[Resolu] Windows XP ne boote plus - infection rootkit possible

Je me suis douté vu l'heure ;)

Bon, j'ai quelques heures en moins par rapport a ce qui est affiche, mais ca faisait tard quand meme pour moi :D.



Bon essai de démarrer le pc en mode normal


Pour info sur le demarrage: il semble pour l'instant comme auparavant: il m'a mis l'ecran bleu "verification du systeme de fichiers sur C:......."... puis de nouveau le message d'erreur "services.exe......"....

Refait moi un nouveau rapport stp


  • Retourner dans la fenêtre de OTLPE
    faire un clic droit dans la fenêtre située en bas nommée "Custom Scans/Fixes"
  • et choisir Coller
    Le contenu du fichier OTLPE-1.txt est ainsi inséré dans le panneau "Custom Scans/Fixes".
  • Puis cliquer sur le bouton Run Scan.
  • Laisser l'outil travailler sans l'interrompre.
  • Lorsque l'outil a terminé
    il y a ouverture d'une fenêtre du Bloc-notes contenant un rapport (log).
    Post le moi stp








%ALLUSERSPROFILE%\Application Data\*.

%ALLUSERSPROFILE%\Application Data\*.exe /s


%APPDATA%\*.exe /s



























































%systemroot%\*. /mp /s

%systemroot%\system32\*.dll /lockedfiles

%systemroot%\Tasks\*.job /lockedfiles

%systemroot%\system32\drivers\*.sys /lockedfiles

%systemroot%\system32\drivers\*.sys /90



HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


Dir /a:d C:\ /c

Type c:\Boot.ini /c





C'est exatement la même manip que la premier fois :D

Tu copie et colle les lignes dans Custom Scans et tu clique sur le bouton Run Scan. :super:


Si le rapport est trop long post le via

Dans l'encadré en bas copier/coller le contenu du rapport puis cliquez sur le bouton Envoyer

Post moi le lien stp


Par contre tu as toujours le CD bootable avec la console de récupération XP ?



OK, Merci. Je te poste le rapport...


Le fichier Extrat est ci dessous

et le fichier OTL est ici: - TXT_TITLE



Par contre tu as toujours le CD bootable avec la console de récupération XP ?







OTL Extras logfile created on: 5/1/2011 5:47:16 PM - Run

OTLPE by OldTimer - Version Folder = X:\Programs\OTLPE

Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) - Type = SYSTEM

Internet Explorer (Version = 8.0.6001.18702)

Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy


510.00 Mb Total Physical Memory | 254.00 Mb Available Physical Memory | 50.00% Memory free

458.00 Mb Paging File | 275.00 Mb Available in Paging File | 60.00% Paging File free

Paging file location(s): C:\pagefile.sys 768 1536 [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 93.16 Gb Total Space | 39.21 Gb Free Space | 42.09% Space Free | Partition Type: NTFS

Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS


Computer Name: REATOGO | User Name: SYSTEM

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

Using ControlSet: ControlSet001


========== Extra Registry (SafeList) ==========



========== File Associations ==========



.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*


========== Shell Spawning ==========



batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Parcourir avec XnView] -- "C:\Documents and Settings\Nicolas\Mes documents\Téléchargements\XnView-win\XnView\xnview.exe" "%1"

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)


========== Security Center Settings ==========


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0





[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]


========== System Restore Settings ==========


[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

"DisableConfig" = 0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0



"Start" = 0



"Start" = 2


========== Firewall Settings ==========



"EnableFirewall" = 0

"DoNotAllowExceptions" = 0

"DisableNotifications" = 1



"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 1



"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008


========== Authorized Applications List ==========



"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)



"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger

"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager -- (Skype Technologies)

"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe -- (Microsoft Corporation)

"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe -- (Microsoft Corporation)

"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe -- (Microsoft Corporation)

"C:\Program Files\Microsoft LifeCam\LifeTray.exe" = C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe -- (Microsoft Corporation)

"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)



========== HKEY_LOCAL_MACHINE Uninstall List ==========



"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player

"{05832D65-6EDB-4D32-BA78-BCD0E2B91C02}" = Atheros Wireless LAN MiniPCI card Driver

"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel

"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA

"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver

"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = Assist TOSHIBA

"{188BA1CC-F3A1-49B0-A34D-8C861C64E1AE}" = Manuels TOSHIBA

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java 6 Update 24

"{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0

"{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3A57482F-BEBC-47E4-ADA1-6302403C7E50}" = TOSHIBA Accessibility

"{48CF9A66-5F03-4025-ABD0-B3A3FA095A59}" = Formatage de carte mémoire SD TOSHIBA

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password

"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup

"{59FDFDFB-52FE-45B1-8A2A-A00079B07FF0}" = TOSHIBA Power Saver Driver

"{5BCA8D15-BCB6-421E-9654-238B43456A4F}" = TOSHIBA Controls Driver

"{5D96E2B1-D9AC-46E0-9073-425C5F63E338}" = Touch and Launch

"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam

"{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = Utilitaire de zoom TOSHIBA

"{7900D3A6-A9E8-4954-ACCB-AB15867978BF}" = TOSHIBA Hotkey Utility

"{80977342-27E8-4FF7-8B6A-D8D89461DA7F}" = TouchPad On/Off Utility

"{86AA1376-1970-41A6-A154-430A4A190BF4}" = TIxx21/x515

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile

"{8B12BA86-ADAC-4BA6-B441-FFC591087252}" = Son virtuel TOSHIBA

"{9011040C-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003

"{9017040C-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003

"{90A4040C-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components

"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA

"{91A1040C-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003

"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver

"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9A394342-4A68-4EBA-85A6-55B559F4E700}" = Microsoft .NET Framework 1.1 French Language Pack

"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = Pilote du DVD-RAM

"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver

"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = Réducteur de bruit lect. CD/DVD

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = Commandes TOSHIBA

"{AC76BA86-7AD7-1036-7646-A70000000000}" = Adobe Reader 7.0 - Français

"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation

"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{C45F4811-31D5-4786-801D-F79CD06EDD85}" = SD Secure Module

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars

"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype 5.1

"{F196AC50-7C95-42E1-9947-BDAB18BF3C8C}" = Microsoft .NET Framework 2.0 Language Pack - FRA

"{F1B8DB67-D30E-4FF9-A85F-3CEE51825AA2}" = SMSC IrCC V5.1.3600.5 SP2

"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio

"{FCE19796-1ADF-42DF-81D8-3563867FC2C2}" = TOSHIBA Zooming Hook

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"ATI Display Driver" = ATI Display Driver

"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus

"CAL" = Canon Camera Access Library

"CameraWindowDC" = Canon Utilities CameraWindow DC

"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX

"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX

"CameraWindowLauncher" = Canon Utilities CameraWindow

"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder

"Canon MOV Decoder" = Canon MOV Decoder

"Canon MOV Encoder" = Canon MOV Encoder

"CCleaner" = CCleaner

"Celtx (2.0.1)" = Celtx (2.0.1)

"ChangeWallpaper_is1" = ChangeWallpaper 1.3

"CSCLIB" = Canon Camera Support Core Library

"ie8" = Windows Internet Explorer 8

"ImageJ_is1" = ImageJ 1.42q

"InstallShield_{3A57482F-BEBC-47E4-ADA1-6302403C7E50}" = TOSHIBA Accessibility

"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Mot de passe responsable

"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup

"InstallShield_{7900D3A6-A9E8-4954-ACCB-AB15867978BF}" = Utilitaire Hotkey TOSHIBA

"InstallShield_{80977342-27E8-4FF7-8B6A-D8D89461DA7F}" = Utilitaire TouchPad ON/OFF

"InstallShield_{86AA1376-1970-41A6-A154-430A4A190BF4}" = Texas Instruments PCIxx21/x515 drivers.

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 2.0 Language Pack - FRA" = Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"MiKTeX 2.8" = MiKTeX 2.8

"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX

"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)

"Mozilla Thunderbird (3.1.8)" = Mozilla Thunderbird (3.1.8)

"MyCamera" = Canon Utilities MyCamera

"MyCameraDC" = Canon Utilities MyCamera DC

"Outil de diagnostic PC" = Outil de diagnostic PC TOSHIBA

"PhotoStitch" = Canon Utilities PhotoStitch

"Picasa 3" = Picasa 3

"Power Saver" = Gestion d'énergie TOSHIBA

"PrimoPDF" = PrimoPDF -- by Nitro PDF Software

"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX

"RemoteCaptureDC" = Canon Utilities RemoteCapture DC

"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX

"Secunia PSI" = Secunia PSI (

"Sheherazade" = Sheherazade

"Tennis Elbow 2009" = Tennis Elbow 2009 1.0e

"Tennis Elbow 2011" = Tennis Elbow 2011 1.0

"TOSHIBA Software Modem" = TOSHIBA Software Modem

"WIC" = Windows Imaging Component

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows Media Player" = Lecteur Windows Media 10

"WMFDist11" = Windows Media Format 11 runtime

"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility


< End of report >

C'est un peu long :D


Bon voilà on fait un autre essai ;)



  • Redemarre sur Reatogo
    relançe OTLPE
    sous Custom Scan box copie_colle le contenu du cadre ci dessous:
    En commençant bien à :OTL
    les : inclus devant OTL, et clique RUNFIX
    SRV - [2011/01/10 10:24:20 | 000,993,848 | ---- | M] (Secunia) [Auto] -- C:\Program Files\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
    SRV - [2011/01/10 10:24:20 | 000,399,416 | ---- | M] (Secunia) [Auto] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
    DRV - [2010/09/01 04:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand] -- C:\WINDOWS\system32\drivers\psi_mf.sys -- (PSI)
    O1 - Hosts: ::1 localhost
    O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.5.0)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (Reg Error: Key error.)
    O31 - SafeBoot: AlternateShell - cmd.exe
    MsConfig - StartUpReg: SUPERAntiSpyware - hkey= - key= - File not found
    SafeBootMin: ccEvtMgr - Reg Error: Value error.
    SafeBootMin: ccSetMgr - Reg Error: Value error.
    SafeBootMin: Symantec Antivirus - Reg Error: Value error.
    SafeBootNet: ccEvtMgr - Reg Error: Value error.
    SafeBootNet: ccSetMgr - Reg Error: Value error.
    SafeBootNet: SmcService - Reg Error: Value error.
    SafeBootNet: Symantec Antivirus - Reg Error: Value error.
    SafeBootNet: Symantec Antvirus - Reg Error: Value error.
    [2011/04/30 20:13:53 | 000,142,592 | ---- | C] (Microsoft Corporation) -- C:\aec.sys
    [2011/04/21 07:18:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp2
    [2011/04/02 12:06:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Nicolas\Local Settings\Application Data\WMTools Downloaded Files
    [2011/04/02 09:32:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrateur\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000}
    [2010/07/23 11:49:40 | 000,000,048 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
    [2011/02/17 09:18:24 | 000,455,936 | ---- | M] (Microsoft Corporation) MD5=0EA4D8ED179B75F8AFA7998BA22285CA -- C:\WINDOWS\SoftwareDistribution\Download\699ee2ac4f9ea8ea1babe26c8f35b4ef\SP3GDR\mrxsmb.sys
    [2011/02/17 09:19:38 | 000,457,472 | ---- | M] (Microsoft Corporation) MD5=FB7DFD15D760AD339837A470F0E780D3 -- C:\WINDOWS\SoftwareDistribution\Download\699ee2ac4f9ea8ea1babe26c8f35b4ef\SP3QFE\mrxsmb.sys
    [2011/03/03 09:53:37 | 001,858,048 | ---- | M] (Microsoft Corporation) MD5=3BEDF6024160399E2AF010BB2E7F4F59 -- C:\WINDOWS\SoftwareDistribution\Download\45fa26c815a59b9da6bd422e449ae5ac\sp3gdr\win32k.sys
    [2011/03/03 09:52:12 | 001,867,008 | ---- | M] (Microsoft Corporation) MD5=E832E04ADDD745DC462ED800E8416B9C -- C:\WINDOWS\SoftwareDistribution\Download\45fa26c815a59b9da6bd422e449ae5ac\sp3qfe\win32k.sys
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = DWORD:0
    "Start" = DWORD:0
    "Start" = DWORD:2
    "EnableFirewall" = DWORD:1
    "EnableFirewall"= 0
    "DisableNotifications"= 0
    net start srservice /c
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
    C:\WINDOWS\Driver Cache\i386\
  • Clique ensuite sur Correction laisse l'outil travailler.
  • Poste le contenu du nouveau rapport c'est un fichier "LOG"
    Il est sauvegardé dans le dossier C:\OTL\MovedFiles qui doit s'ouvrir avec le bloc-notes.
  • Copie-colle ce texte dans ta prochaine réponse


Fait ensuite pour le moment,un démarrage en mode sans échec avec reseau.

Donne moi le résultat,on vois pour la suite ;)

Voila le rapport.



========== OTL ==========

Service\Driver key Secunia PSI Agent not found.

File C:\Program Files\Secunia\PSI\PSIA.exe not found.

Service\Driver key Secunia Update Agent not found.

File C:\Program Files\Secunia\PSI\sua.exe not found.

Service\Driver key PSI not found.

File C:\WINDOWS\system32\drivers\psi_mf.sys not found.

Starting removal of ActiveX control {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_USERS\Administrateur_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_USERS\Nicolas_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_USERS\systemprofile_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.

Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_USERS\Administrateur_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_USERS\Nicolas_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_USERS\systemprofile_ON_C\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\\AlternateShell not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SUPERAntiSpyware\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\ccEvtMgr\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\ccSetMgr\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Symantec Antivirus\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\ccEvtMgr\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\ccSetMgr\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\SmcService\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Symantec Antivirus\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Symantec Antvirus\ not found.

File C:\aec.sys not found.

Folder C:\WINDOWS\temp2\ not found.

Folder C:\Documents and Settings\Nicolas\Local Settings\Application Data\WMTools Downloaded Files\ not found.

Folder C:\Documents and Settings\Administrateur\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000}\ not found.

File C:\WINDOWS\System32\ezsidmv.dat not found.

File C:\WINDOWS\SoftwareDistribution\Download\699ee2ac4f9ea8ea1babe26c8f35b4ef\SP3GDR\mrxsmb.sys not found.

File C:\WINDOWS\SoftwareDistribution\Download\699ee2ac4f9ea8ea1babe26c8f35b4ef\SP3QFE\mrxsmb.sys not found.

File C:\WINDOWS\SoftwareDistribution\Download\45fa26c815a59b9da6bd422e449ae5ac\sp3gdr\win32k.sys not found.

File C:\WINDOWS\SoftwareDistribution\Download\45fa26c815a59b9da6bd422e449ae5ac\sp3qfe\win32k.sys not found.

========== REGISTRY ==========

Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec\ not found.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\\"DisableNotifications"|0 /E : value set successfully!

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\ not found.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\\"DisableSR" | DWORD:0 /E : value set successfully!

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr\\"Start" | DWORD:0 /E : value set successfully!

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService\\"Start" | DWORD:2 /E : value set successfully!

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\"EnableFirewall" | DWORD:1 /E : value set successfully!

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\"EnableFirewall"| 0 /E : value set successfully!

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\"DisableNotifications"| 0 /E : value set successfully!

========== FILES ==========

< net start srservice /c >

C:\cmd.bat deleted successfully.

C:\cmd.txt deleted successfully.

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

Invalid Switch: replace

========== COMMANDS ==========




User: Administrateur

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->FireFox cache emptied: 0 bytes

->Flash cache emptied: 0 bytes


User: All Users


User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes


User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes


User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes


User: Nicolas

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 0 bytes

->Flash cache emptied: 0 bytes


%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes


Total Files Cleaned = 0.00 mb



OTLPE by OldTimer - Version log created on 05012011_230229

NickCouk :D

Désoler J'ai fait une erreur dans mon script, rien de grave rassure toi ;)

Peux-tu refaire la même manip avec ceci stp


  • sous Custom Scan box copie_colle le contenu du cadre ci dessous:
    En commençant bien à :OTL
    les : inclus devant OTL et clique RUNFIX
C:\WINDOWS\Driver Cache\i386\ /e
C:\WINDOWS\Driver Cache\i386\
C:\WINDOWS\Driver Cache\i386\
C:\WINDOWS\Driver Cache\i386\
C:\WINDOWS\Driver Cache\i386\
C:\WINDOWS\Driver Cache\i386\
C:\WINDOWS\Driver Cache\i386\
C:\WINDOWS\Driver Cache\i386\
C:\WINDOWS\Driver Cache\i386\
C:\WINDOWS\Driver Cache\i386\
Clique ensuite sur Correction laisse l'outil travailler.
Poste le contenu du nouveau rapport c'est un fichier "LOG"
Il est sauvegardé dans le dossier C:\OTL\MovedFiles qui doit s'ouvrir avec le bloc-notes.
Copie-colle ce texte dans ta prochaine réponse


Ensuite :


Merci pour La Procédure de petitbonhomme ;)

  • Démarre sur le CD bootable avec la console de récupération.
  • N.B. : Assure-toi que l'ordinateur est paramétré pour démarrer sur le CD - la touche [F12]
    permet généralement d'avoir accès au menu de boot (ou parfois les touches [F11]
    [F9][Esc] ou [Del]) - Regarder ce qui est indiqué en bas de l'écran de démarrage.
    normalement tu as déja les paramétre pour Booter sur le CD ,donc ici inutile :D
  • Tape la lettre R pour sélectionner la réparation du système puis appuis sur [Entrée]
  • Sélectionne le système d'exploitation - si un seul système est installé
    il sera affiché 1 : C:\WINDOWS (cas le plus général)
    tape 1 puis appuis sur [Entrée]
    Vérifie bien quelle est la lettre attribuée à la partition système et note-la
    elle sera importante pour la suite
  • Entre un mot de passe si demandé
  • L'Invite de commande s'affiche
  • Tape chkdsk X: /p /r puis appuie sur [Entrée] - attention à la syntaxe : c'est chkdsk < espace > X: < espace > /p < espace > /r -
    X: est à remplacer par la lettre attribuée à ta partition système soit en général >>C ce qui doit faire chkdsk C: /p /r
  • Si un message t'indique que la commande n'est pas valable
    utilise celle-ci chkdsk C: /r (si C: est ta partition système sinon remplacer par la lettre attribuée à ta partition système)
  • Laisse l'opération s'effectuer jusqu'à son terme. En fonction de la taille de la partition
    cela peut parfois prendre quelques heures.
  • Une fois la vérification terminée
    un rapport s'affiche. Vérifie si des secteurs ont été réparés.
  • Toujours en Invite de commande
    tape sfc /scannow puis appuie sur la touche [Entrée] - Attention à la syntaxe : c'est sfc < espace > /scannow
    (si C: est ta partition système sinon remplacer par la lettre attribuée à ta partition système)
  • Attends patiemment la fin de la procédure qui peut être longue
  • Examine le rapport en fin.
  • Lorsque cela est fini
    tape exit pour sortir de l'invite de commande.
  • Ferme la console
  • Ejecte le CD/DVD
  • Tente un redémarrage.


Voilà a te lire bonne soirée



