cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:17-12-2015
Exécuté par Kevin Clickoo (administrateur) sur CLICKOO-KEVIN (17-12-2015 10:34:39)
Exécuté depuis C:\Users\Kevin Clickoo\Desktop
Profils chargés: Kevin Clickoo (Profils disponibles: Kevin Clickoo)
Platform: Windows 10 Home (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(PointGrab LTD) C:\Program Files (x86)\PointGrab\Hand Gesture Control\PGService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Key Suite\AsKeySuite.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\NFC Express\DTNFCServer.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Power Manager\Power Manager_background.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{9AF45D7C-34F1-4BA0-B799-825C8C04494C}\AiChargerDT.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Ai Charger II\Ai_ChargerII_TrayIcon(ASUS_Manager).exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\SyncUp\Server\SyncUp Server.exe
() C:\Program Files (x86)\ASUS\ASUS Manager\PC Cleanup\SecureDeleteBackground.exe
() C:\Program Files (x86)\ASUS\ASUS Manager\NFC Express\DT_NFCExpressDesktops.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6416.42001.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Atheros) C:\Program Files (x86)\Qualcomm Atheros\AWiCMgr.exe
(Flux Software LLC) C:\Users\Kevin Clickoo\AppData\Local\FluxSoftware\Flux\flux.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Elias Fotinis) C:\Program Files (x86)\DeskPins\DeskPins.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [AWiC] => C:\Program Files (x86)\Qualcomm Atheros\AWiCMgr.exe [179840 2014-05-14] (Atheros)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3216032 2014-12-25] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-09] (AVAST Software)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\Run: [GSEUUT_2216] => 0
HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\Run: [f.lux] => C:\Users\Kevin Clickoo\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\Run: [Google Update] => C:\Users\Kevin Clickoo\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-11-20] (Google Inc.)
HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [465920 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\RunOnce: [Uninstall C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\RunOnce: [Uninstall C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626"
HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\RunOnce: [Uninstall C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64"
HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\RunOnce: [Uninstall C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5907.0716] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5907.0716"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-09-28] (AVAST Software)
Startup: C:\Users\Kevin Clickoo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeskPins.lnk [2015-10-14]
ShortcutTarget: DeskPins.lnk -> C:\Program Files (x86)\DeskPins\DeskPins.exe (Elias Fotinis)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{329e73ab-10db-471d-81be-d5bf795138cd}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6af7ed1e-7068-4b4c-841d-c7145bdf149f}: [DhcpNameServer] 212.27.40.241 212.27.40.240

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKU\S-1-5-21-2915926479-3701056459-1286684747-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-10] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-10] (AVAST Software)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2915926479-3701056459-1286684747-1001 -> hxxp://www.delta-homes.com/?type=hp&ts=1444640317&z=9e5433ab3419e96b59d1d2bg6z7zaz5q2z5e5c0g3z&from=wpm07163&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX

FireFox:
========
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-09-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-09-03] (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-04-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2915926479-3701056459-1286684747-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Kevin Clickoo\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-2915926479-3701056459-1286684747-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Kevin Clickoo\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-07] (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [PointGrab@PointGrab.com] - C:\Program Files (x86)\PointGrab\Hand Gesture Control\PointGrab.xpi
FF Extension: PointGrab - C:\Program Files (x86)\PointGrab\Hand Gesture Control\PointGrab.xpi [2014-04-23] [non signé]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-11]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.fr/
CHR StartupUrls: Default -> "hxxp://www.oursurfing.com/?type=hp&ts=1437587005&z=a5b143e3ee3eaa42171c144g3z6c1m2wbb4cazbz1m&from=2sq&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX","hxxp://www.delta-homes.com/?type=hp&ts=1444640317&z=9e5433ab3419e96b59d1d2bg6z7zaz5q2z5e5c0g3z&from=wpm07163&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX","hxxp://www.omniboxes.com/?type=hp&ts=1448619136&z=e043e86710b0ed414f5a960gcz0z0bdq7gbtbg4cfc&from=ient07021&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX","hxxp://www.yoursites123.com/?type=hp&ts=1449832221&z=fc3734f2d096e2de1c1d623gdz5z5t4b7c6o6oag8b&from=ient07021&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX"
CHR Profile: C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Deezer Control) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmkmelneeccijablfclenghkcbopdemg [2015-12-17]
CHR Extension: (Facebook™ Messenger) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecmfchgfmbbddembehpkopmhjiepcckd [2015-12-17]
CHR Extension: (Avast SafePrice) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-12-16]
CHR Extension: (Vérificateur de messages Google) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-12-17]
CHR Extension: (Ghostery) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-12-17]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-16]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-07-16]

==================== Services (Avec liste blanche) ========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-28] (AVAST Software)
S3 AWiCSrvc; C:\Program Files (x86)\Qualcomm Atheros\AWiCSrvc.exe [50816 2014-05-14] (Atheros Communications) [Fichier non signé]
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-07-18] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-09-03] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-09-03] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 PGService; C:\Program Files (x86)\PointGrab\Hand Gesture Control\PGService.exe [64776 2014-04-23] (PointGrab LTD)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-01-02] (Atheros) [Fichier non signé]
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]

===================== Pilotes (Avec liste blanche) ==========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R0 assdv2; C:\Windows\System32\Drivers\assdv2.sys [21816 2013-12-05] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-09-28] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-09-28] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-09-28] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-09-28] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-09] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-09-28] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-09-28] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athwbx.sys [4226560 2014-10-17] (Qualcomm Atheros Communications, Inc.)
R3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [165376 2015-07-10] (Microsoft Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2015-12-17 10:34 - 2015-12-17 10:35 - 00017314 _____ C:\Users\Kevin Clickoo\Desktop\FRST.txt
2015-12-17 10:34 - 2015-12-17 10:34 - 02370048 _____ (Farbar) C:\Users\Kevin Clickoo\Desktop\FRST64.exe
2015-12-17 10:34 - 2015-12-17 10:34 - 00000000 ____D C:\FRST
2015-12-17 10:30 - 2015-12-17 10:30 - 00016148 _____ C:\WINDOWS\system32\CLICKOO-KEVIN_Kevin Clickoo_HistoryPrediction.bin
2015-12-16 17:49 - 2015-12-16 17:49 - 00001069 _____ C:\Users\Kevin Clickoo\Desktop\malware.txt
2015-12-16 17:31 - 2015-12-16 17:47 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-16 17:31 - 2015-12-16 17:31 - 00001182 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-16 17:31 - 2015-12-16 17:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-16 17:31 - 2015-12-16 17:31 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-16 17:31 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-12-16 17:31 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-12-16 17:31 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-12-16 17:30 - 2015-12-16 17:30 - 00001842 _____ C:\Users\Kevin Clickoo\Desktop\AdwCleaner[C2].txt
2015-12-16 17:24 - 2015-12-16 17:24 - 00010489 _____ C:\Users\Kevin Clickoo\Desktop\ZHPCleaner.txt
2015-12-16 17:17 - 2015-12-16 17:17 - 22908888 _____ (Malwarebytes ) C:\Users\Kevin Clickoo\Desktop\mbam-setup-2.2.0.1024.exe
2015-12-16 17:16 - 2015-12-16 17:16 - 01740288 _____ C:\Users\Kevin Clickoo\Desktop\adwcleaner_5.025 (1).exe
2015-12-16 17:14 - 2015-12-16 17:19 - 00000934 _____ C:\Users\Kevin Clickoo\Desktop\ZHPCleaner.lnk
2015-12-16 17:14 - 2015-12-16 17:14 - 01946112 _____ C:\Users\Kevin Clickoo\Desktop\ZHPCleaner.exe
2015-12-16 16:58 - 2015-12-16 17:54 - 00079660 _____ C:\Users\Kevin Clickoo\Desktop\ZHPDiag.txt
2015-12-16 16:54 - 2015-12-16 17:51 - 00000214 _____ C:\Users\Kevin
2015-12-16 16:53 - 2015-12-16 17:51 - 00000924 _____ C:\Users\Kevin Clickoo\Desktop\ZHPDiag.lnk
2015-12-16 16:53 - 2015-12-16 17:51 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\ZHP
2015-12-16 16:53 - 2015-12-16 16:53 - 02019328 _____ C:\Users\Kevin Clickoo\Downloads\ZHPDiag3.exe
2015-12-16 16:19 - 2015-12-16 17:27 - 00000000 ____D C:\AdwCleaner
2015-12-16 16:19 - 2015-12-16 16:19 - 01740288 _____ C:\Users\Kevin Clickoo\Downloads\adwcleaner_5.025.exe
2015-12-16 16:16 - 2015-12-16 16:16 - 00002341 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-16 16:16 - 2015-12-16 16:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-16 16:15 - 2015-12-17 10:31 - 00001106 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-16 16:15 - 2015-12-16 18:20 - 00001110 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-16 16:15 - 2015-12-16 16:15 - 00927824 _____ (Google Inc.) C:\Users\Kevin Clickoo\Downloads\ChromeSetup.exe
2015-12-16 16:15 - 2015-12-16 16:15 - 00004168 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-16 16:15 - 2015-12-16 16:15 - 00003936 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-16 16:10 - 2015-12-16 16:10 - 00032987 _____ C:\Users\Kevin Clickoo\Documents\favoris_16_12_2015.html
2015-12-16 15:58 - 2015-12-16 17:42 - 00018338 _____ C:\Users\Kevin Clickoo\Desktop\Sans nom 1.odt
2015-12-16 15:37 - 2015-12-16 15:37 - 00000290 __RSH C:\ProgramData\ntuser.pol
2015-12-16 14:32 - 2015-12-16 15:12 - 00030720 _____ C:\Users\Kevin Clickoo\Downloads\traduction ndtwi.xls
2015-12-16 14:32 - 2015-12-16 14:32 - 00034518 _____ C:\Users\Kevin Clickoo\Downloads\Rapport sur les mots clés.csv
2015-12-16 14:23 - 2015-12-16 14:23 - 00010240 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Mot clés control.xls
2015-12-16 11:23 - 2015-12-16 11:23 - 00000000 ____D C:\Users\Kevin Clickoo\Documents\sonoscanner
2015-12-15 18:23 - 2015-12-15 18:23 - 00010444 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Mots clés QAQC.csv
2015-12-15 18:22 - 2015-12-16 14:21 - 00008896 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Mot clés control.csv
2015-12-15 18:22 - 2015-12-16 14:12 - 00014086 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Annonces control.csv
2015-12-15 18:22 - 2015-12-15 18:23 - 00015136 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Annonces QAQC.csv
2015-12-15 18:17 - 2015-12-15 18:17 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\OpenOffice
2015-12-15 18:15 - 2015-12-15 18:16 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2
2015-12-15 18:15 - 2015-12-15 18:15 - 00001092 _____ C:\Users\Public\Desktop\OpenOffice 4.1.2.lnk
2015-12-15 18:14 - 2015-12-15 18:15 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2015-12-15 18:02 - 2015-12-15 18:02 - 00000000 ____D C:\Users\Kevin Clickoo\Desktop\OpenOffice 4.1.2 (fr) Installation Files
2015-12-11 12:10 - 2015-12-16 17:23 - 00000000 ____D C:\ProgramData\rWdMr
2015-12-09 12:01 - 2015-12-11 12:41 - 00363008 _____ C:\Users\Kevin Clickoo\Downloads\Bulletin d'inscription FF.XLS
2015-11-25 18:33 - 2015-11-25 18:33 - 00000512 _____ C:\Users\Kevin Clickoo\Downloads\700AAE40
2015-11-25 15:13 - 2015-11-25 15:13 - 00023433 _____ C:\Users\Kevin Clickoo\Desktop\sonoscanner deutsch avec caracteres.xlsx
2015-11-20 14:11 - 2015-11-20 14:11 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AdWords Editor
2015-11-20 14:10 - 2015-12-16 18:20 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2915926479-3701056459-1286684747-1001UA.job
2015-11-20 14:10 - 2015-12-16 11:20 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2915926479-3701056459-1286684747-1001Core.job
2015-11-20 14:10 - 2015-12-07 11:15 - 00004272 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2915926479-3701056459-1286684747-1001UA
2015-11-20 14:10 - 2015-12-07 11:15 - 00003896 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2915926479-3701056459-1286684747-1001Core
2015-11-18 12:09 - 2015-11-18 12:09 - 00000000 ____D C:\Users\Kevin Clickoo\Desktop\crea

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2015-12-17 10:34 - 2015-07-10 10:05 - 00000000 ____D C:\Windows
2015-12-17 10:30 - 2015-08-06 15:43 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-12-17 10:30 - 2015-07-17 05:23 - 00000000 __SHD C:\Users\Kevin Clickoo\IntelGraphicsProfiles
2015-12-16 18:33 - 2015-07-16 14:41 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\Google
2015-12-16 17:46 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-16 17:46 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Vss
2015-12-16 17:45 - 2015-07-10 10:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-12-16 17:42 - 2015-09-25 16:09 - 00565248 ___SH C:\Users\Kevin Clickoo\Desktop\Thumbs.db
2015-12-16 16:51 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-16 16:51 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-16 16:50 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-16 16:15 - 2015-07-17 05:37 - 00000000 ____D C:\Program Files (x86)\Google
2015-12-16 16:00 - 2015-07-10 13:20 - 00488296 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-16 15:44 - 2015-07-17 05:40 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\Skype
2015-12-16 15:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2015-12-16 15:37 - 2013-08-22 16:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2015-12-16 11:21 - 2015-10-22 14:08 - 00000000 ____D C:\Users\Kevin Clickoo\Downloads\acceor
2015-12-16 11:21 - 2015-08-03 16:18 - 00000000 ____D C:\install
2015-12-15 18:02 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-12-11 18:31 - 2015-08-07 15:31 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-11 18:31 - 2015-08-07 15:31 - 00000000 ____D C:\Program Files\Microsoft Office
2015-12-11 18:30 - 2015-07-10 17:28 - 00000000 ____D C:\WINDOWS\ShellNew
2015-12-11 18:29 - 2015-08-07 15:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-12-11 18:29 - 2015-07-10 12:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-12-11 18:28 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\System
2015-12-11 18:28 - 2013-08-22 14:25 - 00000108 _____ C:\WINDOWS\win.ini
2015-12-09 12:02 - 2015-07-17 05:23 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Local\Packages
2015-12-01 10:36 - 2015-08-06 16:01 - 01839260 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-01 10:36 - 2015-07-10 17:24 - 00819778 _____ C:\WINDOWS\system32\perfh00C.dat
2015-12-01 10:36 - 2015-07-10 17:24 - 00154144 _____ C:\WINDOWS\system32\perfc00C.dat
2015-12-01 10:36 - 2015-07-10 12:02 - 00000000 ____D C:\WINDOWS\INF
2015-11-30 12:40 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-30 11:53 - 2015-08-10 11:42 - 00005368 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for CLICKOO-KEVIN-Kevin Clickoo Clickoo-Kevin
2015-11-30 10:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-26 10:43 - 2015-08-06 18:12 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-25 16:33 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-11-20 14:13 - 2015-07-17 10:16 - 00001484 _____ C:\Users\Kevin Clickoo\Desktop\Google AdWords Editor.lnk
2015-11-20 14:10 - 2015-07-17 05:37 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Local\Google

==================== Fichiers à la racine de certains dossiers =======

2015-07-17 15:17 - 2015-08-11 09:59 - 0000600 _____ () C:\Users\Kevin Clickoo\AppData\Local\PUTTY.RND
2015-08-06 15:44 - 2015-08-06 15:44 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Certains fichiers dans TEMP:
====================
C:\Users\Kevin Clickoo\AppData\Local\Temp\2g20seak.cquBingAdsEditor.exe
C:\Users\Kevin Clickoo\AppData\Local\Temp\GoogleAdWordsEditorSetup.exe
C:\Users\Kevin Clickoo\AppData\Local\Temp\sqlite3.dll
C:\Users\Kevin Clickoo\AppData\Local\Temp\wwspvfek.uhjBingAdsEditor.exe


==================== Bamital & volsnap =================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement


LastRegBack: 2015-11-30 11:15

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité