cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Exécuté par nounours (administrateur) sur NOUNOURS-PC (27-03-2016 11:41:50)
Exécuté depuis C:\Users\nounours\Desktop
Profils chargés: nounours (Profils disponibles: nounours)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
(CyberLink Corp.) C:\Program Files (x86)\Hp\QuickPlay\QPService.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-15] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [450048 2009-07-22] (IDT, Inc.)
HKLM-x32\...\Run: [QPService] => C:\Program Files (x86)\HP\QuickPlay\QPService.exe [468264 2009-06-23] (CyberLink Corp.)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-17] (CyberLink Corp.)
HKLM-x32\...\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2009-11-24] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard)
HKLM-x32\...\Run: [avast5] => C:\Program Files\Alwil Software\Avast5\avastUI.exe [4282728 2012-08-21] (AVAST Software)
HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [500792 2010-03-23] (Hewlett-Packard Company)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-01-20] (Apple Inc.)
HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1444880 2016-03-26] (Easybits)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66328 2016-03-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira System Speedup User Starter] => C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [14952 2016-03-23] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [807392 2016-02-22] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\Run: [ISUSPM] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [205480 2007-08-30] (Macrovision Corporation)
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8686296 2016-03-11] (Piriform Ltd)
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\Policies\system: [WallpaperStyle] 2
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\MountPoints2: {ec318f2a-7ece-11df-af0b-00269e5b8a48} - F:\USBAutoRun.exe
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [241664 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-31] (Microsoft Corporation)
HKU\S-1-5-18\...\Policies\system: [WallpaperStyle] 2
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{15A6835B-2CE9-4B4E-A54A-913503111E89}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3A1F5D24-79FC-4741-9C34-EF47B89CDDCF}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-2932048975-2122173119-2500850375-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.fr/
SearchScopes: HKLM -> DefaultScope {2B7B7EFC-C234-4532-822B-A8D74D7EF7EB} URL =
SearchScopes: HKLM -> {56FE2731-5995-410E-A077-2A2774529F93} URL = hxxp://fr.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913932
SearchScopes: HKLM -> {5F5D59D2-5CD3-47DB-8AF9-484104C05C9D} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {56FE2731-5995-410E-A077-2A2774529F93} URL = hxxp://fr.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913932
SearchScopes: HKLM-x32 -> {5F5D59D2-5CD3-47DB-8AF9-484104C05C9D} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
SearchScopes: HKU\S-1-5-21-2932048975-2122173119-2500850375-1000 -> {56FE2731-5995-410E-A077-2A2774529F93} URL = hxxp://fr.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913932
SearchScopes: HKU\S-1-5-21-2932048975-2122173119-2500850375-1000 -> {5F5D59D2-5CD3-47DB-8AF9-484104C05C9D} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
BHO-x32: AviraBrowserSafety.BrowserSafety -> {c3c77255-42c0-499f-b664-6e981a0b1647} -> C:\Windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-2932048975-2122173119-2500850375-1000 -> Pas de nom - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Pas de fichier
Handler-x32: abs - {E00957BD-D0E1-4eb9-A025-7743FDC8B27B} - C:\Windows\SysWOW64\mscoree.dll [2010-11-05] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default
FF SelectedSearchEngine:
FF Homepage: hxxp://trouve.info/pole-emploi.htm
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-26] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-26] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2008-11-13] (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [Pas de fichier]
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [Pas de fichier]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-26] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-26] (Google Inc.)
FF user.js: detected! => C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\user.js [2016-03-25]
FF Plugin ProgramFiles/Appdata: C:\Users\nounours\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-25] (Microsoft Corporation)
FF SearchPlugin: C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\searchplugins\dilandau.xml [2014-10-19]
FF SearchPlugin: C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\searchplugins\durable.xml [2010-02-23]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\.xml [2016-03-25]
FF Extension: Rappel Actualisation Pole Emploi - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\{c1889950-4218-11e3-aa6e-0800200c9a66}.xpi [2013-12-28] [non signé]
FF Extension: notraceunisait - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\notrace@unisa.it [2014-12-13] [non signé]
FF Extension: 146f18202b0d49efacbfd85a6986e10c - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\{146f1820-2b0d-49ef-acbf-d85a6986e10c} [2014-12-13] [non signé]
FF Extension: infocloudaclcom - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\info@cloudacl.com [2014-12-17] [non signé]
FF Extension: Pas de nom - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\{2e549179-ae27-47de-bff3-b445e0bfda1a}.xpi [non trouvé(e)]
FF Extension: CouponFactor - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\ezbtlkvrsueku_gnjx@gbbjjoehbyzzeob.com [2015-03-03] [non signé]
FF Extension: Pas de nom - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\6cfae8cc4676442fa78d9dcdf@bd4ea874e76d4af1994ba.com [non trouvé(e)]
FF Extension: Pas de nom - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\williamslake@yahoo.com [non trouvé(e)]
FF Extension: Pas de nom - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\43f13f31-cec7-4ac7-ad4a-18dfdaeae120@gmail.com [non trouvé(e)]
FF Extension: Pas de nom - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\extensions\taylorralston@hotmail.com [non trouvé(e)]
FF Extension: SSalesMagnoeT - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\9j0Oi6aB6i@c.com [2014-12-23] [non signé]
FF Extension: Avira Browser Safety - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\abs@avira.com.xpi [2016-03-27]
FF Extension: KingCoupuon - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\aYJE@YWxe.edu [2015-01-15] [non signé]
FF Extension: QuueenCouponu - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\Cn@W.net [2015-01-28] [non signé]
FF Extension: iCloud Bookmarks - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\firefoxdav@icloud.com [2014-11-15] [non signé]
FF Extension: FlashhCoupeon - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\MT@m.org [2015-02-17] [non signé]
FF Extension: FlashCouapOan - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\P9PT93Rp@yHF.com [2015-02-27] [non signé]
FF Extension: deal4mie - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\rV623jq@M.edu [2014-12-29] [non signé]
FF Extension: saverron - C:\Users\nounours\AppData\Roaming\Mozilla\Firefox\Profiles\5zk1xt8p.default\Extensions\sl@47Ly2Onj.com [2015-01-06] [non signé]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\my-prefs.js [2015-03-25] <==== ATTENTION (Pointe vers un fichier *.cfg)

Chrome:
=======
CHR Profile: C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-26]
CHR Extension: (Google Docs) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-26]
CHR Extension: (Google Drive) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-26]
CHR Extension: (YouTube) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-26]
CHR Extension: (Adblock Plus) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-26]
CHR Extension: (Google Sheets) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-26]
CHR Extension: (Google Docs hors connexion) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-26]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-26]
CHR Extension: (Gmail) - C:\Users\nounours\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-26]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Avec liste blanche) ========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe [89600 2009-03-02] (Andrea Electronics Corporation)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [955736 2016-02-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [466504 2016-02-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [466504 2016-02-22] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1424880 2016-02-22] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [272304 2016-03-04] (Avira Operations GmbH & Co. KG)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129584 2009-02-22] (EasyBits Sofware AS) [Fichier non signé]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [Fichier non signé]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [Fichier non signé]
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [Fichier non signé]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-01-21] ()
R2 SpeedupService; C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe [24224 2016-03-23] (Avira Operations GmbH & Co. KG)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe [240128 2009-07-22] (IDT, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 RoxLiveShare9; "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [X]

===================== Pilotes (Avec liste blanche) ==========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [154816 2016-02-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [133168 2016-02-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2016-02-22] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69888 2016-02-22] (Avira Operations GmbH & Co. KG)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-03-27] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [Fichier non signé]
U4 eabfiltr; pas de ImagePath
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [X]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-03-27 11:41 - 2016-03-27 11:42 - 00023100 _____ C:\Users\nounours\Desktop\FRST.txt
2016-03-27 11:41 - 2016-03-27 11:41 - 00000000 ____D C:\FRST
2016-03-27 11:40 - 2016-03-27 11:40 - 02374144 _____ (Farbar) C:\Users\nounours\Desktop\FRST64.exe
2016-03-27 11:21 - 2016-03-27 11:21 - 00000000 ____D C:\Users\nounours\AppData\Local\Avira
2016-03-27 10:34 - 2016-03-27 10:34 - 00001614 _____ C:\Users\nounours\Desktop\ZHPFixReport.txt
2016-03-27 10:31 - 2016-03-27 10:32 - 00000000 ____D C:\Program Files (x86)\ZHPFix
2016-03-27 10:31 - 2016-03-27 10:31 - 00001813 _____ C:\Users\Public\Desktop\ZHPFix.lnk
2016-03-27 10:31 - 2016-03-27 10:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
2016-03-27 10:26 - 2016-03-27 10:27 - 03521617 _____ (Nicolas Coolman ) C:\Users\nounours\Downloads\ZHPFix.exe
2016-03-27 02:48 - 2016-03-27 02:48 - 00003434 _____ C:\Windows\System32\Tasks\Avira Browser Safety Updater Task
2016-03-27 02:47 - 2016-03-27 02:47 - 00000000 ____D C:\Users\nounours\AppData\Roaming\Avira
2016-03-27 02:42 - 2016-02-22 18:23 - 00154816 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2016-03-27 02:42 - 2016-02-22 18:23 - 00133168 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2016-03-27 02:42 - 2016-02-22 18:23 - 00069888 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2016-03-27 02:42 - 2016-02-22 18:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2016-03-27 02:32 - 2016-03-27 02:32 - 00001103 _____ C:\Users\Public\Desktop\Avira System Speedup.lnk
2016-03-27 02:30 - 2016-03-27 11:20 - 00000000 ____D C:\Users\Public\Speedup Sessions
2016-03-27 02:30 - 2016-03-27 02:30 - 00003344 _____ C:\Windows\System32\Tasks\Avira System Speedup Tray
2016-03-27 02:28 - 2016-03-27 02:28 - 00001176 _____ C:\Users\Public\Desktop\Avira Launcher.lnk
2016-03-27 02:27 - 2016-03-27 02:47 - 00000000 ____D C:\Program Files (x86)\Avira
2016-03-27 02:27 - 2016-03-27 02:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-03-27 02:27 - 2016-03-27 02:42 - 00000000 ____D C:\ProgramData\Avira
2016-03-27 02:25 - 2016-03-27 02:26 - 04733568 _____ (Avira Operations GmbH & Co. KG) C:\Users\nounours\Downloads\avira_fr_av_56f72879a1e12__ws.exe
2016-03-26 23:57 - 2016-03-26 23:57 - 00408906 _____ C:\Users\nounours\Documents\cc_20160326_225659.reg
2016-03-26 22:17 - 2016-03-26 22:17 - 00101147 _____ C:\Users\nounours\Documents\ZHPDiag.txt
2016-03-26 21:40 - 2016-03-26 21:40 - 01530368 _____ C:\Users\nounours\Downloads\adwcleaner_5.105 (1).exe
2016-03-26 21:10 - 2016-03-26 21:47 - 00000000 ____D C:\ProgramData\Easybits Magic Desktop for HP
2016-03-26 20:59 - 2016-03-27 00:55 - 00002628 _____ C:\Users\nounours\Desktop\ZHPCleaner.txt
2016-03-26 19:42 - 2016-03-27 00:35 - 00000836 _____ C:\Users\nounours\Desktop\ZHPCleaner.lnk
2016-03-26 19:37 - 2016-03-26 19:38 - 02099200 _____ C:\Users\nounours\Downloads\ZHPCleaner.exe
2016-03-26 18:05 - 2016-03-27 10:46 - 00101136 _____ C:\Users\nounours\Desktop\ZHPDiag.txt
2016-03-26 17:48 - 2016-03-27 10:51 - 00000000 ____D C:\Users\nounours\AppData\Roaming\ZHP
2016-03-26 17:48 - 2016-03-27 10:36 - 00000826 _____ C:\Users\nounours\Desktop\ZHPDiag.lnk
2016-03-26 17:47 - 2016-03-26 17:47 - 02162688 _____ C:\Users\nounours\Downloads\ZHPDiag3.exe
2016-03-26 17:14 - 2016-03-26 17:15 - 00000000 ____D C:\Program Files (x86)\GUMA65C.tmp
2016-03-26 17:14 - 2016-03-26 17:14 - 06871040 _____ C:\Program Files (x86)\GUTA821.tmp
2016-03-26 13:01 - 2016-03-26 13:02 - 05956080 _____ (AVAST Software) C:\Users\nounours\Downloads\avastclear.exe
2016-03-26 12:09 - 2016-03-26 12:09 - 00000000 ____D C:\Windows\SysWOW64\%Data%
2016-03-26 11:34 - 2016-03-26 22:25 - 00000000 ____D C:\AdwCleaner
2016-03-26 11:33 - 2016-03-26 11:33 - 01530368 _____ C:\Users\nounours\Downloads\adwcleaner_5.105.exe
2016-03-26 11:14 - 2016-03-26 11:14 - 00262144 _____ C:\Windows\system32\config\elam
2016-03-26 10:00 - 2016-03-26 10:01 - 01950728 _____ (Kaspersky Lab) C:\Users\nounours\Downloads\kis16.0.0.614abcdfr_9987.exe
2016-03-26 09:29 - 2016-03-26 09:29 - 04733568 _____ (Avira Operations GmbH & Co. KG) C:\Users\nounours\Downloads\avira_fr_av_56efa03146dd4__ws (1).exe
2016-03-26 08:56 - 2016-03-26 08:56 - 00002229 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-26 08:56 - 2016-03-26 08:56 - 00002217 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-26 08:51 - 2016-03-26 08:51 - 00987728 _____ (Google Inc.) C:\Users\nounours\Downloads\ChromeSetup.exe
2016-03-26 01:49 - 2016-03-26 01:49 - 04733568 _____ (Avira Operations GmbH & Co. KG) C:\Users\nounours\Downloads\avira_fr_froe4_56f5ce52c2d09__ws.exe
2016-03-26 01:09 - 2016-03-26 01:09 - 00894960 _____ C:\Users\nounours\Downloads\Norton_Removal_Tool.exe
2016-03-26 01:05 - 2016-03-26 01:05 - 00003168 _____ C:\Windows\System32\Tasks\{356CC5CC-4DB3-4201-9D5E-312E4085CE0E}
2016-03-25 20:08 - 2016-03-25 20:08 - 02870984 _____ (ESET) C:\Users\nounours\Downloads\esetsmartinstaller_fra.exe
2016-03-25 18:33 - 2016-03-25 18:33 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2016-03-25 18:04 - 2016-03-25 18:05 - 04733568 _____ (Avira Operations GmbH & Co. KG) C:\Users\nounours\Downloads\avira_fr_av_56f561868cf5c__ws.exe
2016-03-25 15:52 - 2016-03-27 02:24 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-25 15:52 - 2016-03-25 15:52 - 00000000 _____ C:\Users\nounours\AppData\Local\.a852.db
2016-03-25 15:51 - 2016-03-25 15:51 - 00001066 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-25 15:51 - 2016-03-25 15:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-25 15:50 - 2016-03-25 15:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-25 15:50 - 2016-03-25 15:50 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-25 15:50 - 2016-03-10 15:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-03-25 15:50 - 2016-03-10 15:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-25 15:50 - 2016-03-10 15:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-03-25 15:46 - 2016-03-25 15:48 - 22851472 _____ (Malwarebytes ) C:\Users\nounours\Downloads\mbam-setup-2.2.1.1043.exe
2016-03-25 15:41 - 2016-03-25 15:45 - 01720061 _____ (Avira Operations GmbH & Co. KG) C:\Users\nounours\Downloads\avira_fr_av_56f53f1b8c280__ws.exe
2016-03-25 14:16 - 2016-03-25 14:16 - 00002802 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2016-03-25 14:16 - 2016-03-25 14:16 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-03-25 14:16 - 2016-03-25 14:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-03-25 14:15 - 2016-03-25 14:16 - 00000000 ____D C:\Program Files\CCleaner
2016-03-25 14:01 - 2016-03-25 14:04 - 06868672 _____ (Piriform Ltd) C:\Users\nounours\Downloads\ccsetup516.exe
2016-03-25 13:12 - 2016-03-25 13:12 - 00000000 __SHD C:\Users\nounours\AppData\LocalLow\EmieUserList
2016-03-25 13:12 - 2016-03-25 13:12 - 00000000 __SHD C:\Users\nounours\AppData\LocalLow\EmieBrowserModeList
2016-03-25 13:03 - 2016-03-25 13:03 - 00000000 __SHD C:\Users\nounours\AppData\Local\EmieUserList
2016-03-25 13:03 - 2016-03-25 13:03 - 00000000 __SHD C:\Users\nounours\AppData\Local\EmieSiteList
2016-03-25 13:03 - 2016-03-25 13:03 - 00000000 __SHD C:\Users\nounours\AppData\Local\EmieBrowserModeList

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-03-27 11:30 - 2009-07-14 06:45 - 00026192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-27 11:30 - 2009-07-14 06:45 - 00026192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-27 11:24 - 2009-08-20 00:40 - 00747910 _____ C:\Windows\system32\perfh00C.dat
2016-03-27 11:24 - 2009-08-20 00:40 - 00150402 _____ C:\Windows\system32\perfc00C.dat
2016-03-27 11:24 - 2009-07-14 07:13 - 01669656 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-27 11:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-03-27 11:21 - 2009-12-11 17:27 - 00000184 _____ C:\ProgramData\HPWALog.txt
2016-03-27 11:20 - 2009-12-11 17:22 - 00085096 _____ C:\Users\nounours\AppData\Local\GDIPFONTCACHEV1.DAT
2016-03-27 11:20 - 2009-08-31 01:52 - 00000292 _____ C:\ProgramData\hpqp.ini
2016-03-27 11:18 - 2013-02-08 13:58 - 00001066 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1ce05f3ab706ae7.job
2016-03-27 11:18 - 2009-07-14 06:45 - 00350184 _____ C:\Windows\system32\FNTCACHE.DAT
2016-03-27 11:17 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-27 11:16 - 2010-02-01 21:28 - 00001070 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-27 10:55 - 2012-10-11 15:56 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-27 10:44 - 2015-02-17 14:23 - 00000000 ____D C:\Program Files (x86)\Guitar Hero 3D
2016-03-27 02:27 - 2015-01-18 20:35 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-27 00:25 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2016-03-26 23:36 - 2012-01-04 22:50 - 134163456 ___SH C:\Users\nounours\Downloads\Thumbs.db
2016-03-26 23:11 - 2013-05-30 23:30 - 00003814 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1ce05f3ab706ae7
2016-03-26 23:11 - 2010-02-01 21:28 - 00004066 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-03-26 21:39 - 2009-08-19 16:58 - 00009988 _____ C:\Windows\SysWOW64\ezdigsgn.dat
2016-03-26 18:07 - 2010-02-01 21:28 - 00000000 ____D C:\Users\nounours\AppData\Local\Google
2016-03-26 17:08 - 2009-07-14 06:45 - 00000000 ____D C:\Windows\Setup
2016-03-26 15:27 - 2009-12-14 09:49 - 00000000 ____D C:\Windows\Minidump
2016-03-26 13:56 - 2012-10-11 15:56 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-03-26 13:56 - 2012-10-11 15:56 - 00003940 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-03-26 13:56 - 2011-12-04 12:11 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-26 11:48 - 2015-01-28 17:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-03-26 11:21 - 2009-12-11 17:26 - 00001445 _____ C:\Users\nounours\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-03-26 11:09 - 2010-02-08 22:37 - 00001028 _____ C:\Users\nounours\Desktop\Internet Explorer.lnk
2016-03-26 08:55 - 2010-02-01 21:28 - 00000000 ____D C:\Program Files (x86)\Google
2016-03-26 01:35 - 2009-08-19 14:55 - 00000000 ____D C:\Program Files (x86)\Windows Live
2016-03-26 01:30 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-03-26 01:15 - 2015-02-12 22:43 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2016-03-26 01:14 - 2012-11-29 18:58 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-03-25 22:06 - 2010-02-01 19:26 - 00003960 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F69945ED-6370-470C-9B05-A36CDBBB90C4}
2016-03-25 21:31 - 2009-07-14 07:08 - 00032482 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-03-25 18:48 - 2010-02-01 21:28 - 00000000 ____D C:\Program Files\Google
2016-03-25 18:21 - 2014-06-14 11:05 - 00000000 ____D C:\ProgramData\Skype
2016-03-25 18:20 - 2014-06-14 11:06 - 00000000 ____D C:\Users\nounours\AppData\Roaming\Skype
2016-03-25 17:50 - 2010-02-01 21:28 - 00000000 ____D C:\ProgramData\Google
2016-03-25 15:14 - 2015-04-03 14:02 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2016-03-25 14:44 - 2009-12-18 14:35 - 00000000 ____D C:\Users\nounours\Tracing
2016-03-25 14:40 - 2009-07-25 08:11 - 00000000 ____D C:\Windows\Panther
2016-03-25 14:40 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\ModemLogs
2016-03-25 14:26 - 2009-12-11 17:08 - 00000000 ____D C:\Users\nounours
2016-03-25 13:12 - 2014-10-01 21:06 - 00000000 __SHD C:\Users\nounours\AppData\LocalLow\EmieSiteList
2016-03-25 12:55 - 2009-08-19 15:53 - 00000000 ____D C:\ProgramData\Symantec

==================== Fichiers à la racine de certains dossiers =======

2016-03-26 17:14 - 2016-03-26 17:14 - 6871040 _____ () C:\Program Files (x86)\GUTA821.tmp
2015-03-03 13:20 - 2015-03-03 13:20 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2010-12-24 19:06 - 2010-12-25 01:01 - 0003778 _____ () C:\Users\nounours\AppData\Roaming\38B4.F40
2011-01-12 11:27 - 2011-09-08 15:29 - 0001854 _____ () C:\Users\nounours\AppData\Roaming\GhostObjGAFix.xml
2010-02-25 03:20 - 2010-02-25 03:20 - 1761575 _____ () C:\Users\nounours\AppData\Roaming\UserTile.png
2016-03-25 15:52 - 2016-03-25 15:52 - 0000000 _____ () C:\Users\nounours\AppData\Local\.a852.db
2009-12-11 17:27 - 2009-12-11 17:27 - 0000000 _____ () C:\Users\nounours\AppData\Local\AtStart.txt
2010-01-12 03:41 - 2013-08-28 20:30 - 0017408 _____ () C:\Users\nounours\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-12-11 17:27 - 2009-12-11 17:27 - 0000000 _____ () C:\Users\nounours\AppData\Local\DSwitch.txt
2009-12-11 17:27 - 2009-12-11 17:27 - 0000000 _____ () C:\Users\nounours\AppData\Local\QSwitch.txt
2009-08-31 01:52 - 2016-03-27 11:20 - 0000292 _____ () C:\ProgramData\hpqp.ini
2009-12-11 19:07 - 2013-04-23 14:49 - 0000021 _____ () C:\ProgramData\hpqp.txt
2009-12-11 17:27 - 2016-03-27 11:21 - 0000184 _____ () C:\ProgramData\HPWALog.txt
2009-08-31 01:54 - 2009-08-31 01:54 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2009-08-19 16:47 - 2009-08-19 16:48 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2009-08-31 01:53 - 2009-08-31 01:53 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2009-08-19 16:42 - 2009-08-19 16:43 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2009-08-31 01:52 - 2009-08-31 01:52 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2009-08-31 01:53 - 2009-08-31 01:53 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2009-08-19 16:41 - 2009-08-19 16:41 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2009-08-19 16:43 - 2009-08-19 16:47 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2009-08-31 01:54 - 2009-08-31 01:54 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

Certains fichiers dans TEMP:
====================
C:\Users\nounours\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap =================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement
C:\Windows\system32\wininit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement
C:\Windows\explorer.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\Windows\system32\svchost.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\Windows\system32\services.exe => Le fichier est signé numériquement
C:\Windows\system32\User32.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\Windows\system32\userinit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement
C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement


LastRegBack: 2014-12-05 13:12

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité