cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 06-08-2017
Exécuté par user (administrateur) sur JEAN-LOUIS (08-08-2017 17:20:44)
Exécuté depuis C:\Users\user\Desktop
Profils chargés: user (Profils disponibles: user)
Platform: Windows 7 Professional Service Pack 1 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
( ) C:\Windows\System32\lxebcoms.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Dell\Drivers\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registre (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2796272 2013-11-22] (SynapticsIncorporated)
HKLM-x32\...\Run: [StartCCC] => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{96086BC6-8AC2-484C-8E82-3234474B83E2}: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{9ED9F339-922A-4EEA-AD6B-E5B0BCC776CC}: [DhcpNameServer] 192.168.0.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.fr/?q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.fr/?q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.fr/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.fr/
HKU\S-1-5-21-2661643720-1140485415-1478318601-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.facebook.com/
HKU\S-1-5-21-2661643720-1140485415-1478318601-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://outlook.live.com/owa/?path=/mail/inbox
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fLfUu8UD.default [2017-03-26]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-14] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> D:\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> D:\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.trotux.com/?z=e6858a97f36f601eced9861g4z3b8q7g7q7z7b6o0g&from=icb&uid=SamsungXSSDX750XEVOX500GB_S36SNWBH530646X&type=hp
CHR StartupUrls: Default -> "hxxps://translate.google.fr/?hl=fr#fr/en/j'aimerai%20que%20le%20baiser%20de%20p%C3%A2ques%20soit%20r%C3%A9el","hxxp://mostwantedhf.info/","hxxps://www.facebook.com/","hxxps://mail.google.com/mail/u/0/#inbox","hxxps://blu184.mail.live.com/default.aspx?tid=cmnewaff3y5RGNYWw75adL5A2&fid=flinbox","hxxps://www.google.fr/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=blablacar","hxxps://www.blablacar.fr/search?fn=Lorgues&fc=43.493236%7C6.361557&fcc=FR&tn=Vitry-le-Fran%C3%A7ois&tc=48.726087%7C4.585745&tcc=FR&db=02%2F04%2F2016","hxxps://www.google.fr/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=supprimer%20babylon%20search%20de%20google%20chrome","hxxp://mister%20menuiserie/","hxxps://www.qwant.com/","hxxp://www.trotux.com/?z=e6858a97f36f601eced9861g4z3b8q7g7q7z7b6o0g&from=icb&uid=SamsungXSSDX750XEVOX500GB_S36SNWBH530646X&type=hp","hxxps://www.duckduckgo.com"
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default [2017-08-08]
CHR Extension: (Google Traduction) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-08-08]
CHR Extension: (Netcraft Extension) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmejphbfclcpmpohkggcjeibfilpamia [2017-08-08]
CHR Extension: (Adblock Plus) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-08-08]
CHR Extension: (Adobe Acrobat) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-08-08]
CHR Extension: (ZenMate VPN - Sécurité internet & Unblock) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2017-08-08]
CHR Extension: (Imprimer) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\idfnpgjblkahngbondojabhffkkdekbd [2017-08-08]
CHR Extension: (Vérificateur de messages Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2017-08-08]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-08]
CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-08]
CHR Extension: (Chrome Media Router) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08]
CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S4 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2572024 2016-06-23] (DellInc.)
S4 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [202488 2016-06-23] (DellInc.)
R2 IAStorDataMgrSvc; C:\Dell\Drivers\IAStorDataMgrSvc.exe [15720 2013-08-30] (IntelCorporation)
S4 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (IntelCorporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (IntelCorporation)
S2 lxebCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxebserv.exe [45736 2010-04-14] (LexmarkInternational,Inc.)
