Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 05-03-2017 Exécuté par Patrick (administrateur) sur PATRICK (07-03-2017 15:45:54) Exécuté depuis C:\Users\Patrick\Desktop Profils chargés: Patrick (Profils disponibles: Patrick & VERONIK & Invité) Platform: Windows 10 Home Version 1607 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Edge) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (© 2015 Microsoft Corporation) C:\Users\Patrick\AppData\Local\Microsoft\BingSvc\BingSvc.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam7\YouCamService7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation) C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileCoAuth.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.693_none_42ff55c9655f38bf\TiWorker.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSYNC.EXE (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe ==================== Registre (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8496344 2015-11-23] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-11-23] (Realtek Semiconductor) HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [274200 2016-07-14] (CyberLink Corp.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [909744 2017-03-03] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation) HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318248 2016-01-08] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [509192 2014-12-01] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [61896 2016-12-29] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [YouCam Service7] => C:\Program Files (x86)\CyberLink\YouCam7\YouCamService7.exe [466712 2016-07-04] (CyberLink Corp.) HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [Le Cloud d'Orange - Transfert de fichiers Client] => C:\Users\Patrick\AppData\Local\Le Cloud Orange\omclient.exe [1178112 2014-03-27] (Orange-France) HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1572648 2016-01-08] (Samsung) HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [KiesPDLR.exe] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1021736 2016-01-08] (Samsung) HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [Orange mes contenus] => C:\Program Files\Orange\Orange mes contenus\OrangeSC.exe [12995408 2012-07-18] (F-Secure) HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [BingSvc] => C:\Users\Patrick\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-22] (© 2015 Microsoft Corporation) HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29642368 2016-09-12] (Skype Technologies S.A.) HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9363672 2017-02-08] (Piriform Ltd) HKU\S-1-5-21-3311965274-403475795-341010734-1001\...\MountPoints2: {788f2c87-f9d9-11e3-825e-b8ee652537d4} - "F:\LaunchU3.exe" -a HKU\S-1-5-21-3311965274-403475795-341010734-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [572416 2016-07-16] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll [2017-02-28] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll [2017-02-28] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll [2017-02-28] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileSyncShell.dll [2017-02-28] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileSyncShell.dll [2017-02-28] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Patrick\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\FileSyncShell.dll [2017-02-28] (Microsoft Corporation) ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{13d3b3b4-32e4-44d8-b91d-2260d48c1030}: [DhcpNameServer] 192.168.40.4 Tcpip\..\Interfaces\{1ba87505-f6de-4514-9ee0-f003fcb2ac81}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{2d93315f-35aa-42b5-abcf-36c189117fae}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{7c643847-8226-471e-a585-f07aef0b04dd}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM14/9 HKU\S-1-5-21-3311965274-403475795-341010734-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/ HKU\S-1-5-21-3311965274-403475795-341010734-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM14/9 HKU\S-1-5-21-3311965274-403475795-341010734-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.msn.com/?pc=SL5M&ocid=SL5MDHP&osmkt=fr-fr SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {8E9AEB09-3658-4FA2-B85B-40B932D0F5B3} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {8E9AEB09-3658-4FA2-B85B-40B932D0F5B3} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKU\S-1-5-21-3311965274-403475795-341010734-1001 -> {8E9AEB09-3658-4FA2-B85B-40B932D0F5B3} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-21-3311965274-403475795-341010734-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-01-29] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-01-29] (Microsoft Corporation) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-12-06] (HP Inc.) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-12-06] (HP Inc.) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default [2017-03-07] FF user.js: detected! => C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\user.js [2014-07-26] FF Extension: (Avira Browser Safety) - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\i7wi9c2o.default\Extensions\abs@avira.com [2016-10-04] FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] [non signé] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-21] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-21] () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-01-29] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-14] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-01-14] (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3311965274-403475795-341010734-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Patrick\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2016-09-08] (Zoom Video Communications, Inc.) Chrome: ======= CHR Profile: C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default [2017-02-25] CHR Extension: (Google Slides) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-23] CHR Extension: (Docs) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-23] CHR Extension: (Google Drive) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-23] CHR Extension: (YouTube) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-23] CHR Extension: (Google Sheets) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-23] CHR Extension: (Protection Web Avira) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2017-02-23] CHR Extension: (Google Docs hors connexion) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-23] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-23] CHR Extension: (Gmail) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-23] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1115552 2017-03-03] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [487424 2017-03-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [487424 2017-03-03] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1519144 2017-03-03] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-08-07] (Windows (R) Win 7 DDK provider) [Fichier non signé] R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272 2016-12-29] (Avira Operations GmbH & Co. KG) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3704520 2017-02-18] (Microsoft Corporation) R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-09-05] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-09-05] (CyberLink) S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.) R2 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [573704 2014-12-01] (Hewlett-Packard Development Company, L.P.) R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [Fichier non signé] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [294616 2015-11-23] (Realtek Semiconductor) R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [260704 2016-09-02] (Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 athr; C:\WINDOWS\System32\drivers\athwbx.sys [3858944 2013-10-17] (Qualcomm Atheros Communications, Inc.) R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [161824 2017-03-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [163976 2017-03-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-03-03] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-03-03] (Avira Operations GmbH & Co. KG) R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) R3 clwvd7; C:\WINDOWS\system32\DRIVERS\clwvd7.sys [49944 2016-06-02] (CyberLink Corporation) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-09-20] (Synaptics Incorporated) R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [52904 2016-04-27] (Synaptics Incorporated) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [87568 2013-07-01] (Intel Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R3 WirelessButtonDriver; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (HP Inc.) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-03-07 15:45 - 2017-03-07 15:47 - 00023829 _____ C:\Users\Patrick\Desktop\FRST.txt 2017-03-07 15:45 - 2017-03-07 15:45 - 00000000 ____D C:\FRST 2017-03-07 15:43 - 2017-03-07 15:45 - 02423808 _____ (Farbar) C:\Users\Patrick\Desktop\FRST64.exe 2017-03-07 09:19 - 2017-03-07 09:19 - 00000738 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assistant Mise à niveau de Windows 10.lnk 2017-03-07 09:19 - 2017-03-07 09:19 - 00000726 _____ C:\Users\Patrick\Desktop\Assistant Mise à niveau de Windows 10.lnk 2017-03-07 09:19 - 2017-03-07 09:19 - 00000000 ____D C:\Windows10Upgrade 2017-03-05 16:43 - 2017-03-05 16:43 - 00000000 ___HD C:\$SysReset 2017-03-02 15:59 - 2017-03-02 15:59 - 00003762 _____ C:\WINDOWS\System32\Tasks\HP AR Program Upload - 4ba89dd2808145be9d415a1b82b2d4c59d7a2adb9e264a46961bacc5917ba472 2017-02-28 09:08 - 2017-02-28 09:08 - 00001286 _____ C:\Users\Patrick\Desktop\Stellar Phoenix Windows Data Recovery - Home.lnk 2017-02-28 09:08 - 2017-02-28 09:08 - 00000081 _____ C:\WINDOWS\spwdrhfa.INI 2017-02-28 09:08 - 2017-02-28 09:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellar Phoenix Windows Data Recovery - Home 2017-02-28 09:08 - 2017-02-28 09:08 - 00000000 ____D C:\Program Files (x86)\Stellar Phoenix Windows Data Recovery 2017-02-28 09:08 - 2017-02-28 09:08 - 00000000 ____D C:\Log 2017-02-27 19:59 - 2017-02-27 20:09 - 00001297 _____ C:\Users\Public\Desktop\Wondershare Data Recovery.lnk 2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\Users\Patrick\AppData\Local\Wondershare 2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\ProgramData\Wondershare 2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare 2017-02-27 19:59 - 2017-02-27 19:59 - 00000000 ____D C:\Program Files (x86)\Wondershare 2017-02-27 19:58 - 2017-02-27 20:08 - 00805960 _____ C:\Users\Patrick\Downloads\data-recovery_setup_full935.exe 2017-02-27 19:58 - 2017-02-27 19:59 - 00000000 ____D C:\Users\Public\Documents\Wondershare 2017-02-27 19:39 - 2017-02-27 19:39 - 00435241 _____ C:\Users\Patrick\Downloads\releve.pdf 2017-02-27 17:53 - 2017-02-27 17:53 - 00003186 _____ C:\WINDOWS\System32\Tasks\{B90BE772-893A-4871-BAB2-FF70C4B45845} 2017-02-27 16:18 - 2017-03-07 14:15 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2017-02-27 14:14 - 2017-02-27 14:14 - 00001341 _____ C:\Users\Patrick\Desktop\COURSES MARS 2017i.lnk 2017-02-25 16:40 - 2017-02-25 16:40 - 43626400 _____ C:\Users\Patrick\Desktop\OJ4630_Basicx64_198.exe 2017-02-24 10:17 - 2017-02-24 10:38 - 00000000 ____D C:\Program Files\ReviverSoft 2017-02-23 19:06 - 2017-02-23 19:06 - 00002858 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2017-02-23 19:06 - 2017-02-23 19:06 - 00002349 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-02-23 19:06 - 2017-02-23 19:06 - 00002337 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-02-23 19:06 - 2017-02-23 19:06 - 00000870 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-02-23 19:06 - 2017-02-23 19:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-02-23 19:06 - 2017-02-23 19:06 - 00000000 ____D C:\Program Files\CCleaner 2017-02-22 19:14 - 2017-02-22 19:14 - 00002320 _____ C:\Users\Public\Desktop\HP Officejet 4630 series.lnk 2017-02-22 19:14 - 2014-07-21 16:31 - 00763912 ____N (Hewlett-Packard Development Company, LP) C:\WINDOWS\system32\HPDiscoPMC611.dll 2017-02-22 18:50 - 2017-02-22 18:51 - 10779584 _____ C:\Users\Patrick\Downloads\HPPSdr.exe 2017-02-20 23:09 - 2017-02-20 23:09 - 00110712 _____ C:\Users\Patrick\Desktop\Dépannage - Échec de l'installation HP - Réseau.hta 2017-02-20 12:34 - 2017-02-20 12:34 - 00002307 _____ C:\Users\Public\Desktop\HP Support Assistant.lnk 2017-02-20 12:30 - 2017-02-20 12:31 - 43544408 _____ (HP Inc. ) C:\Users\Patrick\Downloads\sp78153.exe 2017-02-20 10:57 - 2017-02-20 10:58 - 00000000 ____D C:\Users\Patrick\Downloads\HP Downloads 2017-02-20 09:45 - 2017-02-20 09:45 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\HPPSDr 2017-02-06 19:29 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2017-02-06 19:29 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-03-07 15:37 - 2016-10-02 10:46 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-03-07 15:05 - 2014-08-08 17:10 - 00000000 ____D C:\Users\Patrick\Documents\Fichiers Outlook 2017-03-07 14:48 - 2016-10-02 10:57 - 00000000 ____D C:\Users\Patrick 2017-03-07 14:47 - 2014-07-26 13:07 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\Skype 2017-03-07 14:47 - 2014-06-22 06:36 - 00000000 ____D C:\Users\Patrick\Documents\Youcam 2017-03-07 14:45 - 2015-11-19 12:50 - 00000000 __SHD C:\Users\Patrick\IntelGraphicsProfiles 2017-03-07 14:44 - 2016-10-02 11:48 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-03-07 14:43 - 2016-07-16 07:04 - 01310720 _____ C:\WINDOWS\system32\config\BBI 2017-03-07 14:26 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\registration 2017-03-07 14:12 - 2014-06-22 08:24 - 00000000 __RDO C:\Users\Patrick\SkyDrive 2017-03-07 14:10 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-03-07 14:05 - 2013-11-04 12:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-03-06 19:11 - 2016-10-29 17:36 - 00000356 _____ C:\WINDOWS\Tasks\HPCeeScheduleForPatrick.job 2017-03-05 16:50 - 2014-09-01 06:45 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-03-05 16:41 - 2014-08-10 09:57 - 00000000 ____D C:\Users\Patrick\AppData\Local\ElevatedDiagnostics 2017-03-03 20:03 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-03-03 09:47 - 2014-09-08 13:27 - 00002088 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk 2017-03-03 09:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-03-03 07:40 - 2014-07-26 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2017-03-03 07:39 - 2016-10-12 07:21 - 00048584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys 2017-03-03 07:39 - 2014-07-26 12:14 - 00163976 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2017-03-03 07:39 - 2014-07-26 12:14 - 00161824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2017-03-03 07:39 - 2014-07-26 12:14 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys 2017-03-03 07:39 - 2014-07-26 12:14 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 2017-03-02 19:18 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-03-02 15:43 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF 2017-03-01 10:48 - 2014-06-22 08:46 - 00000000 ____D C:\Users\Patrick\AppData\Roaming\HpUpdate 2017-03-01 09:39 - 2014-06-22 06:34 - 00000000 ____D C:\Users\Patrick\AppData\Local\Packages 2017-02-28 09:03 - 2016-12-13 19:05 - 00003278 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2017-02-28 09:03 - 2015-11-19 13:00 - 00002458 _____ C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-02-24 09:00 - 2014-06-27 11:39 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-02-24 08:53 - 2014-06-27 11:39 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-02-23 19:17 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-02-23 19:06 - 2014-06-23 07:54 - 00000000 ____D C:\Users\Patrick\AppData\Local\Google 2017-02-23 19:06 - 2014-06-22 16:56 - 00000000 ____D C:\Program Files (x86)\Google 2017-02-23 11:18 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-02-22 19:14 - 2014-06-22 08:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2017-02-22 19:13 - 2014-06-22 08:43 - 00000000 ____D C:\ProgramData\HP 2017-02-22 19:13 - 2014-06-22 08:43 - 00000000 ____D C:\Program Files (x86)\HP 2017-02-22 19:07 - 2016-10-07 18:40 - 00001064 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job 2017-02-22 19:07 - 2014-08-26 16:34 - 00001002 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2017-02-22 01:35 - 2016-10-07 18:40 - 00004142 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-02-22 01:35 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-02-22 01:35 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-02-21 17:47 - 2015-04-29 11:09 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-02-21 01:36 - 2016-10-02 11:47 - 00003988 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2017-02-20 13:40 - 2016-10-02 11:47 - 00000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard 2017-02-20 13:40 - 2013-11-04 12:34 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2017-02-20 12:34 - 2013-11-04 12:47 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support 2017-02-20 12:34 - 2013-11-04 12:46 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-02-20 12:34 - 2013-11-04 11:54 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2017-02-20 10:57 - 2014-06-22 07:43 - 00000000 ____D C:\Users\Patrick\AppData\Local\Hewlett-Packard 2017-02-20 10:40 - 2013-09-01 04:49 - 00000000 ____D C:\SWSetup 2017-02-15 18:30 - 2016-10-08 08:28 - 00000000 ___HD C:\OneDriveTemp 2017-02-15 18:30 - 2014-08-29 17:21 - 00000000 ____D C:\Users\VERONIK\Documents\Fichiers Outlook 2017-02-15 18:30 - 2014-08-29 16:30 - 00000000 ___RD C:\Users\VERONIK\OneDrive 2017-02-15 18:15 - 2014-08-29 15:46 - 00000000 ____D C:\Users\VERONIK\Documents\Youcam 2017-02-15 18:09 - 2015-11-19 17:29 - 00000000 __SHD C:\Users\VERONIK\IntelGraphicsProfiles 2017-02-12 20:12 - 2016-05-22 10:49 - 00000000 ____D C:\Users\Patrick\AppData\Local\PackageStaging 2017-02-06 20:48 - 2016-07-16 12:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-02-06 20:48 - 2016-07-16 12:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-02-06 19:14 - 2014-08-21 09:38 - 00000000 ____D C:\ProgramData\Package Cache ==================== Fichiers à la racine de certains dossiers ======= 2014-11-19 11:36 - 2014-11-19 11:36 - 0000268 ___RH () C:\Users\Patrick\AppData\Roaming\Overdrive 2014-11-19 11:37 - 2014-11-19 11:37 - 0000268 ___RH () C:\Users\Patrick\AppData\Roaming\PDEs 2014-11-19 11:36 - 2014-11-19 11:36 - 0000268 ___RH () C:\Users\Patrick\AppData\Roaming\PPD Plugins 2015-08-08 15:36 - 2015-08-08 15:36 - 0000017 _____ () C:\Users\Patrick\AppData\Local\resmon.resmoncfg 2014-06-22 08:43 - 2014-06-22 08:43 - 0000057 _____ () C:\ProgramData\Ament.ini 2014-08-26 18:43 - 2014-08-26 18:43 - 4954384 _____ () C:\ProgramData\pclunst.exe 2014-11-19 11:36 - 2014-11-19 11:36 - 0000268 ___RH () C:\ProgramData\Pedal Hard 2014-11-19 11:37 - 2014-11-19 11:37 - 0000268 ___RH () C:\ProgramData\People 2014-11-19 11:36 - 2014-11-19 11:36 - 0000268 ___RH () C:\ProgramData\Percussion Kit 2014-11-19 11:37 - 2014-11-19 11:37 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT 2014-11-19 11:36 - 2016-09-18 16:31 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT 2014-11-19 11:36 - 2016-08-29 15:31 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT Fichiers à déplacer ou supprimer: ==================== C:\ProgramData\pclunst.exe Certains fichiers dans TEMP: ==================== 2017-02-26 09:02 - 2017-02-27 16:21 - 3651584 _____ (Igor Pavlov) C:\Users\Patrick\AppData\Local\Temp\Package_fr_ww.exe 2016-10-03 11:41 - 2016-10-03 11:41 - 0000000 ____D () C:\Users\VERONIK\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2017-03-07 15:17 ==================== Fin de FRST.txt ============================