Erreur iexplorer et msimn

Bonsoir,

J'ai un gros problème avec Internet Explorer (6.0.29) et Outlook Express : dès que j'ouvre un site sur IE ou que je tente d'ouvrir un mail contenant du html (voire même au bout d'un moment quand je ne fais rien), j'ai droit à une erreur de l'application et le fameux "envoyer à microsoft..."

Après un scan, j'ai découvert que j'avais pokapoka75 d'installé, que je me suis empressé de virer à coup de hijackthis, ccleaner, et à priori je ne l'ai plus. Mais le problème persiste :(

En regardant de plus près le log d'erreur, il indique une erreur sur "ModName: waxw2k.dll". Sauf que je n'ai pas cette dll sur mon pc et que je ne la trouve pas, ni sur internet ni sur une autre machine... je ne retrouve son nom que dans le log d'hijack, mais je ne trouve pas le fichier.

Avez vous des suggestions, j'aimerais bien éviter de devoir passer un week end à reformater et réinstaller :(

Ci dessous le log okazou... merci d'avance pour toute suggestion.

Logfile of HijackThis v1.99.1
Scan saved at 21:50:05, on 11/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
D:\PowerToy\taskswitch.exe
D:\ANTIVI~1\AVG7\avgcc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\CAPRPCSK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
D:\ANTIVI~1\AVG7\avgamsvr.exe
D:\ANTIVI~1\AVG7\avgupsvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\gearsec.exe
D:\Antivirus\Norton Antivirus\navapsvc.exe
D:\Antivirus\Norton Antivirus\IWP\NPFMntor.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Antivirus\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\DaemonTools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [CoolSwitch] D:\PowerToy\taskswitch.exe
O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\System32\Spool\Drivers\w32x86\3\CAPONN.EXE
O4 - HKLM\..\Run: [AVG7_CC] D:\ANTIVI~1\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Fenêtre d'état Canon LBP-800.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122650811499
O20 - Winlogon Notify: waxw2k - C:\WINDOWS\SYSTEM32\waxw2k.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\ANTIVI~1\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\ANTIVI~1\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - D:\Antivirus\Norton Antivirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - D:\Antivirus\Norton Antivirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Antivirus\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
Configuration: Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

10 réponses

  1. Bonjour,
    Dééjà, tu devrais supprimer Norton, une vrai passoire.
    Perso, j'ai avast! Mais tu peux choisir, va voir par là ::
    http://sebsauvage.net/
    A=
    0
    1. Bah en fait mon antivirus habituel c'est avg, mais comme il ne m'avait pas détecté le pokatruc, j'avais fait une tentative avec norton...

      Mais ce que j'aimerais résoudre, c'est d'avantage cette histoire de waxw2k.dll ;) (même si je suis pas un grand fan de IE, c'est quand même pratique, et puis c'est surtout pour express..)

      Je vais quand même jeter un coup d'oeil à ton lien :)
      0
      1. Bonjour,
        J'ai le même problème.
        Sous XP Pro.
        Internet Explorer et Outlook Express : dès que j'ouvre un site sur IE ou que je tente d'ouvrir un mail contenant du html, l'application plante avec le message d'erreur "iexplorer.exe a du fermer etc..."
        Même chose avec Windows Media Player.
        En fait, tout ce qui demande accès à du html.
        Car, Outlook fonctionne (j'ai la connexion) si c'est des messages textes et plante dès que c'est un message html.
        par contre, Netscape que j'avais gardé su mon DD fonctionne (j'écris d'ailleurs à partir de celui-ci).
        AVAST : rien
        ANTIVIR : rien.

        J'ai le log d'erreur : "Application défaillante msimn.exe, version 6.0.2600.0, module défaillant waxw2k.dll, version 0.0.0.0, adresse de défaillance 0x00002200."

        Même chose avec IEplorer.

        j'ai tenté Winsockfix : rien n'y fait :-((

        Auriez-vous la solution ?
        0
    2. Contributeur sécurité
      salut
      tente ceci
      clik sur demarrer/executer et tape cmd
      ensuite copie colle ceci dans la fenetre qui c est ouverte
      netsh winsock reset catalog

      la redemarre

      si cela ne change rien
      telecharge ceci
      telecharge ceci
      http://www.downloads.subratam.org/l2mfix.exe
      decompresse le double clik sur l2mfix.bat appuie sur n importe quelle touche et ensuite choisi l option 1
      attend il vas faire un rapport fait un copier coller de celui ci
      ne fait surtout rien d autres
      0
      1. Voilà
        Alors la commande netsh winsock reset catalog n'a pas marché.
        Il me met la commande suivante winsock reset catalog n'a pas été trouvée.

        Je te copie le log

        L2MFIX find log 1.04a
        These are the registry keys present
        **********************************************************************************
        Winlogon/notify:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
        6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
        "DLLName"="wlnotify.dll"
        "Logon"="SCardStartCertProp"
        "Logoff"="SCardStopCertProp"
        "Lock"="SCardSuspendCertProp"
        "Unlock"="SCardResumeCertProp"
        "Enabled"=dword:00000001
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "StartShell"="SchedStartShell"
        "Logoff"="SchedEventLogOff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "PostShell"="SensPostShellEvent"
        "Disconnect"="SensDisconnectEvent"
        "Reconnect"="SensReconnectEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "Logoff"="TSEventLogoff"
        "Logon"="TSEventLogon"
        "PostShell"="TSEventPostShell"
        "Shutdown"="TSEventShutdown"
        "StartShell"="TSEventStartShell"
        "Startup"="TSEventStartup"
        "MaxWait"=dword:00000258
        "Reconnect"="TSEventReconnect"
        "Disconnect"="TSEventDisconnect"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\waxw2k]
        "DllName"=hex(2):77,00,61,00,78,00,77,00,32,00,6b,00,2e,00,64,00,6c,00,6c,00,\
        00,00
        "Startup"="waxw2k"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001
        "MaxWait"=dword:00000001
        "key4"="[442695539247[Philippe M]"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
        "DLLName"="wlnotify.dll"
        "Logon"="RegisterTicketExpiredNotificationEvent"
        "Logoff"="UnregisterTicketExpiredNotificationEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
        (ID-NI) ALLOW Full access BUILTIN\Administrateurs
        (ID-IO) ALLOW Full access BUILTIN\Administrateurs
        (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

        **********************************************************************************
        useragent:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        "Wanadoo 6.0"="IEAKFT"

        **********************************************************************************
        Shell Extension key:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
        "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
        "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
        "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
        "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
        "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
        "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
        "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
        "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
        "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
        "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
        "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
        "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
        "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
        "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
        "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
        "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
        "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
        "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
        "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
        "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
        "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
        "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
        "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
        "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
        "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
        "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
        "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
        "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
        "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
        "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
        "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
        "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
        "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
        "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
        "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
        "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
        "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
        "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
        "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
        "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
        "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
        "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
        "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
        "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
        "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
        "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
        "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
        "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
        "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
        "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
        "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
        "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
        "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
        "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
        "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
        "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
        "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
        "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
        "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
        "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
        "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
        "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
        "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
        "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
        "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
        "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
        "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
        "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
        "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
        "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
        "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
        "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
        "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
        "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
        "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
        "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
        "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
        "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
        "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
        "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
        "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
        "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
        "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
        "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
        "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
        "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
        "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
        "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
        "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
        "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
        "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
        "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
        "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
        "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
        "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
        "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
        "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
        "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
        "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
        "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
        "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
        "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
        "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
        "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
        "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
        "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
        "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
        "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
        "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
        "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
        "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
        "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
        "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
        "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
        "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
        "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
        "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
        "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
        "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
        "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
        "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
        "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
        "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
        "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
        "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
        "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
        "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
        "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
        "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
        "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
        "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
        "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
        "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
        "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
        "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
        "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
        "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
        "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
        "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
        "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
        "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
        "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
        "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
        "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
        "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
        "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
        "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
        "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
        "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
        "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
        "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
        "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
        "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
        "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
        "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
        "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
        "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
        "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
        "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
        "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
        "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
        "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
        "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
        "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
        "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
        "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
        "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
        "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
        "{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
        "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
        "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
        "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
        "{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="P‚riph‚riques Plug and Play universels"

        **********************************************************************************
        HKEY ROOT CLASSIDS:
        **********************************************************************************
        Files Found are not all bad files:
        Locate .tmp files:
        **********************************************************************************
        Directory Listing of system files:
        Le volume dans le lecteur C n'a pas de nom.
        Le num‚ro de s‚rie du volume est 94C7-95AB

        R‚pertoire de C:\WINDOWS\System32

        20/10/2005 22:07 <REP> dllcache
        08/07/2004 07:35 6ÿ580 KGyGaAvL.sys
        07/04/2004 00:54 56 B13BD484D4.sys
        19/11/2003 15:37 <REP> Microsoft
        2 fichier(s) 6ÿ636 octets
        2 R‚p(s) 363ÿ331ÿ584 octets libres
        0
      2. Voilà
        Alors la commande netsh winsock reset catalog n'a pas marché.
        Il me met la commande suivante winsock reset catalog n'a pas été trouvée.

        Je te copie le log

        L2MFIX find log 1.04a
        These are the registry keys present
        **********************************************************************************
        Winlogon/notify:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
        6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
        "DLLName"="wlnotify.dll"
        "Logon"="SCardStartCertProp"
        "Logoff"="SCardStopCertProp"
        "Lock"="SCardSuspendCertProp"
        "Unlock"="SCardResumeCertProp"
        "Enabled"=dword:00000001
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "StartShell"="SchedStartShell"
        "Logoff"="SchedEventLogOff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "PostShell"="SensPostShellEvent"
        "Disconnect"="SensDisconnectEvent"
        "Reconnect"="SensReconnectEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "Logoff"="TSEventLogoff"
        "Logon"="TSEventLogon"
        "PostShell"="TSEventPostShell"
        "Shutdown"="TSEventShutdown"
        "StartShell"="TSEventStartShell"
        "Startup"="TSEventStartup"
        "MaxWait"=dword:00000258
        "Reconnect"="TSEventReconnect"
        "Disconnect"="TSEventDisconnect"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\waxw2k]
        "DllName"=hex(2):77,00,61,00,78,00,77,00,32,00,6b,00,2e,00,64,00,6c,00,6c,00,\
        00,00
        "Startup"="waxw2k"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001
        "MaxWait"=dword:00000001
        "key4"="[442695539247[Philippe M]"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
        "DLLName"="wlnotify.dll"
        "Logon"="RegisterTicketExpiredNotificationEvent"
        "Logoff"="UnregisterTicketExpiredNotificationEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
        (ID-NI) ALLOW Full access BUILTIN\Administrateurs
        (ID-IO) ALLOW Full access BUILTIN\Administrateurs
        (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

        **********************************************************************************
        useragent:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        "Wanadoo 6.0"="IEAKFT"

        **********************************************************************************
        Shell Extension key:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
        "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
        "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
        "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
        "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
        "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
        "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
        "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
        "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
        "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
        "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
        "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
        "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
        "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
        "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
        "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
        "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
        "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
        "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
        "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
        "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
        "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
        "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
        "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
        "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
        "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
        "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
        "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
        "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
        "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
        "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
        "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
        "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
        "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
        "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
        "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
        "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
        "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
        "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
        "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
        "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
        "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
        "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
        "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
        "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
        "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
        "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
        "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
        "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
        "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
        "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
        "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
        "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
        "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
        "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
        "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
        "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
        "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
        "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
        "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
        "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
        "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
        "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
        "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
        "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
        "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
        "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
        "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
        "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
        "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
        "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
        "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
        "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
        "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
        "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
        "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
        "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
        "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
        "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
        "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
        "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
        "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
        "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
        "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
        "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
        "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
        "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
        "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
        "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
        "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
        "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
        "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
        "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
        "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
        "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
        "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
        "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
        "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
        "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
        "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
        "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
        "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
        "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
        "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
        "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
        "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
        "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
        "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
        "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
        "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
        "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
        "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
        "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
        "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
        "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
        "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
        "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
        "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
        "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
        "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
        "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
        "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
        "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
        "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
        "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
        "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
        "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
        "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
        "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
        "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
        "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
        "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
        "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
        "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
        "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
        "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
        "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
        "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
        "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
        "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
        "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
        "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
        "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
        "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
        "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
        "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
        "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
        "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
        "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
        "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
        "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
        "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
        "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
        "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
        "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
        "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
        "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
        "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
        "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
        "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
        "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
        "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
        "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
        "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
        "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
        "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
        "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
        "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
        "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
        "{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
        "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
        "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
        "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
        "{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="P‚riph‚riques Plug and Play universels"

        **********************************************************************************
        HKEY ROOT CLASSIDS:
        **********************************************************************************
        Files Found are not all bad files:
        Locate .tmp files:
        **********************************************************************************
        Directory Listing of system files:
        Le volume dans le lecteur C n'a pas de nom.
        Le num‚ro de s‚rie du volume est 94C7-95AB

        R‚pertoire de C:\WINDOWS\System32

        20/10/2005 22:07 <REP> dllcache
        08/07/2004 07:35 6ÿ580 KGyGaAvL.sys
        07/04/2004 00:54 56 B13BD484D4.sys
        19/11/2003 15:37 <REP> Microsoft
        2 fichier(s) 6ÿ636 octets
        2 R‚p(s) 363ÿ331ÿ584 octets libres
        0
      3. @robespierre24Encore moi,
        Je suis absent une semaine, donc rien n'urge, mais c'est pénible.

        Je colle aussi le ogfile of HijackThis v1.99.1
        Scan saved at 00:30:52, on 22/10/2005
        Platform: Windows XP (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 (6.00.2600.0000)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\AVPersonal\AVWUPSRV.EXE
        C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\Program Files\Inventel\Gateway\wlancfg.exe
        C:\WINDOWS\System32\sstray.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\WINDOWS\mHotkey.exe
        C:\PROGRA~1\MESSAG~1\StartMessager.exe
        C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\ATI Multimedia\main\launchpd.exe
        C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
        C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
        D:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
        C:\WINDOWS\System32\rundll32.exe
        D:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
        D:\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
        C:\WINDOWS\System32\HPZipm12.exe
        C:\WINDOWS\System32\wuauclt.exe
        D:\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Outlook Express\msimn.exe
        C:\Program Files\Netscape\Communicator\Program\netscape.exe
        C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
        C:\Documents and Settings\Philippe M\Mes documents\philippe.mallard\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://abonnes.lemonde.fr/web/sequence/0,2-3208,1-0,0.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.google.fr"); (C:\Program Files\Netscape\Users\default\prefs.js)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
        O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
        O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
        O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: hp psc 2000 Series.lnk = D:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
        O4 - Global Startup: hpoddt01.exe.lnk = ?
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
        O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
        O20 - Winlogon Notify: waxw2k - C:\WINDOWS\SYSTEM32\waxw2k.dll
        O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: Protocol IP V4 RunTime - Unknown owner - C:\WINDOWS\System32\SVCIPV4.EXE (file missing)
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
        O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
        0
    3. Contributeur sécurité
      relance l2mfix et clik sur l2mfix.bat et cette foix clik sur l option2 et laisse le faire et met moi le rapport et un
      nouveau rapport hijack
      0
      1. Voilà,
        il a rebooté. Je te mets le Log de L2Mfix puis Hijack.
        Merci pour les infos.
        Dans un heure je pars sur les routes pour une semaine....
        je reprendrai le fil après...

        Setting Directory
        C:\
        C:\
        System Rebooted!

        Running From:
        C:\

        killing explorer and rundll32.exe

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 1620 'explorer.exe'

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 1836 'rundll32.exe'

        Scanning First Pass. Please Wait!

        First Pass Completed

        Second Pass Scanning

        Second pass Completed!

        Zipping up files for submission:
        adding: clear.reg (188 bytes security) (deflated 2%)
        adding: boot.ini (124 bytes security) (deflated 30%)
        adding: lo2.txt (188 bytes security) (deflated 51%)
        adding: test.txt (188 bytes security) (stored 0%)
        adding: test2.txt (188 bytes security) (stored 0%)
        adding: test3.txt (188 bytes security) (stored 0%)
        adding: test5.txt (188 bytes security) (stored 0%)
        adding: xscan.txt (188 bytes security) (deflated 94%)

        Restoring Registry Permissions:

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Revoking access for predefined group "Administrators"
        Inherited ACE can not be revoked here!
        Inherited ACE can not be revoked here!

        Registry permissions set too:

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
        (ID-NI) ALLOW Full access BUILTIN\Administrateurs
        (ID-IO) ALLOW Full access BUILTIN\Administrateurs
        (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

        Restoring Sedebugprivilege:

        Granting SeDebugPrivilege to Administrators ... failed (GetAccountSid(Administrators)=1332

        Restoring Windows Update Certificates.:

        The following Is the Current Export of the Winlogon notify key:
        ****************************************************************************
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
        6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
        "DLLName"="wlnotify.dll"
        "Logon"="SCardStartCertProp"
        "Logoff"="SCardStopCertProp"
        "Lock"="SCardSuspendCertProp"
        "Unlock"="SCardResumeCertProp"
        "Enabled"=dword:00000001
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "StartShell"="SchedStartShell"
        "Logoff"="SchedEventLogOff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "PostShell"="SensPostShellEvent"
        "Disconnect"="SensDisconnectEvent"
        "Reconnect"="SensReconnectEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "Logoff"="TSEventLogoff"
        "Logon"="TSEventLogon"
        "PostShell"="TSEventPostShell"
        "Shutdown"="TSEventShutdown"
        "StartShell"="TSEventStartShell"
        "Startup"="TSEventStartup"
        "MaxWait"=dword:00000258
        "Reconnect"="TSEventReconnect"
        "Disconnect"="TSEventDisconnect"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\waxw2k]
        "DllName"=hex(2):77,00,61,00,78,00,77,00,32,00,6b,00,2e,00,64,00,6c,00,6c,00,\
        00,00
        "Startup"="waxw2k"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001
        "MaxWait"=dword:00000001
        "key4"="[442695539247[Philippe M]"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
        "DLLName"="wlnotify.dll"
        "Logon"="RegisterTicketExpiredNotificationEvent"
        "Logoff"="UnregisterTicketExpiredNotificationEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
        "DLLName"="wzcdlg.dll"
        "Logon"="WZCEventLogon"
        "Logoff"="WZCEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000000

        The following are the files found:
        ****************************************************************************

        Registry Entries that were Deleted:
        Please verify that the listing looks ok.
        If there was something deleted wrongly there are backups in the backreg folder.
        ****************************************************************************
        REGEDIT4

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        REGEDIT4

        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        ****************************************************************************
        Desktop.ini Contents:
        ****************************************************************************
        ****************************************************************************

        -------------

        --------------

        et le LOG Hijack

        Logfile of HijackThis v1.99.1
        Scan saved at 01:17:50, on 22/10/2005
        Platform: Windows XP (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 (6.00.2600.0000)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\AVPersonal\AVWUPSRV.EXE
        C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\Program Files\Inventel\Gateway\wlancfg.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\WINDOWS\explorer.exe
        C:\WINDOWS\system32\NOTEPAD.EXE
        C:\WINDOWS\System32\wuauclt.exe
        C:\Program Files\Netscape\Communicator\Program\netscape.exe
        C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
        C:\Documents and Settings\Philippe M\Mes documents\philippe.mallard\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://abonnes.lemonde.fr/web/sequence/0,2-3208,1-0,0.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.google.fr"); (C:\Program Files\Netscape\Users\default\prefs.js)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
        O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
        O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
        O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: hp psc 2000 Series.lnk = D:\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
        O4 - Global Startup: hpoddt01.exe.lnk = ?
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
        O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
        O20 - Winlogon Notify: waxw2k - C:\WINDOWS\SYSTEM32\waxw2k.dll
        O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: Protocol IP V4 RunTime - Unknown owner - C:\WINDOWS\System32\SVCIPV4.EXE (file missing)
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
        O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
        0
        1. Salut,
          De retour....
          Bon, j'ai toujours ce problème :
          Tout accès internet a pour conséquence de planter les applications : IE, Outlook quand un message contient du .html, WMP, etc...
          J'ai voulu scanné SVCIPV4.EXE mais je ne le trouve pas dans le system32
          J'ai effectué une recherche automatique : RAS.
          Par ailleurs, j'utilise un vieux Netscpae Navigator puisque IE plante et il ne peut afficher la page :
          http://www.virustotal.com/xhtml/virustotal_en.html

          Je suis coincé de coincé.

          Merci de votre aide..
          0
          1. Contributeur sécurité
            télécharge : process xp ici:
            http://www.sysinternals.com/files/procexpnt.zip
            decompresse le

            Déconnecte toi
            Ferme tous les programmes

            double clic sur processxp.exe

            * Dans la fenêtre principale de processxp double clic sur winlogon.exe
            Dans la nouvelle fenêtre qui s'ouvre clique sur threads
            sélectionne seulement les lignes qui contiennent waxw2k.dll puis clique sur kill pour chacune des lignes trouvées.
            une fois fait, valide avec ok

            * Dans la fenêtre principale de processxp double clic sur explorer.exe
            Dans la nouvelle fenêtre qui s'ouvre clique sur threads
            sélectionner seulement les lignes qui contiennent waxw2k.dll puis clique sur kill pour chacune des lignes trouvées.
            une fois fait, valide avec ok

            relance hijack coche ces lignes et ensuite clik sur fix
            O20 - Winlogon Notify: waxw2k - C:\WINDOWS\SYSTEM32\waxw2k.dll

            ****************************************************************

            ****************************************************************
            redemarre en mode sans echec

            mode sans echec pour cela tu tapote la touche f8
            des le debut de l allumage du pc sans t arreter
            une fenetre vas souvrir tute deplace avec les fleches du clavier sur demarreren mode sans echec
            une fois sur le bureau il ni auras pas toutes les couleurs et autres c est normal.si f8 ne marche pas utilise la touche f5
            ****************************************************************
            recherche et suppr ceci
            C:\WINDOWS\SYSTEM32\waxw2k.dll

            0
            1. Merci !
              Tout fonctionne, j'ai suivi point par point : nickel ! ;-))

              Merci encore.

              Et maintenant pour éviter cela :
              Avast ou Antivir ?
              Quel soft pour contrôler les troyens et worms ?

              Philippe Mallard
              0
              1. Contributeur sécurité
                content pour toi
                pour les anti virus perso j utilise bit defender
                et je n est jamais utiliser ceux que tu site
                0