cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016
Exécuté par besmellah (administrateur) sur BESMELLAH-PC (10-12-2016 19:41:55)
Exécuté depuis C:\Users\besmellah\Desktop
Profils chargés: besmellah (Profils disponibles: besmellah)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: FF)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registre (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2650576 2016-11-15] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3907152 2015-08-29] (Tonec Inc.)
HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Run: [uTorrent] => C:\Users\besmellah\AppData\Roaming\uTorrent\uTorrent.exe [2145984 2016-12-05] (BitTorrent Inc.)
HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2016-12-06] (SUPERAntiSpyware)
HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Run: [EasyHideIPVPN] => C:\Program Files (x86)\Easy-Hide-IP VPN\vpn.client.exe
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
GroupPolicy: Restriction <======= ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Winsock: Catalog9-x64 01 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech)
Winsock: Catalog9-x64 02 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech)
Winsock: Catalog9-x64 03 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech)
Winsock: Catalog9-x64 04 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech)
Winsock: Catalog9-x64 16 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech)
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 8.8.8.8
Tcpip\..\Interfaces\{3B2B300C-B9DD-4A1D-AD0C-08AE295DEFAB}: [NameServer] 208.67.222.222,8.8.8.8
Tcpip\..\Interfaces\{AC5BADE8-21FD-4530-9866-D65771C99DAA}: [DhcpNameServer] 208.67.222.222 8.8.8.8

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-79894898-3895581772-2634441730-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-79894898-3895581772-2634441730-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-11-30] (Internet Download Manager, Tonec Inc.)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-11-30] (Internet Download Manager, Tonec Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-09] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-09] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-79894898-3895581772-2634441730-1000 -> Pas de nom - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Pas de fichier

FireFox:
========
FF DefaultProfile: eeli9j4q.default-1418442691211
FF ProfilePath: C:\Users\besmellah\AppData\Roaming\Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211 [2016-12-10]
FF user.js: detected! => C:\Users\besmellah\AppData\Roaming\Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211\user.js [2016-12-09]
FF NetworkProxy: Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211 -> socks_remote_dns", true
FF NetworkProxy: Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211 -> type", 0
FF Extension: (Adblock Plus) - C:\Users\besmellah\AppData\Roaming\Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-05]
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-11-16]
FF HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\besmellah\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\besmellah\AppData\Roaming\IDM\idmmzcc5 [2015-08-31] [non signé]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-12-05] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [Pas de fichier]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-12-05] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [Pas de fichier]
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-09] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-09] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL [2003-07-14] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-10-27] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default [2016-12-10]
CHR Extension: (عروض Google التقديمية) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-17]
CHR Extension: (محرّر مستندات Google) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-17]
CHR Extension: (Google Drive) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-17]
CHR Extension: (Youtube) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-17]
CHR Extension: (آدبلوك بلس) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-12-05]
CHR Extension: (بحث Google) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-17]
CHR Extension: (جداول بيانات Google ) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-17]
CHR Extension: (مستندات Google في وضع عدم الاتصال) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (آدبلوك بلس) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-05]
CHR Extension: (IDM Integration Module) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2016-12-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-06]
CHR Extension: (Gmail) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-17]
CHR Extension: (Chrome Media Router) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-07]
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-11-30]
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-11-30]

==================== Services (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
S3 EHttpSrv; C:\Program Files\ESET\ESET Endpoint Security\ehttpsrv.exe [51872 2016-05-24] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2815520 2016-10-11] (ESET)
S3 eshasrv; C:\Program Files\ESET\ESET Endpoint Security\eshasrv.exe [193696 2016-05-24] (ESET)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [155600 2016-11-15] (Malwarebytes Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10216688 2016-11-28] (TeamViewer GmbH)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [Fichier non signé]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 vssbrigde64; "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\x64\vssbridge64.exe" [X]
S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X]

===================== Pilotes (Avec liste blanche) ======================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [35496 2000-01-01] (Advanced Micro Devices, Inc.)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-09-28] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [232072 2016-10-07] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [212096 2016-10-07] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [177792 2016-10-07] (ESET)
R2 ekbdflt; C:\Windows\System32\DRIVERS\ekbdflt.sys [48768 2016-10-07] (ESET)
R1 epfw; C:\Windows\System32\DRIVERS\epfw.sys [76416 2016-10-07] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59528 2016-10-13] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [91784 2016-10-07] (ESET)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [77408 2016-11-15] ()
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-02-06] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-12-10] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2015-09-29] () [Fichier non signé]
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2016-12-09] ()
S1 AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-12-10 19:41 - 2016-12-10 19:43 - 00017504 _____ C:\Users\besmellah\Desktop\FRST.txt
2016-12-10 19:41 - 2016-12-10 19:41 - 00000000 ____D C:\FRST
2016-12-10 19:40 - 2016-12-10 19:40 - 02420224 _____ (Farbar) C:\Users\besmellah\Desktop\FRST64.exe
2016-12-10 19:33 - 2016-12-10 19:33 - 00000000 _____ C:\Users\besmellah\Desktop\Nouveau document texte (4).txt
2016-12-10 19:20 - 2016-12-10 19:20 - 00000000 _____ C:\Users\besmellah\Desktop\Nouveau document texte (3).txt
2016-12-10 19:03 - 2016-12-10 19:03 - 00001965 _____ C:\Users\besmellah\Desktop\ESET Smart Security.lnk
2016-12-10 18:50 - 2016-12-10 18:51 - 03137664 _____ (ESET) C:\Users\besmellah\Desktop\eset_smart_security_live_installer.exe
2016-12-10 18:46 - 2016-12-10 18:46 - 00000000 _____ C:\Users\besmellah\Desktop\Nouveau document texte (2).txt
2016-12-10 18:16 - 2016-12-10 18:16 - 00001003 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2016-12-10 18:16 - 2016-12-10 18:16 - 00000991 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
2016-12-10 18:14 - 2016-12-10 18:15 - 14386888 _____ (TeamViewer GmbH) C:\Users\besmellah\Desktop\TeamViewer_Setup.exe
2016-12-10 17:02 - 2016-12-10 17:43 - 00000786 _____ C:\Users\besmellah\Desktop\ZHPDiag.lnk
2016-12-10 17:01 - 2016-12-10 17:02 - 02567680 _____ C:\Users\besmellah\Desktop\ZHPDiag3.exe
2016-12-10 14:55 - 2016-12-10 14:55 - 00001550 _____ C:\Users\besmellah\Desktop\ZHPCleaner.txt
2016-12-10 14:47 - 2016-12-10 14:47 - 00000796 _____ C:\Users\besmellah\Desktop\ZHPCleaner.lnk
2016-12-10 13:23 - 2016-12-10 19:03 - 00000000 ____D C:\ProgramData\ESET
2016-12-10 13:23 - 2016-12-10 19:03 - 00000000 ____D C:\Program Files\ESET
2016-12-09 21:36 - 2016-12-09 21:36 - 00002288 _____ C:\Windows\SysWOW64\EasyRedirectOff.ini
2016-12-09 21:36 - 2016-12-09 21:36 - 00002288 _____ C:\Windows\system32\EasyRedirectOff.ini
2016-12-09 21:36 - 2016-12-09 21:36 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\Easy-Hide-IP VPN
2016-12-09 21:34 - 2016-12-09 21:38 - 00000000 ____D C:\Program Files (x86)\Easy-Hide-IP VPN
2016-12-09 21:34 - 2016-12-09 21:37 - 00000000 ____D C:\Program Files\TAP-Windows
2016-12-09 21:34 - 2016-07-01 00:07 - 00547544 _____ (EasyTech) C:\Windows\system32\EasyRedirect64.dll
2016-12-09 21:34 - 2016-07-01 00:07 - 00388312 _____ (EasyTech) C:\Windows\SysWOW64\EasyRedirect.dll
2016-12-09 21:33 - 2016-12-09 21:33 - 07113208 _____ (Easy-Hide-IP VPN ) C:\Users\besmellah\Downloads\easy-hide-ip-vpn-4.4.exe
2016-12-09 19:14 - 2016-12-10 07:12 - 00000000 ____D C:\Users\besmellah\Desktop\فساتين
2016-12-09 18:08 - 2016-12-10 14:47 - 00000000 ____D C:\Users\besmellah\Desktop\برامج حماية
2016-12-09 17:59 - 2016-12-09 17:59 - 00013972 _____ C:\ComboFix.txt
2016-12-09 17:50 - 2016-12-09 17:59 - 00000000 ____D C:\Qoobox
2016-12-09 14:26 - 2016-12-09 14:26 - 00000000 ____D C:\KVRT_Data
2016-12-09 14:19 - 2016-12-09 14:28 - 00324540 _____ C:\Windows\ntbtlog.txt
2016-12-07 23:27 - 2016-12-07 23:27 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\SUPERAntiSpyware.com
2016-12-07 23:26 - 2016-12-09 18:01 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2016-12-07 23:26 - 2016-12-08 20:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2016-12-07 23:26 - 2016-12-07 23:26 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2016-12-06 19:27 - 2016-12-06 12:26 - 07122944 _____ C:\Users\besmellah\Desktop\ICONE_I2020_20161206.bin
2016-12-06 04:31 - 2016-12-10 19:00 - 00000000 ____D C:\Users\besmellah\AppData\LocalLow\Mozilla
2016-12-05 22:14 - 2016-12-06 06:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-11-30 16:21 - 2016-10-17 16:35 - 00223464 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2016-12-10 19:33 - 2016-08-07 00:44 - 00000075 _____ C:\Users\besmellah\Desktop\Nouveau document texte.txt
2016-12-10 19:22 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-10 19:22 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-10 19:18 - 2014-08-04 20:34 - 00000000 ____D C:\Users\besmellah\AppData\Local\CrashDumps
2016-12-10 19:15 - 2016-07-01 17:13 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-12-10 19:15 - 2015-01-29 22:14 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\uTorrent
2016-12-10 19:13 - 2014-12-27 09:54 - 00000840 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-10 19:12 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-12-10 19:11 - 2014-03-30 19:56 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\DMCache
2016-12-10 19:10 - 2014-12-25 18:33 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-12-10 19:04 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-12-10 18:55 - 2015-07-30 00:11 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-12-10 18:44 - 2015-07-30 00:41 - 00001064 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-12-10 18:37 - 2013-11-15 00:55 - 00179016 _____ C:\Users\besmellah\AppData\Local\GDIPFONTCACHEV1.DAT
2016-12-10 18:20 - 2009-07-14 05:45 - 05279152 _____ C:\Windows\system32\FNTCACHE.DAT
2016-12-10 18:16 - 2014-12-25 18:33 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\TeamViewer
2016-12-10 17:43 - 2014-12-12 20:04 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\ZHP
2016-12-10 16:49 - 2014-01-17 14:33 - 00003968 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{373C4E0F-773C-46C5-9411-725193941D68}
2016-12-10 13:58 - 2016-02-22 13:42 - 00000000 ____D C:\Users\besmellah\AppData\Local\ESET
2016-12-10 13:23 - 2016-02-22 13:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2016-12-10 13:03 - 2015-06-27 01:37 - 00000803 _____ C:\Users\besmellah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2016-12-09 19:20 - 2015-03-14 11:31 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\IDM
2016-12-09 18:42 - 2015-09-30 11:24 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2016-12-09 17:57 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2016-12-09 07:30 - 2015-12-12 15:55 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-12-07 20:01 - 2015-06-27 01:42 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2016-12-06 22:54 - 2015-11-04 18:12 - 00046840 _____ C:\Windows\ZAM_Guard.krnl.trace
2016-12-06 19:16 - 2015-11-04 18:12 - 00055702 _____ C:\Windows\ZAM.krnl.trace
2016-12-06 19:13 - 2011-04-12 10:16 - 00735468 _____ C:\Windows\system32\perfh00C.dat
2016-12-06 19:13 - 2011-04-12 10:16 - 00148390 _____ C:\Windows\system32\perfc00C.dat
2016-12-06 19:13 - 2009-07-14 06:13 - 01662566 _____ C:\Windows\system32\PerfStringBackup.INI
2016-12-06 06:47 - 2014-07-30 12:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-05 23:10 - 2015-12-17 21:12 - 00002155 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-05 20:02 - 2015-07-30 00:41 - 00004074 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-12-05 20:02 - 2015-07-30 00:11 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-12-05 20:02 - 2015-07-30 00:11 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-12-05 20:02 - 2015-07-30 00:11 - 00003940 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-12-05 20:02 - 2014-01-18 17:50 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-12-05 20:02 - 2014-01-18 17:49 - 00000000 ____D C:\Windows\system32\Macromed
2016-12-05 18:44 - 2016-08-02 22:14 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-12-05 18:10 - 2014-12-25 15:38 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-12-05 17:57 - 2015-03-14 11:30 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager
2016-12-05 17:55 - 2015-09-30 11:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
2016-12-05 17:55 - 2015-09-30 11:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
2016-11-30 12:46 - 2013-12-22 18:21 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\vlc

==================== Fichiers à la racine de certains dossiers =======

2014-08-14 12:53 - 2014-08-14 12:53 - 0000132 _____ () C:\Users\besmellah\AppData\Roaming\Adobe PNG Format CS6 Prefs
2013-11-15 22:12 - 2013-11-15 22:12 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Certains fichiers dans TEMP:
====================
C:\Users\besmellah\AppData\Local\Temp\SpOrder.dll


==================== Bamital & volsnap ======================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement
C:\Windows\system32\wininit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement
C:\Windows\explorer.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\Windows\system32\svchost.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\Windows\system32\services.exe => Le fichier est signé numériquement
C:\Windows\system32\User32.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\Windows\system32\userinit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement
C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

LastRegBack: 2016-12-05 19:35

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité