Format du document : text/plain
Prévisualisation
Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 17-09-2017 01
Exécuté par sternouille (administrateur) sur STERNA (18-09-2017 19:03:27)
Exécuté depuis C:\Users\sternouille\Desktop
Profils chargés: sternouille (Profils disponibles: sternouille)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Langue: Français (France)
Internet Explorer Version 10 (Navigateur par défaut: "C:\icedragon\Comodo\IceDragon\icedragon.exe" -osint -url "%1")
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processus (Avec liste blanche) =================
(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Rene.E Laboratory) C:\Program Files (x86)\Rene.E Laboratory\Becca\x64\bcservice.exe
(Camshare Inc.) E:\dossier d instalation\camfrog\update\cf_update_service.exe
() C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
() C:\Program Files (x86)\No-IP\ducservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Dashlane, Inc.) C:\Users\sternouille\AppData\Roaming\Dashlane\DashlanePlugin.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
() C:\Program Files (x86)\DocFetcher\docfetcher-daemon-windows.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dashlane, Inc.) C:\Users\sternouille\AppData\Roaming\Dashlane\Dashlane.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registre (Avec liste blanche) ====================
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1489088 2017-09-17] (COMODO)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [186408 2013-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DocFetcher-Daemon] => C:\Program Files (x86)\DocFetcher\docfetcher-daemon-windows.exe [563621 2017-05-27] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-03] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1237048931-779808844-1748554049-1000\...\Run: [VPSKEYS] => C:\Program Files (x86)\Vpskeys\vpskeys.exe [102400 2003-03-29] (Hoi Chuyen Gia Viet Nam)
HKU\S-1-5-21-1237048931-779808844-1748554049-1000\...\Run: [DVSSkypeRecorder] => C:\Program Files (x86)\DVDVideoSoft\Free Video Call Recorder for Skype\skyui.exe [1028264 2014-06-06] (DVDVideoSoft Ltd.)
HKU\S-1-5-21-1237048931-779808844-1748554049-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1237048931-779808844-1748554049-1000\...\Run: [Viber] => C:\Users\sternouille\AppData\Local\Viber\Viber.exe [30797904 2017-09-13] (Viber Media S.Ã r.l.)
HKU\S-1-5-21-1237048931-779808844-1748554049-1000\...\Run: [C874335D7CF63340FCE43A591A7E2B77AD2EFF55._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1301848 2017-09-17] (Google Inc.)
HKU\S-1-5-21-1237048931-779808844-1748554049-1000\...\Run: [DashlanePlugin] => C:\Users\sternouille\AppData\Roaming\Dashlane\DashlanePlugin.exe [552400 2017-09-12] (Dashlane, Inc.)
HKU\S-1-5-21-1237048931-779808844-1748554049-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8686296 2016-03-11] (Piriform Ltd)
IFEO\DisplaySwitch.exe: [Debugger]
IFEO\taskmgr.exe: [Debugger]
==================== Internet (Avec liste blanche) ====================
(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)
Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{6B24D73F-9BF8-48C1-BDCF-70B9AC4FC964}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{BF6FAABB-B2B1-4079-B8E6-189C2D56DFA0}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{EB4CAF99-720D-4110-AA40-AFDE41FA916A}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{EB4CAF99-720D-4110-AA40-AFDE41FA916A}: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{F3499C4F-27B1-4DDA-83AC-B6686994445C}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{FB323203-0031-471F-BCC3-3D792FF7A124}: [NameServer] 8.8.8.8
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-1237048931-779808844-1748554049-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://fr.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-1237048931-779808844-1748554049-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1237048931-779808844-1748554049-1000 -> {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-09-03] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-09-03] (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-07-18] (Skype Technologies)
FireFox:
========
FF DefaultProfile: sternouille@yahoo.fr
FF ProfilePath: C:\Users\sternouille\AppData\Roaming\Comodo\IceDragon\Profiles\fogdacis.default [2017-09-18]
FF DefaultSearchEngine: Comodo\IceDragon\Profiles\fogdacis.default -> Yahoo! FR
FF SelectedSearchEngine: Comodo\IceDragon\Profiles\fogdacis.default -> Yahoo
FF Homepage: Comodo\IceDragon\Profiles\fogdacis.default -> hxxps://fr.yahoo.com/?fr=fp-comodo&type=25050004003_id_hp
FF Keyword.URL: Comodo\IceDragon\Profiles\fogdacis.default -> hxxp://fr.search.yahoo.com/search?fr=ytff-comodo&p=
FF NetworkProxy: Comodo\IceDragon\Profiles\fogdacis.default -> type", 0
FF Extension: (Itineraire - Offres shopping) - C:\Users\sternouille\AppData\Roaming\Comodo\IceDragon\Profiles\fogdacis.default\Extensions\application@itineraire.info.xpi [2017-08-13]
FF Extension: (PrivDog) - C:\Users\sternouille\AppData\Roaming\Comodo\IceDragon\Profiles\fogdacis.default\Extensions\IcePrivDog@AdTrustMedia.com [2014-02-02] [non signé]
FF Extension: (PrivDog) - C:\Users\sternouille\AppData\Roaming\Comodo\IceDragon\Profiles\fogdacis.default\Extensions\IcePrivDog@AdTrustMedia.com.xpi [2014-06-19] [non signé]
FF Extension: (COMODO IceDragon Language Pack) - C:\Users\sternouille\AppData\Roaming\Comodo\IceDragon\Profiles\fogdacis.default\Extensions\langpack@firefox.mozilla.org.xpi [2014-01-20] [non signé]
FF Extension: (COMODO SecureBox) - C:\Program Files (x86)\Comodo\IceDragon\browser\features\@csb [2017-05-30] [non signé]
FF Extension: (DragAndDrop) - C:\Program Files (x86)\Comodo\IceDragon\browser\features\DnD@comodo.com [2017-05-30] [non signé]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll [2014-01-18] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll [2014-01-18] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-09-03] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-09-03] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-08-18] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.ourluckysites.com/?type=hp&ts=1493980482&z=4be8f4df01ecfb68e4482e4g5z8t1c6t2bbe9zcbde&from=che0812&uid=ST1000DM003-1CH162_S1DDBTJQXXXXS1DDBTJQ
CHR StartupUrls: Default -> "hxxp://www.ourluckysites.com/?type=hp&ts=1493980482&z=4be8f4df01ecfb68e4482e4g5z8t1c6t2bbe9zcbde&from=che0812&uid=ST1000DM003-1CH162_S1DDBTJQXXXXS1DDBTJQ"
CHR DefaultSearchURL: Default -> hxxp://www.ourluckysites.com/search/?type=ds&ts=1493980482&z=4be8f4df01ecfb68e4482e4g5z8t1c6t2bbe9zcbde&from=che0812&uid=ST1000DM003-1CH162_S1DDBTJQXXXXS1DDBTJQ&q={searchTerms}
CHR DefaultSearchKeyword: Default -> ourluckysites
CHR Profile: C:\Users\sternouille\AppData\Local\Google\Chrome\User Data\Default [2017-09-18]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\sternouille\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-17]
CHR Extension: (Chrome Media Router) - C:\Users\sternouille\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-17]
==================== Services (Avec liste blanche) ====================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R2 Becca Service; C:\Program Files (x86)\Rene.E Laboratory\Becca\x64\bcservice.exe [71152 2017-01-07] (Rene.E Laboratory)