R2 lxeb_device; C:\Windows\system32\lxebcoms.exe [1052328 2010-04-14] ()
R2 lxeb_device; C:\Windows\SysWOW64\lxebcoms.exe [598696 2010-04-14] ()
S3 MBAMService; D:\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (MicrosoftCorporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (MicrosoftCorporation)
S4 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201872 2012-11-23] (RealtekSemiconductor)
S4 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [31704 2016-09-09] (DellInc.)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-03-25] (MicrosoftCorporation)
R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [6178304 2017-01-03] (DellInc.) [Fichier non signé]
S4 SpeedupService; "C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe" [X]

===================== Pilotes (Avec liste blanche) ======================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 aliide; C:\Windows\system32\drivers\aliide.sys [15080 2016-03-25] (AcerLaboratoriesInc.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [35496 2012-07-09] (AdvancedMicroDevices,Inc.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [172760 2017-01-03] (BroadcomCorporation.)
S3 cmdide; C:\Windows\system32\drivers\cmdide.sys [17128 2016-03-25] (CMDTechnology,Inc.)
R3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [32464 2016-06-23] (DellComputerCorporation)
R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [24240 2016-06-23] (DellComputerCorporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-05-31] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-30] (IntelCorporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [252832 2017-08-08] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (MicrosoftCorporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (MicrosoftCorporation)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [254520 2017-03-15] (QUALCOMMIncorporated)
S3 Revoflt; C:\Windows\System32\DRIVERS\revoflt.sys [40240 2016-12-21] (VSRevoGroup)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [31472 2013-11-22] (SynapticsIncorporated)
U5 UnlockerDriver5; C:\Users\user\Downloads\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 viaide; C:\Windows\system32\drivers\viaide.sys [17128 2016-03-25] (VIATechnologies,Inc.)
S3 vsmraid; C:\Windows\system32\drivers\vsmraid.sys [161872 2009-07-14] (VIATechnologiesInc.,Ltd)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2017-08-08 17:20 - 2017-08-08 17:21 - 000014626 _____ C:\Users\user\Desktop\FRST.txt
2017-08-08 11:45 - 2017-08-08 11:45 - 000004660 _____ C:\Users\user\Desktop\Fixlog1.txt
2017-08-08 10:42 - 2017-08-08 10:42 - 000048251 _____ C:\Users\user\Desktop\Addition1.txt
2017-08-08 10:41 - 2017-08-08 17:20 - 000000000 ____D C:\FRST
2017-08-08 10:41 - 2017-08-08 10:42 - 000044046 _____ C:\Users\user\Desktop\FRST1.txt
2017-08-08 10:41 - 2017-08-08 10:41 - 002381312 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2017-08-08 07:40 - 2017-08-08 07:40 - 000112548 _____ C:\Users\user\Desktop\ZHPDiag.txt
2017-08-08 07:38 - 2017-08-08 07:38 - 000001523 _____ C:\Users\user\Desktop\rapport Malwarebytes1.txt
2017-08-08 07:10 - 2017-08-08 07:11 - 000007146 _____ C:\Users\user\Desktop\ZHPCleaner.txt
2017-08-07 18:38 - 2017-08-07 18:38 - 000000086 _____ C:\Users\user\Desktop\Firefox SEND - envoyer vos fichiers volumineux, par Grey Cat. - Sospc.url
2017-08-04 10:07 - 2017-08-04 10:07 - 000000118 _____ C:\Users\user\Desktop\Assurances - Lorraine Champagne-Ardenne - Particuliers - Caisse d'Epargne.url
2017-08-04 09:58 - 2017-08-04 09:58 - 000939948 _____ C:\Users\user\Desktop\Banque à distance - E-documents.pdf
2017-08-04 07:02 - 2017-08-04 07:02 - 002020034 _____ C:\Users\user\Desktop\jean-louis111111111111111.pdf
2017-07-31 17:19 - 2017-07-31 17:19 - 000000127 _____ C:\Users\user\Desktop\Super Shop Stop - 🔧🔩🔧 🔩 Finally a solution I have been looking..-.url
2017-07-28 11:46 - 2017-08-08 07:25 - 000000616 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-27 17:44 - 2017-07-27 17:44 - 000000068 _____ C:\Users\user\Desktop\Banque et assurances - Particuliers - Caisse d'Epargne.url
2017-07-27 17:36 - 2017-07-27 17:36 - 000000000 ____D C:\Users\user\Documents\caisse épargne 0
2017-07-27 17:31 - 2017-07-27 17:31 - 000000000 ____D C:\Users\user\Documents\caisse épargne 2
2017-07-27 17:30 - 2017-07-27 17:34 - 000000000 ____D C:\Users\user\Desktop\caisee épargne
2017-07-27 17:30 - 2017-07-27 17:30 - 000000000 ____D C:\Users\user\Documents\caisse épargne 1
2017-07-26 17:37 - 2017-07-26 17:37 - 000002135 _____ C:\Users\user\Desktop\Microsoft Security Essentials.lnk
2017-07-25 15:15 - 2017-07-26 19:13 - 000001540 _____ C:\Users\user\Desktop\Skype.lnk
2017-07-25 15:04 - 2017-07-25 15:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-07-25 11:50 - 2017-07-25 11:50 - 000000128 _____ C:\Users\user\Desktop\12 utilisations méconnues des bouchons de bouteille - Pagina 10 di 10 - Astuces Express.url
2017-07-22 16:45 - 2017-07-22 17:00 - 000001837 _____ C:\Users\user\Desktop\RIB jean-Louis caisse épargne - Raccourci.lnk
2017-07-22 11:27 - 2017-07-22 11:27 - 000482005 _____ C:\Users\user\Desktop\tarifs-juillet-2017-b caisse épargne.pdf
2017-07-21 18:29 - 2017-08-03 10:19 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-07-21 18:29 - 2017-07-21 18:35 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-07-21 18:29 - 2017-07-21 18:29 - 000000000 ____D C:\Program Files (x86)\Adobe
2017-07-21 10:51 - 2017-07-25 15:04 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-07-21 10:49 - 2017-07-21 10:49 - 000001219 _____ C:\Users\user\Desktop\skype3 - Raccourci.lnk
2017-07-21 10:46 - 2017-08-08 17:15 - 000000000 ____D C:\Users\user\AppData\Roaming\Skype
2017-07-20 16:19 - 2017-08-08 06:50 - 000000000 ____D C:\ProgramData\Skype
2017-07-20 16:10 - 2017-07-20 16:12 - 000000000 ____D C:\Users\user\Desktop\Skype2
2017-07-20 15:58 - 2017-07-20 15:58 - 000000000 ____D C:\MATS
2017-07-20 10:44 - 2017-07-20 10:44 - 000000000 ____D C:\ProgramData\ABBYY
2017-07-20 10:01 - 2017-07-20 10:01 - 000000000 ____D C:\ProgramData\Wondershare
2017-07-20 09:57 - 2017-07-20 11:01 - 000000000 ____D C:\Users\user\AppData\Roaming\Wondershare
2017-07-20 09:56 - 2017-07-20 09:58 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2017-07-20 08:55 - 2017-07-20 09:05 - 000012800 ___SH C:\Users\user\Documents\Thumbs.db
2017-07-14 07:33 - 2017-07-14 07:33 - 000003274 _____ C:\Windows\System32\Tasks\00, notes 1
2017-07-12 06:32 - 2017-07-06 06:56 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthpan.sys
2017-07-12 06:32 - 2017-06-30 06:15 - 000394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-07-12 06:32 - 2017-06-30 05:32 - 000346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-07-12 06:32 - 2017-06-30 04:57 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-07-12 06:32 - 2017-06-30 04:40 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-07-12 06:32 - 2017-06-30 04:40 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-07-12 06:32 - 2017-06-30 04:39 - 001549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-07-12 06:32 - 2017-06-30 04:39 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-07-12 06:32 - 2017-06-30 04:38 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-07-12 06:32 - 2017-06-30 04:38 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-07-12 06:32 - 2017-06-30 04:38 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-07-12 06:32 - 2017-06-30 04:38 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-07-12 06:32 - 2017-06-30 04:38 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-07-12 06:32 - 2017-06-30 04:38 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-07-12 06:32 - 2017-06-30 04:38 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-07-12 06:32 - 2017-06-30 04:38 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-07-12 06:32 - 2017-06-30 04:27 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-07-12 06:32 - 2017-06-30 04:27 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-07-12 06:32 - 2017-06-30 04:26 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-07-12 06:32 - 2017-06-30 04:26 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-07-12 06:32 - 2017-06-29 08:27 - 025734656 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-07-12 06:32 - 2017-06-29 08:19 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-07-12 06:32 - 2017-06-29 08:18 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-07-12 06:32 - 2017-06-29 08:04 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-07-12 06:32 - 2017-06-29 08:03 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-07-12 06:32 - 2017-06-29 08:03 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-07-12 06:32 - 2017-06-29 08:02 - 002899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-07-12 06:32 - 2017-06-29 08:02 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-07-12 06:32 - 2017-06-29 08:02 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-07-12 06:32 - 2017-06-29 07:55 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-07-12 06:32 - 2017-06-29 07:54 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-07-12 06:32 - 2017-06-29 07:51 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-07-12 06:32 - 2017-06-29 07:50 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-07-12 06:32 - 2017-06-29 07:50 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-07-12 06:32 - 2017-06-29 07:50 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-07-12 06:32 - 2017-06-29 07:50 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-07-12 06:32 - 2017-06-29 07:44 - 005975552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-07-12 06:32 - 2017-06-29 07:43 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-07-12 06:32 - 2017-06-29 07:39 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-07-12 06:32 - 2017-06-29 07:35 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-07-12 06:32 - 2017-06-29 07:31 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-07-12 06:32 - 2017-06-29 07:31 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-07-12 06:32 - 2017-06-29 07:30 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-07-12 06:32 - 2017-06-29 07:27 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-07-12 06:32 - 2017-06-29 07:26 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-07-12 06:32 - 2017-06-29 07:23 - 020270592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-07-12 06:32 - 2017-06-29 07:23 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-07-12 06:32 - 2017-06-29 07:23 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-07-12 06:32 - 2017-06-29 07:23 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-07-12 06:32 - 2017-06-29 07:23 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-07-12 06:32 - 2017-06-29 07:22 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-07-12 06:32 - 2017-06-29 07:22 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-07-12 06:32 - 2017-06-29 07:22 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-07-12 06:32 - 2017-06-29 07:19 - 002290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-07-12 06:32 - 2017-06-29 07:17 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-07-12 06:32 - 2017-06-29 07:16 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-07-12 06:32 - 2017-06-29 07:14 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-07-12 06:32 - 2017-06-29 07:13 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-07-12 06:32 - 2017-06-29 07:13 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-07-12 06:32 - 2017-06-29 07:13 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-07-12 06:32 - 2017-06-29 07:11 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-07-12 06:32 - 2017-06-29 07:09 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-07-12 06:32 - 2017-06-29 07:09 - 000725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-07-12 06:32 - 2017-06-29 07:08 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-07-12 06:32 - 2017-06-29 07:07 - 002132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-07-12 06:32 - 2017-06-29 07:05 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-07-12 06:32 - 2017-06-29 07:01 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-07-12 06:32 - 2017-06-29 07:00 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-07-12 06:32 - 2017-06-29 07:00 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-07-12 06:32 - 2017-06-29 06:58 - 015253504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-07-12 06:32 - 2017-06-29 06:58 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-07-12 06:32 - 2017-06-29 06:56 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-07-12 06:32 - 2017-06-29 06:56 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-07-12 06:32 - 2017-06-29 06:54 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-07-12 06:32 - 2017-06-29 06:53 - 003240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-07-12 06:32 - 2017-06-29 06:52 - 004549632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-07-12 06:32 - 2017-06-29 06:48 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-07-12 06:32 - 2017-06-29 06:47 - 000693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-07-12 06:32 - 2017-06-29 06:46 - 002057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-07-12 06:32 - 2017-06-29 06:46 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-07-12 06:32 - 2017-06-29 06:43 - 013663744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-07-12 06:32 - 2017-06-29 06:41 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-07-12 06:32 - 2017-06-29 06:29 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-07-12 06:32 - 2017-06-29 06:28 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-07-12 06:32 - 2017-06-29 06:24 - 001314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-07-12 06:32 - 2017-06-29 06:23 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-07-12 06:32 - 2017-06-22 16:58 - 003223040 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-07-12 06:32 - 2017-06-15 22:23 - 000753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-07-12 06:32 - 2017-06-13 00:54 - 000370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-07-12 06:32 - 2017-06-13 00:54 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-07-12 06:32 - 2017-06-13 00:54 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-07-12 06:32 - 2017-06-13 00:49 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 001363456 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000475136 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2017-07-12 06:32 - 2017-06-13 00:49 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-07-12 06:32 - 2017-06-13 00:49 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-07-12 06:32 - 2017-06-13 00:29 - 001227264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-07-12 06:32 - 2017-06-13 00:29 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-07-12 06:32 - 2017-06-13 00:29 - 000444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2017-07-12 06:32 - 2017-06-13 00:29 - 000390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2017-07-12 06:32 - 2017-06-13 00:29 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-07-12 06:32 - 2017-06-13 00:29 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-07-12 06:32 - 2017-06-13 00:29 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-07-12 06:32 - 2017-06-13 00:29 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-07-12 06:32 - 2017-06-13 00:28 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-07-12 06:32 - 2017-06-13 00:19 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-07-12 06:32 - 2017-06-13 00:14 - 000379392 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2017-07-12 06:32 - 2017-06-13 00:14 - 000172544 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2017-07-12 06:32 - 2017-06-13 00:14 - 000103936 _____ (Microsoft Corporation) C:\Windows\system32\resmon.exe
2017-07-12 06:32 - 2017-06-13 00:12 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-07-12 06:32 - 2017-06-13 00:12 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-07-12 06:32 - 2017-06-13 00:12 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-07-12 06:32 - 2017-06-13 00:11 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-07-12 06:32 - 2017-06-13 00:09 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-07-12 06:32 - 2017-06-13 00:06 - 000303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2017-07-12 06:32 - 2017-06-13 00:06 - 000157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe
2017-07-12 06:32 - 2017-06-13 00:06 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resmon.exe
2017-07-12 06:32 - 2017-06-13 00:05 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-07-12 06:32 - 2017-06-10 17:59 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-07-12 06:32 - 2017-06-10 17:39 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-07-12 06:32 - 2017-06-09 17:33 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-07-12 06:32 - 2017-06-06 17:30 - 001867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-07-12 06:32 - 2017-06-06 17:12 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-07-12 06:32 - 2017-05-30 06:56 - 001895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-07-12 06:32 - 2017-05-30 06:56 - 000377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-07-12 06:32 - 2017-05-30 06:56 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2017-08-08 15:25 - 2017-01-04 10:55 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-08-08 15:25 - 2017-01-04 10:55 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-08-08 15:25 - 2017-01-04 10:55 - 000004484 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-08-08 15:25 - 2017-01-04 10:55 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-08-08 15:25 - 2017-01-04 10:55 - 000000000 ____D C:\Windows\system32\Macromed
2017-08-08 15:03 - 2011-04-12 11:16 - 000748608 _____ C:\Windows\system32\perfh00C.dat
2017-08-08 15:03 - 2011-04-12 11:16 - 000150598 _____ C:\Windows\system32\perfc00C.dat
2017-08-08 15:03 - 2009-07-14 07:13 - 001671678 _____ C:\Windows\system32\PerfStringBackup.INI
2017-08-08 15:03 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2017-08-08 14:38 - 2009-07-14 06:45 - 000031904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-08-08 14:38 - 2009-07-14 06:45 - 000031904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-08-08 14:30 - 2009-07-14 07:08 - 000032482 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-08-08 14:30 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-08-08 11:47 - 2017-01-31 12:30 - 000000008 __RSH C:\ProgramData\ntuser.pol
2017-08-08 11:45 - 2017-06-03 09:06 - 000000000 ____D C:\Users\user\AppData\LocalLow\Temp
2017-08-08 11:45 - 2009-07-14 05:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2017-08-08 07:39 - 2017-02-04 08:42 - 000000000 ____D C:\Users\user\AppData\Roaming\ZHP
2017-08-08 07:25 - 2017-04-11 15:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-08-08 07:25 - 2017-02-11 07:49 - 000252832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-08-08 07:15 - 2017-05-10 11:03 - 000000000 ____D C:\AdwCleaner
2017-08-07 21:02 - 2017-06-14 19:56 - 000002211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-07 21:02 - 2017-06-14 19:56 - 000002199 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-04 07:03 - 2017-01-11 13:32 - 000000000 ____D C:\ProgramData\Lx_cats
2017-08-01 18:56 - 2017-02-04 07:52 - 000002396 _____ C:\Users\user\Downloads\ccleaner.ini
2017-07-28 18:28 - 2017-01-11 12:37 - 000000000 ____D C:\Users\user\AppData\Local\ElevatedDiagnostics
2017-07-28 12:41 - 2017-04-29 10:36 - 000000000 ____D C:\Users\user\AppData\Local\ZHP
2017-07-25 15:00 - 2017-03-26 11:12 - 000000000 ____D C:\Windows\system32\appmgmt
2017-07-24 12:03 - 2017-01-17 19:35 - 000000000 ____D C:\Users\user\AppData\Roaming\Skype4 date 24.07
2017-07-21 18:32 - 2017-01-04 10:54 - 000000000 ____D C:\Users\user\AppData\Local\Adobe
2017-07-20 16:30 - 2017-05-06 18:06 - 000000000 ____D C:\Users\user\AppData\Roaming\vlc
2017-07-20 15:54 - 2017-02-14 08:22 - 000000000 ____D C:\Program Files (x86)\Emjysoft
2017-07-20 14:18 - 2009-07-14 06:45 - 000272024 _____ C:\Windows\system32\FNTCACHE.DAT
2017-07-20 10:01 - 2017-01-03 16:15 - 000059808 _____ C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
2017-07-20 08:04 - 2017-05-06 18:05 - 000000510 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-07-13 15:30 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\rescache
2017-07-13 02:08 - 2017-01-03 17:29 - 000000000 ____D C:\Windows\system32\MRT
2017-07-13 02:07 - 2017-01-03 17:29 - 135225752 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Fichiers à la racine de certains dossiers =======

2010-02-28 11:13 - 2017-01-04 00:21 - 009360555 _____ (WordAddin Studio ) C:\Program Files (x86)\SVCRGD15.exe
2017-01-11 12:52 - 2017-01-11 12:52 - 000000000 _____ () C:\ProgramData\cmn_upld.log
2017-01-11 15:00 - 2017-01-11 15:00 - 000000110 _____ () C:\ProgramData\Coinstaller.log
2017-01-11 13:32 - 2017-05-10 08:19 - 000000756 _____ () C:\ProgramData\FastPics.log
2017-01-11 13:32 - 2017-05-10 07:42 - 000000525 _____ () C:\ProgramData\lxeb.log
2017-05-02 15:57 - 2017-05-02 16:01 - 000000309 _____ () C:\ProgramData\lxebDiagnostics.log
2017-01-11 15:02 - 2017-08-04 07:03 - 000081614 _____ () C:\ProgramData\lxebJSW.log
2017-01-11 12:56 - 2017-08-08 15:05 - 000041518 _____ () C:\ProgramData\lxebscan.log
2017-01-11 12:52 - 2017-01-11 12:52 - 000000000 _____ () C:\ProgramData\LxWbGwLog.log
2017-01-11 12:51 - 2017-01-11 12:51 - 000000000 _____ () C:\ProgramData\UpdaterLog.txt

Fichiers à déplacer ou supprimer:
====================
C:\Users\user\wdsutil.dll


==================== Bamital & volsnap ======================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement
C:\Windows\system32\wininit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement
C:\Windows\explorer.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\Windows\system32\svchost.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\Windows\system32\services.exe => Le fichier est signé numériquement
C:\Windows\system32\User32.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\Windows\system32\userinit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement
C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

LastRegBack: 2017-08-01 20:29

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité