Virus et spybot (suite)

Tu peut vérifier avec des scan en ligne Kaspersky, Housecall, Bitdenfender

Excusez les Amis un probs de ligne depuis Samedi matin et ce pour quelques jours,le mieux un scan

trendMicro ( Houscall)+supression des resultats

housecall.trendmicro.com…

  On va utiliser Ccleaner 
  Télécharger CCleaner sur le bureau:
  Ne le télécharge pas si tu l'as déjà !
  [www.clubic.com...](http://www.clubic.com/telecharger-fiche14492-ccleaner-crap-cleaner.html)
  Une fois sur le bureau, clic sur l'install de CCleaner.
  -> Mais avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires".
  Ensuite, clique sur "Options", "Avancé" et décoche la case--->
  "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
  Clique sur l'onglet "Nettoyeur" puis sur "Lancer le Nettoyage".
  -> Ensuite clique sur l'icone Registre, à droite, clique sur "Chercher des erreurs" puis sur "Réparer les erreurs sélectionnées".

  Accepte la sauvegarde, de la BDR (base de registre )qu'il propose .
  Je te conseille de le repasser au moins deux fois,(ou + jusqu'à qu'il ne trouve plus d'erreurs.)

Puis Scan en Ligne avec Kaspersky ,post le log ici
a+
Un bonjour perso a Guigui14100:hello:

:hello:

Je dévis le sujet mais AOL fournis sa version bridée de McAfee VirusScan. :slight_smile: Cependant McAfee n’est pas un des meilleurs.

retour difficile ce 22 aout et en plus sous la pluie … bouh… et puis mon fichu virus …
OH … il va falloir que je m’y colle (pas lyonnaise pour rien la nana)
mais que vois-je :ouch:
WAOUH une réponse de guigui14100 et cricri58 (trop fort)
Trop cool… ah le soleil resurgit tout à coup …
J’y vais de ce pas sur Housecall
d’ailleurs il bosse pendant que j’écris et ensuite je télécharge ccleaner avec toute la manip à suivre

Merci merci les mecs, c’est trop cooooooooooolllllllllllllllll !!!
Je vous tiens au courant de l’évolution
:oui:
@+++++++++++

Ok je suis la si ta besoin :wink:

Bouhhhhhhhh :kaola: grrrrrrrrrrrrrr!!! :-@:
J’ai bien bossé, hum hum … 2 passages de Housecall à la demande de la boite de dialogue (bizarre non???)
J’ai mis comme me l’a demandé cricri58 CCleaner sur le bureau.
Je double clique sur l’icone. J’arrive à décocher toutes les options supplémentaires mais je ne trouve pas (nom d’un chien, j’ai essayé au moins 4 fois) Options puis Avancées … du coup impossible de poursuivre la manip. :@

Qu’est-ce que je fais mal ??? :grrr:
Zut de flûte!!!
Tout ça pour vous dire que je n’y arrive pas. Que dois-je faire pour en terminer… de tout cela?
Merci de votre écoute
Douce nuit
Mod

Bonjour
Télécharger CCleaner sur le bureau:
Ne le télécharge pas si tu l’as déjà !
www.clubic.com…

Une fois sur le bureau, clic sur l’install de CCleaner.
-> Mais avant de cliquer sur le bouton “installer”, décoche toutes les “options supplémentaires”.
Ensuite, clique sur “Options”, “Avancé” et décoche la case—>
“Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures”.
Clique sur l’onglet “Nettoyeur” puis sur “Lancer le Nettoyage”.
-> Ensuite clique sur l’icone Registre, à droite, clique sur “Chercher des erreurs” puis sur “Réparer les erreurs sélectionnées”.

Accepte la sauvegarde, de la BDR (base de registre )qu’il propose .
Je te conseille de le repasser au moins deux fois,(ou + jusqu’à qu’il ne trouve plus d’erreurs.)

Une Fois Installé ,ouvre Ccleaner puis options,clique sur Avancé
tu decoches la ligne du haut
Effacer les fichiers,du dossier temp de windows,plus vieux que 48 heures et tu refermes
ou tu l utilises
OK!!!

:hello:

coucou :wink:
toujours présent :clap:
ok… c’est fait (j’ai enfin réussi la manip :super: et je te joins le truc que j’ai sauvegardé, apparemment aucune erreur trouvée
Pour tout dire, je ne comprends RIEN
Normal… pour moi
Merci encore et je t’écoute cricri58 pour savoir la suite à donner à tout cela
^ ^)

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\Artcopy6x.Document]
@=“DocumentArtcopy”

[HKEY_CLASSES_ROOT\Artcopy6x.Document\shell]

[HKEY_CLASSES_ROOT\AU_ISC]
@=“AU ISC Server Application”

[HKEY_CLASSES_ROOT\AU_ISC\CLSID]
@="{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}"

[HKEY_CLASSES_ROOT\AU_ISC\CurVer]
@=“AU_ISC.1”

[HKEY_CLASSES_ROOT\AU_ISC.1]
@=“AU ISC Server Application”

[HKEY_CLASSES_ROOT\AU_ISC.1\CLSID]
@="{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}"

[HKEY_CLASSES_ROOT\Cab.CabIn]
@=“CabIn Class”

[HKEY_CLASSES_ROOT\Cab.CabIn\CLSID]
@="{D8B4A55C-FA70-4181-B340-B92451E4DA62}"

[HKEY_CLASSES_ROOT\Cab.CabIn\CurVer]
@=“Cab.CabIn.1”

[HKEY_CLASSES_ROOT\Cab.CabIn.1]
@=“CabIn Class”

[HKEY_CLASSES_ROOT\Cab.CabIn.1\CLSID]
@="{D8B4A55C-FA70-4181-B340-B92451E4DA62}"

[HKEY_CLASSES_ROOT\CmdLineExt.CmdLineContextMenu]
@=“CmdLineContextMenu Class”

[HKEY_CLASSES_ROOT\CmdLineExt.CmdLineContextMenu\CLSID]
@="{9869EFB4-18E9-11D3-A837-00104B9E30B5}"

[HKEY_CLASSES_ROOT\CmdLineExt.CmdLineContextMenu\CurVer]
@=“CmdLineExt.CmdLineContextMenu.1”

[HKEY_CLASSES_ROOT\CmdLineExt.CmdLineContextMenu.1]
@=“CmdLineContextMenu Class”

[HKEY_CLASSES_ROOT\CmdLineExt.CmdLineContextMenu.1\CLSID]
@="{9869EFB4-18E9-11D3-A837-00104B9E30B5}"

[HKEY_CLASSES_ROOT\helix.duration]
@=“HelixDuration Class”

[HKEY_CLASSES_ROOT\helix.duration\CLSID]
@="{80F6E410-210B-454C-B523-97D7C2541FF3}"

[HKEY_CLASSES_ROOT\helix.duration\CurVer]
@=“Ctrl.Duration.1”

[HKEY_CLASSES_ROOT\helix.duration.1]
@=“HelixDuration Class”

[HKEY_CLASSES_ROOT\helix.duration.1\CLSID]
@="{80F6E410-210B-454C-B523-97D7C2541FF3}"

[HKEY_CLASSES_ROOT\helix.producer]
@=“HelixProducerCtrl Class”

[HKEY_CLASSES_ROOT\helix.producer\CLSID]
@="{66F8592D-33E8-11D7-8A24-00045A785B71}"

[HKEY_CLASSES_ROOT\helix.producer\CurVer]
@=“helix.producer.1”

[HKEY_CLASSES_ROOT\helix.producer.1]
@=“HelixProducerCtrl Class”

[HKEY_CLASSES_ROOT\helix.producer.1\CLSID]
@="{66F8592D-33E8-11D7-8A24-00045A785B71}"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin]
@=“ActiveXPlugin Object”

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\CLSID]
@="{06DD38D3-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\CurVer]
@=“Microsoft.ActiveXPlugin.1”

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin\NotInsertable]

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1]
@=“ActiveXPlugin Object”

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1\CLSID]
@="{06DD38D3-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\Microsoft.ActiveXPlugin.1\NotInsertable]

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker]
@=""

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker\CLSID]
@="{111C85E9-BB62-4528-A806-F0BE908E02F0}"

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker\CurVer]
@=“MSNMessenger.ContactsPicker.1”

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker.1]
@=""

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker.1\CLSID]
@="{111C85E9-BB62-4528-A806-F0BE908E02F0}"

[HKEY_CLASSES_ROOT\MSNMessenger.ContactsPicker.1\CurVer]
@=“MSNMessenger.ContactsPicker”

[HKEY_CLASSES_ROOT\OrbTVBuffer.MiTVSink]
@=“CMiTVSink Object”

[HKEY_CLASSES_ROOT\OrbTVBuffer.MiTVSink\CLSID]
@="{EEB09DE1-1892-43B5-9730-B3FA8361B13A}"

[HKEY_CLASSES_ROOT\OrbTVBuffer.MiTVSink\CurVer]
@=“OrbTVBuffer.MiTVSink.1”

[HKEY_CLASSES_ROOT\OrbTVBuffer.MiTVSink.1]
@=“CMiTVSink Object”

[HKEY_CLASSES_ROOT\OrbTVBuffer.MiTVSink.1\CLSID]
@="{EEB09DE1-1892-43B5-9730-B3FA8361B13A}"

[HKEY_CLASSES_ROOT\SpybotSD.DisabledFile]
@=“Disabled startup file”

[HKEY_CLASSES_ROOT\SpybotSD.DisabledFile\shell]

[HKEY_CLASSES_ROOT\SpybotSD.SBEFile]
@=“Spyware exclude file”

[HKEY_CLASSES_ROOT\SpybotSD.SBEFile\shell]

[HKEY_CLASSES_ROOT\SpybotSD.SBIFile]
@=“Spyware include file”

[HKEY_CLASSES_ROOT\SpybotSD.SBIFile\shell]

[HKEY_CLASSES_ROOT\SpybotSD.SBSFile]
@=“Spyware supplemental file”

[HKEY_CLASSES_ROOT\SpybotSD.SBSFile\shell]

[HKEY_CLASSES_ROOT\SpybotSD.TInfoFile]
@=“Internal informations”

[HKEY_CLASSES_ROOT\SpybotSD.TInfoFile\shell]

[HKEY_CLASSES_ROOT\SpybotSD.UTIFile]
@=“Usage tracks include file”

[HKEY_CLASSES_ROOT\SpybotSD.UTIFile\shell]

[HKEY_CLASSES_ROOT\SpybotSD.UTSFile]
@=“Usage tracks supplemental file”

[HKEY_CLASSES_ROOT\SpybotSD.UTSFile\shell]

[HKEY_CLASSES_ROOT\ViewingBooth6.Document]
@=“Document Viewing Booth 6.0”

[HKEY_CLASSES_ROOT\ViewingBooth6.Document\shell]

[HKEY_CLASSES_ROOT\Applications\ARTCOP~1.EXE]

[HKEY_CLASSES_ROOT\Applications\ARTCOP~1.EXE\shell]

[HKEY_CLASSES_ROOT\Applications\MSMoney.EXE]

[HKEY_CLASSES_ROOT\Applications\MSMoney.EXE\shell]
@=“Open”

[HKEY_CLASSES_ROOT\Applications\viewbo~1.exe]

[HKEY_CLASSES_ROOT\Applications\viewbo~1.exe\shell]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ShockwaveFlash]
“SlowInfoCache”=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000


C'était donc le second nettoyage. Ci-joint le premier Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
“C:\Program Files\Ahead\Nero BackItUp\BackItUp-Deu.nls”=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
“C:\WINDOWS\TEMP\_ISTMP0.DIR\LXARPP.DLL”=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
“C:\WINDOWS\system32\pxwma.dll”=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
“C:\WINDOWS\system32\pxinsi64.exe”=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
“C:\WINDOWS\system32\pxcpyi64.exe”=dword:00000001

[HKEY_CLASSES_ROOT.aa]

[HKEY_CLASSES_ROOT.jpa]
@=""

[HKEY_CLASSES_ROOT.MP+]

[HKEY_CLASSES_ROOT.MPC]

[HKEY_CLASSES_ROOT.MPP]

[HKEY_CLASSES_ROOT.ndf]

[HKEY_CLASSES_ROOT.pcx]
@=""

[HKEY_CLASSES_ROOT\OmniPage]

[HKEY_CLASSES_ROOT\PrintArtist.Document]

[HKEY_CLASSES_ROOT\SysmonLogManager.Snapin]

[HKEY_CLASSES_ROOT\WMPCD]

[HKEY_CLASSES_ROOT{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.\OpenWithList]
“a”=“shimgvw.dll”
“MRUList”=“ba”
“b”=“Psuite.exe”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.001]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.001\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.256]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.256\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.adh]
“Progid”=“adhfile”
“Application”=“C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.awl]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.awl\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.BMK]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.BMK\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.BWA]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.BWA\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.BWI]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.BWI\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.BWT]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.BWT\OpenWithList]
“a”=“Alcohol.exe”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.CD1]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.CD1\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.CE]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.CE\OpenWithList]
“a”=“EXCEL.EXE”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.class]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.class\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.cue]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.cue\OpenWithList]
“a”=“Alcohol.exe”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.CWS]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.CWS\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.DBF]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.DBF\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.dxr]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.dxr\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.FAV]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.FAV\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.HT_]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.HT_\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.isu]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.isu\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.LiveSubscribe]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.LiveSubscribe\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.LiveSubscribe\OpenWithProgids]
“LiveReg.UserProfile”=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.M12]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.M12\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.M12\OpenWithProgids]
“Money.LegacyDoc12”=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.mbf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.mbf\OpenWithList]
“a”=“MSMoney.EXE”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.mbf\OpenWithProgids]
“MoneyBackup.Document”=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.MDX]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.MDX\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.mny]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.mny\OpenWithList]
“a”=“MSMoney.EXE”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.mny\OpenWithProgids]
“Money.Document”=hex(0):

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.MSW]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.MSW\OpenWithList]
“a”=“moviemk.exe”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.PC]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.PC\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.pe4]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.pe4\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.Po]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.Po\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.prn]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.prn\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.pst]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.pst\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.ra]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.ra\OpenWithList]
“a”=“firefox.exe”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.ram]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.ram\OpenWithList]
“a”=“firefox.exe”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.rm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.rm\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.SAV]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.SAV\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.scc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.scc\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.sfv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.sfv\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.stw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.stw\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.sxw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.sxw\OpenWithList]
“a”=“iexplore.exe”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.tmp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.tmp\OpenWithList]
“a”=“WINWORD.EXE”
“MRUList”=“a”

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.trace]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.trace\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.tst]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.tst\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.USB]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.USB\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.xsv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts.xsv\OpenWithList]

[HKEY_CLASSES_ROOT\acrobat\DefaultIcon]
@=“C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroRd32.exe”

[HKEY_CLASSES_ROOT\Artcopy6x.Document\DefaultIcon]
@=“C:\PROGRA~1\LEXMAR~1\ARTCOP~1.EXE,1”

[HKEY_CLASSES_ROOT\Artcopy6x.Document\shell\open]

[HKEY_CLASSES_ROOT\Artcopy6x.Document\shell\open\command]
@="C:\PROGRA~1\LEXMAR~1\ARTCOP~1.EXE “%1"”

[HKEY_CLASSES_ROOT\Artcopy6x.Document\shell\print]

[HKEY_CLASSES_ROOT\Artcopy6x.Document\shell\print\command]
@="C:\PROGRA~1\LEXMAR~1\ARTCOP~1.EXE /p “%1"”

[HKEY_CLASSES_ROOT\Artcopy6x.Document\shell\printto]

[HKEY_CLASSES_ROOT\Artcopy6x.Document\shell\printto\command]
@="C:\PROGRA~1\LEXMAR~1\ARTCOP~1.EXE /pt “%1” “%2” “%3” “%4"”

[HKEY_CLASSES_ROOT\DirectAnimation.PathControl]
@=“Microsoft DirectAnimation Path”

[HKEY_CLASSES_ROOT\DirectAnimation.PathControl\CLSID]
@="{D7A7D7C3-D47F-11D0-89D3-00A0C90833E6}"

[HKEY_CLASSES_ROOT\DirectAnimation.Sequence]
@=“Microsoft DirectAnimation Sequence”

[HKEY_CLASSES_ROOT\DirectAnimation.Sequence\CLSID]
@="{4F241DB1-EE9F-11D0-9824-006097C99E51}"

[HKEY_CLASSES_ROOT\DirectAnimation.SequencerControl]
@=“Microsoft DirectAnimation Sequencer”

[HKEY_CLASSES_ROOT\DirectAnimation.SequencerControl\CLSID]
@="{B0A6BAE2-AAF0-11D0-A152-00A0C908DB96}"

[HKEY_CLASSES_ROOT\DirectAnimation.SpriteControl]
@=“Microsoft DirectAnimation Sprite”

[HKEY_CLASSES_ROOT\DirectAnimation.SpriteControl\CLSID]
@="{FD179533-D86E-11D0-89D6-00A0C90833E6}"

[HKEY_CLASSES_ROOT\DirectAnimation.StructuredGraphicsControl]
@=“Microsoft DirectAnimation Structured Graphics”

[HKEY_CLASSES_ROOT\DirectAnimation.StructuredGraphicsControl\CLSID]
@="{369303C2-D7AC-11D0-89D5-00A0C90833E6}"

[HKEY_CLASSES_ROOT\SpybotSD.DisabledFile\DefaultIcon]
@="“C:\Program Files\Spybot - Search & Destroy\blindman.exe”,0"

[HKEY_CLASSES_ROOT\SpybotSD.DisabledFile\shell\open]

[HKEY_CLASSES_ROOT\SpybotSD.DisabledFile\shell\open\command]
@="“C:\Program Files\Spybot - Search & Destroy\blindman.exe” “%1"”

[HKEY_CLASSES_ROOT\SpybotSD.SBEFile\DefaultIcon]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe”,0"

[HKEY_CLASSES_ROOT\SpybotSD.SBEFile\shell\open]

[HKEY_CLASSES_ROOT\SpybotSD.SBEFile\shell\open\command]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe” “%1"”

[HKEY_CLASSES_ROOT\SpybotSD.SBIFile\DefaultIcon]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe”,0"

[HKEY_CLASSES_ROOT\SpybotSD.SBIFile\shell\open]

[HKEY_CLASSES_ROOT\SpybotSD.SBIFile\shell\open\command]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe” “%1"”

[HKEY_CLASSES_ROOT\SpybotSD.SBSFile\DefaultIcon]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe”,0"

[HKEY_CLASSES_ROOT\SpybotSD.SBSFile\shell\open]

[HKEY_CLASSES_ROOT\SpybotSD.SBSFile\shell\open\command]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe” “%1"”

[HKEY_CLASSES_ROOT\SpybotSD.TInfoFile\DefaultIcon]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe”,0"

[HKEY_CLASSES_ROOT\SpybotSD.TInfoFile\shell\open]

[HKEY_CLASSES_ROOT\SpybotSD.TInfoFile\shell\open\command]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe” “%1"”

[HKEY_CLASSES_ROOT\SpybotSD.UTIFile\DefaultIcon]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe”,0"

[HKEY_CLASSES_ROOT\SpybotSD.UTIFile\shell\open]

[HKEY_CLASSES_ROOT\SpybotSD.UTIFile\shell\open\command]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe” “%1"”

[HKEY_CLASSES_ROOT\SpybotSD.UTSFile\DefaultIcon]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe”,0"

[HKEY_CLASSES_ROOT\SpybotSD.UTSFile\shell\open]

