cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:10-04-2016 01
Exécuté par Thierry & Bea (administrateur) sur THIERRYBEA-HP (12-04-2016 20:30:10)
Exécuté depuis C:\Users\Thierry & Bea\telechargements
Profils chargés: Thierry & Bea (Profils disponibles: Thierry & Bea & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files (x86)\ProgCtrl\ProgCtrlSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
() C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\DedicarzService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(BitTorrent, Inc.) C:\Program Files (x86)\uTorrent\uTorrent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [611896 2010-09-15] ()
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1803392 2015-10-18] (NVIDIA Corporation)
HKLM-x32\...\Run: [Google Quick Search Box] => C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe [126976 2011-06-24] (Google Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [55264 2016-03-10] (Malwarebytes)
HKLM\...\Winlogon: [Userinit] wscript,
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-06-24] (Google Inc.)
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Run: [OrangeInside] => C:\Users\Thierry & Bea\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe [1508864 2012-04-16] (Orange)
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Run: [MailNotifier] => C:\Program Files (x86)\Orange\MailNotifier\MailNotifier.exe [912896 2015-05-28] (Orange)
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-30] (Disc Soft Ltd)
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Run: [GoogleChromeAutoLaunch_564402EB2FECE1AF0B12BF2B26852402] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [741704 2015-12-11] (Google Inc.)
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\RunOnce: [Uninstall C:\Users\Thierry & Bea\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Thierry & Bea\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64"
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\RunOnce: [Uninstall C:\Users\Thierry & Bea\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Thierry & Bea\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1"
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Policies\system: [Shell] "C:\Program Files (x86)\EasyBits For Kids\ezMDLauncher.exe" /shell
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Policies\Explorer: [NoLogoff] 0
Startup: C:\Users\Thierry & Bea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Alertes de surveillance de l'encre - HP Deskjet 2540 series.lnk [2016-04-12]
ShortcutTarget: Alertes de surveillance de l'encre - HP Deskjet 2540 series.lnk -> C:\Program Files\hp\HP Deskjet 2540 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath devrait être "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath devrait être "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath devrait être "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath devrait être "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath devrait être "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath devrait être "%SystemRoot%\System32\winrnr.dll"
Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{09987999-ecbe-4ee2-92f2-d6e2d1e5620c}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131049458180406132&GUID=B9189F0C-25D7-4947-A175-9BCD0E12D373
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131049458180409265&GUID=B9189F0C-25D7-4947-A175-9BCD0E12D373
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131042566927240604&GUID=B9189F0C-25D7-4947-A175-9BCD0E12D373
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131042566927240604&GUID=B9189F0C-25D7-4947-A175-9BCD0E12D373
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131049458180415576&GUID=B9189F0C-25D7-4947-A175-9BCD0E12D373
HKU\S-1-5-21-2716573329-757678112-2829408005-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131042566927240604&GUID=B9189F0C-25D7-4947-A175-9BCD0E12D373
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = hxxp://rover.ebay.com/rover/1/709-111075-12437-0/4?satitle={searchTerms}&mfe=Desktops
SearchScopes: HKLM-x32 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = hxxp://rover.ebay.com/rover/1/709-111075-12437-0/4?satitle={searchTerms}&mfe=Desktops
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2716573329-757678112-2829408005-1001 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL =
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-08-05] (Google Inc.)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-23] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-08-05] (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-23] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-08-05] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-08-05] (Google Inc.)
Toolbar: HKU\S-1-5-21-2716573329-757678112-2829408005-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-08-05] (Google Inc.)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - Pas de fichier
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - Pas de fichier

FireFox:
========
FF ProfilePath: C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF Homepage: hxxp://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage_FF
FF SelectedSearchEngine: Orange
FF Keyword.URL: hxxp://r.orange.fr/r?ref=O_OI_hook_openSearchFF&url=http%3A//rws.search.ke.voila.fr/RW/S/opensearch_orange?rdata=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-07] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-07] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2011-10-17] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-23] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-13] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-11-20] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-11-20] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-06-28] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\user.js [2016-04-11]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\g3nu3jim.default\searchplugins\orange.xml [2015-12-27]
FF SearchPlugin: C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\orange.xml [2016-04-11]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-06-24] [non signé]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-14] [non signé]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-11] [non signé]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-25] [non signé]
FF Extension: barre d'outils Orange - C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\toolbar@Orange.fr [2015-12-27] [non signé]
FF Extension: Plugin Orange Installeur - C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\{4D9AE42B-F4C0-40e6-AEDB-4EC6E42B77AF} [2015-12-27] [non signé]
FF Extension: Pas de nom - C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\{eaf2d947-d815-4e6e-a363-d91c59ded9be} [non trouvé(e)]
FF Extension: Menu Contextuel Orange - C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\menu_contextuel_orange@orange.fr [2016-04-11] [non signé]
FF Extension: Pas de nom - C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\cacaoweb@cacaoweb.org [non trouvé(e)]
FF Extension: Menu Contextuel Orange - C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\g3nu3jim.default\Extensions\menu_contextuel_orange@orange.fr [2015-12-27] [non signé]
FF Extension: barre d'outils Orange - C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\g3nu3jim.default\Extensions\toolbar@Orange.fr [2012-02-13] [non signé]
FF Extension: Plugin Orange Installeur - C:\Users\Thierry & Bea\AppData\Roaming\Mozilla\Firefox\Profiles\g3nu3jim.default\Extensions\{4D9AE42B-F4C0-40e6-AEDB-4EC6E42B77AF} [2011-12-10] [non signé]
FF HKLM-x32\...\Firefox\Extensions: [{3112ca9c-de6d-4884-a869-9855de68056c}] - C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}
FF Extension: Google Toolbar for Firefox - C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011-06-24] [non signé]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-07-07] [non signé]
FF HKU\S-1-5-21-2716573329-757678112-2829408005-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-04-02] <==== ATTENTION

Chrome:
=======
CHR StartupUrls: Default -> "hxxps://www.google.fr/webhp?gws_rd=ssl"
CHR DefaultSearchURL: Default -> hxxp://www-searching.com/search.aspx?s=G4Azftpbl0cshmoBJ,7ea14bbe-e68e-4dbd-9826-87eedeadd799,&prd=smw&q={searchTerms}
CHR DefaultSearchKeyword: Default -> www-searching.com
CHR DefaultSuggestURL: Default -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\PepperFlash\11.6.602.167\pepflashplayer.dll => Pas de fichier
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\ppGoogleNaClPluginChrome.dll => Pas de fichier
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\pdf.dll => Pas de fichier
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => Pas de fichier
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll => Pas de fichier
CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => Pas de fichier
CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => Pas de fichier
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll => Pas de fichier
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll => Pas de fichier
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll => Pas de fichier
CHR Profile: C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Adblock Plus) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-12]
CHR Extension: (ZenMate VPN - Sécurité internet & Unblock) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2016-04-09]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-07]
CHR Profile: C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Mysearchdial) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-09]
CHR Extension: (Mysearchdial) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-09]
CHR Extension: (GoSave) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\elmhikipebgpenpobclikhngcchohcgl [2014-10-15]
CHR Extension: (GoSave) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hciccclocgefpahmfcfgmfnfmdempimi [2014-10-17]
CHR Extension: (GoSave) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\homgoodgbekocjomogagcdfgnigmbmlo [2014-10-15]
CHR Extension: (Mysearchdial) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\onmkoldigcfmebcinpmineoadckalllb [2014-10-15]
CHR Extension: (Mysearchdial) - C:\Users\Thierry & Bea\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-13]
CHR HKLM-x32\...\Chrome\Extension: [odbbfaealmlpnodchplhdomkgpdkeeal] - C:\Program Files (x86)\RebateInformer\Chrome\rebateinformer_c.crx

==================== Services (Avec liste blanche) ========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 Dedicarz Service; C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\DedicarzService.exe [1966960 2013-09-17] () [Fichier non signé]
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1368408 2015-11-30] (Disc Soft Ltd)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2015-04-15] (Freemake) [Fichier non signé]
R3 hpqcxs08; C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll [253568 2009-11-18] (Hewlett-Packard Co.)
