Message d'exception!!!

Salut à tous,

A chaque démarrage ce message apparait: "Une exception s'est produite lors de la tentative d'execution: C:\WINDOWS\system32\wjiprop.dll" DllGetVersion"
La partie avant l'extension .dll change à chaque fois.

Que faire pour stopper cette anomalie

Merci
Nico

23 réponses

Résumé de la discussion

Une exception survient au démarrage, indiquant l'échec d'exécution d'un fichier DLL référencé dans C:\WINDOWS\system32\wjiprop.dll et variant par la ligne avant l'extension, suscitant une panne répétitive. Des solutions proposées incluent l'utilisation de KillBox pour supprimer des fichiers douteux comme guard.tmp et plusieurs DLL situés dans System32, suivie d'un redémarrage pour nettoyer l'infection. Cependant la manipulation via KillBox est considérée comme inefficace par certains et l'accent est mis sur la réparation de l'erreur et l'usage d'outils comme L2MeFix ou HijackThis pour analyser la configuration. Des éléments techniques additionnels évoquent une erreur du sous-système MS-DOS 16 bits et un rapport HijackThis détaillé montrant des clés Winlogon Notify et des extensions potentiellement malveillantes.

Bobot (l’IA à votre service)
  1. salut pour les ralentissement essay ceci dans l'ordre

    1. reg cleaner pour netoyer le registre :

    http://www.01net.com/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/4894.html
    pour le rendre en francais tu va dans
    option / language et tu choisi francais

    options > nettoyage du registre > sauvegarde > créer une sauvegarde : cela permettras de restaurer une clé supprimée ultérieurement par erreur avec regcleaner.

    pour effectuer un netoyage du registre :

    outils/netoyage du registre/ tout faire
    apres l'analyse clike sur " selection/ tout puis clike sur "supprimer selections ( en bas a droite)

    2.supprime des programes du demarrage pour gagné en rapidité :

    Démarrer/Exécuter/tape: msconfig/ dans l'onglet demarage decoche tout laisse coché seulement ce qui est utile c'est a dire antivirus/ firewall
    tu clike sur appliquer/ redemarrer maintenant

    au redemarage une petit fenetre s'affiche coche ne plus afficher ce message

    3. effectues un nettoyage du disque:

    menu Démarrer > Accessoires > Outils système > Nettoyage du disque
    choisi lecteur C: valide par oui

    ensuite coche tout et clike sur ok

    demo:
    http://web.hec.ca/virtuose/index.cfm?page=152

    tu fait pareille mais cette fois ci ouvre l'onglet "autre option"
    dans la rubrique Restauration du système, clique Nettoyer

    demo:
    http://www.libellules.ch/dotclear/index.php?2005/12/16/704-supprimer-les-points-de-restauration-de-windows-xp

    4. Supprimer les fichiers temporaires

    vides tout le contenu de ces dossiers en gras

    * C:\Documents and Settings\ton compte\Local Settings\Temp
    * C:\Documents and Settings\tous les autres comptes\Local Settings\Temp
    * C:\Windows\Temp
    * C:\Windows\Prefetch supprime tout ce qu'il y'a a l'interieur sauf le fichier nommée " layout.ini"

    vide la corbeille

    5. scan disk pour reparer les erreurs :
    demo:
    http://www.chez.com/apollo0302/pages/nettoyag/nettoy04.htm

    6. defragmentation :(vaut mieu la faire la nuit parceque ca prend bcp de temp)
    demo:

    http://www.astucesinternet.com/modules/smartfaq/faq.php?faqid=3&PHPSESSID=99df8657524ae17ac1d985e846b78069

    @+++++
    1. Encore merci

      Nikko
  2. Salut,

    Ca y est, j'ai installé Kério, merci

    Y a t il une solution pour régler le probleme de lenteur de mon PC ?

    @+
    1. salut ok c'est bon just cette ligne a fixé avec hijack

      O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\k8lq0i35e8.dll (file missing)

      esque tu recois toujour des pub?

      @+++++++++
      1. Salut Jess,

        J'ai fixé la ligne en question, voici le rapport qui s'en suit,
        Effectivement, j'ai l'impression qu'il n'y a plus d pub,

        C'est fantastique, je suis impressionné,

        Merci beaucoup,

        Nikko

        Logfile of HijackThis v1.99.1
        Scan saved at 22:40:30, on 01/02/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Program Files\ewido anti-malware\ewidoctrl.exe
        C:\WINDOWS\system32\HPConfig.exe
        C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
        C:\WINDOWS\System32\tcpsvcs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Vg\VirtuaGirl2.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\Veger\Bureau\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - - (no file)
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\fr\msntb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - Startup: VirtuaGirl2.lnk = C:\Program Files\Vg\VirtuaGirl2.exe
        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
        O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
        O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O12 - Plugin for .3gp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O12 - Plugin for .amr: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
        O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
        O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O12 - Plugin for ¸æ: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://photos04.aol.fr/ygp/aol/plugin/screensaver/YGPPicScreensaver.fr-FR.9.1.6.20.cab
        O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://photos04.aol.fr/ygp/aol/plugin/download/YGPPicDownload.fr-FR.9.1.6.18.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
        O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
        O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

        @+
    2. salut
      ferme tous les programmes parce qu'il va y avoir reboot automatique
      Ouvre le dossier l2mfix créé sur le bureau puis double-clic sur L2Mfix.bat
      Ensuite choisis l'option 2 puis Entrée
      Puis appuie sur n'importe quelle touche pour redémarrer l'ordinateur
      Après redémarrage, le bureau et les icônes vont apparaître puis disparaître, c'est normal ! Et un nouveau rapport va apparaître à l'écran.
      >> Si après redémarrage les icônes n'apparaissent/disparaissent pas ou si le rapport n'apparaît pas, alors ouvre le dossier l2mfix et lance second.bat

      Enfin poste ce 2ème rapport avec un nouveau rapport HJT.

