Message au démarrage de Windows

peaceandlover -  
 Utilisateur anonyme -
Bonjour !

J'ai un petit ennui. A chaque démarrage de Windows, une boîte de dialoque sans titre s'ouvre. Elle contient le message suivant : SOFTWARE\Microsoft\Windows\CurrentVersion\Run .
La boîte de dialogue ne comport qu'un simple bouton "OK" et réapparaît à chaque démarrage de Windows.

Comment régler le problème ? Je vous remercie d'avance.
Configuration: Windows XP SP1
Avast! antivirus

2 réponses

  1. Utilisateur anonyme
     
    ouvre regedit.
    va voir dans HKLM, à l'endroit de cette clé:
    SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    dis-moi si possible ce qu'il ya ...
    S'il y a un truc que tu ne comprends pas ne sachant de quel niveau tu es, tu demandes, il n'y a pas de soucis , je serais plus clair.
    0
    1. peaceandlover
       
      Merci pour ta réponse !

      Une fois l'éditeur du registre ouvert, j'ai 5 dossiers :

      HKEY_CLASSES_ROOT
      HKEY_CURRENT_USER
      HKEY_LOCAL_MACHINE
      HKEY_USERS
      HKEY_CURRENT_CONFIG

      Que dois-je faire ?
      0
  2. blondin777 Messages postés 6162 Statut Contributeur 945
     
    Tu prends ce chemin là:HKEY_LOCAL_MACHINE /SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    0
    1. peaceandlover
       
      Il y plusieurs fichiers dans ce dossier :

      (par défaut)
      Advanced DHYML Enable
      avast!
      EM_EXEC
      Local Security Authority Service
      LogitechVideoRepair
      LogitechVideoTray
      NeroFilterCheck
      NvCplDaemon
      NvMediaCenter
      nwiz
      Omnipage
      Windows Spyware remover
      zBrowser launcher
      0
    2. Utilisateur anonyme
       
      Ben dis-moi faut faire le ménage là-dedans.
      EM_EXEC
      Bon ça c'est le truc de logitech.
      pas indispensable à virer.
      ça aussi.
      LogitechVideoRepair
      LogitechVideoTray

      C'est c'est la carte Vidéo.
      NvCplDaemon
      NvMediaCenter
      Omnipage
      zBrowser launcher
      nwiz


      pas utiles
      Advanced DHYML Enable
      Je ne sais pas ce que c'est ça !!!

      Bref à part Avast, je ne vois rien d'indispensable....
      Donc,
      Démarrer/Exécuter/Msconfig/onglet démarrage/décoche tout sauf avast
      Redémarre ton ordi.
      0
    3. Utilisateur anonyme
       
      Ceci dit download ceci:
      http://www.infos-du-net.com/telecharger/HijackThis,0301-454.html
      lance le programme et fait un scan +log.
      Copie-moi le log ici....il ya des trucs pas catho...
      0
      1. peaceandlover > Utilisateur anonyme
         
        Logfile of HijackThis v1.99.1
        Scan saved at 20:13:29, on 16/09/2006
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avast4\aswUpdSv.exe
        C:\Program Files\Avast4\ashServ.exe
        C:\WINDOWS\System32\CTSvcCDA.EXE
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\Avast4\ashDisp.exe
        C:\WINDOWS\System32\RUNDLL32.EXE
        C:\Program Files\Logitech\iTouch\iTouch.exe
        C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
        D:\OmniPageSE\opware32.exe
        C:\WINDOWS\System32\lssas.exe
        C:\dihd.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
        C:\Program Files\Avast4\ashMaiSv.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
        C:\Program Files\Avast4\ashWebSv.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
        D:\OpenOffice.org 2.0\program\soffice.exe
        D:\OpenOffice.org 2.0\program\soffice.BIN
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Windows Media Player\wmplayer.exe
        D:\VLC\vlc.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        D:\BonkEnc\BonkEnc.exe
        C:\Program Files\Outlook Express\msimn.exe
        C:\Documents and Settings\Tristan\Local Settings\Temporary Internet Files\Content.IE5\8OPEEF9D\HijackThis[1].exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://news.google.com/topstories?hl=fr&gl=FR&ceid=FR:fr
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
        O4 - HKLM\..\Run: [Omnipage] D:\OmniPageSE\opware32.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [LogitechVideoTray] D:\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
        O4 - HKLM\..\RunServices: [Windows spyware remover] Windows-spyware.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - Startup: OpenOffice.org 2.0.lnk = D:\OpenOffice.org 2.0\program\quickstart.exe
        O4 - Global Startup: Bluetooth Manager.lnk = ?
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = D:\Acrobat 7.0\Reader\reader_sl.exe
        O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        0
      2. Utilisateur anonyme > Utilisateur anonyme
         
        Bon, je crois que je l'ai repéré....
        Il se cache ici:
        Il pourrait sagir d'un vers
        supprime ceci en mode sans échec (f8 au redémarrage)
        C:\dihd.exe

        Par précaution download ce fix:
        https://www.broadcom.com/support/security-center
        désactiver la restauration système. Et puis tu le lance.

        D:\OmniPageSE\opware32.exe ...là je ne comprends pas ce que ça fait en D:
        Normalement ça doit se trouver ici:
        c:\programme\caere\omnipa~1.0\
        c:\program files\caere\omnipa~1.0\
        Mais certainement dans d: ou alors tu as changé le chemin d'install.
        Et ça c'est quoi ???
        D:\BonkEnc\BonkEnc.exe
        vérifies-moi ce truc aussi....
        ça pourrait être un encodeur mp3....
        mais je vois pas ce que ça viens faire au démarrage...LOL
        tape dans Exécuter " msconfig " et décoche BonkEnc.exe si tu le vois. Ainsi que dihd.exe évidemment !
        0