bitdefender est entrain de se faire, mais il enest même pas au quart donc il va falloir patienter.
Voici le rapport de suspect file :
SystemScan - www.suspectfile.com - ver. 3.1.2
Running on: Windows XP HOME Edition, Service Pack 2 (2600.5.1)
System directory: C:\WINDOWS
Date: 2007-06-29
Time: 15:58:19
Output limited to:
-Recent files
-Registry Run Keys
===================== Recent files (60 days old)=====================
----- recent files in C:\
22-06-2007 09:38:14 (DIR) 0 byte 7 days old -- Team17
22-06-2007 12:25:46 (DIR) 0 byte 7 days old -- MyCloneDVD
22-06-2007 12:25:46 (DIR) 0 byte 7 days old -- TempSDVDClone
22-06-2007 16:20:59 303 byte 7 days old -- Cleanup.txt
22-06-2007 16:33:53 7598 byte 7 days old -- caisslog.txt
23-06-2007 21:27:07 36864 byte 6 days old -- t220
23-06-2007 21:55:19 126976 byte 6 days old -- t220.1
24-06-2007 11:53:58 5622 byte 5 days old -- MACDR001.CST
27-06-2007 11:29:07 (DIR) 0 byte 2 days old -- Config.Msi
28-06-2007 11:02:17 2043 byte 1 days old -- fixnavi.txt
28-06-2007 11:08:11 (DIR) 0 byte 1 days old -- Documents and Settings
28-06-2007 11:09:51 (DIR) 0 byte 1 days old -- RECYCLER
28-06-2007 11:29:52 1906 byte 1 days old -- rapport.txt
29-06-2007 14:17:33 64 byte 0 days old -- ComboFix.txt.bat
29-06-2007 14:22:56 (DIR) 0 byte 0 days old -- QooBox
29-06-2007 14:25:29 (DIR) 0 byte 0 days old -- ComboFix
29-06-2007 15:06:40 (DIR) 0 byte 0 days old -- Downloads
29-06-2007 15:16:45 (DIR) 0 byte 0 days old -- Program Files
29-06-2007 15:34:38 291 byte 0 days old -- BOOT.INI
29-06-2007 15:35:50 (DIR) 0 byte 0 days old -- VundoFix Backups
29-06-2007 15:36:52 2727 byte 0 days old -- VundoFix.txt
29-06-2007 15:37:47 150994944 byte 0 days old -- pagefile.sys
29-06-2007 15:43:09 13004 byte 0 days old -- lop.txt
29-06-2007 15:53:20 (DIR) 0 byte 0 days old -- WINDOWS
29-06-2007 15:58:19 (DIR) 0 byte 0 days old -- suspectfile
----- recent files in C:\WINDOWS\
03-06-2007 21:57:28 130 byte 26 days old -- Merrills.cfg
05-06-2007 05:24:03 87552 byte 24 days old -- catchme.exe
19-05-2007 19:23:56 (DIR) 0 byte 41 days old -- Minidump
19-05-2007 23:31:17 (DIR) 0 byte 41 days old -- WinSxS
27-05-2007 18:28:50 1156 byte 33 days old -- mozver.dat
13-06-2007 11:39:20 (DIR) 0 byte 16 days old -- $hf_mig$
17-06-2007 23:47:50 (DIR) 0 byte 12 days old -- Debug
19-06-2007 10:44:48 316640 byte 10 days old -- WMSysPr9.prx
20-06-2007 02:43:41 (DIR) 0 byte 9 days old -- Help
22-06-2007 09:46:16 239 byte 7 days old -- SIERRA.INI
22-06-2007 10:24:54 396 byte 7 days old -- Ulead32.ini
22-06-2007 10:24:57 52 byte 7 days old -- pex.INI
22-06-2007 12:31:11 (DIR) 0 byte 7 days old -- system
22-06-2007 13:51:11 0 byte 7 days old -- sectors.txt
22-06-2007 15:02:23 (DIR) 0 byte 7 days old -- pss
22-06-2007 15:28:35 (DIR) 0 byte 7 days old -- PIF
22-06-2007 15:33:58 0 byte 7 days old -- pestpatrol5.INI
25-06-2007 21:28:25 71906 byte 4 days old -- call.exe
25-06-2007 23:37:40 40960 byte 4 days old -- retadpu1000627.exe.ren
27-06-2007 10:23:46 54156 byte 2 days old -- QTFont.qfn
27-06-2007 10:23:46 1409 byte 2 days old -- QTFont.for
27-06-2007 11:27:53 (DIR) 0 byte 2 days old -- Installer
29-06-2007 14:17:20 (DIR) 0 byte 0 days old -- Prefetch
29-06-2007 14:25:27 (DIR) 0 byte 0 days old -- Tasks
29-06-2007 15:23:21 32606 byte 0 days old -- SchedLgU.Txt
29-06-2007 15:34:38 633 byte 0 days old -- win.ini
29-06-2007 15:34:38 227 byte 0 days old -- system.ini
29-06-2007 15:37:49 2048 byte 0 days old -- bootstat.dat
29-06-2007 15:38:17 50 byte 0 days old -- wiaservc.log
29-06-2007 15:38:23 159 byte 0 days old -- wiadebug.log
29-06-2007 15:38:24 1299881 byte 0 days old -- WindowsUpdate.log
29-06-2007 15:38:33 0 byte 0 days old -- 0.log
29-06-2007 15:39:40 (DIR) 0 byte 0 days old -- TEMP
29-06-2007 15:41:48 (DIR) 0 byte 0 days old -- system32
29-06-2007 15:53:10 (DIR) 0 byte 0 days old -- LastGood
29-06-2007 15:53:17 (DIR) 0 byte 0 days old -- inf
29-06-2007 15:53:23 10960 byte 0 days old -- setupapi.log
29-06-2007 15:53:23 (DIR) 0 byte 0 days old -- Downloaded Program Files
29-06-2007 15:54:06 (DIR) 0 byte 0 days old -- BDOSCAN8
----- recent files in C:\WINDOWS\Downloaded Program Files\
----- recent files in C:\WINDOWS\system\
22-06-2007 12:31:11 53760 byte 7 days old -- ppacklib.dll
----- recent files in C:\WINDOWS\system32\
04-05-2007 14:36:14 3079680 byte 56 days old -- mshtml.dll
16-05-2007 17:13:53 683520 byte 44 days old -- inetcomm.dll
16-05-2007 17:15:53 40960 byte 44 days old -- avi32.dll
06-06-2007 08:38:41 15747032 byte 23 days old -- MRT.exe
19-06-2007 11:41:38 145216 byte 10 days old -- FNTCACHE.DAT
22-06-2007 12:31:11 237568 byte 7 days old -- lame_enc.dll
22-06-2007 12:31:11 753664 byte 7 days old -- agsaamg.dll
22-06-2007 12:31:11 372736 byte 7 days old -- agsaamc.dll
22-06-2007 12:31:11 538624 byte 7 days old -- agsaamb.dll
22-06-2007 12:31:11 331776 byte 7 days old -- agsaama.dll
22-06-2007 12:31:11 360448 byte 7 days old -- agsaamf.ocx
22-06-2007 12:31:11 551424 byte 7 days old -- agsaame.dll
22-06-2007 12:31:11 544256 byte 7 days old -- agsaamd.dll
22-06-2007 12:31:12 90112 byte 7 days old -- agsaami.dll
22-06-2007 12:31:12 626688 byte 7 days old -- agsaamh.dll
22-06-2007 12:31:12 2846720 byte 7 days old -- agsaamj.dll
22-06-2007 12:31:16 41 byte 7 days old -- winitn.dll
25-06-2007 22:17:06 6369 byte 4 days old -- hjkkj.bak1.ren
26-06-2007 10:19:39 4672 byte 3 days old -- rlhpijoq.exe
26-06-2007 14:31:03 681984 byte 3 days old -- CDUninst.exe
26-06-2007 23:12:34 (DIR) 0 byte 3 days old -- dllcache
26-06-2007 23:12:46 (DIR) 0 byte 3 days old -- CatRoot
28-06-2007 10:18:29 973970 byte 1 days old -- hjkkj.bak2.ren
28-06-2007 10:21:46 128576 byte 1 days old -- bxbcgujs.dll.ren
28-06-2007 10:22:02 465 byte 1 days old -- sjugcbxb.ini.ren
28-06-2007 10:34:06 955778 byte 1 days old -- hjkkj.ini.ren
28-06-2007 11:11:48 0 byte 1 days old -- tmp.txt
28-06-2007 11:11:48 2594 byte 1 days old -- tmp.reg
28-06-2007 15:40:56 143 byte 1 days old -- mcrh.tmp
29-06-2007 12:29:27 2238 byte 0 days old -- ClickToFindandFixErrors_Intl.ico
29-06-2007 15:06:40 2560 byte 0 days old -- BitCometRes.dll
29-06-2007 15:17:06 3121 byte 0 days old -- CONFIG.NT
29-06-2007 15:17:08 (DIR) 0 byte 0 days old -- drivers
29-06-2007 15:21:17 (DIR) 0 byte 0 days old -- config
29-06-2007 15:39:10 1170 byte 0 days old -- wpa.dbl
29-06-2007 15:53:10 (DIR) 0 byte 0 days old -- CatRoot2
----- recent files in C:\WINDOWS\system32\drivers\
19-06-2007 11:39:51 682232 byte 10 days old -- sptd.sys
22-06-2007 12:25:04 47360 byte 7 days old -- Pcouffin.sys
27-06-2007 22:20:18 72832 byte 2 days old -- core.sys
27-06-2007 22:20:19 164787 byte 2 days old -- core.cache.dsk
----- recent files in C:\WINDOWS\temp\
29-06-2007 15:35:53 16384 byte 0 days old -- Perflib_Perfdata_5c4.dat
29-06-2007 15:37:57 16384 byte 0 days old -- Perflib_Perfdata_584.dat
29-06-2007 15:38:01 255 byte 0 days old -- WGAErrLog.txt
29-06-2007 15:39:13 409 byte 0 days old -- WGANotify.settings
29-06-2007 15:55:53 (DIR) 0 byte 0 days old -- _avast4_
----- recent files in C:\Program Files\
14-06-2007 03:02:40 (DIR) 0 byte 15 days old -- Outlook Express
14-06-2007 03:02:55 (DIR) 0 byte 15 days old -- Internet Explorer
17-06-2007 23:52:44 (DIR) 0 byte 12 days old -- Smart Projects
22-06-2007 09:45:54 (DIR) 0 byte 7 days old -- EA GAMES
22-06-2007 09:46:44 (DIR) 0 byte 7 days old -- microsoft office
22-06-2007 19:14:19 (DIR) 0 byte 7 days old -- RealMedia
25-06-2007 15:35:30 (DIR) 0 byte 4 days old -- Zoom Player
25-06-2007 21:28:47 (DIR) 0 byte 4 days old -- MSN Messenger
28-06-2007 11:05:43 (DIR) 0 byte 1 days old -- Mozilla Firefox
29-06-2007 14:23:16 (DIR) 0 byte 0 days old -- Fichiers communs
29-06-2007 14:27:24 (DIR) 0 byte 0 days old -- InstallShield Installation Information
29-06-2007 14:52:48 (DIR) 0 byte 0 days old -- BitTorrent
29-06-2007 15:08:59 (DIR) 0 byte 0 days old -- BitComet
29-06-2007 15:16:45 (DIR) 0 byte 0 days old -- Alwil Software
09-05-2007 23:15:01 (DIR) 0 byte 51 days old -- Microsoft CAPICOM 2.1.0.2
----- recent files in C:\Program Files\Fichiers communs\
14-06-2007 03:02:40 (DIR) 0 byte 15 days old -- System
===================== REGISTRY SCAN =====================
-----HKLM\Software\Microsoft\Windows\CurrentVersion\Run-----
[Run]
"VCSPlayer"="\"C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe\""
"UpdateManager"="\"c:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe\" /r"
"TkBellExe"="\"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe\" -osboot"
"SoundMan"="SOUNDMAN.EXE"
"PCMService"="\"c:\Apps\Powercinema\PCMService.exe\""
"Norton Ghost 9.0"="C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe"
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
"ATIModeChange"="Ati2mdxx.exe"
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe"
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe"
[Run\OptionalComponents]
[Run\OptionalComponents\IMAIL]
"Installed"="1"
[Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[Run\OptionalComponents\MSFS]
"Installed"="1"
-----HKCU\Software\Microsoft\Windows\CurrentVersion\Run-----
[Run]
@SACL=
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
"BitTorrent"="\"C:\Program Files\BitTorrent\bittorrent.exe\" --force_start_minimized"
"autoupdatev2"="C:\WINDOWS\system32\autoupdatev2.exe"
"Tvadk"="\"C:\Documents and Settings\Famille VERRY\Mes documents\W?nSxS\w?auclt.exe\""
"Sra"="\"C:\DOCUME~1\FAMILL~1\MESDOC~1\SCURIT~1\lsass.exe\" -vt ndrv"
-----HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run-----
[Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE"
-----HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run-----
[run]
-----HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run-----
[Run]
-----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows-----
[Windows]
"AppInit_DLLs"=""
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad-----
[ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
#### HKCR\CLSID\{7849596a-48ea-486e-8937-a2a3009f31a9}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
#### HKCR\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
#### HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32 @=expand:"%SystemRoot%\System32\webcheck.dll"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
#### HKCR\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524153}\InprocServer32 @="C:\WINDOWS\System32\stobject.dll"
-----HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks-----
[ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
#### HKCR\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InprocServer32 @="shell32.dll"
"{DC192567-65F9-4AB6-ADB7-E13575F81726}"=""
-----HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-----
[Winlogon]
"Shell"="Explorer.exe"
"System"=""
"Userinit"="C:\WINDOWS\system32\userinit.exe,"
"VmApplet"="rundll32 shell32,Control_RunDLL \"sysdm.cpl\""
"UIHost"=expand:"logonui.exe"
"LogonType"=dword:00000001
"WinStationsDisabled"="0"
[Winlogon\GPExtensions]
[Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
"@="Quota du disque Microsoft"
"DllName"=expand:"dskquota.dll"
[Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
"@="Mappage de zones Internet Explorer"
"DllName"=expand:"iedkcs32.dll"
[Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
"DllName"=expand:"scecli.dll"
"@="Security"
[Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
"DllName"=expand:"iedkcs32.dll"
"@="Personnalisation de Internet Explorer"
[Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
"DllName"=expand:"scecli.dll"
"@="EFS recovery"
[Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
"@="Installation de logiciel"
"DllName"=expand:"appmgmts.dll"
[Winlogon\Notify]
[Winlogon\Notify\crypt32chain]
"DllName"=expand:"crypt32.dll"
"Logoff"="ChainWlxLogoffEvent"
[Winlogon\Notify\cryptnet]
"DllName"=expand:"cryptnet.dll"
"Logoff"="CryptnetWlxLogoffEvent"
[Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"StartShell"="WinlogonStartShellEvent"
[Winlogon\Notify\igfxnet]
"DllName"="avi32.dll"
"Logoff"="StopProcessAtWinLogoff"
"Logon"="StartProcessAtWinLogon"
"Startup"="StartProcessAtStartup"
[Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
[Winlogon\Notify\Schedule]
"DllName"=expand:"wlnotify.dll"
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"DllName"=expand:"sclgntfy.dll"
[Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
[Winlogon\Notify\termsrv]
"DllName"=expand:"wlnotify.dll"
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[Winlogon\Notify\WgaLogon]
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=expand:"WgaLogon.dll"
[Winlogon\Notify\WgaLogon\Settings]
[Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
[Winlogon\SpecialAccounts]
[Winlogon\SpecialAccounts\UserList]
"HelpAssistant"=dword:00000000
"TsInternetUser"=dword:00000000
"SQLAgentCmdExec"=dword:00000000
"NetShowServices"=dword:00000000
"IWAM_"=dword:00010000
"IUSR_"=dword:00010000
"VUSR_"=dword:00010000
-----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-----
[Winlogon]
@SACL=
"ParseAutoexec"="1"
"ExcludeProfileDirs"="Local Settings;Temporary Internet Files;Historique;Temp"
"BuildNumber"=dword:00000a28
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options-----
[Image File Execution Options\Your Image File Name Here without a path]
"Debugger"="ntsd -d"
-----HKLM\System\CurrentControlSet\Control\Session Manager\-----
[Session Manager]
"BootExecute"=multi:"autocheck autochk *\00\00"
[Session Manager\SubSystems]
"Windows"=expand:"%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16"
-----HKLM\SYSTEM\CurrentControlSet\Control\WOW-----
[WOW]
"cmdline"=expand:"%SystemRoot%\system32\ntvdm.exe"
"wowcmdline"=expand:"%SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386"
-----HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run-----
-----HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce-----
[RunOnce]
-----HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx-----
[RunOnceEx]
-----HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices-----
[RunServices]
-----HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce-----
-----HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce-----
[RunOnce]
-----HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx-----
-----HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices-----
[RunServices]
-----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run-----
-----HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce-----
-----HKLM\Software\Microsoft\Command Processor\Autorun-----
-----HKCU\Software\Microsoft\Command Processor\Autorun-----
-----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load-----
-----HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup-----
-----HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon-----
-----HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon-----
-----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Runonce-----
-----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Run-----
-----HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms-----
-----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Runonce-----
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler-----
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
#### HKCR\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InprocServer32 @=expand:"%SystemRoot%\System32\browseui.dll"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
#### HKCR\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InprocServer32 @=expand:"%SystemRoot%\System32\browseui.dll"
-----HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects-----
[Browser Helper Objects]
@SACL=
[Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
#### HKCR\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\InprocServer32 @="C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll"
@SACL=
[Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
#### HKCR\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\InprocServer32 @="C:\Program Files\BitComet\tools\BitCometBHO_1.1.5.19.dll"
@="BitComet ClickCapture"
[Browser Helper Objects\{8D1568BA-3C89-47FB-A8D2-7BBBC26AB4BE}]
#### HKCR\CLSID\{8D1568BA-3C89-47FB-A8D2-7BBBC26AB4BE}\InprocServer32 @="C:\WINDOWS\system32\jkkjh.dll"
-----HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks-----
[URLSearchHooks]
@SACL=
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
#### HKCR\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\InprocServer32 @=expand:"%SystemRoot%\System32\shdocvw.dll"
-----HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder-----
[startupfolder]
-----HKCU\Control Panel\Desktop\-----
[Desktop]
[Desktop\WindowMetrics]
-----HKEY_CLASSES_ROOT\exefile\shell\open\command-----
[command]
@="\"%1\" %*"
-----HKEY_CLASSES_ROOT\comfile\shell\open\command-----
[command]
@="\"%1\" %*"
-----HKEY_CLASSES_ROOT\batfile\shell\open\command-----
[command]
@="\"%1\" %*"
-----HKEY_CLASSES_ROOT\piffile\shell\open\command-----
[command]
@="\"%1\" %*"
-----HKEY_CLASSES_ROOT\scrFile\shell\open\command-----
[command]
@="\"%1\" /S"
-----HKEY_CLASSES_ROOT\htafile\shell\open\command-----
[Command]
@="C:\WINDOWS\System32\mshta.exe \"%1\" %*"
-----HKEY_CLASSES_ROOT\logfile\shell\open\command-----
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL-----
[URL]
[URL\DefaultPrefix]
@="
http://"
[URL\Prefixes]
"ftp"="
ftp://"
"gopher"="gopher://"
"home"="
http://"
"mosaic"="
http://"
"www"="
http://"
-----HKLM\SYSTEM\CurrentControlSet\Control\Lsa-----
[Lsa]
"Authentication Packages"=multi:"msv1_0\00\00"
"Bounds"=hex:00,30,00,00,00,20,00,00
"Security Packages"=multi:"kerberos\00msv1_0\00schannel\00wdigest\00\00"
"LsaPid"=dword:00000310
"SecureBoot"=dword:00000001
"auditbaseobjects"=dword:00000000
"crashonauditfail"=dword:00000000
"disabledomaincreds"=dword:00000000
"everyoneincludesanonymous"=dword:00000000
"fipsalgorithmpolicy"=dword:00000000
"forceguest"=dword:00000001
"fullprivilegeauditing"=hex:00
"limitblankpassworduse"=dword:00000001
"lmcompatibilitylevel"=dword:00000000
"nodefaultadminowner"=dword:00000001
"nolmhash"=dword:00000000
"restrictanonymous"=dword:00000000
"restrictanonymoussam"=dword:00000001
"Notification Packages"=multi:"scecli\00\00"
"ImpersonatePrivilegeUpgradeToolHasRun"=dword:00000001
"enabledcom"="y"
[Lsa\AccessProviders]
"ProviderOrder"=multi:"Windows NT Access Provider\00\00"
[Lsa\AccessProviders\Windows NT Access Provider]
"ProviderPath"=expand:"%SystemRoot%\system32\ntmarta.dll"
[Lsa\Audit]
[Lsa\Audit\PerUserAuditing]
[Lsa\Audit\PerUserAuditing\System]
[Lsa\Data]
@Class="eed829a3"
"Pattern"=hex:7c,49,0f,41,3c,20,b9,b8,21,6a,7b,39,a2,76,bc,88,65,65,64,38,32,\
39,61,33,00,00,00,00,01,00,00,00,c0,01,00,00,c4,01,00,00,34,ca,06,00,45,9d,\
b5,71,04,00,00,00,10,00,00,00,00,00,00,00,7c,72,54,cd
[Lsa\GBG]
@Class="7c14f6ce"
"GrafBlumGroup"=hex:dd,9c,b8,fc,5b,8a,55,80,2e
[Lsa\JD]
@Class="1421cde0"
"Lookup"=hex:69,e7,7d,50,7f,83
[Lsa\Kerberos]
[Lsa\Kerberos\Domains]
[Lsa\Kerberos\SidCache]
[Lsa\msv1_0]
"ntlmminclientsec"=dword:00000000
"ntlmminserversec"=dword:00000000
[Lsa\Skew1]
@Class="547262fa"
"SkewMatrix"=hex:4f,02,8d,cb,fd,15,ce,c9,ad,2d,43,1f,4e,34,19,98
[Lsa\SSO]
[Lsa\SSO\Passport1.4]
"SSOURL"="
http://www.passport.com"
[Lsa\SspiCache]
"Time"=hex:4a,3d,b4,ba,a7,cc,c5,01
[Lsa\SspiCache\digest.dll]
"Name"="Digest"
"Comment"="Digest SSPI Authentication Package"
"Capabilities"=dword:00004050
"RpcId"=dword:0000ffff
"Version"=dword:00000001
"TokenSize"=dword:0000ffff
"Time"=hex:00,fd,fd,8f,41,86,c4,01
"Type"=dword:00000031
[Lsa\SspiCache\msapsspc.dll]
"Name"="DPA"
"Comment"="DPA Security Package"
"Capabilities"=dword:00000037
"RpcId"=dword:00000011
"Version"=dword:00000001
"TokenSize"=dword:00000300
"Time"=hex:80,74,8c,96,41,86,c4,01
"Type"=dword:00000031
[Lsa\SspiCache\msnsspc.dll]
"Name"="MSN"
"Comment"="MSN Security Package"
"Capabilities"=dword:00000037
"RpcId"=dword:00000012
"Version"=dword:00000001
"TokenSize"=dword:00000300
"Time"=hex:80,74,8c,96,41,86,c4,01
"Type"=dword:00000031
-----HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess-----
[SharedAccess]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=expand:"%SystemRoot%\System32\svchost.exe -k netsvcs"
"DisplayName"="Internet Connection Sharing"
"DependOnService"=multi:"Netman\00WinMgmt\00\00"
"DependOnGroup"=multi:"\00"
"ObjectName"="LocalSystem"
"Description"="Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection."
[SharedAccess\Epoch]
"Epoch"=dword:00000c9a
[SharedAccess\Parameters]
"ServiceDll"=expand:"%SystemRoot%\System32\ipnathlp.dll"
[SharedAccess\Parameters\FirewallPolicy]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"
[SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000000
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\kamjvhxu.exe"="C:\WINDOWS\system32\kamj"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"
"9237:TCP"="9237:TCP:*:Enabled:BitComet 9237 TCP"
"9237:UDP"="9237:UDP:*:Enabled:BitComet 9237 UDP"
[SharedAccess\Setup]
"ServiceUpgrade"=dword:00000001
[SharedAccess\Setup\InterfacesUnfirewalledAtUpdate]
"{C7E3BF90-3B1A-440E-BF21-75B9E82C78DF}"=dword:00000001
"{017DA56C-AE4B-4184-9CA8-4CE3894FF6A3}"=dword:00000001
"{59400E24-A36C-4AC9-A8F4-4EAB07061AA9}"=dword:00000001
"{15B9A252-2039-4436-8765-28549615B4CC}"=dword:00000001
"{F55CCDD4-7989-4DA3-B1E1-4327BB265C70}"=dword:00000001
"{FE27AC42-B0FF-4A1C-8361-6EDAC9004D93}"=dword:00000001
"{BD6CFB76-63DF-474C-B735-09E7D1520539}"=dword:00000001
"{BC840197-0E96-442D-9343-F2C9EDEE33D3}"=dword:00000001
"{42B562EA-C4F0-4300-B6BB-3A42DBA1DD80}"=dword:00000001
"{AA3FA9C3-09C5-4E9A-ABF8-275948374615}"=dword:00000001
"{BBB286B8-5860-4100-A102-466953741020}"=dword:00000001
"All"=dword:00000001
-----HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Firewall\-----
-----HKEY_LOCAL_MACHINE\SOFTWARE\Winsock2-----
-----HKLM\Software\Microsoft\Ole-----
[Ole]
"DefaultLaunchPermission"=hex:01,00,04,80,64,00,00,00,80,00,00,00,00,00,00,00,\
14,00,00,00,02,00,50,00,03,00,00,00,00,00,18,00,01,00,00,00,01,01,00,00,00,\
00,00,05,12,00,00,00,00,00,00,00,00,00,18,00,01,00,00,00,01,01,00,00,00,00,\
00,05,04,00,00,00,00,00,00,00,00,00,18,00,01,00,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00,01,05,00,00,00,00,00,05,15,00,00,00,a0,5f,84,1f,\
5e,2e,6b,49,ce,12,03,03,f4,01,00,00,01,05,00,00,00,00,00,05,15,00,00,00,a0,\
5f,84,1f,5e,2e,6b,49,ce,12,03,03,f4,01,00,00
"EnableDCOM"="Y"
"MachineLaunchRestriction"=hex:01,00,04,80,48,00,00,00,58,00,00,00,00,00,00,00,\
14,00,00,00,02,00,34,00,02,00,00,00,00,00,18,00,1f,00,00,00,01,02,00,00,00,\
00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,0b,00,00,00,01,01,00,00,00,00,\
00,01,00,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,\
00,00,00,00,05,20,00,00,00,20,02,00,00
"MachineAccessRestriction"=hex:01,00,04,80,44,00,00,00,54,00,00,00,00,00,00,00,\
14,00,00,00,02,00,30,00,02,00,00,00,00,00,14,00,03,00,00,00,01,01,00,00,00,\
00,00,05,07,00,00,00,00,00,14,00,07,00,00,00,01,01,00,00,00,00,00,01,00,00,\
00,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00
[Ole\AppCompat]
[Ole\AppCompat\ActivationSecurityCheckExemptionList]
"{A50398B8-9075-4FBF-A7A1-456BF21937AD}"="1"
"{AD65A69D-3831-40D7-9629-9B0B50A93843}"="1"
"{0040D221-54A1-11D1-9DE0-006097042D69}"="1"
"{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3}"="1"
[Ole\NONREDIST]
"System.EnterpriseServices.Thunk.dll"=""
-----HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU\-----
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\-----
[Security Center]
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[Security Center\Monitoring]
[Security Center\Monitoring\AhnlabAntiVirus]
[Security Center\Monitoring\ComputerAssociatesAntiVirus]
[Security Center\Monitoring\KasperskyAntiVirus]
[Security Center\Monitoring\McAfeeAntiVirus]
[Security Center\Monitoring\McAfeeFirewall]
[Security Center\Monitoring\PandaAntiVirus]
[Security Center\Monitoring\PandaFirewall]
[Security Center\Monitoring\SophosAntiVirus]
[Security Center\Monitoring\SymantecAntiVirus]
[Security Center\Monitoring\SymantecFirewall]
[Security Center\Monitoring\TinyFirewall]
[Security Center\Monitoring\TrendAntiVirus]
[Security Center\Monitoring\TrendFirewall]
[Security Center\Monitoring\ZoneLabsFirewall]
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\-----
[SystemRestore]
"DisableSR"=dword:00000000
"CreateFirstRunRp"=dword:00000001
"DSMin"=dword:000000c8
"DSMax"=dword:00000190
"RPSessionInterval"=dword:00000000
"RPGlobalInterval"=dword:00015180
"RPLifeInterval"=dword:0076a700
"CompressionBurst"=dword:0000003c
"TimerInterval"=dword:00000078
"DiskPercent"=dword:0000000c
"ThawInterval"=dword:00000384
"RestoreDiskSpaceError"=dword:00000000
"RestoreStatus"=dword:00000001
"RestoreSafeModeStatus"=dword:00000000
[SystemRestore\Cfg]
"DiskPercent"=dword:0000000c