      @++++++++
      1. Jess,
        La deuxieme tentative a réusssi,

        L2mfix 010406
        Creating Account.
        La commande s'est termin‚e correctement.

        Adding Administrative privleges.
        Checking for L2MFix account(0=no 1=yes):
        1
        Granting SeDebugPrivilege to L2MFIX ... successful

        Running From:
        C:\WINDOWS\system32

        Killing Processes!

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 704 'smss.exe'

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 1044 'winlogon.exe'
        Killing PID 1044 'winlogon.exe'
        Killing PID 1044 'winlogon.exe'
        Killing PID 1044 'winlogon.exe'
        Killing PID 1044 'winlogon.exe'

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 2996 'explorer.exe'
        Killing PID 2996 'explorer.exe'
        Killing PID 2996 'explorer.exe'
        Killing PID 2996 'explorer.exe'
        Killing PID 2996 'explorer.exe'
        Killing PID 2996 'explorer.exe'
        Killing PID 2996 'explorer.exe'

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 2476 'rundll32.exe'
        Restoring Sedebugprivilege:
        Granting SeDebugPrivilege to Administrateurs ... successful

        Scanning First Pass. Please Wait!

        First Pass Completed

        Second Pass Scanning

        Second pass Completed!
        0 fichier(s) copi‚(s).
        0 fichier(s) copi‚(s).
        0 fichier(s) copi‚(s).
        0 fichier(s) copi‚(s).
        Deleting: C:\WINDOWS\system32\d2j00c1mef.dll
        Successfully Deleted: C:\WINDOWS\system32\d2j00c1mef.dll
        Deleting: C:\WINDOWS\system32\ir42l5ho1.dll
        Successfully Deleted: C:\WINDOWS\system32\ir42l5ho1.dll
        Deleting: C:\WINDOWS\system32\k8lq0i35e8.dll
        Successfully Deleted: C:\WINDOWS\system32\k8lq0i35e8.dll
        Deleting: C:\WINDOWS\system32\mocat32.dll
        Successfully Deleted: C:\WINDOWS\system32\mocat32.dll

        msg11?.dll
        0 fichier(s) copi‚(s).

        Restoring Windows Update Certificates.:

        The following Is the Current Export of the Winlogon notify key:
        ****************************************************************************
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
        6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Dynamic Directory]
        "Asynchronous"=dword:00000000
        "DllName"="C:\\WINDOWS\\system32\\k8lq0i35e8.dll"
        "Impersonate"=dword:00000000
        "Logon"="WinLogon"
        "Logoff"="WinLogoff"
        "Shutdown"="WinShutdown"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
        "DLLName"="wlnotify.dll"
        "Logon"="SCardStartCertProp"
        "Logoff"="SCardStopCertProp"
        "Lock"="SCardSuspendCertProp"
        "Unlock"="SCardResumeCertProp"
        "Enabled"=dword:00000001
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "StartShell"="SchedStartShell"
        "Logoff"="SchedEventLogOff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "PostShell"="SensPostShellEvent"
        "Disconnect"="SensDisconnectEvent"
        "Reconnect"="SensReconnectEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "Logoff"="TSEventLogoff"
        "Logon"="TSEventLogon"
        "PostShell"="TSEventPostShell"
        "Shutdown"="TSEventShutdown"
        "StartShell"="TSEventStartShell"
        "Startup"="TSEventStartup"
        "MaxWait"=dword:00000258
        "Reconnect"="TSEventReconnect"
        "Disconnect"="TSEventDisconnect"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
        "DLLName"="wlnotify.dll"
        "Logon"="RegisterTicketExpiredNotificationEvent"
        "Logoff"="UnregisterTicketExpiredNotificationEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
        "Asynchronous"=dword:00000000
        "DllName"="WRLogonNTF.dll"
        "Impersonate"=dword:00000001
        "Lock"="WRLock"
        "StartScreenSaver"="WRStartScreenSaver"
        "StartShell"="WRStartShell"
        "Startup"="WRStartup"
        "StopScreenSaver"="WRStopScreenSaver"
        "Unlock"="WRUnlock"
        "Shutdown"="WRShutdown"
        "Logoff"="WRLogoff"
        "Logon"="WRLogon"

        The following are the files found:
        ****************************************************************************
        C:\WINDOWS\system32\d2j00c1mef.dll
        C:\WINDOWS\system32\ir42l5ho1.dll
        C:\WINDOWS\system32\k8lq0i35e8.dll
        C:\WINDOWS\system32\mocat32.dll

        Registry Entries that were Deleted:
        Please verify that the listing looks ok.
        If there was something deleted wrongly there are backups in the backreg folder.
        ****************************************************************************
        Windows Registry Editor Version 5.00

        [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\Implemented Categories]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\InprocServer32]
        @="C:\\WINDOWS\\system32\\mocat32.dll"
        "ThreadingModel"="Apartment"

        Windows Registry Editor Version 5.00

        [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\Implemented Categories]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\InprocServer32]
        @="C:\\WINDOWS\\system32\\mynetobj.dll"
        "ThreadingModel"="Apartment"

        REGEDIT4

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        "{E752D257-9390-41A9-9F47-4105697315F6}"=-
        "{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}"=-
        [-HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}]
        [-HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}]
        REGEDIT4

        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        "SV1"=""
        ****************************************************************************
        Desktop.ini Contents:
        ****************************************************************************

        ****************************************************************************
        Checking for L2MFix account(0=no 1=yes):
        0
        Zipping up files for submission:
        zip warning: name not matched: dlls\*.*

        zip error: Nothing to do! (backup.zip)
        adding: backregs/4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7.reg (104 bytes security) (deflated 70%)
        adding: backregs/E752D257-9390-41A9-9F47-4105697315F6.reg (104 bytes security) (deflated 70%)
        adding: backregs/notibac.reg (140 bytes security) (deflated 87%)

        Rapport Hijack:

        Logfile of HijackThis v1.99.1
        Scan saved at 19:45:47, on 01/02/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Program Files\ewido anti-malware\ewidoctrl.exe
        C:\WINDOWS\system32\HPConfig.exe
        C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
        C:\WINDOWS\System32\tcpsvcs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\notepad.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Vg\VirtuaGirl2.exe
        C:\Documents and Settings\Veger\Bureau\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - - (no file)
        O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\fr\msntb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
        O4 - Startup: VirtuaGirl2.lnk = C:\Program Files\Vg\VirtuaGirl2.exe
        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
        O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
        O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O12 - Plugin for .3gp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O12 - Plugin for .amr: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
        O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
        O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O12 - Plugin for ¸æ: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://photos04.aol.fr/ygp/aol/plugin/screensaver/YGPPicScreensaver.fr-FR.9.1.6.20.cab
        O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://photos04.aol.fr/ygp/aol/plugin/download/YGPPicDownload.fr-FR.9.1.6.18.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\k8lq0i35e8.dll (file missing)
        O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
        O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
        O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

        Merci
    3. Salut

      Voici le long rapport de l'option 1 de l2m:

      L2MFIX find log 010406
      These are the registry keys present
      **********************************************************************************
      Winlogon/notify:
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000000
      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
      6c,00,00,00
      "Logoff"="ChainWlxLogoffEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000000
      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
      6c,00,6c,00,00,00
      "Logoff"="CryptnetWlxLogoffEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
      "DLLName"="cscdll.dll"
      "Logon"="WinlogonLogonEvent"
      "Logoff"="WinlogonLogoffEvent"
      "ScreenSaver"="WinlogonScreenSaverEvent"
      "Startup"="WinlogonStartupEvent"
      "Shutdown"="WinlogonShutdownEvent"
      "StartShell"="WinlogonStartShellEvent"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ModuleUsage]
      "Asynchronous"=dword:00000000
      "DllName"="C:\\WINDOWS\\system32\\k8lq0i35e8.dll"
      "Impersonate"=dword:00000000
      "Logon"="WinLogon"
      "Logoff"="WinLogoff"
      "Shutdown"="WinShutdown"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
      "DLLName"="wlnotify.dll"
      "Logon"="SCardStartCertProp"
      "Logoff"="SCardStopCertProp"
      "Lock"="SCardSuspendCertProp"
      "Unlock"="SCardResumeCertProp"
      "Enabled"=dword:00000001
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
      "Asynchronous"=dword:00000000
      "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
      6c,00,6c,00,00,00
      "Impersonate"=dword:00000000
      "StartShell"="SchedStartShell"
      "Logoff"="SchedEventLogOff"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
      "Logoff"="WLEventLogoff"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000001
      "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
      6c,00,6c,00,00,00

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
      "DLLName"="WlNotify.dll"
      "Lock"="SensLockEvent"
      "Logon"="SensLogonEvent"
      "Logoff"="SensLogoffEvent"
      "Safe"=dword:00000001
      "MaxWait"=dword:00000258
      "StartScreenSaver"="SensStartScreenSaverEvent"
      "StopScreenSaver"="SensStopScreenSaverEvent"
      "Startup"="SensStartupEvent"
      "Shutdown"="SensShutdownEvent"
      "StartShell"="SensStartShellEvent"
      "PostShell"="SensPostShellEvent"
      "Disconnect"="SensDisconnectEvent"
      "Reconnect"="SensReconnectEvent"
      "Unlock"="SensUnlockEvent"
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
      "Asynchronous"=dword:00000000
      "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
      6c,00,6c,00,00,00
      "Impersonate"=dword:00000000
      "Logoff"="TSEventLogoff"
      "Logon"="TSEventLogon"
      "PostShell"="TSEventPostShell"
      "Shutdown"="TSEventShutdown"
      "StartShell"="TSEventStartShell"
      "Startup"="TSEventStartup"
      "MaxWait"=dword:00000258
      "Reconnect"="TSEventReconnect"
      "Disconnect"="TSEventDisconnect"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
      "DLLName"="wlnotify.dll"
      "Logon"="RegisterTicketExpiredNotificationEvent"
      "Logoff"="UnregisterTicketExpiredNotificationEvent"
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
      "Asynchronous"=dword:00000000
      "DllName"="WRLogonNTF.dll"
      "Impersonate"=dword:00000001
      "Lock"="WRLock"
      "StartScreenSaver"="WRStartScreenSaver"
      "StartShell"="WRStartShell"
      "Startup"="WRStartup"
      "StopScreenSaver"="WRStopScreenSaver"
      "Unlock"="WRUnlock"
      "Shutdown"="WRShutdown"
      "Logoff"="WRLogoff"
      "Logon"="WRLogon"

      **********************************************************************************
      useragent:
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
      "{B2DA0D1B-6740-C2A0-9800-2CC6BA19C18E}"=""

      **********************************************************************************
      Shell Extension key:
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
      "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
      "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
      "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
      "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
      "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
      "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
      "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
      "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
      "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
      "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
      "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
      "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
      "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
      "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
      "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
      "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
      "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
      "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
      "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
      "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
      "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
      "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
      "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
      "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
      "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
      "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
      "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
      "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
      "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
      "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
      "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
      "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
      "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
      "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
      "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
      "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
      "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
      "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
      "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
      "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
      "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
      "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
      "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
      "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
      "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
      "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
      "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
      "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
      "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
      "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
      "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
      "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
      "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
      "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
      "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
      "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
      "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
      "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
      "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
      "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
      "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
      "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
      "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
      "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
      "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
      "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
      "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
      "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
      "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
      "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
      "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
      "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
      "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
      "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
      "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
      "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
      "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
      "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
      "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
      "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
      "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
      "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
      "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
      "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
      "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
      "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
      "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
      "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
      "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
      "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
      "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
      "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
      "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
      "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
      "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
      "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
      "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
      "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
      "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
      "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
      "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
      "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
      "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
      "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
      "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
      "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
      "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
      "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
      "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
      "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
      "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
      "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
      "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
      "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
      "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
      "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
      "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
      "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
      "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
      "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
      "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
      "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
      "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
      "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
      "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
      "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
      "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
      "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
      "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
      "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
      "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
      "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
      "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
      "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
      "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
      "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
      "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
      "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
      "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
      "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
      "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
      "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
      "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
      "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
      "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
      "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
      "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
      "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
      "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
      "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
      "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
      "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
      "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
      "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
      "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
      "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
      "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
      "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
      "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
      "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
      "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
      "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
      "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
      "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
      "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
      "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
      "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
      "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
      "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
      "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
      "{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
      @=""
      "{1530F7EE-5128-43BD-9977-84A4B0FAD7DF}"="PhotoToys"
      "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
      "{40950107-FEA6-4d53-A65F-B2DCBA57DD58}"="Nokia Phone Browser"
      "{FBFE7864-D495-41f0-B7DC-4BB601CC295E}"="Contact View"
      "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
      "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
      "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
      "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
      "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
      "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
      "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
      "{E752D257-9390-41A9-9F47-4105697315F6}"=""
      "{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
      "{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="P‚riph‚riques Plug and Play universels"
      "{6EE51AA0-77A0-11D7-B4E1-000347126E46}"="Window Washer Shredding Utility"
      "{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}"=""
      "{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Context Menu Shell Extension"
      "{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 DragDrop Shell Extension"
      "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Context Menu Shell Extension"
      "{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Property Sheet Shell Extension"

      **********************************************************************************
      HKEY ROOT CLASSIDS:
      Windows Registry Editor Version 5.00

      [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\Implemented Categories]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\InprocServer32]
      @="C:\\WINDOWS\\system32\\ahferror.dll"
      "ThreadingModel"="Apartment"

      Windows Registry Editor Version 5.00

      [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\Implemented Categories]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\InprocServer32]
      @="C:\\WINDOWS\\system32\\mynetobj.dll"
      "ThreadingModel"="Apartment"

      **********************************************************************************
      Files Found are not all bad files:

      C:\WINDOWS\SYSTEM32\
      ahferror.dll Wed 1 Feb 2006 15:05:36 ..S.R 235 733 230,21 K
      browseui.dll Thu 24 Nov 2005 1:08:34 A.... 1 022 976 999,00 K
      danim.dll Sat 5 Nov 2005 4:17:22 A.... 1 056 768 1,01 M
      gccoll~1.dll Tue 15 Nov 2005 12:12:08 A.... 126 680 123,71 K
      gcunco~1.dll Tue 15 Nov 2005 12:12:06 A.... 95 448 93,21 K
      gdi32.dll Thu 29 Dec 2005 3:56:04 A.... 280 064 273,50 K
      gwfspi~1.dll Fri 4 Nov 2005 16:27:18 A.... 23 304 22,76 K
      hashlib.dll Tue 15 Nov 2005 12:12:08 A.... 117 976 115,21 K
      ir42l5~1.dll Tue 31 Jan 2006 16:26:12 ..S.R 236 898 231,34 K
      k8lq0i~1.dll Tue 31 Jan 2006 15:26:14 ..S.R 235 733 230,21 K
      legitc~1.dll Fri 4 Nov 2005 16:27:24 A.... 534 280 521,76 K
      mshtml.dll Thu 24 Nov 2005 1:08:36 A.... 3 013 632 2,87 M
      shdocvw.dll Thu 1 Dec 2005 5:01:16 A.... 1 492 992 1,42 M
      urlmon.dll Sat 5 Nov 2005 4:17:26 A.... 606 208 592,00 K
      wrlogo~1.dll Wed 14 Dec 2005 19:29:02 A.... 492 544 481,00 K
      wrlzma.dll Wed 14 Dec 2005 19:28:58 A.... 17 920 17,50 K

      16 items found: 16 files (3 H/S), 0 directories.
      Total of file sizes: 9 589 156 bytes 9,14 M
      Locate .tmp files:

      No matches found.
      **********************************************************************************
      Directory Listing of system files:
      Le volume dans le lecteur C n'a pas de nom.
      Le num‚ro de s‚rie du volume est 4D8B-C31B

      R‚pertoire de C:\WINDOWS\System32

      01/02/2006 15:05 235ÿ733 ahferror.dll
      31/01/2006 16:26 236ÿ898 ir42l5ho1.dll
      31/01/2006 15:26 235ÿ733 k8lq0i35e8.dll
      25/01/2006 15:21 <REP> dllcache
      12/12/2002 13:24 <REP> Microsoft
      3 fichier(s) 708ÿ364 octets
      2 R‚p(s) 24ÿ330ÿ117ÿ120 octets libres
      1. salut nikko refait un scan d'edwido mais cette fois ci en mode sans echec ( redemarrage + tappotte sans arret sur la touche F8 desque l'ordi s'allume) ensuite post le rapport suivi d'un hijack
        si le probleme persiste alors on va faire ce que moe a dit ( que je remercie au passage pour l'info)

        c'est a dire restauré le fichier autoexec.nt

        @++++++++
        1. salut Jess, je crois que ce n'est pas encore suffisant...

          Rapport Hijack:

          Logfile of HijackThis v1.99.1
          Scan saved at 14:36:08, on 31/01/2006
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\LEXBCES.EXE
          C:\WINDOWS\system32\LEXPPS.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Program Files\ewido anti-malware\ewidoctrl.exe
          C:\WINDOWS\system32\HPConfig.exe
          C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
          C:\WINDOWS\System32\tcpsvcs.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\POPUPKILLER\PopupKiller.exe
          C:\Program Files\Vg\VirtuaGirl2.exe
          C:\DOCUME~1\Veger\LOCALS~1\Temp\Répertoire temporaire 3 pour hijackthis.zip\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: (no name) - - (no file)
          O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\fr\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
          O4 - Startup: POPUP KILLER.lnk = C:\Program Files\POPUPKILLER\PopupKiller.exe
          O4 - Startup: VirtuaGirl2.lnk = C:\Program Files\Vg\VirtuaGirl2.exe
          O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
          O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
          O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
          O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O12 - Plugin for .3gp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
          O12 - Plugin for .amr: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
          O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
          O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
          O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
          O12 - Plugin for ¸æ: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
          O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
          O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://photos04.aol.fr/ygp/aol/plugin/screensaver/YGPPicScreensaver.fr-FR.9.1.6.20.cab
          O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://photos04.aol.fr/ygp/aol/plugin/download/YGPPicDownload.fr-FR.9.1.6.18.cab
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
          O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\ir44l5hq1.dll
          O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
          O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
          O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
          O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
          O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      2. salut l'antivirus n'as pas supprimer l2me vu que cette ligne est tjr presente O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\q8ps0i77e8.dll

        malheureusement l2mefix ne marche pas chez toi a cause du message d'erreur donc on va essayé autrement mais ca va etre dur

        telecharge et execute ces antispywares ( pense a les mettre a jour avant de les lancées)
        (1) ad-aware version 1.06

        (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
        voir demo
        http://pageperso.aol.fr/balltrap34/adwseflash.zip
        ***
        (2) spybot version 1.4

        (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite

        voir demo d utilisation
        http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
        ***

        (3) spysweeper
        il est payant mais tu peu l'utliser gratuitement pendant 15 jours
        http://www.01net.com/windows/Utilitaire/antivirus/fiches/26411.html

        (4) Edwido
        http://download.ewido.net/ewido-setup.exe
        Pendant l'installation, sur la page "Additional Options", décoche les deux options "Install background guard" et "Install scan via context menu Ewido Security Suite. Clique sur mise à jour.

        Clique sur scanner puis sur scan complet du système ensuite colle le resultat ici :) suivi d'un rapport hijack

        @++++++++++
        1. Voici le rapport Ewido
          suivi d'un Hijackthis

          ---------------------------------------------------------
          ewido anti-malware - Rapport de scan
          ---------------------------------------------------------

          + Créé le: 22:11:59, 30/01/2006
          + Somme de contrôle: BA7EDD59

          + Résultats du scan:

          HKU\S-1-5-21-1448739025-430466593-3954060551-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D1-F8E0-41AD-92A3-14154ECE70AC} -> Spyware.MyWay : Nettoyer et sauvegarder
          HKU\S-1-5-21-1448739025-430466593-3954060551-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC} -> Spyware.MyWay : Nettoyer et sauvegarder
          [844] C:\WINDOWS\system32\whnfax.dll -> Spyware.Look2Me : Erreur durant le nettoyage
          [664] C:\WINDOWS\system32\whnfax.dll -> Spyware.Look2Me : Erreur durant le nettoyage
          C:\Program Files\Hitman Pro\hitmanpro2.exe -> Trojan.Rebooter.r : Nettoyer et sauvegarder
          C:\Program Files\Hitman Pro\updates\hitmanpro2.pak -> Trojan.Rebooter.r : Nettoyer et sauvegarder
          C:\WINDOWS\system32\eaent.dll -> Spyware.Look2Me : Nettoyer et sauvegarder
          C:\WINDOWS\system32\f42m0ef1eh2.dll -> Spyware.Look2Me : Nettoyer et sauvegarder
          C:\WINDOWS\system32\mynetobj.dll -> Spyware.Look2Me : Nettoyer et sauvegarder
          C:\WINDOWS\Temp\Cookies\veger@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder

          ::Fin du rapport

          Hijackthis:
          Logfile of HijackThis v1.99.1
          Scan saved at 22:15:17, on 30/01/2006
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\LEXBCES.EXE
          C:\WINDOWS\system32\LEXPPS.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\HPConfig.exe
          C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
          C:\WINDOWS\System32\tcpsvcs.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\POPUPKILLER\PopupKiller.exe
          C:\Program Files\Vg\VirtuaGirl2.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\ewido anti-malware\ewidoctrl.exe
          C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
          C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
          C:\WINDOWS\system32\NOTEPAD.EXE
          C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
          C:\DOCUME~1\Veger\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: (no name) - - (no file)
          O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\fr\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
          O4 - Startup: POPUP KILLER.lnk = C:\Program Files\POPUPKILLER\PopupKiller.exe
          O4 - Startup: VirtuaGirl2.lnk = C:\Program Files\Vg\VirtuaGirl2.exe
          O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
          O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
          O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
          O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O12 - Plugin for .3gp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
          O12 - Plugin for .amr: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
          O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
          O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
          O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
          O12 - Plugin for ¸æ: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
          O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
          O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://photos04.aol.fr/ygp/aol/plugin/screensaver/YGPPicScreensaver.fr-FR.9.1.6.20.cab
          O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://photos04.aol.fr/ygp/aol/plugin/download/YGPPicDownload.fr-FR.9.1.6.18.cab
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
          O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\s0pula791d.dll
          O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
          O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
          O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
          O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
          O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

          Merci
          @+
      3. Mes fenetres pop up sont du style yyy___.html
        Unique offer
        Ebay
        etc...

        Voici le rapport

        Logfile of HijackThis v1.99.1
        Scan saved at 17:43:45, on 25/01/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\HPConfig.exe
        C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
        C:\Program Files\Spyware Doctor\sdhelp.exe
        C:\WINDOWS\System32\tcpsvcs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Vg\VirtuaGirl2.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\Program Files\POPUPKILLER\PopupKiller.exe
        C:\Program Files\POPUPKILLER\PopupKiller.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\DOCUME~1\Veger\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - - (no file)
        O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\fr\msntb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - Startup: POPUP KILLER.lnk = C:\Program Files\POPUPKILLER\PopupKiller.exe
        O4 - Startup: VirtuaGirl2.lnk = C:\Program Files\Vg\VirtuaGirl2.exe
        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
        O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
        O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O12 - Plugin for .3gp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O12 - Plugin for .amr: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
        O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
        O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O12 - Plugin for ¸æ: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
        O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
        O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
        O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://photos04.aol.fr/ygp/aol/plugin/screensaver/YGPPicScreensaver.fr-FR.9.1.6.20.cab
        O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://photos04.aol.fr/ygp/aol/plugin/download/YGPPicDownload.fr-FR.9.1.6.18.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\q8ps0i77e8.dll
        O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
        O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
        O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
        1. salut contente que tes probleme sois resolu

          pour les pop up : quelle genre de pub tu recois ??
          je crain que l'antivirus n'as pas erradiqué le spy l2me ... remet un hijack pour voir?

          @+++++++++++
          1. salut c'est vrai qu'avec le cd c'est plus facile j'espere que tu trouvera un

            pour reparer les 2 fichiers tu doit just suivre les instruction des liens http://bvrve.club.fr/Astuces_Michel/34xp.html
            http://bvrve.club.fr/Astuces_Michel/116xp.html

            @++++++++
            1. Salut,

              Je n'ai pas trouvé le CD ROm encore mais le problem semble résolu grace au bon conseil d'un ami: il m'a envoyé un antivirus super puissant qui utilise les définitions de virus de plein de logiciel différents. Après un bon 2 heures de travaux forcés, tous les problems ont disparus, même le message d'erreur du début et le pC n'est plus trop lent, Super! A priori je n'ai plus besoin de faire la manip que tu m'avais conseillé. J'ai beaucoup appris quant aux virus et moyens de les anéantir, merci pour cette aide précieuse. Je n'hésiterais pas à conseiller ce site à mon entourage. Un seul problem persiste: les pop up incessants malgré la barre Google. Aurais tu un dernier conseil à ce sujet pour un pop up blocker plus efficace?

              Merci encore
              Nikko
          2. salut c'est bizzare tout ca , essay avec un cd d'un ami ( xp famillial) et dit moi ce que ca donne

            le but c'est de reparer c'est 2 fichiers system qui sont endomagé

            C:\WINDOWS\system32\cmd.exe
            C:\WINDOWS\SYSTEM32\AUTOEXEC.NT

            si tu trouve pas un autre cd xp familial essay ceci :

            va dans post de travaille \lecteur C:\Windows\Repair

            dans ce dossier cherche le fichier Autoexec.nt clike droit dessu "copier"

            ensuite va dans poste de travail \lecteur C:\Windows\System32 colle le fichier "AUTOEXEC.NT" ensuite clike droit dessu dans attribut coche "lecture seul" pour evité la suppression au demarrage

            pour plus d'info jette un coup d'oeil ici :)
            http://www.commentcamarche.net/forum/affich-933092-Autoexec-nt
            http://www.laureats.com/dossiers/club/forum/divers/autoexec.htm
            @++++++++
            1. Salut
              C'est plus compliqué que je n'aurais pu l'imaginer!!! Merci pour ta tenacité...

              A priori copier le fichier autoexec.nt ds system 32 ne fonctionne pas.
              J'essaie de me procurer un CD ROM windows pour reparer. Dois réparer les 2 fichiers AUTOEXEC et CMD?
              Est il normal que les PC sont commercialisés désormais avec le systeme windows intégré mais sans le logiciel en CD ROM?

              @ +
          3. salut
            tu as bien fait la manip avec the killbox mais l2me est tres corriace :(

            repare le windows en suivant les instruction de ces lien

            http://bvrve.club.fr/Astuces_Michel/34xp.html
            http://bvrve.club.fr/Astuces_Michel/116xp.html

            @+++++++++
            1. Salut,

              En tout et pour tout, je possède les 3 CD de "Quick restore" et un "Compaq Operating System CD" pour windows!!!

              J'ai conserver tous les drivers de ce PC acheter neuf chez Darty en 2003.
              Comment se fait il que le CD ROM n'est pas le bon afin d coriger les ichiers DLL de windows?, Il s'agit de XP edition familiale version 2002, est ce SP1 ou SP2?
          4. salut la manip avec the killbox n'as pas marché . on va essayé de reparer l'erreur pour que tu puisse utilisé l2mefix :)
            Fenetre: Sous-systeme MS-DOS 16 bits 
            C:\WINDOWS\system32\cmd.exe 
            C:\WINDOWS\SYSTEM32\AUTOEXEC.NT. 
            Le fichier système ne convient pas à l'execution des applications MS-DOS ou Microsoft windows. 


            as tu le cd de windows xp sous la main ???

            @+++++++++
            1. Salut Jeff,

              J'ai 3 CD Compaq Quick Restore System Recovery pour microsoft Windows XP Home SP1!!!

              Sinon j'ai peut etre mal fait la manip Killbox??

              @+
          5. ok c pas grave supprime les comme ceci :

            telecharge the killbox
            http://pageperso.aol.fr/Balltrap34/KillBox.exe
            Double clic sur killbox.exe (Pocket Killbox)

            - coche: delete on reboot
            - Dans "Full Path of File to Delete"
            copie et colle: un par un

            C:\WINDOWS\System32\guard.tmp
            C:\WINDOWS\System32\n66qlgj516o.dll
            C:\WINDOWS\System32\g8jo0i13e8.dll
            C:\WINDOWS\System32\eaent.dll
            C:\WINDOWS\System32\aai3d1ag.dll
            C:\WINDOWS\System32\mynetobj.dll
            C:\WINDOWS\System32\f42m0ef1eh2.dll

            - clique sur la croix rouge
            - une fenêtre va apparaître pour confirmation clique sur YES
            - une seconde fenêtre te demande si tu veux redémarrer clique sur YES

            ensuite apres la suppression des fichiers refait un hijack et colle le resultat ici

            @+++++++++
            1. Rapport apres the KillBox:

              Logfile of HijackThis v1.99.1
              Scan saved at 14:57:33, on 20/01/2006
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\LEXBCES.EXE
              C:\WINDOWS\system32\LEXPPS.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\HPConfig.exe
              C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
              C:\WINDOWS\System32\tcpsvcs.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Vg\VirtuaGirl2.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\DOCUME~1\Veger\LOCALS~1\Temp\Répertoire temporaire 7 pour hijackthis.zip\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - Default URLSearchHook is missing
              O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\fr\msntb.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [TVAgent WiFi] C:\Program Files\Kit ADSL\Wizard\Agent_WiFi.exe
              O4 - Startup: VirtuaGirl2.lnk = C:\Program Files\Vg\VirtuaGirl2.exe
              O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
              O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
              O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
              O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
              O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O12 - Plugin for .3gp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
              O12 - Plugin for .amr: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
              O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
              O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
              O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
              O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
              O12 - Plugin for ¸æ: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
              O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
              O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
              O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} (AOL YGP Screensaver) - http://photos04.aol.fr/ygp/aol/plugin/screensaver/YGPPicScreensaver.fr-FR.9.1.6.20.cab
              O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://photos04.aol.fr/ygp/aol/plugin/download/YGPPicDownload.fr-FR.9.1.6.18.cab
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
              O20 - Winlogon Notify: policies - C:\WINDOWS\system32\f8l0li3m18.dll
              O20 - Winlogon Notify: ssldr - C:\WINDOWS\
              O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
              O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
              O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
              O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
          6. salut

            ferme tous les programmes parce qu'il va y avoir reboot automatique
            Ouvre le dossier l2mfix créé sur le bureau puis double-clic sur L2Mfix.bat
            Ensuite choisis l'option 2 puis Entrée
            Puis appuie sur n'importe quelle touche pour redémarrer l'ordinateur
            Après redémarrage, le bureau et les icônes vont apparaître puis disparaître, c'est normal ! Et un nouveau rapport va apparaître à l'écran.
            >> Si après redémarrage les icônes n'apparaissent/disparaissent pas ou si le rapport n'apparaît pas, alors ouvre le dossier l2mfix et lance second.bat

            Enfin poste ce 2ème rapport avec un nouveau rapport HJT.

            @+++++++++++
            1. Salut,
              je ne parviens pas à redemarrer le PC avec l'option 2 car on me demande un mot de passe??

              De plus

              En executant ce programme , j'ai un message d'erreur qui s'affiche:

              Fenetre: Sous-systeme MS-DOS 16 bits
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\SYSTEM32\AUTOEXEC.NT.
              Le fichier système ne convient pas à l'execution des applications MS-DOS ou Microsoft windows.

              On peut alors FERMER ou IGNORER.

              Que faire?
          7. salut refait stp l2me.fix parcequ'il manque la suite du scan ensuite copie l'integralité du rapport et colle le tout ici

            @+++++++++
            1. Salut
              Pour info:
              En executant ce programme avec l'option 1 comme spécifié, j'ai un message d'erreur qui s'affiche:

              Fenetre: Sous-systeme MS-DOS 16 bits
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\SYSTEM32\AUTOEXEC.NT.
              Le fichier système ne convient pas à l'execution des applications MS-DOS ou Microsoft windows.

              On peut alors FERMER ou IGNORER.
              J'obtiens finalement le rapport en ignorant.

              L2MFIX find log 010406
              These are the registry keys present
              **********************************************************************************
              Winlogon/notify:
              Windows Registry Editor Version 5.00

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
              "Asynchronous"=dword:00000000
              "Impersonate"=dword:00000000
              "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
              6c,00,00,00
              "Logoff"="ChainWlxLogoffEvent"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
              "Asynchronous"=dword:00000000
              "Impersonate"=dword:00000000
              "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Logoff"="CryptnetWlxLogoffEvent"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
              "DLLName"="cscdll.dll"
              "Logon"="WinlogonLogonEvent"
              "Logoff"="WinlogonLogoffEvent"
              "ScreenSaver"="WinlogonScreenSaverEvent"
              "Startup"="WinlogonStartupEvent"
              "Shutdown"="WinlogonShutdownEvent"
              "StartShell"="WinlogonStartShellEvent"
              "Impersonate"=dword:00000000
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnce]
              "Asynchronous"=dword:00000000
              "DllName"="C:\\WINDOWS\\system32\\g8jo0i13e8.dll"
              "Impersonate"=dword:00000000
              "Logon"="WinLogon"
              "Logoff"="WinLogoff"
              "Shutdown"="WinShutdown"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
              "DLLName"="wlnotify.dll"
              "Logon"="SCardStartCertProp"
              "Logoff"="SCardStopCertProp"
              "Lock"="SCardSuspendCertProp"
              "Unlock"="SCardResumeCertProp"
              "Enabled"=dword:00000001
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
              "Asynchronous"=dword:00000000
              "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Impersonate"=dword:00000000
              "StartShell"="SchedStartShell"
              "Logoff"="SchedEventLogOff"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
              "Logoff"="WLEventLogoff"
              "Impersonate"=dword:00000000
              "Asynchronous"=dword:00000001
              "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
              "DLLName"="WlNotify.dll"
              "Lock"="SensLockEvent"
              "Logon"="SensLogonEvent"
              "Logoff"="SensLogoffEvent"
              "Safe"=dword:00000001
              "MaxWait"=dword:00000258
              "StartScreenSaver"="SensStartScreenSaverEvent"
              "StopScreenSaver"="SensStopScreenSaverEvent"
              "Startup"="SensStartupEvent"
              "Shutdown"="SensShutdownEvent"
              "StartShell"="SensStartShellEvent"
              "PostShell"="SensPostShellEvent"
              "Disconnect"="SensDisconnectEvent"
              "Reconnect"="SensReconnectEvent"
              "Unlock"="SensUnlockEvent"
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssldr]
              "Asynchronous"=dword:00000000
              "Impersonate"=dword:00000000
              "Logon"="StartProcessAtWinLogon"
              "Logoff"="StopProcessAtWinLogoff"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
              "Asynchronous"=dword:00000000
              "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Impersonate"=dword:00000000
              "Logoff"="TSEventLogoff"
              "Logon"="TSEventLogon"
              "PostShell"="TSEventPostShell"
              "Shutdown"="TSEventShutdown"
              "StartShell"="TSEventStartShell"
              "Startup"="TSEventStartup"
              "MaxWait"=dword:00000258
              "Reconnect"="TSEventReconnect"
              "Disconnect"="TSEventDisconnect"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
              "DLLName"="wlnotify.dll"
              "Logon"="RegisterTicketExpiredNotificationEvent"
              "Logoff"="UnregisterTicketExpiredNotificationEvent"
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
              "Asynchronous"=dword:00000000
              "DllName"="WRLogonNTF.dll"
              "Impersonate"=dword:00000001
              "Lock"="WRLock"
              "StartScreenSaver"="WRStartScreenSaver"
              "StartShell"="WRStartShell"
              "Startup"="WRStartup"
              "StopScreenSaver"="WRStopScreenSaver"
              "Unlock"="WRUnlock"
              "Shutdown"="WRShutdown"
              "Logoff"="WRLogoff"
              "Logon"="WRLogon"

              **********************************************************************************
              useragent:
              Windows Registry Editor Version 5.00

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
              "{B2DA0D1B-6740-C2A0-9800-2CC6BA19C18E}"=""

              **********************************************************************************
              Shell Extension key:
              Windows Registry Editor Version 5.00

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
              "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
              "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
              "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
              "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
              "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
              "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
              "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
              "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
              "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
              "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
              "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
              "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
              "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
              "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
              "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
              "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
              "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
              "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
              "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
              "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
              "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
              "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
              "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
              "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
              "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
              "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
              "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
              "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
              "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
              "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
              "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
              "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
              "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
              "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
              "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
              "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
              "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
              "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
              "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
              "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
              "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
              "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
              "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
              "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
              "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
              "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
              "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
              "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
              "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
              "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
              "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
              "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
              "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
              "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
              "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
              "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
              "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
              "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
              "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
              "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
              "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
              "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
              "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
              "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
              "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
              "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
              "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
              "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
              "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
              "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
              "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
              "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
              "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
              "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
              "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
              "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
              "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
              "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
              "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
              "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
              "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
              "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
              "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
              "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
              "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
              "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
              "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
              "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
              "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
              "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
              "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
              "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
              "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
              "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
              "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
              "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
              "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
              "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
              "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
              "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
              "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
              "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
              "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
              "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
              "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
              "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
              "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
              "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
              "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
              "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
              "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
              "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
              "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
              "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
              "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
              "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
              "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
              "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
              "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
              "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
              "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
              "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
              "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
              "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
              "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
              "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
              "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
              "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
              "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
              "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
              "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
              "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
              "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
              "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
              "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
              "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
              "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
              "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
              "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
              "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
              "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
              "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
              "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
              "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
              "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
              "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
              "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
              "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
              "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
              "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
              "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
              "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
              "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
              "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
              "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
              "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
              "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
              "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
              "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
              "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
              "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
              "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
              "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
              "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
              "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
              "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
              "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
              "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
              "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
              "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
              "{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
              @=""
              "{1530F7EE-5128-43BD-9977-84A4B0FAD7DF}"="PhotoToys"
              "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
              "{40950107-FEA6-4d53-A65F-B2DCBA57DD58}"="Nokia Phone Browser"
              "{FBFE7864-D495-41f0-B7DC-4BB601CC295E}"="Contact View"
              "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
              "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
              "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
              "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
              "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
              "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
              "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
              "{E752D257-9390-41A9-9F47-4105697315F6}"=""
              "{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
              "{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="P‚riph‚riques Plug and Play universels"
              "{6EE51AA0-77A0-11D7-B4E1-000347126E46}"="Window Washer Shredding Utility"
              "{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}"=""

              **********************************************************************************
              HKEY ROOT CLASSIDS:
              Windows Registry Editor Version 5.00

              [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\Implemented Categories]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{E752D257-9390-41A9-9F47-4105697315F6}\InprocServer32]
              @="C:\\WINDOWS\\system32\\vlpodbc.dll"
              "ThreadingModel"="Apartment"

              Windows Registry Editor Version 5.00

              [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\Implemented Categories]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{4AA803A9-8D80-4B21-B3C9-8EDA4DB32FC7}\InprocServer32]
              @="C:\\WINDOWS\\system32\\mynetobj.dll"
              "ThreadingModel"="Apartment"

              **********************************************************************************
              Files Found are not all bad files:
              **********************************************************************************
              Directory Listing of system files:
              Le volume dans le lecteur C n'a pas de nom.
              Le num‚ro de s‚rie du volume est 4D8B-C31B

              R‚pertoire de C:\WINDOWS\System32

              19/01/2006 15:17 235ÿ418 guard.tmp
              19/01/2006 12:36 235ÿ733 n66qlgj516o.dll
              17/01/2006 15:08 235ÿ418 g8jo0i13e8.dll
              17/01/2006 00:01 235ÿ418 eaent.dll
              16/01/2006 22:54 235ÿ733 aai3d1ag.dll
              11/01/2006 21:05 <REP> dllcache
              11/01/2006 11:05 234ÿ263 mynetobj.dll
              29/12/2005 17:03 235ÿ552 f42m0ef1eh2.dll
              12/12/2002 13:24 <REP> Microsoft
              7 fichier(s) 1ÿ647ÿ535 octets
              2 R‚p(s) 25ÿ029ÿ398ÿ528 octets libres
          • 1
          • 2