R2 hpqddsvc; C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll [137344 2009-11-18] (Hewlett-Packard Co.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [26680 2016-02-18] (Hewlett-Packard Company)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [Fichier non signé]
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [Fichier non signé]
S2 Orange update Core Service; C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe [730368 2016-02-17] (Orange SA)
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [Fichier non signé]
R2 ProgCtrlSvc; C:\Program Files (x86)\ProgCtrl\ProgCtrlSvc.exe [40960 2007-01-25] () [Fichier non signé]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 Gemkexfh; "C:\Users\Thierry & Bea\AppData\Roaming\EeiteToclisc\Huuczes.exe" -cms [X]

===================== Pilotes (Avec liste blanche) ==========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-12-27] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [46392 2015-12-27] (Disc Soft Ltd)
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )
R1 UCGuard; C:\Windows\System32\DRIVERS\ucguard.sys [80768 2016-03-28] (Huorong Borui (Beijing) Technology Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; pas de ImagePath
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-04-12 20:29 - 2016-04-12 20:30 - 00000000 ____D C:\FRST
2016-04-12 12:28 - 2016-04-12 12:28 - 00000049 _____ C:\Users\Thierry & Bea\Desktop\iGoogle.url
2016-04-11 22:49 - 2016-04-11 22:49 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-04-11 22:46 - 2016-04-11 22:49 - 00108560 _____ C:\WINDOWS\ntbtlog.txt
2016-04-11 21:56 - 2016-04-11 21:56 - 00000000 ____D C:\$SysReset
2016-04-10 21:10 - 2016-04-10 21:13 - 00007605 _____ C:\Users\Thierry & Bea\AppData\Local\resmon.resmoncfg
2016-04-10 20:41 - 2016-04-10 20:41 - 00003676 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2016-04-10 19:23 - 2016-04-10 19:23 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-04-10 19:11 - 2016-04-10 19:11 - 00000000 ____D C:\WINDOWS\system32\gawj
2016-04-10 19:00 - 2016-04-10 19:01 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Roaming\ZHP
2016-04-10 17:59 - 2016-04-10 17:59 - 00000000 ____D C:\WINDOWS\system32\jid
2016-04-10 17:16 - 2016-04-10 17:16 - 00000000 ____D C:\WINDOWS\system32\vor
2016-04-10 16:54 - 2016-04-10 16:54 - 00000000 ____D C:\WINDOWS\system32\gafu
2016-04-10 16:41 - 2016-04-10 16:41 - 00000000 ____D C:\WINDOWS\system32\ucom
2016-04-10 15:49 - 2016-04-10 15:49 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Roaming\MCorp
2016-04-10 15:47 - 2016-04-11 19:02 - 00000398 _____ C:\WINDOWS\Tasks\FYJHMJXE1.job
2016-04-10 15:47 - 2016-04-11 19:02 - 00000386 ____H C:\WINDOWS\Tasks\MNBMOBWWFOFVQJGP.job
2016-04-10 15:47 - 2016-04-10 15:47 - 00003494 _____ C:\WINDOWS\System32\Tasks\MNBMOBWWFOFVQJGP
2016-04-10 15:47 - 2016-04-10 15:47 - 00003438 _____ C:\WINDOWS\System32\Tasks\Khebi
2016-04-10 15:47 - 2016-04-10 15:47 - 00002974 _____ C:\WINDOWS\System32\Tasks\FYJHMJXE1
2016-04-10 15:46 - 2016-04-10 20:06 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Roaming\Naqbegoza
2016-04-10 15:46 - 2016-04-10 15:46 - 00000000 ____D C:\ProgramData\19a87fa1ec024bbcbb41931263354405
2016-04-10 15:36 - 2016-04-10 15:44 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器
2016-04-10 15:35 - 2016-04-10 15:35 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Local\UCBrowser
2016-04-10 15:35 - 2016-03-28 14:28 - 00080768 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-04-10 15:28 - 2016-04-10 20:06 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Roaming\Bulxo
2016-04-10 15:28 - 2016-04-10 20:05 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Roaming\JusjotSuvda
2016-04-10 15:28 - 2016-04-10 15:46 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Local\Tempfolder
2016-04-10 15:28 - 2016-04-10 15:28 - 00003442 _____ C:\WINDOWS\System32\Tasks\Nypulh
2016-04-10 15:27 - 2016-04-10 15:54 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Local\app
2016-04-10 15:26 - 2016-04-10 19:59 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Local\bvyvave
2016-04-10 15:26 - 2016-04-10 15:28 - 00003598 _____ C:\WINDOWS\System32\Tasks\bvyvave
2016-04-10 15:25 - 2016-04-10 20:00 - 00000000 ____D C:\Users\Thierry & Bea\AppData\LocalLow\Company
2016-04-10 15:25 - 2016-04-10 15:25 - 00003438 _____ C:\WINDOWS\System32\Tasks\Colnour
2016-04-10 15:25 - 2016-04-10 15:25 - 00000000 ____D C:\uninst
2016-04-10 15:23 - 2016-04-11 12:18 - 00187904 _____ C:\WINDOWS\rsrcs.dll
2016-04-10 15:14 - 2016-04-10 15:12 - 00001006 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2016-04-10 15:12 - 2016-04-10 15:15 - 00000855 _____ C:\WINDOWS\SysWOW64\${LOGFILE}
2016-04-10 15:11 - 2016-04-10 19:59 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Local\wd
2016-04-09 21:28 - 2016-04-08 13:54 - 898867209 _____ C:\Users\Thierry & Bea\Desktop\Joy.2015.MULTi.1080p.WEB.H264-SiGeRiS.www.Zone-Telechargement.com.mkv
2016-04-09 20:21 - 2016-04-09 13:37 - 3516808652 _____ C:\Users\Thierry & Bea\Desktop\Ooops.Noah.is.gone.2015.FRENCH.720p.BluRay.x264-LOST.www.Zone-Telechargement.com.mkv
2016-04-09 17:22 - 2016-04-08 17:30 - 3675244984 _____ C:\Users\Thierry & Bea\Desktop\The.Revenant.2015.MULTi.1080p.BluRay.x264-ULS.www.Zone-Telechargement.com.mkv
2016-04-09 14:08 - 2016-04-06 13:37 - 1574777220 _____ C:\Users\Thierry & Bea\Desktop\Un.Plus.Une.2015.FRENCH.720p.BluRay.x264-LOST.www.Zone-Telechargement.com.mkv
2016-04-09 11:26 - 2016-04-09 11:26 - 00000259 _____ C:\Users\Thierry & Bea\Desktop\Zone Telechargement - Site de Téléchargement Gratuit.url
2016-04-06 15:09 - 2016-04-06 15:09 - 00694272 _____ C:\WINDOWS\system32\bi.exe
2016-04-05 16:29 - 2016-04-05 16:29 - 00137728 _____ C:\WINDOWS\1edb4f06f6ad9d6d8af8a810c05351d5.exe
2016-03-26 12:48 - 2016-03-26 12:48 - 00368982 _____ C:\Users\Thierry & Bea\Desktop\Scan.pdf
2016-03-24 21:45 - 2016-03-24 21:45 - 00000000 ____D C:\WINDOWS\Minidump
2016-03-18 10:57 - 2016-03-18 11:00 - 00000000 ____D C:\Users\Thierry & Bea\Desktop\photo boulot

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-04-12 20:30 - 2011-12-23 18:58 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Roaming\uTorrent
2016-04-12 20:30 - 2011-06-24 21:10 - 00000000 ___RD C:\Users\Thierry & Bea\telechargements
2016-04-12 20:15 - 2011-06-24 21:30 - 00001110 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-12 20:01 - 2012-04-18 09:10 - 00001002 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-12 18:59 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-04-12 16:16 - 2011-06-24 21:27 - 00004196 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{815AF816-5561-4B7C-8D68-74FA33E087C9}
2016-04-12 12:45 - 2011-06-24 21:32 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Roaming\vlc
2016-04-12 09:51 - 2016-01-28 13:01 - 00003348 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForThierry & Bea
2016-04-12 09:51 - 2016-01-28 13:01 - 00000392 _____ C:\WINDOWS\Tasks\HPCeeScheduleForThierry & Bea.job
2016-04-11 22:51 - 2016-02-27 11:42 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-11 22:51 - 2016-02-27 10:54 - 00000000 ____D C:\ProgramData\NVIDIA
2016-04-11 22:50 - 2015-10-30 08:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-04-11 22:02 - 2015-10-30 09:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-11 21:01 - 2016-02-27 10:57 - 02129142 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-11 21:01 - 2015-10-30 21:00 - 00931396 _____ C:\WINDOWS\system32\perfh00C.dat
2016-04-11 21:01 - 2015-10-30 21:00 - 00197908 _____ C:\WINDOWS\system32\perfc00C.dat
2016-04-11 20:56 - 2011-06-28 19:32 - 00000000 ____D C:\Users\Thierry & Bea\AppData\Local\ElevatedDiagnostics
2016-04-11 20:24 - 2016-02-27 10:58 - 00000000 ____D C:\Users\Thierry & Bea
2016-04-11 20:24 - 2016-02-27 10:48 - 00000000 ___DC C:\WINDOWS\Panther
2016-04-11 20:24 - 2011-06-24 21:30 - 00001106 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-11 19:05 - 2015-12-09 17:16 - 00003036 _____ C:\WINDOWS\System32\Tasks\AssistanceLivebox
2016-04-11 18:37 - 2014-04-30 18:33 - 00000000 ____D C:\AdwCleaner
2016-04-11 13:40 - 2011-07-05 08:51 - 00000000 ____D C:\Users\Thierry & Bea\BEATRICE
2016-04-10 22:02 - 2015-10-30 09:18 - 00686984 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-10 22:02 - 2015-10-30 09:18 - 00535088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-10 21:14 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\Registration
2016-04-10 20:05 - 2015-10-30 09:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2016-04-10 20:04 - 2016-02-27 11:09 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-04-10 20:04 - 2015-09-08 09:00 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-04-10 20:04 - 2013-02-12 18:47 - 00002419 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk
2016-04-10 20:04 - 2011-06-24 21:10 - 00001787 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garantie.lnk
2016-04-10 20:04 - 2011-03-25 05:48 - 00002372 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Install HP Power Assistant.lnk
2016-04-10 20:04 - 2011-03-25 05:32 - 00001429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk
2016-04-10 20:03 - 2016-01-29 20:32 - 00002237 _____ C:\Users\Public\Desktop\Style Builder 2016.lnk
2016-04-10 20:03 - 2016-01-29 20:32 - 00002151 _____ C:\Users\Public\Desktop\LayOut 2016.lnk
2016-04-10 20:03 - 2016-01-29 20:32 - 00002062 _____ C:\Users\Public\Desktop\SketchUp 2016.lnk
2016-04-10 20:03 - 2015-12-27 15:44 - 00001860 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2016-04-10 20:03 - 2015-12-10 20:09 - 00002291 _____ C:\Users\Public\Desktop\HP Deskjet 2540 series.lnk
2016-04-10 20:03 - 2015-12-10 20:09 - 00002022 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk
2016-04-10 20:03 - 2015-12-10 20:09 - 00001238 _____ C:\Users\Public\Desktop\Achat de consommables - HP Deskjet 2540 series.lnk
2016-04-10 20:03 - 2015-09-08 09:00 - 00002086 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-04-10 20:03 - 2015-08-14 21:02 - 00001049 _____ C:\Users\Thierry & Bea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fonctionnalités optionnelles.lnk
2016-04-10 20:03 - 2015-08-14 21:01 - 00002478 _____ C:\Users\Thierry & Bea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-04-10 20:03 - 2015-05-17 14:51 - 00001282 _____ C:\Users\Public\Desktop\Freemake Audio Converter.lnk
2016-04-10 20:03 - 2014-07-27 14:57 - 00000363 _____ C:\Users\Thierry & Bea\Desktop\ordi.lnk
2016-04-10 20:03 - 2014-07-07 19:00 - 00001474 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Centre de solutions HP.lnk
2016-04-10 20:03 - 2013-02-20 18:41 - 00000993 _____ C:\Users\Public\Desktop\PDFCreator.lnk
2016-04-10 20:03 - 2011-12-23 18:59 - 00000911 _____ C:\ProgramData\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-04-10 20:03 - 2011-12-23 18:59 - 00000905 _____ C:\Users\Public\Desktop\µTorrent.lnk
2016-04-10 20:03 - 2011-11-29 10:51 - 00001307 _____ C:\Users\Thierry & Bea\Desktop\Assistance Livebox.lnk
2016-04-10 20:03 - 2011-11-21 11:56 - 00002174 _____ C:\Users\Public\Desktop\Google Earth.lnk
2016-04-10 20:03 - 2011-11-12 20:51 - 00001224 _____ C:\Users\Thierry & Bea\Desktop\Paint.lnk
2016-04-10 20:03 - 2011-06-24 23:33 - 00001068 _____ C:\Users\Thierry & Bea\Desktop\Picasa 3.lnk
2016-04-10 20:03 - 2011-06-24 23:32 - 00002777 _____ C:\Users\Thierry & Bea\Desktop\Microsoft Office Outlook 2007.lnk
2016-04-10 20:03 - 2011-06-24 23:32 - 00002735 _____ C:\Users\Thierry & Bea\Desktop\Microsoft Office Word 2007.lnk
2016-04-10 20:03 - 2011-06-24 23:32 - 00002710 _____ C:\Users\Thierry & Bea\Desktop\Nero StartSmart Essentials.lnk
2016-04-10 20:03 - 2011-06-24 23:32 - 00002693 _____ C:\Users\Thierry & Bea\Desktop\Microsoft Office Excel 2007.lnk
2016-04-10 20:03 - 2011-06-24 23:32 - 00002665 _____ C:\Users\Thierry & Bea\Desktop\Microsoft Office Publisher 2007.lnk
2016-04-10 20:03 - 2011-06-24 23:32 - 00002649 _____ C:\Users\Thierry & Bea\Desktop\Microsoft Office PowerPoint 2007.lnk
2016-04-10 20:03 - 2011-06-24 23:32 - 00001152 _____ C:\Users\Thierry & Bea\Desktop\OpenOffice.org.lnk
2016-04-10 20:03 - 2011-06-24 21:48 - 00002687 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Nouveau document Microsoft Office.lnk
2016-04-10 20:03 - 2011-06-24 21:48 - 00002683 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Ouvrir un document Microsoft Office.lnk
2016-04-10 20:03 - 2009-07-14 06:55 - 00001212 _____ C:\Users\Thierry & Bea\Desktop\Calculator.lnk
2016-04-10 19:59 - 2011-07-05 09:18 - 00000000 ____D C:\Users\Thierry & Bea\THIERRY
2016-04-10 16:09 - 2014-10-15 17:12 - 00000290 __RSH C:\ProgramData\ntuser.pol
2016-04-10 16:00 - 2009-07-14 04:34 - 00000580 _____ C:\WINDOWS\win.ini
2016-04-10 15:44 - 2015-08-14 20:54 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-04-10 15:11 - 2012-01-19 19:31 - 00000000 ____D C:\Temp
2016-04-09 17:03 - 2015-10-30 09:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-08 14:30 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-07 17:11 - 2011-06-28 19:39 - 00183808 _____ C:\Users\Thierry & Bea\Desktop\répertoire.xls
2016-04-05 20:21 - 2011-07-25 14:21 - 00003268 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForTHIERRYBEA-HP$
2016-04-05 20:21 - 2011-07-25 14:21 - 00000354 _____ C:\WINDOWS\Tasks\HPCeeScheduleForTHIERRYBEA-HP$.job
2016-04-05 09:32 - 2011-06-24 21:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-04-04 17:04 - 2016-02-27 10:49 - 00382640 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-31 16:58 - 2011-07-05 08:49 - 00000000 ____D C:\Users\Thierry & Bea\LOIC
2016-03-24 21:44 - 2011-03-25 07:28 - 00147772 ____N C:\WINDOWS\Minidump\032416-22687-01.dmp
2016-03-23 13:08 - 2015-10-30 09:11 - 00000000 ____D C:\WINDOWS\CbsTemp

==================== Fichiers à la racine de certains dossiers =======

2011-12-20 16:09 - 2011-12-21 16:29 - 0001671 _____ () C:\Users\Thierry & Bea\AppData\Roaming\Ashampoo Gadge It event.log
2014-05-31 17:44 - 2014-05-31 17:44 - 0000036 _____ () C:\Users\Thierry & Bea\AppData\Roaming\DOK52P4Q3J.dat
2011-12-10 19:31 - 2012-02-13 13:42 - 0000043 _____ () C:\Users\Thierry & Bea\AppData\Roaming\stats.txt
2014-07-31 15:32 - 2014-07-31 15:32 - 0000036 _____ () C:\Users\Thierry & Bea\AppData\Roaming\SuYZkvrV.tmp
2013-03-25 21:16 - 2013-03-25 21:16 - 0027128 _____ () C:\Users\Thierry & Bea\AppData\Roaming\UserTile.png
2014-04-29 21:51 - 2014-04-29 21:51 - 0000045 _____ () C:\Users\Thierry & Bea\AppData\Roaming\WB.CFG
2012-08-01 11:47 - 2014-10-24 17:01 - 0009728 _____ () C:\Users\Thierry & Bea\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-04-10 21:10 - 2016-04-10 21:13 - 0007605 _____ () C:\Users\Thierry & Bea\AppData\Local\resmon.resmoncfg
2013-02-21 19:49 - 2013-02-21 19:48 - 0338815 _____ () C:\Users\Thierry & Bea\AppData\Local\speeddial.crx
2011-09-16 19:57 - 2011-09-16 19:57 - 0000000 _____ () C:\Users\Thierry & Bea\AppData\Local\{90A833B5-7C23-4873-98FF-BE7E127FE09B}
2015-12-10 20:09 - 2015-12-10 20:09 - 0000057 _____ () C:\ProgramData\Ament.ini
2011-11-04 15:12 - 2014-07-07 20:11 - 0006871 _____ () C:\ProgramData\hpzinstall.log

Fichiers à déplacer ou supprimer:
====================
C:\Users\Thierry & Bea\Framakey.exe


Certains fichiers dans TEMP:
====================
C:\Users\Thierry & Bea\AppData\Local\Temp\23333.exe
C:\Users\Thierry & Bea\AppData\Local\Temp\32RZAE5PU0.exe
C:\Users\Thierry & Bea\AppData\Local\Temp\bitool.dll
C:\Users\Thierry & Bea\AppData\Local\Temp\Browser_V5.6.11466.7_r_4728_(Build1603281525).exe
C:\Users\Thierry & Bea\AppData\Local\Temp\libeay32.dll
C:\Users\Thierry & Bea\AppData\Local\Temp\msvcr120.dll
C:\Users\Thierry & Bea\AppData\Local\Temp\NJ2VAPY73O.exe
C:\Users\Thierry & Bea\AppData\Local\Temp\NUU0BMEEUB.exe
C:\Users\Thierry & Bea\AppData\Local\Temp\OLY2RWXXGE.exe
C:\Users\Thierry & Bea\AppData\Local\Temp\Q623JTI969.exe
C:\Users\Thierry & Bea\AppData\Local\Temp\qqpcmgr_v11.4.17339.217_45303_Silence.exe
C:\Users\Thierry & Bea\AppData\Local\Temp\Quarantine.exe
C:\Users\Thierry & Bea\AppData\Local\Temp\sqlite3.dll
C:\Users\Thierry & Bea\AppData\Local\Temp\tu17p84.exe


==================== Bamital & volsnap =================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement


LastRegBack: 2016-04-11 12:52

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité