Informatique - Forum informatique - telechargement gratuit

 CONTACT 
Gsiteg(à)gmail.com
Renplacer (à) par @



 FAQFAQ   RechercherRechercher   S'enregistrerS'enregistrer   ProfilProfil   Se connecter pour vérifier ses messages privésSe connecter pour vérifier ses messages privés   ConnexionConnexion 


PC infecté par divers virus (chevaux de troie, adware)
Aller à la page 1, 2  Suivante
 
Poster un nouveau sujet   Répondre au sujet    GsiteG Index du Forum -> Sécurité
Auteur Message
Nicokid



Inscrit le: 18 Jan 2009
Messages: 14

MessagePosté le: Dim Jan 18, 2009 11:32 am    Sujet du message: PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

Bonjour,
Mon Pc est donc infecté par plusieurs virus, dont un adware (Win32 : Adware-Gen) et trois chevaux de troie (Win32 : Fasec et son ami Win32 : Triojan-Gen) et apparemment un autre dont je ne connais pas vraiment la nature : JS : Redirector-B.

J'ai pu mettre les fichier infectés en quarantaine (grâce à Avast) et j'en ai supprimé quelques-uns qui étaient dans mes fichiers temporaires.

J'ai téléchargé HijackThis et je vous donne le rapport :

Logfile of HijackThis v1.99.1
Scan saved at 16:52:14, on 02/01/2009
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Jean\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Wallpaper\Wallpaper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Alwil Software\Avast4\ashChest.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Windows\system32\SearchFilterHost.exe
C:\HIJACKTHIS\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = -://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = -://www.daemon-search.com/default
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = -://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = -://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = -://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = -://ie.redirect.hp.com/...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jean\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Wallpaper] "C:\Program Files\Wallpaper\Wallpaper.exe" Starter
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger avec &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - -s://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - -s://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

Voilà merci de me répondre rapidement si possible car je suis étudiant et en pleine période de partiels alors si mon pc me lache on va me retrouver pendu dans ma chambre !!!
Voir le profil de l'utilisateur Envoyer un message privé
arba
..
..


Inscrit le: 27 Jan 2008
Messages: 864

MessagePosté le: Dim Jan 18, 2009 11:46 am    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

salut

tu as utilisé une version trop ancienne de hijackthis.

Télécharge Hijackthis V 2.02 -://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe
Voir le profil de l'utilisateur Envoyer un message privé
Nicokid



Inscrit le: 18 Jan 2009
Messages: 14

MessagePosté le: Dim Jan 18, 2009 3:34 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

Salut,

Merci de ton aide d'abord. Je ne savais pas que ce n'était pas la dernière version. J'ai installé la nouvelle et voici le nouveau rapport:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:33:02, on 18/01/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Jean\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Wallpaper\Wallpaper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jean\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = -://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = -://www.daemon-search.com/default
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = -://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = -://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = -://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = -://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=73&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jean\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Wallpaper] "C:\Program Files\Wallpaper\Wallpaper.exe" Starter
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger avec &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - -s://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - -s://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - -://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - -://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - -://messenger.zone.msn.com/binary/Chess.cab57176.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 10281 bytes
Voir le profil de l'utilisateur Envoyer un message privé
arba
..
..


Inscrit le: 27 Jan 2008
Messages: 864

MessagePosté le: Dim Jan 18, 2009 3:44 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

1) désactive l'uac : -://www.generation-nt.com/desactiver-user-account-control-windows-vista-beta-2-astuce-24678-1.html

2) Telecharges Toolbar sd sur ton bureau

-://eric.71.mespages.googlepages.com/ToolBarSD.exe

Ferme tous les programmes en cours et desactive Avast

clique droit et exécuter en tant qu'administateur sur toolbarsd

Choisis la langue et valides par " entrée "

Au menu, choisis l'option 1

Poste le rapport généré

Note le rapport se trouve aussi à C:\TB.txt
Voir le profil de l'utilisateur Envoyer un message privé
arba
..
..


Inscrit le: 27 Jan 2008
Messages: 864

MessagePosté le: Dim Jan 18, 2009 3:54 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

peux tu au passage me faire un copier coller du rapport avast ou m'indiquer les éléments que tu as mis en quarantaine s'il te plait.
Voir le profil de l'utilisateur Envoyer un message privé
arba
..
..


Inscrit le: 27 Jan 2008
Messages: 864

MessagePosté le: Dim Jan 18, 2009 4:03 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

ayant des choses a faire je repasserai ce soir ou demain pour t'indiquer la marche à suivre mais sache que mise a part l'adware SaveNow présent dans la barre d'outil Daemon tools ton rapport est propre donc pas trop d'inquiétude!!!

on fera des vérifications d'usage pour voir si tout est bien niquel.

A plus tard Wink
Voir le profil de l'utilisateur Envoyer un message privé
Nicokid



Inscrit le: 18 Jan 2009
Messages: 14

MessagePosté le: Dim Jan 18, 2009 5:07 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

Re bonjour,

Pas de problème c'est déjà très gentil à toi de m'aider. En plus ça fait déjà une bonne semaine que mon PC est infecté alors je me dit que ça peut attendre demain.

Voilà le premier rapport (entre temps j'ai viré Daemon toolbar de mon PC) :



-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz )
BIOS : Ver 1.00PARTTBL
USER : Jean ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090117-0] 4.8.1296 (Not Activated)
C:\ (Local Disk) - NTFS - Total:225 Go (Free:98 Go)
D:\ (Local Disk) - NTFS - Total:7 Go (Free:2 Go)
E:\ (CD or DVD) - UDF - Total:6 Go (Free:0 Go)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 18/01/2009|17:53 )

[ UAC => 1 ]

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="-://www.daemon-search.com/default"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="-://go.microsoft.com/fwlink/?LinkId=54896"
"Url"="-://go.microsoft.com/fwlink/?LinkId=75720"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="-://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=73&bd=Pavilion&pf=laptop"
"Default_Page_URL"="-://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=73&bd=Pavilion&pf=laptop"
"Default_Search_URL"="-://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="-://go.microsoft.com/fwlink/?LinkId=54896"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[ UAC => 1 ]


1 - "C:\ToolBar SD\TB_1.txt" - 18/01/2009|17:17 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 18/01/2009|17:48 - Option : [1]
3 - "C:\ToolBar SD\TB_3.txt" - 18/01/2009|17:52 - Option : [1]
4 - "C:\ToolBar SD\TB_4.txt" - 18/01/2009|17:53 - Option : [1]

-----------\\ Fin du rapport a 17:53:52,44

Je te met la liste des fichiers infectés :

$RW4KNZ0.exe localisé : C:\$RECYCLE.BIN\S-1-5-21-620141055-4067909338-1249092210-1000 => infecté par "Win32:Adware-gen (Adw)

5D.tmp localisé : C:\Windows\Temp infecté par : Win32:Fasec (Trj)

boot.com localisé : C:\resycled infecté par : Win32:Fasec (Trj)

boot.com localisé : D:\resycled infecté par : Win32:Fasec (Trj)

iamfamous.dll localisé : C:\Program Files\Mozilla Firefox\components infecté par : Win32:Trojan-gen (Other)

msqpdxvdmcmtct.dll localisé ici : C:\Windows\System32 infecté par : Win32:Fasec (Trj)
Il me semble que c'est celui ci qui m'embète : j'ai des messages d'avast tout le temps qui me dit que ce fichier est infecté mais bizarement il me semble que je ne peux pas le mettre en quarantaine (je sais c'est bizarre puisqu'il est marqué là...)

tooltip_main(1).htm localisé : C:\Users\Jean\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2RCGR9JZ infecté par : JS:Redirector-B (Trj).

Bon voilà je crois que je t'ai tout dit pour l'instant. J'attends ta réponse.
Merci encore, bonne soirée,

Nicolas.
Voir le profil de l'utilisateur Envoyer un message privé
arba
..
..


Inscrit le: 27 Jan 2008
Messages: 864

MessagePosté le: Dim Jan 18, 2009 8:33 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

1) télécharge et installe ccleaner ici : -://www.filehippo.com/download_ccleaner/

un tutoriel pour son installation : -://www.malekal.com/tutorial_CCleaner.html (merci Malekal).


2) télécharge et installe malwaresbytes antimalware (mbam) ici : -://www.clubic.com/telecharger-fiche215092-malwarebytes-anti-malware.html

faire sa mise a jour.


3) télécharge SDfix : -://downloads.andymanchesta.com/RemovalTools/SDFix.exe


4) redémarre en mode sans echec (tapoter f8 au démarrage, mode sans echec , choisir sa session et pas celle nommée administrateur).


5) double click sur le raccourci ccleaner :

1- Dans l'onglet "Nettoyeur" cliquer sur "Analyse".

2- Une fois l'analyse terminée, cliquer sur "Lancer le Nettoyage".

3- Ensuite, dans l'onglet "Registre" cliquer sur "Chercher des erreurs" puis sur "Réparer les erreurs sélectionnées" et effectuer la sauvegarde du registre qui est proposée.

4- Recommencer jusqu’à ce qu’il ne trouve plus rien.


6) double click sur le raccourci mbam :

faire un scan complet de tous les lecteurs et patienter.

Clique sur le bouton resultats en bas pour afficher les éléments détectés
Les éléments détectés apparaissent sous forme de liste.

Ces derniers sont tous cochés, pour les supprimer, clique sur le bouton supprimer la selection en bas à gauche.

Un rapport va s'afficher ,le sauvegarder sur le bureau.

Mbam peut demander de redémarrer, dans ce cas redémarrer et revenir en mode sans echec.


7) Double-clique sur le fichier SDFix.exe, la décompression du programme va s'effectuer.

Le Bloc-note va s'ouvrir pour signaler que le programme a été décomprésse dans C:\SDFix

Clique sur le menu Démarrer puis executer

Saisis la commande suivante : %systemdrive%\SDfix puis clique sur OK.
Le dossier SDfix s'ouvre... Double-clique sur RunThis.bat (le .bat peut ne pas être présent).

Répondre oui à la question en appuyant sur la touche Y puis appuyer sur la touche entrée du clavier pour valider.

Le menu Démarrer va disparaître.. c'est normal.

SDFix va redémarrer l'ordinateur...
Appuyer sur une touche pour redémarrer l'ordinateur

Une fois l'ordinateur redémarré en mode normal, un rapport s'ouvre et tu dois l'enregistrer sur le bureau.

aprés tout ceci, poste dans ta prochaine réponse les rapport Mbam, SDfix ainsi qu'un nouveau rapport HIjackthis éxécuté en mode normal.
Voir le profil de l'utilisateur Envoyer un message privé
Nicokid



Inscrit le: 18 Jan 2009
Messages: 14

MessagePosté le: Mar Jan 20, 2009 8:08 am    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

Bonjour,

Voici les rapports Ccleaner et Mbam, par contre je n'arrive pas à exécuter SDFix lorsque je suis en mode sans échec : la fenêtre s'ouvre et se referme aussitôt donc le programme ne se lance jamais... Peut-être faut-il que je le désinstalle et que je le réinstalle ?

Rapport Ccleaner :

Windows Registry Editor Version 5.00


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\vsavb7rt.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\system.enterpriseservices.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\mscorrc.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\mscordbi.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\mscorsec.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\system.configuration.install.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\microsoft.vsa.vb.codedomprocessor.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\wminet_utils.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\microsoft.jscript.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\diasymreader.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\iehost.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Windows\\Microsoft.NET\\Framework\\v1.0.3705\\system.data.dll"=dword:00001000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\1036\\GRINTL32.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\1036\\GRLEX.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\GREN50.OLB"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\GRFR50.OLB"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\1036\\VBAOF11.CHM"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\1036\\QRYINT32.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\GRAPH.EXE"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\MSQRY32.EXE"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\DSITF.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\DSSM.EXE"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\MSOSTYLE.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\SAEXT.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\USP10.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\REFEDIT.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Common Files\\PX Storage Engine\\pxwma.dll"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Common Files\\Microsoft Shared\\OFFICE12\\1036\\MSOINTL.DLL"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Microsoft Office\\Office12\\1036\\OFMAIN11.CHM"=dword:00000001

[HKEY_CLASSES_ROOT\.b5t]

[HKEY_CLASSES_ROOT\.b6t]

[HKEY_CLASSES_ROOT\.bwt]

[HKEY_CLASSES_ROOT\.ccd]

[HKEY_CLASSES_ROOT\.cdi]

[HKEY_CLASSES_ROOT\.isz]

[HKEY_CLASSES_ROOT\.nrg]

[HKEY_CLASSES_ROOT\.ogv]

[HKEY_CLASSES_ROOT\.pdi]

[HKEY_CLASSES_ROOT\HPSender.HPSDPError.4=]

[HKEY_CLASSES_ROOT\OISbmpfile]
@=""

[HKEY_CLASSES_ROOT\OISemffile]
@=""

[HKEY_CLASSES_ROOT\OISgiffile]
@=""

[HKEY_CLASSES_ROOT\OISjpegfile]
@=""

[HKEY_CLASSES_ROOT\OISpngfile]
@=""

[HKEY_CLASSES_ROOT\OIStiffile]
@=""

[HKEY_CLASSES_ROOT\OISwmffile]
@=""

[HKEY_CLASSES_ROOT\s]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.)]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.)\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.1-37]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.1-37\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.2\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADM]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADM\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bt!]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bt!\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bt!\OpenWithProgids]
"BitSpirit File"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.com))]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.com))\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CVA]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CVA\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.D]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.D\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.Eng-FxM]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.Eng-FxM\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv\OpenWithProgids]
"mplayerc.flv"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdmov]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdmov\OpenWithProgids]
"mplayerc.hdmov"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iss]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iss\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kc\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\OpenWithProgids]
"mplayerc.m2ts"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mds]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mds\UserChoice]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka\OpenWithProgids]
"mplayerc.mka"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv\OpenWithProgids]
"mplayerc.mkv"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.moXXon]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.moXXon\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.net]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.net\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.O]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.O\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogm\OpenWithProgids]
"mplayerc.ogm"=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OMA]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OMA\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sqm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sqm\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srt]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srt\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sub]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sub\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\OpenWithProgids]
"mplayerc.ts"=hex(0):

[HKEY_CLASSES_ROOT\acrobat\DefaultIcon]
@="C:\\Program Files\\Adobe\\Reader 8.0\\Acrobat\\AcroRd32.exe"

[HKEY_CLASSES_ROOT\Blaze Media Pro Playlist\DefaultIcon]
@="\"C:\\Program Files\\Blaze Media Pro\\BMP.exe\",0"

[HKEY_CLASSES_ROOT\Blaze Media Pro Playlist\shell\open]
@="&Open Blaze Media Pro Playlist"

[HKEY_CLASSES_ROOT\Blaze Media Pro Playlist\shell\open\command]
@="\"C:\\Program Files\\Blaze Media Pro\\BMP.exe\" \"%1\""

[HKEY_CLASSES_ROOT\BMPSkin\DefaultIcon]
@="\"C:\\Program Files\\Blaze Media Pro\\BMP.exe\",0"

[HKEY_CLASSES_ROOT\BMPSkin\shell\open]
@="&Change Blaze Media Pro Skin"

[HKEY_CLASSES_ROOT\BMPSkin\shell\open\command]
@="\"C:\\Program Files\\Blaze Media Pro\\BMP.exe\" \"%1\""

[HKEY_CLASSES_ROOT\CRTXFile\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OART.DLL,-5000"

[HKEY_CLASSES_ROOT\dcsfile\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,11"

[HKEY_CLASSES_ROOT\Directory\shell\OneNote.Open]
@="Ouvrir en tant que bloc-notes dans OneNote"

[HKEY_CLASSES_ROOT\Directory\shell\OneNote.Open\Command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONENOTE.EXE \"%L\""

[HKEY_CLASSES_ROOT\ecsfile\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,10"

[HKEY_CLASSES_ROOT\Excel.AddInMacroEnabled\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\Excel.AddInMacroEnabled\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.AddInMacroEnabled\shell\Open\ddeexec]
@="[open(\"%1\")]"

[HKEY_CLASSES_ROOT\Excel.AddInMacroEnabled\shell\Open\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.AddInMacroEnabled\shell\Open\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.Template\shell\OpenAsReadOnly]
"Extended"=""

[HKEY_CLASSES_ROOT\Excel.Template\shell\OpenAsReadOnly\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /h /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,68,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.Template\shell\OpenAsReadOnly\ddeexec]
@="[open(\"%1\",,,,,,,,,,,,,,1,,1)]"

[HKEY_CLASSES_ROOT\Excel.Template\shell\OpenAsReadOnly\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.Template\shell\OpenAsReadOnly\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.Template\shell\Printto]

[HKEY_CLASSES_ROOT\Excel.Template\shell\Printto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.Template\shell\Printto\ddeexec]
@="[open(\"%1\")][print(1,,,,,,,,,,,2,\"%2\")][close()]"

[HKEY_CLASSES_ROOT\Excel.Template\shell\Printto\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.Template\shell\Printto\ddeexec\ifexec]
@="[open(\"%1\")][print(1,,,,,,,,,,,2,\"%2\")][quit()]"

[HKEY_CLASSES_ROOT\Excel.Template\shell\Printto\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\New]
@="&Nouveau"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\New\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e /n"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,20,00,2f,00,6e,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\New\ddeexec]
@="[new(\"%1\")]"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\New\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\New\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Open]

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Open\ddeexec]
@="[open(\"%1\")]"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Open\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Open\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\OpenAsReadOnly]
"Extended"=""

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\OpenAsReadOnly\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /h /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,68,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\OpenAsReadOnly\ddeexec]
@="[open(\"%1\",,,,,,,,,,,,,,1,,1)]"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\OpenAsReadOnly\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\OpenAsReadOnly\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Print]

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Print\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Print\ddeexec]
@="[open(\"%1\")][print()][close()]"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Print\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Print\ddeexec\ifexec]
@="[open(\"%1\")][print()][quit()]"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Print\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Printto]

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Printto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Printto\ddeexec]
@="[open(\"%1\")][print(1,,,,,,,,,,,2,\"%2\")][close()]"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Printto\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Printto\ddeexec\ifexec]
@="[open(\"%1\")][print(1,,,,,,,,,,,2,\"%2\")][quit()]"

[HKEY_CLASSES_ROOT\Excel.Template.8\shell\Printto\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\New]
@="&Nouveau"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\New\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e /n"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,20,00,2f,00,6e,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\New\ddeexec]
@="[new(\"%1\")]"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\New\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\New\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Open]

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Open\ddeexec]
@="[open(\"%1\")]"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Open\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Open\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\OpenAsReadOnly]
"Extended"=""

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\OpenAsReadOnly\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /h /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,68,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\OpenAsReadOnly\ddeexec]
@="[open(\"%1\",,,,,,,,,,,,,,1,,1)]"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\OpenAsReadOnly\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\OpenAsReadOnly\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Print]

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Print\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Print\ddeexec]
@="[open(\"%1\")][print()][close()]"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Print\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Print\ddeexec\ifexec]
@="[open(\"%1\")][print()][quit()]"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Print\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Printto]

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Printto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE\" /e"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,45,00,58,00,43,00,\
45,00,4c,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,49,00,49,00,3d,00,6c,00,32,00,78,00,61,00,\
54,00,4f,00,35,00,20,00,2f,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Printto\ddeexec]
@="[open(\"%1\")][print(1,,,,,,,,,,,2,\"%2\")][close()]"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Printto\ddeexec\application]
@="Excel"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Printto\ddeexec\ifexec]
@="[open(\"%1\")][print(1,,,,,,,,,,,2,\"%2\")][quit()]"

[HKEY_CLASSES_ROOT\Excel.TemplateMacroEnabled\shell\Printto\ddeexec\topic]
@="system"

[HKEY_CLASSES_ROOT\fcsfile\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,12"

[HKEY_CLASSES_ROOT\GCSXFile\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OART.DLL,-3000"

[HKEY_CLASSES_ROOT\GLOXFile\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OART.DLL,-3000"

[HKEY_CLASSES_ROOT\GQSXFile\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OART.DLL,-3000"

[HKEY_CLASSES_ROOT\ncsfile\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,14"

[HKEY_CLASSES_ROOT\OfficeTheme.12\shell\New]
@="&Nouveau"

[HKEY_CLASSES_ROOT\OfficeTheme.12\shell\New\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE\" /n \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,54,00,\
46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,00,51,\
00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,4f,00,\
35,00,20,00,2f,00,6e,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OfficeTheme.12\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\OfficeTheme.12\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE\" \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,54,00,\
46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,00,51,\
00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,4f,00,\
35,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OfficeTheme.12\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\OfficeTheme.12\shell\Print\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE\" /p \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,54,00,\
46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,00,51,\
00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,4f,00,\
35,00,20,00,2f,00,70,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OfficeTheme.12\shell\Show]
@="A&fficher"

[HKEY_CLASSES_ROOT\OfficeTheme.12\shell\Show\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE\" /s \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,54,00,\
46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,00,51,\
00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,4f,00,\
35,00,20,00,2f,00,73,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OneNote\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONENOTE.EXE,0"

[HKEY_CLASSES_ROOT\OneNote\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\OneNote\shell\Open\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONENOTE.EXE /hyperlink \"%1\""

[HKEY_CLASSES_ROOT\OneNote.Package\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\OneNote.Package\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,65,00,\
4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,\
00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,50,00,\
78,00,61,00,54,00,4f,00,35,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\Edit]
@="&Edition"

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\Edit\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,65,00,\
4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,\
00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,50,00,\
78,00,61,00,54,00,4f,00,35,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\New]
@="&Nouveau"

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\New\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" /new \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,65,00,\
4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,\
00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,50,00,\
78,00,61,00,54,00,4f,00,35,00,20,00,2f,00,6e,00,65,00,77,00,20,00,22,00,25,\
00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,65,00,\
4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,\
00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,50,00,\
78,00,61,00,54,00,4f,00,35,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\OpenAsReadOnly]
@="Open"
"Extended"=""

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\OpenAsReadOnly\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,65,00,\
4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,\
00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,50,00,\
78,00,61,00,54,00,4f,00,35,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\OneNote.Section.1\shell\Print\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" /print \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,65,00,\
4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,\
00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,50,00,\
78,00,61,00,54,00,4f,00,35,00,20,00,2f,00,70,00,72,00,69,00,6e,00,74,00,20,\
00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OneNote.TableOfContents\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\OneNote.TableOfContents\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" /navigate \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,65,00,\
4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,\
00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,50,00,\
78,00,61,00,54,00,4f,00,35,00,20,00,2f,00,6e,00,61,00,76,00,69,00,67,00,61,\
00,74,00,65,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\OneNote.TableOfContents.12\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\OneNote.TableOfContents.12\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE\" /navigate \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,65,00,\
4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,\
00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,50,00,\
78,00,61,00,54,00,4f,00,35,00,20,00,2f,00,6e,00,61,00,76,00,69,00,67,00,61,\
00,74,00,65,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\PowerPoint.Addin.12\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\PowerPoint.Addin.12\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE\" \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,54,00,\
46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,00,51,\
00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,4f,00,\
35,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\New]
@="&Nouveau"

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\New\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE /n \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\Open\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\OpenAsReadOnly]
"Extended"=""
@="Open as Read-Only"

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\OpenAsReadOnly\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE /h \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\Print\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE /p \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\Show]
@="A&fficher"

[HKEY_CLASSES_ROOT\PowerPoint.Slide.12\shell\Show\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE /s \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\New]
@="&Nouveau"

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\New\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE /n \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\Open\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\OpenAsReadOnly]
"Extended"=""
@="Open as Read-Only"

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\OpenAsReadOnly\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE /h \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\Print\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE /p \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\Show]
@="A&fficher"

[HKEY_CLASSES_ROOT\PowerPoint.SlideMacroEnabled.12\shell\Show\command]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE /s \"%1\""

[HKEY_CLASSES_ROOT\PowerPoint.Template.12\shell\Show]
@="A&fficher"

[HKEY_CLASSES_ROOT\PowerPoint.Template.12\shell\Show\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE\" /s \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,54,00,\
46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,00,51,\
00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,4f,00,\
35,00,20,00,2f,00,73,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\PowerPoint.TemplateMacroEnabled.12\shell\Show]
@="A&fficher"

[HKEY_CLASSES_ROOT\PowerPoint.TemplateMacroEnabled.12\shell\Show\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE\" /s \"%1\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,54,00,\
46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,00,51,\
00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,4f,00,\
35,00,20,00,2f,00,73,00,20,00,22,00,25,00,31,00,22,00,00,00,00,00

[HKEY_CLASSES_ROOT\PowerPointViewer.Show.11\DefaultIcon]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe,2"

[HKEY_CLASSES_ROOT\PowerPointViewer.Show.11\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\PowerPointViewer.Show.11\shell\Print\command]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe /p \"%1\""

[HKEY_CLASSES_ROOT\PowerPointViewer.Show.11\shell\Show]
@="&Afficher"

[HKEY_CLASSES_ROOT\PowerPointViewer.Show.11\shell\Show\command]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe \"%1\""

[HKEY_CLASSES_ROOT\PowerPointViewer.SlideShow.11\DefaultIcon]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe,3"

[HKEY_CLASSES_ROOT\PowerPointViewer.SlideShow.11\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\PowerPointViewer.SlideShow.11\shell\Print\command]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe /p \"%1\""

[HKEY_CLASSES_ROOT\PowerPointViewer.SlideShow.11\shell\Show]
@="&Afficher"

[HKEY_CLASSES_ROOT\PowerPointViewer.SlideShow.11\shell\Show\command]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe \"%1\""

[HKEY_CLASSES_ROOT\PowerPointViewer.Template.11\DefaultIcon]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe,4"

[HKEY_CLASSES_ROOT\PowerPointViewer.Template.11\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\PowerPointViewer.Template.11\shell\Print\command]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe /p \"%1\""

[HKEY_CLASSES_ROOT\PowerPointViewer.Template.11\shell\Show]
@="&Afficher"

[HKEY_CLASSES_ROOT\PowerPointViewer.Template.11\shell\Show\command]
@="C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\pptview.exe \"%1\""

[HKEY_CLASSES_ROOT\powerpointxmlfile\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\powerpointxmlfile\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\POWERPNT.EXE\""
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,54,00,\
46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,00,51,\
00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,4f,00,\
35,00,00,00,00,00

[HKEY_CLASSES_ROOT\tcsfile\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,13"

[HKEY_CLASSES_ROOT\urn:content-classes:catalog\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,15"

[HKEY_CLASSES_ROOT\urn:content-classes:catalog-settings\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12471"

[HKEY_CLASSES_ROOT\urn:content-classes:contentclassdef\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-13101"

[HKEY_CLASSES_ROOT\urn:content-classes:exchange55startaddress\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12451"

[HKEY_CLASSES_ROOT\urn:content-classes:exchangestartaddress\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12451"

[HKEY_CLASSES_ROOT\urn:content-classes:filestartaddress\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12453"

[HKEY_CLASSES_ROOT\urn:content-classes:management\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,20"

[HKEY_CLASSES_ROOT\urn:content-classes:notesstartaddress\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12456"

[HKEY_CLASSES_ROOT\urn:content-classes:remoteworkspacestartaddress\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12454"

[HKEY_CLASSES_ROOT\urn:content-classes:webstartaddress\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12450"

[HKEY_CLASSES_ROOT\urn:content-classes:wizard/addcontentclass\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-13100"

[HKEY_CLASSES_ROOT\urn:content-classes:wizard/addsearchcontentlocation\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12461"

[HKEY_CLASSES_ROOT\urn:content-classes:workspace-settings\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12472"

[HKEY_CLASSES_ROOT\urn:content-classes:workspaceconfiguration\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12476"

[HKEY_CLASSES_ROOT\urn:content-classes:workspacestartaddress\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,-12454"

[HKEY_CLASSES_ROOT\VisioViewer.Viewer\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\VVIEWER.DLL,-2"

[HKEY_CLASSES_ROOT\wcsfile\DefaultIcon]
@="C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\pkmres.dll,9"

[HKEY_CLASSES_ROOT\Word.Backup.8\shell\OnenotePrintto]
@="&Imprimer"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.Backup.8\shell\OnenotePrintto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Backup.8\shell\OnenotePrintto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.Backup.8\shell\OnenotePrintto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Backup.8\shell\OnenotePrintto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.Backup.8\shell\OnenotePrintto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Document.12\shell\Edit]
@="&Edition"

[HKEY_CLASSES_ROOT\Word.Document.12\shell\Edit\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Document.12\shell\Edit\ddeexec]
@="[REM _DDE_Direct][FileOpen(\"%1\")]"

[HKEY_CLASSES_ROOT\Word.Document.12\shell\Edit\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Document.12\shell\Edit\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Document.12\shell\OnenotePrintto]
@="&Imprimer"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.Document.12\shell\OnenotePrintto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Document.12\shell\OnenotePrintto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.Document.12\shell\OnenotePrintto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Document.12\shell\OnenotePrintto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.Document.12\shell\OnenotePrintto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Document.8\shell\OnenotePrintto]
@="&Imprimer"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.Document.8\shell\OnenotePrintto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Document.8\shell\OnenotePrintto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.Document.8\shell\OnenotePrintto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Document.8\shell\OnenotePrintto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.Document.8\shell\OnenotePrintto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\Edit]
@="&Edition"

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\Edit\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\Edit\ddeexec]
@="[REM _DDE_Direct][FileOpen(\"%1\")]"

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\Edit\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\Edit\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\OnenotePrintto]
@="&Imprimer"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\OnenotePrintto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\OnenotePrintto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\OnenotePrintto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\OnenotePrintto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.DocumentMacroEnabled.12\shell\OnenotePrintto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.RTF.8\shell\OnenotePrintto]
@="&Imprimer"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.RTF.8\shell\OnenotePrintto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.RTF.8\shell\OnenotePrintto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.RTF.8\shell\OnenotePrintto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.RTF.8\shell\OnenotePrintto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.RTF.8\shell\OnenotePrintto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\New]
@="&Nouveau"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\New\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /f /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,66,00,20,00,2f,00,64,00,64,00,65,\
00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Template.12\shell\New\ddeexec]
@="[REM _DDE_Direct][FileNew(\"%1\")]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\New\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\New\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OnenotePrintto]
@="&Imprimer"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OnenotePrintto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OnenotePrintto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OnenotePrintto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OnenotePrintto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OnenotePrintto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Open]
@="&Ouvrir"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Open\ddeexec]
@="[REM _DDE_Direct][FileOpen(\"%1\")]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Open\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Open\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OpenAsReadOnly]
@="Ouvrir en lecture seule"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OpenAsReadOnly\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /h /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,68,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,\
00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OpenAsReadOnly\ddeexec]
@="[AppShow][REM _DDE_ReadWriteOnSave][FileOpen .Name=\"%1\",.Revert=0]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OpenAsReadOnly\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\OpenAsReadOnly\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Print\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /x /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,78,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,\
00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Print\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][t=IsDocumentDirty()][FilePrint 0][SetDocumentDirty t][DocClose]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Print\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Print\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Print\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Printto]

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Printto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Printto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose 2][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Printto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Printto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.Template.12\shell\Printto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.Template.8\shell\OnenotePrintto]
@="&Imprimer"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.Template.8\shell\OnenotePrintto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.Template.8\shell\OnenotePrintto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.Template.8\shell\OnenotePrintto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.Template.8\shell\OnenotePrintto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.Template.8\shell\OnenotePrintto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\New]
@="&Nouveau"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\New\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /f /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,66,00,20,00,2f,00,64,00,64,00,65,\
00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\New\ddeexec]
@="[REM _DDE_Direct][FileNew(\"%1\")]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\New\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\New\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OnenotePrintto]
@="&Imprimer"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OnenotePrintto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OnenotePrintto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OnenotePrintto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OnenotePrintto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OnenotePrintto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Open]
@="&Ouvrir"
Voir le profil de l'utilisateur Envoyer un message privé
Nicokid



Inscrit le: 18 Jan 2009
Messages: 14

MessagePosté le: Mar Jan 20, 2009 8:17 am    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

Je crois que je n'ai pas pu mettre le rapport Mbam dans la réponse. Peut-être était-ce trop long. J'espère que le rapport Ccleaner est complet.

Malwarebytes' Anti-Malware 1.33
Version de la base de données: 1668
Windows 6.0.6000

20/01/2009 08:46:46
mbam-log-2009-01-20 (08-46-46).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 199555
Temps écoulé: 53 minute(s), 50 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 4
Fichier(s) infecté(s): 6

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\videosoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\videosoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videosoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Program Files\videosoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\videosoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Users\Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\videosoft (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Program Files\videosoft\Uninstall.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\Temp\_avast4_\unp39296294.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Windows\Temp\_avast4_\unp91596767.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\videosoft\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Windows\System32\msqpdxvdmcmtct.dll (Trojan.Agent) -> Delete on reboot.
C:\Windows\System32\drivers\msqpdxbxvfhaex.sys (Trojan.Agent) -> Quarantined and deleted successfully.
Voir le profil de l'utilisateur Envoyer un message privé
Nicokid



Inscrit le: 18 Jan 2009
Messages: 14

MessagePosté le: Mar Jan 20, 2009 8:22 am    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

Bon j'ai vérifié et apparemment le rapport Ccleaner n'était pas complet.
Je te met donc la fin, en espérant ne m'être pas trompé :

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Open\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Open\ddeexec]
@="[REM _DDE_Direct][FileOpen(\"%1\")]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Open\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Open\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OpenAsReadOnly]
@="Ouvrir en lecture seule"
"Extended"=""

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OpenAsReadOnly\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /h /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,68,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,\
00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OpenAsReadOnly\ddeexec]
@="[AppShow][REM _DDE_ReadWriteOnSave][FileOpen .Name=\"%1\",.Revert=0]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OpenAsReadOnly\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\OpenAsReadOnly\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Print]
@="&Imprimer"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Print\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /x /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,78,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,\
00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Print\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][t=IsDocumentDirty()][FilePrint 0][SetDocumentDirty t][DocClose]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Print\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Print\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Print\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Printto]

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Printto\command]
@="\"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE\" /n /dde"
"command"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,52,00,\
44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,54,00,\
4f,00,35,00,20,00,2f,00,6e,00,20,00,2f,00,64,00,64,00,65,00,00,00,00,00

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Printto\ddeexec]
@="[REM _DDE_Minimize][FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][DocClose 2][FilePrintSetup \"\"]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Printto\ddeexec\Application]
@="WinWord"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Printto\ddeexec\ifexec]
@="[FileOpen(\"%1\")][FilePrintSetup \"%2 on p\",.DoNotSetAsSysDefault=1][FilePrint 0][FileExit 2]"

[HKEY_CLASSES_ROOT\Word.TemplateMacroEnabled.12\shell\Printto\ddeexec\Topic]
@="System"

[HKEY_CLASSES_ROOT\CLSID\{00020827-0000-0000-C000-000000000046}]
@="Générateur d'aperçu Microsoft Office Excel"
"DisplayName"="Générateur d'aperçu Microsoft Office Excel"
"DisableLowILProcessIsolation"=dword:00000001

[HKEY_CLASSES_ROOT\CLSID\{00020827-0000-0000-C000-000000000046}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{00020827-0000-0000-C000-000000000046}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\EXCEL.EXE"

[HKEY_CLASSES_ROOT\CLSID\{0009608B-3E4E-4BF4-8C8C-D107F1F7B4CE}]
@="MC Euro Lexical Analyzer"

[HKEY_CLASSES_ROOT\CLSID\{0009608B-3E4E-4BF4-8C8C-D107F1F7B4CE}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MCPS.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{000D0E00-0000-0000-C000-000000001157}]
@="Visio Viewer CAD Drawing"

[HKEY_CLASSES_ROOT\CLSID\{000D0E00-0000-0000-C000-000000001157}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\VVIEWDWG.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{000D0E00-0000-0000-C000-000000001157}\ProgID]
@="Icad.ViewerDrawing"

[HKEY_CLASSES_ROOT\CLSID\{002ABED4-2017-444D-813A-002CC1F8D10B}]
@="MediaCatalogWebDB Provider"

[HKEY_CLASSES_ROOT\CLSID\{002ABED4-2017-444D-813A-002CC1F8D10B}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MSTORDB.EXE"

[HKEY_CLASSES_ROOT\CLSID\{0051FAAD-74C8-4057-8A85-1CFBF9ABB05C}]
@="MC Shared Search Scope"

[HKEY_CLASSES_ROOT\CLSID\{0051FAAD-74C8-4057-8A85-1CFBF9ABB05C}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MCPS.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{00533E77-887C-4742-8885-2720A6E44AB0}]
@="IMCBLOBData Proxy/Stub"

[HKEY_CLASSES_ROOT\CLSID\{00533E77-887C-4742-8885-2720A6E44AB0}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MCPS.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{009B5B61-9EDD-4D87-B6D8-3621F432283A}]
@="MC User Search Scope"

[HKEY_CLASSES_ROOT\CLSID\{009B5B61-9EDD-4D87-B6D8-3621F432283A}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MCPS.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{009E468B-2A34-4B6B-A3D9-F532C074CF80}]
@="MC Office Search Scope"

[HKEY_CLASSES_ROOT\CLSID\{009E468B-2A34-4B6B-A3D9-F532C074CF80}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MCPS.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{00A6A621-72A1-47AF-B86A-9E65C9C72A95}]
@="MediaCatalogDB Provider"

[HKEY_CLASSES_ROOT\CLSID\{00A6A621-72A1-47AF-B86A-9E65C9C72A95}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MSTORDB.EXE"

[HKEY_CLASSES_ROOT\CLSID\{00B90832-DA6C-47D7-9632-8B0727DE0597}]
@="MediaCatalogMergedDB Provider"

[HKEY_CLASSES_ROOT\CLSID\{00B90832-DA6C-47D7-9632-8B0727DE0597}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MSTORDB.EXE"

[HKEY_CLASSES_ROOT\CLSID\{00E6CCA4-6EA1-4859-B118-1A0AA29CA397}]
@="MC Web 12 Search Scope"

[HKEY_CLASSES_ROOT\CLSID\{00E6CCA4-6EA1-4859-B118-1A0AA29CA397}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MCPS.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}]
@="SkinPlasma Object"

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{00F70774-2D88-4627-A971-327E0413271C}]
@="MC Japanese Lexical Analyzer"

[HKEY_CLASSES_ROOT\CLSID\{00F70774-2D88-4627-A971-327E0413271C}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\MCPS.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{021E3A88-0D42-4234-A01D-4968F6D23DF0}]
@="SmartScreenURL Class"

[HKEY_CLASSES_ROOT\CLSID\{021E3A88-0D42-4234-A01D-4968F6D23DF0}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OUTLFLTR.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}]
@="Modèle Microsoft Office PowerPoint 2007"
"IPersistStorageType"=dword:00000002
"MainPartContentType"="application/vnd.openxmlformats-officedocument.presentationml.presentation.main+xml"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\AuxUserType]

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\AuxUserType\2]
@="Diapositive"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\AuxUserType\3]
@="Microsoft Office PowerPoint Slide"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\Conversion]

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\Conversion\Readable]

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\Conversion\Readable\Main]
@="MSPowerPointSho,MSPresentation,PowerPoint.Show.4,PowerPoint.Slide.4,PowerPoint.Show.7,PowerPoint.Slide.7,PowerPoint.Show.8,PowerPoint.Slide.8"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DataFormats]

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DataFormats\DefaultFile]
@="MSPresentation"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DataFormats\GetSet]
@="14,1,61,1"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DataFormats\GetSet\0]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DataFormats\GetSet\1]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DataFormats\GetSet\2]
@="1,1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DataFormats\GetSet\3]
@="NoteshNote,-1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DataFormats\GetSet\4]
@="Rich Text Format,1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DefaultExtension]
@=".sldx, Microsoft Office PowerPoint Slide (.sldx)"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\DefaultIcon]
@="\"C:\\PROGRA~1\\MICROS~4\\OFFICE11\\POWERPNT.EXE\",11"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\Insertable]

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,\
54,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,\
4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\ProgID]
@="PowerPoint.Template.12"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\Verb]

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\Verb\0]
@="&Edition,0,2"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\Verb\1]
@="&Ouvrir,0,2"

[HKEY_CLASSES_ROOT\CLSID\{048EB43E-2059-422F-95E0-557DA96038AF}\VersionIndependentProgID]
@="PowerPoint.Slide"

[HKEY_CLASSES_ROOT\CLSID\{0B78978D-2A7A-4B34-99C0-5A0F0E730DC2}]
@="Microsoft Office OneNote Privilege Elevation"
"LocalizedString"="@C:\\Program Files\\Microsoft Office\\Office12\\1036\\ONINTL.DLL,-15000"

[HKEY_CLASSES_ROOT\CLSID\{0B78978D-2A7A-4B34-99C0-5A0F0E730DC2}\Elevation]
"Enabled"=dword:00000001

[HKEY_CLASSES_ROOT\CLSID\{0B78978D-2A7A-4B34-99C0-5A0F0E730DC2}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\1036\\ONELEV.EXE"

[HKEY_CLASSES_ROOT\CLSID\{0B78978D-2A7A-4B34-99C0-5A0F0E730DC2}\TypeLib]
@="{FB1B729D-440F-4E42-87F8-5ABF7068E5D4}"

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}]
@="SkinStatic Object"

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{18956820-5AF8-4C94-9115-6CE807FB614D}]
@="Hidden Text Document Inspector for Microsoft Word"

[HKEY_CLASSES_ROOT\CLSID\{18956820-5AF8-4C94-9115-6CE807FB614D}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OFFRHD.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{18956820-5AF8-4C94-9115-6CE807FB614D}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{1AD44B54-7E2C-4120-AA68-CAC27175D28E}]
@="Invisible On-Slide Content Document Inspector for Microsoft PowerPoint"

[HKEY_CLASSES_ROOT\CLSID\{1AD44B54-7E2C-4120-AA68-CAC27175D28E}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OFFRHD.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{1AD44B54-7E2C-4120-AA68-CAC27175D28E}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{1B16F523-6FD4-4628-994D-B82381F722BA}]
@="PSFactoryBuffer"

[HKEY_CLASSES_ROOT\CLSID\{1B16F523-6FD4-4628-994D-B82381F722BA}\InProcServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\DSITF.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{1B638296-A382-4B0E-8F51-59CDFF7B8678}]
@="Hidden Worksheets Document Inspector for Microsoft Excel"

[HKEY_CLASSES_ROOT\CLSID\{1B638296-A382-4B0E-8F51-59CDFF7B8678}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OFFRHD.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{1B638296-A382-4B0E-8F51-59CDFF7B8678}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{1CDC7D25-5AA3-4DC4-8E0C-91524280F806}]
@="Microsoft Office Theme"

[HKEY_CLASSES_ROOT\CLSID\{1CDC7D25-5AA3-4DC4-8E0C-91524280F806}\DefaultIcon]
@="C:\\Windows\\Installer\\{91120000-002F-0000-0000-0000000FF1CE}\\misc.exe,19"

[HKEY_CLASSES_ROOT\CLSID\{1CDC7D25-5AA3-4DC4-8E0C-91524280F806}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{1CDC7D25-5AA3-4DC4-8E0C-91524280F806}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,\
54,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,\
4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{1CDC7D25-5AA3-4DC4-8E0C-91524280F806}\ProgID]
@="OfficeTheme.12"

[HKEY_CLASSES_ROOT\CLSID\{1CDC7D25-5AA3-4DC4-8E0C-91524280F806}\VersionIndependentProgID]
@="OfficeTheme"

[HKEY_CLASSES_ROOT\CLSID\{21E17C2F-AD3A-4b89-841F-09CFE02D16B7}]
@="Générateur d'aperçu Microsoft Office Visio"
"DisplayName"="Générateur d'aperçu Microsoft Office Visio"
"DisableLowILProcessIsolation"=dword:00000001

[HKEY_CLASSES_ROOT\CLSID\{21E17C2F-AD3A-4b89-841F-09CFE02D16B7}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{21E17C2F-AD3A-4b89-841F-09CFE02D16B7}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\VPREVIEW.EXE"

[HKEY_CLASSES_ROOT\CLSID\{22148139-F1FC-4EB0-B237-DFCD8A38EFFC}]
@="CSimpleImporter Class"

[HKEY_CLASSES_ROOT\CLSID\{22148139-F1FC-4EB0-B237-DFCD8A38EFFC}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONENOTE.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,6e,00,\
65,00,4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,\
00,7b,00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,52,00,\
50,00,78,00,61,00,54,00,4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{22148139-F1FC-4EB0-B237-DFCD8A38EFFC}\ProgID]
@="OneNote.CSimpleImporter.1"

[HKEY_CLASSES_ROOT\CLSID\{22148139-F1FC-4EB0-B237-DFCD8A38EFFC}\TypeLib]
@="{66C493CA-D5E2-402C-B77E-7388151D41C7}"

[HKEY_CLASSES_ROOT\CLSID\{22148139-F1FC-4EB0-B237-DFCD8A38EFFC}\VersionIndependentProgID]
@="OneNote.CSimpleImporter"

[HKEY_CLASSES_ROOT\CLSID\{238D0F23-5DC9-45A6-9BE2-666160C324DD}]
@="RealVideo Decoder"

[HKEY_CLASSES_ROOT\CLSID\{238D0F23-5DC9-45A6-9BE2-666160C324DD}\InprocServer32]
@="C:\\Program Files\\BitSpirit\\Codec\\RealMediaSplitter.ax"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{2512FE57-5A88-4EE1-AEDD-5893C2FF1136}]
@="Invisible Content Document Inspector for Microsoft Excel"

[HKEY_CLASSES_ROOT\CLSID\{2512FE57-5A88-4EE1-AEDD-5893C2FF1136}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OFFRHD.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{2512FE57-5A88-4EE1-AEDD-5893C2FF1136}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}]
@="Microsoft Visio Document"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\Control]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\EnableFullPage]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\EnableFullPage\.vdx]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\EnableFullPage\.vsd]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\EnableFullPage\.vss]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\EnableFullPage\.vst]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\EnableFullPage\.vsx]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\EnableFullPage\.vtx]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\VVIEWER.DLL"
"InprocServer32"="C:\\PROGRA~1\\MICROS~3\\Office12\\VVIEWER.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\Insertable]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\ProgID]
@="VisioViewer.Viewer.1"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\Programmable]
@=""

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\ToolboxBitmap32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\VVIEWER.DLL, 101"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\TypeLib]
@="{BA35B84E-A623-471B-8B09-6D72DD072F25}"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\Version]
@="1.2"

[HKEY_CLASSES_ROOT\CLSID\{279D6C9A-652E-4833-BEFC-312CA8887857}\VersionIndependentProgID]
@="VisioViewer.Viewer"

[HKEY_CLASSES_ROOT\CLSID\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}]
@="PSFactoryBuffer"

[HKEY_CLASSES_ROOT\CLSID\{31AC3F11-E5EA-4A85-8A3D-8E095A39C27B}\InProcServer32]
@="C:\\Users\\Jean\\AppData\\Local\\Google\\Update\\1.2.131.27\\goopdate.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}]
@="SkinMiscControls Object"

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{3B83A43E-3F73-4A35-BC00-E5726F517DBF}]
@="Microsoft.Office.List.OLEDB.2.0"

[HKEY_CLASSES_ROOT\CLSID\{3B83A43E-3F73-4A35-BC00-E5726F517DBF}\InprocServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\STSLIST.DLL"
"InprocServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4c,00,\
49,00,53,00,54,00,46,00,69,00,6c,00,65,00,73,00,3e,00,2d,00,46,00,48,00,70,\
00,31,00,78,00,53,00,62,00,79,00,3f,00,2b,00,25,00,2b,00,75,00,61,00,60,00,\
41,00,64,00,56,00,69,00,00,00,00,00
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{3B83A43E-3F73-4A35-BC00-E5726F517DBF}\ProgID]
@="Microsoft.Office.List.OLEDB.2.0"

[HKEY_CLASSES_ROOT\CLSID\{3B83A43E-3F73-4A35-BC00-E5726F517DBF}\VersionIndependentProgID]
@="Microsoft.Office.List.OLEDB"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}]
@="Modèle Microsoft Office PowerPoint 2007 avec macros activées"
"IPersistStorageType"=dword:00000002
"MainPartContentType"="application/vnd.ms-powerpoint.presentation.macroEnabled.main+xml"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\AuxUserType]

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\AuxUserType\2]
@="Diapositive"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\AuxUserType\3]
@="Microsoft Office PowerPoint 97-2003 Slide"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\Conversion]

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\Conversion\Readable]

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\Conversion\Readable\Main]
@="MSPowerPointSho,MSPresentation,PowerPoint.Show.4,PowerPoint.Slide.4,PowerPoint.Show.7,PowerPoint.Slide.7,PowerPoint.Show.8,PowerPoint.Slide.8"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DataFormats]

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DataFormats\DefaultFile]
@="MSPresentation"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DataFormats\GetSet]
@="14,1,61,1"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DataFormats\GetSet\0]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DataFormats\GetSet\1]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DataFormats\GetSet\2]
@="1,1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DataFormats\GetSet\3]
@="NoteshNote,-1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DataFormats\GetSet\4]
@="Rich Text Format,1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DefaultExtension]
@=".sldm, Microsoft Office PowerPoint Macro-Enabled Slide (.sldm)"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\DefaultIcon]
@="\"C:\\PROGRA~1\\MICROS~4\\OFFICE11\\POWERPNT.EXE\",12"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\Insertable]

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,\
54,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,\
4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\ProgID]
@="PowerPoint.TemplateMacroEnabled.12"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\Verb]

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\Verb\0]
@="&Edition,0,2"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\Verb\1]
@="&Ouvrir,0,2"

[HKEY_CLASSES_ROOT\CLSID\{3C18EAE4-BC25-4134-B7DF-1ECA1337DDDC}\VersionIndependentProgID]
@="PowerPoint.SlideMacroEnabled"

[HKEY_CLASSES_ROOT\CLSID\{4116117E-002D-4882-854D-3B91B38CF4B4}]
@="SmartScreenFactoryOutlook Class"

[HKEY_CLASSES_ROOT\CLSID\{4116117E-002D-4882-854D-3B91B38CF4B4}\InprocServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\OUTLFLTR.DLL"
"InprocServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,\
72,00,6f,00,64,00,75,00,63,00,74,00,46,00,69,00,6c,00,65,00,73,00,3e,00,54,\
00,60,00,47,00,60,00,31,00,72,00,24,00,21,00,42,00,3f,00,36,00,26,00,62,00,\
52,00,21,00,4e,00,45,00,75,00,2c,00,42,00,00,00,00,00
"ThreadingModel"="free"

[HKEY_CLASSES_ROOT\CLSID\{4116117E-002D-4882-854D-3B91B38CF4B4}\ProgID]
@="outlspam.SmartScreenFactoryOutlook.1"

[HKEY_CLASSES_ROOT\CLSID\{4116117E-002D-4882-854D-3B91B38CF4B4}\VersionIndependentProgID]
@="outlspam.SmartScreenFactoryOutlook"

[HKEY_CLASSES_ROOT\CLSID\{48E73304-E1D6-4330-914C-F5F514E3486C}]
@="Send to OneNote from Internet Explorer button"

[HKEY_CLASSES_ROOT\CLSID\{48E73304-E1D6-4330-914C-F5F514E3486C}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONBttnIE.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{48E73304-E1D6-4330-914C-F5F514E3486C}\ProgID]
@="OneNote.IEAddin.12"

[HKEY_CLASSES_ROOT\CLSID\{48E73304-E1D6-4330-914C-F5F514E3486C}\VersionIndependentProgID]
@="OneNote.IEAddin"

[HKEY_CLASSES_ROOT\CLSID\{48F1A45E-8F68-498E-9001-5D3743D2DB98}]

[HKEY_CLASSES_ROOT\CLSID\{48F1A45E-8F68-498E-9001-5D3743D2DB98}\InProcServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OART.DLL"

[HKEY_CLASSES_ROOT\CLSID\{4A6D5C73-270C-4C05-871A-28230F2A8BCC}]
@="Industrial Streams MPEG Encoder General Property Page"

[HKEY_CLASSES_ROOT\CLSID\{4A6D5C73-270C-4C05-871A-28230F2A8BCC}\InprocServer32]
@="C:\\Windows\\system32\\DirectEncode.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{539E424E-EE72-4439-BB27-6B646D119406}]
@="PSFactoryBuffer"

[HKEY_CLASSES_ROOT\CLSID\{539E424E-EE72-4439-BB27-6B646D119406}\InProcServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\Wordcnvpxy.cnv"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{550D0110-8DCD-11D1-8524-00A02495E426}]
@="Visio Viewer DWG Display"

[HKEY_CLASSES_ROOT\CLSID\{550D0110-8DCD-11D1-8524-00A02495E426}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\VVIEWDWG.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{550D0110-8DCD-11D1-8524-00A02495E426}\ProgID]
@="VisioViewerDWGDisplay.VisioViewerDWGDisplay.1"

[HKEY_CLASSES_ROOT\CLSID\{550D0110-8DCD-11D1-8524-00A02495E426}\Version]
@="3.0"

[HKEY_CLASSES_ROOT\CLSID\{550D0110-8DCD-11D1-8524-00A02495E426}\VersionIndependentProgID]
@="VisioViewerDWGDisplay.VisioViewerDWGDisplay"

[HKEY_CLASSES_ROOT\CLSID\{5858A72C-C2B4-4DD7-B2BF-B76DB1BD9F6C}]
@="Microsoft Office OneNote Namespace Extension for Windows Desktop Search"

[HKEY_CLASSES_ROOT\CLSID\{5858A72C-C2B4-4DD7-B2BF-B76DB1BD9F6C}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONFILTER.DLL"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{5858A72C-C2B4-4DD7-B2BF-B76DB1BD9F6C}\ProgID]
@="OneIndex.ShellFolder.1"

[HKEY_CLASSES_ROOT\CLSID\{5858A72C-C2B4-4DD7-B2BF-B76DB1BD9F6C}\ShellFolder]
"Attributes"=dword:20180000
"WANTSFORPARSING"=""

[HKEY_CLASSES_ROOT\CLSID\{5858A72C-C2B4-4DD7-B2BF-B76DB1BD9F6C}\VersionIndependentProgID]
@="OneIndex.ShellFolder"

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}]
@="SkinRadio Object"

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{5D4A72CA-4907-4ADC-8A5E-0595C1C8369C}]
@="CFileConverter Class"

[HKEY_CLASSES_ROOT\CLSID\{5D4A72CA-4907-4ADC-8A5E-0595C1C8369C}\InprocServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"
"InprocServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,4f,00,\
6e,00,65,00,4e,00,6f,00,74,00,65,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,\
00,57,00,7b,00,7e,00,24,00,34,00,51,00,5d,00,63,00,40,00,44,00,73,00,6a,00,\
52,00,50,00,78,00,61,00,54,00,4f,00,35,00,00,00,00,00
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{5D4A72CA-4907-4ADC-8A5E-0595C1C8369C}\ProgID]
@="OneNote.CFileConverter.1"

[HKEY_CLASSES_ROOT\CLSID\{5D4A72CA-4907-4ADC-8A5E-0595C1C8369C}\VersionIndependentProgID]
@="OneNote.CFileConverter"

[HKEY_CLASSES_ROOT\CLSID\{5D77ED1E-D8A2-420D-B44E-BB2390642608}]
@="Off-Slide Content Document Inspector for Microsoft PowerPoint"

[HKEY_CLASSES_ROOT\CLSID\{5D77ED1E-D8A2-420D-B44E-BB2390642608}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OFFRHD.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{5D77ED1E-D8A2-420D-B44E-BB2390642608}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}]
@="Contact Selector"

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\Control]
@=""

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\CONTAC~1.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\MiscStatus]

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\MiscStatus\1]
@="131473"

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\ProgID]
@="ContactPicker.ContactPicker.1"

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\ToolboxBitmap32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\CONTAC~1.DLL, 102"

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\TypeLib]
@="{39B50B80-9CC3-4895-B2AA-92B3C73B587E}"

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{61E40D31-993D-4777-8FA0-19CA59B6D0BB}\VersionIndependentProgID]
@="ContactPicker.ContactPicker"

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}]
@="SkinButton Object"

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{62B4D041-4667-40B6-BB50-4BC0A5043A73}]
@="SharePoint Export Database Launcher"

[HKEY_CLASSES_ROOT\CLSID\{62B4D041-4667-40B6-BB50-4BC0A5043A73}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OWSSUPP.DLL"

[HKEY_CLASSES_ROOT\CLSID\{62B4D041-4667-40B6-BB50-4BC0A5043A73}\ProgID]
@="SharePoint.ExportDatabase"

[HKEY_CLASSES_ROOT\CLSID\{65235197-874B-4A07-BDC5-E65EA825B718}]
@="Générateur d'aperçu Microsoft Office PowerPoint"
"DisplayName"="Générateur d'aperçu Microsoft Office PowerPoint"
"DisableLowILProcessIsolation"=dword:00000001

[HKEY_CLASSES_ROOT\CLSID\{65235197-874B-4A07-BDC5-E65EA825B718}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{65235197-874B-4A07-BDC5-E65EA825B718}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE"

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}]
@="SkinForm Object"

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{6939BF8D-FF94-492C-9E4E-BD6439D8F867}]
@="Visio Viewer DWG Display Creator"

[HKEY_CLASSES_ROOT\CLSID\{6939BF8D-FF94-492C-9E4E-BD6439D8F867}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\VVIEWDWG.DLL"

[HKEY_CLASSES_ROOT\CLSID\{6939BF8D-FF94-492C-9E4E-BD6439D8F867}\ProgID]
@="VisioViewerDWGDisplayCreator.VisioViewerDWGDisplayCreator.1"

[HKEY_CLASSES_ROOT\CLSID\{6939BF8D-FF94-492C-9E4E-BD6439D8F867}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{6939BF8D-FF94-492C-9E4E-BD6439D8F867}\VersionIndependentProgID]
@="VisioViewerDWGDisplayCreator.VisioViewerDWGDisplayCreator"

[HKEY_CLASSES_ROOT\CLSID\{6B3397BB-E419-4005-8CAA-19CF34BBC97A}]
@="Custom XML Document Inspector for Microsoft Word"

[HKEY_CLASSES_ROOT\CLSID\{6B3397BB-E419-4005-8CAA-19CF34BBC97A}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OFFRHD.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{6B3397BB-E419-4005-8CAA-19CF34BBC97A}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{6D01EC38-83F9-45df-99F0-8A880993928D}]
@="Microsoft Office OneNote Windows Desktop Search IFilter"

[HKEY_CLASSES_ROOT\CLSID\{6D01EC38-83F9-45df-99F0-8A880993928D}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONFILTER.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{709E7045-EE04-45D3-9AE7-6EFFFA705F86}]
@="OneNote Notes about Outlook Items"

[HKEY_CLASSES_ROOT\CLSID\{709E7045-EE04-45D3-9AE7-6EFFFA705F86}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONBttnOL.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{709E7045-EE04-45D3-9AE7-6EFFFA705F86}\ProgID]
@="OneNote.OutlookAddin.12"

[HKEY_CLASSES_ROOT\CLSID\{709E7045-EE04-45D3-9AE7-6EFFFA705F86}\VersionIndependentProgID]
@="OneNote.OutlookAddin"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}]
@="Modèle Microsoft Office PowerPoint 2007"
"IPersistStorageType"=dword:00000002
"MainPartContentType"="application/vnd.openxmlformats-officedocument.presentationml.template.main+xml"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\AuxUserType]

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\AuxUserType\2]
@="Template"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\AuxUserType\3]
@="Microsoft Office PowerPoint 97-2003 Slide"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\Conversion]

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\Conversion\Readable]

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\Conversion\Readable\Main]
@="MSPowerPointSho,MSPresentation,PowerPoint.Show.4,PowerPoint.Slide.4,PowerPoint.Show.7,PowerPoint.Slide.7,PowerPoint.Show.8,PowerPoint.Slide.8"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DataFormats]

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DataFormats\DefaultFile]
@="MSPresentation"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DataFormats\GetSet]
@="14,1,61,1"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DataFormats\GetSet\0]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DataFormats\GetSet\1]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DataFormats\GetSet\2]
@="1,1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DataFormats\GetSet\3]
@="NoteshNote,-1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DataFormats\GetSet\4]
@="Rich Text Format,1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DefaultExtension]
@=".potx, Microsoft Office PowerPoint Template (.potx)"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~4\\OFFICE11\\POWERPNT.EXE,11"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,\
54,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,\
4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\ProgID]
@="PowerPoint.Template.12"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\Verb]

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\Verb\0]
@="&Edition,0,2"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\Verb\1]
@="&Ouvrir,0,2"

[HKEY_CLASSES_ROOT\CLSID\{75D01070-1234-44E9-82F6-DB5B39A47C13}\VersionIndependentProgID]
@="PowerPoint.Template"

[HKEY_CLASSES_ROOT\CLSID\{765035B3-5944-4A94-806B-20EE3415F26F}]
@="RealMedia Source"

[HKEY_CLASSES_ROOT\CLSID\{765035B3-5944-4A94-806B-20EE3415F26F}\InprocServer32]
@="C:\\Program Files\\BitSpirit\\Codec\\RealMediaSplitter.ax"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{767A19A0-3CC7-415B-9D08-D48DD7B8557D}]
@="Microsoft Office PowerPoint Macro-Enabled Addin"

[HKEY_CLASSES_ROOT\CLSID\{767A19A0-3CC7-415B-9D08-D48DD7B8557D}\DefaultIcon]
@="C:\\Windows\\Installer\\{91120000-002F-0000-0000-0000000FF1CE}\\pptico.exe,15"

[HKEY_CLASSES_ROOT\CLSID\{767A19A0-3CC7-415B-9D08-D48DD7B8557D}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{767A19A0-3CC7-415B-9D08-D48DD7B8557D}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,\
54,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,\
4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{767A19A0-3CC7-415B-9D08-D48DD7B8557D}\ProgID]
@="PowerPoint.Addin.12"

[HKEY_CLASSES_ROOT\CLSID\{767A19A0-3CC7-415B-9D08-D48DD7B8557D}\VersionIndependentProgID]
@="PowerPoint.Addin"

[HKEY_CLASSES_ROOT\CLSID\{76FD94BA-8FF3-40B4-9C56-D7421DBFD10D}]
@="PSFactoryBuffer"

[HKEY_CLASSES_ROOT\CLSID\{76FD94BA-8FF3-40B4-9C56-D7421DBFD10D}\InProcServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\excelcnvpxy.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{795514CB-A81C-48f6-87AB-5B22D433D5D8}]
@="SkinImage Object"

[HKEY_CLASSES_ROOT\CLSID\{795514CB-A81C-48f6-87AB-5B22D433D5D8}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{795514CB-A81C-48f6-87AB-5B22D433D5D8}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{82780E93-DEDB-4666-8CEF-E83D451CC53E}]
@="CExcel12Converter Class"

[HKEY_CLASSES_ROOT\CLSID\{82780E93-DEDB-4666-8CEF-E83D451CC53E}\LocalServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\excelcnv.exe"

[HKEY_CLASSES_ROOT\CLSID\{84F66100-FF7C-4fb4-B0C0-02CD7FB668FE}]
@="Générateur d'aperçu Microsoft Office Word"
"DisplayName"="Générateur d'aperçu Microsoft Office Word"
"DisableLowILProcessIsolation"=dword:00000001

[HKEY_CLASSES_ROOT\CLSID\{84F66100-FF7C-4fb4-B0C0-02CD7FB668FE}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{84F66100-FF7C-4fb4-B0C0-02CD7FB668FE}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\WINWORD.EXE"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}]
@="Modèle Microsoft Office Word prenant en charge les macros"
"IPersistStorageType"=dword:00000002
"MainPartContentType"="application/vnd.ms-word.template.macroEnabledTemplate.main+xml"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\AuxUserType]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\AuxUserType\2]
@="Template"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\AuxUserType\3]
@="Microsoft Office Word"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Conversion]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Conversion\Readable]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Conversion\Readable\Main]
@="MSWordDocx,MSWordDocm,MSWordDotx,MSWordDotm,MSWordDoc,1"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Conversion\Readwritable]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Conversion\Readwritable\Main]
@="MSWordDocx,MSWordDocm,MSWordDotx,MSWordDotm,MSWordDoc,MSWordPic"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\DefaultFile]
@="MSWordDotm"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\DelayRenderFormats]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\DelayRenderFormats\0]
@="Woozle"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\GetSet]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\GetSet\0]
@="Embed_Source,1,8,1"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\GetSet\1]
@="1,1,1,3"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\GetSet\2]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\GetSet\3]
@="HTML Format,1,1,3"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\GetSet\4]
@="Rich Text Format,1,1,3"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DataFormats\GetSet\5]
@="NoteshNote, -1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DefaultExtension]
@=".dotm,Word Macro-Enabled Template (.dotm)"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\WINWORD.EXE,2"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\DocObject]
@="16"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Insertable]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\WINWORD.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,\
52,00,44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,\
54,00,4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\NotInsertable]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\OfficeCompliant]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Printable]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\ProgID]
@="Word.TemplateMacroEnabled.12"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\TypeLib]
@="{00020905-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Verb]

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Verb\0]
@="&Edition,0,2"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Verb\1]
@="&Ouvrir,0,2"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\Version]
@="12"

[HKEY_CLASSES_ROOT\CLSID\{8A624388-AA27-43E0-89F8-2A12BFF7BCCD}\VersionIndependentProgID]
@="Word.TemplateMacroEnabled"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}]
@="Modèle Microsoft Office Word"
"IPersistStorageType"=dword:00000002
"MainPartContentType"="application/vnd.openxmlformats-officedocument.wordprocessingml.template.main+xml"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\AuxUserType]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\AuxUserType\2]
@="Template"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\AuxUserType\3]
@="Microsoft Office Word"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Conversion]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Conversion\Readable]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Conversion\Readable\Main]
@="MSWordDocx,MSWordDocm,MSWordDotx,MSWordDotm,MSWordDoc,1"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Conversion\Readwritable]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Conversion\Readwritable\Main]
@="MSWordDocx,MSWordDocm,MSWordDotx,MSWordDotm,MSWordDoc,MSWordPic"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\DefaultFile]
@="MSWordDotx"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\DelayRenderFormats]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\DelayRenderFormats\0]
@="Woozle"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\GetSet]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\GetSet\0]
@="Embed_Source,1,8,1"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\GetSet\1]
@="1,1,1,3"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\GetSet\2]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\GetSet\3]
@="HTML Format,1,1,3"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\GetSet\4]
@="Rich Text Format,1,1,3"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DataFormats\GetSet\5]
@="NoteshNote, -1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DefaultExtension]
@=".dotx,Word Template (.dotx)"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\WINWORD.EXE,2"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\DocObject]
@="16"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Insertable]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\WINWORD.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,57,00,4f,00,\
52,00,44,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,\
00,34,00,51,00,5d,00,63,00,40,00,35,00,64,00,31,00,60,00,2c,00,78,00,61,00,\
54,00,4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\NotInsertable]
@=""

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\OfficeCompliant]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Printable]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\ProgID]
@="Word.Template.12"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\TypeLib]
@="{00020905-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Verb]

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Verb\0]
@="&Edition,0,2"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Verb\1]
@="&Ouvrir,0,2"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\Version]
@="12"

[HKEY_CLASSES_ROOT\CLSID\{912ABC52-36E2-4714-8E62-A8B73CA5E390}\VersionIndependentProgID]
@="Word.Template"

[HKEY_CLASSES_ROOT\CLSID\{9203C2CB-1DC1-482D-967E-597AFF270F0D}]
@="SharePoint OpenDocuments Class"

[HKEY_CLASSES_ROOT\CLSID\{9203C2CB-1DC1-482D-967E-597AFF270F0D}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OWSSUPP.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{9203C2CB-1DC1-482D-967E-597AFF270F0D}\ProgID]
@="SharePoint.OpenDocuments.3"

[HKEY_CLASSES_ROOT\CLSID\{9203C2CB-1DC1-482D-967E-597AFF270F0D}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{9203C2CB-1DC1-482D-967E-597AFF270F0D}\TypeLib]
@="{BDEADEF0-C265-11D0-BCED-00A0C90AB50F}"

[HKEY_CLASSES_ROOT\CLSID\{9203C2CB-1DC1-482D-967E-597AFF270F0D}\VersionIndependentProgID]
@="SharePoint.OpenDocuments"

[HKEY_CLASSES_ROOT\CLSID\{941A4793-A705-4312-8DFC-C11CA05F397E}]
@="RealAudio Decoder"

[HKEY_CLASSES_ROOT\CLSID\{941A4793-A705-4312-8DFC-C11CA05F397E}\InprocServer32]
@="C:\\Program Files\\BitSpirit\\Codec\\RealMediaSplitter.ax"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{99098758-CB85-4A90-924F-F21898796281}]
@="Microsoft Office Slide Library Control"

[HKEY_CLASSES_ROOT\CLSID\{99098758-CB85-4A90-924F-F21898796281}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\PPSLAX.DLL"
"ThreadingModel"="Free"

[HKEY_CLASSES_ROOT\CLSID\{99098758-CB85-4A90-924F-F21898796281}\ProgID]
@="PPSLAX.SlideLibrary.1"

[HKEY_CLASSES_ROOT\CLSID\{99098758-CB85-4A90-924F-F21898796281}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{99098758-CB85-4A90-924F-F21898796281}\TypeLib]
@="{4D95030A-A3A9-4C38-ACA8-D323A2267698}"

[HKEY_CLASSES_ROOT\CLSID\{99098758-CB85-4A90-924F-F21898796281}\Version]
@="12.0"

[HKEY_CLASSES_ROOT\CLSID\{99098758-CB85-4A90-924F-F21898796281}\VersionIndependentProgID]
@="PPSLAX.SlideLibrary"

[HKEY_CLASSES_ROOT\CLSID\{9BF4CFF1-968F-4928-AF25-D1C8C01E63E4}]
@="Headers and Footers Document Inspector for Microsoft Excel"

[HKEY_CLASSES_ROOT\CLSID\{9BF4CFF1-968F-4928-AF25-D1C8C01E63E4}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OFFRHD.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{9BF4CFF1-968F-4928-AF25-D1C8C01E63E4}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{9C87A117-5336-4385-AF22-BABE7F983275}]
@="File Source Filter For Preview"

[HKEY_CLASSES_ROOT\CLSID\{9C87A117-5336-4385-AF22-BABE7F983275}\InprocServer32]
@="C:\\Program Files\\BitSpirit\\Codec\\dxFilter.ax"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{9CDC7B1E-53E4-477f-B05E-50C87D3FFA56}]
@="CChart12Converter Class"

[HKEY_CLASSES_ROOT\CLSID\{9CDC7B1E-53E4-477f-B05E-50C87D3FFA56}\LocalServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\excelcnv.exe"

[HKEY_CLASSES_ROOT\CLSID\{A8CB1D55-99DE-4448-AA2B-69883DEB3037}]
@="SyncMan SyncStatus"

[HKEY_CLASSES_ROOT\CLSID\{A8CB1D55-99DE-4448-AA2B-69883DEB3037}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{A8CB1D55-99DE-4448-AA2B-69883DEB3037}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\DSSM.EXE"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}]
@="Modèle Microsoft Office PowerPoint 2007 avec macros activées"
"IPersistStorageType"=dword:00000002
"MainPartContentType"="application/vnd.ms-powerpoint.template.macroEnabled.main+xml"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\AuxUserType]

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\AuxUserType\2]
@="Template"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\AuxUserType\3]
@="Microsoft Office PowerPoint 97-2003 Slide"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\Conversion]

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\Conversion\Readable]

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\Conversion\Readable\Main]
@="MSPowerPointSho,MSPresentation,PowerPoint.Show.4,PowerPoint.Slide.4,PowerPoint.Show.7,PowerPoint.Slide.7,PowerPoint.Show.8,PowerPoint.Slide.8"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DataFormats]

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DataFormats\DefaultFile]
@="MSPresentation"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DataFormats\GetSet]
@="14,1,61,1"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DataFormats\GetSet\0]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DataFormats\GetSet\1]
@="3,1,32,1"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DataFormats\GetSet\2]
@="1,1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DataFormats\GetSet\3]
@="NoteshNote,-1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DataFormats\GetSet\4]
@="Rich Text Format,1,1,1"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DefaultExtension]
@=".potm, Microsoft Office PowerPoint Macro-Enabled Template (.potm)"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\DefaultIcon]
@="C:\\PROGRA~1\\MICROS~4\\OFFICE11\\POWERPNT.EXE,12"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\InprocHandler32]
@="ole32.dll"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\LocalServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\POWERPNT.EXE"
"LocalServer32"=hex(7):77,00,5f,00,31,00,5e,00,56,00,57,00,21,00,21,00,21,00,21,\
00,21,00,21,00,21,00,21,00,21,00,4d,00,4b,00,4b,00,53,00,6b,00,50,00,50,00,\
54,00,46,00,69,00,6c,00,65,00,73,00,3e,00,74,00,57,00,7b,00,7e,00,24,00,34,\
00,51,00,5d,00,63,00,40,00,59,00,2a,00,47,00,78,00,37,00,78,00,61,00,54,00,\
4f,00,35,00,00,00,00,00

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\ProgID]
@="PowerPoint.TemplateMacroEnabled.12"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\v]
@="C:\\PROGRA~1\\MICROS~4\\OFFICE11\\POWERPNT.EXE"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\Verb]

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\Verb\0]
@="&Edition,0,2"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\Verb\1]
@="&Ouvrir,0,2"

[HKEY_CLASSES_ROOT\CLSID\{AA14F9C9-62B5-4637-8AC4-8F25BF29D5A7}\VersionIndependentProgID]
@="PowerPoint.TemplateMacroEnabled"

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}]
@="SkinScrollBar Object"

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\Implemented Categories\{55E89939-3D2B-4954-80EA-2703A8EA1A10}]

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{B8D12492-CE0F-40AD-83EA-099A03D493F1}]
@="Microsoft Office OneNote Filter"

[HKEY_CLASSES_ROOT\CLSID\{B8D12492-CE0F-40AD-83EA-099A03D493F1}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\ONFILTER.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}]
@="ActiveSkin 4.3 Control"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\Control]

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\InprocServer32]
@="C:\\Windows\\system32\\actskn43.ocx"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\MiscStatus]
@="0"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\MiscStatus\1]
@="132497"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\ProgID]
@="ActiveSkin4.Skin2.1"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\ToolboxBitmap32]
@="C:\\Windows\\system32\\actskn43.ocx, 206"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\TypeLib]
@="{74848F95-A02A-4286-AF0C-A3C755E4A5B3}"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb]

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\1]
@="&Load Skin,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\2]
@="&Save Skin,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\3]
@="&Edit Skin,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\4]
@="&Delete Skin,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\verb\5]
@="&About..,0,2"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\Version]
@="1.0"

[HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\VersionIndependentProgID]
@="ActiveSkin4.Skin2"

[HKEY_CLASSES_ROOT\CLSID\{BC7ADC2B-CC8C-48d2-A820-1BC605B0D3C7}]
@="CWordConv Class"

[HKEY_CLASSES_ROOT\CLSID\{BC7ADC2B-CC8C-48d2-A820-1BC605B0D3C7}\LocalServer32]
@="C:\\Program Files\\Microsoft Office\\Office12\\Wordconv.exe"

[HKEY_CLASSES_ROOT\CLSID\{BDB70B23-BAA7-44A5-8CB5-A3F5F34865C8}]
@="Industrial Streams MPEG Encoder Audio Property Page"

[HKEY_CLASSES_ROOT\CLSID\{BDB70B23-BAA7-44A5-8CB5-A3F5F34865C8}\InprocServer32]
@="C:\\Windows\\system32\\DirectEncode.dll"
"ThreadingModel"="Both"

[HKEY_CLASSES_ROOT\CLSID\{BDEADEF5-C265-11D0-BCED-00A0C90AB50F}]
@="SharePoint Stssync Handler"

[HKEY_CLASSES_ROOT\CLSID\{BDEADEF5-C265-11D0-BCED-00A0C90AB50F}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\OWSSUPP.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{BDEADEF5-C265-11D0-BCED-00A0C90AB50F}\ProgID]
@="SharePoint.StssyncHandler.3"

[HKEY_CLASSES_ROOT\CLSID\{BDEADEF5-C265-11D0-BCED-00A0C90AB50F}\Programmable]

[HKEY_CLASSES_ROOT\CLSID\{BDEADEF5-C265-11D0-BCED-00A0C90AB50F}\Version]
@="3.0"

[HKEY_CLASSES_ROOT\CLSID\{BDEADEF5-C265-11D0-BCED-00A0C90AB50F}\VersionIndependentProgID]
@="SharePoint.StssyncHandler"

[HKEY_CLASSES_ROOT\CLSID\{C55984D2-DC2E-49EC-99F5-0F95B37FA965}]
@="Contact Selector"

[HKEY_CLASSES_ROOT\CLSID\{C55984D2-DC2E-49EC-99F5-0F95B37FA965}\InprocServer32]
@="C:\\PROGRA~1\\MICROS~3\\Office12\\CONTAC~1.DLL"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{C55984D2-DC2E-49EC-99F5-0F95B37FA965}\ProgID]
@="ContactPicker.PropPage2.1"

[HKEY_CLASSES_ROOT\CLSID\{C55984D2-DC2E-49EC-99F5-0F95B37FA965}\TypeLib]
@="{39B50B80-9CC3-4895-B2AA-92B3C73B587E}"

[HKEY_CLASSES_ROOT\CLSID\{C55984D2-DC2E-49EC-99F5-0F95B37FA965}\Version]
@="1.0"

[HKEY_CLASSES_R
Voir le profil de l'utilisateur Envoyer un message privé
arba
..
..


Inscrit le: 27 Jan 2008
Messages: 864

MessagePosté le: Mar Jan 20, 2009 12:03 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

mbam a bien bossé et fait sauter le rootkit (msqpdxvdmcmtct.dll ) qui posait probleme.

essaie de lancer sd fix en mode normal

et télécharge rsit et utilise ce tuto : -://aide-malware.forumactif.net/tutoriels-f6/tutoriel-random-s-system-information-tool-rsit-t29.htm

-://images.malwareremoval.com/random/RSIT.exe

poste moi les rapport rsit (exécuté lui aussi en mode normal) et sdfix

la désinfection est bientot finie courage!
Voir le profil de l'utilisateur Envoyer un message privé
arba
..
..


Inscrit le: 27 Jan 2008
Messages: 864

MessagePosté le: Mar Jan 20, 2009 1:35 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

n'oublie pas de désactiver avast avant d'utiliser sd fix et vérifie que l'uac est toujours désactivé.

si cela ne foctionne pas :

télécharge combofix :
-://download.bleepingcomputer.com/sUBs/ComboFix.exe

double clique sur combofix.exe et poste le rapport s'il te plait.
Voir le profil de l'utilisateur Envoyer un message privé
Nicokid



Inscrit le: 18 Jan 2009
Messages: 14

MessagePosté le: Dim Jan 25, 2009 6:44 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

Bon me revoilà enfin chez moi prêt à en découdre avec ces petits cons de virus !

Voilà le rapport Sdfix :


System Report
*************

Run on 25/01/2009 at 19:26

Microsoft Windows [version 6.0.6000]

Current user is an administrator

Running Processes:

\SystemRoot\System32\smss.exe [528]
C:\Windows\system32\csrss.exe [604]
C:\Windows\system32\wininit.exe [652]
C:\Windows\system32\csrss.exe [664]
C:\Windows\system32\services.exe [696]
C:\Windows\system32\lsass.exe [708]
C:\Windows\system32\lsm.exe [716]
C:\Windows\system32\winlogon.exe [812]
C:\Windows\system32\svchost.exe [896]
C:\Windows\system32\svchost.exe [956]
C:\Windows\System32\svchost.exe [992]
C:\Windows\System32\svchost.exe [1060]
C:\Windows\System32\svchost.exe [1108]
C:\Windows\system32\svchost.exe [1140]
C:\Windows\system32\SLsvc.exe [1292]
C:\Windows\system32\svchost.exe [1336]
C:\Windows\system32\svchost.exe [1540]
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [1696]
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [1732]
C:\Program Files\Alwil Software\Avast4\ashServ.exe [1768]
C:\Windows\system32\Dwm.exe [1840]
C:\Windows\Explorer.EXE [1876]
C:\Program Files\Windows Defender\MSASCui.exe [644]
C:\Windows\System32\spoolsv.exe [1128]
C:\Windows\system32\svchost.exe [1344]
C:\Windows\system32\taskeng.exe [1476]
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1560]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1800]
C:\Windows\RtHDVCpl.exe [1952]
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [2152]
C:\Program Files\HP\QuickPlay\QPService.exe [2184]
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe [2244]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2264]
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [2272]
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [2284]
C:\Program Files\Java\jre6\bin\jusched.exe [2292]
C:\Program Files\Alwil Software\Avast4\ashDisp.exe [2328]
C:\Windows\System32\rundll32.exe [2388]
C:\Windows\System32\rundll32.exe [2472]
C:\Program Files\iTunes\iTunesHelper.exe [2496]
C:\Program Files\Windows Sidebar\sidebar.exe [2516]
C:\Users\Jean\AppData\Local\Google\Update\GoogleUpdate.exe [2524]
C:\Program Files\Wallpaper\Wallpaper.exe [2532]
C:\Program Files\Windows Media Player\wmpnscfg.exe [2540]
C:\Program Files\Windows Sidebar\sidebar.exe [2728]
C:\Windows\System32\mobsync.exe [2808]
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [3116]
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [3128]
C:\Windows\system32\svchost.exe [3312]
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [3324]
C:\Program Files\Common Files\LightScribe\LSSrvc.exe [3364]
C:\Windows\System32\svchost.exe [3384]
C:\Windows\System32\svchost.exe [3516]
C:\Windows\system32\svchost.exe [3532]
C:\Windows\system32\svchost.exe [3632]
C:\Windows\System32\svchost.exe [3688]
C:\Windows\system32\SearchIndexer.exe [3772]
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [3936]
C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [4048]
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [848]
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2548]
C:\Program Files\Windows Media Player\wmpnetwk.exe [3008]
C:\Windows\system32\taskeng.exe [1968]
C:\Windows\system32\wbem\wmiprvse.exe [1964]
C:\Program Files\iPod\bin\iPodService.exe [3112]
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe [4480]
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [4632]
C:\Windows\system32\wbem\unsecapp.exe [5072]
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [5664]
C:\Windows\system32\wuauclt.exe [4120]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3272]
C:\Program Files\Windows Live\Messenger\usnsvc.exe [4232]
C:\Program Files\Windows Media Player\wmplayer.exe [3184]
C:\Windows\system32\conime.exe [3844]


Drivers - Running:

ACPI
AFD
Aspi32
aswFsBlk
aswMonFlt
aswRdr
aswSP
aswTdi
atapi
Beep
bowser
cdfs
cdrom
CLFS
CmBatt
Compbatt
crcdisk
DfsC
disk
DXGKrnl
eabfiltr
Ecache
FileInfo
FltMgr
GEARAspiWDM
HBtnKey
HDAudBus
HTTP
i8042prt
iaStor
IntcAzAudAddService
intelppm
iScsiPrt
kbdclass
kbdhid
KSecDD
lltdio
luafv
Modem
monitor
mouclass
MountMgr
mpsdrv
MRxDAV
mrxsmb
mrxsmb10
mrxsmb20
Msfs
msisadrv
mssmbios
Mup
NativeWifiP
NDIS
NdisTapi
Ndisuio
NdisWan
NDProxy
NetBIOS
netbt
NETw4v32
Npfs
nsiproxy
Ntfs
Null
nvlddmkm
ohci1394
partmgr
pci
pciide
PEAUTH
PptpMiniport
PSched
PxHelp20
RasAcd
Rasl2tp
RasPppoe
rdbss
RDPCDD
RDPENCDD
rimmptsk
rimsptsk
rismxdp
rspndr
RTL8169
sdbus
secdrv
Smb
smserial
spldr
sptd
srv
srv2
srvnet
StarOpen
swenum
SynTP
Tcpip
tcpipreg
tdx
TermDD
tunmp
tunnel
umbus
usbccgp
usbehci
usbhub
usbuhci
usbvideo
VgaSave
volmgr
volmgrx
volsnap
Wanarpv6
Wdf01000
WmiAcpi


Drivers - Stopped:

adp94xx
adpahci
adpu160m
adpu320
agp440
aic78xx
aliide
amdagp
amdide
AmdK7
AmdK8
arc
arcsas
AsyncMac
BCM43XV
blbdrive
BrFiltLo
BrFiltUp
Brserid
BrSerWdm
BrUsbMdm
BrUsbSer
BTHMODEM
circlass
cmdide
Crusoe
Dot4
Dot4Print
dot4usb
drmkaud
E100B
E1G60
elxstor
fastfat
fdc
Filetrace
flpydisk
gagp30kx
gmer
HdAudAddService
HidBth
HidIr
HidUsb
HpCISSs
HSFHWAZL
HSF_DPV
i2omp
ialm
iaStorV
iirsp
intelide
IpFilterDriver
IpInIp
IPMIDRV
IPNAT
IRENUM
isapnp
iteatapi
iteraid
LSI_FC
LSI_SAS
LSI_SCSI
megasas
mouhid
mpio
Mraid35x
msahci
msdsm
MSKSSRV
MSPCLOCK
MSPQM
MsRPC
MSTEE
nfrd960
ntrigdigi
nvraid
nvstor
nv_agp
NwlnkFlt
NwlnkFwd
Parport
Parvdm
pcmcia
Processor
ql2300
ql40xx
QWAVEdrv
rdpdr
RDPWD
sbp2port
Serenum
Serial
sermouse
sffdisk
sffp_mmc
sffp_sd
sfloppy
sisagp
SiSRaid2
SiSRaid4
ssm_bus
ssm_mdfl
ssm_mdm
Symc8xx
Sym_hi
Sym_u3
Tcpip6
TDPIPE
TDTCP
tssecsrv
uagp35
udfs
uliagpkx
uliahci
UlSata
ulsata2
usbcir
usbohci
usbprint
usbscan
USBSTOR
vga
viaagp
ViaC7
viaide
vsmraid
WacomPen
Wanarp
Wd
winachsf
ws2ifsl
WUDFRd


Services - Running:

aawservice
AeLookupSvc
Apple
aswUpdSv
AudioEndpointBuilder
Audiosrv
avast!
avast!
avast!
BFE
BITS
Browser
CLCapSvc
CLSched
CryptSvc
DcomLaunch
Dhcp
Dnscache
DPS
EapHost
EMDMgmt
Eventlog
EventSystem
fdPHost
FDResPub
gpsvc
HP
hpqcxs08
hpqddsvc
hpqwmiex
IAANTMON
IKEEXT
iphlpsvc
iPod
KeyIso
KtmRm
LanmanServer
LanmanWorkstation
LightScribeService
lmhosts
MMCSS
MpsSvc
Net
Netman
netprofm
NlaSvc
nsi
PcaSvc
PlugPlay
Pml
PolicyAgent
ProfSvc
RasMan
RpcSs
SamSs
Schedule
seclogon
SENS
ShellHWDetection
slsvc
Spooler
SSDPSRV
stisvc
SysMain
TabletInputService
TapiSrv
TermService
Themes
TrkWks
upnphost
usnjsvc
UxSms
W32Time
WdiSystemHost
WebClient
WerSvc
WinDefend
Winmgmt
Wlansvc
WMPNetworkSvc
WPDBusEnum
wscsvc
WSearch
wuauserv
wudfsvc


Services - Stopped:

ALG
Appinfo
CertPropSvc
clr_optimization_v2.0.50727_32
COMSysApp
DFSR
dot3svc
ehRecvr
ehSched
ehstart
FontCache3.0.0.0
hidserv
hkmsvc
IDriverT
idsvc
IPBusEnum
lltdsvc
Mcx2Svc
MSCSPTISRV
MSDTC
MSiSCSI
msiserver
napagent
Netlogon
NetTcpPortSharing
odserv
ose
p2pimsvc
p2psvc
PACSPTISVR
pla
PNRPAutoReg
PNRPsvc
ProtectedStorage
QWAVE
RasAuto
RemoteAccess
RemoteRegistry
RoxMediaDB9
RpcLocator
SCardSvr
SCPolicySvc
SDRSVC
SessionEnv
SharedAccess
SLUINotify
SNMPTRAP
SonicStage
SPTISRV
SSScsiSV
stllssvr
swprv
TBS
THREADORDER
TrustedInstaller
UI0Detect
vds
VSS
wcncsvc
WcsPlugInService
WdiServiceHost
Wecsvc
wercplsupport
WinHttpAutoProxySvc
WinRM
WLSetupSvc
wmiApSrv
WPCSvc


Files Created/Modified - 60 Days:


C:\

25 Jan 2009 18:52:32 2 145 837 056 A.SH. "C:\hiberfil.sys"
25 Jan 2009 19:23:18 0 A.SHR "C:\IO.SYS"
25 Jan 2009 19:23:18 0 A.SHR "C:\MSDOS.SYS"
25 Jan 2009 18:52:30 2 459 762 688 A.SH. "C:\pagefile.sys"
23 Jan 2009 23:03:12 1 529 241 A.... "C:\SDFix.exe"


C:\Windows\

25 Jan 2009 18:52:36 67 584 A.S.. "C:\Windows\bootstat.dat"
31 Dec 2008 17:02:56 884 736 A.... "C:\Windows\gmer.dll"
31 Dec 2008 17:02:54 811 008 A...R "C:\Windows\gmer.exe"
26 Nov 2008 18:21:30 1 236 208 A.... "C:\Windows\System32\aswBoot.exe"
30 Dec 2008 7:36:32 410 984 A.... "C:\Windows\System32\deploytk.dll"
3 Jan 2009 20:58:30 405 080 A.... "C:\Windows\System32\FNTCACHE.DAT"
30 Dec 2008 7:36:34 144 792 A.... "C:\Windows\System32\java.exe"
30 Dec 2008 7:36:34 144 792 A.... "C:\Windows\System32\javaw.exe"
30 Dec 2008 7:36:34 148 888 A.... "C:\Windows\System32\javaws.exe"
25 Jan 2009 18:57:50 103 924 A.... "C:\Windows\System32\perfc009.dat"
25 Jan 2009 18:57:50 117 572 A.... "C:\Windows\System32\perfc00C.dat"
25 Jan 2009 18:57:50 610 142 A.... "C:\Windows\System32\perfh009.dat"
25 Jan 2009 18:57:50 690 832 A.... "C:\Windows\System32\perfh00C.dat"
30 Dec 2008 21:09:20 370 176 A.... "C:\Windows\System32\x264vfw.dll"
25 Jan 2009 18:52:46 6 A..H. "C:\Windows\Tasks\SA.DAT"
25 Jan 2009 18:54:56 262 144 A.SH. "C:\Windows\ServiceProfiles\LocalService\ntuser.dat"
25 Jan 2009 18:54:52 262 144 A.SH. "C:\Windows\ServiceProfiles\NetworkService\ntuser.dat"
26 Nov 2008 18:17:26 20 560 A.... "C:\Windows\System32\drivers\aswFsBlk.sys"
26 Nov 2008 18:17:16 51 792 A.... "C:\Windows\System32\drivers\aswMonFlt.sys"
26 Nov 2008 18:16:30 23 152 A.... "C:\Windows\System32\drivers\aswRdr.sys"
26 Nov 2008 18:17:36 111 184 A.... "C:\Windows\System32\drivers\aswSP.sys"
26 Nov 2008 18:16:38 50 864 A.... "C:\Windows\System32\drivers\aswTdi.sys"
31 Dec 2008 17:02:56 85 969 A.... "C:\Windows\System32\drivers\gmer.sys"
14 Jan 2009 16:11:28 15 504 A.... "C:\Windows\System32\drivers\mbam.sys"
14 Jan 2009 16:11:32 38 496 A.... "C:\Windows\System32\drivers\mbamswissarmy.sys"
14 Dec 2008 17:07:40 717 296 A.... "C:\Windows\System32\drivers\sptd.sys"
19 Jan 2009 13:04:48 1 148 A.... "C:\Windows\System32\WDI\ERCQueuedResolutions.dat"
14 Dec 2008 15:18:30 65 536 A.... "C:\Windows\winsxs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e507087\vcomp.dll"
29 Nov 2008 12:05:54 88 590 A.... "C:\Windows\System32\Macromed\Flash\uninstall_activeX.exe"
25 Jan 2009 18:52:38 2 048 A.SH. "C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat"
25 Jan 2009 18:52:38 2 048 A.SH. "C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat"
14 Dec 2008 17:08:42 6 291 456 A.... "C:\Windows\System32\SMI\Store\Machine\schema.dat"


C:\Program Files\

31 Dec 2008 11:55:50 6 317 A.... "C:\Program Files\Audacity\unins000.dat"
31 Dec 2008 11:55:34 674 074 A.... "C:\Program Files\Audacity\unins000.exe"
19 Dec 2008 19:28:02 1 434 864 A.... "C:\Program Files\CCleaner\CCleaner.exe"
18 Jan 2009 12:25:46 114 658 A.... "C:\Program Files\CCleaner\uninst.exe"
29 Dec 2008 8:53:44 125 936 A.... "C:\Program Files\DivX\DivXBundleUninstall.exe"
29 Dec 2008 8:51:28 125 936 A.... "C:\Program Files\DivX\DivXCodecUninstall.exe"
29 Dec 2008 8:51:32 125 936 A.... "C:\Program Files\DivX\DivXConverterUninstall.exe"
29 Dec 2008 8:53:42 125 936 A.... "C:\Program Files\DivX\DivXPlayerUninstall.exe"
27 Dec 2008 18:23:44 419 328 A.... "C:\Program Files\DVD Audio Extractor\DVD Audio Extractor.exe"
21 Dec 2008 20:04:26 182 272 A.... "C:\Program Files\DVD Audio Extractor\libmp3lame.dll"
30 Dec 2008 20:29:50 2 721 A.... "C:\Program Files\DVD Audio Extractor\unins000.dat"
30 Dec 2008 20:29:38 695 578 A.... "C:\Program Files\DVD Audio Extractor\unins000.exe"
30 Dec 2008 21:10:22 44 067 A.... "C:\Program Files\ffdshow\unins000.dat"
30 Dec 2008 21:09:26 684 560 A.... "C:\Program Files\ffdshow\unins000.exe"
29 Dec 2008 20:03:06 22 950 A.... "C:\Program Files\Free Audio Pack\unins000.dat"
29 Dec 2008 20:02:00 694 800 A.... "C:\Program Files\Free Audio Pack\unins000.exe"
14 Jan 2009 16:11:28 380 048 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam-dor.exe"
14 Jan 2009 16:11:26 73 360 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll"
14 Jan 2009 16:11:26 1 273 488 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"
14 Jan 2009 16:11:28 73 360 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll"
14 Jan 2009 16:11:30 399 504 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe"
14 Jan 2009 16:11:30 170 640 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe"
14 Jan 2009 16:11:30 44 688 A.... "C:\Program Files\Malwarebytes' Anti-Malware\ssubtmr6.dll"
19 Jan 2009 21:26:30 8 440 A.... "C:\Program Files\Malwarebytes' Anti-Malware\unins000.dat"
19 Jan 2009 21:26:06 688 784 A.... "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
14 Jan 2009 16:11:32 77 968 A.... "C:\Program Files\Malwarebytes' Anti-Malware\zlib.dll"
15 Dec 2008 10:07:02 17 408 A.... "C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll"
15 Dec 2008 10:07:04 185 856 A.... "C:\Program Files\Mozilla Firefox\crashreporter.exe"
15 Dec 2008 10:07:06 307 712 A.... "C:\Program Files\Mozilla Firefox\firefox.exe"
15 Dec 2008 10:07:06 233 472 A.... "C:\Program Files\Mozilla Firefox\freebl3.dll"
15 Dec 2008 10:07:06 697 344 A.... "C:\Program Files\Mozilla Firefox\js3250.dll"
15 Dec 2008 10:07:06 710 144 A.... "C:\Program Files\Mozilla Firefox\mozcrt19.dll"
15 Dec 2008 10:07:06 198 144 A.... "C:\Program Files\Mozilla Firefox\nspr4.dll"
15 Dec 2008 10:07:08 697 856 A.... "C:\Program Files\Mozilla Firefox\nss3.dll"
15 Dec 2008 10:07:08 304 640 A.... "C:\Program Files\Mozilla Firefox\nssckbi.dll"
15 Dec 2008 10:07:08 103 936 A.... "C:\Program Files\Mozilla Firefox\nssdbm3.dll"
15 Dec 2008 10:07:08 87 552 A.... "C:\Program Files\Mozilla Firefox\nssutil3.dll"
15 Dec 2008 10:07:08 20 480 A.... "C:\Program Files\Mozilla Firefox\plc4.dll"
15 Dec 2008 10:07:08 17 408 A.... "C:\Program Files\Mozilla Firefox\plds4.dll"
15 Dec 2008 10:07:12 103 936 A.... "C:\Program Files\Mozilla Firefox\smime3.dll"
15 Dec 2008 10:07:12 151 552 A.... "C:\Program Files\Mozilla Firefox\softokn3.dll"
15 Dec 2008 10:07:12 395 776 A.... "C:\Program Files\Mozilla Firefox\sqlite3.dll"
15 Dec 2008 10:07:12 136 704 A.... "C:\Program Files\Mozilla Firefox\ssl3.dll"
15 Dec 2008 10:07:12 242 176 A.... "C:\Program Files\Mozilla Firefox\updater.exe"
15 Dec 2008 10:07:12 17 920 A.... "C:\Program Files\Mozilla Firefox\xpcom.dll"
15 Dec 2008 10:07:14 9 729 536 A.... "C:\Program Files\Mozilla Firefox\xul.dll"
30 Dec 2008 21:08:52 39 411 A.... "C:\Program Files\NeoDivX2008\uninstall.exe"
25 Nov 2008 11:02:02 162 304 A.... "C:\Program Files\Vuze\uninstall.exe"
30 Dec 2008 16:59:48 60 331 A.... "C:\Program Files\Wallpaper\uninst.exe"
30 Dec 2008 21:11:40 1 074 A.... "C:\Program Files\WinASPI\unins000.dat"
30 Dec 2008 21:11:40 72 298 A.... "C:\Program Files\WinASPI\unins000.exe"
30 Dec 2008 21:09:20 225 280 A.... "C:\Program Files\x264\megui-x264.exe"
30 Dec 2008 21:09:20 54 676 A.... "C:\Program Files\x264\x264-uninstall.exe"
30 Dec 2008 21:09:20 675 840 A.... "C:\Program Files\x264\x264.exe"
30 Dec 2008 21:09:14 5 702 A.... "C:\Program Files\Xvid\unins000.dat"
30 Dec 2008 21:08:52 673 610 A.... "C:\Program Files\Xvid\unins000.exe"
26 Nov 2008 18:15:32 225 280 A.... "C:\Program Files\Alwil Software\Avast4\Aavm4h.dll"
26 Nov 2008 18:19:02 188 416 A.... "C:\Program Files\Alwil Software\Avast4\AavmGuih.dll"
26 Nov 2008 18:15:26 20 992 A.... "C:\Program Files\Alwil Software\Avast4\AavmRpch.dll"
26 Nov 2008 18:15:42 35 840 A.... "C:\Program Files\Alwil Software\Avast4\AhResMai.dll"
26 Nov 2008 18:17:12 32 768 A.... "C:\Program Files\Alwil Software\Avast4\ahResMes.dll"
26 Nov 2008 18:16:50 53 248 A.... "C:\Program Files\Alwil Software\Avast4\AhResNS.dll"
26 Nov 2008 18:18:40 29 696 A.... "C:\Program Files\Alwil Software\Avast4\AhResOut.dll"
26 Nov 2008 18:17:06 33 280 A.... "C:\Program Files\Alwil Software\Avast4\ahResP2P.dll"
26 Nov 2008 18:19:12 43 008 A.... "C:\Program Files\Alwil Software\Avast4\AhResStd.dll"
26 Nov 2008 18:15:56 53 248 A.... "C:\Program Files\Alwil Software\Avast4\AhResWS.dll"
26 Nov 2008 18:18:00 65 536 A.... "C:\Program Files\Alwil Software\Avast4\AhRuiMai.dll"
26 Nov 2008 18:17:10 36 864 A.... "C:\Program Files\Alwil Software\Avast4\ahRuiMes.dll"
26 Nov 2008 18:16:48 36 864 A.... "C:\Program Files\Alwil Software\Avast4\AhRuiNS.dll"
26 Nov 2008 18:18:12 90 112 A.... "C:\Program Files\Alwil Software\Avast4\AhRuiOut.dll"
26 Nov 2008 18:17:04 22 528 A.... "C:\Program Files\Alwil Software\Avast4\ahRuiP2P.dll"
26 Nov 2008 18:19:10 57 344 A.... "C:\Program Files\Alwil Software\Avast4\AhRuiStd.dll"
26 Nov 2008 18:16:02 49 152 A.... "C:\Program Files\Alwil Software\Avast4\AhRuiWS.dll"
26 Nov 2008 18:13:48 274 640 A.... "C:\Program Files\Alwil Software\Avast4\ashAvast.exe"
26 Nov 2008 18:11:32 225 280 A.... "C:\Program Files\Alwil Software\Avast4\ashBase.dll"
26 Nov 2008 18:14:04 130 440 A.... "C:\Program Files\Alwil Software\Avast4\ashBug.exe"
26 Nov 2008 18:13:20 98 304 A.... "C:\Program Files\Alwil Software\Avast4\ashCfgP.dll"
26 Nov 2008 18:13:32 131 072 A.... "C:\Program Files\Alwil Software\Avast4\ashCfgT.dll"
26 Nov 2008 18:13:38 151 552 A.... "C:\Program Files\Alwil Software\Avast4\ashChest.dll"
26 Nov 2008 18:14:16 68 640 A.... "C:\Program Files\Alwil Software\Avast4\ashChest.exe"
26 Nov 2008 18:14:10 53 792 A.... "C:\Program Files\Alwil Software\Avast4\ashCnsnt.exe"
26 Nov 2008 18:18:52 81 000 A.... "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
26 Nov 2008 18:13:54 50 184 A.... "C:\Program Files\Alwil Software\Avast4\ashLogV.exe"
26 Nov 2008 18:18:32 254 040 A.... "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe"
26 Nov 2008 18:18:40 204 600 A.... "C:\Program Files\Alwil Software\Avast4\ashOutXt.dll"
26 Nov 2008 18:18:58 208 720 A.... "C:\Program Files\Alwil Software\Avast4\ashPopWz.exe"
26 Nov 2008 18:14:58 282 880 A.... "C:\Program Files\Alwil Software\Avast4\ashQuick.exe"
26 Nov 2008 18:18:46 155 160 A.... "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
26 Nov 2008 18:15:02 76 880 A.... "C:\Program Files\Alwil Software\Avast4\ashShell.dll"
26 Nov 2008 18:14:22 126 320 A.... "C:\Program Files\Alwil Software\Avast4\ashSimp2.exe"
26 Nov 2008 18:15:22 159 280 A.... "C:\Program Files\Alwil Software\Avast4\ashSimpl.exe"
26 Nov 2008 18:13:56 17 920 A.... "C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe"
26 Nov 2008 18:13:58 61 440 A.... "C:\Program Files\Alwil Software\Avast4\ashSkPck.exe"
26 Nov 2008 18:11:38 53 248 A.... "C:\Program Files\Alwil Software\Avast4\ashSODBC.dll"
26 Nov 2008 18:12:00 233 472 A.... "C:\Program Files\Alwil Software\Avast4\ashSSqlt.dll"
26 Nov 2008 18:12:16 48 128 A.... "C:\Program Files\Alwil Software\Avast4\ashSXML.dll"
26 Nov 2008 18:11:44 118 784 A.... "C:\Program Files\Alwil Software\Avast4\ashTask.dll"
26 Nov 2008 18:13:12 327 680 A.... "C:\Program Files\Alwil Software\Avast4\ashUInt.dll"
26 Nov 2008 18:11:50 68 640 A.... "C:\Program Files\Alwil Software\Avast4\ashUpd.exe"
26 Nov 2008 18:16:24 352 920 A.... "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe"
26 Nov 2008 18:16:26 65 536 A.... "C:\Program Files\Alwil Software\Avast4\ashWsFtr.dll"
26 Nov 2008 18:11:36 659 456 A.... "C:\Program Files\Alwil Software\Avast4\aswAux.dll"
26 Nov 2008 18:09:14 131 072 A.... "C:\Program Files\Alwil Software\Avast4\aswCmnB.dll"
26 Nov 2008 18:09:10 86 016 A.... "C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll"
26 Nov 2008 18:09:20 192 512 A.... "C:\Program Files\Alwil Software\Avast4\aswCmnS.dll"
26 Nov 2008 18:11:22 1 269 760 A.... "C:\Program Files\Alwil Software\Avast4\aswEngin.dll"
26 Nov 2008 18:12:04 11 584 A.... "C:\Program Files\Alwil Software\Avast4\aswIdle.dll"
26 Nov 2008 18:11:08 22 528 A.... "C:\Program Files\Alwil Software\Avast4\aswInteg.dll"
26 Nov 2008 18:09:34 327 680 A.... "C:\Program Files\Alwil Software\Avast4\aswRawFS.dll"
26 Nov 2008 18:09:02 147 456 A.... "C:\Program Files\Alwil Software\Avast4\aswRes.dll"
26 Nov 2008 18:10:56 86 016 A.... "C:\Program Files\Alwil Software\Avast4\aswScan.dll"
26 Nov 2008 18:12:08 18 752 A.... "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
26 Nov 2008 18:17:00 106 496 A.... "C:\Program Files\Alwil Software\Avast4\avCommEx.dll"
26 Nov 2008 18:13:42 13 656 A.... "C:\Program Files\Alwil Software\Avast4\AVSSHOOK.dll"
26 Nov 2008 18:21:10 68 640 A.... "C:\Program Files\Alwil Software\Avast4\sched.exe"
26 Nov 2008 18:15:06 68 640 A.... "C:\Program Files\Alwil Software\Avast4\VisthAux.exe"
26 Nov 2008 18:15:14 53 280 A.... "C:\Program Files\Alwil Software\Avast4\VisthLic.exe"
26 Nov 2008 18:14:48 53 280 A.... "C:\Program Files\Alwil Software\Avast4\VisthUpd.exe"
26 Nov 2008 18:12:54 917 504 A.... "C:\Program Files\Alwil Software\Avast4\XT1922.dll"
19 Dec 2008 3:33:50 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1063.dll"
19 Dec 2008 3:34:22 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1071.dll"
19 Dec 2008 3:34:34 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1066.dll"
19 Dec 2008 3:34:30 22 016 A.... "C:\Program Files\CCleaner\Lang\lang-1050.dll"
19 Dec 2008 3:33:16 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1030.dll"
19 Dec 2008 3:33:40 23 552 A.... "C:\Program Files\CCleaner\Lang\lang-1040.dll"
19 Dec 2008 3:34:12 24 576 A.... "C:\Program Files\CCleaner\Lang\lang-1034.dll"
19 Dec 2008 3:33:54 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1044.dll"
19 Dec 2008 3:33:38 23 040 A.... "C:\Program Files\CCleaner\Lang\lang-1038.dll"
19 Dec 2008 3:33:10 11 776 A.... "C:\Program Files\CCleaner\Lang\lang-1028.dll"
19 Dec 2008 3:34:06 22 016 A.... "C:\Program Files\CCleaner\Lang\lang-1048.dll"
19 Dec 2008 3:33:28 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1110.dll"
19 Dec 2008 3:32:50 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1051.dll"
19 Dec 2008 3:34:12 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1055.dll"
19 Dec 2008 3:33:04 19 456 A.... "C:\Program Files\CCleaner\Lang\lang-1025.dll"
19 Dec 2008 3:33:22 23 040 A.... "C:\Program Files\CCleaner\Lang\lang-1035.dll"
19 Dec 2008 3:33:58 22 016 A.... "C:\Program Files\CCleaner\Lang\lang-1045.dll"
19 Dec 2008 3:33:12 20 480 A.... "C:\Program Files\CCleaner\Lang\lang-1029.dll"
19 Dec 2008 3:32:52 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-1052.dll"
19 Dec 2008 3:33:32 26 112 A.... "C:\Program Files\CCleaner\Lang\lang-1032.dll"
19 Dec 2008 3:33:48 11 776 A.... "C:\Program Files\CCleaner\Lang\lang-1042.dll"
19 Dec 2008 3:34:24 24 064 A.... "C:\Program Files\CCleaner\Lang\lang-1026.dll"
19 Dec 2008 3:33:26 24 576 A.... "C:\Program Files\CCleaner\Lang\lang-1036.dll"
19 Dec 2008 3:34:04 24 576 A.... "C:\Program Files\CCleaner\Lang\lang-1046.dll"
19 Dec 2008 3:33:18 24 576 A.... "C:\Program Files\CCleaner\Lang\lang-1043.dll"
19 Dec 2008 3:33:00 23 040 A.... "C:\Program Files\CCleaner\Lang\lang-1027.dll"
19 Dec 2008 3:33:34 18 944 A.... "C:\Program Files\CCleaner\Lang\lang-1037.dll"
19 Dec 2008 3:32:58 22 016 A.... "C:\Program Files\CCleaner\Lang\lang-1031.dll"
19 Dec 2008 3:33:44 14 848 A.... "C:\Program Files\CCleaner\Lang\lang-1041.dll"
19 Dec 2008 3:34:10 20 992 A.... "C:\Program Files\CCleaner\Lang\lang-1049.dll"
19 Dec 2008 3:32:54 22 016 A.... "C:\Program Files\CCleaner\Lang\lang-1053.dll"
19 Dec 2008 3:34:00 25 088 A.... "C:\Program Files\CCleaner\Lang\lang-2070.dll"
19 Dec 2008 3:33:06 11 776 A.... "C:\Program Files\CCleaner\Lang\lang-2052.dll"
19 Dec 2008 3:34:20 20 992 A.... "C:\Program Files\CCleaner\Lang\lang-2074.dll"
19 Dec 2008 3:34:16 20 992 A.... "C:\Program Files\CCleaner\Lang\lang-3098.dll"
19 Dec 2008 3:34:28 21 504 A.... "C:\Program Files\CCleaner\Lang\lang-5146.dll"
20 Dec 2008 19:18:58 719 104 A.... "C:\Program Files\Free Audio Pack\FreeConverter\FreeConverter.exe"
25 Jan 2009 12:05:20 29 774 A.... "C:\Program Files\HP\HP Software Update\Contents.dat"
30 Dec 2008 7:36:30 994 A.... "C:\Program Files\Java\jre6\Welcome.html"
15 Dec 2008 10:07:02 23 040 A.... "C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll"
15 Dec 2008 10:07:02 134 656 A.... "C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll"
30 Dec 2008 7:36:36 410 984 A.... "C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll"
15 Dec 2008 10:07:08 65 536 A.... "C:\Program Files\Mozilla Firefox\plugins\npnul32.dll"
15 Dec 2008 10:07:10 117 A.... "C:\Program Files\Mozilla Firefox\res\hiddenWindow.html"
15 Dec 2008 10:07:12 510 600 A.... "C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
15 Dec 2008 10:06:16 4 608 A.... "C:\Program Files\Vuze\.install4j\i4jdel.exe"
15 Dec 2008 10:06:16 108 544 A.... "C:\Program Files\Vuze\.install4j\i4jinst.dll"
15 Dec 2008 10:06:16 57 344 A.... "C:\Program Files\Vuze\.install4j\i4j_extf_8_5p83tu.dll"
15 Dec 2008 10:06:16 865 312 A.... "C:\Program Files\Vuze\.install4j\i4j_extf_12_5p83tu.exe"
15 Dec 2008 10:06:16 54 664 A.... "C:\Program Files\Vuze\.install4j\i4j_extf_7_5p83tu.exe"
15 Dec 2008 10:06:16 245 408 A.... "C:\Program Files\Vuze\.install4j\unicows.dll"
15 Dec 2008 10:06:16 22 528 A.... "C:\Program Files\Vuze\.install4j\_shfoldr.dll"
25 Jan 2009 18:54:58 245 800 A.... "C:\Program Files\Alwil Software\Avast4\DATA\aswar0.dll"
19 Jan 2009 21:25:30 245 800 A.... "C:\Program Files\Alwil Software\Avast4\DATA\aswar1.dll"
25 Jan 2009 18:54:58 391 216 A.... "C:\Program Files\Alwil Software\Avast4\DATA\clnr0.dll"
25 Jan 2009 18:54:58 309 912 A.... "C:\Program Files\Alwil Software\Avast4\DATA\dllcc0.dat"
25 Jan 2009 18:54:58 9 080 A.... "C:\Program Files\Alwil Software\Avast4\DATA\exts0.dll"
25 Jan 2009 18:53:44 70 766 A.... "C:\Program Files\Alwil Software\Avast4\DATA\iNews.htm"
26 Nov 2008 18:08:16 98 304 A.... "C:\Program Files\Alwil Software\Avast4\FRENCH\Base.dll"
26 Nov 2008 18:07:30 17 920 A.... "C:\Program Files\Alwil Software\Avast4\FRENCH\Boot.dll"
26 Nov 2008 18:08:16 2 572 288 A.... "C:\Program Files\Alwil Software\Avast4\FRENCH\Lang.dll"
26 Nov 2008 18:08:14 61 440 A.... "C:\Program Files\Alwil Software\Avast4\FRENCH\LangMai.dll"
28 Dec 2008 0:19:02 159 792 A.... "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll"
29 Nov 2008 13:08:40 2 356 088 A.... "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
29 Nov 2008 12:21:22 82 808 A.... "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdaterInstallMgr.exe"
31 Dec 2008 13:25:34 20 A.... "C:\Program Files\Common Files\Sony Shared\OpenMG\icv.dat"
31 Dec 2008 13:25:34 4 964 A.... "C:\Program Files\Common Files\Sony Shared\OpenMG\maclist1.dat"
31 Dec 2008 13:25:34 4 964 A.... "C:\Program Files\Common Files\Sony Shared\OpenMG\maclist2.dat"
30 Dec 2008 7:36:30 1 130 496 A.... "C:\Program Files\Java\jre6\bin\awt.dll"
30 Dec 2008 7:36:30 110 592 A.... "C:\Program Files\Java\jre6\bin\axbridge.dll"
30 Dec 2008 7:36:32 192 512 A.... "C:\Program Files\Java\jre6\bin\cmm.dll"
30 Dec 2008 7:36:32 143 360 A.... "C:\Program Files\Java\jre6\bin\dcpr.dll"
30 Dec 2008 7:36:32 77 824 A.... "C:\Program Files\Java\jre6\bin\deploy.dll"
30 Dec 2008 7:36:32 410 984 A.... "C:\Program Files\Java\jre6\bin\deploytk.dll"
30 Dec 2008 7:36:32 16 896 A.... "C:\Program Files\Java\jre6\bin\dt_shmem.dll"
30 Dec 2008 7:36:32 13 312 A.... "C:\Program Files\Java\jre6\bin\dt_socket.dll"
30 Dec 2008 7:36:32 339 968 A.... "C:\Program Files\Java\jre6\bin\fontmanager.dll"
30 Dec 2008 7:36:32 15 872 A.... "C:\Program Files\Java\jre6\bin\hpi.dll"
30 Dec 2008 7:36:32 139 264 A.... "C:\Program Files\Java\jre6\bin\hprof.dll"
30 Dec 2008 7:36:32 98 304 A.... "C:\Program Files\Java\jre6\bin\instrument.dll"
30 Dec 2008 7:36:32 12 800 A.... "C:\Program Files\Java\jre6\bin\ioser12.dll"
30 Dec 2008 7:36:32 7 680 A.... "C:\Program Files\Java\jre6\bin\j2pcsc.dll"
30 Dec 2008 7:36:32 37 376 A.... "C:\Program Files\Java\jre6\bin\j2pkcs11.dll"
30 Dec 2008 7:36:34 10 240 A.... "C:\Program Files\Java\jre6\bin\jaas_nt.dll"
30 Dec 2008 7:36:34 32 664 A.... "C:\Program Files\Java\jre6\bin\java-rmi.exe"
30 Dec 2008 7:36:34 126 976 A.... "C:\Program Files\Java\jre6\bin\java.dll"
30 Dec 2008 7:36:34 144 792 A.... "C:\Program Files\Java\jre6\bin\java.exe"
30 Dec 2008 7:36:34 58 776 A.... "C:\Program Files\Java\jre6\bin\javacpl.exe"
30 Dec 2008 7:36:34 144 792 A.... "C:\Program Files\Java\jre6\bin\javaw.exe"
30 Dec 2008 7:36:34 148 888 A.... "C:\Program Files\Java\jre6\bin\javaws.exe"
30 Dec 2008 7:36:34 14 336 A.... "C:\Program Files\Java\jre6\bin\java_crw_demo.dll"
30 Dec 2008 7:36:34 5 120 A.... "C:\Program Files\Java\jre6\bin\jawt.dll"
30 Dec 2008 7:36:34 79 256 A.... "C:\Program Files\Java\jre6\bin\jbroker.exe"
30 Dec 2008 7:36:34 36 352 A.... "C:\Program Files\Java\jre6\bin\JdbcOdbc.dll"
30 Dec 2008 7:36:34 167 936 A.... "C:\Program Files\Java\jre6\bin\jdwp.dll"
30 Dec 2008 7:36:34 274 432 A.... "C:\Program Files\Java\jre6\bin\jkernel.dll"
30 Dec 2008 7:36:34 77 824 A.... "C:\Program Files\Java\jre6\bin\jli.dll"
30 Dec 2008 7:36:34 94 208 A.... "C:\Program Files\Java\jre6\bin\jp2iexp.dll"
30 Dec 2008 7:36:34 22 424 A.... "C:\Program Files\Java\jre6\bin\jp2launcher.exe"
30 Dec 2008 7:36:34 8 192 A.... "C:\Program Files\Java\jre6\bin\jp2native.dll"
30 Dec 2008 7:36:34 34 816 A.... "C:\Program Files\Java\jre6\bin\jp2ssv.dll"
30 Dec 2008 7:36:34 147 456 A.... "C:\Program Files\Java\jre6\bin\jpeg.dll"
30 Dec 2008 7:36:34 98 304 A.... "C:\Program Files\Java\jre6\bin\jpicom.dll"
30 Dec 2008 7:36:34 110 592 A.... "C:\Program Files\Java\jre6\bin\jpiexp.dll"
30 Dec 2008 7:36:34 98 304 A.... "C:\Program Files\Java\jre6\bin\jpinscp.dll"
30 Dec 2008 7:36:34 65 536 A.... "C:\Program Files\Java\jre6\bin\jpioji.dll"
30 Dec 2008 7:36:34 122 880 A.... "C:\Program Files\Java\jre6\bin\jpishare.dll"
30 Dec 2008 7:36:34 152 984 A.... "C:\Program Files\Java\jre6\bin\jqs.exe"
30 Dec 2008 7:36:34 54 680 A.... "C:\Program Files\Java\jre6\bin\jqsnotify.exe"
30 Dec 2008 7:36:34 147 456 A.... "C:\Program Files\Java\jre6\bin\jsound.dll"
30 Dec 2008 7:36:34 18 432 A.... "C:\Program Files\Java\jre6\bin\jsoundds.dll"
30 Dec 2008 7:36:34 382 384 A.... "C:\Program Files\Java\jre6\bin\jucheck.exe"
30 Dec 2008 7:36:36 54 680 A.... "C:\Program Files\Java\jre6\bin\jureg.exe"
30 Dec 2008 7:36:36 136 600 A.... "C:\Program Files\Java\jre6\bin\jusched.exe"
30 Dec 2008 7:36:36 33 176 A.... "C:\Program Files\Java\jre6\bin\keytool.exe"
30 Dec 2008 7:36:36 33 176 A.... "C:\Program Files\Java\jre6\bin\kinit.exe"
30 Dec 2008 7:36:36 33 176 A.... "C:\Program Files\Java\jre6\bin\klist.exe"
30 Dec 2008 7:36:36 33 176 A.... "C:\Program Files\Java\jre6\bin\ktab.exe"
30 Dec 2008 7:36:36 18 432 A.... "C:\Program Files\Java\jre6\bin\management.dll"
30 Dec 2008 7:36:36 602 112 A.... "C:\Program Files\Java\jre6\bin\mlib_image.dll"
30 Dec 2008 7:36:36 348 160 A.... "C:\Program Files\Java\jre6\bin\msvcr71.dll"
30 Dec 2008 7:36:36 266 293 A.... "C:\Program Files\Java\jre6\bin\msvcrt.dll"
30 Dec 2008 7:36:36 77 824 A.... "C:\Program Files\Java\jre6\bin\net.dll"
30 Dec 2008 7:36:36 20 480 A.... "C:\Program Files\Java\jre6\bin\nio.dll"
30 Dec 2008 7:36:36 410 984 A.... "C:\Program Files\Java\jre6\bin\npdeploytk.dll"
30 Dec 2008 7:36:36 132 504 A.... "C:\Program Files\Java\jre6\bin\npjpi160_11.dll"
30 Dec 2008 7:36:36 126 976 A.... "C:\Program Files\Java\jre6\bin\npoji610.dll"
30 Dec 2008 7:36:38 8 192 A.... "C:\Program Files\Java\jre6\bin\npt.dll"
30 Dec 2008 7:36:38 33 176 A.... "C:\Program Files\Java\jre6\bin\orbd.exe"
30 Dec 2008 7:36:38 33 176 A.... "C:\Program Files\Java\jre6\bin\pack200.exe"
30 Dec 2008 7:36:38 33 176 A.... "C:\Program Files\Java\jre6\bin\policytool.exe"
30 Dec 2008 7:36:38 5 120 A.... "C:\Program Files\Java\jre6\bin\rmi.dll"
30 Dec 2008 7:36:38 33 176 A.... "C:\Program Files\Java\jre6\bin\rmid.exe"
30 Dec 2008 7:36:38 33 176 A.... "C:\Program Files\Java\jre6\bin\rmiregistry.exe"
30 Dec 2008 7:36:38 33 176 A.... "C:\Program Files\Java\jre6\bin\servertool.exe"
30 Dec 2008 7:36:38 131 072 A.... "C:\Program Files\Java\jre6\bin\splashscreen.dll"
30 Dec 2008 7:36:38 320 920 A.... "C:\Program Files\Java\jre6\bin\ssv.dll"
30 Dec 2008 7:36:38 17 816 A.... "C:\Program Files\Java\jre6\bin\ssvagent.exe"
30 Dec 2008 7:36:38 16 384 A.... "C:\Program Files\Java\jre6\bin\sunmscapi.dll"
30 Dec 2008 7:36:38 33 176 A.... "C:\Program Files\Java\jre6\bin\tnameserv.exe"
30 Dec 2008 7:36:38 245 400 A.... "C:\Program Files\Java\jre6\bin\unicows.dll"
30 Dec 2008 7:36:38 61 440 A.... "C:\Program Files\Java\jre6\bin\unpack.dll"
30 Dec 2008 7:36:38 128 408 A.... "C:\Program Files\Java\jre6\bin\unpack200.exe"
30 Dec 2008 7:36:38 31 744 A.... "C:\Program Files\Java\jre6\bin\verify.dll"
30 Dec 2008 7:36:38 24 701 A.... "C:\Program Files\Java\jre6\bin\w2k_lsa_auth.dll"
30 Dec 2008 7:36:38 110 592 A.... "C:\Program Files\Java\jre6\bin\wsdetect.dll"
30 Dec 2008 7:36:38 47 104 A.... "C:\Program Files\Java\jre6\bin\zip.dll"
15 Dec 2008 10:07:06 7 142 A.... "C:\Program Files\Mozilla Firefox\defaults\profile\bookmarks.html"
15 Dec 2008 10:07:52 2 619 426 A.... "C:\Program Files\Vuze\plugins\azemp\azemp_2.0.32.zip"
15 Dec 2008 10:07:52 5 472 734 A.... "C:\Program Files\Vuze\plugins\azemp\azmplay.exe"
26 Nov 2008 18:15:36 26 944 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\Aavmker4.sys"
26 Nov 2008 18:17:26 20 560 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\aswFsBlk.sys"
26 Nov 2008 18:18:26 93 296 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMon.sys"
26 Nov 2008 18:18:18 94 032 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMon2.sys"
26 Nov 2008 18:17:16 51 792 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\aswMonFlt.sys"
26 Nov 2008 18:16:30 23 152 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AswRdr.sys"
26 Nov 2008 18:17:36 111 184 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\aswSP.sys"
26 Nov 2008 18:16:38 50 864 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AswTdi.sys"
30 Dec 2008 7:36:32 2 359 296 A.... "C:\Program Files\Java\jre6\bin\client\jvm.dll"
30 Dec 2008 7:36:36 348 160 A.... "C:\Program Files\Java\jre6\bin\new_plugin\msvcr71.dll"
30 Dec 2008 7:36:36 410 984 A.... "C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll"
30 Dec 2008 7:36:36 65 536 A.... "C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll"
30 Dec 2008 7:36:38 16 801 A.... "C:\Program Files\Java\jre6\lib\deploy\ffjcext.zip"
30 Dec 2008 7:36:38 152 576 A.... "C:\Program Files\Java\jre6\lib\deploy\lzma.dll"
26 Nov 2008 18:15:40 25 168 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\Aavmker4.sys"
26 Nov 2008 18:17:30 22 096 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswFsBlk.sys"
26 Nov 2008 18:18:22 75 856 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswMon2.sys"
26 Nov 2008 18:17:24 64 592 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswMonFlt.sys"
26 Nov 2008 18:16:32 27 216 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswRdr.sys"
26 Nov 2008 18:17:50 89 168 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswSP.sys"
26 Nov 2008 18:16:42 57 936 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\AMD64\aswTdi.sys"
26 Nov 2008 18:17:28 37 968 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswFsBlk.sys"
26 Nov 2008 18:17:20 140 368 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswMonFlt.sys"
26 Nov 2008 18:16:34 55 376 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswRdr.sys"
26 Nov 2008 18:17:44 168 016 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswSP.sys"
26 Nov 2008 18:16:44 126 544 A.... "C:\Program Files\Alwil Software\Avast4\Setup\INF\IA64\aswTdi.sys"
30 Dec 2008 7:36:38 73 728 A.... "C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll"


Files with hidden attributes:

Thu 2 Nov 2006 524,288 A.SH. --- "C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
Thu 2 Nov 2006 524,288 A.SH. --- "C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
Mon 19 Jan 2009 524,288 A.SH. --- "C:\Users\Jean\ntuser.dat{8a1bb9f3-e66a-11dd-ae8c-001b24bcfba5}.TMContainer00000000000000000001.regtrans-ms"
Mon 19 Jan 2009 524,288 A.SH. --- "C:\Users\Jean\ntuser.dat{8a1bb9f3-e66a-11dd-ae8c-001b24bcfba5}.TMContainer00000000000000000002.regtrans-ms"
Fri 8 Feb 2008 524,288 A.SH. --- "C:\Users\Jean\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
Fri 8 Feb 2008 524,288 A.SH. --- "C:\Users\Jean\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
Mon 17 Nov 2008 524,288 A.SH. --- "C:\Users\Jean\ntuser.dat{1b138c86-b499-11dd-8672-001b24bcfba5}.TMContainer00000000000000000001.regtrans-ms"
Mon 17 Nov 2008 524,288 A.SH. --- "C:\Users\Jean\ntuser.dat{1b138c86-b499-11dd-8672-001b24bcfba5}.TMContainer00000000000000000002.regtrans-ms"
Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
Sun 5 Oct 2008 4,348 A.SH. --- "C:\ProgramData\Microsoft\Windows\DRM\DRMv1.bak"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\0aabbcc4513bb089c02b7acf85b2e2a6\BITB1D.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\0b2a5d3729102bcb5f9c439959308769\BITABF.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\0bd4a26dfe5022e596017f8e60c3a146\BITB9EA.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\181f20742d7a06495060916ec54125e6\BITB409.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\1948a194d707791595d98a3a5efd9474\BITB3BA.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\2a31037e43e8b46c68a61c9917fe8b76\BITBB93.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\3155412f64c3a98cffde3a594ff64de3\BITB34B.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\330b3bd669ac05283ff55af103ae13c7\BITE69.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\60320e1ac6a2029bdd1c27c55030226a\BITBA88.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\689110a199f9585d29ed2a2af4026976\BITB2ED.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\6ea446189eb7b4a6a327f0701a421fd0\BITB478.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\7be372b0ed44236e5738808b5bc9c620\BITB37B.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\87313842df3a2315ff55b79b5bac1a83\BITB23E.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\9064aeb183e12468f105e099436d1375\BITB506.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\9de4903f01b4008e08b567e41ba8107e\BITBA29.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\b15f12905daf2d5f4bb1d398773d75a0\BITBAF6.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\b4c69ff8f33fa7dd5264c611efa9e416\BITBC21.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\cf4e1dbdcf095ab07744ae90d61e99dc\BITB729.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\d2dde36955ee80cd2f8313b4669191da\BITB28E.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\d3be1c9286afce88253c06caef847d99\BITB4B7.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\dc1d8ccec91deada1441910fe3c741ba\BITB7F6.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\dcfb3f0fee0b76240a4ce7e93515b1e3\BITB788.tmp"
Tue 30 Dec 2008 0 A..H. --- "C:\Windows\SoftwareDistribution\Download\deb185b7c3743a27be869545db996079\BITB25E.tmp"
Thu 24 Nov 2005 524,288 A.SH. --- "C:\Windows\System32\config\systemprofile\ntuser.dat{6bd0e5c9-5d26-11da-a2ca-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms"
Thu 24 Nov 2005 524,288 A.SH. --- "C:\Windows\System32\config\systemprofile\ntuser.dat{6bd0e5c9-5d26-11da-a2ca-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms"
Sun 14 Dec 2008 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms"
Mon 10 Nov 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms"
Sat 6 Dec 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms"
Sun 25 Jan 2009 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms"
Wed 17 Sep 2008 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms"
Sun 25 Jan 2009 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms"
Mon 19 Jan 2009 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms"
Sat 27 Dec 2008 0 A.SH. --- "C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp"
Sun 5 Oct 2008 4,348 A.SH. --- "C:\Users\All Users\Microsoft\Windows\DRM\DRMv1.bak"
Sat 22 Nov 2008 524,288 A.SH. --- "C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
Sat 27 Dec 2008 0 A.SH. --- "C:\Users\All Users\Microsoft\Windows\DRM\Cache\Indiv01.tmp"
Fri 8 Feb 2008 524,288 A.SH. --- "C:\Users\Jean\AppData\Local\Microsoft\Windows\UsrClass.dat{26cd4a05-d60b-11dc-8be1-001b24bcfba5}.TMContainer00000000000000000001.regtrans-ms"
Fri 8 Feb 2008 524,288 A.SH. --- "C:\Users\Jean\AppData\Local\Microsoft\Windows\UsrClass.dat{26cd4a05-d60b-11dc-8be1-001b24bcfba5}.TMContainer00000000000000000002.regtrans-ms"
Fri 9 Jan 2009 1,400,304 A..H. --- "C:\Users\Jean\AppData\Local\Google\Update\Download\BITEA6C.tmp"
Mon 11 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat{669c735c-d87f-11dc-8ece-001b24bcfba5}.TMContainer00000000000000000001.regtrans-ms"
Mon 11 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat{669c735c-d87f-11dc-8ece-001b24bcfba5}.TMContainer00000000000000000002.regtrans-ms"
Tue 12 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat{bc057486-d972-11dc-afc0-001b24bcfba5}.TMContainer00000000000000000001.regtrans-ms"
Tue 12 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat{bc057486-d972-11dc-afc0-001b24bcfba5}.TMContainer00000000000000000002.regtrans-ms"
Tue 12 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat{bc05748a-d972-11dc-afc0-001b24bcfba5}.TMContainer00000000000000000001.regtrans-ms"
Tue 12 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat{bc05748a-d972-11dc-afc0-001b24bcfba5}.TMContainer00000000000000000002.regtrans-ms"
Tue 12 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat{bc057491-d972-11dc-afc0-001b24bcfba5}.TMContainer00000000000000000001.regtrans-ms"
Tue 12 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat{bc057491-d972-11dc-afc0-001b24bcfba5}.TMContainer00000000000000000002.regtrans-ms"


Program Folders:

C:\Program Files\

Adobe
Alwil Software
Apple Software Update
Audacity
CCleaner
Common Files
DivX
DVD Audio Extractor
EasyBits
EasyBits For Kids
ffdshow
Fichiers communs
Free Audio Pack
fxc
Hewlett-Packard
HP
HPQ
InstallShield Installation Information
Intel
Internet Explorer
iPod
iTunes
Java
Lavasoft
Ma‹do Production
Malwarebytes' Anti-Malware
Microsoft CAPICOM 2.1.0.2
Microsoft Games
Microsoft Office 2003
Microsoft Silverlight
Microsoft Works
Microsoft.NET
Motorola
Movie Maker
Mozilla Firefox
MSBuild
MSN
MSXML 4.0
NeoDivX2008
Neuf
OpenOffice.org 2.3
Opera
Quark
QuickTime
Realtek
Reference Assemblies
Roxio
Samsung
Services en ligne
Sony
Synaptics
Uninstall Information
Vuze
Wallpaper
WinASPI
Windows Calendar
Windows Collaboration
Windows Defender
Windows Journal
Windows Live
Windows Mail
Windows Media Player
Windows NT
Windows Photo Gallery
Windows Sidebar
x264
Xvid

C:\Program Files\Common Files\

Adobe
Apple
DESIGNER
Hewlett-Packard
HP
InstallShield
Java
LightScribe
microsoft shared
PX Storage Engine
Roxio Shared
Services
Sonic Shared
Sony Shared
SpeechEngines
SureThing Shared
Symantec Shared
System
WindowsLiveInstaller
Wise Installation Wizard


Add/Remove Programs:

Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Audacity 1.2.6
avast! Antivirus
CCleaner (remove only)
Compel Adaptec WinASPI
DVD Audio Extractor 4.5.0
ffdshow [rev 2060] [2008-08-01]
Free Mp3 Wma Converter V 1.8.0
HijackThis 2.0.2
Microsoft Office Home and Student 2007
HP Imaging Device Functions 8.0
HP Photosmart Essential 2.0
HP Solution Center 8.0
HP Customer Participation Program 8.0
HP OCR Software 8.0
OpenMG Secure Module 4.7.00
Security Update for CAPICOM (KB931906)
Malwarebytes' Anti-Malware
mmFollow
Mozilla Firefox (3.0.4)
NeoDivx 2008
TV sur PC
NVIDIA Drivers
OpenMG Limited Patch 4.7-07-14-05-01
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem Software
SAMSUNG Mobile USB Modem 1.0 Software
Motorola SM56 Data Fax Modem
Synaptics Pointing Device Driver
Vuze
Wallpaper
x264 Revision 305 x264.nl (remove only)
Xvid 1.1.3 final uninstall
Roxio Creator Tools
HP Doc Viewer
PSSWCORE
AIO_Scan
Roxio Creator Data
Security Update for CAPICOM (KB931906)
Roxio Creator EasyArchive
Scan
WebReg
AutoUpdate
Hewlett-Packard Active Check
Java(TM) 6 Update 11
HP Active Support Library
DHTML Editing Component
Java(TM) SE Runtime Environment 6
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
MSCU for Microsoft Vista
Roxio MyDVD Basic v9
HP Quick Launch Buttons 6.20 B1
Roxio Activation Module
HP Easy Setup - Frontend
iTunes
Samsung PC Studio 3
IziSpot 4.10
HP QuickPlay 3.2
DocProc
Samsung PC Studio
HP Pavilion Webcam Driver for Vista v061.001.00006
Roxio Creator Copy
Roxio Express Labeler 3
Hewlett-Packard Asset Agent
eSupportQFolder
HPProductAssistant
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Apple Software Update
Windows Media Player Firefox Plugin
Microsoft Works
CustomerResearchQFolder
HP Update
Fax
DivX Codec
Roxio Creator Audio
DocProcQFolder
Microsoft Silverlight
DivX Player
HP Photosmart Essential2.5
QuickTime
Microsoft Office Professional Edition 2003
Microsoft Office Excel MUI (French) 2007
Microsoft Office PowerPoint MUI (French) 2007
Microsoft Office Word MUI (French) 2007
Microsoft Office Proof (Arabic) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Dutch) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (French) 2007
Microsoft Office Shared MUI (French) 2007
Microsoft Office OneNote MUI (French) 2007
HP Help and Support
Intel Matrix Storage Manager
Microsoft Office Home and Student 2007
Security Update for Office 2007 (KB947801)
Security Update for Office 2007 (KB934062)
Security Update for the 2007 Microsoft Office System (KB936960)
Security Update for Excel 2007 (KB946974)
Security Update for Microsoft Office system 2007 (KB951808)
Update for Office 2007 (KB946691)
Security Update for Microsoft Office Word 2007 (KB950113)
Update for Office 2007 (KB932080)
MarketResearch
Status
Destinations
SonicStage 4.3
SolutionCenter
QuarkXPress 7.5
Copy
LightScribe 1.4.136.1
Apple Mobile Device Support
DeviceManagementQFolder
HP Customer Experience Enhancements
Adobe Reader 8.1.2 - Français
Assistant de connexion Windows Live
OpenOffice.org 2.3
DivX Converter
Windows Live Messenger
BufferChm
MSXML 4.0 SP2 (KB936181)
Samsung PC Studio 3
MSXML 4.0 SP2 (KB941833)
Toolbox
Roxio Creator Basic v9
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
OpenMG Secure Module 4.7.00
HP Wireless Assistant
ESU for Microsoft Vista
HP User Guides 0057
Ad-Aware
UnloadSupport
AIO_CDB_Software
2570_Help
AIO_CDB_ProductContext
2570
HP Photosmart Essential
HPSSupply
Realtek High Definition Audio Driver
32 Bit HP CIO Components Installer
2570Trb
HP Active Support Library 32 bit components
Windows Live installer
TrayApp
Google Chrome


Run Values:

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Windows Defender"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
00,69,00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\
73,00,20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,4d,00,53,\
00,41,00,53,00,43,00,75,00,69,00,2e,00,65,00,78,00,65,00,20,00,2d,00,68,00,\
69,00,64,00,65,00,00,00
"SMSERIAL"="C:\\Program Files\\Motorola\\SMSERIAL\\sm56hlpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"RtHDVCpl"="RtHDVCpl.exe"
"IAAnotif"="C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe"
"QPService"="\"C:\\Program Files\\HP\\QuickPlay\\QPService.exe\""
"QlbCtrl"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,00,\
6c,00,65,00,73,00,25,00,5c,00,48,00,65,00,77,00,6c,00,65,00,74,00,74,00,2d,\
00,50,00,61,00,63,00,6b,00,61,00,72,00,64,00,5c,00,48,00,50,00,20,00,51,00,\
75,00,69,00,63,00,6b,00,20,00,4c,00,61,00,75,00,6e,00,63,00,68,00,20,00,42,\
00,75,00,74,00,74,00,6f,00,6e,00,73,00,5c,00,51,00,6c,00,62,00,43,00,74,00,\
72,00,6c,00,2e,00,65,00,78,00,65,00,20,00,2f,00,53,00,74,00,61,00,72,00,74,\
00,00,00
"HP Health Check Scheduler"="C:\\Program Files\\Hewlett-Packard\\HP Health Check\\HPHC_Scheduler.exe"
"hpWirelessAssistant"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,\
46,00,69,00,6c,00,65,00,73,00,25,00,5c,00,48,00,65,00,77,00,6c,00,65,00,74,\
00,74,00,2d,00,50,00,61,00,63,00,6b,00,61,00,72,00,64,00,5c,00,48,00,50,00,\
20,00,57,00,69,00,72,00,65,00,6c,00,65,00,73,00,73,00,20,00,41,00,73,00,73,\
00,69,00,73,00,74,00,61,00,6e,00,74,00,5c,00,48,00,50,00,57,00,41,00,4d,00,\
61,00,69,00,6e,00,2e,00,65,00,78,00,65,00,00,00
"WAWifiMessage"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,\
69,00,6c,00,65,00,73,00,25,00,5c,00,48,00,65,00,77,00,6c,00,65,00,74,00,74,\
00,2d,00,50,00,61,00,63,00,6b,00,61,00,72,00,64,00,5c,00,48,00,50,00,20,00,\
57,00,69,00,72,00,65,00,6c,00,65,00,73,00,73,00,20,00,41,00,73,00,73,00,69,\
00,73,00,74,00,61,00,6e,00,74,00,5c,00,57,00,69,00,46,00,69,00,4d,00,73,00,\
67,00,2e,00,65,00,78,00,65,00,00,00
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre6\\bin\\jusched.exe\""
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"NvSvc"="RUNDLL32.EXE C:\\Windows\\system32\\nvsvc.dll,nvsvcStart"
"NvCplDaemon"="RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
@=""
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
@=""
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
@=""
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Sidebar"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"
"Google Update"="\"C:\\Users\\Jean\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c"
"Wallpaper"="\"C:\\Program Files\\Wallpaper\\Wallpaper.exe\" Starter"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"RocketDock"="\"C:\\Program Files\\RocketDock\\RocketDock.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"Launcher"=hex(2):25,00,57,00,49,00,4e,00,44,00,49,00,52,00,25,00,5c,00,53,00,\
4d,00,49,00,4e,00,53,00,54,00,5c,00,6c,00,61,00,75,00,6e,00,63,00,68,00,65,\
00,72,00,2e,00,65,00,78,00,65,00,00,00


Bot Check:

SERVICE_NAME: wscsvc
DISPLAY_NAME : Centre de sécurité
START_TYPE : 2 AUTO_START

SERVICE_NAME: sharedaccess
DISPLAY_NAME : Partage de connexion Internet (ICS)
START_TYPE : 4 DISABLED

SERVICE_NAME: wuauserv
DISPLAY_NAME : Windows Update
START_TYPE : 2 AUTO_START

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"EnableDCOM"="Y"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"restrictanonymous"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"AUOptions"=dword:00000002

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UacDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000000
"AntiSpywareOverride"=dword:00000000
"FirewallOverride"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"WaitToKillServiceTimeout"="20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
"Userinit"="C:\\Windows\\system32\\userinit.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions]


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters]
"TransportBindName"="\\Device\\"


ShellExecuteHooks:


Environment:


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\environment
ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe
OS REG_SZ Windows_NT
Path REG_EXPAND_SZ %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Samsung\Samsung PC Studio 3\
PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.
Voir le profil de l'utilisateur Envoyer un message privé
Nicokid



Inscrit le: 18 Jan 2009
Messages: 14

MessagePosté le: Dim Jan 25, 2009 6:49 pm    Sujet du message: - : PC infecté par divers virus (chevaux de troie, adware) Répondre en citant

Bon il manque la fin du premier rapport, que voici :

SecurityProviders:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders
SecurityProviders REG_SZ credssp.dll


Authentication Packages:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0


Subsystem Startup:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems]
"Windows"="%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16"


Midi Drivers:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midi"="wdmaud.drv"


Non-Default IFEO Debugger:


Non-Default Installed Components:


Non-Default Safeboot Minimal:


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\appinfo
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\keyiso
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\ntds
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\profsvc
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sacsvr
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\swprv
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\tabletinputservice
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\tbs
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\trustedinstaller
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\volmgr.sys
<NO NAME> REG_SZ Driver


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\volmgrx.sys
<NO NAME> REG_SZ Driver


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\windefend
<NO NAME> REG_SZ Service


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{6bdd1fc1-810f-11d0-bec7-08002be2092f}
<NO NAME> REG_SZ IEEE 1394 Bus host controllers


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{d48179be-ec20-11d1-b6b8-00c04fa372a7}
<NO NAME> REG_SZ SBP2 IEEE 1394 Devices


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}
<NO NAME> REG_SZ SecurityDevices


File Associations:


[HKEY_CLASSES_ROOT\batfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\cmdfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\comfile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"
"IsolatedCommand"="\"%1\" %*"

[HKEY_CLASSES_ROOT\htafile\shell\open\command]
@="C:\\Windows\\system32\\mshta.exe \"%1\" %*"

[HKEY_CLASSES_ROOT\-\shell\open\command]
@="\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -requestPending -osint -url \"%1\""

[HKEY_CLASSES_ROOT\htmlfile\shell\open\command]
@="\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" -nohome"

[HKEY_CLASSES_ROOT\regedit\shell\open\command]
@="regedit.exe \"%1\""

[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@="regedit.exe \"%1\""

[HKEY_CLASSES_ROOT\scrfile\shell\open\command]
@="\"%1\" /S"

[HKEY_CLASSES_ROOT\txtfile\shell\open\command]
@="%SystemRoot%\system32\NOTEPAD.EXE %1"


Finished!
Voir le profil de l'utilisateur Envoyer un message privé


Montrer les messages depuis:   
Poster un nouveau sujet   Répondre au sujet    GsiteG Index du Forum -> Sécurité Toutes les heures sont au format GMT
Aller à la page 1, 2  Suivante
Page 1 sur 2

 
Sauter vers:  

discussions similaires
anti virus
infecté parWorm
Gros Virus
Utilitaires virus
gros virus help!!!!
anti virus kaspersky
[UP]Kaspersky Rescue Disk Anti-Virus v10.0.23.14
les virus


Powered by phpBB © 2001, 2005 phpBB Group
Traduction par : phpBB-fr.com

phpBB SEO


Articles OuedZem | Gagner de l'argent | Webdesigner | Forum informatique | Sapeurs-pompiers

Copyright © 2007 www.GsiteG.com - Tous droits réservés