Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x86) Version:23-12-2015 Exécuté par acer (administrateur) sur PC-DE-ACER (25-12-2015 11:57:51) Exécuté depuis H:\Fichiers Reçus\FRST Profils chargés: acer & Invité (Profils disponibles: acer & Invité) Platform: Microsoft Windows 7 Édition Familiale Premium Service Pack 1 (X86) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe (Arachnoid Biometrics Identification Group Corp.) C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (CyberLink Corp.) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe () C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe (CyberLink) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (Acer Incorporated) C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor Corp.) C:\Users\INVIT~1\AppData\Local\Temp\RtkBtMnt.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Acer Corp.) C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe () C:\Windows\PLFSetI.exe (Arachnoid Biometrics Identification Group Corp.) C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe () C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe (Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe () C:\Program Files\Acer\Empowering Technology\Service\ETService.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe () C:\Program Files\Acer\Acer Bio Protection\BASVC.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe ( ) C:\Windows\System32\lxblcoms.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe () C:\ACER\Mobility Center\MobilityService.exe (NewTech InfoSystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe () C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe () C:\Program Files\Cyberlink\Shared files\RichVideo.exe (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Dritek System Inc.) C:\Program Files\Launch Manager\QtZgAcer.EXE (Mixesoft Project) C:\Users\Invité\AppData\Local\Mixesoft\AppNHost\appnhost.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1049896 2008-04-25] (Synaptics, Inc.) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor) HKLM\...\Run: [ArcadeDeluxeAgent] => C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [147456 2008-07-24] (CyberLink Corp.) HKLM\...\Run: [BkupTray] => C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [28672 2008-04-25] () HKLM\...\Run: [CLMLServer] => C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [167936 2008-07-24] (CyberLink) HKLM\...\Run: [eAudio] => C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe [544768 2008-05-30] (Acer Incorporated) HKLM\...\Run: [eDataSecurity Loader] => C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [526896 2008-05-14] (Egis Incorporated) HKLM\...\Run: [ePower_DMC] => C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [405504 2008-08-01] (Acer Inc.) HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-07-20] (Intel Corporation) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-29] (Microsoft Corporation) HKLM\...\Run: [PlayMovie] => C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [167936 2008-07-18] (Acer Corp.) HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2007-10-23] () HKLM\...\Run: [WarReg_PopUp] => C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe [303104 2008-01-29] (Acer Incorporated) HKLM\...\Run: [ZPdtWzdVitaKey MC3000] => C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe [3676160 2014-01-28] (Arachnoid Biometrics Identification Group Corp.) HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\QtZgAcer.EXE [817672 2008-06-04] (Dritek System Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe [2621240 2015-11-18] (Malwarebytes Corporation) HKLM\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-10-05] (Malwarebytes) Winlogon\Notify\AWinNotifyVitaKey MC3000: C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll [2014-01-28] (Arachnoid Biometrics Identification Group Corp.) Winlogon\Notify\ScCertProp: wlnotify.dll [X] Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll [2008-03-25] (UPEK Inc.) HKU\S-1-5-21-2975540974-3318519047-2496667730-1000\...\Run: [uTorrent] => "C:\Users\Invité\Downloads\uTorrent.exe" /MINIMIZED HKU\S-1-5-21-2975540974-3318519047-2496667730-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6602152 2015-11-16] (Piriform Ltd) HKU\S-1-5-21-2975540974-3318519047-2496667730-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [28917376 2015-05-14] (Skype Technologies S.A.) HKU\S-1-5-21-2975540974-3318519047-2496667730-1000\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[C2].txt HKU\S-1-5-21-2975540974-3318519047-2496667730-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Program Files\Screensavers\Snow_Chr.scr [2062800 2015-12-21] () HKU\S-1-5-21-2975540974-3318519047-2496667730-501\...\Run: [appnhost] => C:\Users\Invité\AppData\Local\Mixesoft\AppNHost\appnhost.exe [453176 2014-08-08] (Mixesoft Project) HKU\S-1-5-21-2975540974-3318519047-2496667730-501\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6602152 2015-11-16] (Piriform Ltd) HKU\S-1-5-21-2975540974-3318519047-2496667730-501\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Program Files\Screensavers\Snowy_Ho.scr [3036042 2015-12-21] () HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-02-17] (Microsoft Corporation) Lsa: [Notification Packages] scecli C:\Program Files\Acer\Acer Bio Protection\PwdFilter ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [2008-05-14] (Egis Inc.) Startup: C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\screensaver-aquarium.lnk [2015-02-21] ShortcutTarget: screensaver-aquarium.lnk -> C:\ProgramData\{ff99b54a-34bc-b85f-ff99-9b54a34bd528}\screensaver-aquarium.exe (Pas de fichier) Startup: C:\Users\acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\screensaver-tropical-aquarium.lnk [2015-02-21] ShortcutTarget: screensaver-tropical-aquarium.lnk -> C:\ProgramData\{b5b1a5f0-3e4a-2a42-b5b1-1a5f03e497c0}\screensaver-tropical-aquarium.exe (Pas de fichier) CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 212.27.40.241 212.27.40.240 Tcpip\..\Interfaces\{0E06914D-F636-4897-A0F8-71CA9A4F8CDE}: [DhcpNameServer] 212.27.40.241 212.27.40.240 Tcpip\..\Interfaces\{F8B2785F-DCDA-462E-B262-1E314AFAC753}: [DhcpNameServer] 212.27.40.241 212.27.40.240 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm HKU\S-1-5-21-2975540974-3318519047-2496667730-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0114&m=aspire_6930g HKU\S-1-5-21-2975540974-3318519047-2496667730-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com HKU\S-1-5-21-2975540974-3318519047-2496667730-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE HKU\S-1-5-21-2975540974-3318519047-2496667730-501\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0114&m=aspire_6930g HKU\S-1-5-21-2975540974-3318519047-2496667730-501\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com HKU\S-1-5-21-2975540974-3318519047-2496667730-501\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE SearchScopes: HKLM -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKLM -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\.DEFAULT -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKU\.DEFAULT -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = SearchScopes: HKU\S-1-5-21-2975540974-3318519047-2496667730-1000 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-2975540974-3318519047-2496667730-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKU\S-1-5-21-2975540974-3318519047-2496667730-1000 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-2975540974-3318519047-2496667730-501 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-30] (Oracle Corporation) BHO: ShowBarObj Class -> {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-05-14] (Egis) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-01-28] (Google Inc.