[HKEY_CLASSES_ROOT\SpybotSD.UTSFile\shell\open\command]
@="“C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe” “%1"”

[HKEY_CLASSES_ROOT\ViewingBooth6.Document\DefaultIcon]
@=“C:\PROGRA~1\LEXMAR~1\viewbo~1.exe,1”

[HKEY_CLASSES_ROOT\ViewingBooth6.Document\shell\open]

[HKEY_CLASSES_ROOT\ViewingBooth6.Document\shell\open\command]
@="C:\PROGRA~1\LEXMAR~1\viewbo~1.exe “%1"”

[HKEY_CLASSES_ROOT\ViewingBooth6.Document\shell\print]

[HKEY_CLASSES_ROOT\ViewingBooth6.Document\shell\print\command]
@="C:\PROGRA~1\LEXMAR~1\viewbo~1.exe /p “%1"”

[HKEY_CLASSES_ROOT\ViewingBooth6.Document\shell\printto]

[HKEY_CLASSES_ROOT\ViewingBooth6.Document\shell\printto\command]
@="C:\PROGRA~1\LEXMAR~1\viewbo~1.exe /pt “%1” “%2” “%3” “%4"”

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}]
@=“ActiveXPlugin Object”

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Control]

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories]

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories{7DD95801-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Implemented Categories{7DD95802-9882-11CF-9FA9-00AA006C42C4}]

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\InprocServer32]
@=“C:\WINDOWS\System32\plugin.ocx”
“ThreadingModel”=“Apartment”

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\MiscStatus]
@=“0”

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\MiscStatus\1]
@=“131473”

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\ProgID]
@=“Microsoft.ActiveXPlugin.1”

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\ToolboxBitmap32]
@=“C:\WINDOWS\System32\plugin.ocx, 1”

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\TypeLib]
@="{06DD38D0-D187-11CF-A80D-00C04FD74AD8}"

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\Version]
@=“1.0”

[HKEY_CLASSES_ROOT\CLSID{06DD38D3-D187-11CF-A80D-00C04FD74AD8}\VersionIndependentProgID]
@=“Microsoft.ActiveXPlugin”

[HKEY_CLASSES_ROOT\CLSID{111C85E9-BB62-4528-A806-F0BE908E02F0}]

[HKEY_CLASSES_ROOT\CLSID{111C85E9-BB62-4528-A806-F0BE908E02F0}\InprocServer32]
“ThreadingModel”=“Apartment”
@="“C:\PROGRA~1\MSNMES~1\msgsc.dll”"

[HKEY_CLASSES_ROOT\CLSID{111C85E9-BB62-4528-A806-F0BE908E02F0}\LocalServer32]
“ThreadingModel”=“Apartment”
@="“C:\PROGRA~1\MSNMES~1\msnmsgr.exe”"

[HKEY_CLASSES_ROOT\CLSID{111C85E9-BB62-4528-A806-F0BE908E02F0}\ProgID]
@=“MSNMessenger.ContactsPicker”

[HKEY_CLASSES_ROOT\CLSID{111C85E9-BB62-4528-A806-F0BE908E02F0}\Programmable]
@=""

[HKEY_CLASSES_ROOT\CLSID{111C85E9-BB62-4528-A806-F0BE908E02F0}\Version]
@=“1.0”

[HKEY_CLASSES_ROOT\CLSID{111C85E9-BB62-4528-A806-F0BE908E02F0}\VersionIndependentProgID]
@=“MSNMessenger.ContactsPicker.1”

[HKEY_CLASSES_ROOT\CLSID{238D0F23-5DC9-45A6-9BE2-666160C324DD}]
@=“RealVideo Decoder”

[HKEY_CLASSES_ROOT\CLSID{238D0F23-5DC9-45A6-9BE2-666160C324DD}\InprocServer32]
@=“C:\Program Files\Winamp Remote\bin\RealMediaSplitter.ax”
“ThreadingModel”=“Both”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}]
@=“InterActual Skin”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\AuxUserType]

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\AuxUserType\2]
@=“ITICl”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\AuxUserType\3]
@=“iPlayer”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\DefaultIcon]
@=“C:\PROGRA~1\INTERA~1\INTERA~1\iPlayer.exe,0”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\InprocHandler32]
@=“ole32.dll”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\Insertable]
@=""

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\LocalServer32]
@=“C:\PROGRA~1\INTERA~1\INTERA~1\iPlayer.exe”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\MiscStatus]
@=“32”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\ProgID]
@=“ITIClient.Document”

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\Verb]

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\Verb\0]
@="&Edit,0,2"

[HKEY_CLASSES_ROOT\CLSID{2524A5A2-6DE6-433B-A067-33AAA8CF1587}\Verb\1]
@="&Open,0,2"

[HKEY_CLASSES_ROOT\CLSID{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}]
@=“AU ISC Server Application”

[HKEY_CLASSES_ROOT\CLSID{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}\LocalServer32]
@=“C:\Program Files\MSN Apps\Updater\01.05.0000.1009\fr\msnappau.exe”
“ThreadingModel”=“Both”

[HKEY_CLASSES_ROOT\CLSID{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}\ProgID]
@=“AU_ISC.1”

[HKEY_CLASSES_ROOT\CLSID{499C2688-85A5-41B5-B8A7-DCC8DCF797B4}\VersionIndependentProgID]
@=“AU_ISC”

[HKEY_CLASSES_ROOT\CLSID{539E5EC1-5BD3-420C-8F64-EF55AE95F369}]
@=“IAUISC_PSFactory”

[HKEY_CLASSES_ROOT\CLSID{539E5EC1-5BD3-420C-8F64-EF55AE95F369}\InprocServer32]
@=“C:\Program Files\MSN Apps\Updater\01.05.0000.1009\fr\au_iscPS.dll”

[HKEY_CLASSES_ROOT\CLSID{5CE44120-E684-11D2-9F08-00A0C98E9EA4}]
@=“Still Image Capture”

[HKEY_CLASSES_ROOT\CLSID{5CE44120-E684-11D2-9F08-00A0C98E9EA4}\InprocServer32]
@=“C:\Program Files\Creative\ShareDLL\CTStillCapture.ax”
“ThreadingModel”=“Both”

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}]
@=“HelixProducerCtrl Class”

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\Control]

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\InprocServer32]
@=“C:\Program Files\Winamp Remote\bin\HelixProducer\helixprodctrl.dll”
“ThreadingModel”=“Apartment”

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\Insertable]

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\MiscStatus]
@=“0”

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\MiscStatus\1]
@=“131473”

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\ProgID]
@=“helix.producer.1”

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\Programmable]

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\ToolboxBitmap32]
@=“C:\Program Files\Winamp Remote\bin\HelixProducer\helixprodctrl.dll, 101”

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\TypeLib]
@="{BE746EB1-6F27-47D9-BA6D-313633547328}"

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\Version]
@=“1.0”

[HKEY_CLASSES_ROOT\CLSID{66F8592D-33E8-11D7-8A24-00045A785B71}\VersionIndependentProgID]
@=“helix.producer”

[HKEY_CLASSES_ROOT\CLSID{765035B3-5944-4A94-806B-20EE3415F26F}]
@=“RealMedia Source”

[HKEY_CLASSES_ROOT\CLSID{765035B3-5944-4A94-806B-20EE3415F26F}\InprocServer32]
@=“C:\Program Files\Winamp Remote\bin\RealMediaSplitter.ax”
“ThreadingModel”=“Both”

[HKEY_CLASSES_ROOT\CLSID{80F6E410-210B-454C-B523-97D7C2541FF3}]
@=“HelixDuration Class”

[HKEY_CLASSES_ROOT\CLSID{80F6E410-210B-454C-B523-97D7C2541FF3}\InprocServer32]
@=“C:\Program Files\Winamp Remote\bin\HelixProducer\helixprodctrl.dll”
“ThreadingModel”=“Apartment”

[HKEY_CLASSES_ROOT\CLSID{80F6E410-210B-454C-B523-97D7C2541FF3}\ProgID]
@=“helix.duration.1”

[HKEY_CLASSES_ROOT\CLSID{80F6E410-210B-454C-B523-97D7C2541FF3}\Programmable]

[HKEY_CLASSES_ROOT\CLSID{80F6E410-210B-454C-B523-97D7C2541FF3}\TypeLib]
@="{BE746EB1-6F27-47D9-BA6D-313633547328}"

[HKEY_CLASSES_ROOT\CLSID{80F6E410-210B-454C-B523-97D7C2541FF3}\VersionIndependentProgID]
@=“helix.duration”

[HKEY_CLASSES_ROOT\CLSID{941A4793-A705-4312-8DFC-C11CA05F397E}]
@=“RealAudio Decoder”

[HKEY_CLASSES_ROOT\CLSID{941A4793-A705-4312-8DFC-C11CA05F397E}\InprocServer32]
@=“C:\Program Files\Winamp Remote\bin\RealMediaSplitter.ax”
“ThreadingModel”=“Both”

[HKEY_CLASSES_ROOT\CLSID{9869EFB4-18E9-11D3-A837-00104B9E30B5}]
@=“CmdLineContextMenu Class”

[HKEY_CLASSES_ROOT\CLSID{9869EFB4-18E9-11D3-A837-00104B9E30B5}\InprocServer32]
@=“C:\DOCUME~1\DOMITI~1\LOCALS~1\Temp\CmdLineExt02.dll”
“ThreadingModel”=“Apartment”

[HKEY_CLASSES_ROOT\CLSID{9869EFB4-18E9-11D3-A837-00104B9E30B5}\ProgID]
@=“CmdLineExt.CmdLineContextMenu.1”

[HKEY_CLASSES_ROOT\CLSID{9869EFB4-18E9-11D3-A837-00104B9E30B5}\TypeLib]
@="{9869EFA6-18E9-11D3-A837-00104B9E30B5}"

[HKEY_CLASSES_ROOT\CLSID{9869EFB4-18E9-11D3-A837-00104B9E30B5}\VersionIndependentProgID]
@=“CmdLineExt.CmdLineContextMenu”

[HKEY_CLASSES_ROOT\CLSID{D8B4A55C-FA70-4181-B340-B92451E4DA62}]
@=“CabIn Class”

[HKEY_CLASSES_ROOT\CLSID{D8B4A55C-FA70-4181-B340-B92451E4DA62}\InprocServer32]
@=“C:\Program Files\Winamp Remote\bin\Cab.dll”
“ThreadingModel”=“Free”

[HKEY_CLASSES_ROOT\CLSID{D8B4A55C-FA70-4181-B340-B92451E4DA62}\ProgID]
@=“Cab.CabIn.1”

[HKEY_CLASSES_ROOT\CLSID{D8B4A55C-FA70-4181-B340-B92451E4DA62}\Programmable]

[HKEY_CLASSES_ROOT\CLSID{D8B4A55C-FA70-4181-B340-B92451E4DA62}\TypeLib]
@="{E349194C-BA1A-4968-B06E-E4E8C1CDB4DB}"

[HKEY_CLASSES_ROOT\CLSID{D8B4A55C-FA70-4181-B340-B92451E4DA62}\VersionIndependentProgID]
@=“Cab.CabIn”

[HKEY_CLASSES_ROOT\CLSID{E21BE468-5C18-43EB-B0CC-DB93A847D769}]
@=“RealMedia Splitter”

[HKEY_CLASSES_ROOT\CLSID{E21BE468-5C18-43EB-B0CC-DB93A847D769}\InprocServer32]
@=“C:\Program Files\Winamp Remote\bin\RealMediaSplitter.ax”
“ThreadingModel”=“Both”

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}]
@=“CMiTVSink Object”
“AppID”="{1EEAE99F-158C-403E-ABAE-D8FF9696CB21}"

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\Control]

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\LocalServer32]
@="“C:\Program Files\Winamp Remote\bin\OrbTVBuffer.exe”"
“ThreadingModel”=“apartment”

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\MiscStatus]
@=“0”

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\MiscStatus\1]
@=“131473”

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\ProgID]
@=“OrbTVBuffer.MiTVSink.1”

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\ToolboxBitmap32]
@="“C:\Program Files\Winamp Remote\bin\OrbTVBuffer.exe”, 1"

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\TypeLib]
@="{1EEAE99F-158C-403E-ABAE-D8FF9696CB21}"

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\Version]
@=“1.0”

[HKEY_CLASSES_ROOT\CLSID{EEB09DE1-1892-43B5-9730-B3FA8361B13A}\VersionIndependentProgID]
@=“OrbTVBuffer.MiTVSink”

[HKEY_CLASSES_ROOT\Interface{099944FB-BCDA-453E-8C41-E13DA2ADF7F3}]
@=“IRTCMediaEvent”

[HKEY_CLASSES_ROOT\Interface{099944FB-BCDA-453E-8C41-E13DA2ADF7F3}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{099944FB-BCDA-453E-8C41-E13DA2ADF7F3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{099944FB-BCDA-453E-8C41-E13DA2ADF7F3}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{09BCB597-F0FA-48F9-B420-468CEA7FDE04}]
@=“IRTCParticipantStateChangeEvent”

[HKEY_CLASSES_ROOT\Interface{09BCB597-F0FA-48F9-B420-468CEA7FDE04}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{09BCB597-F0FA-48F9-B420-468CEA7FDE04}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{09BCB597-F0FA-48F9-B420-468CEA7FDE04}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{13FA24C7-5748-4B21-91F5-7397609CE747}]
@=“IRTCEventNotification”

[HKEY_CLASSES_ROOT\Interface{13FA24C7-5748-4B21-91F5-7397609CE747}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{13FA24C7-5748-4B21-91F5-7397609CE747}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{13FA24C7-5748-4B21-91F5-7397609CE747}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{2B493B7A-3CBA-4170-9C8B-76A9DACDD644}]
@=“IRTCClientEvent”

[HKEY_CLASSES_ROOT\Interface{2B493B7A-3CBA-4170-9C8B-76A9DACDD644}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{2B493B7A-3CBA-4170-9C8B-76A9DACDD644}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{2B493B7A-3CBA-4170-9C8B-76A9DACDD644}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{3F578A46-082A-4C83-947A-CC7FF8B4A089}]
@=“IXLInit”

[HKEY_CLASSES_ROOT\Interface{3F578A46-082A-4C83-947A-CC7FF8B4A089}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{3F578A46-082A-4C83-947A-CC7FF8B4A089}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{3F578A46-082A-4C83-947A-CC7FF8B4A089}\TypeLib]
@="{54635C92-DFAF-4A99-8802-92FB068A6154}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{4C23BF51-390C-4992-A41D-41EEC05B2A4B}]
@=“IRTCIntensityEvent”

[HKEY_CLASSES_ROOT\Interface{4C23BF51-390C-4992-A41D-41EEC05B2A4B}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{4C23BF51-390C-4992-A41D-41EEC05B2A4B}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{4C23BF51-390C-4992-A41D-41EEC05B2A4B}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{56A868B4-0AD4-11CE-B03A-0020AF0BA770}]
@=“IVideoWindow”

[HKEY_CLASSES_ROOT\Interface{56A868B4-0AD4-11CE-B03A-0020AF0BA770}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{56A868B4-0AD4-11CE-B03A-0020AF0BA770}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{56A868B4-0AD4-11CE-B03A-0020AF0BA770}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{60D5B879-F621-4E99-8474-9AF1C5EE11BB}]
@=“INSWLauncher”

[HKEY_CLASSES_ROOT\Interface{60D5B879-F621-4E99-8474-9AF1C5EE11BB}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{60D5B879-F621-4E99-8474-9AF1C5EE11BB}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{60D5B879-F621-4E99-8474-9AF1C5EE11BB}\TypeLib]
@="{B6B6E59D-F7D5-11D2-8B29-0050041850C1}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{62D0991B-50AB-4F02-B948-CA94F26F8F95}]
@=“IRTCRegistrationStateChangeEvent”

[HKEY_CLASSES_ROOT\Interface{62D0991B-50AB-4F02-B948-CA94F26F8F95}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{62D0991B-50AB-4F02-B948-CA94F26F8F95}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{62D0991B-50AB-4F02-B948-CA94F26F8F95}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{A6BFF4C0-F7C8-4D3C-9A41-3550F78A95B0}]
@=“IRTCSessionOperationCompleteEvent”

[HKEY_CLASSES_ROOT\Interface{A6BFF4C0-F7C8-4D3C-9A41-3550F78A95B0}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{A6BFF4C0-F7C8-4D3C-9A41-3550F78A95B0}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{A6BFF4C0-F7C8-4D3C-9A41-3550F78A95B0}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{B5BAD703-5952-48B3-9321-7F4500521506}]
@=“IRTCSessionStateChangeEvent”

[HKEY_CLASSES_ROOT\Interface{B5BAD703-5952-48B3-9321-7F4500521506}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{B5BAD703-5952-48B3-9321-7F4500521506}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{B5BAD703-5952-48B3-9321-7F4500521506}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{D3609541-1B29-4DE5-A4AD-5AEBAF319512}]
@=“IRTCMessagingEvent”

[HKEY_CLASSES_ROOT\Interface{D3609541-1B29-4DE5-A4AD-5AEBAF319512}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{D3609541-1B29-4DE5-A4AD-5AEBAF319512}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{D3609541-1B29-4DE5-A4AD-5AEBAF319512}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{DA77C14B-6208-43CA-8DDF-5B60A0A69FAC}]
@=“IRTCPortManager”

[HKEY_CLASSES_ROOT\Interface{DA77C14B-6208-43CA-8DDF-5B60A0A69FAC}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{DA77C14B-6208-43CA-8DDF-5B60A0A69FAC}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{DA77C14B-6208-43CA-8DDF-5B60A0A69FAC}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{EC7C8096-B918-4044-94F1-E4FBA0361D5C}]
@=“IRTCCollection”

[HKEY_CLASSES_ROOT\Interface{EC7C8096-B918-4044-94F1-E4FBA0361D5C}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{EC7C8096-B918-4044-94F1-E4FBA0361D5C}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{EC7C8096-B918-4044-94F1-E4FBA0361D5C}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{F30D7261-587A-424F-822C-312788F43548}]
@=“IRTCWatcherEvent”

[HKEY_CLASSES_ROOT\Interface{F30D7261-587A-424F-822C-312788F43548}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{F30D7261-587A-424F-822C-312788F43548}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{F30D7261-587A-424F-822C-312788F43548}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Interface{F36D755D-17E6-404E-954F-0FC07574C78D}]
@=“IRTCBuddyEvent”

[HKEY_CLASSES_ROOT\Interface{F36D755D-17E6-404E-954F-0FC07574C78D}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{F36D755D-17E6-404E-954F-0FC07574C78D}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface{F36D755D-17E6-404E-954F-0FC07574C78D}\TypeLib]
@="{CD260094-DE10-4AEE-AC73-EF87F6E12683}"
“Version”=“1.0”

[HKEY_CLASSES_ROOT\Applications\Artcopy55.exe]

[HKEY_CLASSES_ROOT\Applications\Artcopy55.exe\shell]
“FriendlyCache”=“Lexmark Scan & Copy Control Program”

[HKEY_CLASSES_ROOT\Applications\ARTCOP~1.EXE\shell\open]

[HKEY_CLASSES_ROOT\Applications\ARTCOP~1.EXE\shell\open\command]
@="C:\PROGRA~1\LEXMAR~1\ARTCOP~1.EXE “%1"”

[HKEY_CLASSES_ROOT\Applications\ARTCOP~1.EXE\shell\print]

[HKEY_CLASSES_ROOT\Applications\ARTCOP~1.EXE\shell\print\command]
@="C:\PROGRA~1\LEXMAR~1\ARTCOP~1.EXE /p “%1"”

[HKEY_CLASSES_ROOT\Applications\ARTCOP~1.EXE\shell\printto]

[HKEY_CLASSES_ROOT\Applications\ARTCOP~1.EXE\shell\printto\command]
@="C:\PROGRA~1\LEXMAR~1\ARTCOP~1.EXE /pt “%1” “%2” “%3” “%4"”

[HKEY_CLASSES_ROOT\Applications\MSMoney.EXE\shell\Open]

[HKEY_CLASSES_ROOT\Applications\MSMoney.EXE\shell\Open\Command]
@="“C:\Program Files\Microsoft Money 2005\MNYCoreFiles\MSMoney.EXE” “%1"”

[HKEY_CLASSES_ROOT\Applications\viewbo~1.exe\shell\open]

[HKEY_CLASSES_ROOT\Applications\viewbo~1.exe\shell\open\command]
@="C:\PROGRA~1\LEXMAR~1\viewbo~1.exe “%1"”

[HKEY_CLASSES_ROOT\Applications\viewbo~1.exe\shell\print]

[HKEY_CLASSES_ROOT\Applications\viewbo~1.exe\shell\print\command]
@="C:\PROGRA~1\LEXMAR~1\viewbo~1.exe /p “%1"”

[HKEY_CLASSES_ROOT\Applications\viewbo~1.exe\shell\printto]

[HKEY_CLASSES_ROOT\Applications\viewbo~1.exe\shell\printto\command]
@="C:\PROGRA~1\LEXMAR~1\viewbo~1.exe /pt “%1” “%2” “%3” “%4"”

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\Artcopy55.exe]
@=“C:\Program Files\LexmarkX73\Artcopy55.exe”
“Path”=“C:\Program Files\LexmarkX73”

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\Easy-WebPrint]
“Path”=“C:\Program Files\Canon\Easy-WebPrint”
@=“C:\Program Files\Canon\Easy-WebPrint\Easy-WebPrint”

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\Sprint.exe]
@=“C:\PROGRA~1\LEXMAR~1\Sprint\Sprint.exe”

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
“C:\Program Files\Norton Internet Security\”=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
“C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\”=“1”

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
“C:\Program Files\Norton Internet Security\Norton AntiVirus\”=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
“C:\Program Files\Norton SystemWorks\”=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
“C:\Program Files\Norton SystemWorks\Norton AntiVirus\”=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
“C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\”=“1”

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ShockwaveFlash]
“QuietDisplayName”=“Shockwave Flash”
“QuietUninstallString”=“RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5”
“RequiresIESysFile”=“4.70.0.1155”
“DisplayName”=“Adobe Flash Player 9 ActiveX”
“UninstallString”=“C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock”
“Publisher”=“Adobe Systems”
“DisplayVersion”=“9”
“VersionMajor”=“9”
“VersionMinor”=“0”
“HelpLink”=“http://www.adobe.com/go/flashplayer_support/
“URLUpdateInfo”=“http://www.adobe.com/go/flashplayer/

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AdobeESD]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,20,08,00,00,00,00,00,42,bc,70,
f1,cd,fb,c4,01,00,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,46,00,69,00,63,00,68,
00,69,00,65,00,72,00,73,00,20,00,63,00,6f,00,6d,00,6d,00,75,00,6e,00,73,00,
5c,00,41,00,64,00,6f,00,62,00,65,00,5c,00,45,00,53,00,44,00,5c,00,41,00,64,
00,6f,00,62,00,65,00,44,00,6f,00,77,00,6e,00,6c,00,6f,00,61,00,64,00,4d,00,
61,00,6e,00,61,00,67,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Creative Video Blaster WebCam 5]
“SlowInfoCache”=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Lexmark X73]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,70,31,07,00,00,00,00,6a,c9,0e,
d5,0d,9a,c6,01,06,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4c,00,65,00,78,00,6d,
00,61,00,72,00,6b,00,58,00,37,00,33,00,5c,00,41,00,63,00,42,00,74,00,6e,00,
4d,00,67,00,72,00,5f,00,58,00,37,00,33,00,2e,00,65,00,78,00,65,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\LiveReg]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,f0,2d,00,00,00,00,00,d4,c5,c7,
61,be,a3,c4,01,02,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,46,00,69,00,63,00,68,
00,69,00,65,00,72,00,73,00,20,00,63,00,6f,00,6d,00,6d,00,75,00,6e,00,73,00,
5c,00,53,00,79,00,6d,00,61,00,6e,00,74,00,65,00,63,00,20,00,53,00,68,00,61,
00,72,00,65,00,64,00,5c,00,4c,00,69,00,76,00,65,00,52,00,65,00,67,00,5c,00,
73,00,79,00,6d,00,63,00,73,00,75,00,62,00,2e,00,65,00,78,00,65,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (1.5)]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,c0,fc,00,00,00,00,00,2c,dd,eb,
1b,38,71,c6,01,05,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,6f,00,7a,00,69,
00,6c,00,6c,00,61,00,20,00,46,00,69,00,72,00,65,00,66,00,6f,00,78,00,5c,00,
66,00,69,00,72,00,65,00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (1.5.0.10)]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,e0,20,01,00,00,00,00,00,38,3d,
02,38,69,c7,01,4c,02,00,00,43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,
41,00,7e,00,31,00,5c,00,4d,00,4f,00,5a,00,49,00,4c,00,4c,00,7e,00,31,00,5c,
00,66,00,69,00,72,00,65,00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (1.5.0.4)]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,20,fa,00,00,00,00,00,ec,cc,7d,
b6,7f,89,c6,01,69,00,00,00,43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,
41,00,7e,00,31,00,5c,00,4d,00,4f,00,5a,00,49,00,4c,00,4c,00,7e,00,31,00,5c,
00,66,00,69,00,72,00,65,00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (1.5.0.9)]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,d0,23,01,00,00,00,00,2c,02,32,
84,42,5b,c7,01,32,02,00,00,43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,
41,00,7e,00,31,00,5c,00,4d,00,4f,00,5a,00,49,00,4c,00,4c,00,7e,00,31,00,5c,
00,66,00,69,00,72,00,65,00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (2.0.0.11)]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,2c,50,01,00,00,00,00,fa,60,b9,
32,21,3c,c8,01,51,01,00,00,43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,
41,00,7e,00,31,00,5c,00,4d,00,6f,00,7a,00,69,00,6c,00,6c,00,61,00,20,00,46,
00,69,00,72,00,65,00,66,00,6f,00,78,00,5c,00,66,00,69,00,72,00,65,00,66,00,
6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (2.0.0.15)]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,1c,65,01,00,00,00,00,28,ef,36,
ca,2f,e3,c8,01,17,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,6f,00,7a,00,69,
00,6c,00,6c,00,61,00,20,00,46,00,69,00,72,00,65,00,66,00,6f,00,78,00,5c,00,
66,00,69,00,72,00,65,00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (2.0.0.4)]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,ac,52,01,00,00,00,00,d6,23,b9,
e1,ee,bc,c7,01,fa,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,6f,00,7a,00,69,
00,6c,00,6c,00,61,00,20,00,46,00,69,00,72,00,65,00,66,00,6f,00,78,00,5c,00,
66,00,69,00,72,00,65,00,66,00,6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Mozilla Firefox (2.0.0.9)]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,2c,54,01,00,00,00,00,0c,56,dd,
87,68,24,c8,01,c6,01,00,00,43,00,3a,00,5c,00,50,00,52,00,4f,00,47,00,52,00,
41,00,7e,00,31,00,5c,00,4d,00,6f,00,7a,00,69,00,6c,00,6c,00,61,00,20,00,46,
00,69,00,72,00,65,00,66,00,6f,00,78,00,5c,00,66,00,69,00,72,00,65,00,66,00,
6f,00,78,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
00,00,00,00,00,00,00,00
“Changed”=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MSI Live Update 3]
“SlowInfoCache”=hex:28,02,00,00,01,00,00,00,00,40,50,00,00,00,00,00,62,5b,64,
fd,c6,a3,c4,01,06,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,
61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,4d,00,53,00,49,00,5c,
00,4c,00,69,00,76,00,65,00,20,00,55,00,70,00,64,00,61,00,74,00,65,00,20,00,
33,00,5c,00,4d,00,53,00,49,00,57,00,55,00,50,00,72,00,6f,00,2e,00,65,00,78,
00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,0

Bonjour
va ici Scan online Bitdefender avec Explorer
www.zebulon.fr…

Faudra rajouter plus tard un Firewall
PC Tools ou Sunbelt personal firewallou COMMODO Firewall Pro et mettre a jour Windows est passer au SP3 mais plus tard
une fois l analyse finie avec bitdefender ,passe Ccleaner et post un nouveau Log Hijackthis

:hello:


Encore une Chose il faut toujours renommer Hijacthis par Hijackthis.exe ou Monjack.exe Pourquoi ? Certaines variantes du Virus Vundo détecte Hijackthis, , ben on joue à cache-virus.... :hello:

Re salut , merci pour ta fidélité … :oui:
ok, c’est incroyable tout de même…
Je lance le scan avec Bitdefender sur explorer et j’en ai profité pour renommer Hijack (chose que je n’avait pas faite) mais dois-je aller renommer dans “Ajouter Supprimer des programmes”??? Et oui, pas doué …
Si je comprends bien avec Avira je ne suis pas suffisamment bien protéger… il me faut un firewall.
Qu’est-ce qu’il y a de plus simple à utiliser pour moi ?? :wink:
Quant à windows … je fais quoi? comment?
Xié xié ni —> Merci à toi
Mod

Re
hijackthis est sur ton bureau
Clic droit dans le menu contextuel ,selectionne renomer et donne le nom de Hijack.exe

Avira Antivir Personal n est pas suffisant prends un Firewall

Simple et leger PC Tools Firewall Plus
www.clubic.com…
Ok installe est fait le reste preconisé

:hello:

J oublie Renome hijackthis egalement dans " program file "

:hello:

OK encore merci :super:
Tout est renommé et voici le log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:16:28, on 23/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\Monjack\Monjack.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.free.fr…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d’aide de l’Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM…\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM…\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM…\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe”
O4 - HKLM…\Run: [SSBkgdUpdate] “C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe” -Embedding -boot
O4 - HKLM…\Run: [OpwareSE4] “C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe”
O4 - HKLM…\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM…\Run: [WinampAgent] “C:\Program Files\Winamp\winampa.exe”
O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM…\Run: [avgnt] “C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe” /min
O4 - HKCU…\Run: [NBJ] “C:\Program Files\Ahead\Nero BackItUp\NBJ.exe”
O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SERVICE LOCAL’)
O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SERVICE RÉSEAU’)
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘Default user’)
O4 - Global Startup: Lancement rapide d’Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Windows Live Search - C:\Program… Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE…
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra ‘Tools’ menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - tw.msi.com.tw…
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - www.zebulon.fr…
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com…
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal ? Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal ? Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE


End of file - 7194 bytes
:pt1cable:

Et voilà du travail pour toi :arf:
J’attends tes conseils pour la suite
:ange:

Nouveau problème …hum hum hum :@
Je reçois pendant l’installation du logiciel PC Tools Firewall Plus un message …
AVERTISSEMENT comme quoi ce logiciel n’est pas validé par Windows et qu’il risque de mettre en péril voir destabiliser le fonctionnement de mon système.
Non mais ça fini jamais.
Du coup au second avertissement, j’ai stoppé. Bien fait ou pas???
Est-il installé correctement ???
Oui, je crois que je les cumule…
No comment
Merci de me dire

T’inquiéte pas c’est normal c’est que le pilote n’a pas été signer par microsoft :wink:
Si tu a arréte il n’a pas été installer

ok,merci
j’ai désinstallé et réinstaller. Je le laisse bosser tout seul ce truc… super!
Jj’ai pris la totale .
Maintenant, je fais quoi avec tout ça… :frowning:
les antivirus que j’ai à gogo, les log sont-ils ok???
Mon petit virus “adoré” est-il tjs par là???
Oui, je sais on me l’a déjà dit … “tu veux que ça aille trop vite…”
Merci de votre aide
@+
Merci

Je pense que c’est bon tu peut vérifié avec des scan en ligne housecall / kaspersky

message courant avec PC Tools vise a vis de Microsoft

Pas de probs ca marche
fais ce que dis guigui14100
peut être voir pour mettre a jour Windows ,passer a la SP3
www.microsoft.com…

ton log est assez correct
une ligne pouvant être effacée,guigui141100 a du la voir
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

autrement c est ok !!

tiens bien a jour tes logiciels en general sinon prends ceci cadeau
Secunia PSI RC-3 leger est tie tiens au courant des mises a jour

:hello:


le lien pour Secunia [psi.secunia.com...](https://psi.secunia.com/)

:hello:

merci :super: merci :jap: merci … :clap:
J’ai supprimé la fameuse ligne (guigui14100 ne m’avait rien dit)
Je fais le nécessaire pour que mon ordi soit en pleine forme voire au top!!!
C’est quoi exactement ce petit kdo ??? :neutre:
un pense-bête :wink:

@+ qui sait
    Mod

C’est une ligne qi sert a rien et qui réaparer tout le temps :wink: