cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-08-2016
Ran by Bouhafsi (administrator) on BOUHAFSI-PC (03-08-2016 20:35:01)
Running from C:\Users\Bouhafsi\Desktop
Loaded Profiles: Bouhafsi (Available Profiles: Bouhafsi & Invité)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Language: العربية (السعودية)‏
Internet Explorer Version 8 (Default browser: "C:\Program Files\Maxthon\Bin\Maxthon.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\ProgramData\DatacardService\HWDeviceService.exe
() C:\ProgramData\MobiConnect\OnlineUpdate\ouc.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_22_0_0_192_ActiveX.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(TechSmith Corporation) C:\Program Files\TechSmith\Snagit 10\Snagit32.exe
(TechSmith Corporation) C:\Program Files\TechSmith\Snagit 10\TscHelp.exe
(TechSmith Corporation) C:\Program Files\TechSmith\Snagit 10\SnagPriv.exe
(TechSmith Corporation) C:\Program Files\TechSmith\Snagit 10\SnagitEditor.exe
(Maxthon International ltd.) C:\Program Files\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files\Maxthon\Bin\Maxthon.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\Policies\Explorer: [NoRecentDocsHistory] 1
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: H - H:\AutoRun.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {3d9579b5-306b-11e5-9abd-28e347569d88} - G:\AutoRun.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {3d9579c6-306b-11e5-9abd-344b50b7efb4} - G:\AutoRun.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {3f314811-5139-11e5-83fd-28e347561ed2} - G:\Startme.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {472e106a-58c6-11e6-927d-201a06e1383f} - H:\AutoRun.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {472e112f-58c6-11e6-927d-201a06e1383f} - H:\AutoRun.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {53e42b92-b519-11e5-a57e-344b50b7efb4} - H:\AutoRun.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {611c2803-a8eb-11e5-bb46-28e347561ed2} - H:\Startme.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {686c4c89-ad9b-11e5-940e-28e347561ed2} - G:\autorun.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {a04dddd4-aaff-11e5-902e-806e6f6e6963} - G:\autorun.exe
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\...\MountPoints2: {de44bec3-b2f9-11e5-a137-344b50b7efb4} - H:\AutoRun.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
GroupPolicyScripts: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{037C5E21-8673-4CC4-BB66-1730BDE82C12}: [NameServer] 209.244.0.3,209.244.0.4
Tcpip\..\Interfaces\{037C5E21-8673-4CC4-BB66-1730BDE82C12}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{18BCC017-74F4-4DC9-B733-DBF984230518}: [NameServer] 192.168.4.220 209.244.0.3
Tcpip\..\Interfaces\{27FC7266-381E-4A27-9E64-3C4437763677}: [DhcpNameServer] 192.168.0.1 192.168.0.1
Tcpip\..\Interfaces\{3FC8CA3E-80B8-49AF-BE28-3DFDC46D9965}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{64BF9585-E79F-4A5F-8F52-513C9DFCCE02}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{7FD3D4C0-00C2-43C6-8832-C7DEF199E6B9}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{93F8ECAF-0547-4DCE-AA76-DCC1F49EF35E}: [DhcpNameServer] 192.168.0.1 192.168.0.1
Tcpip\..\Interfaces\{C3F48772-9896-4024-AAE3-5CE9A5CEA9B3}: [DhcpNameServer] 192.168.8.1 192.168.8.1

Internet Explorer:
==================
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-3481782987-2517284933-296613505-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKU\S-1-5-21-3481782987-2517284933-296613505-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: SnagIt Toolbar Loader -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll [2011-03-21] (TechSmith Corporation)
BHO: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\IEExt\ie_plugin.dll [2015-12-08] (AO Kaspersky Lab)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2015-07-22] (Sun Microsystems, Inc.)
Toolbar: HKLM - Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll [2011-03-21] (TechSmith Corporation)
Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\IEExt\ie_plugin.dll [2015-12-08] (AO Kaspersky Lab)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab

FireFox:
========
FF ProfilePath: C:\Users\Bouhafsi\AppData\Roaming\Mozilla\Firefox\Profiles\x1c7tlrg.default
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2010-01-12] (Adobe Systems, Inc.)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-04-02] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2013-04-02] (Foxit Corporation)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2012-12-14] (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-02] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-07-19] (VideoLAN)
FF Plugin HKU\S-1-5-21-3481782987-2517284933-296613505-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Bouhafsi\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeploytk.dll [2015-07-22] (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll [2010-01-15] (mozilla.org)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPSWF32.dll [2010-01-26] ()
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\answers.xml [2010-01-15]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2010-01-15]
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [not found]
FF Extension: Test Pilot - C:\Users\Bouhafsi\AppData\Roaming\Mozilla\Firefox\Profiles\x1c7tlrg.default\extensions\testpilot@labs.mozilla.com.xpi [2016-03-25]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} [2015-08-06] [not signed]
FF HKLM\...\Firefox\Extensions: [light_plugin_D772DC8D6FAF43A29B25C4EBAA5AD1DE@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\FFExt\light_plugin_firefox
FF Extension: Kaspersky Protection - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\FFExt\light_plugin_firefox [2016-06-28]
StartMenuInternet: FIREFOX.EXE - C:\Program Files\Aurora\firefox.exe
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox-branding.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox-l10n.js [2010-02-13]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\reporter.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\mozilla.cfg [2007-04-03] <==== ATTENTION

Chrome:
=======
CHR Profile: C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (عروض Google التقديمية) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-06]
CHR Extension: (محرّر مستندات Google) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-06]
CHR Extension: (Google Drive) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-01]
CHR Extension: (Youtube) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (بحث Google) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Kaspersky Protection) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\eahebamiopdhefndnmappcihfajigkka [2016-06-28]
CHR Extension: (مستندات Google في وضع عدم الاتصال) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]
CHR Extension: (Gmail) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-23]
CHR Extension: (Chrome Media Router) - C:\Users\Bouhafsi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-02]
CHR HKLM\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] -

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AVP16.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\avp.exe [194000 2015-12-08] (Kaspersky Lab ZAO)
R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [276048 2013-04-10] ()
S4 Lenovo EasyPlus Hotspot; C:\Program Files\Common Files\LENOVO\easyplussdk\bin\EPHotspot.exe [509424 2015-06-08] (Lenovo)
S2 MobiConnect. RunOuc; C:\Program Files\MobiConnect\UpdateDog\ouc.exe [656976 2013-11-14] ()
S4 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [242256 2014-08-20] ()
S4 ShareItSvc; C:\Program Files\SHAREit\SHAREit\Shareit.Service.exe [31176 2016-02-04] (SHAREit Technologies Co.Ltd)
S4 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
R2 Themes; C:\Windows\system32\themeservice.dll [37376 2010-03-14] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
S4 ZDServ; C:\ProgramData\ZDSupport\ZDServ\ZDServ.exe [427264 2013-11-06] ()
S2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [X]
S2 avast! Firewall; "C:\Program Files\AVAST Software\Avast\afwServ.exe" [X]
S2 ekrn; "C:\Program Files\ESET\ESET Smart Security\ekrn.exe" [X]
S2 ProductAgentService; "C:\Program Files\Bitdefender Agent\ProductAgentService.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26136 2016-03-21] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2016-03-21] (AVAST Software)
R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [264560 2016-03-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2016-03-21] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2016-03-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2016-03-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2016-03-21] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2016-03-21] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2016-03-21] ()
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3260416 2014-03-31] (Qualcomm Atheros Communications, Inc.)
S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [510248 2015-01-04] (Qualcomm Atheros)
S3 CisUtMonitor; C:\Windows\System32\DRIVERS\CisUtMonitor.sys [27600 2014-08-07] (CrystalIdea Software)
S3 cmusbser; C:\Windows\System32\DRIVERS\cmusbser.sys [103552 2008-08-29] (Mobile Connector)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [201912 2015-07-06] (Kaspersky Lab ZAO)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [188808 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [37416 2013-09-17] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [49240 2013-09-17] (ESET)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [101248 2013-11-14] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27776 2013-11-14] (Huawei Technologies Co., Ltd.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [208384 2013-11-14] (Huawei Technologies Co., Ltd.)
R3 int0800; C:\Windows\System32\DRIVERS\flashud.sys [42496 2009-09-09] (Intel Corporation)
S3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [808720 2015-01-27] (Intel Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [153784 2015-06-22] (Kaspersky Lab ZAO)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [46776 2015-06-06] (Kaspersky Lab ZAO)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [58224 2015-06-27] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [66976 2016-06-28] (AO Kaspersky Lab)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [147328 2015-12-08] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [53168 2016-06-28] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [785328 2016-06-28] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [44120 2016-06-28] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [37048 2015-06-06] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [38072 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [39304 2015-12-08] (AO Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54328 2015-06-11] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [87736 2015-06-16] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [156856 2015-06-23] (Kaspersky Lab ZAO)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2004-04-01] (Padus, Inc.) [File not signed]
R3 RSBASTOR; C:\Windows\System32\DRIVERS\RtsBaStor.sys [235736 2014-11-06] (Realtek Semiconductor Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2015-07-22] () [File not signed]
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-06-27] ()
R2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam.sys [1068216 2012-04-15] (Windows (R) Win 7 DDK provider)
S3 cpuz134; \??\C:\Users\Bouhafsi\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
S3 ESETCleanersDriver; \??\C:\Windows\system32\Drivers\ESETCleanersDriver.sys [X]
U4 JavaQuickStarterService; no ImagePath
U4 klkbdflt2; system32\DRIVERS\klkbdflt2.sys [X]
S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-03 20:35 - 2016-08-03 20:35 - 00018400 _____ C:\Users\Bouhafsi\Desktop\FRST.txt
2016-08-03 20:34 - 2016-08-03 20:35 - 00000000 ____D C:\FRST
2016-08-03 20:33 - 2016-08-03 20:34 - 01743872 _____ (Farbar) C:\Users\Bouhafsi\Desktop\FRST.exe
2016-08-03 20:04 - 2016-08-03 20:04 - 00110820 _____ C:\Users\Bouhafsi\Desktop\ZHPDiag.txt
2016-08-03 19:59 - 2016-08-03 19:59 - 00000826 _____ C:\Users\Bouhafsi\Desktop\ZHPDiag.lnk
2016-08-03 19:53 - 2016-08-03 19:53 - 02393600 _____ (Farbar) C:\Users\Bouhafsi\Desktop\FRST64.exe
2016-08-03 19:49 - 2016-08-03 19:50 - 02235392 _____ C:\Users\Bouhafsi\Desktop\ZHPDiag3.exe
2016-08-03 19:29 - 2016-08-03 19:32 - 00001101 _____ C:\Users\Public\Desktop\DLL-Files.com Client.lnk
2016-08-03 19:29 - 2016-08-03 19:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DLL-Files.com Client
2016-08-03 19:29 - 2016-08-03 19:32 - 00000000 ____D C:\Program Files\DLL-Files.com Client
2016-08-03 19:29 - 2016-08-03 19:30 - 00000000 ____D C:\Users\Bouhafsi\AppData\Roaming\DFXCT
2016-08-03 19:29 - 2016-08-03 19:29 - 00000000 ____D C:\Users\Bouhafsi\AppData\Roaming\DLL-files.com
2016-08-02 21:05 - 2016-08-02 21:05 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ew_juextctrl_01007.Wdf
2016-08-02 21:05 - 2016-08-02 21:05 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf
2016-08-02 21:04 - 2016-08-02 21:04 - 00001009 _____ C:\Users\Public\Desktop\MobiConnect.lnk
2016-08-02 21:04 - 2016-08-02 21:04 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
2016-08-02 21:04 - 2016-08-02 21:04 - 00000000 ____D C:\ProgramData\MobiConnect
2016-08-02 21:04 - 2013-11-14 11:39 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll
2016-08-02 21:04 - 2013-11-14 11:39 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll
2016-08-02 21:04 - 2013-11-14 11:39 - 00861696 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00381952 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00315520 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_wwanecm.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00208384 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00199168 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00108032 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_cdcacm.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00101248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00095232 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00077824 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00070528 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00027776 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00025856 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00019200 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys
2016-08-02 21:04 - 2013-11-14 11:39 - 00011904 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys
2016-08-02 21:02 - 2016-08-02 21:04 - 00000000 ____D C:\Program Files\MobiConnect
2016-08-02 21:00 - 2016-08-02 21:05 - 00000000 ____D C:\ProgramData\DatacardService
2016-08-01 12:52 - 2016-08-01 12:52 - 00435168 _____ C:\Windows\Minidump\080116-25740-01.dmp
2016-07-31 09:47 - 2016-07-31 09:47 - 00435168 _____ C:\Windows\Minidump\073116-24554-01.dmp
2016-07-30 11:09 - 2016-07-30 11:09 - 00461136 _____ C:\Windows\Minidump\073016-25724-01.dmp
2016-07-29 07:38 - 2016-07-29 07:38 - 00447480 _____ C:\Windows\Minidump\072916-24804-01.dmp
2016-07-28 16:54 - 2016-07-28 16:54 - 00438880 _____ C:\Windows\Minidump\072816-24538-01.dmp
2016-07-28 13:39 - 2016-07-28 13:39 - 00438880 _____ C:\Windows\Minidump\072816-24882-01.dmp
2016-07-27 17:55 - 2016-07-27 17:55 - 00447360 _____ C:\Windows\Minidump\072716-28610-01.dmp
2016-07-27 09:03 - 2016-07-27 09:03 - 00448280 _____ C:\Windows\Minidump\072716-24024-01.dmp
2016-07-26 19:04 - 2016-07-26 19:05 - 00439296 _____ C:\Windows\Minidump\072616-24897-01.dmp
2016-07-26 16:48 - 2016-08-01 12:52 - 305782627 _____ C:\Windows\MEMORY.DMP
2016-07-26 16:48 - 2016-07-26 16:49 - 00439296 _____ C:\Windows\Minidump\072616-61152-01.dmp
2016-07-20 07:43 - 2016-07-20 07:43 - 00439224 _____ C:\Windows\Minidump\072016-24850-01.dmp
2016-07-19 07:42 - 2016-07-19 07:42 - 00464776 _____ C:\Windows\Minidump\071916-23540-01.dmp
2016-07-18 18:35 - 2016-07-18 18:35 - 00438760 _____ C:\Windows\Minidump\071816-27362-01.dmp
2016-07-18 00:08 - 2016-07-18 00:08 - 00452280 _____ C:\Windows\Minidump\071816-27596-01.dmp
2016-07-16 14:13 - 2016-07-16 14:13 - 00434632 _____ C:\Windows\Minidump\071616-27097-01.dmp
2016-07-13 18:57 - 2016-07-13 18:57 - 00452280 _____ C:\Windows\Minidump\071316-24289-01.dmp
2016-07-12 20:40 - 2016-07-12 20:40 - 00438880 _____ C:\Windows\Minidump\071216-24148-01.dmp
2016-07-11 19:59 - 2016-07-11 19:59 - 00438760 _____ C:\Windows\Minidump\071116-24741-01.dmp
2016-07-11 16:48 - 2016-07-11 16:48 - 00443744 _____ C:\Windows\Minidump\071116-24663-01.dmp
2016-07-10 00:39 - 2016-07-10 00:39 - 00439224 _____ C:\Windows\Minidump\071016-24788-01.dmp
2016-07-09 00:01 - 2016-07-09 00:01 - 00439296 _____ C:\Windows\Minidump\070916-24242-01.dmp
2016-07-08 10:23 - 2016-07-08 10:24 - 00439296 _____ C:\Windows\Minidump\070816-24648-01.dmp
2016-07-08 02:15 - 2016-07-08 02:15 - 00439296 _____ C:\Windows\Minidump\070816-26192-01.dmp
2016-07-07 01:32 - 2016-07-07 01:32 - 00439296 _____ C:\Windows\Minidump\070716-25116-01.dmp
2016-07-06 12:33 - 2016-07-06 12:33 - 00439296 _____ C:\Windows\Minidump\070616-25131-01.dmp
2016-07-05 22:35 - 2016-07-05 22:35 - 00438808 _____ C:\Windows\Minidump\070516-25568-01.dmp
2016-07-04 00:29 - 2016-07-04 00:29 - 00440800 _____ C:\Windows\Minidump\070416-26130-01.dmp