R2 camfrog_update_service; E:\dossier d instalation\camfrog\update\cf_update_service.exe [1063968 2016-06-15] (Camshare Inc.)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [10501616 2017-09-17] (COMODO)
R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2876096 2017-09-17] (COMODO)
S3 HmaOpenVpnService; C:\Program Files (x86)\HMA! Pro VPN\bin\openvpnserv.exe [38912 2017-05-02] (The OpenVPN Project)
R2 IceDragonUpdater; C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe [4295328 2017-05-24] ()
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)
R2 NoIPDUCService4; C:\Program Files (x86)\No-IP\ducservice.exe [12288 2017-04-20] () [Fichier non signé]
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Fichier non signé]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7032080 2016-07-04] (TeamViewer GmbH)
S3 vncserver; C:\Program Files\RealVNC\VNC Server\vncserver.exe [5663824 2016-06-06] (RealVNC Ltd)
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 OneDriverSvc; C:\ProgramData\Microsoft OneNote\Updates\Check\verchk.dll [X]
===================== Pilotes (Avec liste blanche) ======================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2013-06-02] (Wondershare)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [31664 2017-08-08] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [844584 2017-08-08] (COMODO)
R3 DroidCam; C:\Windows\System32\DRIVERS\droidcam.sys [33592 2016-09-24] (Dev47Apps)
R3 DroidCamVideo; C:\Windows\System32\DRIVERS\droidcamvideo.sys [229432 2016-09-24] (Dev47Apps)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-08-31] (Disc Soft Ltd)
R3 hmatap; C:\Windows\System32\DRIVERS\hmatap.sys [45312 2017-05-02] (The OpenVPN Project)
R3 jakstaVA; C:\Windows\System32\DRIVERS\jaksta_va.sys [103816 2014-12-09] (e2eSoft)
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
==================== Un mois - Créés - fichiers et dossiers ========
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2017-09-18 19:03 - 2017-09-18 19:03 - 000016779 _____ C:\Users\sternouille\Desktop\FRST.txt
2017-09-18 18:59 - 2017-09-18 18:59 - 002399744 _____ (Farbar) C:\Users\sternouille\Desktop\FRST64.exe
2017-09-18 16:40 - 2017-09-18 17:09 - 000000155 _____ C:\Users\sternouille\Desktop\cnet.txt
2017-09-18 16:20 - 2017-09-18 16:20 - 000001688 _____ C:\Users\sternouille\Desktop\ZHPFixReport.txt
2017-09-18 16:18 - 2017-09-18 16:18 - 000000000 ____D C:\Users\sternouille\Desktop\Quarantine
2017-09-18 16:14 - 2017-09-18 16:14 - 003067264 _____ (Nicolas Coolman) C:\Users\sternouille\Desktop\zhpfix_2017-6-13-1.exe
2017-09-17 18:08 - 2017-09-18 17:10 - 000253888 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-09-17 18:08 - 2017-09-17 18:23 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-09-17 18:08 - 2017-09-17 18:23 - 000045472 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-09-17 18:08 - 2017-09-17 18:12 - 000192960 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-09-17 18:08 - 2017-09-17 18:12 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-09-17 18:08 - 2017-09-17 18:08 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-09-17 18:08 - 2017-09-17 18:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-09-17 18:08 - 2017-09-17 18:08 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-09-17 18:08 - 2017-09-17 18:08 - 000000000 ____D C:\Program Files\Malwarebytes
2017-09-17 17:46 - 2017-09-17 20:27 - 000000000 ____D C:\Program Files (x86)\DuJJwz9buz
2017-09-17 17:46 - 2017-09-17 17:55 - 000000002 _____ C:\END
2017-09-17 17:38 - 2017-09-17 17:47 - 000000000 ____D C:\Users\sternouille\AppData\Local\Viber
2017-09-17 17:02 - 2017-09-17 17:26 - 000045044 _____ C:\Users\sternouille\Desktop\ZHPCleaner.txt
2017-09-17 16:49 - 2017-09-18 16:29 - 002840448 _____ C:\Users\sternouille\Desktop\zhpdiag_2017.9.13.157.exe
2017-09-17 16:45 - 2017-09-17 16:46 - 065942208 _____ (Malwarebytes ) C:\Users\sternouille\Desktop\mb3-setup-35891.35891-3.2.2.2018.exe
2017-09-17 16:44 - 2017-09-17 16:44 - 008182736 _____ (Malwarebytes) C:\Users\sternouille\Desktop\adwcleaner_7.0.2.1.exe
2017-09-17 16:25 - 2017-09-17 16:25 - 002882432 _____ C:\Users\sternouille\Desktop\zhpcleaner_2017.9.13.157.exe
2017-09-17 11:35 - 2017-09-18 19:03 - 000000000 ____D C:\FRST
2017-09-17 09:38 - 2017-09-17 17:50 - 000003464 _____ C:\Windows\System32\Tasks\Xl5jVVxcVWIx
2017-09-16 19:04 - 2017-09-17 16:29 - 000000000 ____D C:\Users\sternouille\AppData\Local\ZHP
2017-09-16 18:09 - 2017-09-18 17:05 - 000000000 ____D C:\Users\sternouille\Desktop\diagnostic
2017-09-14 14:34 - 2017-09-14 14:59 - 000000000 ____D C:\Users\sternouille\AppData\LocalLow\uTorrent
2017-09-14 09:46 - 2017-09-14 12:30 - 000000000 ____D C:\Users\sternouille\Desktop\thao
2017-09-12 13:46 - 2017-09-12 13:46 - 000000000 ____D C:\Users\sternouille\Desktop\google chrome
2017-09-12 01:31 - 2017-09-12 01:31 - 000000000 ____D C:\Users\sternouille\AppData\Local\Geckofx
2017-09-12 01:29 - 2017-09-18 16:19 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\1337
2017-09-12 01:29 - 2017-09-17 19:25 - 000000000 ____D C:\Program Files (x86)\Widget 1.2
2017-09-12 01:19 - 2017-09-17 17:32 - 000000000 ____D C:\Program Files (x86)\O3wigRykxYJX Updater
2017-09-12 01:19 - 2017-09-12 01:19 - 000021536 _____ C:\Windows\System32\Tasks\O3wigRykxYJX
2017-09-10 02:06 - 2017-09-12 01:26 - 000803840 _____ C:\Windows\9e49066e4005b14faa9020c7ffc49a45.exe
2017-09-10 02:06 - 2017-09-10 02:06 - 000051639 _____ C:\Windows\uninstaller.dat
2017-09-04 20:35 - 2017-09-04 21:15 - 000012113 _____ C:\Users\sternouille\Desktop\test.mcv
2017-09-03 11:47 - 2017-09-03 11:47 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\Sun
2017-09-03 11:47 - 2015-05-10 22:52 - 000111016 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-64.dll
2017-09-03 11:45 - 2017-09-03 11:45 - 000738368 _____ (Oracle Corporation) C:\Users\sternouille\jxpiinstall.exe
2017-09-02 17:13 - 2017-09-02 17:13 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\dvdcss
2017-09-01 00:41 - 2017-09-01 05:37 - 000000000 ____D C:\Users\sternouille\Desktop\l imposteur amine mojito
2017-08-29 08:40 - 2017-09-01 00:51 - 000000000 ____D C:\Users\sternouille\Desktop\afrique
2017-08-28 05:24 - 2017-08-28 05:24 - 000001855 _____ C:\Users\sternouille\Desktop\Kodi.lnk
2017-08-28 05:08 - 2017-09-17 20:58 - 000000000 ____D C:\kodi
2017-08-28 00:33 - 2017-08-28 00:34 - 000000550 _____ C:\Users\sternouille\Desktop\repository.colossus-999.999.1.zip
2017-08-27 20:48 - 2017-08-27 20:49 - 000038287 _____ C:\Users\sternouille\Desktop\script.module.f4mproxy-1.0.16.zip
2017-08-27 20:31 - 2017-09-17 21:43 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\Kodi
2017-08-27 20:30 - 2017-08-27 20:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodi
2017-08-27 20:28 - 2017-08-27 20:30 - 000000000 ____D C:\Program Files (x86)\Kodi
2017-08-27 20:24 - 2017-08-27 20:24 - 001086754 _____ C:\Users\sternouille\Desktop\instal.zip
2017-08-27 20:22 - 2017-08-27 20:25 - 081790517 _____ (XBMC-Foundation) C:\Users\sternouille\Desktop\kodi-17.4-Krypton-x86.exe
2017-08-20 21:10 - 2017-08-20 21:11 - 000000000 ____D C:\Users\sternouille\Desktop\kyste
==================== Un mois - Modifiés - fichiers et dossiers ========
