cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 05-03-2017
Exécuté par Patrick (administrateur) sur PATRICK (07-03-2017 15:45:54)
Exécuté depuis C:\Users\Patrick\Desktop
Profils chargés: Patrick (Profils disponibles: Patrick & VERONIK & Invité)
Platform: Windows 10 Home Version 1607 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Edge)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(© 2015 Microsoft Corporation) C:\Users\Patrick\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam7\YouCamService7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
(Microsoft Corporation) C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileCoAuth.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.693_none_42ff55c9655f38bf\TiWorker.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSYNC.EXE
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe

==================== Registre (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8496344 2015-11-23] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-11-23] (Realtek Semiconductor)
HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [274200 2016-07-14] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [909744 2017-03-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318248 2016-01-08] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [509192 2014-12-01] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [61896 2016-12-29] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [YouCam Service7] => C:\Program Files (x86)\CyberLink\YouCam7\YouCamService7.exe [466712 2016-07-04] (CyberLink Corp.)
HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [Le Cloud d'Orange - Transfert de fichiers Client] => C:\Users\Patrick\AppData\Local\Le Cloud Orange\omclient.exe [1178112 2014-03-27] (Orange-France)
HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1572648 2016-01-08] (Samsung)
HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [KiesPDLR.exe] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1021736 2016-01-08] (Samsung)
HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [Orange mes contenus] => C:\Program Files\Orange\Orange mes contenus\OrangeSC.exe [12995408 2012-07-18] (F-Secure)
HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [BingSvc] => C:\Users\Patrick\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-22] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29642368 2016-09-12] (Skype Technologies S.A.)
HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9363672 2017-02-08] (Piriform Ltd)
HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\MountPoints2: {788f2c87-f9d9-11e3-825e-b8ee652537d4} - "F:\LaunchU3.exe" -a
HKU\S-1-5-21-3311965274-403475795-341010734-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [572416 2016-07-16] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll [2017-02-28] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll [2017-02-28] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll [2017-02-28] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileSyncShell.dll [2017-02-28] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileSyncShell.dll [2017-02-28] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileSyncShell.dll [2017-02-28] (Microsoft Corporation)

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{13d3b3b4-32e4-44d8-b91d-2260d48c1030}: [DhcpNameServer] 192.168.40.4
Tcpip\..\Interfaces\{1ba87505-f6de-4514-9ee0-f003fcb2ac81}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2d93315f-35aa-42b5-abcf-36c189117fae}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7c643847-8226-471e-a585-f07aef0b04dd}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM14/9
HKU\S-1-5-21-3311965274-403475795-341010734-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/
HKU\S-1-5-21-3311965274-403475795-341010734-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM14/9
HKU\S-1-5-21-3311965274-403475795-341010734-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.msn.com/?pc=SL5M&ocid=SL5MDHP&osmkt=fr-fr
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {8E9AEB09-3658-4FA2-B85B-40B932D0F5B3} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {8E9AEB09-3658-4FA2-B85B-40B932D0F5B3} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-3311965274-403475795-341010734-1001 -> {8E9AEB09-3658-4FA2-B85B-40B932D0F5B3} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-3311965274-403475795-341010734-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-01-29] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-01-29] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-12-06] (HP Inc.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-12-06] (HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default [2017-03-07]
FF user.js: detected! => C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\user.js [2014-07-26]
FF Extension: (Avira Browser Safety) - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\Extensions\abs@avira.com [2016-10-04]
FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] [non signé]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-21] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-21] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-01-29] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-14] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3311965274-403475795-341010734-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Patrick\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2016-09-08] (Zoom Video Communications, Inc.)

Chrome:
=======
CHR Profile: C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default [2017-02-25]
CHR Extension: (Google Slides) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-23]
CHR Extension: (Docs) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-23]
CHR Extension: (Google Drive) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-23]
CHR Extension: (YouTube) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-23]
CHR Extension: (Google Sheets) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-23]
CHR Extension: (Protection Web Avira) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2017-02-23]
CHR Extension: (Google Docs hors connexion) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-23]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-23]
CHR Extension: (Gmail) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-23]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1115552 2017-03-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [487424 2017-03-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [487424 2017-03-03] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1519144 2017-03-03] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-08-07] (Windows (R) Win 7 DDK provider) [Fichier non signé]
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272 2016-12-29] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3704520 2017-02-18] (Microsoft Corporation)
R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-09-05] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-09-05] (CyberLink)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [573704 2014-12-01] (Hewlett-Packard Development Company, L.P.)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [Fichier non signé]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [294616 2015-11-23] (Realtek Semiconductor)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [260704 2016-09-02] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)

===================== Pilotes (Avec liste blanche) ======================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R3 athr; C:\WINDOWS\System32\drivers\athwbx.sys [3858944 2013-10-17] (Qualcomm Atheros Communications, Inc.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [161824 2017-03-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [163976 2017-03-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-03-03] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-03-03] (Avira Operations GmbH & Co. KG)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 clwvd7; C:\WINDOWS\system32\DRIVERS\clwvd7.sys [49944 2016-06-02] (CyberLink Corporation)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-09-20] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [52904 2016-04-27] (Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [87568 2013-07-01] (Intel Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (HP Inc.)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2017-03-07 15:45 - 2017-03-07 15:47 - 00023829 _____ C:\Users\Patrick\Desktop\FRST.txt
2017-03-07 15:45 - 2017-03-07 15:45 - 00000000 ____D C:\FRST
2017-03-07 15:43 - 2017-03-07 15:45 - 02423808 _____ (Farbar) C:\Users\Patrick\Desktop\FRST64.exe
2017-03-07 09:19 - 2017-03-07 09:19 - 00000738 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assistant Mise à niveau de Windows 10.lnk
2017-03-07 09:19 - 2017-03-07 09:19 - 00000726 _____ C:\Users\Patrick\Desktop\Assistant Mise à niveau de Windows 10.lnk
2017-03-07 09:19 - 2017-03-07 09:19 - 00000000 ____D C:\Windows10Upgrade
2017-03-05 16:43 - 2017-03-05 16:43 - 00000000 ___HD C:\$SysReset
2017-03-02 15:59 - 2017-03-02 15:59 - 00003762 _____ C:\WINDOWS\System32\Tasks\HP AR Program Upload - 4ba89dd2808145be9d415a1b82b2d4c59d7a2adb9e264a46961bacc5917ba472
2017-02-28 09:08 - 2017-02-28 09:08 - 00001286 _____ C:\Users\Patrick\Desktop\Stellar Phoenix Windows Data Recovery - Home.lnk
2017-02-28 09:08 - 2017-02-28 09:08 - 00000081 _____ C:\WINDOWS\spwdrhfa.INI
2017-02-28 09:08 - 2017-02-28 09:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellar Phoenix Windows Data Recovery - Home
2017-02-28 09:08 - 2017-02-28 09:08 - 00000000 ____D C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery
2017-02-28 09:08 - 2017-02-28 09:08 - 00000000 ____D C:\Log
2017-02-27 19:59 - 2017-02-27 20:09 - 00001297 _____ C:\Users\Public\Desktop\Wondershare Data Recovery.lnk
2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\Users\Patrick\AppData\Local\Wondershare
2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\ProgramData\Wondershare
2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\Program Files (x86)\Wondershare
2017-02-27 19:58 - 2017-02-27 20:08 - 00805960 _____ C:\Users\Patrick\Downloads\data-recovery_setup_full935.exe
2017-02-27 19:58 - 2017-02-27 19:59 - 00000000 ____D C:\Users\Public\Documents\Wondershare
2017-02-27 19:39 - 2017-02-27 19:39 - 00435241 _____ C:\Users\Patrick\Downloads\releve.pdf
2017-02-27 17:53 - 2017-02-27 17:53 - 00003186 _____ C:\WINDOWS\System32\Tasks\{B90BE772-893A-4871-BAB2-FF70C4B45845}
2017-02-27 16:18 - 2017-03-07 14:15 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-27 14:14 - 2017-02-27 14:14 - 00001341 _____ C:\Users\Patrick\Desktop\COURSES MARS 2017i.lnk
2017-02-25 16:40 - 2017-02-25 16:40 - 43626400 _____ C:\Users\Patrick\Desktop\OJ4630_Basicx64_198.exe
2017-02-24 10:17 - 2017-02-24 10:38 - 00000000 ____D C:\Program Files\ReviverSoft
2017-02-23 19:06 - 2017-02-23 19:06 - 00002858 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-02-23 19:06 - 2017-02-23 19:06 - 00002349 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-23 19:06 - 2017-02-23 19:06 - 00002337 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-02-23 19:06 - 2017-02-23 19:06 - 00000870 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-02-23 19:06 - 2017-02-23 19:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-02-23 19:06 - 2017-02-23 19:06 - 00000000 ____D C:\Program Files\CCleaner
2017-02-22 19:14 - 2017-02-22 19:14 - 00002320 _____ C:\Users\Public\Desktop\HP Officejet 4630 series.lnk
2017-02-22 19:14 - 2014-07-21 16:31 - 00763912 ____N (Hewlett-Packard Development Company, LP) C:\WINDOWS\system32\HPDiscoPMC611.dll
2017-02-22 18:50 - 2017-02-22 18:51 - 10779584 _____ C:\Users\Patrick\Downloads\HPPSdr.exe
2017-02-20 23:09 - 2017-02-20 23:09 - 00110712 _____ C:\Users\Patrick\Desktop\Dépannage - Échec de l'installation HP - Réseau.hta
2017-02-20 12:34 - 2017-02-20 12:34 - 00002307 _____ C:\Users\Public\Desktop\HP Support Assistant.lnk
2017-02-20 12:30 - 2017-02-20 12:31 - 43544408 _____ (HP Inc. ) C:\Users\Patrick\Downloads\sp78153.exe
2017-02-20 10:57 - 2017-02-20 10:58 - 00000000 ____D C:\Users\Patrick\Downloads\HP Downloads
2017-02-20 09:45 - 2017-02-20 09:45 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\HPPSDr
2017-02-06 19:29 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-02-06 19:29 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2017-03-07 15:37 - 2016-10-02 10:46 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-07 15:05 - 2014-08-08 17:10 - 00000000 ____D C:\Users\Patrick\Documents\Fichiers Outlook
2017-03-07 14:48 - 2016-10-02 10:57 - 00000000 ____D C:\Users\Patrick
2017-03-07 14:47 - 2014-07-26 13:07 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\Skype
2017-03-07 14:47 - 2014-06-22 06:36 - 00000000 ____D C:\Users\Patrick\Documents\Youcam
2017-03-07 14:45 - 2015-11-19 12:50 - 00000000 __SHD C:\Users\Patrick\IntelGraphicsProfiles
2017-03-07 14:44 - 2016-10-02 11:48 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-07 14:43 - 2016-07-16 07:04 - 01310720 _____ C:\WINDOWS\system32\config\BBI
2017-03-07 14:26 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\registration
2017-03-07 14:12 - 2014-06-22 08:24 - 00000000 __RDO C:\Users\Patrick\SkyDrive
2017-03-07 14:10 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-03-07 14:05 - 2013-11-04 12:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-03-06 19:11 - 2016-10-29 17:36 - 00000356 _____ C:\WINDOWS\Tasks\HPCeeScheduleForPatrick.job
2017-03-05 16:50 - 2014-09-01 06:45 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-05 16:41 - 2014-08-10 09:57 - 00000000 ____D C:\Users\Patrick\AppData\Local\ElevatedDiagnostics
2017-03-03 20:03 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-03 09:47 - 2014-09-08 13:27 - 00002088 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2017-03-03 09:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-03 07:40 - 2014-07-26 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-03-03 07:39 - 2016-10-12 07:21 - 00048584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2017-03-03 07:39 - 2014-07-26 12:14 - 00163976 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2017-03-03 07:39 - 2014-07-26 12:14 - 00161824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2017-03-03 07:39 - 2014-07-26 12:14 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2017-03-03 07:39 - 2014-07-26 12:14 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2017-03-02 19:18 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-02 15:43 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-01 10:48 - 2014-06-22 08:46 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\HpUpdate
2017-03-01 09:39 - 2014-06-22 06:34 - 00000000 ____D C:\Users\Patrick\AppData\Local\Packages
2017-02-28 09:03 - 2016-12-13 19:05 - 00003278 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-02-28 09:03 - 2015-11-19 13:00 - 00002458 _____ C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-24 09:00 - 2014-06-27 11:39 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-24 08:53 - 2014-06-27 11:39 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-23 19:17 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-02-23 19:06 - 2014-06-23 07:54 - 00000000 ____D C:\Users\Patrick\AppData\Local\Google
2017-02-23 19:06 - 2014-06-22 16:56 - 00000000 ____D C:\Program Files (x86)\Google
2017-02-23 11:18 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-22 19:14 - 2014-06-22 08:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2017-02-22 19:13 - 2014-06-22 08:43 - 00000000 ____D C:\ProgramData\HP
2017-02-22 19:13 - 2014-06-22 08:43 - 00000000 ____D C:\Program Files (x86)\HP
2017-02-22 19:07 - 2016-10-07 18:40 - 00001064 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-02-22 19:07 - 2014-08-26 16:34 - 00001002 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-22 01:35 - 2016-10-07 18:40 - 00004142 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-02-22 01:35 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-22 01:35 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-21 17:47 - 2015-04-29 11:09 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-21 01:36 - 2016-10-02 11:47 - 00003988 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-02-20 13:40 - 2016-10-02 11:47 - 00000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard
2017-02-20 13:40 - 2013-11-04 12:34 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2017-02-20 12:34 - 2013-11-04 12:47 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2017-02-20 12:34 - 2013-11-04 12:46 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-02-20 12:34 - 2013-11-04 11:54 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2017-02-20 10:57 - 2014-06-22 07:43 - 00000000 ____D C:\Users\Patrick\AppData\Local\Hewlett-Packard
2017-02-20 10:40 - 2013-09-01 04:49 - 00000000 ____D C:\SWSetup
2017-02-15 18:30 - 2016-10-08 08:28 - 00000000 ___HD C:\OneDriveTemp
2017-02-15 18:30 - 2014-08-29 17:21 - 00000000 ____D C:\Users\VERONIK\Documents\Fichiers Outlook
2017-02-15 18:30 - 2014-08-29 16:30 - 00000000 ___RD C:\Users\VERONIK\OneDrive
2017-02-15 18:15 - 2014-08-29 15:46 - 00000000 ____D C:\Users\VERONIK\Documents\Youcam
2017-02-15 18:09 - 2015-11-19 17:29 - 00000000 __SHD C:\Users\VERONIK\IntelGraphicsProfiles
2017-02-12 20:12 - 2016-05-22 10:49 - 00000000 ____D C:\Users\Patrick\AppData\Local\PackageStaging
2017-02-06 20:48 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-06 20:48 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-06 19:14 - 2014-08-21 09:38 - 00000000 ____D C:\ProgramData\Package Cache

==================== Fichiers à la racine de certains dossiers =======

2014-11-19 11:36 - 2014-11-19 11:36 - 0000268 ___RH () C:\Users\Patrick\AppData\Roaming\Overdrive
2014-11-19 11:37 - 2014-11-19 11:37 - 0000268 ___RH () C:\Users\Patrick\AppData\Roaming\PDEs
2014-11-19 11:36 - 2014-11-19 11:36 - 0000268 ___RH () C:\Users\Patrick\AppData\Roaming\PPD Plugins
2015-08-08 15:36 - 2015-08-08 15:36 - 0000017 _____ () C:\Users\Patrick\AppData\Local\resmon.resmoncfg
2014-06-22 08:43 - 2014-06-22 08:43 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-08-26 18:43 - 2014-08-26 18:43 - 4954384 _____ () C:\ProgramData\pclunst.exe
2014-11-19 11:36 - 2014-11-19 11:36 - 0000268 ___RH () C:\ProgramData\Pedal Hard
2014-11-19 11:37 - 2014-11-19 11:37 - 0000268 ___RH () C:\ProgramData\People
2014-11-19 11:36 - 2014-11-19 11:36 - 0000268 ___RH () C:\ProgramData\Percussion Kit
2014-11-19 11:37 - 2014-11-19 11:37 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2014-11-19 11:36 - 2016-09-18 16:31 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2014-11-19 11:36 - 2016-08-29 15:31 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT

Fichiers à déplacer ou supprimer:
====================
C:\ProgramData\pclunst.exe


Certains fichiers dans TEMP:
====================
2017-02-26 09:02 - 2017-02-27 16:21 - 3651584 _____ (Igor Pavlov) C:\Users\Patrick\AppData\Local\Temp\Package_fr_ww.exe
2016-10-03 11:41 - 2016-10-03 11:41 - 0000000 ____D () C:\Users\VERONIK\AppData\Local\Temp\avgnt.exe

==================== Bamital & volsnap ======================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

LastRegBack: 2017-03-07 15:17

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité