Finalement, ça a fini par marcher et voilà le rapport :
ComboFix 09-01-17.04 - Antoine 2009-01-18 20:14:36.1 - NTFSx86 NETWORK
Microsoft® Windows Vista™ Professionnel 6.0.6001.1.1252.1.1036.18.3581.2873 [GMT 1:00]
Lancé depuis: C:\Users\Antoine\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-18 au 2009-01-18 ))))))))))))))))))))))))))))))))))))
.
2009-01-18 17:41 . 2009-01-18 17:41 <REP> d-------- C:\Users\All Users\Avira
2009-01-18 17:41 . 2009-01-18 17:41 <REP> d-------- C:\Program Files\Avira
2009-01-18 17:41 . 2009-01-18 17:41 <REP> d-------- C:\PROGRA~2\Avira
2009-01-17 18:05 . 2009-01-17 18:05 <REP> d-------- C:\Users\Antoine\AppData\Roaming\PC Tools
2009-01-17 18:05 . 2009-01-17 18:22 <REP> d-------- C:\Program Files\Spyware Doctor
2009-01-17 18:05 . 2008-08-25 12:36 81,288 --a------ C:\Windows\System32\drivers\iksyssec.sys
2009-01-17 18:05 . 2008-08-25 12:36 66,952 --a------ C:\Windows\System32\drivers\iksysflt.sys
2009-01-17 18:05 . 2008-08-25 12:36 40,840 --a------ C:\Windows\System32\drivers\ikfilesec.sys
2009-01-17 18:05 . 2008-06-02 16:19 29,576 --a------ C:\Windows\System32\drivers\kcom.sys
2009-01-14 15:30 . 2009-01-14 15:30 <REP> d-------- C:\Program Files\Codemasters
2009-01-14 14:39 . 2009-01-14 14:39 <REP> d-------- C:\Users\Antoine\AppData\Roaming\Sierra Entertainment
2009-01-14 14:39 . 2009-01-14 14:39 <REP> dr-h----- C:\Users\Antoine\AppData\Roaming\SecuROM
2009-01-14 14:36 . 2009-01-14 14:36 <REP> d-------- C:\Windows\System32\AGEIA
2009-01-14 14:36 . 2009-01-14 14:36 <REP> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2009-01-14 14:36 . 2009-01-14 14:36 <REP> d-------- C:\Program Files\AGEIA Technologies
2009-01-14 14:23 . 2009-01-14 14:23 <REP> d-------- C:\Program Files\Sierra Entertainment
2009-01-14 02:18 . 2008-12-16 03:42 288,768 --a------ C:\Windows\System32\drivers\srv.sys
2009-01-10 16:56 . 2009-01-10 16:56 <REP> d-------- C:\Users\All Users\Adobe Systems
2009-01-10 16:56 . 2009-01-10 16:56 <REP> d-------- C:\PROGRA~2\Adobe Systems
2009-01-10 16:52 . 2009-01-10 16:52 <REP> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2009-01-10 16:31 . 2009-01-10 16:31 <REP> d-------- C:\Program Files\Wolfenstein - Enemy Territory
2009-01-10 15:54 . 2009-01-10 15:54 <REP> d-------- C:\Program Files\Common Files\Macrovision Shared
2009-01-09 21:35 . 2007-05-08 09:41 44,814,336 --a------ C:\Photoshop.exe
2009-01-09 12:51 . 2009-01-18 20:27 <REP> d-------- C:\Users\Antoine\Tracing
2009-01-09 12:49 . 2009-01-09 12:49 <REP> d-------- C:\Program Files\Windows Live SkyDrive
2009-01-09 12:49 . 2009-01-09 12:49 <REP> d-------- C:\Program Files\Microsoft
2009-01-09 12:40 . 2009-01-09 12:40 <REP> d-------- C:\Program Files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 19:25 --------- d---a-w C:\PROGRA~2\TEMP
2009-01-17 18:29 27,525 ----a-w C:\Users\Antoine\AppData\Roaming\nvModes.dat
2009-01-17 18:06 --------- d-----w C:\Program Files\Yahoo!
2009-01-17 13:54 --------- d-----w C:\Users\Antoine\AppData\Roaming\LimeWire
2009-01-15 11:08 --------- d-----w C:\PROGRA~2\Microsoft Help
2009-01-14 15:56 --------- d-----w C:\PROGRA~2\TrackMania
2009-01-14 14:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2009-01-14 10:04 --------- d-----w C:\Program Files\Windows Mail
2009-01-10 15:53 --------- d-----w C:\Program Files\Common Files\Adobe
2009-01-09 11:50 --------- d-----w C:\Program Files\Windows Live
2009-01-09 11:04 --------- d-----w C:\Program Files\McAfee
2009-01-03 20:21 --------- d-----w C:\PROGRA~2\Lx_cats
2008-12-12 21:59 --------- d-----w C:\Users\Antoine\AppData\Roaming\DivX
2008-12-02 21:37 49,480 ----a-w C:\Windows\System32\sirenacm.dll
2008-12-02 15:38 --------- d-----w C:\Program Files\QuickTime
2008-12-02 14:52 --------- d-----w C:\PROGRA~2\ArcSoft
2008-12-01 06:25 --------- d-----w C:\Users\Antoine\AppData\Roaming\ArcSoft
2008-11-30 20:07 --------- d-----w C:\Program Files\Common Files\ArcSoft
2008-11-30 20:03 --------- d-----w C:\Program Files\ArcSoft
2008-11-30 20:02 --------- d-----w C:\Users\Antoine\AppData\Roaming\Panasonic
2008-11-30 19:58 --------- d-----w C:\Program Files\Panasonic
2008-11-29 20:04 --------- d-----w C:\Program Files\iTunes
2008-11-29 20:04 --------- d-----w C:\Program Files\iPod
2008-11-29 20:04 --------- d-----w C:\Program Files\Common Files\Apple
2008-11-29 20:04 --------- d-----w C:\PROGRA~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-29 19:52 --------- d-----w C:\Program Files\Safari
2008-11-23 21:45 --------- d-----w C:\Program Files\Activision
2008-11-20 08:45 --------- d-----w C:\Program Files\CCleaner
2008-11-01 03:44 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 ----a-w C:\Windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 ----a-w C:\Windows\explorer.exe
2008-10-22 03:57 241,152 ----a-w C:\Windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-10-21 05:25 296,960 ----a-w C:\Windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 ----a-w C:\Windows\System32\connect.dll
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2008-12-02 22:41 3882312]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 03:25 202240]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-24 16:02 490952]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2008-08-01 18:41 5480448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-09-25 12:35 159744]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-01-03 19:05 405504]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-03 10:52 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-03 10:51 8478720]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-03 10:52 81920]
"NVHotkey"="C:\Windows\system32\nvHotkey.dll" [2007-12-03 10:52 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 03:27 144784]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 12:37 174872]
"WavXMgr"="C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2007-09-10 08:54 85504]
"SecureUpgrade"="C:\Program Files\Wave Systems Corp\SecureUpgrade.exe" [2007-09-14 09:53 218424]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 21:33 582992]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 09:57 128296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 01:38 34672]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 19:12 111936]
"lxdfmon.exe"="C:\Program Files\Lexmark 6500 Series\lxdfmon.exe" [2007-06-11 14:53 455600]
"lxdfamon"="C:\Program Files\Lexmark 6500 Series\lxdfamon.exe" [2007-06-01 09:06 20480]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-11-20 13:20 290088]
"ArcSoft Connection Service"="C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 10:06 178688]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 15:09 413696]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-08-25 12:36 1168264]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 13:28 266497]
C:\Users\Antoine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
Outil de notification Live Search.lnk - C:\Users\Antoine\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe [2009-01-09 12:39:34 143360]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-07-29 23:19:30 50688]
NDAS Device Management.lnk - C:\Program Files\NDAS\System\ndasmgmt.exe [2007-06-29 17:32:50 236520]
PHOTOfunSTUDIO -viewer-.lnk - C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe [2008-11-30 20:58:43 40960]
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2008-02-22 16:01:38 1193240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gemsafe]
2006-11-16 14:20 73728 C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{65697C36-ADAD-4E8B-BFF1-285E86A56FE3}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{FCE83088-6406-4657-AFA3-B06D7EA83DEE}"= C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:CyberLink PowerDVD DX
"{F675D52E-C14D-4DA3-AF3B-5DEF8927D4C3}"= C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:CyberLink PowerDVD DX Resident Program
"{C5B0E133-8EDA-45F5-800C-45B2ED5B4481}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{FCA79E25-DDA2-42C4-8964-C5B2CE560138}"= UDP:4662:emule
"{C40F5050-B028-45A2-9339-18A4FC7E4C6A}"= TCP:4672:emule2
"{C8663DBA-AF31-4972-94AE-343310F97238}"= UDP:C:\Program Files\Lexmark 6500 Series\lxdfamon.exe:Lexmark Device Monitor
"{FA0140C8-F719-46DD-94AB-1EEDBF41CDD3}"= TCP:C:\Program Files\Lexmark 6500 Series\lxdfamon.exe:Lexmark Device Monitor
"{5B7B5113-F10C-4F48-A137-F67734E5E87D}"= UDP:C:\Program Files\Lexmark 6500 Series\frun.exe:Lexmark Productivity Studio
"{522C3276-7E85-44E9-BCF9-3B81913761E0}"= TCP:C:\Program Files\Lexmark 6500 Series\frun.exe:Lexmark Productivity Studio
"{CAE87021-BCAB-483E-84BC-FE98CB7E03BC}"= UDP:C:\Program Files\Lexmark 6500 Series\lxdfmon.exe:Printer Device Monitor
"{4C90EF04-90A9-4E3B-9991-36DDEB67C7AD}"= TCP:C:\Program Files\Lexmark 6500 Series\lxdfmon.exe:Printer Device Monitor
"{CE69D490-C139-481B-9296-3B04EB15CED0}"= UDP:C:\Windows\System32\lxdfcfg.exe:Printer Communication System
"{9277D569-05E7-4BBB-9EE7-D960C432DC29}"= TCP:C:\Windows\System32\lxdfcfg.exe:Printer Communication System
"{7BD9F7C4-7996-4552-88F6-3E723903F459}"= UDP:C:\Windows\System32\lxdfcoms.exe:Lexmark Communications System
"{D40FE480-9589-4F6C-A849-949F374DE7A8}"= TCP:C:\Windows\System32\lxdfcoms.exe:Lexmark Communications System
"{49C85113-8F7E-4062-B109-3469F245CE03}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxdfpswx.exe:Printer Status Window Interface
"{025954EE-8894-432A-87FC-EC1C77C0A996}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxdfpswx.exe:Printer Status Window Interface
"{0DDBE590-7792-4A90-BBE8-997294EE2A02}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxdftime.exe:Lexmark Connect Time Executable
"{A1534C49-EF09-4038-A5B9-DC6FC0F927CD}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxdftime.exe:Lexmark Connect Time Executable
"{AE9E654A-1197-4C1C-BEA6-2AA451D0DC9E}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxdfjswx.exe:Job Status Window Interface
"{BF3F04DA-4023-41C3-99CB-759CBF2F784D}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxdfjswx.exe:Job Status Window Interface
"{8917B9F8-A239-4630-810F-D2B620E630AE}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{EC03F0C4-7A2A-417C-B6C7-BEE4CC974E0E}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{5818EBA1-E879-47F8-887E-C76D17D2BBD2}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{32902A13-3351-4EFD-8EF4-AEA7FDCE5EF8}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{3C6A28CA-D69E-4BD8-996E-4AC8BD8E0DB6}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{1C20E501-8B21-4E03-BA0A-FB0EB37969F8}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{AC843EB2-3E3F-41A2-9B5B-24939BA841F6}C:\\program files\\tmnationsforever\\tmforever.exe"= UDP:C:\program files\tmnationsforever\tmforever.exe:TmForever
"UDP Query User{6DD79A23-0FA4-420B-AD51-2A9B01CDCD20}C:\\program files\\tmnationsforever\\tmforever.exe"= TCP:C:\program files\tmnationsforever\tmforever.exe:TmForever
"{311CF82D-DE06-4F7F-BE05-CE6AF485653C}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{327FBDE9-0BAA-42D5-A943-02100BD7A44A}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{D043C281-1E29-4E9D-8D53-7785948DC4A4}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{53CB481D-B191-4057-8DE9-A41FF4DD87BA}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{E526CDA8-EB01-4CEB-83AA-724C56452E5A}C:\\program files\\wolfenstein - enemy territory\\et.exe"= UDP:C:\program files\wolfenstein - enemy territory\et.exe:ET
"UDP Query User{CF93B83C-77DA-4A2A-B716-44FB6371E136}C:\\program files\\wolfenstein - enemy territory\\et.exe"= TCP:C:\program files\wolfenstein - enemy territory\et.exe:ET
"{50F2C94E-C8EE-4D74-9D51-B6DECD6488F5}"= UDP:C:\Program Files\Sierra Entertainment\Empire Earth III\EE3.exe:Empire Earth III
"{AFAE53ED-C9B6-4C8C-9E23-EA6C6994C826}"= TCP:C:\Program Files\Sierra Entertainment\Empire Earth III\EE3.exe:Empire Earth III
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R2 lxdfCATSCustConnectService;lxdfCATSCustConnectService;C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdfserv.exe [2007-05-29 07:06 99248]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-03-19 07:44 179712]
R3 BTHFILT;Filtre de commande Bluetooth;C:\Windows\system32\DRIVERS\BthFilt.sys [2007-05-05 18:51 13824]
R3 ggflt;SEMC USB Flash Driver Filter;C:\Windows\system32\DRIVERS\ggflt.sys [2008-09-30 07:05 13352]
R3 ndasscsi;NDAS SCSI Miniport Driver;C:\Windows\system32\DRIVERS\ndasscsi.sys [2007-06-29 17:32 187368]
R3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys [2006-11-28 20:46 28224]
S0 lfsfilt;Lean File Sharing;C:\Windows\system32\DRIVERS\lfsfilt.sys [2007-06-29 17:32 254440]
S0 lpx;LPX Protocol;C:\Windows\system32\DRIVERS\lpx.sys [2007-06-29 17:32 62056]
S1 ndasfat;NDAS FAT;C:\Windows\system32\DRIVERS\ndasfat.sys [2007-06-29 17:32 372584]
S2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe [2006-12-19 13:21 79432]
S2 BthFilterHelper;Bluetooth Feature Support;C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe [2006-11-07 17:26 127488]
S2 lxdf_device;lxdf_device;C:\Windows\system32\lxdfcoms.exe [2007-05-29 07:06 598960]
S3 ndasbus;NDAS Bus Driver;C:\Windows\system32\DRIVERS\ndasbus.sys [2007-06-29 17:32 75880]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - fastfat
*Deregistered* - FileInfo
*Deregistered* - FltMgr
*Deregistered* - HTTP
*Deregistered* - iaStorV
*Deregistered* - IKFileSec
*Deregistered* - IKSysFlt
*Deregistered* - IKSysSec
*Deregistered* - intelide
*Deregistered* - IpFilterDriver
*Deregistered* - iScsiPrt
*Deregistered* - KSecDD
*Deregistered* - lfsfilt
*Deregistered* - lltdio
*Deregistered* - lpx
*Deregistered* - luafv
*Deregistered* - mchInjDrv
*Deregistered* - mfeavfk
*Deregistered* - mfebopk
*Deregistered* - mfehidk
*Deregistered* - mfesmfk
*Deregistered* - MountMgr
*Deregistered* - MPFP
*Deregistered* - mpsdrv
*Deregistered* - MRxDAV
*Deregistered* - mrxsmb
*Deregistered* - mrxsmb10
*Deregistered* - mrxsmb20
*Deregistered* - Msfs
*Deregistered* - msisadrv
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NativeWifiP
*Deregistered* - ndasbus
*Deregistered* - ndasfat
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - netbt
*Deregistered* - Npfs
*Deregistered* - nsiproxy
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PBADRV
*Deregistered* - PEAUTH
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - RasSstp
*Deregistered* - rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RDPENCDD
*Deregistered* - rspndr
*Deregistered* - secdrv
*Deregistered* - Smb
*Deregistered* - spldr
*Deregistered* - sptd
*Deregistered* - srv
*Deregistered* - srv2
*Deregistered* - srvnet
*Deregistered* - ssmdrv
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - tcpipreg
*Deregistered* - tdx
*Deregistered* - TermDD
*Deregistered* - tunmp
*Deregistered* - tunnel
*Deregistered* - udfs
*Deregistered* - umbus
*Deregistered* - VgaSave
*Deregistered* - volmgr
*Deregistered* - volmgrx
*Deregistered* - volsnap
*Deregistered* - Wanarpv6
*Deregistered* - WavxDMgr
*Deregistered* - Wdf01000
*Deregistered* - XAudio
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\shell\AutoRun\command - E:\EE3AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{64d5ba2c-6bae-11dd-a18f-0021864817f9}]
\shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{72b31a88-5dca-11dd-bb50-806e6f6e6963}]
\shell\AutoRun\command - E:\EE3AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5e1991e-b348-11dd-b47c-0021864817f9}]
\shell\AutoRun\command - G:\setup\rsrc\Autorun.exe
\shell\dinstall\command - G:\Directx\dxsetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5e19965-b348-11dd-b47c-0021864817f9}]
\shell\AutoRun\command - H:\setup\rsrc\Autorun.exe
\shell\dinstall\command - H:\Directx\dxsetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d39b2317-d984-11dd-a7ab-0021706d2de7}]
\shell\AutoRun\command - F:\Autorun.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-Wdf01000.sys
.
------- Examen supplémentaire -------
.
mStart Page =
hxxp://www.ustart.org
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone:
www.orange.fr
C:\Windows\Downloaded Program Files\ewidoOnlineScan.dll - O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1}
hxxp://downloads.ewido.net/ewidoOnlineScan.cab
FF - ProfilePath - C:\Users\Antoine\AppData\Roaming\Mozilla\Firefox\Profiles\u8g7tfvb.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/ig
FF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q=
FF - component: C:\Program Files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
.