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2017-09-18 19:00 - 2016-12-24 15:12 - 000000000 ____D C:\Users\sternouille\AppData\LocalLow\Mozilla
2017-09-18 19:00 - 2015-08-13 19:11 - 000411436 _____ C:\Windows\system32\Drivers\fvstore.dat
2017-09-18 17:09 - 2014-01-18 18:08 - 000000674 _____ C:\Windows\Tasks\hpwebreg_CN2BS1FRKK05YC.job
2017-09-18 16:51 - 2009-07-14 06:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-18 16:51 - 2009-07-14 06:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-18 16:48 - 2017-02-18 21:19 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\ZHP
2017-09-18 16:46 - 2017-02-18 21:19 - 000000824 _____ C:\Users\sternouille\Desktop\ZHPDiag.lnk
2017-09-18 16:44 - 2014-09-30 12:15 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\ViberPC
2017-09-18 16:42 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-18 16:19 - 2017-05-27 20:50 - 000000000 ____D C:\Program Files (x86)\DocFetcher
2017-09-18 06:55 - 2014-01-18 21:57 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\vlc
2017-09-18 02:00 - 2014-01-18 22:35 - 000000000 ____D C:\Users\sternouille\AppData\Local\Adobe
2017-09-17 21:35 - 2014-01-18 19:22 - 000000000 ____D C:\Windows\System32\Tasks\COMODO
2017-09-17 21:33 - 2014-01-18 18:53 - 000000000 ____D C:\ProgramData\COMODO
2017-09-17 21:32 - 2011-04-12 11:16 - 000942434 _____ C:\Windows\system32\perfh00C.dat
2017-09-17 21:32 - 2011-04-12 11:16 - 000266356 _____ C:\Windows\system32\perfc00C.dat
2017-09-17 20:27 - 2017-05-04 16:23 - 000000000 ____D C:\Users\sternouille\AppData\Local\background_fault
2017-09-17 20:27 - 2017-02-28 01:23 - 000000000 ____D C:\Program Files (x86)\ScreenShot
2017-09-17 20:10 - 2017-04-17 16:08 - 000002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-09-17 20:10 - 2017-04-17 16:08 - 000002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-09-17 19:25 - 2014-03-02 14:04 - 000000000 ____D C:\Program Files\CamStudio 2.7
2017-09-17 17:40 - 2017-02-17 10:49 - 000000000 ____D C:\AdwCleaner
2017-09-17 17:37 - 2014-09-30 12:21 - 000000000 ____D C:\Users\sternouille\Documents\ViberDownloads
2017-09-17 17:20 - 2017-04-17 16:07 - 000000000 ____D C:\Program Files (x86)\MIO
2017-09-17 17:20 - 2015-10-01 00:35 - 000000659 _____ C:\Users\sternouille\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet-Explorer.lnk
2017-09-16 19:43 - 2014-02-19 15:44 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\Skype
2017-09-14 15:00 - 2014-11-12 16:21 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\uTorrent
2017-09-13 15:12 - 2009-07-14 07:13 - 001815370 _____ C:\Windows\system32\PerfStringBackup.INI
2017-09-13 15:12 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2017-09-12 12:28 - 2016-05-03 21:58 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\Dashlane
2017-09-12 12:27 - 2016-05-03 22:04 - 000001927 _____ C:\Users\sternouille\Desktop\Dashlane.lnk
2017-09-12 12:27 - 2016-05-03 21:58 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane
2017-09-11 14:02 - 2017-02-28 01:25 - 000000000 ____D C:\Users\sternouille\AppData\Local\JDownloader v2.0
2017-09-09 05:59 - 2015-12-08 21:52 - 000000132 _____ C:\Users\sternouille\AppData\Roaming\Préfs Format PNG Adobe CS6
2017-09-07 14:51 - 2017-07-15 21:51 - 000000000 ____D C:\Users\sternouille\Desktop\captvty-2.6
2017-09-06 17:47 - 2017-03-02 15:38 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-09-06 17:47 - 2014-02-19 15:44 - 000000000 ____D C:\ProgramData\Skype
2017-09-03 11:55 - 2014-04-19 15:51 - 000000000 ____D C:\Program Files (x86)\Java
2017-09-03 11:54 - 2015-05-10 22:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2017-09-03 11:54 - 2014-04-19 15:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-09-03 11:47 - 2014-04-19 15:52 - 000097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2017-09-03 11:45 - 2014-01-18 17:33 - 000000000 ____D C:\Users\sternouille
2017-09-03 11:42 - 2015-09-28 05:55 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\DocFetcher
2017-09-02 17:12 - 2014-08-31 16:05 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\DAEMON Tools Lite
2017-09-02 14:12 - 2014-02-24 12:46 - 000000000 ____D C:\Users\sternouille\AppData\Roaming\avidemux
2017-08-29 06:59 - 2013-11-14 12:38 - 000051808 _____ (COMODO) C:\Windows\system32\cmdcsr.dll
2017-08-29 06:59 - 2013-09-24 11:53 - 000939144 _____ (COMODO) C:\Windows\system32\guard64.dll
2017-08-29 06:59 - 2013-09-24 11:53 - 000731344 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll
2017-08-29 06:57 - 2013-09-24 11:53 - 000457408 _____ (COMODO) C:\Windows\system32\cmdvrt64.dll
2017-08-29 06:55 - 2013-09-24 11:53 - 000363712 _____ (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll
==================== Fichiers à la racine de certains dossiers =======
2012-12-22 08:13 - 2012-12-22 08:13 - 002174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2015-06-30 14:07 - 2015-07-01 15:05 - 000000576 _____ () C:\Users\sternouille\AppData\Roaming\burnaware.ini
2014-03-02 16:45 - 2016-01-18 03:34 - 000000096 _____ () C:\Users\sternouille\AppData\Roaming\Camdata.ini
2014-03-02 16:45 - 2016-01-18 03:34 - 000000408 _____ () C:\Users\sternouille\AppData\Roaming\CamLayout.ini
2014-03-02 16:45 - 2016-01-18 03:34 - 000000408 _____ () C:\Users\sternouille\AppData\Roaming\CamShapes.ini
2014-03-02 16:45 - 2016-01-18 03:34 - 000004535 _____ () C:\Users\sternouille\AppData\Roaming\CamStudio.cfg
2015-11-24 17:22 - 2015-11-24 17:22 - 000005120 _____ () C:\Users\sternouille\AppData\Roaming\GiftBag.db
2016-12-25 21:54 - 2016-12-26 03:17 - 000000132 _____ () C:\Users\sternouille\AppData\Roaming\Préfs Format GIF Adobe CS6
2015-12-08 21:52 - 2017-09-09 05:59 - 000000132 _____ () C:\Users\sternouille\AppData\Roaming\Préfs Format PNG Adobe CS6
2014-03-02 14:05 - 2016-01-18 03:34 - 000000096 _____ () C:\Users\sternouille\AppData\Roaming\version2.xml
2015-11-04 20:25 - 2017-08-13 01:43 - 000001456 _____ () C:\Users\sternouille\AppData\Local\Adobe Enregistrer pour le Web 13.0 Prefs
2014-02-26 18:14 - 2017-08-03 10:10 - 000007168 _____ () C:\Users\sternouille\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-15 17:37 - 2014-07-15 17:37 - 000000000 _____ () C:\Users\sternouille\AppData\Local\{0AD8B854-49B2-49E6-8815-0F06E0DCB329}
2016-09-24 01:48 - 2016-09-24 01:55 - 000000034 _____ () C:\ProgramData\droidcam-settings
Fichiers à déplacer ou supprimer:
====================
C:\Users\sternouille\drw_free.exe
C:\Users\sternouille\HMA-Pro-VPN-3.2.19.2-install.exe
C:\Users\sternouille\jxpiinstall.exe
C:\Users\sternouille\rcsetup153.exe
==================== Bamital & volsnap ======================
(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)
C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement
C:\Windows\system32\wininit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement
C:\Windows\explorer.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\Windows\system32\svchost.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\Windows\system32\services.exe => Le fichier est signé numériquement
C:\Windows\system32\User32.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\Windows\system32\userinit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement
C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement
LastRegBack: 2017-09-10 15:51
==================== Fin de FRST.txt ============================