Comprendre le bitcoin, l'intelligence artificielle, faire un site web... En 3 minutes en vidéo!

redondance

<<<1>>>

[Page 1 sur 1 - 13 messages]
Informations Messages

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 27 Janvier 2011 à 14h14

Bonjour,

Depuis hier, lorsque je me connecte sur internet ou lorsque je fais des recherches, j'ai plusieurs sites publicitares ou autres qui s'ouvrent automatiquement.
Comment faire pour que cette redondance s'arrête?

Merci

 

Publicité

Pouzy

Avatar de Pouzy
14213 messages
No-Life
No-Life
Administrateur
Administrateur

Lien direct Le 27 Janvier 2011 à 16h19

Bonjour,

Sûrement une infection, je me permets de déplacer le sujet dans le forum de désinfection, pour une prise en chargeSourire

Devenez fan d'Aidoweb sur Facebook o/ - N'oubliez pas de cliquer sur [Résolu] une fois votre problème réglé
 

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 27 Janvier 2011 à 16h50

Re,

Merci.
J'ai passé mon anti virus, mais rien. Je ne comprends pas

 

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 27 Janvier 2011 à 17h50

en attendant une réponse, j'ai fouiné sur votre site. Voici les résultats obtenus:
LE PREMIER:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrateur at 2011-01-27 17:53:48
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 45 GB (79%) free of 57 GB
Total RAM: 511 MB (14% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:54:23, on 27/01/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\EoRezo\eorezo.exe
C:\Documents and Settings\Administrateur\Application Data\EoRezo\EoRezo\SoftwareUpdateHP.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Hercules\WiFi Station\WifiStation.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\W2D1Y9QH\RSIT[1].exe
C:\Program Files\trend micro\Administrateur.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows XP Ultimate Edition By Mad Dog
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: EOBHO - {C10DC1F4-CCDF-4224-A24D-B23AFC3573C8} - C:\Program Files\EoRezo\EoRezoBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\vsdrv\vsdrv.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [eorezo] "C:\Program Files\EoRezo\eorezo.exe"
O4 - HKLM\..\Run: [SoftwareHelper] C:\Documents and Settings\Administrateur\Application Data\EoRezo\EoRezo\SoftwareUpdateHP.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-20\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: WiFi Station.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O15 - Trusted Zone: http://www.orange.fr
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - Unknown owner - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe

--
End of file - 9624 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}]
EOBHO Class - C:\Program Files\EoRezo\EoRezoBHO.dll [2010-12-31 221184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-26 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-01-26 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2007-01-10 1235456]
"Vistadrv"=C:\WINDOWS\system32\vsdrv\vsdrv.exe [2006-07-30 121089]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2001-09-04 28672]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-03-03 335872]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-04-14 2790472]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-03-18 421888]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-06-15 141624]
"SystrayORAHSS"=C:\Program Files\Orange\Systray\SystrayApp.exe [2007-09-25 94208]
"ORAHSSSessionManager"=C:\Program Files\Orange\SessionManager\SessionManager.exe [2007-09-25 102400]
"eorezo"=C:\Program Files\EoRezo\eorezo.exe [2010-12-31 671744]
"SoftwareHelper"=C:\Documents and Settings\Administrateur\Application Data\EoRezo\EoRezo\SoftwareUpdateHP.exe [2010-12-31 368224]
"SunJavaUpdateSched"=C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe [2010-02-18 248040]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"=C:\WINDOWS\system32\sti_ci.dll [2009-10-23 138240]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"=C:\Program Files\CCleaner\CCleaner.exe [2009-07-27 1644784]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-04-20 26192680]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
WiFi Station.lnk - C:\Program Files\Hercules\WiFi Station\WifiStation.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2004-03-03 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-10-23 190976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayL oad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoUserNameInStartMenu"=1
"NoSMHelp"=1
"NoSMConfigurePrograms"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewall policy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\UltraVNC\vncviewer.exe"="C:\Program Files\UltraVNC\vncviewer.exe:*:Enabled:Client UltraVNC"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Hercules\WiFi Station\WiFiStation.exe"="C:\Program Files\Hercules\WiFi Station\WiFiStation.exe:*:Enabled:WiFi Station"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Service Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Orange\Connectivity\ConnectivityManager.exe"="C:\Program Files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewall policy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 3 months======

2011-01-27 17:53:58 ----D---- C:\Program Files\trend micro
2011-01-27 17:53:48 ----D---- C:\rsit
2011-01-26 17:45:04 ----D---- C:\WINDOWS\system32\appmgmt
2011-01-26 17:26:46 ----D---- C:\Documents and Settings\Administrateur\Application Data\OpenOffice.org
2011-01-26 17:11:13 ----D---- C:\Program Files\OpenOffice.org 3
2011-01-26 17:09:00 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2011-01-26 17:08:58 ----D---- C:\Program Files\Fichiers communs\Java
2011-01-26 17:08:40 ----A---- C:\WINDOWS\system32\javaws.exe
2011-01-26 17:08:40 ----A---- C:\WINDOWS\system32\javaw.exe
2011-01-26 17:08:40 ----A---- C:\WINDOWS\system32\java.exe
2011-01-26 17:08:40 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-01-26 17:07:58 ----D---- C:\Program Files\Java
2011-01-26 17:07:37 ----D---- C:\Documents and Settings\Administrateur\Application Data\Sun
2011-01-26 16:55:08 ----D---- C:\Documents and Settings\Administrateur\Application Data\EoRezo
2011-01-26 16:55:07 ----D---- C:\Program Files\eoRezo
2011-01-23 11:06:37 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2011-01-23 11:06:14 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonBJ
2011-01-23 11:06:03 ----RA---- C:\WINDOWS\system32\CNMIUAA.DLL
2011-01-23 11:05:48 ----A---- C:\WINDOWS\system32\CNMLMAA.DLL
2011-01-23 11:05:17 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2011-01-23 11:04:26 ----RA---- C:\WINDOWS\system32\CNC280O.dll
2011-01-23 11:04:22 ----A---- C:\WINDOWS\system32\CNC280L.dll
2011-01-23 11:04:22 ----A---- C:\WINDOWS\system32\CNC280I.dll
2011-01-23 11:04:21 ----A---- C:\WINDOWS\system32\CNHMCA.dll
2011-01-23 11:04:21 ----A---- C:\WINDOWS\system32\CNC280U.dll
2011-01-23 11:04:21 ----A---- C:\WINDOWS\system32\CNC280C.dll

======List of files/folders modified in the last 3 months======

2011-01-27 17:53:58 ----D---- C:\Program Files
2011-01-27 13:47:39 ----D---- C:\WINDOWS\Temp
2011-01-27 05:22:18 ----D---- C:\WINDOWS
2011-01-26 17:45:04 ----SHD---- C:\WINDOWS\Installer
2011-01-26 17:45:04 ----D---- C:\WINDOWS\system32
2011-01-26 17:41:56 ----RSD---- C:\WINDOWS\assembly
2011-01-26 17:15:24 ----RSD---- C:\WINDOWS\Fonts
2011-01-26 17:08:58 ----D---- C:\Program Files\Fichiers communs
2011-01-26 06:34:50 ----D---- C:\Documents and Settings\Administrateur\Application Data\Skype
2011-01-23 18:55:52 ----D---- C:\WINDOWS\system32\CatRoot2
2011-01-23 11:05:47 ----HD---- C:\WINDOWS\inf
2011-01-23 11:05:17 ----D---- C:\WINDOWS\system32\drivers
2011-01-23 11:04:22 ----D---- C:\WINDOWS\twain_32
2011-01-23 11:04:22 ----D---- C:\WINDOWS\Media
2011-01-23 09:30:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-11-14 06:04:08 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-11-14 06:04:08 ----D---- C:\Documents and Settings\Administrateur\Application Data\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 gagp30kx;Filtre AGP version 3.0 générique Microsoft pour plates-formes à base de processeur K8; C:\WINDOWS\system32\DRIVERS\gagp30kx.sys [2008-04-13 46464]
R0 ohci1394;Contrôleur hôte Texas Instruments IEEE 1394 compatible OHCI (Open Host Controller Interface); C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-06-19 61696]
R0 RecAgent;RecAgent; C:\WINDOWS\system32\DRIVERS\RecAgent.sys [2003-10-29 14160]
R0 Si3112;Si3112; C:\WINDOWS\system32\drivers\Si3112.sys [2009-10-23 69296]
R0 Si3124;Si3124; C:\WINDOWS\system32\drivers\Si3124.sys [2009-10-23 76208]
R0 Si3132;Si3132; C:\WINDOWS\system32\drivers\Si3132.sys [2009-10-23 74672]
R0 Si3132r5;Si3132r5; C:\WINDOWS\system32\drivers\Si3132r5.sys [2009-10-23 208688]
R0 Si3531;Si3531; C:\WINDOWS\system32\drivers\Si3531.sys [2009-10-23 210224]
R0 SiSide;SiSide; C:\WINDOWS\system32\DRIVERS\siside.sys [2009-10-11 4096]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-04-27 691696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-04-14 28880]
R1 AmdK8;Pilote de processeur AMD Athlon64; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2003-11-07 38400]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-04-14 162768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-04-14 46672]
R1 GhPciScan;GhostPciScanner; \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys []
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-04-27 21419]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2003-05-28 17005]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-04-14 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-04-14 100432]
R2 irda;Protocole IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-03-03 679936]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 MODEMCSA;Périphérique de filtrage de flux Unimodem; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 Mtlmnt5;Mtlmnt5; C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys [2003-10-29 226288]
R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 NSCIRDA;Pilote de périphérique infrarouge NSC; C:\WINDOWS\system32\DRIVERS\nscirda.sys [2008-04-13 28672]
R3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
R3 Rasirda;Miniport réseau étendu (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RT2500;RT2500 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2500.sys [2004-03-31 104448]
R3 RT73;Hercules Wireless USB Dongle Driver ; C:\WINDOWS\system32\DRIVERS\rt73.sys [2007-07-28 451456]
R3 SISNIC;Pilote de carte Fast Ethernet PCI SiS; C:\WINDOWS\system32\DRIVERS\sisnic.sys [2008-04-13 32768]
R3 Slntamr;SmartLink AMR_PCI Driver; C:\WINDOWS\system32\DRIVERS\slntamr.sys [2003-11-09 566256]
R3 SlWdmSup;SlWdmSup; C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [2003-10-29 15712]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S0 Si3114r5;Si3114r5; C:\WINDOWS\system32\drivers\Si3114r5.sys [2009-10-23 202032]
S3 a65xmpnc;a65xmpnc; C:\WINDOWS\system32\drivers\a65xmpnc.sys []
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-04-14 23376]
S3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
S3 Mtlstrm;Mtlstrm; C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [2003-11-04 1299976]
S3 NtMtlFax;NtMtlFax; C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys [2003-10-29 180368]
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCAMPR5.SYS []
S3 SlNtHal;SlNtHal; C:\WINDOWS\system32\DRIVERS\Slnthal.sys [2003-10-29 87656]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2009-10-23 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2004-03-03 397312]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2007-09-25 65536]
R2 Irmon;Moniteur infrarouge; C:\WINDOWS\system32\svchost.exe [2009-10-23 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-01-26 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 SLService;SmartLinkService; C:\WINDOWS\system32\slserv.exe [2003-10-29 45056]
R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2010-06-15 540472]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
S3 GhostStartService;GhostStartService; C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe [2003-05-28 200704]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2009-10-23 14336]
S4 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-07-16 33632]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-07-16 68952]

-----------------EOF-----------------

 

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 27 Janvier 2011 à 17h51

LE DEUXIEME:
info.txt logfile of random's system information tool 1.08 2011-01-27 17:54:36

======Uninstall list======

Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 9.3.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A93000000001}
AMD Athlon 64 Processor Driver-->MsiExec.exe /X{ABC62001-AD9F-46DB-8668-9946154D6A07}
Apple Application Support-->MsiExec.exe /I{B2D328BE-45AD-4D92-96F9-2151490A203E}
Apple Mobile Device Support-->MsiExec.exe /I{85991ED2-010C-4930-96FA-52F43C2CE98A}
Apple Software Update-->MsiExec.exe /I{C41300B9-185D-475E-BFEC-39EF732F19B1}
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,[email protected] -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
Bonjour-->MsiExec.exe /X{0CB9668D-F979-4F31-B8B8-67FE90F929F8}
Canon MP280 series MP Drivers-->"C:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series /L0x000c
eoRezo 13.1-->"C:\Program Files\eoRezo\unins000.exe"
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
iTunes-->MsiExec.exe /I{7AB3A249-FB81-416B-917A-A2A10E74C503}
Java(TM) 6 Update 20-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216020FF}
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
LiveReg (Symantec Corporation)-->C:\Program Files\Fichiers communs\Symantec Shared\LiveReg\VcSetup.exe /REMOVE
LiveUpdate 1.80 (Symantec Corporation)-->C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
Logiciel d'archivage WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Media Player Classic - Home Cinema v. 1.3.1249.0-->"C:\Program Files\MPC HomeCinema\unins000.exe"
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
MSFN Codec Pack 5.4-->rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\codec.inf, DefaultUninstall,3
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Navigateur Orange-->C:\Program Files\Orange\Uninstall\Browser\Shell.exe MainUninstall.shl
Nero 8 Lite 8.3.6.0-->"C:\Program Files\Nero\unins000.exe"
Norton Ghost-->MsiExec.exe /I{BBAAACFA-B012-4367-ADDA-4DDCDFD48F96}
Orange - Logiciels Internet-->C:\Program Files\Orange\installation\core\Installgui.exe -u
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Polaroid Digital Cam-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D4CB7852-8308-4BBB-AF7D-48F073B58507}\setup.exe" -l0x40c
QuickTime-->MsiExec.exe /I{3D9892BB-A751-4E48-ADC8-E4289956CE1D}
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
Security Update pour Microsoft .NET Framework 2.0 (KB928365)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
SiSAGP driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC226AC9-0314-496C-BE6A-B6A132628466}\setup.exe" -l0x40c
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Smart Link 56K Modem-->C:\WINDOWS\Modio\SLAMR2KV\Setup.exe /Remove
UltraISO Premium V9.3-->"C:\Program Files\UltraISO\unins000.exe"
WiFi Station-->C:\Program Files\InstallShield Installation Information\{DECE22F4-EEDD-4615-BC56-2F4827FAD64B}\setup.exe -runfromtemp -l0x040c -removeonly
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"

======Hosts File======

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

Securitycenter WMI appears to be broken

======System event log======

Computer Name: E2584C21B7A14B2
Event Code: 4201
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{97634EF0-9658-4962-B49B-058F8A503901} était connectée au réseau,
et a lancé une opération normale sur la carte réseau.

Record Number: 73300
Source Name: Tcpip
Time Written: 20110117184426.000000+060
Event Type: Informations
User:

Computer Name: E2584C21B7A14B2
Event Code: 4201
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{97634EF0-9658-4962-B49B-058F8A503901} était connectée au réseau,
et a lancé une opération normale sur la carte réseau.

Record Number: 73299
Source Name: Tcpip
Time Written: 20110117184419.000000+060
Event Type: Informations
User:

Computer Name: E2584C21B7A14B2
Event Code: 4201
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{97634EF0-9658-4962-B49B-058F8A503901} était connectée au réseau,
et a lancé une opération normale sur la carte réseau.

Record Number: 73298
Source Name: Tcpip
Time Written: 20110117184410.000000+060
Event Type: Informations
User:

Computer Name: E2584C21B7A14B2
Event Code: 4201
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{97634EF0-9658-4962-B49B-058F8A503901} était connectée au réseau,
et a lancé une opération normale sur la carte réseau.

Record Number: 73297
Source Name: Tcpip
Time Written: 20110117184403.000000+060
Event Type: Informations
User:

Computer Name: E2584C21B7A14B2
Event Code: 4201
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{97634EF0-9658-4962-B49B-058F8A503901} était connectée au réseau,
et a lancé une opération normale sur la carte réseau.

Record Number: 73296
Source Name: Tcpip
Time Written: 20110117184354.000000+060
Event Type: Informations
User:

=====Application event log=====

Computer Name: E2584C21B7A14B2
Event Code: 1001
Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été supprimés.
Les données d'enregistrement contiennent les nouvelles valeurs du dernier compteur système
et les dernières entrées du registre d'aide.

Record Number: 5
Source Name: LoadPerf
Time Written: 20100418113851.000000+120
Event Type: Informations
User:

Computer Name: E2584C21B7A14B2
Event Code: 1000
Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.

Record Number: 4
Source Name: LoadPerf
Time Written: 20100418113850.000000+120
Event Type: Informations
User:

Computer Name: E2584C21B7A14B2
Event Code: 1000
Message: Les compteurs de performances pour le service TermService (Services Terminal Server) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.

Record Number: 3
Source Name: LoadPerf
Time Written: 20100418113843.000000+120
Event Type: Informations
User:

Computer Name: E2584C21B7A14B2
Event Code: 1000
Message: Les compteurs de performances pour le service RemoteAccess (Routage et accès distant) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.

Record Number: 2
Source Name: LoadPerf
Time Written: 20100418113712.000000+120
Event Type: Informations
User:

Computer Name: E2584C21B7A14B2
Event Code: 1000
Message: Les compteurs de performances pour le service PSched (PSched) ont été chargés.
Les données d'enregistrement contiennent les nouvelles valeurs d'index
assignées à ce service.

Record Number: 1
Source Name: LoadPerf
Time Written: 20100418113639.000000+120
Event Type: Informations
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;"C:\Program Files\Symantec\Norton Ghost 2003\";C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 10, AuthenticAMD
"PROCESSOR_REVISION"=040a
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"asl.log"=Destination=file;OnFirstLog=command,environment,parent
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

-----------------EOF-----------------

 

Winx

Avatar de Winx
27904 messages
No-Life
No-Life
AidoHardware
AidoHardware
AidoAntivirus
AidoAntivirus
AidoWindows
AidoWindows

Lien direct Le 27 Janvier 2011 à 18h37

Infection

Salut à toi et bienvenue,Sourire Hello

Tu as une infection de type "FakeAlert" sur cette machine.

Fais ceci,

* Désactive ton Antivirus pour le moment.
* Télécharge Ad-Remover (de C_XX) sur le bureau.

* /!\ Déconnecte-toi et ferme toutes les applications en cours /!\
* Double clic sur le programme pour le lancer...
* Pour Vista et Seven toujours faire un clic droit, et choisir lancer comme administrateur
* Au menu principal choisis l'option "Scanner"

* /!\ Laisse travailler l'outil /!\
* Patiente jusqu'à la fin du scan sans rien faire d'autre sur ton PC.
* Un rapport apparaitra à la fin, poste le sur le forum dans ta réponse.
Si tu ne trouve pas !
(Le rapport est aussi sauvegardé sous C:\Ad-Report-SCAN.log)

ensuite:




Passons à la suppression:

-----------------------------------------------------------
* Double clic sur le programme Ad-Remover pour le lancer...
* Pour Vista et Seven toujours faire un clic droit, et choisir lancer comme administrateur
* Au menu principal choisis l'option "Nettoyer"

* /!\ Laisse travailler l'outil /!\
* Patiente jusqu'à la fin du scan sans rien faire d'autre sur ton PC.

* Un rapport apparaitra à la fin, poste le sur le forum dans ta réponse.
Si tu ne trouve pas !
(Le rapport est aussi sauvegardé sous C:\Ad-Report-SCAN.log)




// ! Important !
=======================

Citation

Durant la phase de désinfection, il est absolument indispensable et primordial de ne pas rajouter de programmes à votre PC, afin de ne pas perturber la décontamination de votre machine. Faites-en un usage minimum durant cette phase.

D'autre part, ne pas utiliser d'outil(s) de décontamination de sa propre initiative, cela peut définitivement nuire à notre travail et au bon rétablissement de la machine. Sourire
C'est à la mode en ce moment, d'utiliser des outils comme Combofix sans autorisation !
C'est ABSOLUMENT proscrit ici sur ce Forum.

Il est évident qu'un PC infecté peut tout à fait devenir inutilisable malgré la tentative de désinfection, et de ce fait prendre la précaution de sauvegarder tous ses documents personnels, c'est une très bonne idée en soi....merci de prendre ça en considération LOL !

Il est évident que je considère que l'option formatage et/ou une restauration du Système ne fait pas actuellement partie de ton intention, ce qui m'évite de perdre du temps.... LOL ! merci d'avance



Ps:
======
Conseil d'ordre général Sourire
---->> Aller sur le Net avec Windows Internet Explorer, n'est pas souhaitable.
Pour vous en convaincre, un petit test de votre navigateur Flèche

Comparez-donc Windows Internet Explorer avec Mozilla-Firefox (ce dernier devrait atteindre les 92 )
Quand à Windows Internet Explorer, j'en laisse la surprise... LOL !

Toutefois, ce qui ne veut pas dire que Windows Internet Explorer, ne doit pas être à jour ! (vérifier que vous avez la dernière version ! )

Télécharger Mozilla-Firefox 3.0. X. (le X représente évidemment la dernière version ) et le mettre à l'install comme Navigateur par défaut.

Flèche lien ici

-->source ici de conseils
Eviter à tous prix de poster dans plusieurs Forum à la fois...pas de multi-postage donc !







PS:
si tu ne peux pas télécharger en direct avec la machine infectée, il est évident qu'il faut faire usage, d'une carte SD ou clé usb[color=#0000FF] via un autre PC.

Je n'ai pas la prétention de résoudre les problèmes, mais celle de vous aider à les résoudre ;-)
 

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 27 Janvier 2011 à 19h06

Voici le résultat:
======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

Mis à jour par TeamXscript le 20/01/11 à 19:00
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Site web: http://www.teamxscript.org

C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 19:05:52 le 27/01/2011, Mode normal

Microsoft Windows XP Professionnel Service Pack 3 (X86)
[email protected] ( )

============== RECHERCHE ==============


Dossier trouvé: C:\Documents and Settings\Administrateur\Application Data\EoRezo
Dossier trouvé: C:\Documents and Settings\Administrateur\Local Settings\Application Data\EoRezo
Dossier trouvé: C:\Program Files\EoRezo

Clé trouvée: HKLM\Software\Classes\CLSID\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}
Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}
Clé trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}
Clé trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}
Clé trouvée: HKLM\Software\Classes\Interface\{DF76E9B7-35EC-46FC-AF56-5B79DED9D64F}
Clé trouvée: HKLM\Software\Classes\TypeLib\{18AF7201-4F14-4BCF-93FE-45617CF259FF}
Clé trouvée: HKLM\Software\Classes\EoEngineBHO.EOBHO
Clé trouvée: HKLM\Software\Classes\EoEngineBHO.EOBHO.1
Clé trouvée: HKLM\Software\Classes\AppID\EoEngineBHO.DLL
Clé trouvée: HKLM\Software\Classes\AppID\{AFBB7970-789A-4264-BA70-E8127DECE400}
Clé trouvée: HKLM\Software\EoRezo
Clé trouvée: HKCU\Software\EoRezo
Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\EoRezo_is1

Valeur trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Eorezo
Valeur trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Softwarehelper


============== SCAN ADDITIONNEL ==============

** Internet Explorer Version [8.0.6001.18702] **

[HKCU\Software\Microsoft\Internet Explorer\Main]
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://www.google.fr
Show_ToolBar: yes
Start Page: hxxp://www.orange.fr/portail

[HKLM\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.google.fr/
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://www.google.fr/

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: hxxp://y.lo.st
Blank: res://mshtml.dll/blank.htm

========================================

C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files\Ad-Remover\Backup: 0 Fichier(s)

C:\Ad-Report-SCAN[1].txt - 27/01/2011 (672 Octet(s))

Fin à: 19:09:06, 27/01/2011

============== E.O.F ==============

 

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 27 Janvier 2011 à 20h16

Salut Winx,

J'ai voulu tester 'Antivir free', cependant il n'est pas gratuit, il faut ""dépenser sur des sites""

 

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 28 Janvier 2011 à 07h16

Bonjour,
Voici le résultat du nettoyage:



======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

Mis à jour par TeamXscript le 20/01/11 à 19:00
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Site web: http://www.teamxscript.org

C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 05:50:31 le 28/01/2011, Mode normal

Microsoft Windows XP Professionnel Service Pack 3 (X86)
[email protected] ( )

============== ACTION(S) ==============


Dossier supprimé: C:\Documents and Settings\Administrateur\Application Data\EoRezo
Dossier supprimé: C:\Documents and Settings\Administrateur\Local Settings\Application Data\EoRezo
Dossier supprimé: C:\Program Files\EoRezo

(!) -- Fichiers temporaires supprimés.


Clé supprimée: HKLM\Software\Classes\CLSID\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}
Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}
Clé supprimée: HKLM\Software\Classes\Interface\{DF76E9B7-35EC-46FC-AF56-5B79DED9D64F}
Clé supprimée: HKLM\Software\Classes\TypeLib\{18AF7201-4F14-4BCF-93FE-45617CF259FF}
Clé supprimée: HKLM\Software\Classes\EoEngineBHO.EOBHO
Clé supprimée: HKLM\Software\Classes\EoEngineBHO.EOBHO.1
Clé supprimée: HKLM\Software\Classes\AppID\EoEngineBHO.DLL
Clé supprimée: HKLM\Software\Classes\AppID\{AFBB7970-789A-4264-BA70-E8127DECE400}
Clé supprimée: HKLM\Software\EoRezo
Clé supprimée: HKCU\Software\EoRezo
Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\EoRezo_is1

Valeur supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Eorezo
Valeur supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Softwarehelper


============== SCAN ADDITIONNEL ==============

** Internet Explorer Version [8.0.6001.18702] **

[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/

[HKLM\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm

========================================

C:\Program Files\Ad-Remover\Quarantine: 21 Fichier(s)
C:\Program Files\Ad-Remover\Backup: 13 Fichier(s)

C:\Ad-Report-CLEAN[1].txt - 28/01/2011 (723 Octet(s))
C:\Ad-Report-SCAN[1].txt - 27/01/2011 (2916 Octet(s))

Fin à: 06:34:50, 28/01/2011

============== E.O.F ==============

 

Winx

Avatar de Winx
27904 messages
No-Life
No-Life
AidoHardware
AidoHardware
AidoAntivirus
AidoAntivirus
AidoWindows
AidoWindows

Lien direct Le 28 Janvier 2011 à 20h37

re,

Ensuite fais ceci:
Télécharge Malwarebytes' Anti-Malware (MBAM)


    [*] Double clique sur le fichier téléchargé pour lancer le processus d'installation.
    [*] Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour": si le pare-feu demande l'autorisation à MBAM de se connecter, accepte.
    [*] Une fois la mise à jour terminée, rends-toi dans l'onglet "Recherche".
    [*] Sélectionne "Exécuter un examen rapide"
    [*] Clique sur "Rechercher"
    [*] L'analyse démarre, le scan est relativement long, c'est normal.
    [*] A la fin de l'analyse, un message s'affiche :

    Citation

    L'examen s'est terminé normalement. Clique sur 'Afficher les résultats' pour afficher tous les objets trouvés.


    Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
    [*] Ferme tes navigateurs.
    [*] Si des malwares ont été détectés, clique sur Afficher les résultats.
    Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    [*] MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport et poste-le dans ta prochaine réponse.




ps:
--->aide visuelle sur Mbam ici



ps:
antivir est bien gratuit...sauf la version payante...

va sur cette page et télécharge la version française gratuite.

Je n'ai pas la prétention de résoudre les problèmes, mais celle de vous aider à les résoudre ;-)
 

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 30 Janvier 2011 à 05h51



edit de modération: à refaire pas visible, j'effacerai ensuite

Bonjour, voici le premier résultat:


<?xml version="1.0" encoding="UTF-8" ?>
- <AROScanLog>
<AROVersion>6.0.793.824</AROVersion>
<ScanningDate>Sun. January 30, 2011. 05:49 AM</ScanningDate>
<TotalErrorsFound>260</TotalErrorsFound>
- <Scanning Section="ActiveX and COM">
<Description>ActiveX and COM objects that are based on libraries no longer on your system.</Description>
<ErrorsInThisSection>44 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>Microsoft NetShow Player</Entry>
<Details>The ToolboxBitmap32 key HKEY_CLASSES_ROOT\CLSID\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}\ToolboxBitmap32 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>MiEngine Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{9D13E607-106F-4892-8A83-FF9827C0A3D5}\TypeLib for this object point to the missing type library {BEB70C92-90A2-4166-A7F5-DD648E36594A}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>MiImageLayer Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{8EE4C235-F2CE-4C3B-9ADE-DD68718AE32A}\TypeLib for this object point to the missing type library {4743C1A4-E33C-4495-B873-67AB9EA4E5F9}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>MiRioEventSink Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{5CBAD860-46EE-4193-8FDF-5EF8625E0CA1}\TypeLib for this object point to the missing type library {81BCFB9F-5C3B-404D-B5BF-6BA3F5CE35B7}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>MSAA AccPropServices</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7}\TypeLib for this object point to the missing type library {54559DA5-7D94-42C6-B8F1-E3910737BBF1}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>MSAA AccPropServices</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{b5f8350b-0548-48b1-a6ee-88bd00b4a5e7} points to the missing ApplicationID {667524BE-9EC0-4196-91C9-C6ED1F7A899D}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>MSDMineErrorLookup</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{72B082C6-97D5-11D3-8BEC-00C04F68DDC2}\TypeLib for this object point to the missing type library {72B082B9-97D5-11D3-8BEC-00C04F68DDC2}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>MSOLAP90ErrorLookup</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{07AD8473-5D37-4076-AF40-44FE70B07CD9}\TypeLib for this object point to the missing type library {07AD8473-5D37-4076-AF40-44FE70B07CD9}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>NeroApplication Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{02585C63-DB8D-4077-B2BE-0786B8C945B7}\TypeLib for this object point to the missing type library {70DDA853-41A2-4db2-8441-980AFCB55040}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>NeroDigitalExt 1.0 Type Library</Entry>
<Details>The key HKEY_CLASSES_ROOT\TypeLib\{8042010C-0400-41A1-B344-85F0D08F4F41}\1.0\HELPDIR for this type library serves to indicate a help directory, but contains no data. This subkey can be deleted for this type library.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Network Common Connections Ui</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{7007ACD1-3202-11D1-AAD2-00805FC1270E}\DefaultIcon is incomplete. The subkey DefaultIcon was created to indicate the default icon, but no icon has been entered.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Network Connections Tray</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{7007ACCF-3202-11D1-AAD2-00805FC1270E}\DefaultIcon is incomplete. The subkey DefaultIcon was created to indicate the default icon, but no icon has been entered.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>NodeMgr 1.0 Type Library</Entry>
<Details>The key HKEY_CLASSES_ROOT\TypeLib\{43136EB0-D36C-11CF-ADBC-00AA00A80033}\1.0\HELPDIR for this type library serves to indicate a help directory, but contains no data. This subkey can be deleted for this type library.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>OLE Automation</Entry>
<Details>The key HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\1.0\HELPDIR for this type library serves to indicate a help directory, but contains no data. This subkey can be deleted for this type library.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PSFactoryBuffer</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{9DAA7B9D-CE5B-42CE-B942-32BBC284AC44}\InprocServer32 points to the missing InprocServer32 %SystemRoot%\system32\eapa3hst.dll. The associated CLSID can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PSFactoryBuffer</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{5A8371A3-0C6D-487b-B3C8-46D785C4C940}\InprocServer32 points to the missing InprocServer32 %11%\eapahost.dll. The associated CLSID can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>RadioView Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{847B4DF5-4B61-11D2-9BDB-204C4F4F5020}\TypeLib for this object point to the missing type library {39A2C297-4778-11D2-9BDB-204C4F4F5020}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>RecoManager Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{DE815B00-9460-4F6E-9471-892ED2275EA5}\TypeLib for this object point to the missing type library {9E52A566-D72F-4342-99B9-DBCA6780385F}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>RtpObject Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{DECBDC16-E824-436E-872D-14E8C7BF7D8B}\TypeLib for this object point to the missing type library {887ca720-df84-40e0-bef0-13252008cce8}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Search Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{08C06D61-F1F3-4799-86F8-BE1A89362C85}\TypeLib for this object point to the missing type library {08C06D61-F1F3-4799-86F8-BE1A89362C85}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>SerialNumber Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{2c5e7418-1ac8-4c44-b2dd-f3fbe3684c7b}\TypeLib for this object point to the missing type library {6F125F84-8F3E-45eb-B537-5D6052E48910}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>ShedDSO Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{5F6C4076-12F5-11D3-8CEE-005004838434}\TypeLib for this object point to the missing type library {AE997BEB-0FBD-11D3-8CEE-005004838434}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>ShellManager 1.0 Type Library</Entry>
<Details>The key HKEY_CLASSES_ROOT\TypeLib\{FCAD80DC-FEA2-4E7F-AB1E-C7C6009052CC}\1.0\HELPDIR for this type library serves to indicate a help directory, but contains no data. This subkey can be deleted for this type library.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>SkypeIEPlugin 1.0 Type Library</Entry>
<Details>The key HKEY_CLASSES_ROOT\TypeLib\{E58E25D2-3FD0-4823-8AA9-A476F701410A}\1.0\HELPDIR for this type library serves to indicate a help directory, but contains no data. This subkey can be deleted for this type library.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>SoftphoneDialer Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{FBE342DA-FCD4-49d8-A14E-AFA1F5CC4A85} points to the missing ApplicationID {DFB979A4-3182-475e-9300-1F77BC8CAB8C}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>SoftphoneDialerWindow Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{0284338F-FDBA-4659-AFB6-7C10E1CDBF7F} points to the missing ApplicationID {DFB979A4-3182-475e-9300-1F77BC8CAB8C}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>SoftphoneError Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{64D1E083-F63D-4297-85A0-2E4752FFC90F} points to the missing ApplicationID {DFB979A4-3182-475e-9300-1F77BC8CAB8C}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>SoftphonePhoneContact Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{F4D926F0-E589-450f-B33B-8A14555E1330} points to the missing ApplicationID {DFB979A4-3182-475e-9300-1F77BC8CAB8C}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>SoftphonePhoneNumber Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{0101014E-D958-4d10-82A1-9195E2220B66} points to the missing ApplicationID {DFB979A4-3182-475e-9300-1F77BC8CAB8C}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>TabletManager Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{786CDB70-1628-44A0-853C-5D340A499137}\TypeLib for this object point to the missing type library {D48CA453-5D1A-4BF9-B9BA-6CE8CB16F10A}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>ThirdPartyEapDispatcherAuthenticatorConfig</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{1FF84C3B-1140-4eb6-BE38-4BE618D2E7D6}\InprocServer32 points to the missing InprocServer32 %SystemRoot%\system32\eapa3hst.dll. The associated CLSID can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>ThirdPartyEapDispatcherAuthenticatorRuntime</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{B0E28D63-52F6-4e30-992B-78ECF97268E9}\InprocServer32 points to the missing InprocServer32 %SystemRoot%\system32\eapa3hst.dll. The associated CLSID can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>UserDictionary Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{836FA1B6-1190-4005-B434-7ED921BE2026}\TypeLib for this object point to the missing type library {9E52A566-D72F-4342-99B9-DBCA6780385F}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>VideoRenderCtl Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{888D5481-CABB-11D1-8505-00A0C91F9CA0}\TypeLib for this object point to the missing type library {888D5473-CABB-11D1-8505-00A0C91F9CA0}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>WIA Device Manager</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{A1F4E726-8CF1-11D1-BF92-0060081ED811}\TypeLib for this object point to the missing type library {99F74582-8CF1-11D1-BF92-0060081ED811}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>WIA FileSystem USD</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{D2923B86-15F1-46FF-A19A-DE825F919576}\ShellEx\ContextMenuHandlers\{b6c280f7-0f07-11d3-94c7-00805f6596d2} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{b6c280f7-0f07-11d3-94c7-00805f6596d2}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>WIA Logger</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{A1E75357-881A-419E-83E2-BB16DB197C68}\TypeLib for this object point to the missing type library {99F74582-8CF1-11D1-BF92-0060081ED811}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>WIA Video Preview Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{457A23DF-6F2A-4684-91D0-317FB768D87C}\TypeLib for this object point to the missing type library {179C8845-1F8D-498D-82BB-949CDF2C7236}. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Windows Live HW Device</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{1C109E4C-2F30-4EA3-A57A-A290877A2303} points to the missing ApplicationID {47C4DDCF-73DE-4A8C-B3A8-EBCC6DB01FAF}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Windows Live Logical Device</Entry>
<Details>The key HKEY_CLASSES_ROOT\CLSID\{B9F1D9B8-1DA6-4F17-962F-69EC82EA2704} points to the missing ApplicationID {83C4609B-7A93-4496-B467-21A906DCD9D0}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Windows Media Player</Entry>
<Details>The ToolboxBitmap32 key HKEY_CLASSES_ROOT\CLSID\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}\ToolboxBitmap32 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Windows Media Player</Entry>
<Details>The LocalServer32 key HKEY_CLASSES_ROOT\CLSID\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}\LocalServer32 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>WlcUI.dll</Entry>
<Details>The key HKEY_CLASSES_ROOT\AppID\WlcUI.dll points to the missing ApplicationID {DFB979A4-3182-475e-9300-1F77BC8CAB8C}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>WMI ADSI Extension Type Library</Entry>
<Details>The key HKEY_CLASSES_ROOT\TypeLib\{E503D000-5C7F-11D2-8B74-00104B2AFB41}\1.0\HELPDIR for this type library serves to indicate a help directory, but contains no data. This subkey can be deleted for this type library.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="Application paths">
<Description>The registry contains invalid search paths for a number of programs. These can be deleted.</Description>
<ErrorsInThisSection>2 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>pbrush.exe</Entry>
<Details>The registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\pbrush.exe contains an application path to pbrush.exe. This reference points to the missing target %SystemRoot%\system32\mspaint.exe and can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>yourapp.Exe</Entry>
<Details>The registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\yourapp.Exe contains an application path to yourapp.Exe. This reference points to the missing target C:\WINDOWS\yourapp.Exe and can be deleted.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="File types">
<Description>File types pointing to programs that are no longer on your system.</Description>
<ErrorsInThisSection>25 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>.CLP file (*.clp)</Entry>
<Details>The key HKEY_CLASSES_ROOT\.clp points to the missing key HKEY_CLASSES_ROOT\clpfile.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>.HLP file (*.hlp)</Entry>
<Details>The key HKEY_CLASSES_ROOT\.hlp points to the missing key HKEY_CLASSES_ROOT\hlpfile.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>.QUE file (*.que)</Entry>
<Details>The key HKEY_CLASSES_ROOT\.que points to the missing key HKEY_CLASSES_ROOT\QueueObject.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>AcroExch.RMFFile</Entry>
<Details>The key HKEY_CLASSES_ROOT\AcroExch.RMFFile\DefaultIcon points to the missing icon C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-A93000000001}\RMFFile_8.ico,0. The reference should be deleted so that Windows does not try to find the icon.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Adobe Acrobat Forms Document</Entry>
<Details>The key HKEY_CLASSES_ROOT\AcroExch.XFDFDoc\DefaultIcon points to the missing icon C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-A93000000001}\XFDFFile_8.ico,0. The reference should be deleted so that Windows does not try to find the icon.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Conteneur de classe Annuaire</Entry>
<Details>The key HKEY_CLASSES_ROOT\ADCS\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{89E30300-764D-11d0-B282-00A0C90F56FC}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>JavaPlugin.FamilyVersionSupport</Entry>
<Details>The key HKEY_CLASSES_ROOT\JavaPlugin.FamilyVersionSupport\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNR Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNR.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{B9696D4A-DA0F-4614-9891-EB1081D913E6}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNR Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNR\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{B9696D4A-DA0F-4614-9891-EB1081D913E6}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRCountryList Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRCountryList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{E803EB79-B72B-4974-84B4-1709B350C521}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRCountryList Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRCountryList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{E803EB79-B72B-4974-84B4-1709B350C521}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRGeoZone Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRGeoZone.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{D208013C-F782-4b67-A91C-B7C0FA201E00}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRGeoZone Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRGeoZone\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{D208013C-F782-4b67-A91C-B7C0FA201E00}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRNumberList Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRNumberList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{880EC974-2D63-433b-9B2D-4022476023A9}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRNumberList Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRNumberList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{880EC974-2D63-433b-9B2D-4022476023A9}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRParserSimple Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserSimple.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{76EE3666-467B-404b-A6FB-D1C6F2E3F821}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRParserSimple Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserSimple\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{76EE3666-467B-404b-A6FB-D1C6F2E3F821}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRParserThreaded Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserThreaded.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{EEDBEBD7-A7A2-4eca-ACB2-6EA87AE94F2B}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRParserThreaded Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRParserThreaded\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{EEDBEBD7-A7A2-4eca-ACB2-6EA87AE94F2B}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRPrefixList Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRPrefixList.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A86DEA6C-F7F5-4bfe-841F-D56D0702E46B}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRPrefixList Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRPrefixList\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{A86DEA6C-F7F5-4bfe-841F-D56D0702E46B}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRResults Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRResults.1\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{2FAE9765-4D8B-4bf7-9B85-95DF2A4E6120}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>PNRResults Class</Entry>
<Details>The key HKEY_CLASSES_ROOT\SkypePNR.PNRResults\CLSID points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{2FAE9765-4D8B-4bf7-9B85-95DF2A4E6120}.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>URL:Acrobat Protocol</Entry>
<Details>The key HKEY_CLASSES_ROOT\acrobat\DefaultIcon points to the missing icon C:\Program Files\Adobe\Reader 9.0\Acrobat\AcroRd32.exe. The reference should be deleted so that Windows does not try to find the icon.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>WMPCD</Entry>
<Details>The key HKEY_CLASSES_ROOT\WMPCD is empty. The associated file type is useless and can be deleted.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="Help files">
<Description>The registry contains references to help files that are no available in the system anymore. These entries can be removed safely.</Description>
<ErrorsInThisSection>4 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>Missing help file nwind9.cnt</Entry>
<Details>The registry contains a reference to the missing help file nwind9.cnt in the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Help. The entry can be removed.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing help file nwind9.hlp</Entry>
<Details>The registry contains a reference to the missing help file nwind9.hlp in the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Help. The entry can be removed.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing help file nwindcs9.cnt</Entry>
<Details>The registry contains a reference to the missing help file nwindcs9.cnt in the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Help. The entry can be removed.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing help file nwindcs9.hlp</Entry>
<Details>The registry contains a reference to the missing help file nwindcs9.hlp in the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Help. The entry can be removed.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="History lists">
<Description>Some entries in the Windows and program history lists refer to missing files and can be deleted.</Description>
<ErrorsInThisSection>17 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>Explorer history list: unneeded entry for the file type .BTR file (*.BTR)</Entry>
<Details>The Windows function Open With created the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BTR when you wanted to open a file with the extension .BTR. As no data has been written in the key, it can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Explorer history list: unneeded entry for the file type .DBX file (*.dbx)</Entry>
<Details>The Windows function Open With created the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dbx when you wanted to open a file with the extension .dbx. As no data has been written in the key, it can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Explorer history list: unneeded entry for the file type .DPS file (*.DPS)</Entry>
<Details>The Windows function Open With created the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DPS when you wanted to open a file with the extension .DPS. As no data has been written in the key, it can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Explorer history list: unneeded entry for the file type .UPT file (*.UPT)</Entry>
<Details>The Windows function Open With created the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.UPT when you wanted to open a file with the extension .UPT. As no data has been written in the key, it can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the folder avast! Free Antivirus</Entry>
<Details>The Windows history list contains a reference to the missing folder avast! Free Antivirus, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the folder OpenOffice.org 3.2</Entry>
<Details>The Windows history list contains a reference to the missing folder OpenOffice.org 3.2, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the shortcut avast! Free Antivirus.lnk</Entry>
<Details>The Windows history list contains a reference to the missing file avast! Free Antivirus.lnk, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the shortcut OpenOffice.org Base.lnk</Entry>
<Details>The Windows history list contains a reference to the missing file OpenOffice.org Base.lnk, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the shortcut OpenOffice.org Calc.lnk</Entry>
<Details>The Windows history list contains a reference to the missing file OpenOffice.org Calc.lnk, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the shortcut OpenOffice.org Draw.lnk</Entry>
<Details>The Windows history list contains a reference to the missing file OpenOffice.org Draw.lnk, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the shortcut OpenOffice.org Impress.lnk</Entry>
<Details>The Windows history list contains a reference to the missing file OpenOffice.org Impress.lnk, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the shortcut OpenOffice.org Math.lnk</Entry>
<Details>The Windows history list contains a reference to the missing file OpenOffice.org Math.lnk, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the shortcut OpenOffice.org Writer.lnk</Entry>
<Details>The Windows history list contains a reference to the missing file OpenOffice.org Writer.lnk, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Start menu history list: invalid reference to the shortcut OpenOffice.org.lnk</Entry>
<Details>The Windows history list contains a reference to the missing file OpenOffice.org.lnk, which is no longer in the Start menu. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Windows history list: invalid entry AvastUI.exe</Entry>
<Details>The Windows history list contains a reference to the missing file C:\Program Files\Alwil Software\Avast5\AvastUI.exe. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Windows history list: invalid entry MegaCasino.exe</Entry>
<Details>The Windows history list contains a reference to the missing file C:\Program Files\MegaCasino\MegaCasino.exe. This invalid entry can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Windows history list: invalid entry soffice.exe</Entry>
<Details>The Windows history list contains a reference to the missing file C:\Program Files\OpenOffice.org 3\program\soffice.exe. This invalid entry can be deleted.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="Shared files">
<Description>References and pointers to files in use by more than one application that no longer exist.</Description>
<ErrorsInThisSection>4 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>Missing shared file Extensions de l'environnement de compression de fichiers.</Entry>
<Details>The registry contains a reference to the missing shared file {764BF0E1-F219-11ce-972D-00AA00A14F56} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing shared file HashTab Context Menu.</Entry>
<Details>The registry contains a reference to the missing shared file {B1883831-F0D8-4453-8245-EEAAD866DD6E} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing shared file IE User Assist.</Entry>
<Details>The registry contains a reference to the missing shared file {FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing shared file Menu contextuel de cryptage.</Entry>
<Details>The registry contains a reference to the missing shared file {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="Software">
<Description>Programs listed in the Control Panel are no longer installed, do not have uninstall programs, or have other configuration problems.</Description>
<ErrorsInThisSection>16 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>Apple Application Support</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B2D328BE-45AD-4D92-96F9-2151490A203E} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Apple Mobile Device Support</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{85991ED2-010C-4930-96FA-52F43C2CE98A} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Apple Software Update</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C41300B9-185D-475E-BFEC-39EF732F19B1} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Bonjour</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0CB9668D-F979-4F31-B8B8-67FE90F929F8} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Incomplete entry eoRezo_is1</Entry>
<Details>The key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\eoRezo_is1 does not contain any data needed by Windows to remove the program or component and can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Incomplete entry {AC76BA86-7AD7-0000-2550-7A8C40000933}</Entry>
<Details>The key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AC76BA86-7AD7-0000-2550-7A8C40000933} does not contain any data needed by Windows to remove the program or component and can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>iTunes</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AB3A249-FB81-416B-917A-A2A10E74C503} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\BB2989D3157A84E4DA8C4E829965ECD1\SourceList\Net that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\9B00314CD581E574FBCE93FE37F2911B\SourceList\Net that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\EB823D2BDA5429D4699F121594A002E3\SourceList\Net that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\D8669BC0979F13F48B8B76EF099F928F\SourceList\Net that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\942A3BA718BFB61419A72A1AE0475C30\SourceList\Net that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{14F70674-ACC2-43CC-9DC4-47B8E7FF829E}\</Entry>
<Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF\SourceList\Net that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{14F70674-ACC2-43CC-9DC4-47B8E7FF829E}\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File :C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font 1 under HKEY_CLASSES_ROOT\Installer\Products\2DE19958C010039469AF254FC3C29EA8\SourceList\Net that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>QuickTime</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D9892BB-A751-4E48-ADC8-E4289956CE1D} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>SiSAGP driver</Entry>
<Details>The registry contains an entry for the font Installlocation under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DC226AC9-0314-496C-BE6A-B6A132628466} that points to the missing file C:\Program Files\Silicon Integrated Systems Corp.\SiSAGP driver.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="Sounds">
<Description>Some sounds refer to sound files that are no longer on your system.</Description>
<ErrorsInThisSection>2 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>Event IncomingCallNotification for the program Modem On Hold</Entry>
<Details>The registry key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\ModemOnHold\IncomingCallNotification\.Defaul t for the program Windows contains a reference to the missing file ringin.wav. This invalid reference can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Event IncomingCallNotification for the program Modem On Hold</Entry>
<Details>The registry key HKEY_CURRENT_USER\AppEvents\Schemes\Apps\ModemOnHold\IncomingCallNotification\.Curren t for the program Windows contains a reference to the missing file ringin.wav. This invalid reference can be deleted.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="Start menu">
<Description>Some shortcuts in the Start menu point to target that are no longer exist and/or the registry contains references to Start menu folders that no longer exist.</Description>
<ErrorsInThisSection>2 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>Empty key to Start menu folderHercules</Entry>
<Details>The registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Hercules is empty and is not needed. It can be deleted.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Invalid reference to Start menu folderavast! Free Antivirus</Entry>
<Details>The registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\avast! Free Antivirus points to the Start menu folder avast! Free Antivirus, which has been moved or deleted. The reference can be deleted.</Details>
</EntryDetails>
</Scanning>
- <Scanning Section="Deep Scan">
<Description>Invalid or orphaned references and pathways to system, application, and file settings.</Description>
<ErrorsInThisSection>117 Errors</ErrorsInThisSection>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.ShowMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.ShowMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.4\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.4\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.7\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.7\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.SlideMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.SlideMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Template.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Template.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.4\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.4\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.7\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Slide.7\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.Show.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\LiveScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\LiveScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\MSCAL.Calendar\Insertable key HKEY_LOCAL_MACHINE\software\Classes\MSCAL.Calendar\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\LiveScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\LiveScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2 AuthorJavaScript1.3 Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2 AuthorJavaScript1.3 Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.3\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\MSPowerPoint\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSPowerPoint\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\MSPowerPointSho\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSPowerPointSho\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.5\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\MSGraph.Chart.5\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.TemplateMacroEnabled.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\PowerPoint.TemplateMacroEnabled.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Hercules\WiFi Station\3.3.0.1 key HKEY_LOCAL_MACHINE\software\Hercules\WiFi Station\3.3.0.1 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\JavaSoft\Prefs key HKEY_LOCAL_MACHINE\software\JavaSoft\Prefs for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\FRANCE TELECOM\ORAHSS\SessionManager\Template key HKEY_LOCAL_MACHINE\software\FRANCE TELECOM\ORAHSS\SessionManager\Template for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\WordDocument\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\WordDocument\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\TrendMicro\HijackThis key HKEY_LOCAL_MACHINE\software\TrendMicro\HijackThis for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\wwl536\Polaroid Digital Cam\1.10.000 key HKEY_LOCAL_MACHINE\software\wwl536\Polaroid Digital Cam\1.10.000 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Silicon Integrated Systems Corp.\SiSAGP driver\1.21 key HKEY_LOCAL_MACHINE\software\Silicon Integrated Systems Corp.\SiSAGP driver\1.21 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Nero\Nero8\Nero - Burning Rom key HKEY_LOCAL_MACHINE\software\Nero\Nero8\Nero - Burning Rom for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Secure key HKEY_LOCAL_MACHINE\software\Secure for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Word.TemplateMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\dba64dc0-cd04-4ba0-8234-6597feab48b7 key HKEY_LOCAL_MACHINE\software\Classes\SVCID\ced2de40-bff6-11ce-9de8-00aa00a3f464\Providers\dba64dc0-cd04-4ba0-8234-6597feab48b7 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Sysmon.3\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Sysmon.3\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8213c52-b6b5-45b7-bf81-a80be25cf6ac key HKEY_LOCAL_MACHINE\software\Classes\SVCID\6407e780-7e5d-11d0-8ce6-00c04fdc877e\Providers\c8213c52-b6b5-45b7-bf81-a80be25cf6ac for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\d5644f33-2380-4c35-88e5-f88a7cd636f9 key HKEY_LOCAL_MACHINE\software\Classes\SVCID\01366d42-c04e-11d1-b1c0-00c04fc2f3ef\Providers\d5644f33-2380-4c35-88e5-f88a7cd636f9 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\SVCID\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\f60f7473-bc0a-47fa-bdd9-39d7e84e461f key HKEY_LOCAL_MACHINE\software\Classes\SVCID\488091f0-bff6-11ce-9de8-00aa00a3f464\Providers\f60f7473-bc0a-47fa-bdd9-39d7e84e461f for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Word.Template.12\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\WMPCD key HKEY_LOCAL_MACHINE\software\Classes\WMPCD for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\VBS\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\VBS\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\VBS Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\VBS Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.2\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Equations\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Equations\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation.3\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Equation.3\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation.2\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Equation.2\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.5\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.5\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Sheet.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Sheet.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.5\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Chart.5\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Equation\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\Equation\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\ECMAScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\ECMAScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\ECMAScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\ECMAScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\dba64dc0-cd04-4ba0-8234-6597feab48b7\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\dba64dc0-cd04-4ba0-8234-6597feab48b7\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Auslogics key HKEY_LOCAL_MACHINE\software\Auslogics for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\c8213c52-b6b5-45b7-bf81-a80be25cf6ac\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\c8213c52-b6b5-45b7-bf81-a80be25cf6ac\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\CID\d5644f33-2380-4c35-88e5-f88a7cd636f9\CustomProperties key HKEY_LOCAL_MACHINE\software\Classes\CID\d5644f33-2380-4c35-88e5-f88a7cd636f9\CustomProperties for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.Sheet.8\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.Sheet.8\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\14919ea49a8f3b4aa3cf1058d9a64cec key HKEY_LOCAL_MACHINE\software\14919ea49a8f3b4aa3cf1058d9a64cec for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\ALWIL Software\Avast key HKEY_LOCAL_MACHINE\software\ALWIL Software\Avast for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Apple Inc.\Bonjour\Services\SMB key HKEY_LOCAL_MACHINE\software\Apple Inc.\Bonjour\Services\SMB for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1 Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1 Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript1.1\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\JavaScript Author\OLEScript key HKEY_LOCAL_MACHINE\software\Classes\JavaScript Author\OLEScript for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\ExcelWorksheet\NotInsertable key HKEY_LOCAL_MACHINE\software\Classes\ExcelWorksheet\NotInsertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetBinaryMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetBinaryMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetMacroEnabled.12\Insertable key HKEY_LOCAL_MACHINE\software\Classes\Excel.SheetMacroEnabled.12\Insertable for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\ATI Technologies\ATI Control Panel\1.00.0000 key HKEY_LOCAL_MACHINE\software\ATI Technologies\ATI Control Panel\1.00.0000 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Empty Key</Entry>
<Details>The HKEY_LOCAL_MACHINE\software\ATI Technologies Inc.\Pilotes ATI\1.01.001 key HKEY_LOCAL_MACHINE\software\ATI Technologies Inc.\Pilotes ATI\1.01.001 for this object contains no data. This subkey can be deleted for this object.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : %11%\eapahost.dll</Entry>
<Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A8371A3-0C6D-487b-B3C8-46D785C4C940}\InProcServer32 that points to the missing file %11%\eapahost.dll.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : %SystemRoot%\system32\access.cpl</Entry>
<Details>The registry contains an entry for the font Module under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\Na meSpace\Accessibility_Options that points to the missing file %SystemRoot%\system32\access.cpl.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : %SystemRoot%\system32\asr_ldm.exe /backup</Entry>
<Details>The registry contains an entry for the font ASR utility for Logical Disk Manager under HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Asr\Commands that points to the missing file %SystemRoot%\system32\asr_ldm.exe /backup.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : %SystemRoot%\system32\eapa3hst.dll</Entry>
<Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9DAA7B9D-CE5B-42CE-B942-32BBC284AC44}\InProcServer32 that points to the missing file %SystemRoot%\system32\eapa3hst.dll.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : %SystemRoot%\system32\eapa3hst.dll</Entry>
<Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1FF84C3B-1140-4eb6-BE38-4BE618D2E7D6}\InprocServer32 that points to the missing file %SystemRoot%\system32\eapa3hst.dll.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : %SystemRoot%\system32\eapa3hst.dll</Entry>
<Details>The registry contains an entry for the font under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B0E28D63-52F6-4e30-992B-78ECF97268E9}\InprocServer32 that points to the missing file %SystemRoot%\system32\eapa3hst.dll.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : %SystemRoot%\Web\tip.htm</Entry>
<Details>The registry contains an entry for the font Url under HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4D5C8C25-D075-11d0-B416-00C04FB90376}\Instance\InitPropertyBag that points to the missing file %SystemRoot%\Web\tip.htm.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : @C:\WINDOWS\system32\fr-fr\mstsc.exe.mui,-4002</Entry>
<Details>The registry contains an entry for the font MUIVerb under HKEY_LOCAL_MACHINE\software\Classes\RDP.File\shell\Connect that points to the missing file @C:\WINDOWS\system32\fr-fr\mstsc.exe.mui,-4002.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : @C:\WINDOWS\system32\fr-fr\mstsc.exe.mui,-4003</Entry>
<Details>The registry contains an entry for the font MUIVerb under HKEY_LOCAL_MACHINE\software\Classes\RDP.File\shell\Edit that points to the missing file @C:\WINDOWS\system32\fr-fr\mstsc.exe.mui,-4003.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : @C:\WINDOWS\system32\fr-fr\mstsc.exe.mui,-4004</Entry>
<Details>The registry contains an entry for the font FriendlyTypeName under HKEY_LOCAL_MACHINE\software\Classes\RDP.File that points to the missing file @C:\WINDOWS\system32\fr-fr\mstsc.exe.mui,-4004.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{3D9892BB-A751-4E48-ADC8-E4289956CE1D} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{7AB3A249-FB81-416B-917A-A2A10E74C503} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9B00314CD581E574FBCE93FE37F2911B\InstallProperties that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\{0CB9668D-F979-4F31-B8B8-67FE90F929F8} that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EB823D2BDA5429D4699F121594A002E3\InstallProperties that points to the missing file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\.</Details>
</EntryDetails>
- <EntryDetails>
<Entry>Missing File : C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP591.TMP\</Entry>
<Details>The registry contains an entry for the font InstallSource under HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install

 

soize

Avatar de soize
11 messages
Barrette de RAM
Barrette de RAM

Lien direct Le 30 Janvier 2011 à 06h53

Voici le rapport de avira:




Avira AntiVir Personal
Date de création du fichier de rapport : dimanche 30 janvier 2011 06:57

La recherche porte sur 2435637 souches de virus.

Le programme fonctionne en version intégrale illimitée.
Les services en ligne sont disponibles.

Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
Numéro de série : 0000149996-ADJIE-0000001
Plateforme : Windows XP
Version de Windows : (Service Pack 3) [5.1.2600]
Mode Boot : Démarré normalement
Identifiant : Administrateur
Nom de l'ordinateur : E2584C21B7A14B2

Informations de version :
BUILD.DAT : 10.0.0.107 31825 Bytes 09/12/2010 10:51:00
AVSCAN.EXE : 10.0.3.5 435368 Bytes 06/12/2010 07:47:41
AVSCAN.DLL : 10.0.3.0 56168 Bytes 06/12/2010 07:48:04
LUKE.DLL : 10.0.3.2 104296 Bytes 06/12/2010 07:47:53
LUKERES.DLL : 10.0.0.0 13672 Bytes 06/12/2010 07:48:05
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 08:05:36
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 05:53:34
VBASE002.VDF : 7.11.0.1 2048 Bytes 14/12/2010 05:53:34
VBASE003.VDF : 7.11.0.2 2048 Bytes 14/12/2010 05:53:35
VBASE004.VDF : 7.11.0.3 2048 Bytes 14/12/2010 05:53:35
VBASE005.VDF : 7.11.0.4 2048 Bytes 14/12/2010 05:53:35
VBASE006.VDF : 7.11.0.5 2048 Bytes 14/12/2010 05:53:35
VBASE007.VDF : 7.11.0.6 2048 Bytes 14/12/2010 05:53:35
VBASE008.VDF : 7.11.0.7 2048 Bytes 14/12/2010 05:53:35
VBASE009.VDF : 7.11.0.8 2048 Bytes 14/12/2010 05:53:35
VBASE010.VDF : 7.11.0.9 2048 Bytes 14/12/2010 05:53:35
VBASE011.VDF : 7.11.0.10 2048 Bytes 14/12/2010 05:53:35
VBASE012.VDF : 7.11.0.11 2048 Bytes 14/12/2010 05:53:35
VBASE013.VDF : 7.11.0.52 128000 Bytes 16/12/2010 05:53:36
VBASE014.VDF : 7.11.0.91 226816 Bytes 20/12/2010 05:53:38
VBASE015.VDF : 7.11.0.122 136192 Bytes 21/12/2010 05:53:39
VBASE016.VDF : 7.11.0.156 122880 Bytes 24/12/2010 05:53:40
VBASE017.VDF : 7.11.0.185 146944 Bytes 27/12/2010 05:53:41
VBASE018.VDF : 7.11.0.228 132608 Bytes 30/12/2010 05:53:43
VBASE019.VDF : 7.11.1.5 148480 Bytes 03/01/2011 05:53:45
VBASE020.VDF : 7.11.1.37 156672 Bytes 07/01/2011 05:53:46
VBASE021.VDF : 7.11.1.65 140800 Bytes 10/01/2011 05:53:47
VBASE022.VDF : 7.11.1.87 225280 Bytes 11/01/2011 05:53:49
VBASE023.VDF : 7.11.1.124 125440 Bytes 14/01/2011 05:53:49
VBASE024.VDF : 7.11.1.155 132096 Bytes 17/01/2011 05:53:50
VBASE025.VDF : 7.11.1.189 451072 Bytes 20/01/2011 05:53:53
VBASE026.VDF : 7.11.1.230 138752 Bytes 24/01/2011 05:53:54
VBASE027.VDF : 7.11.2.12 164352 Bytes 27/01/2011 05:53:55
VBASE028.VDF : 7.11.2.13 2048 Bytes 27/01/2011 05:53:55
VBASE029.VDF : 7.11.2.14 2048 Bytes 27/01/2011 05:53:56
VBASE030.VDF : 7.11.2.15 2048 Bytes 27/01/2011 05:53:56
VBASE031.VDF : 7.11.2.31 71168 Bytes 28/01/2011 05:53:56
Version du moteur : 8.2.4.150
AEVDF.DLL : 8.1.2.1 106868 Bytes 06/12/2010 07:47:38
AESCRIPT.DLL : 8.1.3.52 1282426 Bytes 30/01/2011 05:54:08
AESCN.DLL : 8.1.7.2 127349 Bytes 06/12/2010 07:47:36
AESBX.DLL : 8.1.3.2 254324 Bytes 06/12/2010 07:47:36
AERDL.DLL : 8.1.9.2 635252 Bytes 06/12/2010 07:47:36
AEPACK.DLL : 8.2.4.8 512374 Bytes 30/01/2011 05:54:07
AEOFFICE.DLL : 8.1.1.15 205178 Bytes 30/01/2011 05:54:05
AEHEUR.DLL : 8.1.2.68 3178870 Bytes 30/01/2011 05:54:05
AEHELP.DLL : 8.1.16.0 246136 Bytes 03/12/2010 16:43:36
AEGEN.DLL : 8.1.5.2 397683 Bytes 30/01/2011 05:53:59
AEEMU.DLL : 8.1.3.0 393589 Bytes 06/12/2010 07:47:31
AECORE.DLL : 8.1.19.2 196983 Bytes 30/01/2011 05:53:58
AEBB.DLL : 8.1.1.0 53618 Bytes 06/12/2010 07:47:30
AVWINLL.DLL : 10.0.0.0 19304 Bytes 06/12/2010 07:47:42
AVPREF.DLL : 10.0.0.0 44904 Bytes 06/12/2010 07:47:41
AVREP.DLL : 10.0.0.8 62209 Bytes 17/06/2010 13:27:52
AVREG.DLL : 10.0.3.2 53096 Bytes 06/12/2010 07:47:41
AVSCPLR.DLL : 10.0.3.2 84328 Bytes 06/12/2010 07:47:41
AVARKT.DLL : 10.0.22.6 231784 Bytes 06/12/2010 07:47:39
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 06/12/2010 07:47:40
SQLITE3.DLL : 3.6.19.0 355688 Bytes 17/06/2010 13:28:02
AVSMTP.DLL : 10.0.0.17 63848 Bytes 06/12/2010 07:47:42
NETNT.DLL : 10.0.0.0 11624 Bytes 17/06/2010 13:28:01
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 10/02/2010 23:23:03
RCTEXT.DLL : 10.0.58.0 99688 Bytes 06/12/2010 07:48:06

Configuration pour la recherche actuelle :
Nom de la tâche...............................: Bref contrôle système après installation
Fichier de configuration......................: c:\program files\avira\antivir desktop\setupprf.dat
Documentation.................................: bas
Action principale.............................: interactif
Action secondaire.............................: ignorer
Recherche sur les secteurs d'amorçage maître..: marche
Recherche sur les secteurs d'amorçage.........: marche
Recherche dans les programmes actifs..........: marche
Recherche en cours sur l'enregistrement.......: marche
Recherche de Rootkits.........................: arrêt
Contrôle d'intégrité de fichiers système......: arrêt
Fichier mode de recherche.....................: Sélection de fichiers intelligente
Recherche sur les archives....................: marche
Limiter la profondeur de récursivité..........: 20
Archive Smart Extensions......................: marche
Heuristique de macrovirus.....................: marche
Heuristique fichier...........................: moyen

Début de la recherche : dimanche 30 janvier 2011 06:57

La recherche sur les processus démarrés commence :
Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avconfig.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avshadow.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
Processus de recherche 'wmiprvse.exe' - '1' module(s) sont contrôlés
Processus de recherche 'setup.exe' - '1' module(s) sont contrôlés
Processus de recherche 'presetup.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avira_antivir_personal_fr[1].exe' - '1' module(s) sont contrôlés
Processus de recherche 'SkypeNames2.exe' - '1' module(s) sont contrôlés
Processus de recherche 'IEXPLORE.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'IEXPLORE.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'FTCOMModule.exe' - '1' module(s) sont contrôlés
Processus de recherche 'OraConfigRecover.exe' - '1' module(s) sont contrôlés
Processus de recherche 'CoreCom.exe' - '1' module(s) sont contrôlés
Processus de recherche 'deskboard.exe' - '1' module(s) sont contrôlés
Processus de recherche 'connectivitymanager.exe' - '1' module(s) sont contrôlés
Processus de recherche 'Launcher.exe' - '1' module(s) sont contrôlés
Processus de recherche 'iPodService.exe' - '1' module(s) sont contrôlés
Processus de recherche 'WifiStation.exe' - '1' module(s) sont contrôlés
Processus de recherche 'AlertModule.exe' - '1' module(s) sont contrôlés
Processus de recherche 'Skype.exe' - '1' module(s) sont contrôlés
Processus de recherche 'DTLite.exe' - '1' module(s) sont contrôlés
Processus de recherche 'jusched.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SystrayApp.exe' - '1' module(s) sont contrôlés
Processus de recherche 'iTunesHelper.exe' - '1' module(s) sont contrôlés
Processus de recherche 'atiptaxx.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SOUNDMAN.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'Explorer.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'Ati2evxx.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'slserv.exe' - '1' module(s) sont contrôlés
Processus de recherche 'mdm.exe' - '1' module(s) sont contrôlés
Processus de recherche 'jqs.exe' - '1' module(s) sont contrôlés
Processus de recherche 'FTRTSVC.exe' - '1' module(s) sont contrôlés
Processus de recherche 'mDNSResponder.exe' - '1' module(s) sont contrôlés
Processus de recherche 'AppleMobileDeviceService.exe' - '1' module(s) sont contrôlés
Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'Ati2evxx.exe' - '1' module(s) sont contrôlés
Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés

La recherche sur les secteurs d'amorçage maître commence :
Secteur d'amorçage maître HD0
[INFO] Aucun virus trouvé !
Secteur d'amorçage maître HD1
[INFO] Aucun virus trouvé !

La recherche sur les secteurs d'amorçage commence :

La recherche sur les renvois aux fichiers exécutables (registre) commence :
C:\WINDOWS\system32\drivers\sptd.sys
[AVERTISSEMENT] Impossible d'ouvrir le fichier !
Le registre a été contrôlé ( '992' fichiers).



Fin de la recherche : dimanche 30 janvier 2011 06:58
Temps nécessaire: 01:33 Minute(s)

La recherche a été effectuée intégralement

0 Les répertoires ont été contrôlés
1474 Des fichiers ont été contrôlés
0 Des virus ou programmes indésirables ont été trouvés
0 Des fichiers ont été classés comme suspects
0 Des fichiers ont été supprimés
0 Des virus ou programmes indésirables ont été réparés
0 Les fichiers ont été déplacés dans la quarantaine
0 Les fichiers ont été renommés
1 Impossible de scanner des fichiers
1473 Fichiers non infectés
5 Les archives ont été contrôlées
1 Avertissements
0 Consignes

 

Winx

Avatar de Winx
27904 messages
No-Life
No-Life
AidoHardware
AidoHardware
AidoAntivirus
AidoAntivirus
AidoWindows
AidoWindows

Lien direct Le 30 Janvier 2011 à 11h01

re,
refais moi un rapport Malwarebytes' Anti-Malware (MBAM) le tiens est en XLM, et non en fichier texte et pas trés visible
donc refais ceci:

Ensuite fais ceci:
Télécharge Malwarebytes' Anti-Malware (MBAM)


    [*] Double clique sur le fichier téléchargé pour lancer le processus d'installation.
    [*] Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour": si le pare-feu demande l'autorisation à MBAM de se connecter, accepte.
    [*] Une fois la mise à jour terminée, rends-toi dans l'onglet "Recherche".
    [*] Sélectionne "Exécuter un examen rapide"
    [*] Clique sur "Rechercher"
    [*] L'analyse démarre, le scan est relativement long, c'est normal.
    [*] A la fin de l'analyse, un message s'affiche :

    Citation

    L'examen s'est terminé normalement. Clique sur 'Afficher les résultats' pour afficher tous les objets trouvés.


    Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
    [*] Ferme tes navigateurs.
    [*] Si des malwares ont été détectés, clique sur Afficher les résultats.
    Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    [*] MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport et poste-le dans ta prochaine réponse.




ps:
--->aide visuelle sur Mbam ici

Je n'ai pas la prétention de résoudre les problèmes, mais celle de vous aider à les résoudre ;-)
 

<<<1>>>

[Page 1 sur 1 - 13 messages]