cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 13-09-2017 02
Exécuté par Jean-François (administrateur) sur PCASUSJEFF (14-09-2017 14:46:13)
Exécuté depuis C:\Users\Jean-François\Desktop
Profils chargés: Jean-François (Profils disponibles: Jean-François)
Platform: Windows 10 Home Version 1703 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSWinService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
() C:\Program Files (x86)\Repetier-Server\bin\RepetierServer.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.228\WsAppService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSPanel.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8500.40855.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8500.40855.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8500.40855.0_x64__8wekyb3d8bbwe\HxCalendarAppImm.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35071.16410.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11708.1001.21.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEpson Portal\mep.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registre (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [239856 2017-09-07] (AVAST Software)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\ASUSWSLoader.exe [63272 2014-12-04] ()
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-06-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [976832 2010-06-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4174464 2017-05-23] (Safer-Networking Ltd.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-658570963-2578683622-510444264-1001\...\Run: [EPLTarget\P0000000000000001] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHQE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-658570963-2578683622-510444264-1001\...\Run: [Chromium] => c:\users\jean-françois\appdata\local\chromium\application\chrome.exe [1068544 2016-03-18] (The Chromium Authors)
HKU\S-1-5-21-658570963-2578683622-510444264-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9832152 2017-08-03] (Piriform Ltd)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction - Chrome <==== ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{0baa4770-fac0-4bbb-ba63-48c75878f850}: [DhcpNameServer] 109.0.66.11 109.0.66.21
Tcpip\..\Interfaces\{2e525f07-d92b-4562-bf78-96c224d9db2c}: [DhcpNameServer] 172.18.12.1
Tcpip\..\Interfaces\{6541fee3-e873-4a83-9384-0ecca6456053}: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{6c8cb2c1-0f2a-4a18-8371-c546d9da08ab}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{874309ce-b9b2-4677-93be-de0e39e6260e}: [DhcpNameServer] 109.0.66.11 109.0.66.21

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_51¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCzztCyEtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDzztAzztA0AzzyBtGyCzz0AtBtGzzyEyCtDtGyEyCtDtAtGyB0DzztDtC0E0C0F0FyBzzyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1265623805%26a%3Dwbf_fs_16_51%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
HKU\S-1-5-21-658570963-2578683622-510444264-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_51¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCzztCyEtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDzztAzztA0AzzyBtGyCzz0AtBtGzzyEyCtDtGyEyCtDtAtGyB0DzztDtC0E0C0F0FyBzzyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1265623805%26a%3Dwbf_fs_16_51%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
HKU\S-1-5-21-658570963-2578683622-510444264-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_26¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCyCtAzytN1L2XzutAtFtBtAtFtCtFtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StCtDyCyEtB0F0DyBtGtAyBtAyEtG0DtAzztDtGtCtAyEtAtGtBzz0B0BtByBtAtD0B0B0A0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1719168759%26a%3Dwbf_fs_16_26%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_26¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCyCtAzytN1L2XzutAtFtBtAtFtCtFtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StCtDyCyEtB0F0DyBtGtAyBtAyEtG0DtAzztDtGtCtAyEtAtGtBzz0B0BtByBtAtD0B0B0A0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1719168759%26a%3Dwbf_fs_16_26%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_51¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCzztCyEtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDzztAzztA0AzzyBtGyCzz0AtBtGzzyEyCtDtGyEyCtDtAtGyB0DzztDtC0E0C0F0FyBzzyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1265623805%26a%3Dwbf_fs_16_51%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_26¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCyCtAzytN1L2XzutAtFtBtAtFtCtFtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StCtDyCyEtB0F0DyBtGtAyBtAyEtG0DtAzztDtGtCtAyEtAtGtBzz0B0BtByBtAtD0B0B0A0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1719168759%26a%3Dwbf_fs_16_26%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_26¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCyCtAzytN1L2XzutAtFtBtAtFtCtFtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StCtDyCyEtB0F0DyBtGtAyBtAyEtG0DtAzztDtGtCtAyEtAtGtBzz0B0BtByBtAtD0B0B0A0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1719168759%26a%3Dwbf_fs_16_26%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_51¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCzztCyEtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDzztAzztA0AzzyBtGyCzz0AtBtGzzyEyCtDtGyEyCtDtAtGyB0DzztDtC0E0C0F0FyBzzyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1265623805%26a%3Dwbf_fs_16_51%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-09-03] (Microsoft Corporation)
BHO: Pas de nom -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> Pas de fichier
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-09-03] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19] (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-09-03] (Microsoft Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-01-29] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 7p8b2e8g.default
FF ProfilePath: C:\Users\Jean-François\AppData\Roaming\Mozilla\Firefox\Profiles\7p8b2e8g.default [2017-09-14]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\7p8b2e8g.default -> Yahoo! Powered
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\7p8b2e8g.default -> Yahoo! Powered
FF Keyword.URL: Mozilla\Firefox\Profiles\7p8b2e8g.default -> user_pref("keyword.URL", true);
FF Homepage: Mozilla\Firefox\Profiles\7p8b2e8g.default -> hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_51¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyEtD0Bzzzy0AtDtDtAyEtC0Fzy0AtC0DtN0D0Tzu0StCzztCyEtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDzztAzztA0AzzyBtGyCzz0AtBtGzzyEyCtDtGyEyCtDtAtGyB0DzztDtC0E0C0F0FyBzzyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0Dzyzy0E0CtAtGtB0B0BtBtGyEyB0B0AtG0B0E0D0DtG0F0ByD0FtAtCyByC0DtCyBtA2QtN0A0LzuyE%26cr%3D1265623805%26a%3Dwbf_fs_16_51%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
FF Extension: (Firebug) - C:\Users\Jean-François\AppData\Roaming\Mozilla\Firefox\Profiles\7p8b2e8g.default\Extensions\firebug@software.joehewitt.com.xpi [2016-09-02]
FF Extension: (Firefox Hotfix) - C:\Users\Jean-François\AppData\Roaming\Mozilla\Firefox\Profiles\7p8b2e8g.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-29]
FF Extension: (Avast SafePrice) - C:\Users\Jean-François\AppData\Roaming\Mozilla\Firefox\Profiles\7p8b2e8g.default\Extensions\sp@avast.com.xpi [2017-07-28]
FF Extension: (Avast Online Security) - C:\Users\Jean-François\AppData\Roaming\Mozilla\Firefox\Profiles\7p8b2e8g.default\Extensions\wrc@avast.com.xpi [2017-09-07]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-02-25] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-02-25] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-09-03] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-09-03] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-01] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-15] ()

Chrome:
=======
CHR HomePage: Default -> hxxp://rigidtalk.com/wiki/index.php?title=Modifying_a_RAMPS_1.4_board
CHR StartupUrls: Default -> "hxxps://fr.yahoo.com/"
CHR Profile: C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default [2017-09-14]
CHR Extension: (Google Slides) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-10]
CHR Extension: (Google Docs) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-10]
CHR Extension: (Google Drive) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-10]
CHR Extension: (Pearltrees Extension) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgngjfgpahnnncnimlhjgjhdajmaeeoa [2017-02-12]
CHR Extension: (WOT: Web of Trust, Évaluation de la réputation de sites Web) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2017-09-12]
CHR Extension: (YouTube) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-10]
CHR Extension: (Adblock Plus) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-07-20]
CHR Extension: (Recherche Google) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-10]
CHR Extension: (Google Sheets) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-10]
CHR Extension: (Google Docs hors connexion) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (Avast Online Security) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-08-22]
CHR Extension: (Pearltrees) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjcccdngnaailhnoflbeficiokgcfaah [2016-01-10]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (Gmail) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-10]
CHR Extension: (Chrome Media Router) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-09]
CHR Extension: (Always Weather) - C:\Users\Jean-François\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmcboldhlmhecoigccicmippjglnhhic [2017-09-08]
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-658570963-2578683622-510444264-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [clgckgfbhciacomhlchmgdnplmdiadbj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.15.458\AsusWSWinService.exe [71168 2014-12-04] (ASUS Cloud Corporation) [Fichier non signé]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7452288 2017-09-07] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [275208 2017-09-07] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4424384 2017-08-28] (Microsoft Corporation)
R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1037568 2014-09-18] (Intel Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [347200 2015-02-09] (WildTangent)
R2 hasplms; C:\WINDOWS\system32\hasplms.exe [4608320 2014-11-27] (SafeNet Inc.)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373728 2016-11-30] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2014-10-03] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [156960 2015-02-25] (Intel Corporation)
R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [703984 2014-09-22] (SEIKO EPSON CORPORATION)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 RepetierServer; C:\Program Files (x86)\Repetier-Server\bin\RepetierServer.exe [4393544 2015-12-07] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1776864 2017-05-23] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2131760 2017-05-23] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233936 2017-05-23] (Safer-Networking Ltd.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7757552 2017-08-16] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.228\WsAppService.exe [493280 2017-07-28] (Wondershare)
S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\MobileTrans\DriverInstall.exe" [X]

===================== Pilotes (Avec liste blanche) ======================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [320528 2017-09-07] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198976 2017-09-07] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343296 2017-09-07] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57736 2017-09-07] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [47016 2017-09-07] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [41832 2017-09-07] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [147784 2017-09-07] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110376 2017-09-07] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84416 2017-09-07] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1016384 2017-09-07] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [590880 2017-09-07] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [199312 2017-09-07] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [361336 2017-09-07] (AVAST Software)
R3 ATP; C:\WINDOWS\System32\drivers\AsusTP.sys [101368 2015-12-14] (ASUS Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [38720 2014-09-18] (Intel Corporation)
R3 dptf_pch; C:\WINDOWS\System32\drivers\dptf_pch.sys [38208 2014-09-18] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\System32\drivers\esif_lf.sys [216360 2014-09-18] (Intel Corporation)
R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [331608 2014-11-27] (SafeNet Inc.)
R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [79016 2014-08-26] (Intel Corporation)
R3 m76usb; C:\WINDOWS\System32\drivers\m76usb.sys [563360 2015-06-03] (Ralink Technology Corp.)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [129312 2015-02-25] (Intel Corporation)
R3 netr28x; C:\WINDOWS\System32\drivers\netr28x.sys [2537984 2017-03-18] (MediaTek Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvamwu.inf_amd64_d4715679184092a8\nvlddmkm.sys [13754936 2016-09-12] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [895256 2015-07-08] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [428032 2017-02-16] (Realsil Semiconductor Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 tap-tb-0901; C:\WINDOWS\System32\drivers\tap-tb-0901.sys [38656 2017-06-13] (The OpenVPN Project)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2017-09-14 14:46 - 2017-09-14 14:46 - 000031395 _____ C:\Users\Jean-François\Desktop\FRST.txt
2017-09-14 14:46 - 2017-09-14 14:46 - 000000000 ____D C:\FRST
2017-09-14 14:45 - 2017-09-14 14:45 - 002398208 _____ (Farbar) C:\Users\Jean-François\Desktop\FRST64.exe
2017-09-14 14:14 - 2017-09-14 14:14 - 000226981 _____ C:\Users\Jean-François\Desktop\Evaluations diagnostiques CE1 - maître.pdf
2017-09-14 14:13 - 2017-09-14 14:13 - 001537818 _____ C:\Users\Jean-François\Downloads\CE1_Evals_rentrée.zip
2017-09-14 13:58 - 2017-09-14 13:58 - 000003154 _____ C:\Users\Jean-François\Downloads\PDFSimpleListe.pdf
2017-09-14 13:48 - 2017-09-14 13:48 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-09-14 13:29 - 2017-09-14 13:29 - 000000000 ___HD C:\OneDriveTemp
2017-09-13 19:50 - 2017-09-13 19:48 - 001063081 ____T C:\Users\Jean-François\Desktop\MEMOIRE FINAL.pdf
2017-09-13 13:41 - 2017-09-13 13:43 - 000000000 ____D C:\Users\Jean-François\Desktop\Docs Arnaud Septembre 2017
2017-09-12 16:01 - 2017-09-12 16:02 - 009791816 _____ (Piriform Ltd) C:\Users\Jean-François\Downloads\ccsetup533.exe
2017-09-12 15:04 - 2016-12-20 07:18 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20170912-150401.backup
2017-09-12 13:30 - 2017-09-12 13:30 - 000529569 _____ C:\Users\Jean-François\Répertoire outils et activités maître E 2.imx
2017-09-12 13:20 - 2017-09-12 14:58 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-09-12 13:20 - 2017-09-12 13:31 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-09-12 13:20 - 2017-09-12 13:20 - 000001462 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2017-09-12 13:20 - 2017-09-12 13:20 - 000000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2017-09-12 13:20 - 2017-09-12 13:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2017-09-12 13:20 - 2017-05-23 09:22 - 000032240 _____ (Safer-Networking Ltd.) C:\WINDOWS\system32\sdnclean64.exe
2017-09-12 13:18 - 2017-09-13 15:56 - 000000000 ____D C:\AdwCleaner
2017-09-12 13:08 - 2017-09-12 13:12 - 008182736 _____ (Malwarebytes) C:\Users\Jean-François\Desktop\adwcleaner_7.0.2.1.exe
2017-09-12 13:06 - 2017-09-12 13:12 - 051725936 _____ (Safer-Networking Ltd. ) C:\Users\Jean-François\Downloads\spybotsd-2.6.46.exe
2017-09-12 10:23 - 2017-09-12 15:21 - 001080453 _____ C:\Users\Jean-François\Desktop\Répertoire outils et activités maître E.imx
2017-09-08 15:54 - 2017-09-08 15:54 - 000002876 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-09-08 15:54 - 2017-09-08 15:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-09-08 15:54 - 2017-09-08 15:54 - 000000000 ____D C:\Program Files\CCleaner
2017-09-07 15:00 - 2017-09-07 15:08 - 000000000 ____D C:\Users\Jean-François\Desktop\Mémoires G
2017-09-07 11:36 - 2017-09-07 11:36 - 000401488 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-09-06 21:52 - 2017-09-11 14:24 - 000000000 ____D C:\Users\Jean-François\Desktop\Téo mémoire
2017-09-04 13:46 - 2017-09-04 13:46 - 000404788 _____ C:\Users\Jean-François\Downloads\Nvelle Formation CAPPEI.pdf
2017-09-04 13:07 - 2017-09-04 13:07 - 000001085 _____ C:\Users\Jean-François\Downloads\calendar (3).ics
2017-09-04 13:05 - 2017-09-04 13:05 - 000000148 _____ C:\Users\Jean-François\Downloads\calendar (2).ics
2017-09-04 13:03 - 2017-09-04 13:03 - 000001992 _____ C:\Users\Jean-François\Downloads\calendar (1).ics
2017-09-04 11:14 - 2017-09-04 11:14 - 000049457 _____ C:\Users\Jean-François\Downloads\calendar.ics
2017-08-31 12:57 - 2017-08-31 12:57 - 002586889 _____ C:\Users\Jean-François\Downloads\Format-mémoire-S2-S4-SPSC.pdf
2017-08-25 19:53 - 2017-09-12 11:36 - 000000000 ____D C:\Users\Jean-François\AppData\Roaming\TunnelBear
2017-08-25 19:53 - 2017-08-25 19:53 - 000000000 ____D C:\Users\Jean-François\AppData\Local\IsolatedStorage
2017-08-25 19:52 - 2017-08-25 19:53 - 029903688 _____ (TunnelBear) C:\Users\Jean-François\Downloads\TunnelBear-Installer.exe
2017-08-25 08:06 - 2017-08-25 08:24 - 000000000 ____D C:\Users\Jean-François\Desktop\Copie SD 32
2017-08-24 22:24 - 2017-08-24 22:24 - 000112862 _____ C:\Users\Jean-François\Downloads\contacts.csv
2017-08-24 22:17 - 2017-08-25 07:37 - 000000000 ____D C:\ProgramData\Wondershare
2017-08-24 22:17 - 2017-08-24 22:17 - 000000000 ____D C:\Users\Jean-François\AppData\Local\Wondershare
2017-08-24 22:17 - 2015-02-27 10:35 - 000000232 _____ C:\WINDOWS\SysWOW64\dllhost.exe.config
2017-08-24 22:16 - 2017-08-24 23:42 - 000000000 ____D C:\Program Files (x86)\Wondershare
2017-08-24 22:15 - 2017-08-24 22:15 - 050887032 _____ (Wondershare ) C:\Users\Jean-François\Downloads\mobiletrans.exe
2017-08-21 15:43 - 2017-08-21 15:43 - 027718352 _____ (Microsoft Corporation) C:\Users\Jean-François\Downloads\OneDriveSetup.exe
2017-08-17 15:51 - 2017-08-17 15:51 - 000021645 _____ C:\Users\Jean-François\Desktop\Boucle Daelim.skp

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2017-09-14 14:40 - 2017-06-08 10:22 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-09-14 13:58 - 2016-01-09 14:35 - 000000000 ____D C:\Users\Jean-François\AppData\Local\Packages
2017-09-14 13:54 - 2017-06-08 10:24 - 000000000 ____D C:\Users\Jean-François
2017-09-14 13:53 - 2017-03-18 23:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-09-14 13:53 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-09-14 13:52 - 2017-03-18 22:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-09-14 13:52 - 2013-08-22 15:25 - 000000199 _____ C:\WINDOWS\win.ini
2017-09-14 13:29 - 2016-01-09 15:04 - 000000000 __RDO C:\Users\Jean-François\OneDrive
2017-09-14 13:27 - 2017-06-08 10:23 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-09-14 13:27 - 2016-02-22 13:43 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2017-09-14 13:27 - 2016-01-09 14:36 - 000000165 _____ C:\Users\Jean-François\AppData\Roaming\sp_data.sys
2017-09-14 13:27 - 2016-01-09 14:35 - 000000000 __SHD C:\Users\Jean-François\IntelGraphicsProfiles
2017-09-14 13:16 - 2016-01-10 21:02 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-09-14 13:13 - 2016-01-10 21:02 - 138202976 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-09-14 13:08 - 2017-06-08 10:34 - 000004180 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{584AC689-61B9-4FDE-83B1-B3D86C84AB1D}
2017-09-14 13:08 - 2017-06-08 10:34 - 000003550 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update1
2017-09-14 13:08 - 2017-06-08 10:34 - 000003540 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update2
2017-09-13 16:04 - 2017-06-08 10:35 - 002316694 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-09-13 16:04 - 2017-03-20 07:10 - 001068600 _____ C:\WINDOWS\system32\perfh00C.dat
2017-09-13 16:04 - 2017-03-20 07:10 - 000226166 _____ C:\WINDOWS\system32\perfc00C.dat
2017-09-13 15:56 - 2017-06-08 10:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-09-13 15:56 - 2017-03-18 13:40 - 002359296 _____ C:\WINDOWS\system32\config\BBI
2017-09-13 11:17 - 2016-11-12 07:42 - 000000000 ____D C:\Users\Jean-François\.thinkbuzan
2017-09-13 11:17 - 2016-11-12 07:40 - 000000000 ____D C:\ProgramData\ThinkBuzan
2017-09-13 11:17 - 2016-11-12 07:40 - 000000000 ____D C:\ProgramData\JSoft
2017-09-12 13:23 - 2017-06-08 10:34 - 000004038 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1463456163
2017-09-12 13:23 - 2017-03-18 13:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-09-12 13:23 - 2016-05-17 05:36 - 000001090 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-09-12 13:22 - 2017-01-27 15:59 - 000000000 ____D C:\Program Files\Common Files\AV
2017-09-12 11:36 - 2015-04-11 06:37 - 000000000 ____D C:\ProgramData\Package Cache
2017-09-11 11:28 - 2017-03-18 23:01 - 000000000 ____D C:\WINDOWS\INF
2017-09-08 15:55 - 2017-06-07 15:37 - 000000000 ___DC C:\WINDOWS\Panther
2017-09-08 15:55 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2017-09-08 15:55 - 2016-03-21 22:06 - 000000000 ____D C:\Users\Jean-François\AppData\Roaming\TeamViewer
2017-09-08 15:53 - 2017-03-15 20:22 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-09-08 15:53 - 2015-04-11 06:37 - 000000000 ____D C:\ProgramData\Skype
2017-09-08 15:33 - 2016-06-27 10:07 - 000000290 __RSH C:\ProgramData\ntuser.pol
2017-09-08 12:01 - 2016-03-21 22:06 - 000001042 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2017-09-08 12:01 - 2016-03-21 22:06 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2017-09-07 11:36 - 2017-06-08 10:34 - 000003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-09-07 11:36 - 2017-06-07 20:53 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-09-07 11:36 - 2017-02-12 17:52 - 000343296 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-09-07 11:36 - 2017-02-12 17:52 - 000320528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-09-07 11:36 - 2017-02-12 17:52 - 000198976 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-09-07 11:36 - 2017-02-12 17:52 - 000057736 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-09-07 11:36 - 2016-05-15 08:50 - 000041832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-09-07 11:36 - 2016-01-10 10:39 - 001016384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-09-07 11:36 - 2016-01-10 10:39 - 000590880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-09-07 11:36 - 2016-01-10 10:39 - 000361336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-09-07 11:36 - 2016-01-10 10:39 - 000199312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-09-07 11:36 - 2016-01-10 10:39 - 000147784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-09-07 11:36 - 2016-01-10 10:39 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-09-07 11:36 - 2016-01-10 10:39 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-09-07 11:36 - 2016-01-10 10:39 - 000047016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-09-04 10:20 - 2015-04-11 06:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2017-09-03 19:20 - 2017-03-18 23:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-09-02 17:15 - 2017-03-18 23:06 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-09-02 17:15 - 2017-03-18 23:06 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-08-30 21:23 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2017-08-29 11:54 - 2016-01-10 09:56 - 000002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-28 22:11 - 2016-09-01 11:14 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-08-22 20:29 - 2016-01-10 23:08 - 000000000 ____D C:\Users\Jean-François\AppData\Local\Comms

==================== Fichiers à la racine de certains dossiers =======

2016-03-08 15:48 - 2016-11-29 12:28 - 000000792 _____ () C:\Users\Jean-François\AppData\Roaming\.lirecouleur
2016-01-09 14:36 - 2017-09-14 13:27 - 000000165 _____ () C:\Users\Jean-François\AppData\Roaming\sp_data.sys
2017-06-08 10:22 - 2017-06-08 10:22 - 000000000 ____H () C:\ProgramData\DP45977C.lfl
2015-04-11 06:36 - 2012-09-07 13:40 - 000000256 _____ () C:\ProgramData\SetStretch.cmd
2015-04-11 06:36 - 2009-07-22 12:04 - 000024576 _____ () C:\ProgramData\SetStretch.exe
2015-04-11 06:36 - 2012-09-07 13:37 - 000000103 _____ () C:\ProgramData\SetStretch.VBS

Fichiers à déplacer ou supprimer:
====================
C:\Users\Jean-François\Quentin.dat


==================== Bamital & volsnap ======================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

LastRegBack: 2017-09-14 13:48

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité