Fenetre intempestives

Bonjour a tous
j ai problemes de fenetres pub qui s ouvrent pendant que je suis connecter .ou chercher ?ou que faire?
j ai ad aware6 ,spybot ,cleanup.et j ai passer ccleaner .
j ai effacer l historique de ma messagerie et effacer les temporaty internet
si vous pouver m aider merci .docteur

40 réponses

Résumé de la discussion

Problème central : des fenêtres publicitaires apparaissent pendant la connexion et l’utilisation, malgré des outils comme Ad-Aware, Spybot et CCleaner, et la suppression de l’historique et des fichiers temporaires. Plusieurs solutions proposées incluent l’activation de TeaTimer avec Spybot S&D, l’usage d’Ewido puis HijackThis, et l’emploi d’un anti-programme malveillant pour un nettoyage en profondeur du système et des processus. D’autres échanges recommandent la désinstallation d’un outil potentiellement nuisible (WinAntiSpyware 2006), puis la ré-exécution de l2mfix et de l’analyse des clés de démarrage (O4 Run) afin d’éliminer les fichiers malveillants et les entrées. En dernier, le journal d’exécution décrit la suppression de DLL système et de multiples entrées de registre et propose de vérifier les sauvegardes backreg en cas d’erreur.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonsoir,

    Télécharge Edwido
    http://download.ewido.net/ewido-setup.exe
    Pendant l'installation, sur la page "Additional Options", décoche les deux options "Install background guard" et "Install scan via context menu Ewido Security Suite. Clique sur mise à jour.

    Clique sur scanner puis sur scan complet du système.

    ensuite,

    télécharge HijackThis ici:
    http://www.hijackthis.de/downloads/hijackthis_199.zip

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    Bon courage

    A+

    1. voila j Logfile of HijackThis v1.99.1
      Scan saved at 21:52:54, on 15/03/2006
      Platform: Windows XP (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Adobe Version Cue\ControlPanel\VersionCueTray.exe
      C:\Program Files\Generic\USB Card Reader Driver v2.2e5\FlashIcon.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
      C:\Program Files\Adobe Acrobat 6.0\Distillr\acrotray.exe
      C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Wanadoo\EspaceWanadoo.exe
      C:\Program Files\Wanadoo\ComComp.exe
      C:\Program Files\Wanadoo\Watch.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\ewido anti-malware\ewidoctrl.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Documents and Settings\Mickael & Jennifer\Local Settings\Temp\Répertoire temporaire 1 pour hijackthis_199.zip\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.1.1/ServicesAcces.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O3 - Toolbar: Toolbar888 - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Toolbar888\ToolBar888.dll (file missing)
      O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe Version Cue\ControlPanel\VersionCueTray.exe
      O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.2e5\FlashIcon.EXE
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
      O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [newname] C:\\newname2.exe
      O4 - HKLM\..\Run: [WinAntiSpyware 2006] "c:\program files\winantispyware 2006 scanner\was6.exe" /min
      O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
      O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe Acrobat 6.0\Distillr\acrotray.exe
      O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
      O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
      O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: H323TSP - C:\WINDOWS\system32\k0800almedqa0.dll
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe Version Cue\service\VersionCue.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

      ai effectuer les scans et voici le copier coller
      1. Contributeur
        RE,

        Télécharge l2mfix ici:

        http://www.downloads.subratam.org/l2mfix.exe

        Double clic sur l2mfix.exe pour lancer l'extraction.
        Dans le dossier l2mfix, double clic sur l2mfix.bat et choisis l'option #1 (et pas autre chose) et valide avec la touche entrée.
        Le bloc note va s'ouvrir avec le résultat du scan.
        Fais un copier coller du résultat sur le forum.

        A+
        1. excuse moi je n arrive la derniere manip mais il y a toujours des fenetres int
          1. Contributeur
            Ok,

            On va faire autrement.

            Va dans Ajout suppression de programme et desinstalle WinAntiSpyware 2006

            Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

            O4 - HKLM\..\Run: [newname] C:\\newname2.exe

            O4 - HKLM\..\Run: [WinAntiSpyware 2006] "c:\program files\winantispyware 2006 scanner\was6.exe" /min

            O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab

            Recherche et supprime ce fichier :

            C:\\newname2.exe

            et ensuite refait le l2mfix stp.

            Bon courage.

            A+

            1. je n avais pas
              O4 - HKLM\..\Run: [WinAntiSpyware 2006] "c:\program files\winantispyware 2006 scanner\was6.exe" /min
              autrement pour l2mfix s qu il serait possible defaire plus detaille pour la procedure merci pour l aide
              1. excuse moi je suis encore la
                j ai lancer ad aware
                et il me trouve 2fichiersque je ne peut pas effacer:
                redirected hostfile entry hosts file misc 127.0.01:websearch.com possible coolwebsearch hijack
                merci si tu as des info
                1. je n arrive pas a m ensortir avec les fenetres intempestives
                  1. Contributeur
                    Bonsoir,

                    Pour L2mfix, je vais essayer de faire plus détaillé :

                    Tu télécharges l2mfix.exe sur le bureau windows :
                    http://www.downloads.subratam.org/l2mfix.exe

                    Tu te déconnecte d'internet

                    Tu fais un double clic sur ce fichier et tu extrait tous les fichiers dans un dossier L2MFIX

                    Dans ce dossier tu fais un double clic sur l2mfix.bat et choisis l'option #1 (et pas autre chose) et valide avec la touche entrée.

                    Le bloc note va s'ouvrir avec le résultat du scan.

                    Tu te reconnecte au web

                    Tu fais un copier coller du résultat sur le forum.

                    Bon courage.

                    A+
                    1. bonsoir et merci encore pour ton soutien
                      j ai bien telecharger l2mfix.exe
                      le dossier exe c quand on a une envelloppe jaune en icone je comprends pas la phrase tu extrait tous les fichiers dans un dossier L2MFIX
                      merci encor j ai poster hier soir apresnotre discussion les fenetres qui s ouvrait et le pb avec ad aware
                      1. Contributeur
                        Re,

                        si tu fais un double clic sur le fichier que tu as téléchargé, que ce passe-t-il ?

                        A+

                        1. quand tu dis "extraire", il suffit de double cliquer pour "décompresser " le fichier? C'est ce que j'ai fais. Le pb c'est qu'il n'y a pas le fichier l2mfix.bat
                          Désolé de t'embeter autant
                          1. Contributeur
                            Re,

                            Tu ne m'embête pas :-) j'ai bcp de patience.

                            Est ce que tu as un fichier L2mfix avec comme icone un ecran et dedans une roue dentée ?
                            si oui, fait un doucle clic dessus et choisi l'option 1 et rien d'autre valide avec la touche entrée.

                            Le bloc note va s'ouvrir avec le résultat du scan.
                            Fais un copier coller du résultat sur le forum.

                            A+
                            1. L2MFIX find log 010406
                              These are the registry keys present
                              **********************************************************************************
                              Winlogon/notify:
                              Windows Registry Editor Version 5.00

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Applets]
                              "Asynchronous"=dword:00000000
                              "DllName"="C:\\WINDOWS\\system32\\o4ns0e57eh.dll"
                              "Impersonate"=dword:00000000
                              "Logon"="WinLogon"
                              "Logoff"="WinLogoff"
                              "Shutdown"="WinShutdown"

                              **********************************************************************************
                              useragent:
                              Windows Registry Editor Version 5.00

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                              "{BB299BD9-E0C4-32B3-BD7A-E091C42533F0}"=""

                              **********************************************************************************
                              Shell Extension key:
                              Windows Registry Editor Version 5.00

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                              "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
                              "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
                              "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
                              "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
                              "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                              "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
                              "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
                              "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
                              "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
                              "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
                              "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
                              "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
                              "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
                              "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
                              "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
                              "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
                              "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
                              "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
                              "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
                              "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
                              "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
                              "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
                              "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
                              "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
                              "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
                              "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                              "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
                              "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
                              "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
                              "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
                              "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
                              "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
                              "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
                              "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
                              "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
                              "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
                              "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
                              "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
                              "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
                              "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
                              "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
                              "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
                              "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
                              "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
                              "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
                              "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                              "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                              "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
                              "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
                              "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
                              "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
                              "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
                              "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
                              "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
                              "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
                              "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
                              "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
                              "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
                              "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
                              "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
                              "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
                              "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
                              "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
                              "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
                              "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
                              "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
                              "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
                              "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
                              "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
                              "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
                              "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
                              "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
                              "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
                              "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
                              "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
                              "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
                              "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
                              "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
                              "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
                              "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
                              "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
                              "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
                              "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
                              "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
                              "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
                              "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
                              "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
                              "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
                              "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
                              "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
                              "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
                              "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
                              "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
                              "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
                              "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                              "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                              "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
                              "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
                              "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
                              "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
                              "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
                              "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
                              "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
                              "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
                              "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                              "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                              "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
                              "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
                              "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
                              "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
                              "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
                              "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
                              "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
                              "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
                              "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
                              "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
                              "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
                              "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
                              "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
                              "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
                              "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
                              "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
                              "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
                              "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
                              "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
                              "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
                              "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
                              "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
                              "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
                              "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
                              "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
                              "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
                              "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
                              "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
                              "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
                              "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
                              "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
                              "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
                              "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
                              "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
                              "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
                              "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
                              "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
                              "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
                              "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
                              "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
                              "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
                              "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
                              "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
                              "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
                              "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
                              "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
                              "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
                              "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
                              "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
                              "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
                              "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
                              "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
                              "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
                              "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
                              "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
                              "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
                              "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
                              "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
                              "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
                              "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
                              "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}"="BitDefender Antivirus v7"
                              "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
                              "{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
                              "{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
                              "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
                              "{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}"="Adobe.Acrobat.ContextMenu"
                              "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
                              "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
                              "{0879FECF-BFAE-41E0-B0F2-716C9BC230E4}"=""
                              "{2527E547-B26C-4CF6-BDFD-352AC850C10A}"=""
                              "{57181F0D-33EC-4955-880E-3DB6AE9DFB9A}"=""
                              "{A97EA539-FB3B-43A0-9857-E88FEE61F90A}"=""
                              "{C377564D-CA07-4DCE-8D70-877049AF09FD}"=""
                              "{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}"="TuneUp Shredder Shell Context Menu Extension"
                              "{14C2DF8C-8585-40DD-9720-5843D03CF375}"=""
                              "{F3C04DA6-2D46-4D56-9A44-A3A7A679EC0B}"=""
                              "{DEE7B5F9-01BB-412C-94D3-B1D493299176}"=""

                              **********************************************************************************
                              HKEY ROOT CLASSIDS:
                              Windows Registry Editor Version 5.00

                              [HKEY_CLASSES_ROOT\CLSID\{14C2DF8C-8585-40DD-9720-5843D03CF375}]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{14C2DF8C-8585-40DD-9720-5843D03CF375}\Implemented Categories]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{14C2DF8C-8585-40DD-9720-5843D03CF375}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{14C2DF8C-8585-40DD-9720-5843D03CF375}\InprocServer32]
                              @="C:\\WINDOWS\\system32\\mxc40loc.dll"
                              "ThreadingModel"="Apartment"

                              Windows Registry Editor Version 5.00

                              [HKEY_CLASSES_ROOT\CLSID\{F3C04DA6-2D46-4D56-9A44-A3A7A679EC0B}]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{F3C04DA6-2D46-4D56-9A44-A3A7A679EC0B}\Implemented Categories]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{F3C04DA6-2D46-4D56-9A44-A3A7A679EC0B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{F3C04DA6-2D46-4D56-9A44-A3A7A679EC0B}\InprocServer32]
                              @="C:\\WINDOWS\\system32\\WNVADVE.DLL"
                              "ThreadingModel"="Apartment"

                              Windows Registry Editor Version 5.00

                              [HKEY_CLASSES_ROOT\CLSID\{DEE7B5F9-01BB-412C-94D3-B1D493299176}]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{DEE7B5F9-01BB-412C-94D3-B1D493299176}\Implemented Categories]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{DEE7B5F9-01BB-412C-94D3-B1D493299176}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                              @=""

                              [HKEY_CLASSES_ROOT\CLSID\{DEE7B5F9-01BB-412C-94D3-B1D493299176}\InprocServer32]
                              @="C:\\WINDOWS\\system32\\guard.tmp"
                              "ThreadingModel"="Apartment"

                              **********************************************************************************
                              Files Found are not all bad files:

                              C:\WINDOWS\SYSTEM32\
                              browser.dll Mon 26 Dec 2005 19:05:40 A.... 48 640 47,50 K
                              browse~1.dll Mon 26 Dec 2005 19:05:40 A.... 48 640 47,50 K
                              i4600e~1.dll Wed 15 Mar 2006 17:48:28 ..S.R 236 032 230,50 K
                              itss.dll Mon 26 Dec 2005 19:08:32 A.... 123 392 120,50 K
                              mstask.dll Mon 26 Dec 2005 19:05:40 A.... 257 536 251,50 K
                              mv26l9~1.dll Thu 16 Mar 2006 18:06:18 ..S.R 234 062 228,57 K
                              mxc40loc.dll Wed 15 Mar 2006 22:24:36 ..S.R 235 736 230,21 K
                              netapi32.dll Mon 26 Dec 2005 19:05:40 A.... 301 568 294,50 K
                              netapi~1.dll Mon 26 Dec 2005 19:05:40 A.... 301 568 294,50 K
                              o4ns0e~1.dll Wed 15 Mar 2006 22:24:36 ..S.R 236 490 230,95 K
                              schedsvc.dll Mon 26 Dec 2005 19:05:40 A.... 161 280 157,50 K
                              scheds~1.dll Mon 26 Dec 2005 19:05:40 A.... 161 280 157,50 K
                              sintf16.dll Thu 2 Feb 2006 20:16:34 A.... 12 067 11,78 K
                              sintf32.dll Thu 2 Feb 2006 20:16:34 A.... 17 212 16,81 K
                              sintfnt.dll Thu 2 Feb 2006 20:16:34 A.... 21 840 21,33 K
                              wnvadve.dll Thu 16 Mar 2006 18:06:18 ..S.R 236 490 230,95 K

                              16 items found: 16 files (5 H/S), 0 directories.
                              Total of file sizes: 2 633 833 bytes 2,51 M
                              Locate .tmp files:

                              C:\WINDOWS\SYSTEM32\
                              __dele~1.tmp Thu 16 Mar 2006 18:22:50 A.... 236 490 230,95 K

                              1 item found: 1 file, 0 directories.
                              Total of file sizes: 236 490 bytes 230,95 K
                              **********************************************************************************
                              Directory Listing of system files:
                              Le volume dans le lecteur C n'a pas de nom.
                              Le num‚ro de s‚rie du volume est 4CE1-2313

                              R‚pertoire de C:\WINDOWS\System32

                              16/03/2006 18:06 236ÿ490 WNVADVE.DLL
                              16/03/2006 18:06 234ÿ062 mv26l9fs1.dll
                              15/03/2006 22:24 235ÿ736 mxc40loc.dll
                              15/03/2006 22:24 236ÿ490 o4ns0e57eh.dll
                              15/03/2006 17:48 236ÿ032 i4600ejmehoa0.dll
                              06/02/2006 21:22 <REP> dllcache
                              28/11/2005 17:37 <REP> Microsoft
                              5 fichier(s) 1ÿ178ÿ810 octets
                              2 R‚p(s) 8ÿ967ÿ004ÿ160 octets libres

                              Voici le rapport d'erreur que j'ai reçu
                              1. Contributeur
                                re,

                                ferme toutes les applications,

                                Relances l2mfix et sélectionne l'option #2

                                L'ordi va redémarrer automatiquement sinon le faire manuellement

                                Recopie le log et colle-le ici

                                Ensuite, relance hijackthis et colle le log ici.

                                A+

                                1. Running From:
                                  C:\Documents and Settings\Mickael & Jennifer\Bureau\l2mfix

                                  Killing Processes!

                                  Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
                                  Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
                                  Killing PID 608 'smss.exe'

                                  Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
                                  Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
                                  Killing PID 688 'winlogon.exe'

                                  Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
                                  Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
                                  Killing PID 876 'explorer.exe'

                                  Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
                                  Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
                                  Killing PID 2040 'rundll32.exe'
                                  Restoring Sedebugprivilege:
                                  Granting SeDebugPrivilege to Administrateurs ... successful

                                  Scanning First Pass. Please Wait!

                                  First Pass Completed

                                  Second Pass Scanning

                                  Second pass Completed!
                                  1 fichier(s) copi‚(s).
                                  1 fichier(s) copi‚(s).
                                  1 fichier(s) copi‚(s).
                                  1 fichier(s) copi‚(s).
                                  1 fichier(s) copi‚(s).
                                  1 fichier(s) copi‚(s).
                                  1 fichier(s) copi‚(s).
                                  Deleting: C:\WINDOWS\system32\hr6m05j1e.dll
                                  Successfully Deleted: C:\WINDOWS\system32\hr6m05j1e.dll
                                  Deleting: C:\WINDOWS\system32\i4600ejmehoa0.dll
                                  Successfully Deleted: C:\WINDOWS\system32\i4600ejmehoa0.dll
                                  Deleting: C:\WINDOWS\system32\mtcms.dll
                                  Successfully Deleted: C:\WINDOWS\system32\mtcms.dll
                                  Deleting: C:\WINDOWS\system32\mv26l9fs1.dll
                                  Successfully Deleted: C:\WINDOWS\system32\mv26l9fs1.dll
                                  Deleting: C:\WINDOWS\system32\mxc40loc.dll
                                  Successfully Deleted: C:\WINDOWS\system32\mxc40loc.dll
                                  Deleting: C:\WINDOWS\system32\o4ns0e57eh.dll
                                  Successfully Deleted: C:\WINDOWS\system32\o4ns0e57eh.dll
                                  Deleting: C:\WINDOWS\system32\WNVADVE.DLL
                                  Successfully Deleted: C:\WINDOWS\system32\WNVADVE.DLL

                                  msg11?.dll
                                  0 fichier(s) copi‚(s).

                                  Restoring Windows Update Certificates.:

                                  The following Is the Current Export of the Winlogon notify key:
                                  ****************************************************************************
                                  Windows Registry Editor Version 5.00

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                                  "Asynchronous"=dword:00000000
                                  "Impersonate"=dword:00000000
                                  "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                                  6c,00,00,00
                                  "Logoff"="ChainWlxLogoffEvent"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                                  "Asynchronous"=dword:00000000
                                  "Impersonate"=dword:00000000
                                  "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                                  6c,00,6c,00,00,00
                                  "Logoff"="CryptnetWlxLogoffEvent"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                                  "DLLName"="cscdll.dll"
                                  "Logon"="WinlogonLogonEvent"
                                  "Logoff"="WinlogonLogoffEvent"
                                  "ScreenSaver"="WinlogonScreenSaverEvent"
                                  "Startup"="WinlogonStartupEvent"
                                  "Shutdown"="WinlogonShutdownEvent"
                                  "StartShell"="WinlogonStartShellEvent"
                                  "Impersonate"=dword:00000000
                                  "Asynchronous"=dword:00000001

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                                  "DLLName"="wlnotify.dll"
                                  "Logon"="SCardStartCertProp"
                                  "Logoff"="SCardStopCertProp"
                                  "Lock"="SCardSuspendCertProp"
                                  "Unlock"="SCardResumeCertProp"
                                  "Enabled"=dword:00000001
                                  "Impersonate"=dword:00000001
                                  "Asynchronous"=dword:00000001

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                                  "Asynchronous"=dword:00000000
                                  "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                                  6c,00,6c,00,00,00
                                  "Impersonate"=dword:00000000
                                  "StartShell"="SchedStartShell"
                                  "Logoff"="SchedEventLogOff"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                                  "Logoff"="WLEventLogoff"
                                  "Impersonate"=dword:00000000
                                  "Asynchronous"=dword:00000001
                                  "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                                  6c,00,6c,00,00,00

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                                  "DLLName"="WlNotify.dll"
                                  "Lock"="SensLockEvent"
                                  "Logon"="SensLogonEvent"
                                  "Logoff"="SensLogoffEvent"
                                  "Safe"=dword:00000001
                                  "MaxWait"=dword:00000258
                                  "StartScreenSaver"="SensStartScreenSaverEvent"
                                  "StopScreenSaver"="SensStopScreenSaverEvent"
                                  "Startup"="SensStartupEvent"
                                  "Shutdown"="SensShutdownEvent"
                                  "StartShell"="SensStartShellEvent"
                                  "PostShell"="SensPostShellEvent"
                                  "Disconnect"="SensDisconnectEvent"
                                  "Reconnect"="SensReconnectEvent"
                                  "Unlock"="SensUnlockEvent"
                                  "Impersonate"=dword:00000001
                                  "Asynchronous"=dword:00000001

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                                  "Asynchronous"=dword:00000000
                                  "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                                  6c,00,6c,00,00,00
                                  "Impersonate"=dword:00000000
                                  "Logoff"="TSEventLogoff"
                                  "Logon"="TSEventLogon"
                                  "PostShell"="TSEventPostShell"
                                  "Shutdown"="TSEventShutdown"
                                  "StartShell"="TSEventStartShell"
                                  "Startup"="TSEventStartup"
                                  "MaxWait"=dword:00000258
                                  "Reconnect"="TSEventReconnect"
                                  "Disconnect"="TSEventDisconnect"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Themes]
                                  "Asynchronous"=dword:00000000
                                  "DllName"="C:\\WINDOWS\\system32\\o4ns0e57eh.dll"
                                  "Impersonate"=dword:00000000
                                  "Logon"="WinLogon"
                                  "Logoff"="WinLogoff"
                                  "Shutdown"="WinShutdown"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                                  "DLLName"="wlnotify.dll"
                                  "Logon"="RegisterTicketExpiredNotificationEvent"
                                  "Logoff"="UnregisterTicketExpiredNotificationEvent"
                                  "Impersonate"=dword:00000001
                                  "Asynchronous"=dword:00000001

                                  The following are the files found:
                                  ****************************************************************************
                                  C:\WINDOWS\system32\hr6m05j1e.dll
                                  C:\WINDOWS\system32\i4600ejmehoa0.dll
                                  C:\WINDOWS\system32\mtcms.dll
                                  C:\WINDOWS\system32\mv26l9fs1.dll
                                  C:\WINDOWS\system32\mxc40loc.dll
                                  C:\WINDOWS\system32\o4ns0e57eh.dll
                                  C:\WINDOWS\system32\WNVADVE.DLL

                                  Registry Entries that were Deleted:
                                  Please verify that the listing looks ok.
                                  If there was something deleted wrongly there are backups in the backreg folder.
                                  ****************************************************************************
                                  Windows Registry Editor Version 5.00

                                  [HKEY_CLASSES_ROOT\CLSID\{49C3BDF8-93EC-4F26-B44A-648A42A63026}]
                                  @=""

                                  [HKEY_CLASSES_ROOT\CLSID\{49C3BDF8-93EC-4F26-B44A-648A42A63026}\Implemented Categories]
                                  @=""

                                  [HKEY_CLASSES_ROOT\CLSID\{49C3BDF8-93EC-4F26-B44A-648A42A63026}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                                  @=""

                                  [HKEY_CLASSES_ROOT\CLSID\{49C3BDF8-93EC-4F26-B44A-648A42A63026}\InprocServer32]
                                  @="C:\\WINDOWS\\system32\\mtcms.dll"
                                  "ThreadingModel"="Apartment"

                                  REGEDIT4

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                                  "{49C3BDF8-93EC-4F26-B44A-648A42A63026}"=-
                                  [-HKEY_CLASSES_ROOT\CLSID\{49C3BDF8-93EC-4F26-B44A-648A42A63026}]
                                  REGEDIT4

                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                                  ****************************************************************************
                                  Desktop.ini Contents:
                                  ****************************************************************************
                                  ****************************************************************************

                                  voici le log
                                  1. et voici le hijackthis
                                    Logfile of HijackThis v1.99.1
                                    Scan saved at 21:54:33, on 16/03/2006
                                    Platform: Windows XP (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\System32\Ati2evxx.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\LEXBCES.EXE
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\WINDOWS\system32\LEXPPS.EXE
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                                    C:\Program Files\Generic\USB Card Reader Driver v2.2e5\FlashIcon.EXE
                                    C:\WINDOWS\SOUNDMAN.EXE
                                    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                                    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
                                    C:\Program Files\Adobe Acrobat 6.0\Distillr\acrotray.exe
                                    C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe
                                    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                    C:\Program Files\ewido anti-malware\ewidoctrl.exe
                                    C:\WINDOWS\System32\FTRTSVC.exe
                                    C:\WINDOWS\system32\slserv.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\NOTEPAD.EXE
                                    C:\Program Files\Wanadoo\EspaceWanadoo.exe
                                    C:\Program Files\Wanadoo\ComComp.exe
                                    C:\PROGRA~1\Wanadoo\Toaster.exe
                                    C:\PROGRA~1\Wanadoo\Inactivity.exe
                                    C:\PROGRA~1\Wanadoo\PollingModule.exe
                                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                    C:\Program Files\Wanadoo\Watch.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Documents and Settings\Mickael & Jennifer\Bureau\HijackThis.exe

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
                                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.1.1/ServicesAcces.html
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                                    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                                    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                                    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                    O3 - Toolbar: Toolbar888 - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
                                    O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe Version Cue\ControlPanel\VersionCueTray.exe
                                    O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
                                    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                    O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.2e5\FlashIcon.EXE
                                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                                    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
                                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
                                    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                    O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                                    O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe Acrobat 6.0\Distillr\acrotray.exe
                                    O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                                    O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
                                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
                                    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                                    O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\o4ns0e57eh.dll (file missing)
                                    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                    O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe Version Cue\service\VersionCue.exe
                                    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                                    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                    O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
                                    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                    O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
                                    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
                                    1. Contributeur
                                      Re,

                                      tu as bien travaillé, le l2mfix aussi d'ailleurs !
                                      je reviens dans une minute avec la suite du programme.

                                      A+
                                      1. Contributeur
                                        La suite :

                                        1 - Arrête ces services :

                                        Clique sur Démarrer->exécuter->tape: services.msc

                                        Double-clique: Service: TuneUp WinStyler Theme Service

                                        Règle-le sur "Arrêté" et "Désactivé".

                                        2 - Va dans Ajout/suppression de programme et desinstalle TuneUp WinStyler Theme Service

                                        3 - Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.1.1/ServicesAcces.html

                                        O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\o4ns0e57eh.dll (file missing)

                                        puis relance hijackthis et colle le log sur le forum.

                                        Bon courage.

                                        A+

                                        • 1
                                        • 2