2 R‚p(s) 15ÿ834ÿ906ÿ624 octets libres

******************************************
Recherche dans Program files

Le dossier C:\Program Files\C2Media n'existe pas

*************** Fin du rapport ****************
28 Novembre 2006 11:17:38

PAR AVANCE MERCI ENORMEMENT !!!!!!!!!!
a b 8 Sécurité
28 Novembre 2006 17:41:17

Crée ton propre sujet stp.
Tom's guide dans le monde
  • Allemagne
  • Italie
  • Irlande
  • Royaume Uni
  • Etats Unis
Suivre Tom's Guide
Inscrivez-vous à la Newsletter
  • ajouter à twitter
  • ajouter à facebook
  • ajouter un flux RSS