"MachineGuid"="{9AEDEF4B-1977-4657-B854-EFDB21259CFF}"
[SystemRestore\SnapshotCallbacks]
@=""
-----HKEY_CURRENT_USER\Software\VB and VBA Program Settings-----
[VB and VBA Program Settings]
[VB and VBA Program Settings\CCleaner]
[VB and VBA Program Settings\CCleaner\Options]
[VB and VBA Program Settings\frmCDDVDWriter]
[VB and VBA Program Settings\frmCDDVDWriter\WindowInfo]
[VB and VBA Program Settings\WindowsSystem]
[VB and VBA Program Settings\WindowsSystem\acd]
-----HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\-----
[MountPoints2]
@SACL=
[MountPoints2\A]
"BaseClass"="Drive"
[MountPoints2\C]
"BaseClass"="Drive"
[MountPoints2\D]
"BaseClass"="Drive"
[MountPoints2\D\_Autorun]
[MountPoints2\D\_Autorun\DefaultIcon]
@="D:\setup.ico"
[MountPoints2\E]
"BaseClass"="Drive"
[MountPoints2\F]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,df,df,5f,5f,\
df,df,df,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,cf,5f,5f,5f,\
df,df,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,5f,5f,5f,5f,5f,00,00,00,01,00,00,00,08,\
00,00,00
[MountPoints2\G]
"BaseClass"="Drive"
[MountPoints2\I]
"BaseClass"="Drive"
[MountPoints2\J]
@SACL=
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,df,df,5f,5f,\
df,df,df,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,cf,5f,5f,5f,\
df,df,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,5f,5f,5f,5f,5f,00,00,00,01,00,00,00,08,\
00,00,00
[MountPoints2\K]
@SACL=
"BaseClass"="Drive"
[MountPoints2\L]
"BaseClass"="Drive"
[MountPoints2\N]
"BaseClass"="Drive"
[MountPoints2\{0764e482-2224-11db-adb6-000d6155c657}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,cf,\
cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,01,00,00
[MountPoints2\{0764e482-2224-11db-adb6-000d6155c657}\shell]
@="None"
[MountPoints2\{0764e482-2224-11db-adb6-000d6155c657}\shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{0764e482-2224-11db-adb6-000d6155c657}\shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{1496d036-5270-11da-ad6f-000d6155c657}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,01,00,00,00,08,07,00,00
[MountPoints2\{1496d036-5270-11da-ad6f-000d6155c657}\shell]
@="None"
[MountPoints2\{1496d036-5270-11da-ad6f-000d6155c657}\shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{1496d036-5270-11da-ad6f-000d6155c657}\shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{23986508-2c73-11da-ad2c-000e5061be3b}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,01,00,00,00,08,07,00,00
[MountPoints2\{23986508-2c73-11da-ad2c-000e5061be3b}\shell]
@="None"
[MountPoints2\{23986508-2c73-11da-ad2c-000e5061be3b}\shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{23986508-2c73-11da-ad2c-000e5061be3b}\shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{3599ad53-2bf7-11da-ad25-000e5061be3b}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{3599ad53-2bf7-11da-ad25-000e5061be3b}\shell]
@="None"
[MountPoints2\{3599ad53-2bf7-11da-ad25-000e5061be3b}\shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{3599ad53-2bf7-11da-ad25-000e5061be3b}\shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{58b9592c-82a9-11db-ae0c-000d6155c657}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,00,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,09,03,00,00
[MountPoints2\{58b9592c-82a9-11db-ae0c-000d6155c657}\Shell]
@="AutoRun"
[MountPoints2\{58b9592c-82a9-11db-ae0c-000d6155c657}\Shell\Auto]
[MountPoints2\{58b9592c-82a9-11db-ae0c-000d6155c657}\Shell\Auto\command]
@="F:\BootIO.exe"
[MountPoints2\{58b9592c-82a9-11db-ae0c-000d6155c657}\Shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{58b9592c-82a9-11db-ae0c-000d6155c657}\Shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{58b9592c-82a9-11db-ae0c-000d6155c657}\Shell\AutoRun]
"Extended"=""
@="&Exécution automatique"
[MountPoints2\{58b9592c-82a9-11db-ae0c-000d6155c657}\Shell\AutoRun\command]
@="C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL BootIO.exe"
[MountPoints2\{5fbab06a-d473-11d6-9787-806d6172696f}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{5fbab06b-d473-11d6-9787-806d6172696f}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{5fbab06c-d473-11d6-9787-806d6172696f}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{a8d03ef1-1803-11db-ad9d-000d6155c657}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,09,02,00,00
[MountPoints2\{a8d03ef1-1803-11db-ad9d-000d6155c657}\Shell]
@="AutoRun"
[MountPoints2\{a8d03ef1-1803-11db-ad9d-000d6155c657}\Shell\Auto]
[MountPoints2\{a8d03ef1-1803-11db-ad9d-000d6155c657}\Shell\Auto\command]
@="F:\BootIO.exe"
[MountPoints2\{a8d03ef1-1803-11db-ad9d-000d6155c657}\Shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{a8d03ef1-1803-11db-ad9d-000d6155c657}\Shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{a8d03ef1-1803-11db-ad9d-000d6155c657}\Shell\AutoRun]
"Extended"=""
@="&Exécution automatique"
[MountPoints2\{a8d03ef1-1803-11db-ad9d-000d6155c657}\Shell\AutoRun\command]
@="C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL BootIO.exe"
[MountPoints2\{b2f90242-1a36-11db-ada3-000d6155c657}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,cf,\
cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,02,00,00
[MountPoints2\{b2f90242-1a36-11db-ada3-000d6155c657}\shell]
@="None"
[MountPoints2\{b2f90242-1a36-11db-ada3-000d6155c657}\shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{b2f90242-1a36-11db-ada3-000d6155c657}\shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{b68006d0-2b2c-11da-ad21-806d6172696f}]
"BaseClass"="Drive"
[MountPoints2\{b68006d1-2b2c-11da-ad21-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,20,00,00,00,09,00,00,00
[MountPoints2\{b68006d1-2b2c-11da-ad21-806d6172696f}\Name]
@="Harry Potter II"
[MountPoints2\{b68006d1-2b2c-11da-ad21-806d6172696f}\_Autorun]
[MountPoints2\{b68006d1-2b2c-11da-ad21-806d6172696f}\_Autorun\DefaultIcon]
@="D:\age2x.ico"
[MountPoints2\{b68006d2-2b2c-11da-ad21-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,df,\
df,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,e0,00,00,00,08,00,00,00
[MountPoints2\{b68006d2-2b2c-11da-ad21-806d6172696f}\Name]
@="The Battle for Middle-earth"
[MountPoints2\{b68006d2-2b2c-11da-ad21-806d6172696f}\_Autorun]
[MountPoints2\{b68006d2-2b2c-11da-ad21-806d6172696f}\_Autorun\DefaultIcon]
@="E:\medieval.ico"
[MountPoints2\{b68006d3-2b2c-11da-ad21-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,20,00,00,00,08,\
00,00,00
[MountPoints2\{b68006d6-2b2c-11da-ad21-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,cf,\
cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,cf,cf,cf,5f,cf,cf,cf,5f,5f,5f,5f,5f,5f,5f,5f,\
5f,5f,00,00,10,00,00,00,00,00,00
[MountPoints2\{b68006d7-2b2c-11da-ad21-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,cf,\
cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,cf,cf,cf,5f,cf,cf,cf,5f,5f,5f,5f,5f,5f,5f,5f,\
5f,5f,00,00,10,00,00,00,00,00,00
[MountPoints2\{b68006d8-2b2c-11da-ad21-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,cf,\
cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,02,00,00
[MountPoints2\{b68006d9-2b2c-11da-ad21-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,06,00,00
[MountPoints2\{bffeb724-82d3-11d8-b559-000d6155c657}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{bffeb725-82d3-11d8-b559-000d6155c657}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{bffeb726-82d3-11d8-b559-000d6155c657}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{c97f78d4-82d0-11d8-b555-806d6172696f}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{c97f78d5-82d0-11d8-b555-806d6172696f}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{c97f78d6-82d0-11d8-b555-806d6172696f}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{c97f78d7-82d0-11d8-b555-000d6155c657}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{c97f78d8-82d0-11d8-b555-000d6155c657}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{c97f78d9-82d0-11d8-b555-000d6155c657}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{c97f78da-82d0-11d8-b555-000d6155c657}]
@SACL=
"BaseClass"="Drive"
[MountPoints2\{df67819a-3774-11da-ad5c-000d6155c657}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,cf,\
cf,5f,5f,5f,5f,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,01,00,00
[MountPoints2\{df67819a-3774-11da-ad5c-000d6155c657}\shell]
@="None"
[MountPoints2\{df67819a-3774-11da-ad5c-000d6155c657}\shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{df67819a-3774-11da-ad5c-000d6155c657}\shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{fb5f387e-39ce-11da-ad67-000d6155c657}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,\
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,00,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,01,00,00,00,08,07,00,00
[MountPoints2\{fb5f387e-39ce-11da-ad67-000d6155c657}\shell]
@="None"
[MountPoints2\{fb5f387e-39ce-11da-ad67-000d6155c657}\shell\Autoplay]
"MUIVerb"="@shell32.dll,-8504"
[MountPoints2\{fb5f387e-39ce-11da-ad67-000d6155c657}\shell\Autoplay\DropTarget]
"CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"
#### HKCR\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
[MountPoints2\{fd73458f-f008-11db-ae44-000d6155c657}]
"BaseClass"="Drive"
[MountPoints2\{fd73458f-f008-11db-ae44-000d6155c657}\Shell]
@="AutoRun"
[MountPoints2\{fd73458f-f008-11db-ae44-000d6155c657}\Shell\Auto]
[MountPoints2\{fd73458f-f008-11db-ae44-000d6155c657}\Shell\Auto\command]
@="F:\BootIO.exe"
[MountPoints2\{fd73458f-f008-11db-ae44-000d6155c657}\Shell\AutoRun]
"Extended"=""
@="&Exécution automatique"
[MountPoints2\{fd73458f-f008-11db-ae44-000d6155c657}\Shell\AutoRun\command]
@="C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL BootIO.exe"
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions-----
[AdvancedOptions]
-----HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions-----
-----HKLM\Software\Microsoft\Active Setup\Installed Components-----
[Installed Components]
[Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
