Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x86) Version:18-04-2016 Exécuté par zak (administrateur) sur ZAK-PC (24-04-2016 23:34:06) Exécuté depuis C:\Users\zak\Desktop Profils chargés: zak (Profils disponibles: zak) Platform: Microsoft Windows 7 Professionnel Service Pack 1 (X86) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: "C:\Program Files\Mozilla Firefox 4.0 Beta 5\firefox.exe" -osint -url "%1") Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe () C:\ProgramData\MobileBrServ\mbbService.exe (Microsoft) C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe (Malwarebytes) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe () C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (WIBU-SYSTEMS AG) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe () C:\Program Files\RealNetworks\RealDownloader\downloader2.exe (Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe () C:\Program Files\HSPA USB Modem\HSPALauncher.exe (South Bay Software) C:\Program Files\NoAds\NoAds.exe (Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCcUxSys.exe ( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe (Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox 4.0 Beta 5\firefox.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [AVP] => C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2015-10-21] (Kaspersky Lab ZAO) HKLM\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [366904 2015-07-23] (Power Software Ltd) HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\Update\realsched.exe [296520 2015-10-22] (RealNetworks, Inc.) HKLM\...\Run: [RealDownloader] => C:\Program Files\RealNetworks\RealDownloader\downloader2.exe [560192 2014-10-29] () HKLM\...\Run: [ControlCenter4] => C:\Program Files\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.) HKLM\...\Run: [BrStsMon00] => C:\Program Files\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.) HKLM\...\Run: [QlbCtrl.exe] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] ( Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [HSPALauncher] => C:\Program Files\HSPA USB Modem\HSPALauncher.exe [233472 2012-01-09] () HKU\S-1-5-21-1689956482-851412590-4082513307-1000\...\Run: [NoAds] => C:\Program Files\NoAds\NoAds.exe [151552 2015-11-07] (South Bay Software) HKU\S-1-5-21-1689956482-851412590-4082513307-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [50670720 2016-03-01] (Skype Technologies S.A.) HKU\S-1-5-21-1689956482-851412590-4082513307-1000\...\MountPoints2: {3b4ec94e-98c8-11e5-aa52-0025b35a94fc} - G:\AutoRun.exe HKU\S-1-5-21-1689956482-851412590-4082513307-1000\...\MountPoints2: {68c1ec6c-8dc1-11e5-99f7-00247e85488d} - G:\autorun.exe HKU\S-1-5-21-1689956482-851412590-4082513307-1000\...\MountPoints2: {68c1ec76-8dc1-11e5-99f7-00247e85488d} - G:\autorun.exe HKU\S-1-5-21-1689956482-851412590-4082513307-1000\...\MountPoints2: {bb010e5d-8dbd-11e5-9c0e-00247e85488d} - G:\autorun.exe HKU\S-1-5-21-1689956482-851412590-4082513307-1000\...\MountPoints2: {bf5c6644-78a6-11e5-b6d2-00247e85488d} - G:\autorun.exe HKU\S-1-5-21-1689956482-851412590-4082513307-1000\...\MountPoints2: {bf5c664d-78a6-11e5-b6d2-00247e85488d} - G:\autorun.exe HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2015-10-25] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2015-10-22] ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.) BootExecute: autocheck autochk /r \??\G:autocheck autochk * ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{683E57DE-FBB5-4CDD-9592-6CCC0FFF272F}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{6B14DCE4-BD49-4F98-84F8-78FFF9921ED6}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{6DEA278D-F2BA-4D47-8C97-926998672195}: [DhcpNameServer] 192.168.8.1 192.168.8.1 Tcpip\..\Interfaces\{D61BF750-3C33-4DC3-ACDF-BD2213CCF4F6}: [DhcpNameServer] 192.168.8.1 192.168.8.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-26] (RealDownloader) BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2015-10-22] (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2015-10-22] (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [2015-10-22] (Kaspersky Lab ZAO) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2015-10-22] (Kaspersky Lab ZAO) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\zak\AppData\Roaming\Mozilla\Firefox\Profiles\fflprtl8.default-1451320452237 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [2015-10-17] () FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=17.0.15.10 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2015-10-22] (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-26] (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=17.0.15.10 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2015-10-22] (RealPlayer Cloud) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-29] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-29] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2015-10-23] [non signé] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2015-10-23] [non signé] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2015-10-23] [non signé] FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2015-10-23] [non signé] FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2015-10-23] [non signé] FF HKLM\...\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2015-10-22] [non signé] StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox 4.0 Beta 5\firefox.exe Chrome: ======= CHR Profile: C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (عروض Google التقديمية) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-29] CHR Extension: (محرّر مستندات Google) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-29] CHR Extension: (Google Drive) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-29] CHR Extension: (Youtube) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-29] CHR Extension: (بحث Google) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-29] CHR Extension: (Kaspersky URL Advisor) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2016-02-29] CHR Extension: (جداول بيانات Google ) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-29] CHR Extension: (مستندات Google في وضع عدم الاتصال) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15] CHR Extension: (Safe Money) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2016-02-29] CHR Extension: (Content Blocker) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2016-02-29] CHR Extension: (لوحة المفاتيح الظاهرية) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2016-02-29] CHR Extension: (Skype) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-04-21] CHR Extension: (Chrome Web Store Payments) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04] CHR Extension: (Gmail) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-29] CHR Extension: (Anti-Banner) - C:\Users\zak\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2016-02-29] CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-25] CHR HKLM\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-10-25] CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-10-25] CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2015-10-22] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08] CHR HKLM\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - hxxps://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-25] ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2015-10-21] (Kaspersky Lab ZAO) R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [Fichier non signé] R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 CodeMeter.exe; C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe [2568120 2012-07-19] (WIBU-SYSTEMS AG) S3 Lenovo EasyPlus Hotspot; C:\Program Files\Common Files\LENOVO\easyplussdk\bin\EPHotspot.exe [509424 2015-06-08] (Lenovo) R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [242256 2014-08-20] () R2 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [41760 2015-10-13] (Microsoft) R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] () R2 RealPlayer Cloud Service; C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [1141848 2015-10-22] (RealNetworks, Inc.) R2 RealPlayerUpdateSvc; C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] () R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 cmusbser; C:\Windows\System32\DRIVERS\cmusbser.sys [103552 2008-08-29] (Mobile Connector) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2015-10-23] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [597600 2015-10-23] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2015-10-23] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25696 2015-10-23] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2015-10-23] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [44000 2015-10-23] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [145224 2015-10-23] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [24448 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2016-04-24] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [53120 2016-03-10] (Malwarebytes Corporation) R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [114304 2015-07-23] (Power Software Ltd) S3 Ser2plx86; C:\Windows\System32\DRIVERS\ser2pl.sys [75776 2007-02-12] (Prolific Technology Inc.) S3 umpusbxp; C:\Windows\System32\DRIVERS\umpusbxp.sys [75584 2004-07-20] (Texas Instruments) [Fichier non signé] S3 catchme; \??\C:\Users\zak\AppData\Local\Temp\catchme.sys [X] U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2015-10-23] (Kaspersky Lab ZAO) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-04-24 23:34 - 2016-04-24 23:35 - 00020467 _____ C:\Users\zak\Desktop\FRST.txt 2016-04-24 23:33 - 2016-04-24 23:34 - 00000000 ____D C:\FRST 2016-04-24 22:56 - 2016-04-24 22:57 - 01726464 _____ (Farbar) C:\Users\zak\Desktop\FRST.exe 2016-04-24 20:30 - 2016-04-24 20:31 - 00865272 _____ (Panda Security ) C:\Users\zak\Downloads\usbvaccine.exe 2016-04-24 20:04 - 2016-04-24 20:29 - 00000000 ____D C:\Rem-VBSqt 2016-04-24 19:01 - 2016-04-24 19:01 - 00000000 ____H C:\ProgramData\cm-lock 2016-04-24 18:56 - 2016-04-24 18:56 - 00110592 _____ (bartblaze) C:\Users\zak\Desktop\Rem-VBSworm(1).exe 2016-04-24 18:55 - 2016-04-24 18:55 - 00110592 _____ (bartblaze) C:\Users\zak\Downloads\Rem-VBSworm.exe 2016-04-24 11:03 - 2016-04-24 11:03 - 01157552 _____ C:\Users\zak\Desktop\intr decplg.pdf 2016-04-24 10:52 - 2016-04-24 10:54 - 00205094 _____ C:\Users\zak\Downloads\TDn3.pdf.part 2016-04-24 10:51 - 2016-04-24 10:53 - 01157552 _____ C:\Users\zak\Downloads\RPNE000025C.pdf 2016-04-24 00:57 - 2016-04-24 00:57 - 00000871 _____ C:\Windows\syspropr.INI 2016-04-23 22:24 - 2016-04-23 22:39 - 00000000 ____D C:\Users\zak\Desktop\Tlemcani 2016-04-23 21:53 - 2016-04-23 21:58 - 00000000 ____D C:\UsbFix 2016-04-23 21:53 - 2016-04-23 21:53 - 00001448 _____ C:\Users\zak\Desktop\UsbFix.lnk 2016-04-23 19:02 - 2016-04-23 19:05 - 03089485 _____ (El Desaparecido - SosVirus.net - UsbFix.net) C:\Users\zak\Desktop\UsbFix_2016_8.228.exe 2016-04-23 18:27 - 2016-04-23 18:29 - 00000000 ____D C:\Users\zak\Desktop\FIG CHP3 2016-04-23 13:42 - 2016-04-24 19:02 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-04-23 13:41 - 2016-04-23 13:41 - 00001060 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-04-23 13:41 - 2016-04-23 13:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-04-23 13:41 - 2016-04-23 13:41 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-04-23 13:41 - 2016-04-23 13:41 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware 2016-04-23 13:41 - 2016-03-10 14:09 - 00053120 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-04-23 13:41 - 2016-03-10 14:08 - 00126336 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-04-23 13:41 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-04-23 12:45 - 2016-04-23 13:16 - 22851472 _____ (Malwarebytes ) C:\Users\zak\Downloads\mbam-setup-2.2.1.1043.exe 2016-04-23 12:35 - 2016-04-23 12:37 - 00018589 _____ C:\Users\zak\Downloads\V1I5_IJERTV1IS5447.pdf.part 2016-04-23 11:15 - 2016-04-23 11:15 - 00115133 _____ C:\Users\zak\Downloads\ijpcsc2012-2.pdf 2016-04-23 10:55 - 2016-04-23 10:56 - 00635308 _____ C:\Users\zak\Downloads\OR1236.pdf 2016-04-23 10:55 - 2016-04-23 10:56 - 00275279 _____ C:\Users\zak\Downloads\10.1.1.463.8318.pdf.part 2016-04-23 10:55 - 2016-04-23 10:56 - 00269083 _____ C:\Users\zak\Downloads\ijicic-12-07018.pdf 2016-04-23 10:54 - 2016-04-23 10:54 - 00461192 _____ C:\Users\zak\Desktop\4_1_7.pdf 2016-04-23 10:37 - 2016-04-23 10:41 - 02690382 _____ C:\Users\zak\Downloads\Modeling and current control strategy for a medium-voltage cascad.pdf 2016-04-23 10:37 - 2016-04-23 10:39 - 00837675 _____ C:\Users\zak\Downloads\20130603035710936.pdf 2016-04-23 10:37 - 2016-04-23 10:38 - 00461192 _____ C:\Users\zak\Downloads\4_1_7.pdf 2016-04-23 09:39 - 2016-04-23 09:40 - 01540623 _____ C:\Users\zak\Downloads\IC177.pdf 2016-04-23 09:38 - 2016-04-23 09:41 - 01074453 _____ C:\Users\zak\Downloads\JDCTA1699PPL.pdf 2016-04-23 09:38 - 2016-04-23 09:38 - 00300373 _____ C:\Users\zak\Desktop\P20.pdf 2016-04-23 09:37 - 2016-04-23 09:37 - 00298960 _____ C:\Users\zak\Downloads\P20.pdf 2016-04-23 09:12 - 2016-04-23 09:16 - 00949334 _____ C:\Users\zak\Downloads\1. Power Quality Improvement by using DSTATCOM.pdf 2016-04-23 09:12 - 2016-04-23 09:12 - 00362180 _____ C:\Users\zak\Downloads\Design-of-DC-Voltage-Control-for-D-STATCOM.pdf 2016-04-23 08:52 - 2016-04-23 08:54 - 00082574 _____ C:\Users\zak\Downloads\ipi70740.pdf.part 2016-04-23 08:52 - 2016-04-23 08:52 - 00375218 _____ C:\Users\zak\Downloads\4-COMPARATIVE STUDY OF DIFFERENT-1.pdf 2016-04-23 00:57 - 2016-04-23 00:58 - 00000000 ____D C:\Program Files\ZHPFix 2016-04-23 00:57 - 2016-04-23 00:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2016-04-23 00:05 - 2016-04-23 01:00 - 00000000 ____D C:\Users\zak\AppData\Roaming\ZHP 2016-04-22 15:00 - 2016-04-23 01:12 - 00054201 ____H C:\Users\zak\Desktop\~WRL0004.tmp 2016-04-22 02:01 - 2016-04-22 02:01 - 00000000 ____D C:\Program Files\ESET 2016-04-21 23:44 - 2016-04-21 23:44 - 00111020 _____ C:\Users\zak\Downloads\convocation(2).pdf 2016-04-21 23:13 - 2016-04-21 23:13 - 00111020 _____ C:\Users\zak\Downloads\convocation.pdf 2016-04-21 23:11 - 2016-04-21 23:12 - 00009795 _____ C:\Users\zak\Downloads\convocation(1).pdf 2016-04-20 12:24 - 2016-04-20 12:25 - 00878626 _____ C:\Users\zak\Downloads\الوثيقة المرافقة لمنهاج مادة التربية العلمية والتكنولوجية.pdf 2016-04-18 19:10 - 2012-04-16 22:53 - 02333719 _____ C:\Users\zak\Desktop\gholipour_2003.pdf 2016-04-18 18:47 - 2013-06-05 18:11 - 07624815 _____ C:\Users\zak\Desktop\leredde.pdf 2016-04-18 18:38 - 2013-05-08 11:50 - 01293832 _____ C:\Users\zak\Desktop\2_Kiran_KP_570_Research_Article_EEC_May_2012.pdf 2016-04-18 18:13 - 2013-05-17 15:13 - 01344336 _____ C:\Users\zak\Desktop\g .pdf 2016-04-18 18:08 - 2014-06-28 23:12 - 00240838 _____ C:\Users\zak\Desktop\Decoupling Control Strategy of D-STATCOM.pdf 2016-04-18 12:26 - 2013-04-03 22:31 - 00922909 _____ C:\Users\zak\Desktop\aece_2012_1_13.pdf 2016-04-18 12:23 - 2011-05-28 18:44 - 01390267 _____ C:\Users\zak\Desktop\24.pdf 2016-04-18 11:54 - 2010-02-08 19:26 - 09752748 _____ C:\Users\zak\Desktop\Saeedifard_Maryam_200811_PhD_thesis.pdf 2016-04-18 11:53 - 2012-12-26 22:46 - 00457312 _____ C:\Users\zak\Desktop\pxc3877206.pdf 2016-04-18 11:51 - 2012-10-02 19:17 - 00955542 _____ C:\Users\zak\Desktop\imp svm.pdf 2016-04-18 11:46 - 2012-12-26 22:48 - 00504720 _____ C:\Users\zak\Desktop\06.pdf 2016-04-18 11:30 - 2013-12-04 15:53 - 00544574 _____ C:\Users\zak\Desktop\Modeling and Simulation of DSTATCOM Using Space Vector Pulse Width Modulation for Load Variation.pdf 2016-04-17 12:06 - 2016-04-17 12:06 - 27215171 _____ C:\Users\zak\Desktop\PETITCLAIR_Patrice_1997_opt(1).pdf 2016-04-17 11:53 - 2016-04-17 11:55 - 00581407 _____ C:\Users\zak\Downloads\10.1.1.397.5560.pdf.part 2016-04-17 11:42 - 2016-04-19 18:27 - 00040490 ____H C:\Users\zak\Desktop\~WRL0518.tmp 2016-04-17 11:42 - 2016-04-19 00:49 - 00040333 ____H C:\Users\zak\Desktop\~WRL0003.tmp 2016-04-17 11:38 - 2016-04-17 11:39 - 00654033 _____ C:\Users\zak\Downloads\Art17-1_13.pdf 2016-04-17 10:21 - 2016-04-17 10:21 - 00222886 _____ C:\Users\zak\Downloads\paper_2_ 53_332(2).pdf 2016-04-17 09:51 - 2016-04-17 10:07 - 27531804 _____ C:\Users\zak\Downloads\PETITCLAIR_Patrice_1997_opt(1).pdf 2016-04-16 18:32 - 2016-04-21 00:42 - 00000000 ____D C:\Users\zak\Desktop\CHP3 2016-04-15 23:17 - 2016-03-31 20:41 - 00346320 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-04-15 23:17 - 2016-03-31 02:03 - 20352512 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-04-15 23:17 - 2016-03-31 02:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-04-15 23:17 - 2016-03-31 02:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-04-15 23:17 - 2016-03-31 01:53 - 00496640 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-04-15 23:17 - 2016-03-31 01:52 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-04-15 23:17 - 2016-03-31 01:52 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-04-15 23:17 - 2016-03-31 01:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-04-15 23:17 - 2016-03-31 01:52 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-04-15 23:17 - 2016-03-31 01:51 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-04-15 23:17 - 2016-03-31 01:48 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-04-15 23:17 - 2016-03-31 01:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-04-15 23:17 - 2016-03-31 01:46 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-04-15 23:17 - 2016-03-31 01:45 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-04-15 23:17 - 2016-03-31 01:45 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-04-15 23:17 - 2016-03-31 01:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-04-15 23:17 - 2016-03-31 01:45 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-04-15 23:17 - 2016-03-31 01:41 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-04-15 23:17 - 2016-03-31 01:38 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-04-15 23:17 - 2016-03-31 01:34 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-04-15 23:17 - 2016-03-31 01:33 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2016-04-15 23:17 - 2016-03-31 01:31 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-04-15 23:17 - 2016-03-31 01:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-04-15 23:17 - 2016-03-31 01:30 - 04611072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-04-15 23:17 - 2016-03-31 01:30 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-04-15 23:17 - 2016-03-31 01:29 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-04-15 23:17 - 2016-03-31 01:24 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-04-15 23:17 - 2016-03-31 01:23 - 02056192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-04-15 23:17 - 2016-03-31 01:23 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-04-15 23:17 - 2016-03-31 01:23 - 00689664 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-04-15 23:17 - 2016-03-31 01:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-04-15 23:17 - 2016-03-31 01:21 - 13811712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-04-15 23:17 - 2016-03-31 01:05 - 02121216 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-04-15 23:17 - 2016-03-31 01:02 - 01311744 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-04-15 23:17 - 2016-03-31 01:00 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-04-15 21:53 - 2016-03-11 20:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2016-04-15 21:51 - 2016-03-16 20:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll 2016-04-15 21:51 - 2016-03-16 20:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-04-15 21:51 - 2016-02-02 20:48 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2016-04-15 21:50 - 2016-03-18 00:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2016-04-15 21:50 - 2016-03-18 00:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-04-15 21:50 - 2016-03-18 00:36 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-04-15 21:50 - 2016-03-18 00:36 - 00067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-04-15 21:50 - 2016-03-18 00:33 - 01310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-04-15 21:50 - 2016-03-18 00:30 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-04-15 21:50 - 2016-03-18 00:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-04-15 21:50 - 2016-03-18 00:30 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-04-15 21:50 - 2016-03-18 00:30 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-04-15 21:50 - 2016-03-18 00:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-04-15 21:50 - 2016-03-18 00:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-04-15 21:50 - 2016-03-18 00:29 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-04-15 21:50 - 2016-03-18 00:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-04-15 21:50 - 2016-03-18 00:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2016-04-15 21:50 - 2016-03-18 00:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2016-04-15 21:50 - 2016-03-18 00:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-04-15 21:50 - 2016-03-18 00:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2016-04-15 21:50 - 2016-03-18 00:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-04-15 21:50 - 2016-03-18 00:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-04-15 21:50 - 2016-03-18 00:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-04-15 21:50 - 2016-03-18 00:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-04-15 21:50 - 2016-03-18 00:26 - 01062400 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-04-15 21:50 - 2016-03-18 00:26 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-04-15 21:50 - 2016-03-18 00:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-04-15 21:50 - 2016-03-18 00:26 - 00294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-04-15 21:50 - 2016-03-18 00:25 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-04-15 21:50 - 2016-03-18 00:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-04-15 21:50 - 2016-03-18 00:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-04-15 21:50 - 2016-03-17 23:42 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2016-04-15 21:50 - 2016-03-17 23:42 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2016-04-15 21:50 - 2016-03-17 23:42 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2016-04-15 21:50 - 2016-03-17 23:42 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2016-04-15 21:50 - 2016-03-17 23:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-04-15 21:50 - 2016-03-17 23:36 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-04-15 21:50 - 2016-03-17 23:35 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-04-15 21:50 - 2016-03-17 23:30 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-04-15 21:50 - 2016-03-17 23:30 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-04-15 21:50 - 2016-03-17 23:30 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-04-15 21:50 - 2016-03-17 23:29 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-04-15 21:50 - 2016-03-17 23:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-04-15 21:50 - 2016-03-17 23:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-04-15 21:50 - 2016-03-17 23:29 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-04-15 21:50 - 2016-03-17 23:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-04-15 21:50 - 2016-03-17 23:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-04-15 21:50 - 2016-03-17 23:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-04-15 21:50 - 2016-03-17 23:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-04-15 21:47 - 2016-03-16 01:53 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2016-04-15 21:47 - 2016-03-16 01:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2016-04-15 21:41 - 2016-01-21 02:51 - 00057280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2016-04-15 21:36 - 2016-04-04 19:54 - 00034024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-04-15 21:36 - 2016-04-04 19:42 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-04-15 21:36 - 2016-04-02 15:07 - 01218048 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-04-15 21:36 - 2016-03-23 16:02 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2016-04-15 21:36 - 2016-03-17 20:04 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-04-15 21:36 - 2016-03-17 20:04 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-04-15 21:36 - 2016-03-17 20:04 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-04-15 21:36 - 2016-03-17 20:04 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-04-15 21:26 - 2016-03-29 19:35 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-04-15 21:24 - 2016-03-06 20:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2016-04-15 21:24 - 2016-03-06 20:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2016-04-15 21:22 - 2016-02-05 20:44 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll 2016-04-15 21:22 - 2016-02-05 19:33 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll 2016-04-15 21:22 - 2015-06-03 22:22 - 00355456 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll 2016-04-10 23:21 - 2016-04-10 23:21 - 01509888 _____ C:\Users\zak\Documents\Rescue.asd 2016-04-10 19:04 - 2016-04-10 19:14 - 09357997 _____ C:\Users\zak\Downloads\تحفة الزائر في مآثر الأمير عبد القادر وأخبار الجزائر.pdf 2016-04-10 18:47 - 2016-04-10 18:58 - 11339652 _____ C:\Users\zak\Downloads\عقد الاجياد في الصافنات الجياد، الأمير عبد القادر الجزائري .pdf 2016-04-10 18:33 - 2016-04-10 18:37 - 02633026 _____ C:\Users\zak\Downloads\61.pdf 2016-04-10 18:06 - 2016-04-10 18:28 - 10339336 _____ C:\Users\zak\Downloads\حياة الأمير عبدالقادر.pdf 2016-04-09 15:46 - 2016-04-09 15:46 - 00000000 ____D C:\Users\zak\Tracing 2016-04-09 11:53 - 2016-04-24 23:33 - 00000000 ____D C:\Users\zak\AppData\Roaming\Skype 2016-04-09 11:53 - 2016-04-09 11:57 - 00000000 ___RD C:\Program Files\Skype 2016-04-09 11:53 - 2016-04-09 11:53 - 00002685 _____ C:\Users\Public\Desktop\Skype.lnk 2016-04-09 11:53 - 2016-04-09 11:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-04-09 11:53 - 2016-04-09 11:53 - 00000000 ____D C:\Program Files\Common Files\Skype 2016-04-09 11:52 - 2016-04-09 11:53 - 00000000 ____D C:\ProgramData\Skype 2016-04-09 11:20 - 2016-04-09 11:21 - 01503872 _____ (Skype Technologies S.A.) C:\Users\zak\Downloads\SkypeSetup.exe 2016-04-08 22:55 - 2016-04-17 11:50 - 00335298 _____ C:\Users\zak\Downloads\tds_udm_nov2011c.pdf.part 2016-04-07 23:50 - 2016-04-07 23:57 - 00000000 ____D C:\Users\zak\Desktop\three level svm with balancing voltage 2016-04-06 23:51 - 2016-04-06 23:53 - 02690292 _____ C:\Users\zak\Downloads\كتاب الرياضيات للسنة الأولى متوسط 2004 ...2005.pdf.part 2016-04-05 23:54 - 2016-04-05 23:56 - 00541528 _____ C:\Users\zak\Downloads\15_JPE-14-01-082.pdf 2016-04-05 23:46 - 2016-04-05 23:47 - 00484453 _____ C:\Users\zak\Downloads\3.pdf 2016-04-05 23:46 - 2016-04-05 08:08 - 20021389 _____ C:\Users\zak\Downloads\11603859.pdf 2016-04-05 09:36 - 2016-04-05 09:36 - 00399522 _____ C:\Users\zak\Downloads\362.PDF 2016-04-05 08:19 - 2016-04-05 08:21 - 01236883 _____ C:\Users\zak\Downloads\Andreas Nordvall.pdf 2016-04-05 08:19 - 2016-04-05 08:20 - 01565802 _____ C:\Users\zak\Downloads\J. Basic. Appl. Sci. Res., 2(8)7632-7644, 2012.pdf 2016-04-05 08:18 - 2016-04-05 08:18 - 00534484 _____ C:\Users\zak\Downloads\ADVANCED FIVE LEVEL - FIVE PHASE CASCADED MULTILEVEL INVERTER WITH SVPWM ALGORIT_ADVANCED FIVE LEVEL - FIVE PHASE CASCADED MULTILEVEL INVERTER WITH SVPWM ALGORIT.pdf 2016-04-05 07:58 - 2016-04-05 07:59 - 01258121 _____ C:\Users\zak\Downloads\fulltext01 2016-04-04 16:08 - 2016-04-09 15:12 - 01043724 ____H C:\Users\zak\Desktop\~WRL1005.tmp 2016-04-04 16:08 - 2016-04-08 19:50 - 00988780 ____H C:\Users\zak\Desktop\~WRL3529.tmp 2016-04-03 22:04 - 2016-04-04 14:22 - 00881308 ____H C:\Users\zak\Desktop\~WRL1928.tmp 2016-04-02 21:49 - 2016-04-02 21:50 - 00363507 _____ C:\Users\zak\Downloads\N_Ould_Cherchali.pdf 2016-04-02 21:47 - 2016-04-02 21:48 - 00389282 _____ C:\Users\zak\Downloads\chibani_submissiontorst.pdf 2016-03-31 15:39 - 2016-03-31 15:40 - 01124616 _____ C:\Users\zak\Downloads\Your published paper in SIC 1-2016-F.B..pdf 2016-03-30 14:54 - 2016-03-31 23:12 - 00760129 _____ C:\Users\zak\Downloads\Moy.pdf 2016-03-30 14:45 - 2016-03-31 23:12 - 01568932 _____ C:\Users\zak\Downloads\مسابقة التعليم(1).pdf 2016-03-30 10:34 - 2016-03-30 10:35 - 01568932 _____ C:\Users\zak\Downloads\مسابقة التعليم.pdf 2016-03-30 10:19 - 2016-04-23 18:28 - 00000000 ____D C:\Users\zak\Desktop\mosabaka 2016-03-28 12:06 - 2016-03-28 12:06 - 00097502 _____ C:\Users\zak\Downloads\HandOutTrig.pdf 2016-03-27 19:30 - 2016-03-27 19:31 - 01497894 _____ C:\Users\zak\Downloads\TrigoTS.pdf 2016-03-27 15:57 - 2016-03-27 15:58 - 00065297 _____ C:\Users\zak\Downloads\TMB-CM5-fcts-circulaires.pdf 2016-03-26 19:43 - 2016-03-26 19:44 - 00000000 ____D C:\Users\zak\Downloads\lir 2016-03-26 19:20 - 2016-03-26 19:20 - 00054652 _____ C:\Users\zak\Downloads\trig.pdf 2016-03-25 08:53 - 2016-03-25 08:54 - 00002715 _____ C:\Users\zak\Downloads\inj MOUSSAOUI LEILA.pdf.part ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-04-24 22:59 - 2016-02-29 18:54 - 00000824 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-04-24 21:48 - 2015-10-17 11:18 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2016-04-24 21:14 - 2009-07-14 06:34 - 00030464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-04-24 21:14 - 2009-07-14 06:34 - 00030464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-04-24 20:07 - 2015-10-17 10:23 - 01668256 _____ C:\Windows\system32\PerfStringBackup.INI 2016-04-24 20:07 - 2009-07-14 10:39 - 00747570 _____ C:\Windows\system32\perfh00C.dat 2016-04-24 20:07 - 2009-07-14 10:39 - 00150062 _____ C:\Windows\system32\perfc00C.dat 2016-04-24 20:07 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\inf 2016-04-24 19:01 - 2016-02-29 18:54 - 00000820 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-04-24 19:01 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-04-23 13:02 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2016-04-23 07:16 - 2015-11-08 02:12 - 00000000 ____D C:\AdwCleaner 2016-04-23 01:11 - 2016-02-09 19:09 - 00000000 ____D C:\Users\zak\Desktop\ch2 2016-04-22 01:39 - 2015-10-22 23:41 - 00000000 ____D C:\Users\zak\Desktop\FRANCAIS 2016-04-22 00:23 - 2016-02-29 19:29 - 00002141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-04-22 00:23 - 2016-02-29 19:29 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-04-21 00:56 - 2015-10-17 10:15 - 00000000 ____D C:\Users\zak 2016-04-21 00:50 - 2015-10-22 12:56 - 00000000 ____D C:\ProgramData\Real 2016-04-21 00:50 - 2009-07-14 11:00 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-04-21 00:50 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2016-04-16 20:46 - 2009-07-14 06:33 - 00436456 _____ C:\Windows\system32\FNTCACHE.DAT 2016-04-16 19:31 - 2016-01-06 09:37 - 00000000 ____D C:\Users\zak\Desktop\TRAVEL1 2016-04-16 19:25 - 2015-10-23 08:13 - 00000000 ____D C:\Users\zak\Desktop\these 2016-04-16 18:26 - 2016-02-08 16:29 - 00000000 ____D C:\Users\zak\Desktop\TH 2016-04-16 18:25 - 2016-02-19 17:30 - 00000000 ____D C:\Users\zak\Desktop\comparaison 3 and 5 2016-04-16 11:59 - 2015-10-22 10:19 - 00000000 ____D C:\Windows\system32\appraiser 2016-04-16 03:42 - 2015-11-02 00:03 - 00000000 ____D C:\Windows\system32\MRT 2016-04-16 03:20 - 2015-11-02 00:02 - 132539272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-04-13 13:40 - 2016-03-20 01:32 - 00000000 ____D C:\Program Files\Mozilla Firefox 4.0 Beta 5 2016-04-13 13:40 - 2015-10-31 14:04 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2016-04-06 10:18 - 2015-10-21 22:51 - 00374944 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-04-03 21:50 - 2015-10-22 12:39 - 00000000 ____D C:\Users\zak\AppData\Roaming\vlc 2016-03-25 02:10 - 2015-11-01 23:38 - 00000000 ___SD C:\Windows\system32\GWX ==================== Fichiers à la racine de certains dossiers ======= 2015-11-02 00:40 - 2015-11-02 00:40 - 0000000 _____ () C:\Users\zak\AppData\Local\AtStart.txt 2015-11-02 00:40 - 2015-11-02 00:40 - 0000000 _____ () C:\Users\zak\AppData\Local\DSwitch.txt 2015-10-18 02:45 - 2015-10-18 02:46 - 0045077 _____ () C:\Users\zak\AppData\Local\FASTWiz.log 2015-11-02 00:40 - 2015-11-02 00:40 - 0000000 _____ () C:\Users\zak\AppData\Local\QSwitch.txt 2016-04-24 19:01 - 2016-04-24 19:01 - 0000000 ____H () C:\ProgramData\cm-lock ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2016-04-23 12:53 ==================== Fin de FRST.txt ============================