Problème rundll32

Bonjour,

Après avoir télécharger un petit logiciel, je me ss aperçu que ca devait ètre autre chose.
Je ne puis ouvrir aucun logiciel de mon bureau, ils ont tous été renommer en .lnk, alors que la cible reste bien l'application en .exe.
Tous les autres programme ne s'ouvrent pas
De plus, je ne peu plu rien ouvrir dans le panneau de configuration, car "windows ne peu ouvrir rundll32.exe."
Je suis allé regarder dans system32, rundll32 est bien présent.
J'ai fait un scan online (mon antivirus avast ne pouvant s'exécuter, sbybot également) grâce a trendMicro, il a détecter qq petit problèmes, les a réglé, mais rien ne change.
Je suis sur un ordinateur au travail, et vite besoin d'aide !

Merci d'avance,
Cordialement
Configuration: Windows XP
Firefox 3.0.11

51 réponses

Résumé de la discussion

Le problème central est l’impossibilité d’ouvrir des programmes sur Windows XP après le téléchargement d’un logiciel suspect, les exécutables ayant été renommés en .lnk et rundll32.exe bloqué. Plusieurs réponses proposent l’outil DAFT et OTL pour dépister les associations de fichiers et restaurer les liaisons, tandis que FindyKill et d’autres scans génèrent des rapports à partager. Des utilisateurs indiquent aussi que Malwarebytes peut être efficace mais peut échouer, et des solutions comme Zeb-Restore, ComboFix et redémarrage en mode sans échec ont été recommandées. En complément, des essais de nettoyage impliquent des rapports systèmes et des règles de démarrage pour revoir les éléments autorisés, et l’assistance conseille d’éviter d’exécuter des fichiers non vérifiés.

Bobot (l’IA à votre service)
  1. salut :

    *****************************************************
    ************** Option 1 (Recherche) **************
    *****************************************************

    Télécharge FindyKill (de Chiquitine29 et C_XX) sur ton bureau :

    ! Déconnecte toi et ferme toutes applications en cours !

    * Double clique sur "FindyKill.exe" pour lancer l'installation et laisse les paramètres d'instalation par défaut .

    * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

    * Double-clique sur le raccourci FindyKill qui est sur ton bureau pour lancer l'outil .

    * Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

    * Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

    Laisse travailler l'outil et ne touche à rien ...

    --> Poste le rapport qui apparait à la fin , sur le forum ...

    ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )
    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    1. Salut,

      Clique droit sur ce lien :
      http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe (par Chiquitine29)
      Choisis > Enregistrer la cible sous ... le Bureau !
      Double-clique sur le raccourci FindyKill sur ton bureau.
      Exécute-le ...

      Il faut lancer l'installation avec les paramètres par défaut.
      Laisse toi guider : Next > I agree > Next, etc ...

      Double-clique sur le 2 ème raccourci FindyKill sur ton bureau.
      Au menu principal, choisis l'option 1 (Recherche).

      Patiente le temps du scan ...

      Un rapport va s ouvrir ; poste-le dans ta prochaine réponse.
      NB : le rapport FindyKill.txt est aussi conservé à
      la racine du disque dur (C:\).
      1. Merci de ces réponses si rapide !
        J'ai bien telecharger Findykill, mais une foi qu'il se met sur le bureau, je ne peut l'ouvrir.
        "Windows ne peut ouvrir ce fichier Fichier : Findykill"
        Que faire ??
        1. Télécharge Zeb-Restore http://telechargement.zebulon.fr/zeb-restore.html enregistre ce fichier sur le bureau.

          -Clic droit Zeb-Restore.zip ==> Extraire tout choisis comme lieu d'enregistrement le bureau.
          -Ouvre le dossier ZR_1.0.0.37 ==> double clic sur Zeb-Restore.exe
          - Coche la case devant :extensions de fichiers
          - Ne coche aucune autre case
          -Clique sur Restaurer
          -Redémarre ton PC
          1. Je ne peu même lancer Zeb-restore.exe après l'avoir extrait
            Il me pose encore et tjrs la boite avec les options "utilier le service web pour trouver le programme approprier" ou " selectionner le programme dans la liste"
            Merci
            1. J'avai pu décompresser le fichier grace a Winzip, et voir les 2 fichier qu'il contenais. Le problème vien juste du fait que je ne peu lancer aucun programme :@
              Merci quand même ...
              1. Après plus de recherche sur le net, j'ai pu trouver une "solution" provisoire.
                Je peu executer un programme en créant un nouveau racourci, et en y affectant le programme selectionner.
                J'ai pu installer FindyKill, mais quand je le lance il ouvre cmd, et une boite s'ouvre informant que le processeur a rencontrer une instruction non autorisé.
                Juste un petit pas en avant ...
                1. Finalement réussi a lancer findyKill !
                  Le rapport :

                  ############################## | FindyKill V6.005 |

                  # User : ELODIE (Administrateurs) # D34L8Y0J
                  # Update on 11/07/09 by Chiquitine29 & C_XX
                  # Start at: 12:42:51 | 13/07/2009
                  # Website : http://pagesperso-orange.fr/NosTools/index.html

                  # Intel(R) Pentium(R) 4 CPU 2.66GHz
                  # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                  # Internet Explorer 8.0.6001.18702
                  # Windows Firewall Status : Enabled
                  # AV : avast! antivirus 4.8.1201 [VPS 080826-0] 4.8.1201 [ Enabled | (!) Outdated ]

                  # A:\ # Lecteur de disquettes 3 ½ pouces
                  # C:\ # Disque fixe local # 38,24 Go (18,75 Go free) # NTFS
                  # D:\ # Disque CD-ROM
                  # E:\ # Disque CD-ROM
                  # F:\ # Disque CD-ROM
                  # Q:\ # Disque CD-ROM
                  # S:\ # Connexion réseau # 33,9 Go (23,45 Go free) [data] # NTFS
                  # T:\ # Connexion réseau # 33,9 Go (23,45 Go free) [data] # NTFS
                  # X:\ # Connexion réseau # 33,9 Go (23,45 Go free) [data] # NTFS

                  ############################## | Processus actifs |

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\wanmpsvc.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\dla\tfswctrl.exe
                  C:\Program Files\Dell\Media Experience\PCMService.exe
                  C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Blue Label Soft\PDF to Excel 2.4\PTEXCON.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\TEMP\tempo-923109.tmp
                  C:\WINDOWS\TEMP\tempo-923218.tmp
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\WINDOWS\system32\taskmgr.exe
                  C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe

                  ################## | Registre Startup |

                  R1 - HKCU\..\Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  R1 - HKCU\..\Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  R1 - HKCU\..\Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
                  F2 - HKLM\..\logon:"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                  F2 - HKLM\..\logon:"DefaultUserName"="ELODIE"
                  F2 - HKLM\..\logon:"AltDefaultUserName"="ELODIE"
                  F2 - HKLM\..\logon:"LegalNoticeCaption"=""
                  F2 - HKLM\..\logon:"LegalNoticeText"=""
                  04 - HKLM\..\Run: IgfxTray=C:\WINDOWS\system32\igfxtray.exe
                  04 - HKLM\..\Run: HotKeysCmds=C:\WINDOWS\system32\hkcmd.exe
                  04 - HKLM\..\Run: dla=C:\WINDOWS\system32\dla\tfswctrl.exe
                  04 - HKLM\..\Run: StorageGuard="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                  04 - HKLM\..\Run: PCMService="C:\Program Files\Dell\Media Experience\PCMService.exe"
                  04 - HKLM\..\Run: Adobe Photo Downloader="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                  04 - HKLM\..\Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  04 - HKLM\..\Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  04 - HKLM\..\Run: SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  04 - HKLM\..\Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
                  04 - HKLM\..\Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                  04 - HKCU\..\Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
                  04 - HKCU\..\Run: Sonic RecordNow!=
                  04 - HKCU\..\Run: C:\Program Files\FeedReader30\feedreader.exe=C:\Program Files\FeedReader30\feedreader.exe
                  04 - HKCU\..\Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  04 - HKCU\..\Run: SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

                  ################## | Fichiers # Dossiers infectieux |

                  Présent ! C:\WINDOWS\Prefetch\.EXE-1A216BCF.pf

                  ################## | C:\Documents and Settings\ELODIE\Temporary Internet Files |

                  ################## | All Drives ... |

                  ################## | Registre # Clés Run infectieuses |

                  Présent ! HKLM\software\microsoft\security center "AntiVirusDisableNotify" ( 0x1 )
                  Présent ! HKLM\software\microsoft\security center "FirewallDisableNotify" ( 0x1 )

                  ################## | Registre # Mountpoints2 |

                  ################## | Etat / Services / Informations |

                  # Affichage des fichiers cachés : OK
                  # Mode sans echec : OK
                  # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                  # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
                  # Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
                  # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                  # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                  # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                  ################## | Cracks / Keygens / Serials |

                  ################## | ! Fin du rapport # FindyKill V6.005 ! |

                  Merci !
                  1. ok tu peux faire l'option nettoyage :

                    *****************************************************
                    ************* Option 2 (Suppression) *************
                    *****************************************************

                    ! Déconnecte toi et ferme toutes application en cours ( navigateur compris ) .

                    * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

                    * Relance "FindyKill" : au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                    * Au second menu choisis l'option 2 (suppression) et tape sur [entrée]

                    * Le pc va redémarrer automatiquement ...

                    --> le programme va travailler , ne touche à rien ... , ton bureau ne sera pas accessible c est normal !

                    * Poste le rapport qui apparait à la fin ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )

                    /!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide

                    1. Aie, en redémarrant, le pc ne peu réouvrir FindyKill, et repose la question quand a savoir comment l'ouvrir.
                      Puis en re sélectionnant FindyKill, il le refait partir au début.
                      Il ne peut donc supprimer ce qu'il y à a supprimer!
                      Que faire ????

                      Merci d'avance
                      1. on va essayer autrement :

                        Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                        ! Déconnecte toi et ferme toutes tes applications en cours !

                        Double-clique sur " RSIT.exe " pour le lancer .

                        -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                        * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                        * clique ensuite sur " Continue " pour lancer l'analyse ...

                        -> laisse faire le scan et ne touche pas au PC ...

                        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                        Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                        Important : poste un rapport, puis l'autre dans la réponse suivante
                        Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                        ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                        1. Merci!

                          log.txt :

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by ELODIE at 2009-07-13 14:13:00
                          Microsoft Windows XP Édition familiale Service Pack 3
                          System drive C: has 19 GB (49%) free of 39 GB
                          Total RAM: 510 MB (40% free)

                          ======Scheduled tasks folder======

                          C:\WINDOWS\tasks\AppleSoftwareUpdate.job
                          C:\WINDOWS\tasks\Norton Security Scan.job
                          C:\WINDOWS\tasks\Rappel d'abonnement 1 auprès de l'ISP.job
                          C:\WINDOWS\tasks\Symantec NetDetect.job
                          C:\WINDOWS\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

                          ======Registry dump======

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
                          Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-06-07 399352]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                          Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
                          Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
                          DriveLetterAccess - C:\WINDOWS\system32\dla\tfswshx.dll [2003-08-06 106548]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                          SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                          Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                          Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-06-22 259696]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                          Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [2009-06-25 669168]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
                          Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-06-22 470512]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                          {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-06-07 399352]
                          {0BF43445-2F28-4351-9252-17FE6E806AA0}
                          {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-06-22 259696]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                          "IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2005-10-19 155648]
                          "HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-10-19 126976]
                          "dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2003-08-06 114741]
                          "StorageGuard"=C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe [2003-02-13 155648]
                          "PCMService"=C:\Program Files\Dell\Media Experience\PCMService.exe [2003-08-26 204800]
                          "Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe [2005-06-23 57344]
                          "TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2006-07-19 180269]
                          "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-05-16 79224]
                          "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
                          "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-02-01 385024]

                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
                          "Sonic RecordNow!"= []
                          "C:\Program Files\FeedReader30\feedreader.exe"=C:\Program Files\FeedReader30\feedreader.exe []
                          "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-16 68856]
                          "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
                          C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized []

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                          C:\Program Files\iTunes\iTunesHelper.exe [2008-02-19 267048]

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-16 68856]

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AOL 8.0 Icône AOL.lnk]
                          C:\PROGRA~1\AOL8~1.0\aoltray.exe [2003-05-14 36937]

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AOL Compagnon.lnk]
                          C:\PROGRA~1\AOLCOM~1\COMPAN~1.EXE [2003-05-14 221258]

                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                          Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
                          C:\WINDOWS\system32\igfxsrvc.dll [2005-10-19 348160]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                          C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                          "dontdisplaylastusername"=0
                          "legalnoticecaption"=
                          "legalnoticetext"=
                          "shutdownwithoutlogon"=1
                          "undockwithoutlogon"=1

                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          "NoDriveTypeAutoRun"=145

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          "HonorAutoRunSetting"=

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                          "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                          "C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
                          "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
                          "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
                          "C:\Program Files\DAP\DAP.exe"="C:\Program Files\DAP\DAP.exe:*:Enabled:Download Accelerator Plus (DAP)"
                          "C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
                          "C:\WINDOWS\SYSTEM32\ftp.exe"="C:\WINDOWS\SYSTEM32\ftp.exe:*:Enabled:Logiciel de transfert de fichiers"
                          "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                          "C:\Program Files\Muzzy Lane Software\Making_History_2_0\bin\makehist.exe"="C:\Program Files\Muzzy Lane Software\Making_History_2_0\bin\makehist.exe:*:Disabled:Making History Client Application"
                          "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                          "C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
                          "C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
                          "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
                          "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
                          "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                          "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                          "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                          "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                          "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
                          "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                          ======File associations======

                          .exe - open -
                          .bat - open -
                          .bat - edit -
                          .cmd - open -
                          .cmd - edit -
                          .inf - open -
                          .inf - install -
                          .ini - open -
                          .js - edit -
                          .js - open -
                          .com - open -
                          .scr - config - "%1" /S
                          .cpl - cplopen -

                          ======List of files/folders created in the last 2 months======

                          2009-07-13 14:13:01 ----D---- C:\Program Files\trend micro
                          2009-07-13 14:13:00 ----D---- C:\rsit
                          2009-07-13 12:29:30 ----D---- C:\FindyKill
                          2009-07-09 14:50:05 ----D---- C:\Program Files\Spybot - Search & Destroy
                          2009-07-09 14:50:05 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                          2009-07-09 10:59:06 ----A---- C:\WINDOWS\iltwain.ini
                          2009-07-09 10:58:39 ----D---- C:\Program Files\Blue Label Soft
                          2009-07-09 10:35:04 ----D---- C:\Program Files\Navilog1
                          2009-07-09 09:20:06 ----D---- C:\WINDOWS\pss
                          2009-07-08 11:16:59 ----D---- C:\Program Files\All Office Converter Platinum
                          2009-07-08 10:39:19 ----D---- C:\Output Files
                          2009-07-08 10:37:30 ----D---- C:\Documents and Settings\ELODIE\Application Data\Thinstall
                          2009-07-03 17:00:57 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
                          2009-07-03 17:00:43 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
                          2009-07-01 09:57:57 ----D---- C:\WINDOWS\Prefetch
                          2009-07-01 09:54:08 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
                          2009-07-01 09:53:50 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
                          2009-07-01 09:53:39 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
                          2009-07-01 09:53:26 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
                          2009-07-01 09:53:16 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
                          2009-07-01 09:53:05 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
                          2009-07-01 09:52:55 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
                          2009-07-01 09:52:43 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
                          2009-07-01 09:52:31 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
                          2009-07-01 09:52:21 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
                          2009-07-01 09:52:09 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
                          2009-07-01 09:51:59 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
                          2009-07-01 09:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
                          2009-07-01 09:51:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
                          2009-07-01 09:51:24 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
                          2009-07-01 09:51:08 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
                          2009-07-01 09:50:51 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
                          2009-07-01 09:50:39 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
                          2009-07-01 09:50:22 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
                          2009-07-01 09:50:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
                          2009-07-01 09:49:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
                          2009-07-01 09:49:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
                          2009-07-01 09:49:36 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
                          2009-07-01 09:49:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
                          2009-07-01 09:49:16 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
                          2009-07-01 09:49:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
                          2009-07-01 09:48:53 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
                          2009-07-01 09:48:45 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
                          2009-07-01 09:48:32 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
                          2009-07-01 09:48:21 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
                          2009-07-01 09:48:10 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
                          2009-07-01 09:41:48 ----D---- C:\WINDOWS\system32\fr
                          2009-07-01 09:41:48 ----D---- C:\WINDOWS\l2schemas
                          2009-06-26 16:53:26 ----D---- C:\WINDOWS\ie8updates
                          2009-06-26 16:49:37 ----HDC---- C:\WINDOWS\ie8
                          2009-06-23 17:08:22 ----HDC---- C:\WINDOWS\$NtUninstallKB961503_0$
                          2009-06-23 09:02:30 ----A---- C:\WINDOWS\system32\muweb.dll
                          2009-06-23 09:02:29 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
                          2009-06-23 09:02:29 ----A---- C:\WINDOWS\system32\mucltui.dll
                          2009-06-22 16:25:27 ----D---- C:\Program Files\Microsoft
                          2009-06-22 16:25:07 ----D---- C:\Program Files\Windows Live SkyDrive
                          2009-06-22 16:24:36 ----D---- C:\Program Files\Windows Live
                          2009-06-22 16:18:03 ----D---- C:\Program Files\Fichiers communs\Windows Live
                          2009-06-16 17:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
                          2009-06-16 17:08:55 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
                          2009-06-16 17:08:44 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
                          2009-06-16 17:07:55 ----HDC---- C:\WINDOWS\$NtUninstallKB968537_0$

                          ======List of files/folders modified in the last 2 months======

                          2009-07-13 14:13:01 ----D---- C:\Program Files
                          2009-07-13 13:55:46 ----D---- C:\Program Files\Mozilla Firefox
                          2009-07-13 13:55:03 ----D---- C:\WINDOWS\Temp
                          2009-07-13 13:53:09 ----A---- C:\WINDOWS\SchedLgU.Txt
                          2009-07-13 13:49:31 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
                          2009-07-13 11:53:00 ----D---- C:\WINDOWS\system32\DRIVERS
                          2009-07-13 09:14:58 ----D---- C:\WINDOWS\system32\CatRoot2
                          2009-07-13 09:14:51 ----SD---- C:\WINDOWS\Tasks
                          2009-07-13 09:14:49 ----D---- C:\WINDOWS\SYSTEM32
                          2009-07-09 15:33:37 ----A---- C:\WINDOWS\wininit.ini
                          2009-07-09 15:33:15 ----D---- C:\WINDOWS
                          2009-07-09 15:33:11 ----D---- C:\Program Files\VVSN
                          2009-07-09 12:45:56 ----D---- C:\Program Files\DivX
                          2009-07-09 10:12:50 ----SD---- C:\WINDOWS\Downloaded Program Files
                          2009-07-09 09:21:09 ----RASH---- C:\BOOT.INI
                          2009-07-09 09:21:09 ----A---- C:\WINDOWS\WIN.INI
                          2009-07-09 09:21:08 ----N---- C:\WINDOWS\SYSTEM.INI
                          2009-07-08 16:42:48 ----SHD---- C:\WINDOWS\Installer
                          2009-07-08 16:42:48 ----SHD---- C:\Config.Msi
                          2009-07-03 17:01:02 ----HD---- C:\WINDOWS\INF
                          2009-07-03 17:01:00 ----RSHD---- C:\WINDOWS\system32\DLLCACHE
                          2009-07-03 17:00:52 ----A---- C:\WINDOWS\imsins.BAK
                          2009-07-03 16:59:27 ----D---- C:\WINDOWS\system32\CatRoot
                          2009-07-03 09:12:52 ----HD---- C:\WINDOWS\$hf_mig$
                          2009-07-01 10:01:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
                          2009-07-01 10:00:11 ----A---- C:\WINDOWS\OEWABLog.txt
                          2009-07-01 09:58:06 ----A---- C:\WINDOWS\SETUPLOG.TXT
                          2009-07-01 09:57:09 ----D---- C:\WINDOWS\system32\Setup
                          2009-07-01 09:57:09 ----D---- C:\WINDOWS\AppPatch
                          2009-07-01 09:57:09 ----D---- C:\Program Files\Windows Media Player
                          2009-07-01 09:57:08 ----D---- C:\WINDOWS\system32\WBEM
                          2009-07-01 09:57:07 ----RSD---- C:\WINDOWS\Fonts
                          2009-07-01 09:53:37 ----D---- C:\WINDOWS\SECURITY
                          2009-07-01 09:48:35 ----D---- C:\Program Files\Messenger
                          2009-07-01 09:48:23 ----D---- C:\WINDOWS\WinSxS
                          2009-07-01 09:42:32 ----D---- C:\WINDOWS\ServicePackFiles
                          2009-07-01 09:42:29 ----D---- C:\WINDOWS\Help
                          2009-07-01 09:42:13 ----D---- C:\WINDOWS\network diagnostic
                          2009-07-01 09:42:13 ----D---- C:\WINDOWS\IME
                          2009-07-01 09:41:52 ----D---- C:\WINDOWS\system32\USMT
                          2009-07-01 09:41:52 ----D---- C:\WINDOWS\system32\fr-fr
                          2009-07-01 09:41:47 ----D---- C:\WINDOWS\system32\bits
                          2009-07-01 09:41:47 ----D---- C:\WINDOWS\peernet
                          2009-07-01 09:41:46 ----D---- C:\Program Files\Movie Maker
                          2009-07-01 09:37:38 ----D---- C:\WINDOWS\system32\Restore
                          2009-07-01 09:37:38 ----D---- C:\WINDOWS\system32\NPP
                          2009-07-01 09:37:36 ----D---- C:\WINDOWS\MSAGENT
                          2009-07-01 09:37:34 ----D---- C:\WINDOWS\SRCHASST
                          2009-07-01 09:37:31 ----D---- C:\Program Files\NetMeeting
                          2009-07-01 09:37:30 ----D---- C:\WINDOWS\system32\Com
                          2009-07-01 09:37:27 ----D---- C:\Program Files\Windows NT
                          2009-07-01 09:37:26 ----D---- C:\Program Files\Outlook Express
                          2009-07-01 09:37:23 ----D---- C:\Program Files\Fichiers communs\System
                          2009-07-01 09:36:55 ----D---- C:\WINDOWS\system32\OOBE
                          2009-07-01 09:36:52 ----D---- C:\WINDOWS\SYSTEM
                          2009-07-01 09:32:20 ----D---- C:\WINDOWS\system32\ReinstallBackups
                          2009-07-01 09:31:49 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
                          2009-07-01 09:23:25 ----D---- C:\WINDOWS\EHome
                          2009-06-29 09:01:30 ----D---- C:\WINDOWS\Media
                          2009-06-29 09:01:30 ----D---- C:\Program Files\Internet Explorer
                          2009-06-24 14:39:23 ----D---- C:\Program Files\DAP
                          2009-06-23 17:04:22 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
                          2009-06-23 09:21:19 ----D---- C:\Documents and Settings\ELODIE\Application Data\Mozilla
                          2009-06-22 16:18:03 ----D---- C:\Program Files\Fichiers communs
                          2009-06-22 16:16:59 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
                          2009-06-22 10:11:01 ----D---- C:\Program Files\Google
                          2009-06-22 09:33:59 ----D---- C:\Documents and Settings\All Users\Application Data\Google
                          2009-06-16 17:08:15 ----D---- C:\WINDOWS\ie7updates
                          2009-06-16 16:21:01 ----D---- C:\Mes Documents
                          2009-06-01 09:51:14 ----A---- C:\WINDOWS\system32\MRT.exe

                          ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                          R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-05-16 26944]
                          R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 78416]
                          R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-05-16 42912]
                          R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40576]
                          R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
                          R1 omci;OMCI WDM Device Driver; C:\WINDOWS\System32\DRIVERS\omci.sys [2002-11-08 17217]
                          R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2003-07-14 5621]
                          R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2003-07-14 23219]
                          R2 acedrv10;acedrv10; \??\C:\WINDOWS\system32\drivers\acedrv10.sys []
                          R2 acehlp10;acehlp10; \??\C:\WINDOWS\system32\drivers\acehlp10.sys []
                          R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 20560]
                          R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-05-16 94416]
                          R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2003-06-20 40448]
                          R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
                          R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
                          R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2003-08-06 25685]
                          R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2003-08-06 34837]
                          R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2003-08-06 4117]
                          R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2003-08-06 2265]
                          R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2003-08-06 83284]
                          R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2003-08-06 14229]
                          R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2003-08-06 6357]
                          R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2003-08-06 98068]
                          R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2003-08-06 100373]
                          R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
                          R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-05-16 23152]
                          R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys [2003-07-15 43136]
                          R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
                          R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
                          R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2005-10-19 807998]
                          R3 mouhid;Pilote HID de souris; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-23 12288]
                          R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-02-28 545024]
                          R3 usbehci;Pilote miniport de contrôleur hôte amélioré USB 2.0 Microsoft; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
                          R3 usbhub;Concentrateur USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
                          R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
                          R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\System32\DRIVERS\wanatw4.sys [2003-05-14 33588]
                          S1 P3;Pilote processeur Intel Pentium III; C:\WINDOWS\System32\DRIVERS\p3.sys [2008-04-14 46848]
                          S3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2003-04-15 113504]
                          S3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2003-04-15 78752]
                          S3 akc6xdnw;akc6xdnw; C:\WINDOWS\system32\drivers\akc6xdnw.sys []
                          S3 catchme;catchme; \??\C:\DOCUME~1\ELODIE\LOCALS~1\Temp\catchme.sys []
                          S3 EL90XBC;Pilote de la carte EtherLink XL 90XB/C 3Com; C:\WINDOWS\System32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
                          S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys []
                          S3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
                          S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2007-10-31 30464]
                          S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
                          S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
                          S4 agp440;Filtre de bus AGP Intel; C:\WINDOWS\System32\DRIVERS\agp440.sys [2008-04-13 42368]
                          S4 agpCPQ;Filtre de bus AGP Compaq; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
                          S4 alim1541;Filtre de bus AGP ALI; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2008-04-13 42752]
                          S4 amdagp;Pilote de filtre du bus AMD AGP; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2008-04-13 43008]
                          S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
                          S4 IntelIde;IntelIde; C:\WINDOWS\System32\DRIVERS\intelide.sys [2008-04-14 5504]
                          S4 sisagp;Filtre de bus AGP SIS; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2008-04-13 40960]
                          S4 viaagp;Filtre de bus AGP VIA; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2008-04-13 42240]

                          ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                          R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-09-06 110592]
                          R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-05-16 17272]
                          R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-05-16 144760]
                          R2 WANMiniportService;WAN Miniport (ATW) Service; C:\WINDOWS\wanmpsvc.exe [2003-05-14 65536]
                          R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-05-16 247160]
                          R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-05-16 349560]
                          S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-22 182768]
                          S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
                          S3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-02-19 504104]
                          S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

                          -----------------EOF-----------------
                          1. et info.txt:

                            info.txt logfile of random's system information tool 1.06 2009-07-13 14:13:28

                            ======Uninstall list======

                            FindyKill-->C:\FindyKill\Uninstal.exe

                            ======Security center information======

                            AV: avast! antivirus 4.8.1201 [VPS 080826-0] (outdated)

                            ======System event log======

                            Computer Name: D34L8Y0J
                            Event Code: 7036
                            Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

                            Record Number: 29828
                            Source Name: Service Control Manager
                            Time Written: 20080305143658.000000+060
                            Event Type: Informations
                            User:

                            Computer Name: D34L8Y0J
                            Event Code: 7035
                            Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.

                            Record Number: 29827
                            Source Name: Service Control Manager
                            Time Written: 20080305143658.000000+060
                            Event Type: Informations
                            User: AUTORITE NT\SYSTEM

                            Computer Name: D34L8Y0J
                            Event Code: 7036
                            Message: Le service Service de découvertes SSDP est entré dans l'état : en cours d'exécution.

                            Record Number: 29826
                            Source Name: Service Control Manager
                            Time Written: 20080305143654.000000+060
                            Event Type: Informations
                            User:

                            Computer Name: D34L8Y0J
                            Event Code: 7035
                            Message: Un contrôle Démarrer a correctement été envoyé au service Service de découvertes SSDP.

                            Record Number: 29825
                            Source Name: Service Control Manager
                            Time Written: 20080305143654.000000+060
                            Event Type: Informations
                            User: AUTORITE NT\SYSTEM

                            Computer Name: D34L8Y0J
                            Event Code: 7036
                            Message: Le service Compatibilité avec le Changement rapide d'utilisateur est entré dans l'état : en cours d'exécution.

                            Record Number: 29824
                            Source Name: Service Control Manager
                            Time Written: 20080305143642.000000+060
                            Event Type: Informations
                            User:

                            =====Application event log=====

                            Computer Name: D34L8Y0J
                            Event Code: 0
                            Message:
                            Record Number: 5
                            Source Name: mcmispupdmgr
                            Time Written: 20070908121919.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: D34L8Y0J
                            Event Code: 1800
                            Message: Le service Centre de sécurité Windows a démarré.

                            Record Number: 4
                            Source Name: SecurityCenter
                            Time Written: 20070908121845.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: D34L8Y0J
                            Event Code: 5000
                            Message:
                            Record Number: 3
                            Source Name: McLogEvent
                            Time Written: 20070908121845.000000+120
                            Event Type: Informations
                            User: AUTORITE NT\SYSTEM

                            Computer Name: D34L8Y0J
                            Event Code: 1
                            Message:
                            Record Number: 2
                            Source Name: Bonjour Service
                            Time Written: 20070908121833.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: D34L8Y0J
                            Event Code: 0
                            Message:
                            Record Number: 1
                            Source Name: McAfee HackerWatch Service
                            Time Written: 20070908121833.000000+120
                            Event Type: Informations
                            User:

                            ======Environment variables======

                            "ComSpec"=%SystemRoot%\system32\cmd.exe
                            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
                            "windir"=%SystemRoot%
                            "OS"=Windows_NT
                            "PROCESSOR_ARCHITECTURE"=x86
                            "PROCESSOR_LEVEL"=15
                            "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
                            "PROCESSOR_REVISION"=0209
                            "NUMBER_OF_PROCESSORS"=1
                            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                            "TEMP"=%SystemRoot%\TEMP
                            "TMP"=%SystemRoot%\TEMP
                            "FP_NO_HOST_CHECK"=NO
                            "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
                            "QTJAVA"=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip

                            -----------------EOF-----------------
                            1. ---> Désactive ton antivirus le temps de la manipulation car OTM est détecté comme une infection à tort.

                              ---> Télécharge OTM (OldTimer) sur ton Bureau :

                              ---> Double-clique sur OTM.exe afin de le lancer.

                              ---> Copie (Ctrl+C) le texte suivant ci-dessous :



                              :processes
                              explorer.exe
                              TeaTimer.exe
                              msnmsgr.exe
                              iexplore.exe
                              firefox.exe

                              :services
                              akc6xdnw
                              catchme

                              :files
                              C:\WINDOWS\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
                              C:\WINDOWS\iltwain.ini
                              C:\Documents and Settings\ELODIE\Application Data\Thinstall
                              C:\Program Files\VVSN

                              :reg
                              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                              "TkBellExe"=-
                              "QuickTime Task"=-
                              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                              "Sonic RecordNow!"=-
                              "C:\Program Files\FeedReader30\feedreader.exe"=-
                              "swg"=-
                              [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]

                              :commands
                              [purity]
                              [emptytemp]
                              [start explorer]
                              [reboot]



                              ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                              ---> Clique maintenant sur le bouton MoveIt! puis ferme OTM

                              Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                              Accepte en cliquant sur YES.

                              ---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
                              Le nom du rapport correspond au moment de sa création : date_heure.log
                              1. manip' fini, mais je ne sais pas si tout a bien été effectuer, vu que le redémarage stop toute activité...

                                Rapport :

                                All processes killed
                                ========== PROCESSES ==========
                                No active process named explorer.exe was found!
                                No active process named TeaTimer.exe was found!
                                No active process named msnmsgr.exe was found!
                                No active process named iexplore.exe was found!
                                Process firefox.exe killed successfully!
                                ========== SERVICES/DRIVERS ==========
                                Service\Driver akc6xdnw not found.
                                Service\Driver key akc6xdnw deleted successfully.
                                Service\Driver akc6xdnw not found.
                                Service\Driver catchme deleted successfully.
                                ========== FILES ==========
                                C:\WINDOWS\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job moved successfully.
                                C:\WINDOWS\iltwain.ini moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%SystemSystem%\TempDir moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%SystemSystem%\spool\drivers\w32x86\3 moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%SystemSystem%\spool\drivers\w32x86 moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%SystemSystem%\spool\drivers moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%SystemSystem%\spool moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%SystemSystem% moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%ProgramFilesDir%\Microsoft Office\OFFICE11\STARTUP moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%ProgramFilesDir%\Microsoft Office\OFFICE11 moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%ProgramFilesDir%\Microsoft Office moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%ProgramFilesDir%\All Office Converter Platinum moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0\%ProgramFilesDir% moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall\All Office Converter Platinum 6.0 moved successfully.
                                C:\Documents and Settings\ELODIE\Application Data\Thinstall moved successfully.
                                C:\Program Files\VVSN moved successfully.
                                ========== REGISTRY ==========
                                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
                                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
                                Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe deleted successfully.
                                Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
                                Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Sonic RecordNow! deleted successfully.
                                Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\C:\Program Files\FeedReader30\feedreader.exe deleted successfully.
                                Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.
                                Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent\ deleted successfully.
                                ========== COMMANDS ==========

                                [EMPTYTEMP]

                                User: All Users

                                User: anne
                                ->Temp folder emptied: 87320068 bytes
                                ->Temporary Internet Files folder emptied: 89144042 bytes
                                ->Java cache emptied: 259161 bytes

                                User: Default User
                                ->Temp folder emptied: 0 bytes
                                ->Temporary Internet Files folder emptied: 32768 bytes

                                User: ELODIE
                                ->Temp folder emptied: 314620147 bytes
                                ->Temporary Internet Files folder emptied: 164400906 bytes
                                ->Java cache emptied: 35734170 bytes
                                ->FireFox cache emptied: 83264425 bytes
                                ->Apple Safari cache emptied: 4191618 bytes

                                User: haidar

                                User: LocalService
                                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
                                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                                ->Temp folder emptied: 99119 bytes
                                ->Temporary Internet Files folder emptied: 4730442 bytes

                                User: NetworkService
                                ->Temp folder emptied: 0 bytes
                                ->Temporary Internet Files folder emptied: 33170 bytes

                                %systemdrive% .tmp files removed: 0 bytes
                                %systemroot% .tmp files removed: 39097 bytes
                                %systemroot%\System32 .tmp files removed: 3072 bytes
                                File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                                File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5c4.dat scheduled to be deleted on reboot.
                                Windows Temp folder emptied: 196764 bytes
                                RecycleBin emptied: 124257 bytes

                                Total Files Cleaned = 747,86 mb

                                OTM by OldTimer - Version 3.0.0.5 log created on 07132009_145316

                                Files moved on Reboot...
                                File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                                File move failed. C:\WINDOWS\temp\Perflib_Perfdata_5c4.dat scheduled to be moved on reboot.

                                Registry entries deleted on Reboot...

                                Cordialement,
                                1. ♦ Télécharge DAFT !

                                  ♦ Sauvegarde-le sur ton Bureau.
                                  ♦ Dézippe le dossier le contenant (clic droit , extraire ici)
                                  ♦ Double-clique sur l'icône de DAFT se trouvant dans son dossier dézippé, présent sur ton bureau.
                                  ♦ Clique sur le bouton Scan.
                                  ♦ Sélectionne tout ce qui apparaît.
                                  ♦ Clique sur le bouton Fix.
                                  ♦ Ensuite relance DAFT. Si tout est OK, un message du type "All associations are OK" devrait apparaître.
                                  ♦ Ferme DAFT.

                                  ensuite :


                                  Télécharge OTL de OLDTimer

                                  et enregistre le sur ton Bureau.

                                  Double clic sur OTL.exe pour le lancer.

                                  Coche les 2 cases Lop et Purity

                                  Coche la case devant scan all users

                                  Clic sur Run Scan.

                                  A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

                                  Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

                                  NE LE POSTE PAS SUR LE FORUM

                                  Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                                  Clique sur Parcourir et cherche le fichier ci-dessus.

                                  Clique sur Ouvrir.

                                  Clique sur "Cliquez ici pour déposer le fichier".

                                  Un lien de cette forme :

                                  http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                                  est ajouté dans la page.

                                  Copie ce lien dans ta réponse.

                                  Tu feras la meme chose avec le "Extra.txt" s'il t'est demandé
                                  • 1
                                  • 2
                                  • 3