#### HKCR\CLSID\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\InprocServer32 @="C:\WINDOWS\system32\wmpdxm.dll"
"Stubpath"="C:\WINDOWS\inf\unregmp2.exe /ShowWMP"
"@="Lecteur Windows Media"
"ComponentID"="WMPACCESS"
[Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
"@="Internet Explorer"
"ComponentID"="IEACCESS"
"StubPath"=expand:"%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE"
[Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
"@="Outlook Express"
"ComponentID"="OEACCESS"
"StubPath"=expand:"%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE"
[Installed Components\>{9655EDED-E87C-4BC2-8C3C-06700035C2C9}]
"StubPath"="RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP"
"@="Personnalisation du navigateur"
"ComponentID"="BRANDING.CAB"
[Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}]
#### HKCR\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}\InprocServer32 @="C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll"
"@="Viewpoint Media Player"
"ComponentID"="Viewpoint"
[Installed Components\{057997dd-71e4-43cc-b161-3f8180691a9e}]
"@="Q824145"
"ComponentID"="Q824145"
[Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
"@="Microsoft VM"
"ComponentID"="JAVAVM"
"KeyFileName"="C:\WINDOWS\System32\msjava.dll"
[Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608555}]
"@="Internet Explorer Classes for Java"
"ComponentID"="IEJAVA"
[Installed Components\{0fde1f56-0d59-4fd7-9624-e3df6b419d0e}]
"@="Fichier Lisez-moi d'Internet Explorer"
"ComponentID"="IEREADME"
[Installed Components\{0fde1f56-0d59-4fd7-9624-e3df6b419d0f}]
"@="IEEX"
"ComponentID"="IEEX"
[Installed Components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
"@="Rendu VML (Vector Graphics Rendering)"
"ComponentID"="MSVML"
[Installed Components\{166B1BCA-3F9C-11CF-8075-444553540000}]
#### HKCR\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\InprocServer32 @="C:\WINDOWS\system32\Macromed\Director\SwDir.dll"
"ComponentID"="Director"
"@="Macromedia Shockwave Director 8.5.1"
[Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}]
#### HKCR\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}\InprocServer32 @="C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll"
"@="Viewpoint Media Player"
"ComponentID"="Viewpoint"
[Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
#### HKCR\CLSID\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}\InprocServer32 @="C:\WINDOWS\system32\wmpdxm.dll"
"ComponentID"="NetShow"
"StubPath"=""
[Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
#### HKCR\CLSID\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\InprocServer32 @="C:\WINDOWS\system32\wmpdxm.dll"
"ComponentID"="Windows Media Player"
"StubPath"=""
"@="Lecteur Windows Media Microsoft 6.4"
[Installed Components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
#### HKCR\CLSID\{283807B5-2C60-11D0-A31D-00AA00B92C03}\InprocServer32 @="C:\WINDOWS\System32\danim.dll"
"@="DirectAnimation"
"ComponentID"="DirectAnimation"
[Installed Components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
"ComponentID"="Director"
"@="Macromedia Shockwave Director 8.5.1"
[Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
"@="Themes Setup"
"ComponentID"="Theme Component"
"StubPath"=expand:"%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll"
[Installed Components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
"@="Liaison de données Dynamic HTML pour Java"
"ComponentID"="TridataJava"
[Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}]
"@="Logiciel de navigation hors connexion"
"ComponentID"="MobilePk"
[Installed Components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
"@="Uniscribe"
"ComponentID"="USP10"
[Installed Components\{4278c270-a269-11d1-b5bf-0000f8051515}]
"@="Création avancée"
"ComponentID"="AdvAuth"
[Installed Components\{44AA3114-D221-43EC-1C32-1EAC52A2014D}]
"StubPath"="C:\WINDOWS\system32\msnvl.exe"
[Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"@="Microsoft Outlook Express 6"
"ComponentID"="MailNews"
"StubPath"=expand:"\"%ProgramFiles%\Outlook Express\setup50.exe\" /APP:OE /CALLER:WINNT /user /install"
[Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
"@="NetMeeting 3.01"
"ComponentID"="NetMeeting"
"StubPath"="rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT"
[Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
"@="DirectShow"
"ComponentID"="activemovie"
[Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}]
"@="Microsoft DirectX"
[Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
"@="DirectDrawEx"
"ComponentID"="DirectDrawEx"
[Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
"@="Aide sur Internet Explorer"
"ComponentID"="HelpCont"
[Installed Components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
"@="Classes Java DirectAnimation"
"ComponentID"="DAJava"
[Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
"@="Microsoft Windows Script 5.6"
"ComponentID"="MSVBSc