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-03 20:28 - 2016-03-25 21:16 - 00000918 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3481782987-2517284933-296613505-1000Core.job
2016-08-03 20:27 - 2015-10-29 00:37 - 00000000 ____D C:\Users\Bouhafsi\AppData\Roaming\ZHP
2016-08-03 20:21 - 2016-03-25 21:16 - 00000940 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3481782987-2517284933-296613505-1000UA.job
2016-08-03 20:00 - 2016-06-27 11:56 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-08-03 19:54 - 2015-07-22 21:42 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-03 18:46 - 2016-06-17 03:10 - 00000000 ____D C:\Users\Bouhafsi\Desktop\touts les cours englais
2016-08-03 18:46 - 2015-10-29 15:44 - 00489520 _____ C:\Windows\system32\perfh001.dat
2016-08-03 18:46 - 2015-10-29 15:44 - 00097930 _____ C:\Windows\system32\perfc001.dat
2016-08-03 18:46 - 2015-07-22 13:53 - 01446852 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-03 18:46 - 2009-07-14 10:36 - 00403388 _____ C:\Windows\system32\perfh00C.dat
2016-08-03 18:46 - 2009-07-14 10:36 - 00067448 _____ C:\Windows\system32\perfc00C.dat
2016-08-03 18:46 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\inf
2016-08-03 18:32 - 2009-07-14 06:34 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-03 18:32 - 2009-07-14 06:34 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-03 18:27 - 2015-10-30 19:06 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2016-08-03 18:27 - 2015-07-22 21:42 - 00001052 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-03 18:25 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-02 22:02 - 2016-01-06 21:28 - 00000000 ____D C:\Users\Bouhafsi\AppData\Local\Messenger
2016-08-02 21:19 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2016-08-02 21:14 - 2015-07-22 14:06 - 00000030 _____ C:\Windows\QQPlayer.INI
2016-08-02 21:06 - 2016-06-27 23:08 - 00000000 ____D C:\Users\Bouhafsi\AppData\Local\VirtualStore
2016-08-02 17:35 - 2016-01-13 22:54 - 00000803 _____ C:\Users\Bouhafsi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Messenger.lnk
2016-08-01 12:52 - 2015-07-29 19:12 - 00000000 ____D C:\Windows\Minidump
2016-07-31 18:45 - 2015-07-22 14:06 - 00000000 ____D C:\Users\Bouhafsi\AppData\Roaming\vlc
2016-07-28 08:52 - 2016-07-01 03:57 - 00000000 ____D C:\Users\Bouhafsi\AppData\Local\CrashDumps
2016-07-28 08:50 - 2016-06-13 22:20 - 00000349 _____ C:\Users\Public\Documents\PCLECHAL.INI
2016-07-28 08:40 - 2016-06-13 22:37 - 00003845 _____ C:\Users\Bouhafsi\AppData\Roaming\BOUHAFSI-PC.MTBF.txt
2016-07-26 12:54 - 2015-08-06 20:33 - 00000000 ____D C:\NST
2016-07-23 17:34 - 2009-07-14 06:53 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-07-23 14:56 - 2016-01-08 21:42 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-07-22 15:34 - 2016-06-14 02:58 - 00000000 ____D C:\Users\Bouhafsi\temp
2016-07-18 13:24 - 2015-11-30 20:15 - 00008192 _____ C:\Users\Bouhafsi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-07-18 07:33 - 2016-06-14 02:48 - 00000000 ____D C:\e1073cb50f80b437cc89

==================== Files in the root of some directories =======

2016-06-13 22:37 - 2016-07-28 08:40 - 0003845 _____ () C:\Users\Bouhafsi\AppData\Roaming\BOUHAFSI-PC.MTBF.txt
2015-12-01 01:15 - 2010-04-12 15:11 - 0003639 _____ () C:\Users\Bouhafsi\AppData\Roaming\GTShell.ini
2016-06-27 10:00 - 2016-06-28 02:22 - 0000126 _____ () C:\Users\Bouhafsi\AppData\Roaming\licecap.ini
2015-11-30 20:15 - 2016-07-18 13:24 - 0008192 _____ () C:\Users\Bouhafsi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-26 23:46 - 2015-07-26 23:46 - 0000000 _____ () C:\Users\Bouhafsi\AppData\Local\{6AA2DA4B-C8EF-4523-A80F-3814574CB151}
2016-06-27 11:04 - 2016-06-27 11:04 - 0043035 _____ () C:\ProgramData\1467018246.bdinstall.bin
2016-06-27 19:44 - 2016-06-27 19:44 - 0026014 _____ () C:\ProgramData\1467049414.bdinstall.bin
2016-06-27 20:42 - 2016-06-27 20:42 - 0026246 _____ () C:\ProgramData\1467052893.bdinstall.bin
2016-06-27 20:44 - 2016-06-27 20:44 - 0026177 _____ () C:\ProgramData\1467052999.bdinstall.bin
2016-06-27 20:49 - 2016-06-27 20:49 - 0026176 _____ () C:\ProgramData\1467053324.bdinstall.bin
2015-07-22 14:34 - 2015-07-22 14:34 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2016-06-14 02:05 - 2016-06-14 02:05 - 1144334 _____ () C:\ProgramData\LogFile 16-06-14 02-05.zip

Some files in TEMP:
====================
C:\Users\Bouhafsi\AppData\Local\Temp\$avantbrowser$.update.exe
C:\Users\Bouhafsi\AppData\Local\Temp\ClearSpot_15.dll
C:\Users\Bouhafsi\AppData\Local\Temp\ClearSpot_36.dll
C:\Users\Bouhafsi\AppData\Local\Temp\ClearSpot_37.dll
C:\Users\Bouhafsi\AppData\Local\Temp\ClearSpot_38.dll
C:\Users\Bouhafsi\AppData\Local\Temp\Foxit Reader Updater.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-07-27 18:26

==================== End of FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité