cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:21-02-2016 01
Exécuté par Ahmet (administrateur) sur WIN-9PFFMPKBSTH (22-02-2016 14:30:14)
Exécuté depuis C:\Users\Responsable\Desktop
Profils chargés: Ahmet (Profils disponibles: Ahmet & Administrateur)
Platform: Windows 10 Pro Version 1511 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\VsHub.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\Microsoft.VsHub.Server.HttpHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\Microsoft.VsHub.Server.HttpHostx64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8466136 2015-05-08] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3952832 2015-08-21] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508104 2015-10-30] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [220704 2015-09-14] (Geek Software GmbH)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127528 2015-07-08] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-12-17] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-12-22] (Oracle Corporation)
HKU\S-1-5-21-511945228-3084827621-2135989165-1002\...\Run: [C] => C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol [750 2016-02-22] ()
HKU\S-1-5-21-511945228-3084827621-2135989165-1002\...\RunOnce: [Uninstall C:\Users\Responsable\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Responsable\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
HKU\S-1-5-21-511945228-3084827621-2135989165-1002\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
Startup: C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\system.pif [2016-02-22] ()
Startup: C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wscanner.lnk [2016-02-22]
ShortcutTarget: wscanner.lnk -> C:\Program Files (x86)\Wscanner\wscanner.exe (Pas de fichier)
Startup: C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\system.pif [2016-02-22] ()
Startup: C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wscanner.lnk [2016-02-22]
ShortcutTarget: wscanner.lnk -> C:\Program Files (x86)\Wscanner\wscanner.exe (Pas de fichier)
GroupPolicy: Restriction - Chrome <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 212.27.40.241 212.27.40.240
Tcpip\..\Interfaces\{01b4a9db-58eb-4046-bae7-bf60142c3f56}: [DhcpNameServer] 192.168.8.1 8.8.8.8
Tcpip\..\Interfaces\{86d0d1c1-43e7-4848-b3ed-3943d8a123b5}: [DhcpNameServer] 212.27.40.241 212.27.40.240

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr
HKU\S-1-5-21-511945228-3084827621-2135989165-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr
HKU\S-1-5-21-511945228-3084827621-2135989165-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.fr
HKU\S-1-5-21-511945228-3084827621-2135989165-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.fr
URLSearchHook: [S-1-5-21-511945228-3084827621-2135989165-1002] ATTENTION => URLSearchHook par défaut est absent
SearchScopes: HKU\S-1-5-21-511945228-3084827621-2135989165-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-511945228-3084827621-2135989165-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-511945228-3084827621-2135989165-1002 -> {55087B7B-CD89-4B11-93A4-0754E4458915} URL = hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-26] (Oracle Corporation)
BHO-x32: Wscanner -> {822B88F2-D7D8-473C-9C82-1A1EDB255268} -> C:\Program Files (x86)\Wscanner\secure\Wscanner.dll [2015-11-27] (Wscanner)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-26] (Oracle Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Responsable\AppData\Roaming\Mozilla\Firefox\Profiles\z7jfasuq.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-09] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-09] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-26] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-22] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-22] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-511945228-3084827621-2135989165-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Responsable\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-01-22] (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Responsable\AppData\Roaming\Mozilla\Firefox\Profiles\z7jfasuq.default\searchplugins\yahoo-ysp.xml [2016-01-26]
FF Extension: iMacros for Firefox - C:\Users\Responsable\AppData\Roaming\Mozilla\Firefox\Profiles\z7jfasuq.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2016-01-01]
FF Extension: New Tab by Yahoo - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\jid1-G80Ec8LLEbK5fQ@jetpack.xpi [2016-01-07]
FF Extension: js4mt - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{9746ad1f-7f2a-4bc8-a61c-2f73d969472d} [2016-02-22] [non signé]
FF HKLM-x32\...\Firefox\Extensions: [fiddlerhook@fiddler2.com] - C:\Program Files (x86)\Fiddler2\FiddlerHook
FF Extension: FiddlerHook - C:\Program Files (x86)\Fiddler2\FiddlerHook [2015-12-10] [non signé]
FF HKLM-x32\...\Firefox\Extensions: [{9746ad1f-7f2a-4bc8-a61c-2f73d969472d}] - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{9746ad1f-7f2a-4bc8-a61c-2f73d969472d}

Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=orcl_default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://fr.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-22]
CHR Extension: (Google Docs) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-22]
CHR Extension: (Google Drive) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-22]
CHR Extension: (YouTube) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-22]
CHR Extension: (Adblock Plus) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-22]
CHR Extension: (Recherche Google) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-22]
CHR Extension: (Google Docs hors connexion) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-22]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-22]
CHR Extension: (Gmail) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-22]
CHR HKLM-x32\...\Chrome\Extension: [kpdmjodecdegfglgaapafjleomjjlpnh] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Avec liste blanche) ========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2020056 2016-02-09] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [441976 2015-10-09] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [421496 2015-10-09] (BlueStack Systems, Inc.)
S3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [867960 2015-10-09] (BlueStack Systems, Inc.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [108248 2015-02-04] ()
R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1332184 2015-03-31] (Intel Corporation)
S3 FBackup5Srv; C:\Program Files (x86)\Softland\FBackup 5\bService.exe [4678680 2015-08-04] (Softland)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-07-18] (Intel Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [295128 2015-05-08] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2015-08-21] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2015-12-14] (TeamViewer GmbH)
R3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X]
S2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe" [X]

===================== Pilotes (Avec liste blanche) ==========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [146040 2015-10-09] (BlueStack Systems)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [165376 2015-10-30] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [36864 2015-10-30] (Microsoft Corporation)
R3 dptf_acpi; C:\Windows\System32\drivers\dptf_acpi.sys [45648 2015-03-31] (Intel Corporation)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [41552 2015-03-31] (Intel Corporation)
R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [243792 2015-03-31] (Intel Corporation)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-11-12] (LogMeIn Inc.)
R3 iagpioe; C:\Windows\System32\drivers\iagpioe.sys [32256 2015-03-28] (Intel(R) Corporation)
R3 igfxLP; C:\Windows\system32\DRIVERS\igdkmd64lp.sys [5864888 2015-07-18] (Intel Corporation)
S3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv.sys [49272 2014-12-29] (Visicom Media Inc.)
S3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (Visicom Media Inc.)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [624424 2015-10-30] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [4549360 2015-08-21] (Realtek Semiconductor Corporation )
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [33448 2015-03-19] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [52912 2015-08-21] (Synaptics Incorporated)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [114976 2015-03-31] (Intel Corporation)
R3 VirtualButtons; C:\Windows\System32\drivers\VirtualButtons.sys [31512 2015-04-08] (Intel Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-08-07] (Hewlett-Packard Development Company, L.P.)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [35880 2016-01-13] (Wellbia.com Co., Ltd.)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [202144 2016-02-22] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [202144 2016-02-22] (Zemana Ltd.)
S3 zttap300; C:\Windows\System32\drivers\zttap300.sys [30488 2015-08-13] (ZeroTier Networks LLC)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-02-22 14:31 - 2016-02-22 14:31 - 00544768 _____ ( ) C:\Users\Responsable\Desktop\yeni.exe
2016-02-22 14:30 - 2016-02-22 14:31 - 00019079 _____ C:\Users\Responsable\Desktop\FRST.txt
2016-02-22 14:30 - 2016-02-22 14:30 - 00069120 _____ C:\Users\Responsable\Desktop\Icon Changer and Extension Spoofer.exe
2016-02-22 14:30 - 2015-02-06 20:13 - 00000000 ____D C:\Users\Responsable\Desktop\Icon Changer and Extension Spoofer
2016-02-22 14:21 - 2016-02-22 14:21 - 00000022 _____ C:\WINDOWS\SysWOW64\mseixml.sei
2016-02-22 14:21 - 2016-02-22 14:21 - 00000022 _____ C:\WINDOWS\mseixml.sei
2016-02-22 14:21 - 2016-02-22 14:21 - 00000002 _____ C:\Users\Responsable\Documents\eisavedicon.bmp
2016-02-22 14:17 - 2016-02-22 14:17 - 00372736 _____ ( ) C:\Users\Responsable\Desktop\yeni.exe.(1).bak
2016-02-22 14:11 - 2016-02-22 14:11 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\nBinder Limited
2016-02-22 13:35 - 2016-02-22 13:59 - 00352256 _____ C:\Users\Responsable\Desktop\SpamBot By InterAhmet.exe
2016-02-22 13:34 - 2015-01-31 22:53 - 00352256 _____ C:\Users\Responsable\Desktop\SpamBot By InterAhmet orj.exe
2016-02-22 13:32 - 2016-02-22 13:43 - 00396802 ___SH C:\Users\Responsable\AppData\Local\CSIDL_
2016-02-22 13:32 - 2016-02-22 13:32 - 00396802 ___SH C:\Users\Responsable\AppData\Local\CSIDL_X
2016-02-22 13:30 - 2016-02-22 13:43 - 00000000 ____D C:\Users\Responsable\Desktop\AegisCrypter8.1
2016-02-22 12:46 - 2016-02-22 12:46 - 00001294 _____ C:\RstHosts.txt
2016-02-22 12:32 - 2016-02-22 12:42 - 00000000 ____D C:\Users\Responsable\Desktop\rapports
2016-02-22 12:29 - 2016-02-22 12:29 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-02-22 12:27 - 2016-02-22 12:27 - 00000620 _____ C:\WINDOWS\ZAM.krnl.trace
2016-02-22 12:27 - 2016-02-22 12:27 - 00000119 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2016-02-22 12:12 - 2016-02-22 12:12 - 00000890 _____ C:\Users\Responsable\Desktop\ZHPCleaner.lnk
2016-02-22 12:10 - 2016-02-22 12:29 - 00353632 _____ C:\Users\Responsable\Desktop\rsthosts_2.0.exe
2016-02-22 12:06 - 2016-02-22 12:06 - 00202144 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2016-02-22 12:06 - 2016-02-22 12:06 - 00202144 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam64.sys
2016-02-22 12:06 - 2016-02-22 12:06 - 00000000 ____D C:\Users\Responsable\AppData\Local\Zemana
2016-02-22 11:36 - 2016-02-22 11:36 - 00000000 ____D C:\Users\Responsable\Desktop\Peid
2016-02-22 11:17 - 2016-02-22 12:34 - 00000878 _____ C:\Users\Responsable\Desktop\ZHPDiag.lnk
2016-02-22 10:54 - 2016-02-22 14:30 - 00000000 ____D C:\FRST
2016-02-22 10:52 - 2016-02-22 10:54 - 02371072 _____ (Farbar) C:\Users\Responsable\Desktop\FRST64.exe
2016-02-22 10:49 - 2016-02-22 12:55 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\ZHP
2016-02-22 10:49 - 2016-02-22 10:50 - 00000000 ____D C:\Program Files (x86)\ZHPFix
2016-02-22 10:49 - 2016-02-22 10:49 - 00001925 _____ C:\Users\Public\Desktop\ZHPFix.lnk
2016-02-22 10:49 - 2016-02-22 10:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
2016-02-22 10:32 - 2016-02-22 13:37 - 00001108 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-22 10:32 - 2016-02-22 12:29 - 00001104 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-22 10:32 - 2016-02-22 10:32 - 00004166 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-22 10:32 - 2016-02-22 10:32 - 00003934 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-02-22 10:32 - 2016-02-22 10:32 - 00002279 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-22 10:32 - 2016-02-22 10:32 - 00002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-22 10:28 - 2016-02-22 10:28 - 01622528 _____ C:\Users\Responsable\Desktop\ResetBrowser.exe
2016-02-22 10:16 - 2016-02-22 10:16 - 00001032 __RSH C:\ProgramData\ntuser.pol
2016-02-22 10:16 - 2016-02-22 10:16 - 00000110 _____ C:\WINDOWS\SysWOW64\L
2016-02-22 10:12 - 2016-02-22 10:18 - 00000000 ____D C:\AdwCleaner
2016-02-22 10:11 - 2016-02-22 10:12 - 01511936 _____ C:\Users\Responsable\Downloads\adwcleaner_5.036.exe
2016-02-22 09:48 - 2016-02-22 10:29 - 00000000 ____D C:\Program Files (x86)\Wscanner
2016-02-22 09:48 - 2016-02-22 09:48 - 00003134 _____ C:\WINDOWS\System32\Tasks\Wscanner Secure
2016-02-22 09:48 - 2016-02-22 09:48 - 00002636 _____ C:\Users\Responsable\AppData\Local\cookies.bin
2016-02-22 09:48 - 2016-02-22 09:48 - 00000000 ____D C:\Program Files (x86)\WCNT
2016-02-22 09:46 - 2016-02-22 09:46 - 00000008 __RSH C:\Users\Responsable\ntuser.pol
2016-02-21 23:21 - 2016-02-21 23:21 - 00004949 _____ C:\ProgramData\rugqgaaw.ekm
2016-02-21 23:14 - 2016-02-21 23:14 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vbkodbank
2016-02-21 23:05 - 2016-02-21 23:05 - 00953856 _____ (CanHit) C:\Users\Responsable\Desktop\Hit Programi.exe
2016-02-21 23:04 - 2016-02-21 23:04 - 00964608 _____ (CanHit) C:\Users\Responsable\Desktop\Hit Programi.exe.(2).bak
2016-02-21 22:59 - 2016-02-21 22:59 - 00809984 _____ (CanHit) C:\Users\Responsable\Desktop\Hit Programi.exe.(1).bak
2016-02-21 22:07 - 2016-02-21 22:07 - 00001219 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\High Proxy Finder.lnk
2016-02-21 22:07 - 2016-02-21 22:07 - 00001207 _____ C:\Users\Public\Desktop\High Proxy Finder.lnk
2016-02-21 22:07 - 2016-02-21 22:07 - 00000000 ____D C:\Program Files (x86)\High Proxy Finder
2016-02-21 22:01 - 2016-02-21 22:01 - 00000000 __HDC C:\ProgramData\{28D47069-C8EF-4BCE-ACD5-7F6FC6BED689}
2016-02-21 22:01 - 2016-02-21 22:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\.NET Reactor
2016-02-21 22:01 - 2016-02-21 22:01 - 00000000 ____D C:\Program Files (x86)\Eziriz
2016-02-20 10:11 - 2016-02-20 10:11 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-02-19 17:01 - 2016-02-19 17:03 - 00000000 ____D C:\Users\Responsable\Source
2016-02-19 16:43 - 2016-02-19 16:43 - 00000000 ____D C:\ProgramData\Microsoft Team Foundation Local Workspaces
2016-02-17 15:57 - 2016-02-17 15:57 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Rugland Digital Systems
2016-02-17 14:51 - 2016-02-17 14:51 - 00000000 ____D C:\WINDOWS\%LOCALAPPDATA%
2016-02-17 13:56 - 2016-02-22 10:24 - 00000000 __SHD C:\bot
2016-02-17 13:56 - 2016-02-22 09:53 - 00003102 _____ C:\WINDOWS\System32\Tasks\Bot Updater
2016-02-17 13:50 - 2016-02-22 10:02 - 00000000 __SHD C:\fix
2016-02-17 13:50 - 2016-02-22 09:53 - 00003100 _____ C:\WINDOWS\System32\Tasks\Coc Updater
2016-02-17 13:50 - 2016-02-17 13:50 - 00000000 ____D C:\Program Files (x86)\WIN-9PFFMPKBSTH
2016-02-16 21:13 - 2016-02-21 12:56 - 00000000 ____D C:\Program Files (x86)\High Yazilim Soft
2016-02-16 21:13 - 2016-02-16 21:13 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Youtube MP3 Converter BETA.lnk
2016-02-16 21:13 - 2016-02-16 21:13 - 00001231 _____ C:\Users\Public\Desktop\Youtube MP3 Converter BETA.lnk
2016-02-16 20:23 - 2016-02-22 09:52 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chrome
2016-02-16 19:13 - 2016-02-16 19:13 - 00001946 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2016-02-15 22:22 - 2016-02-15 22:23 - 01081616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSCOMCTL.OCX
2016-02-15 22:21 - 2016-02-15 22:21 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldUnlock Calculator
2016-02-13 10:40 - 2016-02-13 10:40 - 00000000 ____D C:\Users\Responsable\Documents\OverZ
2016-02-13 10:40 - 2016-02-13 10:40 - 00000000 ____D C:\Users\Responsable\Documents\Infestation
2016-02-12 21:35 - 2016-02-12 21:36 - 01153284 _____ C:\WINDOWS\Minidump\021216-25078-01.dmp
2016-02-12 21:35 - 2016-02-12 21:35 - 00000000 ____D C:\WINDOWS\Minidump
2016-02-11 21:24 - 2016-02-11 21:26 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Web Traffic Generator 2
2016-02-11 21:22 - 2016-02-11 21:22 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Bold Proxy Checker
2016-02-11 20:33 - 2016-02-11 20:47 - 00000000 ____D C:\ProgramData\Magic Submitter
2016-02-11 17:24 - 2016-02-11 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Money Robot
2016-02-10 22:39 - 2016-02-10 22:39 - 00000829 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3 YAPICI.lnk
2016-02-10 22:30 - 2016-02-10 22:30 - 00001200 _____ C:\Users\Public\Desktop\Inno Setup Compiler.lnk
2016-02-10 22:30 - 2016-02-10 22:30 - 00000000 ____D C:\Program Files (x86)\Inno Setup 5
2016-02-09 20:55 - 2016-02-09 20:55 - 00000000 ____D C:\ProgramData\dbg
2016-02-09 20:11 - 2016-02-09 20:11 - 08817344 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2016-02-08 19:22 - 2016-02-16 22:51 - 00000000 ____D C:\Users\Responsable\AppData\Local\ArborSoft
2016-02-05 19:44 - 2016-02-05 19:44 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Unity
2016-02-05 19:37 - 2016-02-05 19:37 - 00000000 ____D C:\Users\Responsable\AppData\LocalLow\Unity
2016-02-05 19:37 - 2016-02-05 19:37 - 00000000 ____D C:\Users\Responsable\AppData\Local\Unity
2016-02-05 19:14 - 2016-02-05 19:14 - 00000000 ____D C:\Users\Responsable\AppData\Local\https___facebook.com_mano
2016-02-04 21:27 - 2016-02-04 21:27 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Crypto Obfuscator For .Net v2015
2016-02-04 21:21 - 2016-02-04 21:21 - 00034308 _____ C:\WINDOWS\SysWOW64\bassmod.dll
2016-02-04 21:19 - 2016-02-04 21:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogicNP Software
2016-02-04 21:19 - 2016-02-04 21:19 - 00000000 ____D C:\Program Files (x86)\LogicNP Software
2016-02-03 15:53 - 2016-02-03 15:54 - 00000000 ____D C:\Users\Responsable\AppData\Local\Vivaldi
2016-02-03 15:53 - 2016-02-03 15:53 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vivaldi
2016-01-31 21:25 - 2016-02-17 22:36 - 00000000 ____D C:\Users\Responsable\Desktop\High
2016-01-31 19:55 - 2016-01-31 19:55 - 00000000 ____D C:\Users\Responsable\AppData\Local\JonathanLeger.com
2016-01-30 11:06 - 2016-02-22 09:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-01-30 09:17 - 2016-01-30 09:17 - 00000000 ____D C:\Users\Responsable\AppData\Local\Red_Gate_Software_Ltd
2016-01-29 23:07 - 2016-01-29 23:07 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\ICSharpCode
2016-01-29 22:23 - 2016-01-29 22:23 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Eziriz
2016-01-29 18:44 - 2016-01-29 18:44 - 00000000 ____D C:\Users\Responsable\Documents\Zeta Resource Editor projects
2016-01-29 18:38 - 2016-01-29 18:45 - 00000000 ____D C:\Users\Responsable\AppData\Local\Zeta Resource Editor
2016-01-29 18:30 - 2016-02-17 22:37 - 00000000 ____D C:\Users\Responsable\AppData\Local\DotNet Resolver
2016-01-29 18:17 - 2016-01-29 18:17 - 00000000 ____D C:\Users\Responsable\Documents\Reflector
2016-01-28 21:54 - 2016-01-28 21:54 - 00000000 ____D C:\Users\Responsable\AppData\Local\Deployment
2016-01-27 22:25 - 2016-01-27 22:25 - 00000000 ____D C:\Users\Responsable\AppData\Local\LogMeIn
2016-01-27 22:25 - 2016-01-27 22:25 - 00000000 ____D C:\ProgramData\LogMeIn
2016-01-26 18:12 - 2016-01-26 18:12 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2016-01-26 18:09 - 2016-01-26 18:08 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-01-25 21:03 - 2016-01-25 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BacklinkSpeed
2016-01-24 14:00 - 2016-01-24 14:00 - 00000000 ___RD C:\Sandbox
2016-01-24 13:59 - 2016-01-24 14:01 - 00001670 _____ C:\WINDOWS\Sandboxie.ini
2016-01-24 13:26 - 2016-01-24 13:26 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-01-24 11:19 - 2014-08-16 15:53 - 00017920 ____H C:\Users\Responsable\Desktop\Tubro_Spinner_Console.suo
2016-01-23 23:36 - 2016-01-23 23:36 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-01-23 23:36 - 2016-01-23 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-01-23 22:44 - 2016-01-23 22:45 - 00000000 ____D C:\Program Files (x86)\Resource Tuner
2016-01-23 22:33 - 2016-01-23 22:34 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\PE Explorer
2016-01-23 22:32 - 2016-01-23 22:32 - 00000000 ____D C:\WINDOWS\Nouveau dossier
2016-01-23 22:31 - 2016-01-23 22:34 - 00000000 ____D C:\Program Files (x86)\PE Explorer

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-02-22 14:27 - 2015-12-21 10:29 - 00000000 ____D C:\Users\Responsable\AppData\Local\CrashDumps
2016-02-22 14:11 - 2015-10-06 13:21 - 00001002 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-02-22 12:33 - 2015-11-26 00:24 - 01956472 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-22 12:33 - 2015-10-30 20:00 - 00866682 _____ C:\WINDOWS\system32\perfh00C.dat
2016-02-22 12:33 - 2015-10-30 20:00 - 00173530 _____ C:\WINDOWS\system32\perfc00C.dat
2016-02-22 12:33 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2016-02-22 12:28 - 2015-11-26 00:25 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-22 12:27 - 2015-10-30 07:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-02-22 12:26 - 2015-11-26 16:53 - 00000000 ____D C:\Program Files (x86)\Skillbrains
2016-02-22 10:32 - 2015-10-06 12:53 - 00000000 ____D C:\Program Files (x86)\Google
2016-02-22 10:29 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-02-22 09:51 - 2015-11-02 15:23 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-22 09:47 - 2015-12-21 16:17 - 00001537 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-02-22 09:47 - 2015-10-06 13:20 - 00001549 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-02-22 09:46 - 2015-11-26 00:09 - 00000000 ____D C:\Users\Responsable
2016-02-22 09:46 - 2013-08-22 16:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-02-22 09:41 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\AppData\Local\Adobe
2016-02-21 22:32 - 2015-11-27 20:41 - 00000000 ____D C:\Users\Responsable\Desktop\Logiciels
2016-02-21 12:09 - 2015-11-26 16:45 - 00000000 ____D C:\Users\Responsable\Desktop\Musique
2016-02-20 10:08 - 2015-12-20 15:45 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\FileZilla
2016-02-18 21:09 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Skype
2016-02-17 22:37 - 2015-11-29 18:52 - 00000000 ____D C:\Users\Responsable\Desktop\Data
2016-02-17 15:45 - 2015-11-25 18:46 - 00000000 ____D C:\Users\Responsable\AppData\Local\VirtualStore
2016-02-17 09:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-02-17 09:02 - 2016-01-22 16:33 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Free Monitor for Google
2016-02-16 19:52 - 2015-11-26 17:46 - 00000000 ____D C:\Users\Responsable\Documents\Visual Studio 2015
2016-02-16 19:13 - 2015-12-20 15:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2016-02-16 19:13 - 2015-12-20 15:39 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2016-02-12 21:35 - 2015-11-02 13:16 - 670926819 _____ C:\WINDOWS\MEMORY.DMP
2016-02-04 20:50 - 2015-10-06 13:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-01 19:07 - 2016-01-01 15:49 - 00002250 ____H C:\Users\Responsable\Documents\Default.rdp
2016-01-29 22:23 - 2015-11-27 17:47 - 00000000 ____D C:\Users\Responsable\AppData\Local\SkinSoft
2016-01-28 21:54 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\AppData\Local\Apps\2.0
2016-01-26 18:11 - 2015-10-06 13:13 - 00000000 ____D C:\ProgramData\Oracle
2016-01-26 18:09 - 2015-10-06 13:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-01-26 18:09 - 2015-10-06 13:13 - 00000000 ____D C:\Program Files (x86)\Java
2016-01-26 18:08 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\.oracle_jre_usage
2016-01-26 17:52 - 2015-11-26 00:01 - 00278104 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-01-25 20:28 - 2016-01-17 14:11 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\uTorrent
2016-01-23 23:36 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\AppData\Local\Skype
2016-01-23 23:36 - 2015-10-12 10:37 - 00000000 ____D C:\ProgramData\Skype
2016-01-23 22:47 - 2016-01-01 20:02 - 00000000 ____D C:\Users\Responsable\Documents\Resource Tuner 2

==================== Fichiers à la racine de certains dossiers =======

2015-12-01 19:05 - 2015-12-01 19:06 - 0025593 _____ () C:\Program Files (x86)\Common Files\TV11Install.log
2015-11-25 11:57 - 2015-11-25 11:59 - 39614808 ___SH (IObit ) C:\Program Files (x86)\Common Files\~jgjjttj.ibo
2016-02-22 09:48 - 2016-02-22 09:48 - 0002636 _____ () C:\Users\Responsable\AppData\Local\cookies.bin
2016-02-22 13:32 - 2016-02-22 13:43 - 0396802 ___SH () C:\Users\Responsable\AppData\Local\CSIDL_
2016-02-22 13:32 - 2016-02-22 13:32 - 0396802 ___SH () C:\Users\Responsable\AppData\Local\CSIDL_X
2015-11-26 16:53 - 2015-11-26 16:53 - 0000003 _____ () C:\Users\Responsable\AppData\Local\updater.log
2015-11-26 16:53 - 2015-11-26 16:53 - 0000424 _____ () C:\Users\Responsable\AppData\Local\UserProducts.xml
2016-02-21 23:21 - 2016-02-21 23:21 - 0004949 _____ () C:\ProgramData\rugqgaaw.ekm

Certains fichiers dans TEMP:
====================
C:\Users\Responsable\AppData\Local\Temp\0SpamBot By InterAhmet.exe
C:\Users\Responsable\AppData\Local\Temp\FB_172C.tmp.exe
C:\Users\Responsable\AppData\Local\Temp\FB_1A91.tmp.exe
C:\Users\Responsable\AppData\Local\Temp\FB_2321.tmp.exe
C:\Users\Responsable\AppData\Local\Temp\FB_3B01.tmp.exe
C:\Users\Responsable\AppData\Local\Temp\FB_498.tmp.exe
C:\Users\Responsable\AppData\Local\Temp\FB_A8AF.tmp.exe
C:\Users\Responsable\AppData\Local\Temp\upx.exe


==================== Bamital & volsnap =================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement


LastRegBack: 2016-02-22 10:38

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité