Alureon.h

Bonjour à tous,

depuis 2 jours, j'ai quelques pb avec IE8 ... macafee ne détecte rien, spyware doctor non plus, mais un live scan one care de microsoft m'indique la présence de WIN32/Alureon.h
Existe t'il un moyen de s'en débarasser ?
Merci d'avance.
Daniel

30 réponses

Résumé de la discussion

Des détections répétées indiquent la présence d'un rootkit WIN32/Alureon.h sur un ordinateur Windows XP utilisant IE8, malgré l'absence de détections par certains antivirus classiques et expliquent certains symptômes. Plusieurs outils recommandés incluent RSIT et HijackThis pour collecter des rapports et GMER pour le scan des rootkits, suivis de redémarrages en mode sans échec et de l’analyse des journaux pour guider les nettoyages. Certaines procédures conseillent de désactiver temporairement les logiciels d’émulation de CD et d’utiliser Defogger puis GMER pour un scan plus fiable, et sauvegarder les rapports sur le Bureau.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    salut

    jme permet d'intervenir car je suivais deja ce sujet est malheureusement ce rootkit patch des fichier systemes

    Blueway poste ce rapport

    C:/combofix.txt et celui de TDSS remover stp
    1. C'est fait voilà ...

      GMER 1.0.15.15281 - http://www.gmer.net
      Rootkit scan 2010-05-22 19:06:53
      Windows 5.1.2600 Service Pack 3
      Running: mgmer0rrcn15u.exe; Driver: C:\DOCUME~1\DMARTI~1\LOCALS~1\Temp\pgriapow.sys

      ---- System - GMER 1.0.15 ----

      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF743AE22]
      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF741BCDC]
      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF741BECE]
      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF743B610]
      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF743B8C4]
      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF7439B14]
      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF743BD30]
      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF743B0E2]
      SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF741B982]
      SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwWriteVirtualMemory [0xB9DD1384]

      ---- Registry - GMER 1.0.15 ----

      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC8 0x2E 0xEC 0x36 ...
      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 D:\Program Files\Alcohol Soft\Alcohol 120\
      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x99 0x09 0x89 0xFA ...
      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x49 0xD0 0x08 0x11 ...
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC8 0x2E 0xEC 0x36 ...
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 D:\Program Files\Alcohol Soft\Alcohol 120\
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x99 0x09 0x89 0xFA ...
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
      Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x49 0xD0 0x08 0x11 ...
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC8 0x2E 0xEC 0x36 ...
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 D:\Program Files\Alcohol Soft\Alcohol 120\
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x99 0x09 0x89 0xFA ...
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x49 0xD0 0x08 0x11 ...
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC8 0x2E 0xEC 0x36 ...
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 D:\Program Files\Alcohol Soft\Alcohol 120\
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x99 0x09 0x89 0xFA ...
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
      Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x49 0xD0 0x08 0x11 ...

      Alors doc ?
      1. Contributeur sécurité
        oO , ya un trcu que je comprends pas la.... (c'est pas toi tkt ;) )

        bon, tu as encore des problemes ? les quels ?

        fait sa :

        Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

        * Télécharge Defogger (de jpshortstuff) sur ton Bureau
        http://www.jpshortstuff.247fixes.com/Defogger.exe
        * Lance le
        * Une fenêtre apparait : clique sur "Disable"
        * Fais redémarrer l'ordinateur si l'outil te le demande
        * Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

        puis

        /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

        * Rends toi sur cette page, et clique sur "Download EXE" pour télécharger Gmer (sous un nom aléatoire, pour éviter qu'il soit bloqué par une infection)
        http://www.gmer.net/
        * Lance Gmer
        * Dans l'onglet "Rootkit", clique sur "Scan" puis patiente.
        * A la fin, clique sur "Save" et enregistre le rapport sur ton Bureau.

        Si GMER bloque ou ne repond plus ou encore te fait un ecran bleu, tu t'inqueite pas. tu redemarre ton PC au bipt tapote F8 et choisit mode sans echec puis relance GMER et enregistre le rapport sur ton bureau et poste le ensuite
        1. Voila pour avira

          http://www.cijoint.fr/cjlink.php?file=cj201005/cijni6e7yG.txt

          et voila pour Malwarebytes

          Malwarebytes' Anti-Malware 1.46
          www.malwarebytes.org

          Version de la base de données: 4124

          Windows 5.1.2600 Service Pack 3
          Internet Explorer 8.0.6001.18702

          22/05/2010 03:22:09
          mbam-log-2010-05-22 (03-22-09).txt

          Type d'examen: Examen complet (C:\|D:\|)
          Elément(s) analysé(s): 443747
          Temps écoulé: 7 heure(s), 8 minute(s), 14 seconde(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)

          A+
          1. Contributeur sécurité
            salut

            jme fache pas t'inquiète mais c'est pour faire reagir ;)

            va dans demarrer/panneau de configuration/ajouter et desinstaller un programme :

            et desinstalle mc affe c'est vraiment nul meme si tu le paye c'est un bon conseil

            tu as deja antivir gratuit beaucoup mieux !!

            * Télécharge Malwarebytes
            http://www.malwarebytes.org/mbam/program/mbam-setup.exe
            * Tu auras un tutoriel à ta disposition pour l'installer et l'utiliser correctement.
            * Fais la mise à jour du logiciel (elle se fait normalement à l'installation)
            * Lance une analyse complète en cliquant sur "Exécuter un examen complet"
            * Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"
            * L'analyse peut durer un bon moment.....
            * Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"
            * Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"
            * Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

            * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée

            puis

            configure antivir comme ceci : https://www.commentcamarche.net/faq/16831-tutoriel-configuration-optimale-d-antivir-personal

            puis a l'ecran d'accueil quand tu double clic sur le parapluie rouge, clic sur "LANCER LA MISE A JOUR" patiente le temps qu'elle finisse

            puis apres toujours a l'ecran d'accueil et apres AVOIR CONFIGURER antivir avec le lien donner + haut, tu clic sur "controler systeme maintenant"
            tu supprime tous ce qu'il trouve et ala fin tu clic sur rapport et copie colle le direct sur le forum en 1 fois celui ci
            1. bon bon ok ... je t'avais dit que j'étais blonde ;-)

              Pour combofix.txt

              http://www.cijoint.fr/cjlink.php?file=cj201005/cijDyAPimJ.txt

              Pour RSIT

              http://www.cijoint.fr/cjlink.php?file=cj201005/cijl8qQkDg.txt

              Voilou ... et te fâche pâ ;-)
              1. Contributeur sécurité
                tu fais n'importe qu'oi, essaye de lire et d'appliquer, jte demandai pas de relancer combofix mais uniquement de poster le rapport qui ce trouver dans C:

                poste ce rapport => ComboFix3.txt

                ensuite j'ai dt dherger les rapport sur ci joint : http://www.cijoint.fr/

                dans chaque rapport tu en oublie des parties...

                poste moi ce rapport via Cijoint C:/RSIT/log.txt

                + dans un autre lien ci joint le rapport combofix3.txt
                1. **************************************************************************
                  .
                  --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                  [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
                  "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
                  00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\

                  [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø*€|ÿÿÿÿ*€| -Ñw*]
                  "C040110900063D11C8EF10054038389C"="C?\\windows\\system32\\FM20ENU.DLL"

                  [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€-€|ÿÿÿÿÀ*€|ù*9~*]
                  "C040110900063D11C8EF10054038389C"="C?\\windows\\system32\\FM20ENU.DLL"
                  .
                  --------------------- DLLs chargées dans les processus actifs ---------------------

                  - - - - - - - > 'winlogon.exe'(1348)
                  c:\windows\system32\ATGinaHook.dll
                  c:\program files\Lenovo Fingerprint Software\ATCSSINT.DLL
                  c:\program files\Lenovo Fingerprint Software\SharedResources.dll
                  c:\program files\Lenovo Fingerprint Software\FPResource.dll
                  c:\program files\Lenovo\Client Security Solution\CSS_Enroll.dll
                  c:\program files\Lenovo\Client Security Solution\css_banner.dll
                  c:\windows\system32\cssuserdatadispatcher.dll
                  c:\windows\system32\tvttsp.dll
                  c:\windows\system32\tcsrpc.dll
                  c:\windows\system32\FpWinLogonNp.dll
                  c:\program files\Lenovo\HOTKEY\tphklock.dll
                  c:\windows\system32\AFSSClientLib.dll
                  c:\windows\system32\igfxdev.dll
                  c:\program files\Lenovo\HOTKEY\notifyf2.dll

                  - - - - - - - > 'explorer.exe'(860)
                  c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
                  c:\windows\system32\webcheck.dll
                  c:\windows\system32\WPDShServiceObj.dll
                  c:\windows\system32\PortableDeviceTypes.dll
                  c:\windows\system32\PortableDeviceApi.dll
                  c:\windows\system32\eappprxy.dll
                  .
                  Heure de fin: 2010-05-20 17:47:32
                  ComboFix-quarantined-files.txt 2010-05-20 15:47
                  ComboFix2.txt 2010-05-18 06:54
                  ComboFix3.txt 2010-05-15 21:08

                  Avant-CF: 30 056 665 088 octets libres
                  Après-CF: 29 999 206 400 octets libres

                  Current=2 Default=2 Failed=4 LastKnownGood=1 Sets=1,2,3,4
                  - - End Of File - - 54E306E96964A378A062441BD201B020
                  1. ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                    REGEDIT4

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "PC Suite Tray"="d:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe \s" [X]
                    "TPFNF7"="c:\progra~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-01-07 60704]
                    "TpShocks"="TpShocks.exe" [2009-02-02 181536]
                    "snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-28 569344]
                    "TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-09-30 68976]
                    "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-10-08 256576]
                    "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2008-03-07 167936]
                    "CameraApplicationLauncher"="c:\program files\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe" [2008-08-12 16384]
                    "PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2009-03-22 389120]
                    "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2009-03-22 208896]
                    "TrackPointSrv"="c:\program files\Lenovo\TrackPoint\tp4serv.exe" [2009-01-26 92960]
                    "picon"="c:\program files\Fichiers communs\Intel\Privacy Icon\PrivacyIconClient.exe" [2009-02-12 357400]
                    "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
                    "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
                    "EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-01-12 669520]
                    "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
                    "avgnt"="d:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
                    "QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2008-09-06 413696]

                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
                    "DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                    "HonorAutoRunSetting"= 0 (0x0)

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                    "HonorAutoRunSetting"= 0 (0x0)

                    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ATFUS]
                    2009-03-19 02:55 180224 ----a-w- c:\windows\system32\FpWinlogonNp.dll

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
                    2006-09-06 14:37 34344 ----a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
                    2008-08-08 10:14 28672 ----a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-7174978-3753775089-2012757992-1314\Scripts\Logon\0\0]
                    "Script"=pushprinterconnections.exe

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
                    @=""

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
                    @=""

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                    @="Driver"

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Acrobat Assistant.lnk]
                    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Acrobat Assistant.lnk
                    backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
                    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk
                    backup=c:\windows\pss\BTTray.lnkCommon Startup

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Digital Line Detect.lnk]
                    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Digital Line Detect.lnk
                    backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Post-it® Software Notes Lite.lnk]
                    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Post-it® Software Notes Lite.lnk
                    backup=c:\windows\pss\Post-it® Software Notes Lite.lnkCommon Startup

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^RCIMGDIR.exe.lnk]
                    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\RCIMGDIR.exe.lnk
                    backup=c:\windows\pss\RCIMGDIR.exe.lnkCommon Startup

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^VPN Client.lnk]
                    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\VPN Client.lnk
                    backup=c:\windows\pss\VPN Client.lnkCommon Startup

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Search.lnk]
                    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Search.lnk
                    backup=c:\windows\pss\Windows Search.lnkCommon Startup

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
                    c:\program files\Fichiers communs\Nokia\MPlatform\NokiaMServer [X]

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
                    2010-03-24 18:17 952768 ----a-w- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
                    2010-04-02 18:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
                    2009-11-15 09:42 33120 ----a-w- d:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMSG]
                    2007-02-01 18:00 419376 ----a-w- c:\program files\ThinkVantage\AMSG\Amsg.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserChoice]
                    2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreateLMBCShortCut]
                    2009-01-21 11:47 36864 ----a-w- c:\program files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cssauth]
                    2008-06-13 19:08 3073336 ----a-w- c:\program files\Lenovo\Client Security Solution\cssauth.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
                    2008-04-13 17:34 15360 ----a-w- c:\windows\system32\ctfmon.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM]
                    2009-02-05 23:00 843776 ------w- c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
                    2008-10-25 10:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
                    2008-10-30 14:38 178712 ----a-w- c:\windows\system32\hkcmd.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
                    2008-10-30 14:38 150040 ----a-w- c:\windows\system32\igfxtray.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPMailChecker]
                    2009-01-29 01:10 124248 ----a-w- c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.EXE

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
                    2009-01-29 01:10 185688 ----a-w- c:\progra~1\THINKV~1\PrdCtr\LPMGR.EXE

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
                    2009-11-06 15:00 2090272 ----a-w- c:\program files\Nokia\Ovi Player\NokiaOviPlayer.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
                    2009-11-11 08:57 1451520 ----a-w- d:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
                    2008-10-30 14:38 150040 ----a-w- c:\windows\system32\igfxpers.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                    2008-09-06 13:09 413696 ----a-w- d:\program files\QuickTime\QTTask.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                    2009-09-17 11:01 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPHELPER]
                    2007-01-09 14:28 868352 ----a-w- c:\program files\ThinkPad\Utilities\TpKmapAp.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
                    2009-08-04 14:49 1068424 ----a-w- d:\program files\Trojan Remover\Trjscan.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
                    2008-11-24 14:42 487424 ----a-w- c:\program files\Fichiers communs\Lenovo\Scheduler\scheduler_proxy.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
                    2006-11-03 07:59 204288 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                    "DWMRCS"=2 (0x2)
                    "SUService"=2 (0x2)
                    "stllssvr"=3 (0x3)
                    "StarWindServiceAE"=2 (0x2)
                    "sdCoreService"=3 (0x3)
                    "sdAuxService"=3 (0x3)
                    "SCardSvr"=2 (0x2)
                    "RoxMediaDB10"=3 (0x3)
                    "ProtexisLicensing"=2 (0x2)
                    "mnmsrvc"=3 (0x3)
                    "Microsoft Office Groove Audit Service"=3 (0x3)
                    "MDM"=3 (0x3)
                    "JavaQuickStarterService"=2 (0x2)
                    "COMSysApp"=2 (0x2)
                    "aspnet_state"=3 (0x3)
                    "WudfSvc"=2 (0x2)
                    "TVT Scheduler"=2 (0x2)
                    "TSSCoreService"=2 (0x2)
                    "ThinkVantage Registry Monitor Service"=3 (0x3)
                    "WMPNetworkSvc"=2 (0x2)
                    "TpKmpSVC"=2 (0x2)
                    "ADMonitor"=3 (0x3)
                    1. ComboFix 10-05-15.01 - DIANO 20/05/2010 17:31:00.3.2 - x86
                      Lancé depuis: c:\documents and settings\DIANO\Bureau\Outils\CLEAN\combofix.exe
                      AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
                      AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
                      * Un antivirus résident est actif

                      .

                      ((((((((((((((((((((((((((((( Fichiers créés du 2010-04-20 au 2010-05-20 ))))))))))))))))))))))))))))))))))))
                      .

                      2010-05-20 14:52 . 2010-05-20 14:53 -------- d-----w- c:\program files\trend micro
                      2010-05-19 06:30 . 2010-05-19 06:30 -------- d-----r- c:\documents and settings\NetworkService\Mes documents
                      2010-05-17 08:16 . 2010-05-17 08:16 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\PCHealth
                      2010-05-17 06:28 . 2010-05-17 06:31 -------- dc-h--w- c:\windows\ie8
                      2010-05-16 17:57 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
                      2010-05-15 17:01 . 2010-05-15 17:54 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
                      2010-05-15 17:01 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
                      2010-05-15 17:01 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
                      2010-05-15 17:01 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
                      2010-05-15 17:01 . 2010-05-15 17:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
                      2010-05-15 05:01 . 2010-05-15 20:07 52736 ----a-w- c:\windows\system32\drivers\rk_remover.sys
                      2010-05-15 04:42 . 2010-05-15 04:42 -------- d-----w- c:\documents and settings\DIANO\Application Data\Malwarebytes
                      2010-05-15 04:42 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                      2010-05-15 04:42 . 2010-05-15 04:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                      2010-05-15 04:42 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
                      2010-05-15 04:42 . 2010-05-15 04:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                      2010-05-15 04:27 . 2010-05-15 04:31 -------- d-----w- c:\program files\ZHPDiag
                      2010-05-14 20:51 . 2010-05-06 08:36 221568 ------w- c:\windows\system32\MpSigStub.exe
                      2010-05-14 12:52 . 2010-05-19 06:29 -------- d-----w- c:\documents and settings\NetworkService\Bureau
                      2010-05-14 07:17 . 2010-05-14 07:17 -------- d-----w- c:\documents and settings\LocalService\Bureau
                      2010-05-14 06:18 . 2010-05-16 08:51 -------- d-----w- c:\program files\Lavasoft
                      2010-05-14 06:18 . 2010-05-14 06:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
                      2010-05-14 05:51 . 2010-05-17 19:33 -------- d-----w- c:\program files\Windows Live Safety Center
                      2010-05-13 21:53 . 2009-09-29 13:14 3101560 ----a-w- c:\documents and settings\DIANO\Application Data\Simply Super Software\Trojan Remover\suf213.exe
                      2010-05-13 21:47 . 2006-06-19 11:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
                      2010-05-13 21:47 . 2006-05-25 13:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
                      2010-05-13 21:47 . 2005-08-25 23:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
                      2010-05-13 21:47 . 2003-02-02 18:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
                      2010-05-13 21:47 . 2002-03-05 23:00 75264 ----a-w- c:\windows\system32\unacev2.dll
                      2010-05-13 21:47 . 2010-05-13 21:47 -------- d-----w- c:\documents and settings\DIANO\Application Data\Simply Super Software
                      2010-05-13 21:47 . 2010-05-13 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
                      2010-05-13 21:22 . 2010-05-13 21:52 -------- d-----w- C:\rsit
                      2010-05-13 18:21 . 2010-05-17 06:32 -------- d--h--w- c:\windows\msdownld.tmp
                      2010-05-13 17:07 . 2010-05-13 18:15 -------- d-----w- c:\windows\SoftwareDistribution.old
                      2010-05-13 13:36 . 2010-05-13 13:36 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\Threat Expert
                      2010-05-13 13:26 . 2010-01-21 23:21 165840 ----a-w- c:\windows\PCTBDRes.dll
                      2010-05-13 13:26 . 2010-01-21 23:21 149456 ----a-w- c:\windows\SGDetectionTool.dll
                      2010-05-13 13:26 . 2010-01-21 23:21 1152444 ----a-w- c:\windows\UDB.zip
                      2010-05-13 13:26 . 2010-01-21 23:21 1652688 ----a-w- c:\windows\PCTBDCore.dll
                      2010-05-13 13:26 . 2010-01-21 23:21 767952 ----a-w- c:\windows\BDTSupport.dll
                      2010-05-13 13:26 . 2008-11-26 10:08 131 ----a-w- c:\windows\IDB.zip
                      2010-05-13 13:14 . 2009-09-24 06:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
                      2010-05-13 13:14 . 2009-10-06 14:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
                      2010-05-13 13:14 . 2009-09-23 14:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
                      2010-05-13 13:13 . 2009-09-03 07:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
                      2010-05-13 13:13 . 2010-05-15 16:22 -------- d-----w- c:\program files\Spyware Doctor
                      2010-05-13 13:13 . 2010-05-13 13:26 -------- d-----w- c:\program files\Fichiers communs\PC Tools
                      2010-05-13 13:13 . 2010-05-13 13:13 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
                      2010-05-13 09:00 . 2010-05-13 09:00 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
                      2010-05-13 08:20 . 2010-05-13 08:05 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
                      2010-05-13 08:20 . 2010-05-13 08:05 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
                      2010-05-13 08:20 . 2009-11-13 16:42 529171 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Player\DivXPlayerUninstall.exe
                      2010-05-13 08:20 . 2010-05-13 08:20 56766 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
                      2010-05-13 08:20 . 2009-11-13 16:42 529171 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Plus DirectShow Filters\DivXDSFiltersUninstall.exe
                      2010-05-13 08:20 . 2009-11-13 16:42 529171 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe
                      2010-05-13 08:20 . 2010-05-13 08:20 56978 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
                      2010-05-13 08:20 . 2010-05-13 08:20 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
                      2010-05-13 08:20 . 2010-05-13 08:20 57679 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
                      2010-05-13 08:20 . 2010-05-13 08:20 84040 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
                      2010-05-13 08:13 . 2010-05-13 21:55 -------- d-----w- c:\program files\DivX
                      2010-05-13 08:05 . 2010-05-13 08:05 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
                      2010-05-13 08:05 . 2010-05-13 08:20 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
                      2010-05-12 05:22 . 2010-05-12 05:22 3532 ----a-w- C:\drmHeader.bin
                      2010-05-04 21:03 . 2010-05-04 21:03 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\GPSENABLER
                      2010-05-03 20:07 . 2010-05-03 20:07 -------- d-----w- c:\program files\Rallentando Software
                      2010-05-03 17:16 . 2010-05-03 17:16 7168 ----a-w- c:\documents and settings\DIANO\Application Data\Thinstall\MidiIllustrator v2.01\10000004b00002i\winhlp32.exe
                      2010-05-03 17:08 . 2010-05-03 17:08 -------- d-----w- c:\documents and settings\DIANO\Application Data\Music Recognition
                      2010-04-30 16:46 . 2010-04-30 16:46 -------- d-----w- c:\documents and settings\DIANO\Application Data\Thinstall
                      2010-04-27 22:45 . 2010-04-27 23:00 3 ----a-w- c:\windows\system32\mnprxp1.bin
                      2010-04-27 22:39 . 2010-04-27 22:39 737280 ----a-w- c:\windows\iun6002.exe
                      2010-04-27 20:25 . 2010-04-27 20:33 -------- d-----w- c:\documents and settings\DIANO\Application Data\REAPER
                      2010-04-27 20:08 . 1998-02-06 19:37 299520 ----a-w- c:\windows\uninst.exe
                      2010-04-27 20:07 . 2010-04-27 20:07 -------- d-----w- c:\documents and settings\DIANO\WINDOWS
                      2010-04-26 14:26 . 2010-04-26 14:26 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\Yamaha Corporation
                      2010-04-26 14:24 . 2010-04-26 14:24 -------- d-----w- c:\program files\Yamaha Corporation
                      2010-04-26 14:24 . 2010-04-26 14:24 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\Downloaded Installations
                      2010-04-26 11:41 . 1997-07-31 21:08 34816 ----a-w- c:\windows\system32\VBHLP32.DLL
                      2010-04-26 11:41 . 2009-02-19 12:15 208896 ----a-w- c:\windows\system32\VBALNCSM6.DLL
                      2010-04-26 11:41 . 2003-01-26 11:41 40960 ----a-w- c:\windows\system32\SSUBTMR6.DLL

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2010-05-20 15:33 . 2009-12-06 17:31 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
                      2010-05-17 19:23 . 2009-11-11 19:12 -------- d-----w- c:\documents and settings\DIANO\Application Data\uTorrent
                      2010-05-17 08:25 . 2009-03-26 07:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
                      2010-05-16 16:32 . 2009-03-26 06:30 -------- d--h--w- c:\program files\InstallShield Installation Information
                      2010-05-15 20:37 . 2004-08-03 22:59 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
                      2010-05-15 20:06 . 2010-05-15 20:06 96512 ----a-w- c:\windows\system32\drivers\tsk7.tmp
                      2010-05-14 20:39 . 2006-01-26 20:35 599052 ----a-w- c:\windows\system32\perfh00C.dat
                      2010-05-14 20:39 . 2006-01-26 20:35 120956 ----a-w- c:\windows\system32\perfc00C.dat
                      2010-05-14 08:09 . 2009-11-20 13:42 -------- d-----w- c:\documents and settings\DIANO\Application Data\webex
                      2010-05-13 09:01 . 2009-11-13 16:43 -------- d-----w- c:\documents and settings\DIANO\Application Data\DivX
                      2010-05-08 15:58 . 2010-04-01 20:20 -------- d-----w- c:\program files\IK Multimedia
                      2010-05-08 15:56 . 2010-04-01 20:28 16 ----a-w- c:\windows\msocreg32.dat
                      2010-05-04 20:22 . 2009-11-11 18:51 1234416 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
                      2010-04-08 18:49 . 2010-01-15 15:34 -------- d-----w- c:\documents and settings\DIANO\Application Data\gtk-2.0
                      2010-04-06 07:11 . 2010-04-06 07:11 -------- d-----w- c:\documents and settings\DIANO\Application Data\Plogue
                      2010-04-05 21:07 . 2010-04-05 21:07 -------- d-----w- c:\documents and settings\DIANO\Application Data\Garritan
                      2010-04-05 21:06 . 2010-04-05 21:06 -------- d-----w- c:\program files\Plogue
                      2010-04-05 16:01 . 2010-04-01 18:12 21840 ----atw- c:\windows\system32\SIntfNT.dll
                      2010-04-05 16:01 . 2010-04-01 18:12 17212 ----atw- c:\windows\system32\SIntf32.dll
                      2010-04-05 16:01 . 2010-04-01 18:12 12067 ----atw- c:\windows\system32\SIntf16.dll
                      2010-04-02 17:04 . 2010-04-02 17:04 -------- d-----w- c:\documents and settings\DIANO\Application Data\Apple Computer
                      2010-04-02 12:05 . 2009-11-28 21:45 2880 --sha-w- c:\windows\system32\KGyGaAvL.sys
                      2010-04-02 06:47 . 2010-04-02 06:47 -------- d-----w- c:\documents and settings\All Users\Application Data\QuickTime
                      2010-04-01 20:24 . 2010-04-01 20:24 -------- d-----w- c:\program files\Fichiers communs\Apple
                      2010-04-01 20:24 . 2010-04-01 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
                      2010-04-01 20:24 . 2010-04-01 20:24 -------- d-----w- c:\program files\Apple Software Update
                      2010-04-01 20:24 . 2010-04-01 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
                      2010-04-01 18:10 . 2010-04-01 18:10 -------- d-----w- c:\program files\Borland
                      2010-04-01 18:08 . 2009-11-09 16:52 -------- d-----w- c:\documents and settings\DIANO\Application Data\Roxio
                      2010-04-01 18:04 . 2010-04-01 18:04 -------- d-----w- c:\program files\Fichiers communs\PCSuite
                      2010-04-01 18:04 . 2009-11-10 16:16 -------- d-----w- c:\program files\Fichiers communs\Nokia
                      2010-04-01 18:02 . 2010-04-01 18:02 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
                      2010-04-01 18:02 . 2010-04-01 18:02 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
                      2010-04-01 18:02 . 2010-04-01 18:02 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
                      2010-04-01 18:02 . 2010-04-01 18:02 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
                      2010-04-01 18:02 . 2009-11-10 15:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
                      2010-04-01 18:02 . 2010-04-01 18:03 34503960 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_fre.exe
                      2010-04-01 17:49 . 2010-04-01 17:49 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
                      2010-04-01 16:18 . 2010-04-01 13:43 -------- d-----w- c:\program files\Fichiers communs\Native Instruments
                      2010-04-01 13:44 . 2010-04-01 13:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Native Instruments
                      2010-03-31 01:58 . 2008-04-08 18:31 125424 ------w- c:\windows\system32\pxinsi64.exe
                      2010-03-31 01:58 . 2007-12-13 13:49 133616 ------w- c:\windows\system32\PxAFS.DLL
                      2010-03-30 14:49 . 2010-03-30 14:49 -------- d-----w- c:\program files\Fichiers communs\L&H
                      2010-03-30 14:23 . 2010-03-30 14:23 -------- d-----w- c:\program files\NCT
                      2010-03-30 14:23 . 2009-06-29 20:12 -------- d-----w- c:\program files\Common Files
                      2010-03-24 05:52 . 2009-11-10 16:17 -------- d-----w- c:\documents and settings\DIANO\Application Data\Nokia
                      2010-03-16 14:49 . 2010-03-16 14:49 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}\Installer\CommonCustomActions\msxml6Exec.exe
                      2010-03-16 14:49 . 2010-03-16 14:49 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}\Installer\CommonCustomActions\Sleep.exe
                      2010-03-16 14:49 . 2010-03-16 14:49 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}\Installer\CommonCustomActions\vcredistExec.exe
                      2010-03-16 14:49 . 2010-03-16 14:51 34679832 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}\NokiaSoftwareUpdaterSetup_fr[1].exe
                      2010-03-10 06:16 . 2006-01-26 20:35 420352 ----a-w- c:\windows\system32\vbscript.dll
                      2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll
                      2010-02-25 06:17 . 2006-01-26 20:35 916480 ----a-w- c:\windows\system32\wininet.dll
                      2010-02-24 13:11 . 2006-01-26 20:34 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
                      2010-02-19 19:27 . 2010-02-19 19:27 720384 ----a-w- c:\windows\system32\DivX.dll
                      2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
                      2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx07.dll
                      2010-02-19 19:27 . 2010-02-19 19:27 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
                      2010-02-19 19:27 . 2010-02-19 19:27 843776 ----a-w- c:\windows\system32\divx_xx16.dll
                      2010-02-19 19:27 . 2010-02-19 19:27 839680 ----a-w- c:\windows\system32\divx_xx11.dll
                      2009-11-28 21:49 . 2009-11-28 21:49 88 --sh--r- c:\windows\system32\C759283878.sys
                      .

                      .
                      1. ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                        R1 avgio;avgio; \??\D:\Program Files\Avira\AntiVir Desktop\avgio.sys []
                        R1 avipbb;avipbb; C:\windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
                        R1 IKSysFlt;System Filter Driver; C:\windows\system32\drivers\iksysflt.sys [2008-08-25 66952]
                        R1 IKSysSec;System Security Driver; C:\windows\system32\drivers\iksyssec.sys [2008-08-25 81288]
                        R1 intelppm;Pilote de processeur Intel; C:\windows\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
                        R1 mferkdk;VSCore mferkdk; \??\C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys []
                        R1 mfetdik;McAfee Inc.; C:\windows\system32\drivers\mfetdik.sys [2006-11-30 52136]
                        R1 ssmdrv;ssmdrv; C:\windows\system32\DRIVERS\ssmdrv.sys [2010-05-15 28520]
                        R1 TPHKDRV;TPHKDRV; C:\windows\system32\DRIVERS\TPHKDRV.sys [2008-05-12 17844]
                        R1 TPPWRIF;TPPWRIF; C:\windows\System32\drivers\Tppwrif.sys [2009-03-23 4442]
                        R1 truecrypt;truecrypt; C:\windows\System32\drivers\truecrypt.sys [2009-12-22 223440]
                        R1 TSMAPIP;TSMAPIP; C:\windows\System32\drivers\TSMAPIP.SYS [2009-01-07 4608]
                        R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI; C:\windows\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
                        R2 avgntflt;avgntflt; C:\windows\system32\DRIVERS\avgntflt.sys [2010-05-15 56816]
                        R2 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\windows\system32\Drivers\CVPNDRVA.sys []
                        R2 pmem;pmem; \??\C:\WINDOWS\System32\drivers\pmemnt.sys []
                        R2 s24trans;Transport RLAN; C:\windows\system32\DRIVERS\s24trans.sys [2008-08-13 11904]
                        R3 5U875UVC;Integrated Camera; C:\windows\system32\DRIVERS\5U875.sys [2008-09-03 72192]
                        R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver; C:\windows\System32\Drivers\ATSwpWDF.sys [2009-03-19 482176]
                        R3 btaudio;Périphérique audio Bluetooth; C:\windows\system32\drivers\btaudio.sys [2008-03-10 534312]
                        R3 BTDriver;Pilote de communications virtuelles Bluetooth; C:\windows\system32\DRIVERS\btport.sys [2008-02-04 37160]
                        R3 BTKRNL;Enumérateur de bus Bluetooth; C:\windows\system32\DRIVERS\btkrnl.sys [2008-03-27 990632]
                        R3 BTWDNDIS;Serveur d'accès au réseau local Bluetooth; C:\windows\system32\DRIVERS\btwdndis.sys [2007-09-20 156392]
                        R3 btwmodem;Modem Bluetooth; C:\windows\system32\DRIVERS\btwmodem.sys [2008-02-04 37032]
                        R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\windows\System32\Drivers\btwusb.sys [2008-03-27 47272]
                        R3 CmBatt;Pilote d'adaptateur secteur Microsoft; C:\windows\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
                        R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDAU32.sys [2009-10-06 814592]
                        R3 DNE;Deterministic Network Enhancer Miniport; C:\windows\system32\DRIVERS\dne2000.sys [2007-01-31 127376]
                        R3 e1yexpress;Intel(R) Gigabit Network Connections Driver; C:\windows\system32\DRIVERS\e1y5132.sys [2009-03-27 239760]
                        R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
                        R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2008-03-26 40832]
                        R3 ialm;ialm; C:\windows\system32\DRIVERS\igxpmp32.sys [2008-10-21 6048480]
                        R3 IBMPMDRV;IBMPMDRV; C:\windows\system32\DRIVERS\ibmpmdrv.sys [2008-02-20 22696]
                        R3 mfeapfk;McAfee Inc.; C:\windows\system32\drivers\mfeapfk.sys [2006-11-30 64360]
                        R3 mfeavfk;McAfee Inc.; C:\windows\system32\drivers\mfeavfk.sys [2006-11-30 72264]
                        R3 mfebopk;McAfee Inc.; C:\windows\system32\drivers\mfebopk.sys [2006-11-30 34152]
                        R3 mfehidk;McAfee Inc.; C:\windows\system32\drivers\mfehidk.sys [2006-11-30 168776]
                        R3 NETw5x32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\windows\system32\DRIVERS\NETw5x32.sys [2009-03-04 4202496]
                        R3 psadd;Lenovo Parties Service Access Device Driver; C:\windows\system32\DRIVERS\psadd.sys [2008-09-25 31680]
                        R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\windows\System32\Drivers\RootMdm.sys [2004-08-05 5888]
                        R3 Tp4Track;PS/2 TrackPoint Driver; C:\windows\system32\DRIVERS\tp4track.sys [2009-01-26 23080]
                        R3 tpm;tpm; C:\windows\system32\DRIVERS\tpm.sys [2008-03-26 13824]
                        R3 TVTI2C;Lenovo SM bus driver; C:\windows\system32\DRIVERS\Tvti2c.sys [2008-02-22 37312]
                        R3 usbccgp;Pilote parent générique USB Microsoft; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
                        R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
                        R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\windows\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
                        R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\windows\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
                        R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\windows\System32\Drivers\wdf01000.sys [2007-09-15 501800]
                        S1 kbdhid;Pilote HID de clavier; C:\windows\system32\DRIVERS\kbdhid.sys [2008-04-13 14720]
                        S1 MpKsl22f1781c;MpKsl22f1781c; \??\C:\Program Files\Windows Live Safety Center\MpKsl22f1781c.sys []
                        S2 mdmxsdk;mdmxsdk; C:\windows\system32\DRIVERS\mdmxsdk.sys []
                        S2 rimmptsk;rimmptsk; C:\windows\system32\DRIVERS\rimmptsk.sys [2008-02-15 46592]
                        S2 rimsptsk;rimsptsk; C:\windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
                        S2 rismxdp;Ricoh xD-Picture Card Driver; C:\windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
                        S3 ac97intc;Service d'installation du pilote audio Intel(r) 82801 (WDM); C:\windows\system32\drivers\ac97intc.sys [2001-08-17 96256]
                        S3 ApfiltrService;Alps Pointing-device Filter Driver; C:\windows\system32\DRIVERS\Apfiltr.sys [2008-03-07 154672]
                        S3 Arp1394;Protocole client ARP 1394; C:\windows\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
                        S3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\windows\system32\DRIVERS\b57xp32.sys [2007-11-29 163328]
                        S3 BrScnUsb;Brother USB Still Image driver; C:\windows\System32\Drivers\BrScnUsb.sys [2003-12-19 15263]
                        S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver; C:\windows\System32\Drivers\BrSerIf.sys [2004-06-12 51712]
                        S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\windows\System32\Drivers\BrUsbSer.sys [2004-01-10 11648]
                        S3 catchme;catchme; \??\C:\DOCUME~1\DMARTI~1\LOCALS~1\Temp\catchme.sys []
                        S3 CCDECODE;Décodeur sous-titre fermé; C:\windows\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
                        S3 cpuz132;cpuz132; \??\C:\windows\TEMP\cpuz132\cpuz132_x32.sys []
                        S3 CVirtA;Cisco Systems VPN Adapter; C:\windows\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
                        S3 DBGMSG;DBGMSG; dbgmsg.sys []
                        S3 dot4;Pilote MS IEEE-1284.4; C:\windows\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
                        S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\windows\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
                        S3 dot4usb;Filtre Dot4USB Dot4USB Filter; C:\windows\system32\DRIVERS\dot4usb.sys [2001-08-23 24064]
                        S3 E100B;Pilote de carte Intel (R) PRO; C:\windows\system32\DRIVERS\e100b325.sys [2001-08-23 117760]
                        S3 G400;G400; C:\windows\system32\DRIVERS\G400m.sys [2001-08-23 322560]
                        S3 HidUsb;Pilote de classe HID Microsoft; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
                        S3 lnvobus;Ericsson F3507g Mobile Broadband Minicard Composite Device driver (WDM); C:\windows\system32\DRIVERS\lnvobus.sys []
                        S3 lnvocard;Ericsson F3507g Mobile Broadband Minicard Device Management; C:\windows\system32\DRIVERS\lnvocard.sys []
                        S3 lnvogps;Ericsson F3507g Mobile Broadband Minicard GPS Port; C:\windows\system32\DRIVERS\lnvogps.sys []
                        S3 lnvomdfl;Ericsson F3507g Mobile Broadband Minicard Modem Filter; C:\windows\system32\DRIVERS\lnvomdfl.sys []
                        S3 lnvomdfl2;Ericsson F3507g Mobile Broadband Minicard Data Modem Filter; C:\windows\system32\DRIVERS\lnvomdfl2.sys []
                        S3 lnvomdm;Ericsson F3507g Mobile Broadband Minicard Modem Driver; C:\windows\system32\DRIVERS\lnvomdm.sys []
                        S3 lnvomdm2;Ericsson F3507g Mobile Broadband Minicard Data Modem; C:\windows\system32\DRIVERS\lnvomdm2.sys []
                        S3 lnvond5;Ericsson F3507g Mobile Broadband Minicard Network Adapter (NDIS); C:\windows\system32\DRIVERS\lnvond5.sys []
                        S3 lnvounic;Ericsson F3507g Mobile Broadband Minicard Network Adapter (WDM); C:\windows\system32\DRIVERS\lnvounic.sys []
                        S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\mbamswissarmy.sys []
                        S3 mosuport;USB Serial/Parallel Ports; C:\windows\system32\DRIVERS\mosuport.sys [2006-05-05 855040]
                        S3 mouhid;Pilote HID de souris; C:\windows\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
                        S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\windows\system32\drivers\MSTEE.sys [2008-04-13 5504]
                        S3 NABTSFEC;Codec NABTS/FEC VBI; C:\windows\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
                        S3 NdisIP;Connection TV/vidéo Microsoft; C:\windows\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
                        S3 NIC1394;Pilote réseau 1394; C:\windows\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
                        S3 nmwcd;Nokia USB Phone Parent; C:\windows\system32\drivers\ccdcmb.sys [2010-01-21 18048]
                        S3 nmwcdc;Nokia USB Generic; C:\windows\system32\drivers\ccdcmbo.sys [2009-12-30 22016]
                        S3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
                        S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
                        S3 rk_remover-boot;rk_remover-boot; \??\C:\windows\system32\drivers\rk_remover.sys []
                        S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
                        S3 SLIP;Détrameur décalage BDA; C:\windows\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
                        S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2007-02-16 9598080]
                        S3 Sony_EricssonWWSC;Ericsson F3507g Mobile Broadband Minicard PC SC Port; C:\windows\system32\DRIVERS\lnvoscard.sys []
                        S3 streamip;BDA IPSink; C:\windows\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
                        S3 TwoTrack;Pilote de filtre de TrackPoint IBM PS/2; C:\windows\system32\DRIVERS\TwoTrack.sys [2001-08-17 11520]
                        S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerflt.sys [2009-12-30 7936]
                        S3 usbprint;Classe d'imprimantes USB Microsoft; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
                        S3 usbscan;Pilote de scanneur USB; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
                        S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2008-04-13 26112]
                        S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-12-30 7936]
                        S3 USBSTOR;Pilote de stockage de masse USB; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
                        S3 usbvideo;Périphérique vidéo USB (WDM); C:\windows\System32\Drivers\usbvideo.sys [2008-04-13 121984]
                        S3 vsdatant;vsdatant; \??\C:\windows\system32\vsdatant.sys []
                        S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
                        S3 WSTCODEC;Codec Teletext standard; C:\windows\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
                        S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
                        S4 agp440;Filtre de bus AGP Intel; C:\windows\system32\DRIVERS\agp440.sys [2008-04-13 42368]
                        S4 agpCPQ;Filtre de bus AGP Compaq; C:\windows\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
                        S4 alim1541;Filtre de bus AGP ALI; C:\windows\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
                        S4 amdagp;Pilote de filtre du bus AMD AGP; C:\windows\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
                        S4 cbidf;cbidf; C:\windows\system32\DRIVERS\cbidf2k.sys [2001-08-18 13952]
                        S4 IntelIde;IntelIde; C:\windows\system32\DRIVERS\intelide.sys [2008-04-13 5504]
                        S4 sisagp;Filtre de bus AGP SIS; C:\windows\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
                        S4 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-04-01 691696]
                        S4 viaagp;Filtre de bus AGP VIA; C:\windows\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

                        ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                        R2 AntiVirSchedulerService;Avira AntiVir Planificateur; D:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-05-15 108289]
                        R2 AntiVirService;Avira AntiVir Guard; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-05-15 185089]
                        R2 ATService;AuthenTec Fingerprint Service; C:\WINDOWS\system32\AtService.exe [2009-03-19 1680632]
                        R2 Brother XP spl Service;BrSplService; C:\windows\system32\brsvc01a.exe [2002-04-12 57344]
                        R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
                        R2 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe [2008-03-28 342624]
                        R2 dtsvc;Data Transfer Service; C:\WINDOWS\system32\DTS.exe [2009-03-19 98304]
                        R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe [2006-12-19 94208]
                        R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2009-02-27 870672]
                        R2 IBMPMSVC;ThinkPad PM Service; C:\windows\system32\ibmpmsvc.exe [2008-02-20 36128]
                        R2 IviRegMgr;IviRegMgr; C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
                        R2 LMS;Intel(R) Active Management Technology Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2009-02-12 174616]
                        R2 McAfeeFramework;McAfee Framework Service; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [2006-11-17 104000]
                        R2 McShield;McAfee McShield; C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe [2006-11-30 144960]
                        R2 McTaskManager;McAfee Task Manager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [2006-11-30 54872]
                        R2 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE [2009-03-23 53248]
                        R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe [2009-02-27 473360]
                        R2 S24EventMonitor;Intel(R) PROSet/Wireless WiFi Service; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [2009-02-27 909312]
                        R2 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\windows\System32\TPHDEXLG.exe [2009-01-28 39976]
                        R2 UNS;Intel(R) Active Management Technology User Notification Service; C:\Program Files\Fichiers communs\Intel\Privacy Icon\UNS\UNS.exe [2009-02-12 2058776]
                        R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-01-26 652800]
                        R3 WSearch;Windows Search; C:\windows\system32\SearchIndexer.exe [2008-05-26 439808]
                        S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
                        S3 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2007-10-26 1524512]
                        S3 FingerprintServer;Fingerprint Server; C:\WINDOWS\system32\FpLogonServ.exe [2009-03-19 118784]
                        S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
                        S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
                        S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 29178224]
                        S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
                        S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
                        S3 SQLWriter;Enregistreur VSS SQL Server; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
                        S4 ADMonitor;AD Monitor; C:\WINDOWS\system32\ADMonitor.exe [2009-03-19 106496]
                        S4 aspnet_state;Service d'état ASP.NET; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
                        S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-09-17 153376]
                        S4 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
                        S4 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
                        S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
                        S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
                        S4 ProtexisLicensing;ProtexisLicensing; C:\windows\system32\PSIService.exe [2007-06-05 177704]
                        S4 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Fichiers communs\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
                        S4 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-09-23 358600]
                        S4 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-09-23 1141200]
                        S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2007-02-10 242544]
                        S4 StarWindServiceAE;StarWind AE Service; D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
                        S4 stllssvr;stllssvr; C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe [2008-03-24 74384]
                        S4 SUService;System Update; c:\program files\lenovo\system update\suservice.exe [2009-05-15 28672]
                        S4 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; c:\Program Files\Fichiers communs\Lenovo\tvt_reg_monitor_svc.exe [2008-06-13 746808]
                        S4 TpKmpSVC;IBM KCU Service; C:\windows\system32\TpKmpSVC.exe [2006-06-29 32768]
                        S4 TSSCoreService;TSS Core Service; C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe [2008-06-13 779576]
                        S4 TVT Scheduler;TVT Scheduler; c:\Program Files\Fichiers communs\Lenovo\Scheduler\tvtsched.exe [2008-11-24 1155072]
                        S4 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe []
                        S4 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-13 14336]

                        -----------------EOF-----------------

                        Le COMBOFIX est en cours de préparation ;-)
                        Merci à vous
                        1. ======List of files/folders created in the last 1 months======

                          2010-05-20 16:52:59 ----D---- C:\Program Files\trend micro
                          2010-05-19 08:44:29 ----SHD---- C:\RECYCLER
                          2010-05-18 08:54:09 ----A---- C:\ComboFix.txt
                          2010-05-18 08:33:29 ----D---- C:\combofix
                          2010-05-18 08:29:01 ----D---- C:\Qoobox
                          2010-05-17 08:28:54 ----HDC---- C:\windows\ie8
                          2010-05-16 20:06:45 ----HDC---- C:\windows\$NtUninstallKB978542$
                          2010-05-16 20:01:50 ----HDC---- C:\windows\$NtUninstallKB979306$
                          2010-05-16 20:01:33 ----A---- C:\windows\imsins.BAK
                          2010-05-16 19:57:32 ----N---- C:\windows\system32\browserchoice.exe
                          2010-05-15 22:42:56 ----RASHD---- C:\cmdcons
                          2010-05-15 22:40:00 ----A---- C:\windows\NIRCMD.exe
                          2010-05-15 22:40:00 ----A---- C:\windows\MBR.exe
                          2010-05-15 22:39:56 ----A---- C:\windows\zip.exe
                          2010-05-15 22:39:56 ----A---- C:\windows\SWXCACLS.exe
                          2010-05-15 22:39:56 ----A---- C:\windows\SWSC.exe
                          2010-05-15 22:39:56 ----A---- C:\windows\SWREG.exe
                          2010-05-15 22:39:56 ----A---- C:\windows\sed.exe
                          2010-05-15 22:39:56 ----A---- C:\windows\PEV.exe
                          2010-05-15 22:39:56 ----A---- C:\windows\grep.exe
                          2010-05-15 22:38:38 ----D---- C:\windows\ERDNT
                          2010-05-15 19:01:10 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
                          2010-05-15 06:42:31 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Malwarebytes
                          2010-05-15 06:42:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                          2010-05-15 06:42:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
                          2010-05-15 06:27:27 ----D---- C:\Program Files\ZHPDiag
                          2010-05-14 22:51:04 ----N---- C:\windows\system32\MpSigStub.exe
                          2010-05-14 22:29:11 ----RAD---- C:\autorun.inf
                          2010-05-14 09:33:58 ----A---- C:\windows\monitor.INI
                          2010-05-14 08:18:49 ----D---- C:\Program Files\Lavasoft
                          2010-05-14 08:18:49 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
                          2010-05-14 07:51:27 ----D---- C:\Program Files\Windows Live Safety Center
                          2010-05-14 00:23:52 ----D---- C:\windows\SoftwareDistribution
                          2010-05-13 23:47:51 ----A---- C:\windows\system32\ztvunrar36.dll
                          2010-05-13 23:47:51 ----A---- C:\windows\system32\ztvunace26.dll
                          2010-05-13 23:47:51 ----A---- C:\windows\system32\ztvcabinet.dll
                          2010-05-13 23:47:50 ----A---- C:\windows\system32\UNRAR3.dll
                          2010-05-13 23:47:50 ----A---- C:\windows\system32\unacev2.dll
                          2010-05-13 23:47:47 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Simply Super Software
                          2010-05-13 23:47:47 ----D---- C:\Documents and Settings\All Users\Application Data\Simply Super Software
                          2010-05-13 23:22:31 ----D---- C:\rsit
                          2010-05-13 20:21:41 ----HD---- C:\windows\msdownld.tmp
                          2010-05-13 19:07:09 ----D---- C:\windows\SoftwareDistribution.old
                          2010-05-13 15:26:24 ----A---- C:\windows\SGDetectionTool.dll
                          2010-05-13 15:26:24 ----A---- C:\windows\PCTBDRes.dll
                          2010-05-13 15:26:24 ----A---- C:\windows\PCTBDCore.dll.old
                          2010-05-13 15:26:24 ----A---- C:\windows\PCTBDCore.dll
                          2010-05-13 15:26:24 ----A---- C:\windows\BDTSupport.dll.old
                          2010-05-13 15:26:24 ----A---- C:\windows\BDTSupport.dll
                          2010-05-13 15:13:46 ----D---- C:\Program Files\Spyware Doctor
                          2010-05-13 15:13:46 ----D---- C:\Program Files\Fichiers communs\PC Tools
                          2010-05-13 15:13:46 ----D---- C:\Documents and Settings\All Users\Application Data\PC Tools
                          2010-05-13 10:13:54 ----D---- C:\Program Files\DivX
                          2010-05-13 10:05:36 ----D---- C:\Documents and Settings\All Users\Application Data\DivX
                          2010-05-03 22:07:39 ----D---- C:\Program Files\Rallentando Software
                          2010-05-03 19:08:23 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Music Recognition
                          2010-04-30 18:46:24 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Thinstall
                          2010-04-28 00:39:54 ----A---- C:\windows\iun6002.exe
                          2010-04-27 22:25:13 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\REAPER
                          2010-04-27 22:08:38 ----A---- C:\windows\uninst.exe
                          2010-04-26 16:25:24 ----A---- C:\windows\DMN.INI
                          2010-04-26 16:24:38 ----D---- C:\Program Files\Yamaha Corporation
                          2010-04-26 13:41:07 ----A---- C:\windows\system32\VBHLP32.DLL
                          2010-04-26 13:41:06 ----A---- C:\windows\system32\VBALNCSM6.DLL
                          2010-04-26 13:41:06 ----A---- C:\windows\system32\SSUBTMR6.DLL

                          ======List of files/folders modified in the last 1 months======

                          2010-05-20 16:53:01 ----D---- C:\windows\Prefetch
                          2010-05-20 16:52:59 ----RD---- C:\Program Files
                          2010-05-20 16:52:33 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
                          2010-05-20 16:15:22 ----D---- C:\windows\Temp
                          2010-05-20 15:31:54 ----AD---- C:\windows\system32
                          2010-05-19 12:31:30 ----A---- C:\windows\ModemLog_Nokia N97 Bluetooth Modem.txt
                          2010-05-19 08:41:30 ----D---- C:\windows\system32\CatRoot2
                          2010-05-19 08:39:56 ----A---- C:\windows\system32\log.txt
                          2010-05-19 08:37:51 ----A---- C:\windows\SchedLgU.Txt
                          2010-05-18 15:05:50 ----AD---- C:\WINDOWS
                          2010-05-18 08:48:50 ----A---- C:\windows\system.ini
                          2010-05-18 08:41:53 ----D---- C:\windows\system32\drivers
                          2010-05-18 08:41:52 ----D---- C:\windows\AppPatch
                          2010-05-18 08:41:34 ----D---- C:\Program Files\Fichiers communs
                          2010-05-18 08:36:40 ----D---- C:\QUARANTINE
                          2010-05-17 21:33:06 ----HD---- C:\windows\inf
                          2010-05-17 21:23:31 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\uTorrent
                          2010-05-17 20:35:51 ----SHD---- C:\windows\CSC
                          2010-05-17 17:37:47 ----SHD---- C:\windows\Installer
                          2010-05-17 10:32:07 ----D---- C:\Program Files\Internet Explorer
                          2010-05-17 10:26:10 ----D---- C:\windows\system32\CatRoot
                          2010-05-17 10:25:44 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
                          2010-05-17 10:24:16 ----ASHD---- C:\windows\system32\dllcache
                          2010-05-17 10:24:12 ----D---- C:\windows\ie8updates
                          2010-05-17 10:16:53 ----RSD---- C:\windows\assembly
                          2010-05-17 10:12:36 ----D---- C:\windows\WinSxS
                          2010-05-17 08:37:32 ----ASH---- C:\boot.ini
                          2010-05-17 08:37:32 ----A---- C:\windows\win.ini
                          2010-05-17 08:33:07 ----D---- C:\windows\system32\fr-fr
                          2010-05-17 08:33:06 ----D---- C:\windows\Media
                          2010-05-17 08:33:05 ----D---- C:\windows\Help
                          2010-05-16 20:06:48 ----D---- C:\Program Files\Outlook Express
                          2010-05-16 20:02:50 ----D---- C:\windows\Debug
                          2010-05-16 20:00:14 ----HD---- C:\windows\$hf_mig$
                          2010-05-16 18:32:48 ----HD---- C:\Program Files\InstallShield Installation Information
                          2010-05-16 11:04:10 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
                          2010-05-16 10:51:43 ----DC---- C:\windows\system32\DRVSTORE
                          2010-05-15 22:39:45 ----SHD---- C:\System Volume Information
                          2010-05-15 22:39:45 ----D---- C:\windows\system32\Restore
                          2010-05-15 11:57:02 ----D---- C:\windows\pss
                          2010-05-14 22:39:31 ----A---- C:\windows\system32\PerfStringBackup.INI
                          2010-05-14 22:32:16 ----D---- C:\UsbFix
                          2010-05-14 10:09:32 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\webex
                          2010-05-14 10:08:33 ----SD---- C:\windows\Downloaded Program Files
                          2010-05-13 19:10:38 ----D---- C:\windows\network diagnostic
                          2010-05-13 11:01:36 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\DivX
                          2010-05-13 10:19:11 ----D---- C:\Program Files\Fichiers communs\DivX Shared
                          2010-05-08 17:58:46 ----D---- C:\Program Files\IK Multimedia
                          2010-05-04 19:41:46 ----A---- C:\windows\demdata.txt
                          2010-05-03 22:07:43 ----RSD---- C:\windows\Fonts
                          2010-05-03 19:16:25 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Help
                          2010-04-30 11:51:08 ----A---- C:\windows\system32\MRT.exe
                          1. Contributeur sécurité
                            slt

                            j'ai ecrit => Blueway poste ce rapport

                            C:/combofix.txt et celui de TDSS remover stp

                            de plus le rapport que tu poste n'est pas entier car trop long, tu le repostera en ^pasant par Cijoint => http://www.cijoint.fr/
                            1. ======Scheduled tasks folder======

                              C:\windows\tasks\PCDoctorBackgroundMonitorTask.job
                              C:\windows\tasks\PMTask.job
                              C:\windows\tasks\Vérifier les mises à jour de Windows Live Toolbar.job
                              C:\windows\tasks\WGASetup.job

                              ======Registry dump======

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                              Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-04-02 61888]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
                              PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
                              Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
                              scriptproxy - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll [2006-11-30 67136]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
                              Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
                              Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 546672]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF468356-BB7E-42D7-9F15-4F3B9BCFCED2}]
                              IePasswordManagerHelper Class - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll [2008-06-13 808248]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                              Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-17 41760]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
                              JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-09-17 73728]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
                              EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-21 368640]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                              {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 546672]
                              {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-21 368640]
                              {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]
                              {472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                              "TPFNF7"=C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe [2009-01-07 60704]
                              "TpShocks"=C:\windows\system32\TpShocks.exe [2009-02-02 181536]
                              "snp2uvc"=C:\WINDOWS\vsnp2uvc.exe [2006-12-28 569344]
                              "TPHOTKEY"=C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2008-09-30 68976]
                              "EZEJMNAP"=C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2008-10-08 256576]
                              "Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2008-03-07 167936]
                              "FingerPrintSoftware"=C:\Program Files\Lenovo Fingerprint Software\fpapp.exe [2009-03-19 12095488]
                              "CameraApplicationLauncher"=C:\Program Files\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe [2008-08-12 16384]
                              "PWRMGRTR"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor []
                              "BLOG"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog []
                              "TrackPointSrv"=C:\Program Files\Lenovo\TrackPoint\tp4serv.exe [2009-01-26 92960]
                              "picon"=C:\Program Files\Fichiers communs\Intel\Privacy Icon\PrivacyIconClient.exe [2009-02-12 357400]
                              "ShStatEXE"=C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [2006-11-30 112216]
                              "McAfeeUpdaterUI"=C:\Program Files\McAfee\Common Framework\UdaterUI.exe [2006-11-17 136768]
                              "EEventManager"=C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe [2009-01-12 669520]
                              "SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
                              "avgnt"=D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
                              "QuickTime Task"=D:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]

                              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                              "PC Suite Tray"=D:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]
                              "ctfmon.exe"=C:\windows\system32\ctfmon.exe [2008-04-13 15360]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
                              C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
                              C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2010-04-02 40368]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
                              D:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMSG]
                              C:\Program Files\ThinkVantage\AMSG\Amsg.exe [2007-02-01 419376]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserChoice]
                              C:\windows\system32\browserchoice.exe [2010-02-12 293376]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreateLMBCShortCut]
                              C:\Program Files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe [2009-01-21 36864]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cssauth]
                              C:\Program Files\Lenovo\Client Security Solution\cssauth.exe [2008-06-13 3073336]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
                              C:\windows\system32\ctfmon.exe [2008-04-13 15360]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM]
                              C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [2009-02-06 843776]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
                              C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
                              C:\windows\system32\hkcmd.exe [2008-10-30 178712]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
                              C:\windows\system32\igfxtray.exe [2008-10-30 150040]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPMailChecker]
                              C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe [2009-01-29 124248]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
                              C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe [2009-01-29 185688]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
                              C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer /watchfiles startup []

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
                              C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe [2009-11-06 2090272]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
                              D:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
                              C:\windows\system32\igfxpers.exe [2008-10-30 150040]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                              D:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                              C:\Program Files\Java\jre6\bin\jusched.exe [2009-09-17 149280]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPHELPER]
                              C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe [2007-01-09 868352]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
                              D:\Program Files\Trojan Remover\Trjscan.exe [2009-08-04 1068424]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
                              C:\Program Files\Fichiers communs\Lenovo\Scheduler\scheduler_proxy.exe [2008-11-24 487424]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
                              C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-03 204288]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Acrobat Assistant.lnk]
                              C:\PROGRA~1\Adobe\ACROBA~1.0\Distillr\AcroTray.exe []

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
                              C:\PROGRA~1\ThinkPad\BLUETO~1\BTTray.exe [2008-03-28 596584]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Digital Line Detect.lnk]
                              C:\PROGRA~1\DIGITA~1\DLG.exe [2006-11-03 50688]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Post-it® Software Notes Lite.lnk]
                              C:\PROGRA~1\3M\PSNLite\PsnLite.exe [2004-10-15 2080768]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^RCIMGDIR.exe.lnk]
                              C:\PROGRA~1\ROTATE~1\RCIMGDIR.exe [2008-06-12 31744]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^VPN Client.lnk]
                              C:\windows\Installer\{871DF2BE-41D2-4334-AC33-839AF16FC8FE}\Icon3E5562ED7.ico [2009-06-29 6144]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Search.lnk]
                              C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                              "DWMRCS"=2
                              "SUService"=2
                              "stllssvr"=3
                              "StarWindServiceAE"=2
                              "sdCoreService"=3
                              "sdAuxService"=3
                              "SCardSvr"=2
                              "RoxMediaDB10"=3
                              "ProtexisLicensing"=2
                              "mnmsrvc"=3
                              "Microsoft Office Groove Audit Service"=3
                              "MDM"=3
                              "JavaQuickStarterService"=2
                              "COMSysApp"=2
                              "aspnet_state"=3
                              "WudfSvc"=2
                              "TVT Scheduler"=2
                              "TSSCoreService"=2
                              "ThinkVantage Registry Monitor Service"=3
                              "WMPNetworkSvc"=2
                              "TpKmpSVC"=2
                              "ADMonitor"=3

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ATFUS]
                              C:\WINDOWS\system32\FpWinLogonNp.dll [2009-03-19 180224]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
                              C:\windows\system32\igfxdev.dll [2008-10-21 217088]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2]
                              C:\Program Files\Lenovo\HOTKEY\notifyf2.dll [2006-09-06 34344]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
                              C:\Program Files\Lenovo\HOTKEY\tphklock.dll [2008-08-08 28672]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
                              WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2006-10-18 133632]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                              "{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
                              "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdauxservice]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdcoreservice]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                              "dontdisplaylastusername"=0
                              "legalnoticecaption"=
                              "legalnoticetext"=
                              "shutdownwithoutlogon"=1
                              "undockwithoutlogon"=1

                              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                              "NoDriveTypeAutoRun"=323
                              "NoDriveAutoRun"=67108863
                              "HonorAutoRunSetting"=0
                              "NoDrives"=0

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                              "HonorAutoRunSetting"=
                              "NoDriveAutoRun"=
                              "NoDriveTypeAutoRun"=
                              "NoDrives"=

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                              "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                              "C:\Program Files\McAfee\Common Framework\FrameworkService.exe"="C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service"
                              "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                              "D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
                              "C:\Program Files\TeamViewer\Version4\TeamViewer.exe"="C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
                              "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"="C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Disabled:EEventManager Application"
                              "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                              "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                              "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                              "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
                              "C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
                              "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
                              "D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
                              "C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
                              "D:\Program Files\CounterPath\X-Lite\x-lite.exe"="D:\Program Files\CounterPath\X-Lite\x-lite.exe:*:Enabled:X-Lite"
                              1. Voilà le rapport RSIT

                                Logfile of random's system information tool 1.07 (written by random/random)
                                Run by DMartiano at 2010-05-20 16:52:58
                                Microsoft Windows XP Professionnel Service Pack 3
                                System drive C: has 29 GB (45%) free of 64 GB
                                Total RAM: 3032 MB (53% free)

                                Logfile of Trend Micro HijackThis v2.0.4
                                Scan saved at 16:53:28, on 20/05/2010
                                Platform: Windows XP SP3 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                Boot mode: Normal

                                Running processes:
                                C:\windows\System32\smss.exe
                                C:\windows\system32\winlogon.exe
                                C:\windows\system32\services.exe
                                C:\windows\system32\lsass.exe
                                C:\WINDOWS\system32\DTS.exe
                                C:\windows\system32\ibmpmsvc.exe
                                C:\WINDOWS\system32\AtService.exe
                                C:\windows\system32\svchost.exe
                                C:\windows\System32\svchost.exe
                                C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
                                C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
                                C:\windows\system32\brsvc01a.exe
                                C:\windows\system32\spoolsv.exe
                                C:\windows\system32\brss01a.exe
                                D:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
                                D:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
                                C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                                C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
                                C:\Program Files\Intel\AMT\LMS.exe
                                C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                                C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                                C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                                C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
                                C:\windows\system32\svchost.exe
                                C:\windows\System32\TPHDEXLG.exe
                                C:\Program Files\Fichiers communs\Intel\Privacy Icon\UNS\UNS.exe
                                C:\windows\system32\ctfmon.exe
                                C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
                                C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe
                                C:\windows\system32\TpShocks.exe
                                C:\WINDOWS\vsnp2uvc.exe
                                C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
                                C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
                                C:\windows\system32\rundll32.exe
                                C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
                                C:\Program Files\McAfee\Common Framework\UdaterUI.exe
                                C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
                                C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
                                D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\Program Files\Lenovo\Zoom\TpScrex.exe
                                C:\Program Files\McAfee\Common Framework\McTray.exe
                                C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                C:\windows\system32\SearchIndexer.exe
                                C:\windows\system32\igfxext.exe
                                C:\windows\system32\igfxsrvc.exe
                                C:\windows\System32\svchost.exe
                                C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
                                C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
                                C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
                                C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE
                                D:\Program Files\Avira\AntiVir Desktop\avcenter.exe
                                C:\windows\explorer.exe
                                C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
                                D:\Program Files\Avira\AntiVir Desktop\avscan.exe
                                C:\windows\system32\rundll32.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Documents and Settings\DMARTIANO\Bureau\Outils\CLEAN\RSIT.exe
                                C:\windows\system32\SearchProtocolHost.exe
                                C:\Program Files\trend micro\DMartiano.exe
                                1. Désolé les amis,
                                  j'étais en mission pour 3 jours je viens de rentrer.
                                  Oulala ... vous me fichez la trouille ... bon je suis blonde mais n'en profitez pas ;-)
                                  Le COMBOFIX est en cours de préparation ;-)

                                  Merci à vous
                                  1. Contributeur
                                    Salut,

                                    Bon ... tu te debrouillera mieux que moi Plopus, je te laisse faire :)

                                    ++
                                    1. Contributeur
                                      Salut
                                      Attention si tu garde plus d'un antivirus en même temps, choisi un SEUL et supprime les autres (conseil : Avira)
                                      Et puis, si tu n'a pas analysé tes rapports ... en plus qu'on utilise pas ces outils sans une demande par une personne qualifiée !!
                                      Alors je crois que tu dois quand même poster un rapport RSIT puisqu'il n'est vraiment pas sur que ton PC soit vraiment clean

                                      ++
                                      1. Bonjour,
                                        après une longue nuit ...
                                        J'ai lancé Combofix, puis TDDS Remover, puis re Combofix.

                                        Pb résolu !

                                        Avira, clean
                                        Macafee clean
                                        Microsoft one care live .... clean

                                        Karel et Nydarion : MERCI
                                        • 1
                                        • 2