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2014-01-28] (Google Inc.) BHO: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2014-01-28] (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-30] (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-01-28] (Google Inc.) Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-05-14] (Egis Incorporated.) Toolbar: HKU\S-1-5-21-2975540974-3318519047-2496667730-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-01-28] (Google Inc.) Toolbar: HKU\S-1-5-21-2975540974-3318519047-2496667730-501 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-01-28] (Google Inc.) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default FF Homepage: hxxps://www.malwarebytes.org/restorebrowser//?pid=2346&r=2015/02/21&hid=14105602325602345097&lg=EN&cc=FR&unqvl=82 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-08] () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1209149.dll [2014-01-29] (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-30] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-30] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-06-07] (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-12-21] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2975540974-3318519047-2496667730-501: @citrixonline.com/appdetectorplugin -> C:\Users\Invité\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-01-22] (Citrix Online) FF SearchPlugin: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\searchplugins\allthegames-search.xml [2009-08-05] FF SearchPlugin: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\searchplugins\babelfish-translate-en--fr.xml [2009-08-05] FF SearchPlugin: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\searchplugins\bing--google.xml [2009-08-05] FF SearchPlugin: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\searchplugins\bitcoca.xml [2009-08-05] FF SearchPlugin: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\searchplugins\grooveshark.xml [2010-10-07] FF SearchPlugin: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\searchplugins\heapr-web-search.xml [2013-12-08] FF SearchPlugin: C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\searchplugins\serpanalytics-google-search.xml [2013-12-08] FF Extension: Master Password Timeout - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\extensions\{96118df2-0d02-4dbc-9ad5-98995dc7d977}.xpi [2015-12-25] FF Extension: Aging Tabs - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\aging-tabs@design-noir.de [2014-02-11] [non signé] FF Extension: Virtus Search Opt-in - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\extension@virtusdesigns.com [2014-02-11] [non signé] FF Extension: iJaw Downloader - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\ijaw@virtualabs.fr [2014-02-11] [non signé] FF Extension: Lightbeam - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2014-02-11] [non signé] FF Extension: FindThatBand - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\mablu@jperryextens.ion.xpi [2013-05-01] [non signé] FF Extension: NASA Night Launch - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\nasanightlaunch@example.com.xpi [2014-02-09] [non signé] FF Extension: Noia 2.0 eXtreme OPT - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\noia2_option@kk.noia [2014-02-11] [non signé] FF Extension: Personas for Firefox - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\personas@christopher(329).beard [2014-02-11] [non signé] FF Extension: Personas Plus - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\personas@christopher.beard.xpi [2014-02-09] [non signé] FF Extension: Cooliris - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\piclens@cooliris.com [2014-02-11] [non signé] FF Extension: Pink-bee - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\pink-bee@loic.com.xpi [2013-12-08] [non signé] FF Extension: samfind Bookmarks Bar - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\sam@samfind.com [2014-02-11] [non signé] FF Extension: SphereGnome - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\SphereGnome [2014-02-11] [non signé] FF Extension: Tab buttons - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\tabbuttons.ff@octopod.org [2014-02-11] [non signé] FF Extension: NASA Normal - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{00df3690-c341-11da-a94d-0800200c9a66} [2014-02-11] [non signé] FF Extension: Super Mario Bros 3 - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{051ce736-d132-4374-9d36-eb192ef3110c} [2014-02-11] [non signé] FF Extension: Forecastfox - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2014-02-11] [non signé] FF Extension: ColorfulTabs - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe} [2014-02-11] [non signé] FF Extension: Vista on XP - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{07b2a769-ed19-4483-87ce-c643914c81b1} [2014-02-11] [non signé] FF Extension: Netcraft Anti-Phishing Toolbar - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{0e10f3d7-07f6-4f12-97b9-9b27e07139a5}.xpi [2013-10-18] [non signé] FF Extension: ELI Theme - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{173487d0-5384-11dd-ae16-0800200c9a66} [2014-02-11] [non signé] FF Extension: Aeon Colors - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}(330) [2014-02-11] [non signé] FF Extension: My_buuf - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{1f870b8e-d71f-11db-8314-0800200c9a66}.xpi [2011-03-28] [non signé] FF Extension: Microsoft .NET Framework Assistant - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2014-02-11] [non signé] FF Extension: Infocon Monitor - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{27772D7B-7C4E-413e-A306-E838FD77D42F} [2014-02-11] [non signé] FF Extension: Tinseltown - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{285da7e0-729d-11db-9fe1-0800200c9a66} [2014-02-11] [non signé] FF Extension: Cobalt Firefox - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{28f708c0-ac24-11db-abbd-0800200c9a66} [2014-02-11] [non signé] FF Extension: LittleFox - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}.xpi [2014-02-11] [non signé] FF Extension: Harley Davidson - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{2c088200-b973-11db-8314-0800200c9a66} [2014-02-11] [non signé] FF Extension: ChromEdit - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{2cf89d59-8610-4053-b207-85c6a128f65d} [2014-02-11] [non signé] FF Extension: Jacksonville Jaguars - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{2f7d180e-3bed-11dc-8314-0800200c9a66} [2014-02-11] [non signé] FF Extension: Scribblies Kids - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{33A8946C-B859-4f7d-8382-ADAB29623DEE}(331) [2014-02-11] [non signé] FF Extension: PDF Download - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}(27) [2014-02-11] [non signé] FF Extension: ShowIP - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi [2013-03-24] [non signé] FF Extension: RefControl - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi [2011-12-27] [non signé] FF Extension: FoxyTunes - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374} [2014-02-11] [non signé] FF Extension: Metal Lion - 300 - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{4A207596-AED2-4223-929F-BBE1D691B7CD} [2014-02-11] [non signé] FF Extension: New Orleans Saints - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{4d05b5ec-2139-11dc-8314-0800200c9a66} [2014-02-11] [non signé] FF Extension: Alienware Invader v1.2 - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{5476e6b0-3de0-11dd-ae16-0800200c9a66} [2014-02-11] [non signé] FF Extension: Foxkeh Theme - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{57407AE0-868F-11DC-AD21-49A755D89593} [2014-02-11] [non signé] FF Extension: Anonymouser - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{5C2A336E-AF61-4fd5-90D7-9BDAC105D064} [2014-02-11] [non signé] FF Extension: Nautipolis for Firefox - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}.xpi [2014-02-11] [non signé] FF Extension: Mattahan - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{7336c430-3def-11dd-ae16-0800200c9a66} [2014-02-11] [non signé] FF Extension: NoScript - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(332) [2014-02-11] [non signé] FF Extension: NoScript - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-02-09] [non signé] FF Extension: Mythical Sirens Summer Night - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{77fe20a8-a8f8-11dc-8314-0800200c9a66} [2014-02-11] [non signé] FF Extension: mediaplayerconnectivity - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{84b24861-62f6-364b-eba5-2e5e2061d7e6} [2014-02-11] [non signé] FF Extension: Showcase - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}.xpi [2013-05-02] [non signé] FF Extension: Blue Craze - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{98291480-7cdc-11db-9fe1-0800200c9a66} [2014-02-11] [non signé] FF Extension: Noia 2.0 (eXtreme) - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} [2014-02-11] [non signé] FF Extension: PimpZilla - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66} [2014-02-11] [non signé] FF Extension: WOT - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-02-11] [non signé] FF Extension: Aluminium Kai 2 - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{a45e6b3a-725d-4b20-afde-e7486bfe317c} [2014-02-11] [non signé] FF Extension: X-Mas - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{a8e099e0-89d6-11db-b606-0800200c9a66} [2014-02-11] [non signé] FF Extension: StumbleUpon - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi [2012-12-30] [non signé] FF Extension: DownloadHelper - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-02-11] [non signé] FF Extension: Halloween - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{BB359C50-BFC9-4f40-8302-3FE5A499A859}(333) [2014-02-11] [non signé] FF Extension: Fasterfox - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{c36177c0-224a-11da-8cd6-0800200c9a66} [2014-02-11] [non signé] FF Extension: iPox - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{c9c58820-7bd4-11da-a72b-0800200c9a66} [2014-02-11] [non signé] FF Extension: Curacao - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{cc6ef5ab-35be-4300-bd07-d12850fc97ff}(28) [2014-02-11] [non signé] FF Extension: Adblock Plus - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-11] [non signé] FF Extension: iFox Smooth - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{d3d70bca-2d54-425e-b02c-b7e2f4b07688} [2014-02-11] [non signé] FF Extension: Miint - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{d596c130-b00a-11db-abbd-0800200c9a66} [2014-02-11] [non signé] FF Extension: FOXSCAPE - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{da7f40f0-8675-11db-b606-0800200c9a66}.xpi [2014-02-09] [non signé] FF Extension: Enhanced Bookmark Search - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{DA92B0E0-6CB4-11d9-941A-444553540001} [2014-02-11] [non signé] FF Extension: Tab Mix Plus - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-11-11] [non signé] FF Extension: Red Cats (green flavor) - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{dd30bf68-268a-4815-ad48-8740b774c764}.xpi [2013-10-27] [non signé] FF Extension: Aeon - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{ded0fc70-7215-4802-afeb-b2982d3e7225}(334) [2014-02-11] [non signé] FF Extension: Arizona Wildcats - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{e458aad0-b532-11db-abbd-0800200c9a66} [2014-02-11] [non signé] FF Extension: Greasemonkey - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2012-09-01] [non signé] FF Extension: SpoofStick - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{ebcf8b39-5cb1-4233-9edf-7d6533455b8d} [2014-02-11] [non signé] FF Extension: Firefox Futurama - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{f3c24b71-1b60-11db-961a-00e08161165f} [2014-02-11] [non signé] FF Extension: Multirow Bookmarks Toolbar - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}.xpi [2011-04-18] [non signé] FF Extension: CustomizeGoogle - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb} [2014-02-11] [non signé] FF Extension: Red Cats (blue flavor) - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{ff356687-aa08-463d-a46c-11c451824939}.xpi [2013-10-27] [non signé] FF Extension: FireCat PalePurplePawsCB - C:\Users\acer\AppData\Roaming\Mozilla\Firefox\Profiles\8v37n3h5.default\Extensions\{FireCat-c52414d1-0f65-11d9-9669-0800200c9a66} [2014-02-11] [non signé] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-02-11] [non signé] Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.free.fr/adsl" CHR Profile: C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Tibi) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahfnihbbceiilhalikfkonbipolponko [2014-02-11] CHR Extension: (Meteo en France) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\anakpfpojdnocblgejmienjaaggfgbdj [2014-02-11] CHR Extension: (Météo Europe) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\baampgkagbmhnlhleemfbpecfjpakffj [2014-02-11] CHR Extension: (Météo (extension)) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\beapnbfmjmjhhfpaoajfhjbbfnnlfpnc [2015-04-30] CHR Extension: (Click&Clean) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2015-04-30] CHR Extension: (Turn Off the Lights) - C:\Users\acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\labjanboighjienkhiabgpefblkbmemd [2015-04-30] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12] ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 BUNAgentSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [16384 2008-03-03] (NewTech Infosystems, Inc.) [Fichier non signé] R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation) R2 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [81504 2008-01-16] () [Fichier non signé] R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-06-02] () [Fichier non signé] S3 GoogleDesktopManager-080708-050100; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [24064 2014-01-28] (Google) [Fichier non signé] R2 IGBASVC; C:\Program Files\Acer\Acer Bio Protection\BASVC.exe [3602432 2014-01-28] () [Fichier non signé] R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [Fichier non signé] R2 lxbl_device; C:\Windows\system32\lxblcoms.exe [537520 2007-04-20] ( ) R2 MbaeSvc; C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe [739640 2015-11-18] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes) R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] () [Fichier non signé] R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation) R2 NTIBackupSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [45056 2008-04-25] (NewTech InfoSystems, Inc.) [Fichier non signé] R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-25] () [Fichier non signé] R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [272024 2007-01-09] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S2 b04ff899; "C:\Windows\system32\rundll32.exe" "c:\Program Files\RelayTurbo\RelayTurbo.dll",serv S3 WPFFontCache_v0400; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [X] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R0 AlfaFF; C:\Windows\System32\Drivers\AlfaFF.sys [42608 2014-01-28] (Alfa Corporation) R1 ESProtectionDriver; C:\Program Files\Malwarebytes Anti-Exploit\mbae.sys [47928 2015-11-18] () R2 int15; C:\Windows\system32\drivers\int15.sys [69632 2007-01-26] () [Fichier non signé] R3 L1E; C:\Windows\System32\DRIVERS\L1E62x86.sys [55848 2015-06-13] (Atheros Communications, Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation) R2 NTIPPKernel; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [122368 2008-01-16] (Cyberlink Corp.) [Fichier non signé] S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [20040 2014-01-14] () S3 SCR3XX2K; C:\Windows\System32\DRIVERS\SCR3XX2K.sys [62976 2014-06-16] (Identive) R3 winbondcir; C:\Windows\System32\DRIVERS\winbondcir.sys [43008 2007-03-28] (Winbond Electronics Corporation) R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [61424 2008-07-18] (Cyberlink Corp.) S1 MpKsl7d5b1a36; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{29758757-EDE1-42A9-B1B4-0205BFB1A102}\MpKsl7d5b1a36.sys [X] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ========================== MD5 Pilotes ======================= C:\Windows\system32\drivers\1394ohci.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\ACPI.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\acpipmi.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\adp94xx.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\adpahci.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\adpu320.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\afd.sys 93B49FA857F7036A4EFF32371F6E7391 C:\Windows\system32\drivers\agp440.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\djsvs.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\AlfaFF.sys 4490B8BDF38750458EB9B24835FDA8FE C:\Windows\system32\drivers\aliide.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\amdagp.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\amdide.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\amdk8.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\amdppm.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\amdsata.sys D320BF87125326F996D4904FE24300FC C:\Windows\system32\DRIVERS\amdsbs.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\amdxata.sys 46387FB17B086D16DEA267D5BE23A2F2 C:\Windows\system32\drivers\appid.sys FE4F2ADE5DBB3B888E9EB0A1FBA1F152 C:\Windows\system32\DRIVERS\arc.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\arcsas.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\asyncmac.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\atapi.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\bxvbdx.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\b57nd60x.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\Beep.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\blbdrive.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\bowser.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\Brserid.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\BrSerWdm.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\BrUsbMdm.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\BrUsbSer.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\bthmodem.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\cdfs.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\cdrom.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\circlass.sys ==> Le MD5 est légitime C:\Windows\System32\CLFS.sys 33A60554882FDF59CDA3E1806370BBA1 C:\Windows\System32\DRIVERS\CmBatt.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\cmdide.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\cng.sys 780FFC005741C9316576086155E55F56 C:\Windows\System32\DRIVERS\compbatt.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\CompositeBus.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\crcdisk.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\dfsc.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\discache.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\disk.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\DKbFltr.sys 73BAF270D24FE726B9CD7F80BB17A23D C:\Windows\system32\drivers\drmkaud.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\dxgkrnl.sys 3583A5A8CC2E682BFFBD4630D0FEC08B C:\Windows\system32\DRIVERS\evbdx.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\elxstor.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\errdev.sys ==> Le MD5 est légitime C:\Program Files\Malwarebytes Anti-Exploit\mbae.sys 6E07CC0EDE471A65D254D75ED221F415 C:\Windows\system32\Drivers\exfat.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\fastfat.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\fdc.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\fileinfo.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\filetrace.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\flpydisk.sys ==> Le MD5 est légitimeB C:\Windows\System32\drivers\fltmgr.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\FsDepends.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\Fs_Rec.sys 7DAE5EBCC80E45D3253F4923DC424D05 C:\Windows\System32\DRIVERS\fvevol.sys E306A24D9694C724FA2491278BF50FDB C:\Windows\system32\DRIVERS\gagp30kx.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\hcw85cir.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\HDAudBus.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\HidBatt.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\hidbth.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\hidir.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\hidusb.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\HpSAMD.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\HSX_DPV.sys FADD7095163CB3CB4073793EBB50FE75 C:\Windows\System32\DRIVERS\HSXHWAZL.sys 058783BEDD17615D1FECE09F77960436 C:\Windows\System32\drivers\HTTP.sys 487569E5DA56A5A432FF8AF6D3599CF9 C:\Windows\System32\drivers\hwpolicy.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\i8042prt.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\iaStor.sys 707C1692214B1C290271067197F075F6 C:\Windows\system32\drivers\iaStorV.sys 5CD5F9A5444E6CDCB0AC89BD62D8B76E C:\Windows\system32\DRIVERS\iirsp.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\int15.sys 4D8D5B1C895EA0F2A721B98A7CE198F1 C:\Windows\System32\drivers\RTKVHDA.sys 219CA9A36D6DE2EC04F958C907673436 C:\Windows\system32\drivers\intelide.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\intelppm.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\IPMIDrv.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\ipnat.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\irenum.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\isapnp.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\msiscsi.sys EB34CE31FABD4DC4343FD2AD16D2CAF9 C:\Windows\system32\drivers\kbdclass.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\kbdhid.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\ksecdd.sys A061E519ACDE34843DFA3F1C7358DAA2 C:\Windows\System32\Drivers\ksecpkg.sys 523091605C05F5DE880426A2FBA0F87C C:\Windows\System32\DRIVERS\L1E62x86.sys 14F63A275C1BFF4D35E02DE1127E8A85 C:\Windows\System32\DRIVERS\lltdio.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\lsi_fc.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\lsi_sas.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\luafv.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\mbam.sys 40C7F4B63337414F967AC53E0520B06B C:\Windows\system32\drivers\mwac.sys 63254775FE0F974F5316B4EC3F163038 C:\Windows\System32\DRIVERS\mdmxsdk.sys 0CEA2D0D3FA284B85ED5B68365114F76 C:\Windows\system32\DRIVERS\megasas.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\MegaSR.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\modem.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\monitor.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\mouclass.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\mouhid.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\mountmgr.sys BAD9C0366134BA181514E9263C8CE606 C:\Windows\System32\DRIVERS\MpFilter.sys F112DA773EC3E9D3CDE9221ED300E033 C:\Windows\system32\drivers\mpio.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\mpsdrv.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\mrxdav.sys 03F899F521D2AAED1C55008F734DF252 C:\Windows\System32\DRIVERS\mrxsmb.sys C7492026F6691A92C4508DDDB041CE4E C:\Windows\System32\DRIVERS\mrxsmb10.sys 34779EBCFEAB87A236B33C365A637144 C:\Windows\System32\DRIVERS\mrxsmb20.sys C34DE43FDAD9C32383BB4A5EE60126D4 C:\Windows\system32\drivers\msahci.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\msdsm.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\Msfs.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\mshidkmdf.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\msisadrv.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\MSKSSRV.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\MSPCLOCK.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\MSPQM.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\MsRPC.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\mssmbios.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\MSTEE.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\MTConfig.sys ==> Le MD5 est légitime C:\Windows\System32\Drivers\mup.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\nwifi.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\ndis.sys 9804FB2E46077F2977552347DFCA7E05 C:\Windows\System32\DRIVERS\ndiscap.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\ndistapi.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\ndisuio.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\ndiswan.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\NDProxy.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\netbios.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\netbt.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\netw5v32.sys 58218EC6B61B1169CF54AAB0D00F5FE2 C:\Windows\system32\DRIVERS\nfrd960.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\NisDrvWFP.sys 780FF28BCD8470C5FDDEEF69982AA295 C:\Windows\system32\Drivers\Npfs.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\nsiproxy.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\Ntfs.sys C8DFF8D07755A66C7A4A738930F0FEAC C:\Windows\System32\DRIVERS\NTIDrvr.sys 2757D2BA59AEE155209E24942AB127C9 C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys 547BFA3591C70674B0BFC99354AB78B3 C:\Windows\system32\Drivers\Null.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\nvhda32v.sys 2C7AC27710E8D41C1EB7D1599187D237 C:\Windows\System32\DRIVERS\nvlddmkm.sys CB0D6F8F65B8766FF2AAAA78881FD9F8 C:\Windows\system32\drivers\nvraid.sys B3E25EE28883877076E0E1FF877D02E0 C:\Windows\system32\drivers\nvstor.sys 4380E59A170D88C4F1022EFF6719A8A4 C:\Windows\system32\drivers\nv_agp.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\ohci1394.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\parport.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\partmgr.sys 3F34A1B4C5F6475F320C275E63AFCE9B C:\Windows\system32\DRIVERS\parvdm.sys ==> Le MD5 est légitime C:\Program Files\PeerBlock\pbfilter.sys DD20CD5991712BE6004F45BE5C44CAD0 C:\Windows\System32\drivers\pci.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\pciide.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\pcmcia.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\pcw.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\peauth.sys AEBC369F7DC72AB3F5B9BDF34FA0D43F C:\Windows\System32\DRIVERS\raspptp.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\processr.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\pacer.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\psdfilter.sys 1DCBB35090CC4B2BD3D661E6089523C6 C:\Windows\System32\DRIVERS\PSDNServ.sys E26E46D619469964AC3609620F443867 C:\Windows\System32\DRIVERS\PSDVdisk.sys 3E1D134AF2806867D06047C4CC33CC65 C:\Windows\system32\DRIVERS\ql2300.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\ql40xx.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\qwavedrv.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\rasacd.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\AgileVpn.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\rasl2tp.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\raspppoe.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\rassstp.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\rdbss.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\rdpbus.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\RDPCDD.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\rdpencdd.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\rdprefmp.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\RDPWD.sys CD9214A6AE17D188D17C3CF8CB9CC693 C:\Windows\System32\drivers\rdyboost.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\rspndr.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\RTSTOR.SYS 7A4F79DF3793160B280CDE152B61FE33 C:\Windows\system32\drivers\sbp2port.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\scfilter.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\SCR3XX2K.sys A2DA64286B2CB929F1B38893F552C5D0 C:\Windows\system32\Drivers\secdrv.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\serenum.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\serial.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\sermouse.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\sffdisk.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\sffp_mmc.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\sffp_sd.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\sfloppy.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\sisagp.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\sisraid4.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\smb.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\spldr.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\srv.sys E4C2764065D66EA1D2D3EBC28FE99C46 C:\Windows\System32\DRIVERS\srv2.sys 03F0545BD8D4C77FA0AE1CEEDFCC71AB C:\Windows\System32\DRIVERS\srvnet.sys BE6BD660CAA6F291AE06A718A4FA8ABC C:\Windows\system32\DRIVERS\stexstor.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\swenum.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\SynTP.sys 4C9BB4B3B9EAC26211484C30B914C6DC C:\Windows\System32\drivers\tcpip.sys 5579DD18546999F5D0EC39D018726C6B C:\Windows\System32\DRIVERS\tcpip.sys 5579DD18546999F5D0EC39D018726C6B C:\Windows\System32\drivers\tcpipreg.sys 3EEBD3BD93DA46A26E89893C7AB2FF3B C:\Windows\System32\Drivers\tcusb.sys 72B9E77565DA5FA564581976E000D29B C:\Windows\System32\drivers\tdpipe.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\tdtcp.sys 2C2C5AFE7EE4F620D69C23C0617651A8 C:\Windows\System32\DRIVERS\tdx.sys BB8817D0508DD5EA69C770C8DEF5AB67 C:\Windows\system32\drivers\termdd.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\tssecsrv.sys 6C5139E4283249518F7743D7043775B3 C:\Windows\System32\drivers\tsusbflt.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\tunnel.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\uagp35.sys ==> Le MD5 est légitime C:\Windows\system32\Drivers\UBHelper.sys F763E070843EE2803DE1395002B42938 C:\Windows\System32\DRIVERS\udfs.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\uliagpkx.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\umbus.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\umpass.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\usbccgp.sys 0803FBA9FE829D61AE26EC0BCC910C46 C:\Windows\system32\drivers\usbcir.sys 2352AB5F9F8F097BF9D41D5A4718A041 C:\Windows\system32\drivers\usbehci.sys D40855F89B69305140BBD7E9A3BA2DA6 C:\Windows\System32\DRIVERS\usbhub.sys EDF2DF71C4F1E13A6AC75F5224DE655A C:\Windows\system32\drivers\usbohci.sys 9828C8D14CC2676421778F0DE638CF97 C:\Windows\System32\DRIVERS\usbprint.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\usbscan.sys FC6B21DB4B5B398AB93DBE59CBF11036 C:\Windows\System32\DRIVERS\USBSTOR.SYS F991AB9CC6B908DB552166768176896A C:\Windows\system32\drivers\usbuhci.sys 800AABFD625EEFF899F7E5496BDE37AB C:\Windows\System32\Drivers\usbvideo.sys DE014425522610BEDCA3821BB8C0F1D5 C:\Windows\System32\drivers\vdrvroot.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\vgapnp.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\vga.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\vhdmp.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\viaagp.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\viac7.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\viaide.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\volmgr.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\volmgrx.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\volsnap.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\vsmraid.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\vwifibus.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\wacompen.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\wanarp.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\wanarp.sys ==> Le MD5 est légitime C:\Windows\system32\DRIVERS\wd.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\Wdf01000.sys 25944D2CC49E0A6C581D02A74B7D6645 C:\Windows\System32\DRIVERS\wfplwf.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\wimmount.sys ==> Le MD5 est légitime C:\Windows\System32\DRIVERS\HSX_CNXT.sys BB9CBAF6AC20452B245C324F1F50EE81 C:\Windows\System32\DRIVERS\winbondcir.sys 3FA87D56769838AAC82FAFC3E78FC732 C:\Windows\System32\DRIVERS\WinUsb.sys A67E5F9A400F3BD1BE3D80613B45F708 C:\Windows\system32\drivers\wmiacpi.sys ==> Le MD5 est légitime C:\Windows\system32\drivers\ws2ifsl.sys ==> Le MD5 est légitime C:\Windows\System32\drivers\WudfPf.sys 06E6F32C8D0A3F66D956F57B43A2E070 C:\Windows\System32\DRIVERS\WUDFRd.sys 867C301E8B790040AE9CF6486E8041DF C:\Windows\System32\DRIVERS\xaudio.sys DAB33CFA9DD24251AAA389FF36B64D4B C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl 4D840C6AF3C020ED3A35EFBA9025CF4A ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Trois mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2015-12-25 11:57 - 2015-12-25 11:57 - 00000000 ____D C:\FRST 2015-12-25 11:20 - 2015-12-25 11:43 - 00236930 _____ C:\Users\Invité\Desktop\topo forum PCA.txt 2015-12-25 10:25 - 2015-12-25 10:26 - 00000000 ____D C:\Program Files\ZHPFix 2015-12-25 10:25 - 2015-12-25 10:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2015-12-25 09:03 - 2015-12-25 09:03 - 00075044 _____ C:\Users\acer\Desktop\zoek-results.txt 2015-12-25 02:33 - 2015-12-25 02:33 - 00000000 ____D C:\zoek_backup 2015-12-25 02:08 - 2015-12-25 02:08 - 00009078 _____ C:\Users\acer\Desktop\ZHPCleaner.txt 2015-12-25 01:44 - 2015-12-25 01:44 - 00009876 _____ C:\Users\acer\Desktop\ZHPCleaner_log25-12-2015.txt 2015-12-25 00:57 - 2015-12-25 00:58 - 00000835 _____ C:\Users\acer\Desktop\ZHPCleaner.lnk 2015-12-25 00:47 - 2015-12-25 00:47 - 00115434 _____ C:\Users\acer\Desktop\ZHPDiag_log 25-12-2015.txt 2015-12-25 00:26 - 2015-12-25 00:26 - 00115446 _____ C:\Users\acer\Desktop\ZHPDiag_log 25-12.txt 2015-12-25 00:25 - 2015-12-25 10:39 - 00114758 _____ C:\Users\acer\Desktop\ZHPDiag.txt 2015-12-25 00:15 - 2015-12-25 00:52 - 00000000 ____D C:\Users\Invité\AppData\LocalLow\Spyware Terminator 2015-12-25 00:05 - 2015-12-25 00:05 - 00000000 ____D C:\Users\acer\AppData\Local\Macromedia 2015-12-25 00:03 - 2015-12-25 00:03 - 02039808 _____ C:\Users\acer\ZHPDiag3.exe 2015-12-25 00:01 - 2015-12-25 10:34 - 00000000 ____D C:\Users\acer\AppData\Roaming\ZHP 2015-12-25 00:01 - 2015-12-25 10:33 - 00000825 _____ C:\Users\acer\Desktop\ZHPDiag.lnk 2015-12-24 23:16 - 2011-06-21 11:24 - 00032768 _____ C:\Windows\system32\Drivers\sp_rsdrv2.sys 2015-12-23 22:38 - 2015-12-23 22:38 - 00793948 _____ C:\Users\Invité\Downloads\BD_Mutuellement N°31-Dec 2015-planchesSTC.pdf 2015-12-23 20:40 - 2015-12-24 21:18 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-12-23 20:18 - 2015-12-24 15:44 - 00000000 ____D C:\Users\Invité\Desktop\Doc & Co 2015-12-22 23:41 - 2015-12-22 23:41 - 00111808 _____ C:\Users\Invité\Documents\tares physiques peuple élu--samacher-celticus.pdf4.pdf 2015-12-21 00:22 - 2015-12-21 00:22 - 02237577 _____ C:\Users\acer\Downloads\ecran-de-veille-arbre-noel-lumieres [1].exe 2015-12-21 00:20 - 2015-12-21 00:20 - 02969890 _____ C:\Users\acer\Downloads\ecran-de-veille-flocons-neige [1].exe 2015-12-21 00:18 - 2015-12-21 00:18 - 03381560 _____ C:\Users\acer\Downloads\ecran-de-veille-scene-noel [1].exe 2015-12-21 00:17 - 2015-12-21 00:17 - 01060182 _____ (hxxp://www.screensaverspc.com/ ) C:\Users\acer\Downloads\ecran-de-veille-recif-corail [1].exe 2015-12-21 00:17 - 2015-12-21 00:17 - 00000000 ____D C:\Windows\Fish Pond Screensaver Uninstaller 2015-12-21 00:17 - 2012-07-27 12:21 - 01101062 _____ (Jan Kolarik & Ondrej Vaverka) C:\Windows\Fish Pond Screensaver.scr 2015-12-21 00:16 - 2015-12-21 00:15 - 02408318 _____ C:\Users\acer\Downloads\ecran-de-veille-arbre-noel-ville [1].exe 2015-12-21 00:12 - 2015-12-21 00:12 - 00002048 _____ C:\Users\acer\Desktop\Arcadestudio.com.lnk 2015-12-21 00:12 - 2015-12-21 00:12 - 00000921 _____ C:\Users\acer\Desktop\3D Funny Fish Free.lnk 2015-12-21 00:12 - 2015-12-21 00:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3D Funny Fish Free 2015-12-21 00:12 - 2015-12-21 00:12 - 00000000 ____D C:\Program Files\3D Funny Fish Free 2015-12-21 00:12 - 2007-06-16 12:33 - 00577536 _____ (margo) C:\Windows\system32\fishfree.scr 2015-12-20 22:50 - 2015-12-20 22:50 - 00001511 _____ C:\Users\Invité\mbam - Raccourci.lnk 2015-12-18 21:52 - 2015-12-18 21:52 - 00014371 _____ C:\Users\Invité\Downloads\Powers Reminder Template.xlsx 2015-12-18 21:49 - 2015-12-18 21:49 - 00056832 _____ C:\Users\Invité\Downloads\Crafting.xls 2015-12-18 15:56 - 2015-12-18 15:56 - 00065024 _____ C:\Users\Invité\Downloads\Archiviste 2015 2015-12-16 14:19 - 2015-12-16 14:19 - 01737313 _____ C:\Users\Invité\Downloads\plan_hupc_plan général sitecochin_siteproyal.pdf 2015-12-15 13:15 - 2015-12-25 09:17 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-12-15 13:14 - 2015-12-20 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-12-15 13:14 - 2015-12-15 13:14 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware 2015-12-15 13:14 - 2015-10-05 09:50 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-12-15 13:14 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-12-15 13:14 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2015-12-11 00:24 - 2015-12-11 00:24 - 00000515 _____ C:\Users\Invité\Documents\corrupotion des politiques- pays arabes.txt 2015-12-10 22:17 - 2015-12-10 22:18 - 00000000 ____D C:\Users\Invité\Desktop\vidéos immigrés foldingues 2015-12-10 12:55 - 2015-12-10 14:08 - 00000835 _____ C:\Users\Invité\Documents\vote fn féminin.txt 2015-12-10 12:43 - 2015-12-10 12:43 - 00000987 _____ C:\Users\Invité\Documents\archanges.txt 2015-12-09 23:08 - 2015-11-11 19:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-12-09 23:08 - 2015-11-11 19:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2015-12-09 23:08 - 2015-11-10 19:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-12-09 23:08 - 2015-11-10 19:39 - 00909824 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-12-09 23:08 - 2015-11-10 19:39 - 00811520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2015-12-09 23:08 - 2015-11-10 18:40 - 02386944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-12-09 23:07 - 2015-11-11 21:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-12-09 23:07 - 2015-11-11 17:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-12-09 23:07 - 2015-11-11 16:44 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-12-09 23:07 - 2015-11-11 16:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-12-09 23:07 - 2015-11-11 16:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-12-09 23:07 - 2015-11-11 15:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-12-09 23:07 - 2015-11-10 01:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-12-09 23:07 - 2015-11-10 01:24 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-12-09 23:07 - 2015-11-10 01:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-12-09 23:07 - 2015-11-10 01:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-12-09 23:07 - 2015-11-10 01:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-12-09 23:07 - 2015-11-10 01:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-12-09 23:07 - 2015-11-10 01:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-12-09 23:07 - 2015-11-10 01:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-12-09 23:07 - 2015-11-10 01:06 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-12-09 23:07 - 2015-11-10 01:06 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-12-09 23:07 - 2015-11-10 01:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-12-09 23:07 - 2015-11-10 01:03 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-12-09 23:07 - 2015-11-10 01:03 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-12-09 23:07 - 2015-11-10 01:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-12-09 23:07 - 2015-11-10 01:02 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-12-09 23:07 - 2015-11-10 00:57 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-12-09 23:07 - 2015-11-10 00:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-12-09 23:07 - 2015-11-10 00:47 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-12-09 23:07 - 2015-11-10 00:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-12-09 23:07 - 2015-11-10 00:44 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2015-12-09 23:07 - 2015-11-10 00:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-12-09 23:07 - 2015-11-10 00:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-12-09 23:07 - 2015-11-10 00:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-12-09 23:07 - 2015-11-10 00:36 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-12-09 23:07 - 2015-11-10 00:35 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-12-09 23:07 - 2015-11-10 00:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-12-09 23:07 - 2015-11-10 00:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-12-09 23:07 - 2015-11-10 00:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-12-09 23:06 - 2015-11-20 19:34 - 02956800 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-12-09 23:06 - 2015-11-20 19:34 - 02062848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-12-09 23:06 - 2015-11-20 19:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-12-09 23:06 - 2015-11-20 19:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-12-09 23:06 - 2015-11-20 19:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-12-09 23:06 - 2015-11-20 19:34 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-12-09 23:06 - 2015-11-20 19:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-12-09 23:06 - 2015-11-20 19:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-12-09 23:06 - 2015-11-20 19:33 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-12-09 23:06 - 2015-11-20 19:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-12-09 23:06 - 2015-11-20 19:33 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-12-09 23:06 - 2015-11-05 20:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2015-12-09 23:06 - 2015-11-03 19:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\els.dll 2015-12-09 23:06 - 2015-10-09 00:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll 2015-12-09 23:06 - 2015-10-09 00:13 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll 2015-12-09 23:06 - 2015-10-09 00:13 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL 2015-12-09 23:06 - 2015-10-09 00:13 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL 2015-12-09 23:06 - 2015-10-08 20:13 - 00419928 _____ C:\Windows\system32\locale.nls 2015-12-09 23:05 - 2015-11-05 20:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll 2015-12-09 23:05 - 2015-11-05 10:48 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-12-09 23:05 - 2015-11-03 19:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2015-12-07 15:30 - 2015-12-07 15:30 - 00120675 _____ C:\Users\Invité\Downloads\Offre CDD KM 6 mois_11 2015.pdf 2015-12-07 15:18 - 2015-12-07 15:18 - 00057292 _____ C:\Users\Invité\Downloads\2014charge.etudes.service.enquetes.sondages.fr.pdf 2015-12-05 13:49 - 2015-12-06 09:19 - 00000000 ____D C:\Program Files\Mozilla Thunderbird 2015-12-03 22:54 - 2015-12-03 22:54 - 00206370 _____ C:\Users\Invité\Downloads\ETRU_189_0057.pdf 2015-12-03 21:37 - 2015-12-03 21:37 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12e0a5fe01f96.job 2015-12-02 13:07 - 2015-12-02 13:08 - 00009052 _____ C:\Users\Invité\Documents\Quêtes tavernes et généraux.txt 2015-12-01 15:22 - 2015-12-01 15:24 - 00000000 ____D C:\Users\Invité\Documents\Feng Shui 2015-11-30 21:15 - 2015-11-30 21:15 - 02166179 _____ C:\Users\Invité\Documents\Rolling-spider_User-guide_FR.pdf 2015-11-30 21:12 - 2015-11-30 21:12 - 02187732 _____ C:\Users\Invité\Downloads\Rolling-spider_User-guide_FR.pdf 2015-11-23 14:51 - 2015-11-23 14:51 - 00081577 _____ C:\Users\Invité\Downloads\Mobile_Bouyguestelecom_Facture_Novembre2015.pdf 2015-11-16 23:17 - 2015-11-16 23:17 - 00001002 _____ C:\Users\Invité\Documents\pkoi allah est un démon.txt 2015-11-13 21:01 - 2015-11-13 21:02 - 02993208 _____ (Blizzard Entertainment) C:\Users\Invité\Desktop\World-of-Warcraft-Setup.exe 2015-11-13 01:03 - 2015-11-13 01:03 - 00040822 _____ C:\Users\Invité\Downloads\SC26 - P Molinie - Sagesse Chretienne 26.pdf 2015-11-11 03:04 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-11-11 03:04 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-11-11 03:04 - 2015-10-29 18:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-11-11 03:04 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-11-11 03:04 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-11-11 03:04 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-11-11 03:04 - 2015-10-20 01:52 - 00138176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-11-11 03:04 - 2015-10-20 01:52 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-11-11 03:04 - 2015-10-20 01:48 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-11-11 03:04 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-11-11 03:04 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-11-11 03:04 - 2015-10-20 01:45 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-11-11 03:04 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-11-11 03:04 - 2015-10-20 01:44 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-11-11 03:04 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-11-11 03:04 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-11-11 03:04 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-11-11 03:04 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-11-11 03:04 - 2015-10-20 00:29 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-11-11 03:04 - 2015-10-20 00:28 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-11-11 03:04 - 2015-10-20 00:28 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-11-11 03:04 - 2015-10-13 17:31 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2015-11-11 03:04 - 2015-10-13 17:31 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-11-11 03:04 - 2015-10-13 05:50 - 00712640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-11-11 03:03 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2015-11-11 03:03 - 2015-10-01 18:50 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2015-11-11 03:03 - 2015-09-23 14:09 - 00371920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-11-11 03:03 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2015-11-10 06:54 - 2015-11-10 06:54 - 00381346 _____ C:\Users\Invité\Documents\bon échange senséo.pdf 2015-10-30 23:23 - 2015-10-30 23:23 - 00170861 _____ C:\Users\Invité\Downloads\Recherche-militaires-archives_nationales-SHD.pdf 2015-10-29 23:10 - 2015-10-29 23:10 - 05485850 _____ C:\Users\Invité\Documents\Journal-indélicat-Enregistré-automatiquement_Joseph Scillipitti.pdf 2015-10-28 13:58 - 2015-10-28 14:13 - 00002237 _____ C:\Users\Invité\Documents\contentieux collant 1 euros.txt 2015-10-27 13:58 - 2015-10-27 13:58 - 00190160 _____ C:\Users\Invité\Downloads\attestation (2).pdf 2015-10-20 22:22 - 2015-10-20 22:22 - 00000770 _____ C:\Users\Invité\Documents\abus de droit.txt 2015-10-20 21:45 - 2015-10-20 21:46 - 00001583 _____ C:\Users\Invité\Documents\malédiction de Saint Jacques sur injustice et richesses injustement acquises.txt 2015-10-17 21:45 - 2015-10-17 21:51 - 00183880 _____ C:\Windows\ntbtlog.txt 2015-10-17 21:22 - 2015-10-17 21:22 - 00001033 _____ C:\Users\Invité\Downloads\La Peau des Rêves, Tome 1 à 4.torrent 2015-10-15 00:33 - 2015-09-18 18:47 - 00023384 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2015-10-15 00:33 - 2015-09-18 18:44 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-10-15 00:33 - 2015-09-18 18:44 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-10-15 00:33 - 2015-09-18 18:44 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-10-15 00:33 - 2015-09-18 18:44 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-10-15 00:33 - 2015-09-18 18:44 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-10-15 00:33 - 2015-09-18 18:35 - 00999936 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-10-13 20:03 - 2015-08-06 18:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-10-13 20:03 - 2015-08-06 18:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2015-10-13 20:03 - 2015-07-18 14:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2015-10-13 20:02 - 2015-10-01 18:50 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2015-10-13 20:02 - 2015-10-01 18:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2015-10-13 20:02 - 2015-10-01 18:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2015-10-13 20:02 - 2015-10-01 18:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2015-10-13 20:02 - 2015-10-01 18:50 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2015-10-13 20:02 - 2015-10-01 17:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2015-10-13 01:29 - 2015-10-13 01:29 - 00875720 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll 2015-10-07 22:11 - 2015-10-07 22:11 - 00000505 _____ C:\Users\Invité\Documents\fissure anale et repose pieds.txt 2015-10-07 21:47 - 2015-10-07 21:47 - 00302011 _____ C:\Users\Invité\Downloads\WindowsUpdateDiagnostic.diagcab 2015-10-06 06:03 - 2015-10-06 06:03 - 00056166 _____ C:\Users\Invité\Downloads\vousreprenezuneactivite65156.pdf ==================== Trois mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2015-12-25 11:57 - 2009-07-14 03:37 - 00000000 ____D C:\Windows 2015-12-25 11:38 - 2014-02-16 13:15 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-12-25 11:36 - 2014-01-28 12:32 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-12-25 10:44 - 2014-02-11 23:20 - 01668256 _____ C:\Windows\system32\PerfStringBackup.INI 2015-12-25 10:44 - 2009-07-14 09:39 - 00747570 _____ C:\Windows\system32\perfh00C.dat 2015-12-25 10:44 - 2009-07-14 09:39 - 00150062 _____ C:\Windows\system32\perfc00C.dat 2015-12-25 10:44 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\inf 2015-12-25 10:42 - 2014-01-28 12:32 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-12-25 09:21 - 2014-02-12 14:04 - 00027934 _____ C:\ProgramData\nvModes.001 2015-12-25 09:15 - 2014-02-17 01:28 - 00000000 ____D C:\Users\Invité\AppData\Local\CrashDumps 2015-12-25 09:07 - 2015-08-03 22:59 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit 2015-12-25 02:34 - 2014-02-11 22:31 - 00018864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-12-25 02:34 - 2014-02-11 22:31 - 00018864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-12-25 02:26 - 2014-01-28 09:43 - 00000000 _____ C:\Windows\system32\LogConfigTemp.xml 2015-12-25 02:26 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-25 00:03 - 2014-02-11 22:37 - 00000000 ____D C:\Users\acer 2015-12-24 22:18 - 2014-12-03 23:54 - 00000000 ____D C:\AdwCleaner 2015-12-24 21:18 - 2014-02-09 19:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-12-21 00:22 - 2015-02-21 17:44 - 00000000 ____D C:\Program Files\Screensavers 2015-12-21 00:22 - 2014-02-12 14:00 - 00027934 _____ C:\ProgramData\nvModes.dat 2015-12-20 22:52 - 2014-02-11 22:37 - 00000000 ____D C:\Users\Invité 2015-12-18 19:24 - 2015-04-05 13:04 - 00000000 ___SD C:\Windows\system32\GWX 2015-12-17 21:22 - 2014-01-28 12:32 - 00001452 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-12-12 12:03 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2015-12-12 08:44 - 2009-07-14 05:33 - 00420680 _____ C:\Windows\system32\FNTCACHE.DAT 2015-12-12 01:50 - 2008-07-25 14:18 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-12-12 01:49 - 2014-03-09 11:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-12-12 01:49 - 2014-03-09 11:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2015-12-09 04:39 - 2014-01-28 12:57 - 00247976 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-12-08 22:38 - 2014-02-16 13:15 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-12-08 22:38 - 2014-02-16 13:15 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-12-08 20:35 - 2014-03-05 00:09 - 00000000 ____D C:\Users\Invité\AppData\Roaming\vlc 2015-12-05 20:34 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF 2015-12-03 21:37 - 2015-09-16 19:36 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f0aea6e18a19.job 2015-11-30 19:50 - 2009-07-14 05:53 - 00032482 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2015-11-25 20:24 - 2014-02-13 13:28 - 00000000 ____D C:\Users\acer\AppData\Local\ElevatedDiagnostics ==================== Fichiers à la racine de certains dossiers ======= 2015-02-23 12:35 - 2015-02-23 12:35 - 0000041 _____ () C:\Program Files\FullScreensavers.ini 2014-02-12 14:04 - 2015-12-25 09:21 - 0027934 _____ () C:\ProgramData\nvModes.001 2014-02-12 14:00 - 2015-12-21 00:22 - 0027934 _____ () C:\ProgramData\nvModes.dat Fichiers à déplacer ou supprimer: ==================== C:\Users\acer\ZHPDiag3.exe C:\Users\Invité\CopyTrans.exe Certains fichiers dans TEMP: ==================== C:\Users\acer\AppData\Local\Temp\bass.dll C:\Users\acer\AppData\Local\Temp\fishdom.exe C:\Users\acer\AppData\Local\Temp\ntdll_dump.dll C:\Users\acer\AppData\Local\Temp\Quarantine.exe C:\Users\acer\AppData\Local\Temp\RtkBtMnt.exe C:\Users\acer\AppData\Local\Temp\screensaver-aquarium.exe C:\Users\acer\AppData\Local\Temp\screensaver-tropical-aquarium.exe C:\Users\acer\AppData\Local\Temp\sqlite3.dll C:\Users\acer\AppData\Local\Temp\vcredist_x86.exe C:\Users\Invité\AppData\Local\Temp\RtkBtMnt.exe ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2015-12-20 06:38 ==================== Fin de FRST.txt ============================