cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:21-05-2016
Exécuté par Naïma (administrateur) sur NAIMALIEDRI (21-05-2016 11:57:59)
Exécuté depuis C:\Users\Naïma\Desktop
Profils chargés: UpdatusUser & Naïma & Administrateur (Profils disponibles: UpdatusUser & Naïma & Administrateur)
Platform: Windows 8.1 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Windows\SysWOW64\PSIService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avpui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Flux Software LLC) C:\Users\Naïma\AppData\Local\FluxSoftware\Flux\flux.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Users\Naïma\Documents\ZHPDiag3.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe


==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506136 2013-12-07] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1368792 2013-11-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1368792 2013-11-13] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-30] (Intel Corporation)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-18] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Corel Photo Downloader] => C:\Program Files (x86)\Corel\Corel MediaOne\Corel Photo Downloader.exe [481608 2008-07-09] (Corel, Inc.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareTray.exe [9558752 2015-08-27] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Corel File Shell Monitor] => C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16712 2008-08-18] ()
HKLM-x32\...\Run: [Corel Photo Downloader] => C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe [532808 2008-08-18] (Corel, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4127488 2015-06-16] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\...\Run: [FlashGet 3] => C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe [3377256 2013-04-18] (Trend Media Corporation Limited)
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [51662464 2016-04-08] (Skype Technologies S.A.)
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\...\Run: [f.lux] => C:\Users\Naïma\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC)
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [589312 2014-10-29] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Gestionnaire Antidote.exe] => C:\PROGRA~2\Druide\Antidote\Gestionnaire Antidote.exe
HKU\S-1-5-18\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [168616 2013-10-24] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [141336 2013-10-24] (NVIDIA Corporation)
AppInit_DLLs-x32: ,C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [141336 2013-10-24] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\WINDOWS\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\WINDOWS\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk [2014-04-22]
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{877E026E-38AE-4671-9BD8-47ECF0542AEC}: [DhcpNameServer] 172.121.1.171
Tcpip\..\Interfaces\{98919D6D-F2BF-4A4E-AE1D-F7425DE969E1}: [DhcpNameServer] 192.168.0.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1001\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-661552332-2814264726-1606198710-1001\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1001\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=SKY2&ocid=SKY2DHP&osmkt=fr-fr
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-1002\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-500\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-500\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-500\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-661552332-2814264726-1606198710-500\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxps://www.google.com/
HKU\S-1-5-21-661552332-2814264726-1606198710-500\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxps://www.google.com/
URLSearchHook: [S-1-5-21-661552332-2814264726-1606198710-1001] ATTENTION => URLSearchHook par défaut est absent
URLSearchHook: [S-1-5-21-661552332-2814264726-1606198710-500] ATTENTION => URLSearchHook par défaut est absent
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {B43B308F-E309-49E8-83C2-0F8569F6CDA7} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-661552332-2814264726-1606198710-500 -> DefaultScope {B43B308F-E309-49E8-83C2-0F8569F6CDA7} URL =
BHO: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2015-10-19] (AO Kaspersky Lab)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: FlashGetBHO -> {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} -> C:\Users\Naïma\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll [2012-11-01] (Trend Media Group)
BHO-x32: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2015-10-19] (AO Kaspersky Lab)
Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\IEExt\ie_plugin.dll [2015-10-19] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2015-10-19] (AO Kaspersky Lab)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-03] (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-04-23] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_D772DC8D6FAF43A29B25C4EBAA5AD1DE@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox
FF Extension: Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox [2016-02-29]

Chrome:
=======
CHR dev: Chrome dev build détecté(e)! <======= ATTENTION
CHR Session Restore: Default -> est activé.
CHR Profile: C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-11]
CHR Extension: (Google Docs) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-11]
CHR Extension: (Google Drive) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-11]
CHR Extension: (Wallpapers for every day) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\clicagfjolhpbjmncgngldfbkmnlpgmj [2016-05-14]
CHR Extension: (Recherche Google) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (New Wallpaper every day) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejaigjemablokgafbchogmobhlbpno [2016-05-11]
CHR Extension: (Google Sheets) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-11]
CHR Extension: (Wallpapers for every day) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnkhlilpallbklddfckpnhhhohpjfaoo [2016-05-13]
CHR Extension: (Google Docs hors connexion) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-19]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Gmail) - C:\Users\Naïma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-11]
CHR HKLM\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka

==================== Services (Avec liste blanche) ========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 AVP16.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe [194000 2015-10-11] (Kaspersky Lab ZAO)
S2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2557136 2015-02-26] (Dell Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Fichier non signé]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-03] (Intel Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-11] (Intel Corporation)
R2 ISCTAgent; c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-10-03] ()
S3 iumsvc; c:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
S2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.8.586.8535\AdAwareService.exe [712432 2015-08-27] ()
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-08-23] ()
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation)
U2 ProtexisLicensing; C:\WINDOWS\SysWOW64\PSIService.exe [177704 2007-06-05] ()
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2013-07-30] (CyberLink)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [289496 2013-12-07] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1750712 2015-06-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2102496 2015-06-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [224712 2015-07-24] (Safer-Networking Ltd.)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1915920 2013-11-21] (SoftThinks SAS)
R2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [21160 2015-09-30] (Dell Inc.)
S3 vssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\vssbridge64.exe [144640 2015-07-09] (AO Kaspersky Lab)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3667696 2013-08-23] (Intel® Corporation)

===================== Pilotes (Avec liste blanche) ==========================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [132608 2015-01-30] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132920 2013-04-23] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1386296 2013-08-19] (Motorola Solutions, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO)
S3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [23760 2015-01-31] (Dell Computer Corporation)
S3 DellProf; C:\Windows\system32\drivers\DellProf.sys [23312 2015-01-31] (Dell Computer Corporation)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-25] (OSR Open Systems Resources, Inc.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [118216 2013-09-10] (Intel Corporation)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-08] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-08] ()
R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-07] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-08] ()
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-22] (Kaspersky Lab ZAO)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [70512 2015-06-27] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [77728 2016-02-29] (AO Kaspersky Lab)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [30328 2015-06-24] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [181640 2015-10-19] (AO Kaspersky Lab)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [227512 2015-10-19] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [927640 2016-02-29] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [39608 2015-06-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [41656 2015-06-06] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [41352 2015-10-11] (AO Kaspersky Lab)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [87944 2015-10-19] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [102584 2015-06-16] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [187056 2015-06-23] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2016-05-15] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3589600 2013-09-25] (Intel Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [444632 2013-10-19] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-09-05] (Synaptics Incorporated)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [452040 2015-01-22] (BitDefender S.R.L.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 PCDSRVC{3B54B31B-D06B6431-06020200}_0; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-05-21 11:55 - 2016-05-21 11:57 - 00048466 _____ C:\Users\Naïma\Desktop\Addition.txt
2016-05-21 11:55 - 2016-05-21 11:57 - 00027575 _____ C:\Users\Naïma\Desktop\FRST.txt
2016-05-21 11:54 - 2016-05-21 11:54 - 02382336 _____ (Farbar) C:\Users\Naïma\Desktop\FRST64.exe
2016-05-21 08:40 - 2016-05-21 08:40 - 00130793 _____ C:\Users\Naïma\Desktop\ZHPDiag.txt
2016-05-21 08:31 - 2016-05-21 08:31 - 02207232 _____ C:\Users\Naïma\Documents\ZHPDiag3.exe
2016-05-20 23:25 - 2016-05-20 23:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
2016-05-20 23:02 - 2016-05-20 23:20 - 00000000 ____D C:\AdwCleaner
2016-05-20 18:55 - 2016-05-20 18:55 - 00085853 _____ C:\Users\Naïma\Documents\403-2728925-2238739-credit-note.pdf
2016-05-20 10:46 - 2016-05-20 10:50 - 00000000 ____D C:\Users\Naïma\Documents\Nouveau dossier
2016-05-18 15:19 - 2016-05-18 15:19 - 00029987 _____ C:\Users\Naïma\Documents\word-caracteres-masques-1628-l3r4tn.pdf
2016-05-18 09:52 - 2016-05-18 09:52 - 00206706 _____ C:\Users\Naïma\Documents\Lev1 Gen Info Rev 5-10-2016.pdf
2016-05-17 11:20 - 2016-05-17 11:20 - 00597304 _____ C:\Users\Naïma\Desktop\flux-setup.exe
2016-05-17 11:20 - 2016-05-17 11:20 - 00000000 ____D C:\Users\Naïma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
2016-05-17 11:20 - 2016-05-17 11:20 - 00000000 ____D C:\Users\Naïma\AppData\Local\FluxSoftware
2016-05-16 18:43 - 2016-05-16 18:43 - 00236425 _____ C:\Users\Naïma\Documents\facture_VM00073563786.pdf
2016-05-12 20:43 - 2016-05-12 20:44 - 01750533 _____ C:\Users\Naïma\Downloads\It_s_Not_About_the_Hat_Pattern_and_Guide_V_3.0.pdf
2016-05-11 16:01 - 2016-05-16 22:35 - 00000000 ____D C:\Users\Naïma\Documents\SYLVAIN
2016-05-11 09:08 - 2016-04-22 22:54 - 25816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-05-11 09:08 - 2016-04-22 22:15 - 00571904 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-05-11 09:08 - 2016-04-22 22:14 - 02893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-05-11 09:08 - 2016-04-22 22:08 - 06052864 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-05-11 09:08 - 2016-04-22 22:06 - 20349952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-05-11 09:08 - 2016-04-22 22:00 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-05-11 09:08 - 2016-04-22 21:35 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-05-11 09:08 - 2016-04-22 21:29 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-05-11 09:08 - 2016-04-22 21:24 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-05-11 09:08 - 2016-04-22 21:23 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-05-11 09:08 - 2016-04-22 21:19 - 15414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-05-11 09:08 - 2016-04-22 21:17 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2016-05-11 09:08 - 2016-04-22 21:14 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-05-11 09:08 - 2016-04-22 21:14 - 00725504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-05-11 09:08 - 2016-04-22 21:14 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-05-11 09:08 - 2016-04-22 21:12 - 02131968 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-05-11 09:08 - 2016-04-22 20:58 - 04611072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-05-11 09:08 - 2016-04-22 20:58 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-05-11 09:08 - 2016-04-22 20:54 - 13811200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-05-11 09:08 - 2016-04-22 20:53 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2016-05-11 09:08 - 2016-04-22 20:52 - 02596864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-05-11 09:08 - 2016-04-22 20:52 - 00693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-05-11 09:08 - 2016-04-22 20:52 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-05-11 09:08 - 2016-04-22 20:51 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-05-11 09:08 - 2016-04-22 20:40 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-05-11 09:08 - 2016-04-22 20:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-05-11 09:08 - 2016-04-22 20:27 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-05-11 09:08 - 2016-04-22 20:24 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-05-11 09:08 - 2016-04-22 20:23 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-05-11 09:08 - 2016-03-31 08:50 - 01307328 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-05-11 09:08 - 2016-03-31 05:40 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2016-05-11 09:06 - 2016-04-11 08:21 - 00074584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2016-05-11 09:06 - 2016-04-10 09:48 - 00738096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2016-05-11 09:06 - 2016-04-10 09:48 - 00613624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2016-05-11 09:06 - 2016-04-10 07:37 - 01549144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-05-11 09:06 - 2016-04-10 06:21 - 01763376 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-05-11 09:06 - 2016-04-10 06:21 - 01489088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-05-11 09:06 - 2016-04-10 06:14 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-05-11 09:06 - 2016-04-10 01:29 - 04169216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-05-11 09:06 - 2016-04-10 00:07 - 01097728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-05-11 09:06 - 2016-04-09 23:58 - 00534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-05-11 09:06 - 2016-04-09 23:50 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-05-11 09:06 - 2016-04-06 23:13 - 00561960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-05-11 09:06 - 2016-04-06 23:13 - 00137976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncrypt.dll
2016-05-11 09:06 - 2016-04-06 20:20 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-05-11 09:06 - 2016-04-06 20:19 - 00401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-05-11 09:06 - 2016-04-06 20:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-05-11 09:06 - 2016-04-06 19:49 - 00120384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncrypt.dll
2016-05-11 09:06 - 2016-04-06 19:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-05-11 09:06 - 2016-04-06 18:57 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-05-11 09:06 - 2016-04-06 18:52 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-05-11 09:06 - 2016-04-06 18:20 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-05-11 09:06 - 2016-04-06 17:48 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-05-11 09:06 - 2016-03-29 03:42 - 07446368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-05-11 09:06 - 2016-03-16 03:58 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-05-11 09:06 - 2016-03-16 03:58 - 00332632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-05-11 09:06 - 2016-03-14 18:50 - 00316760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2016-05-11 09:06 - 2016-03-12 02:49 - 02466136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-05-11 09:06 - 2016-03-12 02:47 - 00160160 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPHLPAPI.DLL
2016-05-11 09:06 - 2016-03-12 02:47 - 00121912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IPHLPAPI.DLL
2016-05-11 09:06 - 2016-03-10 19:03 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsparse.dll
2016-05-11 09:06 - 2016-03-10 18:55 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2016-05-11 09:06 - 2016-03-10 18:52 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2016-05-11 09:06 - 2016-03-10 18:48 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsparse.dll
2016-05-11 09:06 - 2016-03-10 18:42 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2016-05-11 09:06 - 2016-03-05 19:44 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2016-05-11 09:06 - 2016-03-05 19:04 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2016-05-11 09:06 - 2016-02-27 20:28 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-05-11 09:06 - 2016-02-27 19:57 - 03273728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2016-05-11 09:06 - 2016-02-27 19:19 - 03820544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2016-05-11 09:06 - 2016-02-27 18:32 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-05-07 20:03 - 2016-05-07 20:03 - 00000000 ____D C:\Users\Naïma\AppData\Local\calibre-cache
2016-05-07 20:02 - 2016-05-07 20:03 - 00000000 ____D C:\Users\Naïma\Documents\EBBOKS
2016-05-07 20:01 - 2016-05-16 20:55 - 00000000 ____D C:\Users\Naïma\AppData\Roaming\calibre
2016-05-07 20:00 - 2016-05-07 20:00 - 00000974 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk
2016-05-07 20:00 - 2016-05-07 20:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2016-05-07 20:00 - 2016-05-07 20:00 - 00000000 ____D C:\Program Files (x86)\Calibre2
2016-05-07 19:21 - 2016-05-07 19:40 - 67284992 _____ C:\Users\Naïma\Downloads\calibre-2.56.0 (1).msi
2016-05-07 18:34 - 2016-05-07 19:06 - 53739265 _____ C:\Users\Naïma\Downloads\calibre-2.56.0.msi
2016-05-05 22:59 - 2016-05-05 22:59 - 00000000 ____D C:\Users\Naïma\AppData\Local\Icecream
2016-05-05 22:59 - 2016-05-05 22:59 - 00000000 ____D C:\Users\Naïma\.ebookreader
2016-05-05 22:56 - 2016-05-05 22:57 - 25831088 _____ (Icecream Apps ) C:\Users\Naïma\Downloads\ebook_reader_setup.exe
2016-05-05 22:44 - 2016-05-05 22:48 - 00000000 ____D C:\Users\Naïma\Documents\My eBooks
2016-05-05 22:15 - 2016-05-05 22:46 - 00000000 ____D C:\Users\Naïma\AppData\Roaming\Mobipocket
2016-05-05 22:12 - 2016-05-05 22:12 - 03735040 _____ C:\Users\Naïma\Downloads\mobipocket_mobipocket_v5.2_.msi_francais_36901.msi
2016-05-05 20:13 - 2016-05-05 20:13 - 09105160 _____ C:\Users\Naïma\Downloads\Cast_On_Bind_Off_211_Ways.azw3
2016-05-05 20:07 - 2016-05-05 20:08 - 11538376 _____ C:\Users\Naïma\Downloads\Colorwork_Creations (2).azw3
2016-05-05 20:05 - 2016-05-05 20:06 - 11538376 _____ C:\Users\Naïma\Downloads\Colorwork_Creations.azw3
2016-05-05 20:05 - 2016-05-05 20:06 - 11538376 _____ C:\Users\Naïma\Downloads\Colorwork_Creations (1).azw3
2016-05-05 20:04 - 2016-05-05 20:06 - 15612848 _____ C:\Users\Naïma\Downloads\The_Essential_Guide_to_Color_Knitting_Techniques (3).mobi
2016-05-05 20:04 - 2016-05-05 20:05 - 15612848 _____ C:\Users\Naïma\Downloads\The_Essential_Guide_to_Color_Knitting_Techniques (2).mobi
2016-05-05 20:04 - 2016-05-05 20:05 - 15612848 _____ C:\Users\Naïma\Downloads\The_Essential_Guide_to_Color_Knitting_Techniques (1).mobi
2016-05-05 20:02 - 2016-05-05 20:03 - 07124220 _____ C:\Users\Naïma\Downloads\Knitting_out_of_Africa.mobi
2016-05-04 18:36 - 2016-05-04 18:36 - 03192331 _____ C:\Users\Naïma\Downloads\Fw Mably 16 - invitations vernissage - Liste 1 .zip
2016-05-03 17:03 - 2016-05-03 17:03 - 00305595 _____ C:\Users\Naïma\Downloads\Next Steps in Intarsia - Supplies and Patterns.pdf
2016-05-01 08:26 - 2016-05-01 08:26 - 00000000 ____D C:\Users\Naïma\Documents\Fichiers récupérés dans Painter 2015
2016-04-30 12:23 - 2016-04-30 12:23 - 00374139 _____ C:\Users\Naïma\Downloads\gpaper421.zip
2016-04-28 11:57 - 2016-04-28 11:57 - 00328915 _____ C:\Users\Naïma\Downloads\Intarsia - Knitter's Graph Paper - Large - 19 x 27 inches - 48.3 x 68.6 cm (1).pdf
2016-04-27 18:14 - 2016-04-27 18:14 - 00699764 _____ C:\Users\Naïma\Downloads\Modern Stranded Knitting Techniques - Pattern and Charts.pdf
2016-04-27 16:16 - 2016-04-27 16:16 - 00328915 _____ C:\Users\Naïma\Downloads\Intarsia - Knitter's Graph Paper - Large - 19 x 27 inches - 48.3 x 68.6 cm.pdf
2016-04-27 16:16 - 2016-04-27 16:16 - 00115263 _____ C:\Users\Naïma\Downloads\Metric Conversion Guide.pdf
2016-04-27 16:15 - 2016-04-27 16:15 - 00794411 _____ C:\Users\Naïma\Downloads\Intarsia Argyle Pillow Pattern.pdf
2016-04-27 16:15 - 2016-04-27 16:15 - 00248542 _____ C:\Users\Naïma\Downloads\Intarsia Practice Pattern and Knitter's Graph Paper.pdf
2016-04-26 18:44 - 2016-04-26 18:44 - 00001116 _____ C:\Users\UpdatusUser\Desktop\Tricoti tricota.lnk
2016-04-26 18:44 - 2016-04-26 18:44 - 00001116 _____ C:\Users\Naïma\Desktop\Tricoti tricota.lnk
2016-04-26 18:44 - 2016-04-26 18:44 - 00001116 _____ C:\Users\Administrator\Desktop\Tricoti tricota.lnk
2016-04-26 18:44 - 2016-04-26 18:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tricoti tricota
2016-04-26 18:44 - 2016-04-26 18:44 - 00000000 ____D C:\Program Files (x86)\Tricoti tricota
2016-04-25 10:32 - 2016-04-25 10:32 - 00852925 _____ C:\Users\Naïma\Downloads\Worksheets (1).pdf
2016-04-24 14:45 - 2016-04-24 14:45 - 00548339 _____ C:\Users\Naïma\Downloads\Bonus Pattern.pdf
2016-04-24 14:44 - 2016-04-24 14:44 - 00852925 _____ C:\Users\Naïma\Downloads\Worksheets.pdf
2016-04-24 14:24 - 2016-04-24 14:24 - 01343976 _____ C:\Users\Naïma\Downloads\Lesson Handouts.pdf
2016-04-24 14:24 - 2016-04-24 14:24 - 00115263 _____ C:\Users\Naïma\Downloads\Metric Conversion Chart.pdf
2016-04-24 14:23 - 2016-04-24 14:23 - 00549121 _____ C:\Users\Naïma\Downloads\Graphic Pattern.pdf
2016-04-24 14:23 - 2016-04-24 14:23 - 00121485 _____ C:\Users\Naïma\Downloads\Pattern Template.pdf
2016-04-24 14:22 - 2016-04-24 14:22 - 00143781 _____ C:\Users\Naïma\Downloads\Style Sheet.pdf
2016-04-21 15:18 - 2016-04-21 15:18 - 00168739 _____ C:\Users\Naïma\Downloads\Feminine Fit Instructions.pdf
2016-04-21 15:18 - 2016-04-21 15:18 - 00110278 _____ C:\Users\Naïma\Downloads\Feminine Fit Schematics.pdf

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-05-21 11:57 - 2014-12-21 12:50 - 00000000 ____D C:\FRST
2016-05-21 11:57 - 2014-06-08 15:20 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-661552332-2814264726-1606198710-1002
2016-05-21 11:53 - 2014-12-19 15:35 - 00000000 ____D C:\Program Files (x86)\ZHPDiag
2016-05-21 11:52 - 2015-10-13 09:56 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-05-21 11:52 - 2014-04-22 19:42 - 00000000 ____D C:\Program Files\Dell
2016-05-21 11:28 - 2014-06-08 21:41 - 00000000 ____D C:\Users\Naïma\AppData\Roaming\Skype
2016-05-21 11:10 - 2014-06-08 19:03 - 00001100 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-21 10:46 - 2014-06-08 16:54 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2016-05-21 10:07 - 2014-10-11 13:09 - 00000000 ____D C:\Users\Naïma\AppData\Roaming\vlc
2016-05-21 09:10 - 2014-06-08 19:03 - 00001096 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-21 08:32 - 2014-12-19 15:35 - 00000000 ____D C:\Users\Naïma\AppData\Roaming\ZHP
2016-05-21 08:27 - 2014-05-25 11:23 - 00000000 __RDO C:\Users\Naïma\SkyDrive
2016-05-20 23:32 - 2014-04-22 19:59 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2016-05-20 23:29 - 2014-04-22 19:33 - 06081988 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-05-20 23:29 - 2013-08-23 00:25 - 04280798 _____ C:\WINDOWS\system32\perfh00C.dat
2016-05-20 23:29 - 2013-08-23 00:25 - 01246408 _____ C:\WINDOWS\system32\perfc00C.dat
2016-05-20 23:23 - 2015-10-11 09:29 - 00002347 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2016-05-20 23:22 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-05-20 23:21 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-05-20 23:11 - 2015-10-11 09:29 - 00000000 ____D C:\Program Files (x86)\Lavasoft
2016-05-20 23:11 - 2015-10-11 09:26 - 00000000 ____D C:\ProgramData\Lavasoft
2016-05-20 22:46 - 2014-06-08 19:00 - 00000000 ____D C:\Users\Naïma\AppData\Local\CrashDumps
2016-05-20 17:45 - 2016-03-14 19:49 - 00000000 ____D C:\Users\Naïma\Documents\My PSP Files
2016-05-20 17:45 - 2014-07-03 14:08 - 00000000 ____D C:\Users\Naïma\AppData\Local\Corel
2016-05-20 17:45 - 2014-07-03 14:01 - 00002828 ___SH C:\ProgramData\KGyGaAvL.sys
2016-05-17 13:51 - 2014-12-14 14:51 - 00000318 _____ C:\WINDOWS\Tasks\CCleanerClean.job
2016-05-15 15:53 - 2014-12-22 11:59 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-05-15 15:52 - 2014-12-22 11:58 - 00001116 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-05-15 15:52 - 2014-12-22 11:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-05-15 15:52 - 2014-12-22 11:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-05-15 15:38 - 2014-12-21 16:27 - 00000000 ____D C:\AdsFix
2016-05-15 15:25 - 2015-10-11 09:29 - 00000000 ____D C:\Users\Naïma\AppData\Roaming\Lavasoft
2016-05-15 15:02 - 2014-04-22 20:00 - 00000000 ____D C:\Temp
2016-05-15 14:50 - 2016-03-23 21:15 - 00308241 _____ C:\Users\Naïma\ZHPDiag3.exe
2016-05-15 14:50 - 2014-06-08 14:47 - 00000000 ____D C:\Users\Naïma
2016-05-14 14:41 - 2015-07-31 23:22 - 00000000 ____D C:\Users\Naïma\Documents\AAAAAAAAAAAAAAAAAAABUREAU
2016-05-13 20:29 - 2016-04-17 20:00 - 00000000 ____D C:\Users\Naïma\Documents\CINEMA
2016-05-13 19:20 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-05-13 10:14 - 2014-06-08 19:04 - 00002215 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-13 10:14 - 2014-06-08 19:04 - 00002203 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-05-12 11:20 - 2015-04-18 09:12 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-05-11 22:25 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2016-05-11 22:13 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\Inf
2016-05-11 22:12 - 2013-08-22 16:44 - 05116432 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-05-11 22:08 - 2016-03-19 12:58 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-05-11 22:08 - 2016-03-19 12:58 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-05-11 22:06 - 2013-08-23 00:27 - 00000000 ____D C:\Program Files\Windows Journal
2016-05-11 16:02 - 2014-12-15 13:04 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2016-05-11 10:22 - 2014-06-10 09:26 - 139319312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-05-11 10:22 - 2014-06-10 09:26 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-05-11 09:05 - 2016-04-13 09:06 - 01737088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-05-11 09:05 - 2016-04-13 09:06 - 01663184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-05-11 09:05 - 2016-04-13 09:06 - 01523208 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-05-11 09:05 - 2016-04-13 09:06 - 01501488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-05-11 09:05 - 2016-04-13 09:06 - 01490120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-05-11 09:05 - 2016-04-13 09:06 - 01358952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-05-11 09:05 - 2016-04-13 09:06 - 00246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-05-11 09:05 - 2014-06-08 19:03 - 00004072 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-11 09:05 - 2014-06-08 19:03 - 00003836 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-11 08:45 - 2014-12-24 11:44 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-05-09 09:33 - 2014-08-31 20:14 - 00002828 ___SH C:\WINDOWS\SysWOW64\KGyGaAvL.sys
2016-05-09 09:31 - 2014-08-31 20:14 - 00000088 __RSH C:\WINDOWS\SysWOW64\61692E45A7.sys
2016-05-06 10:20 - 2015-04-04 09:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2016-05-06 10:20 - 2015-04-04 09:04 - 00000000 ___SD C:\WINDOWS\system32\GWX
2016-05-04 13:29 - 2014-05-25 11:25 - 00000000 ____D C:\Users\Naïma\Documents\ZJM
2016-04-29 11:38 - 2015-12-30 15:39 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-04-29 11:38 - 2014-06-08 21:41 - 00000000 ____D C:\ProgramData\Skype
2016-04-29 11:21 - 2015-12-12 17:12 - 00000000 ____D C:\Users\Naïma\Documents\identifiants
2016-04-27 09:24 - 2014-05-08 15:12 - 00000000 ____D C:\Users\Naïma\AppData\Local\Packages
2016-04-27 09:24 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness

==================== Fichiers à la racine de certains dossiers =======

2014-12-15 14:24 - 2014-12-21 13:29 - 0000162 _____ () C:\Users\Naïma\AppData\Roaming\WB.CFG
2014-07-03 14:09 - 2014-07-03 14:09 - 0004608 _____ () C:\Users\Naïma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-14 19:49 - 2016-03-14 19:49 - 0000008 __RSH () C:\ProgramData\61692E45A7.sys
2014-07-03 14:01 - 2016-05-20 17:45 - 0002828 ___SH () C:\ProgramData\KGyGaAvL.sys

Fichiers à déplacer ou supprimer:
====================
C:\Users\Naïma\ZHPCleaner.exe
C:\Users\Naïma\ZHPDiag3.exe


Certains fichiers dans TEMP:
====================
C:\Users\Naïma\AppData\Local\Temp\GPP5486.exe
C:\Users\Naïma\AppData\Local\Temp\libeay32.dll
C:\Users\Naïma\AppData\Local\Temp\msvcr120.dll
C:\Users\Naïma\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Naïma\AppData\Local\Temp\sqlite3.dll
C:\Users\Naïma\AppData\Local\Temp\vlc-2.2.1-win32.exe


==================== Bamital & volsnap =================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement


LastRegBack: 2016-05-08 17:32

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité