cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 17-12-2017
Exécuté par fabienne (administrateur) sur DESKTOP-1637DL5 (20-12-2017 18:33:14)
Exécuté depuis C:\Users\fabienne\Desktop
Profils chargés: fabienne (Profils disponibles: defaultuser0 & fabienne)
Platform: Windows 10 Enterprise Version 1607 14393.1944 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16404224 2015-09-17] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)
HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2197608 2017-06-07] ()
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-28] (Microsoft Corporation)
HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [11340752 2016-07-19] (Micro-Star INT'L CO., LTD.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2406496 2017-06-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2138272 2016-10-08] (iSkySoft)
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9818328 2017-06-30] (Piriform Ltd)
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\Run: [f.lux] => C:\Users\fabienne\AppData\Local\FluxSoftware\Flux\flux.exe [1678840 2017-10-10] (f.lux Software LLC)
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\Run: [Discord] => C:\Users\fabienne\AppData\Local\Discord\app-0.0.299\Discord.exe [57954808 2017-12-11] (Discord Inc.)
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\Run: [PrtScr by FireStarter] => C:\Program Files (x86)\PrtScr\PrtScr.exe [1700864 2009-05-16] (FireStarter)
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [5094080 2017-07-03] (Disc Soft Ltd)
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3111712 2017-12-15] (Valve Corporation)
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\Run: [Chromium] => "c:\users\fabienne\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory=Default --restore-last-session
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\RunOnce: [Uninstall C:\Users\fabienne\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\fabienne\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64"
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\RunOnce: [Uninstall C:\Users\fabienne\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\fabienne\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_187_pepper.exe [1319936 2017-11-18] (Adobe Systems Incorporated)
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\MountPoints2: {44ebdef4-6015-11e7-9836-d05099ae5c7a} - "D:\setup.exe"
HKU\S-1-5-21-2180333732-962956309-1127545411-1001\...\MountPoints2: {44ebdf7a-6015-11e7-9836-d05099ae5c7a} - "F:\setup.exe"
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-10-07]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.11.500\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2016-09-27]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
Startup: C:\Users\fabienne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2017-07-10]
ShortcutTarget: MEGAsync.lnk -> C:\Users\fabienne\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{34deba6e-a515-4106-af75-362e131d29f6}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{e418140d-f543-4d23-92eb-8bc24dc4f3d2}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2017-12-08] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll => Pas de fichier
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2017-07-11] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2017-12-08] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll => Pas de fichier
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2017-09-12] (Microsoft Corporation)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll Pas de fichier
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-06-26] (Intel Security)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-06-26] (Intel Security)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-08-15] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-08-15] (Microsoft Corporation)
Handler: WSISVCUchrome - Pas de valeur CLSID
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF DefaultProfile: hgn24u8l.default
FF ProfilePath: C:\Users\fabienne\AppData\Roaming\Mozilla\Firefox\Profiles\hgn24u8l.default [2017-12-12]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-17] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2017-12-08] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2017-12-08] (Oracle Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-06-04] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-17] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-03-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-18] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-06-04] (Adobe Systems)
StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxp://www.calendrier-365.fr/favicon.ico
CHR Profile: C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default [2017-12-20]
CHR Extension: (Calendrier 2016 & Jours fériés 2016) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\afmgnencibdcemafdolfehbkmckljapi [2016-11-15]
CHR Extension: (Docs) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-16]
CHR Extension: (Google Drive) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-27]
CHR Extension: (YouTube) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-27]
CHR Extension: (Adblock Plus) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-09-28]
CHR Extension: (Recherche Google) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-09-27]
CHR Extension: (Google Docs hors connexion) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-27]
CHR Extension: (Itineraire - Offres shopping) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlincbpgbkpbjepghokdnhnnpphmegig [2017-10-24]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-29]
CHR Extension: (Gmail) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-27]
CHR Extension: (Chrome Media Router) - C:\Users\fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-12]

==================== Services (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 ACTION_SVC; C:\Program Files (x86)\Mirillis\Action!\action_svc.exe [16064 2014-10-25] ()
S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [814688 2017-06-04] (Adobe Systems Incorporated)
S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-02-27] (Adobe Systems, Incorporated)
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2017-12-03] ()
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2289856 2017-07-03] (Disc Soft Ltd)
S2 Everything; C:\Program Files\Everything\Everything.exe [2197608 2017-06-07] ()
S4 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
R2 KSDE2.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe [354672 2017-01-24] (AO Kaspersky Lab)
R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.11.500\McCHSvc.exe [272136 2017-01-19] (McAfee, Inc.)
S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2227152 2016-07-19] (Micro-Star INT'L CO., LTD.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518264 2017-10-11] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518264 2017-10-11] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-10-27] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460920 2017-10-11] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123104 2017-11-02] (Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3002728 2017-11-02] (Electronic Arts)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2017-09-29] ()
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2017-08-08] (Microsoft Corporation)
S4 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [1001920 2017-06-26] (McAfee, Inc.)
S4 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16928 2017-06-26] (McAfee, Inc.)
S4 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [87760 2017-06-26] (McAfee, Inc.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103704 2017-10-09] (Microsoft Corporation)
S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 [X]

===================== Pilotes (Avec liste blanche) ======================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2017-07-06] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2017-07-06] (Disc Soft Ltd)
R3 kltap; C:\Windows\System32\drivers\kltap.sys [52152 2016-06-07] (The OpenVPN Project)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [252232 2017-12-20] (Malwarebytes)
R1 MpKsla5ff9115; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1CA8ED71-E456-4A14-BDA1-6E73EAC70481}\MpKsla5ff9115.sys [58120 2017-12-20] (Microsoft Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-10-11] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50808 2017-10-11] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57976 2017-10-11] (NVIDIA Corporation)
S3 qcfilter; C:\Windows\System32\drivers\qcusbfilter.sys [49208 2017-03-15] (QUALCOMM Incorporated)
S3 qcusbser; C:\Windows\system32\DRIVERS\qcusbser.sys [254520 2017-03-15] (QUALCOMM Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
U0 aswVmm; pas de ImagePath
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2017-12-20 18:33 - 2017-12-20 18:33 - 000020317 _____ C:\Users\fabienne\Desktop\FRST.txt
2017-12-20 18:32 - 2017-12-20 18:33 - 000000000 ____D C:\FRST
2017-12-20 18:32 - 2017-12-20 18:32 - 002392064 _____ (Farbar) C:\Users\fabienne\Desktop\FRST64.exe
2017-12-20 18:02 - 2017-12-20 18:02 - 000168585 _____ C:\Users\fabienne\Desktop\ZHPDiag.txt
2017-12-20 18:00 - 2017-12-20 18:01 - 000000000 ____D C:\Users\fabienne\AppData\Roaming\ZHP
2017-12-20 18:00 - 2017-12-20 18:00 - 002950528 _____ C:\Users\fabienne\Downloads\ZHPDiag3.exe
2017-12-20 18:00 - 2017-12-20 18:00 - 000000911 _____ C:\Users\fabienne\Desktop\ZHPDiag.lnk
2017-12-20 18:00 - 2017-12-20 18:00 - 000000000 ____D C:\Users\fabienne\AppData\Local\ZHP
2017-12-20 17:28 - 2017-12-20 17:28 - 000252232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2017-12-20 17:26 - 2017-12-20 17:26 - 026878536 _____ (Adlice Software) C:\Users\fabienne\Downloads\RogueKiller_portable64 (1).exe
2017-12-20 17:26 - 2017-12-20 17:26 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-12-20 17:23 - 2017-12-20 17:23 - 008187336 _____ (Malwarebytes) C:\Users\fabienne\Downloads\adwcleaner_7.0.5.0.exe
2017-12-12 19:58 - 2017-12-02 02:06 - 000835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-12-12 19:58 - 2017-12-02 02:06 - 000177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-12-12 19:52 - 2017-11-30 10:45 - 000982392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2017-12-12 19:52 - 2017-11-30 10:33 - 005688320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-12-12 19:52 - 2017-11-30 10:29 - 000095744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2017-12-12 19:52 - 2017-11-30 10:28 - 007625728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-12-12 19:52 - 2017-11-30 10:28 - 000224256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExSMime.dll
2017-12-12 19:52 - 2017-11-30 10:28 - 000151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2017-12-12 19:52 - 2017-11-30 10:28 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-12-12 19:52 - 2017-11-30 10:26 - 000147456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VCardParser.dll
2017-12-12 19:52 - 2017-11-30 10:25 - 000176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhoneCallHistoryApis.dll
2017-12-12 19:52 - 2017-11-30 10:25 - 000148992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2017-12-12 19:52 - 2017-11-30 10:25 - 000144896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2017-12-12 19:52 - 2017-11-30 10:25 - 000118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentActivation.dll
2017-12-12 19:52 - 2017-11-30 10:25 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscript.ocx
2017-12-12 19:52 - 2017-11-30 10:24 - 000822784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2017-12-12 19:52 - 2017-11-30 10:24 - 000531968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2017-12-12 19:52 - 2017-11-30 10:24 - 000300544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll
2017-12-12 19:52 - 2017-11-30 10:24 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshext.dll
2017-12-12 19:52 - 2017-11-30 10:23 - 000670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
2017-12-12 19:52 - 2017-11-30 10:23 - 000431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
2017-12-12 19:52 - 2017-11-30 10:23 - 000205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrobj.dll
2017-12-12 19:52 - 2017-11-30 10:22 - 019411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-12-12 19:52 - 2017-11-30 10:22 - 018366976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-12-12 19:52 - 2017-11-30 10:22 - 012205056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-12-12 19:52 - 2017-11-30 10:21 - 000713216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2017-12-12 19:52 - 2017-11-30 10:17 - 000858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2017-12-12 19:52 - 2017-11-30 10:17 - 000579072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ChatApis.dll
2017-12-12 19:52 - 2017-11-30 10:16 - 006066688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-12-12 19:52 - 2017-11-30 10:16 - 003662848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-12-12 19:52 - 2017-11-30 10:16 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-12-12 19:52 - 2017-11-30 10:16 - 000238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
2017-12-12 19:52 - 2017-11-30 10:15 - 001599488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-12-12 19:52 - 2017-11-30 10:15 - 000711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentApis.dll
2017-12-12 19:52 - 2017-11-30 10:14 - 002028032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-12-12 19:52 - 2017-11-30 10:14 - 000859136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContactApis.dll
2017-12-12 19:52 - 2017-11-30 10:14 - 000656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-12-12 19:52 - 2017-11-30 09:22 - 007780184 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-12-12 19:52 - 2017-11-30 09:17 - 000983896 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2017-12-12 19:52 - 2017-11-30 09:16 - 001090904 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2017-12-12 19:52 - 2017-11-30 09:16 - 000947544 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi
2017-12-12 19:52 - 2017-11-30 09:16 - 000811864 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe
2017-12-12 19:52 - 2017-11-30 09:15 - 001072240 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2017-12-12 19:52 - 2017-11-30 08:53 - 022571520 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2017-12-12 19:52 - 2017-11-30 08:50 - 007219200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-12-12 19:52 - 2017-11-30 08:45 - 000119808 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2017-12-12 19:52 - 2017-11-30 08:45 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-12-12 19:52 - 2017-11-30 08:44 - 000173056 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2017-12-12 19:52 - 2017-11-30 08:42 - 000862208 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2017-12-12 19:52 - 2017-11-30 08:42 - 000163328 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2017-12-12 19:52 - 2017-11-30 08:41 - 009129984 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-12-12 19:52 - 2017-11-30 08:40 - 000165376 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2017-12-12 19:52 - 2017-11-30 08:39 - 000187904 _____ (Microsoft Corporation) C:\Windows\system32\VCardParser.dll
2017-12-12 19:52 - 2017-11-30 08:38 - 001081856 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2017-12-12 19:52 - 2017-11-30 08:38 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll
2017-12-12 19:52 - 2017-11-30 08:38 - 000224768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-12-12 19:52 - 2017-11-30 08:37 - 008118272 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2017-12-12 19:52 - 2017-11-30 08:37 - 000949248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService.dll
2017-12-12 19:52 - 2017-11-30 08:37 - 000805888 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-12-12 19:52 - 2017-11-30 08:37 - 000590336 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
2017-12-12 19:52 - 2017-11-30 08:37 - 000556544 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2017-12-12 19:52 - 2017-11-30 08:37 - 000388096 _____ (Microsoft Corporation) C:\Windows\system32\UserDataAccountApis.dll
2017-12-12 19:52 - 2017-11-30 08:37 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\PhoneCallHistoryApis.dll
2017-12-12 19:52 - 2017-11-30 08:37 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\wshext.dll
2017-12-12 19:52 - 2017-11-30 08:36 - 023674880 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-12-12 19:52 - 2017-11-30 08:36 - 013108224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-12-12 19:52 - 2017-11-30 08:36 - 004749824 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2017-12-12 19:52 - 2017-11-30 08:36 - 001146880 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll
2017-12-12 19:52 - 2017-11-30 08:36 - 000761856 _____ (Microsoft Corporation) C:\Windows\system32\ChatApis.dll
2017-12-12 19:52 - 2017-11-30 08:36 - 000284160 _____ (Microsoft Corporation) C:\Windows\system32\AboveLockAppHost.dll
2017-12-12 19:52 - 2017-11-30 08:34 - 004739584 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-12-12 19:52 - 2017-11-30 08:33 - 002097664 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-12-12 19:52 - 2017-11-30 08:33 - 001783296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-12-12 19:52 - 2017-11-30 08:33 - 001013760 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll
2017-12-12 19:52 - 2017-11-30 08:33 - 000583168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-12-12 19:52 - 2017-11-30 08:32 - 000799744 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-12-12 19:52 - 2017-11-30 08:32 - 000772096 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentApis.dll
2017-12-12 19:52 - 2017-03-04 07:19 - 000635904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-12-12 19:52 - 2016-09-07 05:56 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentActivation.dll
2017-12-08 18:51 - 2017-12-08 18:51 - 000000000 ____D C:\Users\fabienne\AppData\Roaming\.PixelmonFR
2017-12-08 18:44 - 2017-12-08 18:43 - 000110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2017-12-08 18:43 - 2017-12-08 18:43 - 000000000 ____D C:\Users\fabienne\AppData\LocalLow\Oracle
2017-12-08 18:43 - 2017-12-08 18:43 - 000000000 ____D C:\Users\fabienne\.oracle_jre_usage
2017-12-06 19:41 - 2017-11-18 04:59 - 020967840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-12-06 19:41 - 2017-11-18 04:59 - 006672128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-12-06 19:41 - 2017-11-18 04:43 - 000265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\socialapis.dll
2017-12-06 19:41 - 2017-11-18 04:42 - 000248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlancfg.dll
2017-12-06 19:41 - 2017-11-18 04:42 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertPKICmdlet.dll
2017-12-06 19:41 - 2017-11-18 04:40 - 000368640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanui.dll
2017-12-06 19:41 - 2017-11-18 04:38 - 002750976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2017-12-06 19:41 - 2017-11-18 04:38 - 000343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2017-12-06 19:41 - 2017-11-18 04:37 - 000854528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autofmt.exe
2017-12-06 19:41 - 2017-11-18 04:36 - 000878080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autoconv.exe
2017-12-06 19:41 - 2017-11-18 04:34 - 002002944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2017-12-06 19:41 - 2017-11-18 04:33 - 000754688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-12-06 19:41 - 2017-11-18 04:31 - 002997760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-12-06 19:41 - 2017-11-18 04:31 - 000827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2017-12-06 19:41 - 2017-11-18 04:31 - 000675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2017-12-06 19:40 - 2017-11-18 05:03 - 000195936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll
2017-12-06 19:40 - 2017-11-18 05:01 - 005722312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-12-06 19:40 - 2017-11-18 04:42 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2017-12-06 19:40 - 2017-11-18 04:38 - 000893440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2017-12-06 19:40 - 2017-11-18 04:36 - 012349440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2017-12-06 19:40 - 2017-11-18 04:30 - 000751104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-12-06 19:40 - 2017-03-04 07:13 - 006474752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspaint.exe
2017-12-06 19:32 - 2017-11-18 05:12 - 008178816 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2017-12-06 19:31 - 2017-11-18 05:23 - 000038744 _____ (Microsoft Corporation) C:\Windows\system32\OOBEUpdater.exe
2017-12-06 19:31 - 2017-11-18 05:20 - 000219024 _____ (Microsoft Corporation) C:\Windows\system32\LsaIso.exe
2017-12-06 19:31 - 2017-11-18 05:18 - 002254688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-12-06 19:31 - 2017-11-18 05:13 - 000430424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2017-12-06 19:31 - 2017-11-18 05:12 - 022220856 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-12-06 19:31 - 2017-11-18 05:10 - 000453536 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2017-12-06 19:31 - 2017-11-18 04:43 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\rdpshell.exe
2017-12-06 19:31 - 2017-11-18 04:43 - 000372736 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
2017-12-06 19:31 - 2017-11-18 04:43 - 000299008 _____ (Microsoft Corporation) C:\Windows\system32\rdpinit.exe
2017-12-06 19:31 - 2017-11-18 04:38 - 000442368 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
2017-12-06 19:31 - 2017-11-18 04:37 - 003291648 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2017-12-06 19:31 - 2017-11-18 04:37 - 000061440 _____ (Microsoft Corporation) C:\Windows\system32\CertPKICmdlet.dll
2017-12-06 19:31 - 2017-11-18 04:33 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\wlancfg.dll
2017-12-06 19:31 - 2017-11-18 04:33 - 000231424 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2017-12-06 19:31 - 2017-11-18 04:32 - 000410112 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll
2017-12-06 19:31 - 2017-11-18 04:32 - 000336896 _____ (Microsoft Corporation) C:\Windows\system32\socialapis.dll
2017-12-06 19:31 - 2017-11-18 04:32 - 000147456 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-12-06 19:31 - 2017-11-18 04:29 - 002512384 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2017-12-06 19:31 - 2017-11-18 04:29 - 002321408 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-12-06 19:31 - 2017-11-18 04:28 - 001518080 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2017-12-06 19:31 - 2017-11-18 04:28 - 001512448 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll
2017-12-06 19:31 - 2017-11-18 04:28 - 000932352 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-12-06 19:31 - 2017-11-18 04:28 - 000779776 _____ (Microsoft Corporation) C:\Windows\system32\cscui.dll
2017-12-06 19:31 - 2017-11-18 04:27 - 003616256 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2017-12-06 19:31 - 2017-11-18 04:27 - 000394240 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2017-12-06 19:31 - 2017-11-18 04:26 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2017-12-06 19:31 - 2017-11-07 03:59 - 000449050 _____ C:\Windows\system32\ApnDatabase.xml
2017-12-06 19:31 - 2017-03-04 07:10 - 000971264 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2017-12-06 19:30 - 2017-11-18 05:16 - 000168800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-12-06 19:30 - 2017-11-18 05:14 - 002187616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-12-06 19:30 - 2017-11-18 05:14 - 000658784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2017-12-06 19:30 - 2017-11-18 05:14 - 000402776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-12-06 19:30 - 2017-11-18 05:13 - 007213968 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2017-12-06 19:30 - 2017-11-18 05:13 - 000624048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-12-06 19:30 - 2017-11-18 05:08 - 000222048 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2017-12-06 19:30 - 2017-11-18 04:35 - 000227840 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-12-06 19:30 - 2017-11-18 04:32 - 013441536 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2017-12-06 19:30 - 2017-11-18 04:30 - 001010688 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2017-12-06 19:30 - 2017-11-18 04:30 - 000369152 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2017-12-06 19:30 - 2017-11-18 04:29 - 006664192 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe
2017-12-06 19:30 - 2017-11-18 04:29 - 001485824 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-12-06 19:30 - 2017-11-18 04:29 - 000913920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2017-12-06 19:30 - 2017-11-18 04:28 - 000924672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2017-12-06 19:29 - 2017-11-18 05:11 - 000241504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2017-12-06 19:29 - 2017-11-18 04:38 - 000969728 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2017-12-06 19:29 - 2017-11-18 04:37 - 000926208 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2017-12-06 19:29 - 2017-11-18 04:35 - 000954368 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2017-12-06 19:29 - 2017-11-18 04:32 - 000268800 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2017-12-06 19:29 - 2017-11-18 04:31 - 000956416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2017-12-06 19:29 - 2017-11-18 04:30 - 002278912 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2017-12-06 19:29 - 2017-11-18 04:30 - 001692160 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2017-12-06 19:28 - 2017-11-18 05:13 - 000573792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2017-12-04 19:25 - 2017-12-04 19:25 - 000000000 ____D C:\Users\fabienne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2017-12-03 18:39 - 2017-12-03 18:39 - 000000000 ____D C:\Users\fabienne\AppData\Local\FortniteGame
2017-12-03 17:51 - 2017-12-03 17:51 - 000000000 ____D C:\Program Files\Epic Games
2017-12-03 17:49 - 2017-12-03 17:49 - 000002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-12-03 17:45 - 2017-12-03 18:39 - 000000000 ____D C:\Users\fabienne\AppData\Local\UnrealEngine
2017-12-03 17:45 - 2017-12-03 17:45 - 000001270 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2017-12-03 17:45 - 2017-12-03 17:45 - 000001258 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk
2017-12-03 17:45 - 2017-12-03 17:45 - 000000000 ____D C:\Users\fabienne\AppData\Local\UnrealEngineLauncher
2017-12-03 17:45 - 2017-12-03 17:45 - 000000000 ____D C:\Users\fabienne\AppData\Local\EpicGamesLauncher
2017-12-03 17:44 - 2017-12-03 17:48 - 000000000 ____D C:\ProgramData\Epic
2017-12-03 17:44 - 2017-12-03 17:44 - 000000000 ____D C:\Program Files (x86)\Epic Games

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2017-12-20 17:27 - 2016-07-16 12:45 - 000000000 ____D C:\Windows\INF
2017-12-20 17:25 - 2017-10-22 10:44 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2017-12-20 17:24 - 2016-10-22 15:17 - 000000000 ____D C:\AdwCleaner
2017-12-20 17:24 - 2016-09-27 17:04 - 000000000 ____D C:\ProgramData\NVIDIA
2017-12-20 17:15 - 2016-09-27 11:26 - 000000000 ____D C:\Windows\system32\SleepStudy
2017-12-20 16:35 - 2016-09-27 11:33 - 000000000 ____D C:\Users\fabienne
2017-12-20 16:34 - 2017-04-07 12:52 - 000004182 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3DFBA23A-D5DD-47DF-97DF-EA6BDA3D528C}
2017-12-20 16:33 - 2016-10-23 16:41 - 000000000 ____D C:\Program Files (x86)\Steam
2017-12-20 16:31 - 2016-07-16 12:47 - 000000000 ____D C:\Windows\AppReadiness
2017-12-18 18:28 - 2017-01-25 17:07 - 000002218 _____ C:\Users\fabienne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\f.lux.lnk
2017-12-17 20:17 - 2017-06-30 16:55 - 000000000 ____D C:\Users\fabienne\Documents\Euro Truck Simulator 2
2017-12-17 19:21 - 2016-07-16 12:47 - 000000000 ___HD C:\Program Files\WindowsApps
2017-12-17 18:25 - 2016-09-27 11:36 - 006258340 _____ C:\Windows\system32\PerfStringBackup.INI
2017-12-17 18:25 - 2016-07-16 23:40 - 003053210 _____ C:\Windows\system32\perfh00C.dat
2017-12-17 18:25 - 2016-07-16 23:40 - 000846170 _____ C:\Windows\system32\perfc00C.dat
2017-12-17 18:22 - 2017-06-21 11:38 - 000000000 ____D C:\Users\fabienne\AppData\Roaming\.minecraft
2017-12-17 16:55 - 2017-06-11 13:34 - 000000000 ____D C:\Users\fabienne\Desktop\MILAN
2017-12-17 16:44 - 2016-09-27 17:05 - 000000000 ____D C:\Users\fabienne\AppData\Local\NVIDIA
2017-12-17 16:22 - 2017-05-08 10:13 - 000000000 ____D C:\Users\fabienne\AppData\Roaming\discord
2017-12-17 16:21 - 2017-05-08 10:13 - 000000000 ____D C:\Users\fabienne\AppData\Local\Discord
2017-12-17 13:26 - 2017-09-20 13:36 - 000000000 ____D C:\Users\fabienne\AppData\Roaming\uTorrent
2017-12-17 13:18 - 2017-10-22 11:08 - 000000000 ____D C:\Users\fabienne\AppData\LocalLow\uTorrent
2017-12-17 12:39 - 2017-08-31 17:15 - 000000000 ____D C:\ProgramData\TruckersMP
2017-12-13 18:51 - 2016-09-27 11:33 - 000000000 ____D C:\Users\fabienne\AppData\Local\Packages
2017-12-13 18:49 - 2016-11-15 13:34 - 000000000 ____D C:\Users\fabienne\Desktop\Recherche emploi
2017-12-13 08:54 - 2016-07-16 12:47 - 000000000 ____D C:\Windows\rescache
2017-12-13 08:40 - 2016-09-27 11:26 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-12-12 20:45 - 2016-07-16 07:04 - 000262144 _____ C:\Windows\system32\config\BBI
2017-12-12 20:44 - 2017-06-15 13:03 - 000000000 ___SD C:\Windows\UpdateAssistantV2
2017-12-12 19:58 - 2016-07-16 12:36 - 000000000 ____D C:\Windows\CbsTemp
2017-12-12 19:28 - 2017-04-25 18:58 - 000000000 ____D C:\Users\fabienne\AppData\LocalLow\Mozilla
2017-12-12 19:25 - 2016-10-10 11:09 - 000000000 ____D C:\Users\fabienne\AppData\Local\CrashDumps
2017-12-10 11:27 - 2016-09-27 11:33 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-12-10 11:24 - 2016-09-27 11:26 - 000419256 _____ C:\Windows\system32\FNTCACHE.DAT
2017-12-09 19:59 - 2016-07-16 12:47 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2017-12-09 19:59 - 2016-07-16 12:47 - 000000000 ____D C:\Windows\ShellExperiences
2017-12-08 19:34 - 2017-03-06 17:24 - 000000000 ____D C:\Users\fabienne\AppData\Local\Battle.net
2017-12-08 19:02 - 2017-05-07 11:02 - 000000000 ____D C:\Program Files (x86)\Heroes of the Storm
2017-12-08 18:55 - 2016-09-28 09:05 - 000000000 ____D C:\Users\fabienne\Documents\professionnel Fabienne
2017-12-08 18:44 - 2017-06-21 11:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-12-08 18:44 - 2017-06-21 11:39 - 000000000 ____D C:\Program Files\Java
2017-12-08 17:45 - 2017-07-07 15:23 - 000000000 ____D C:\Program Files (x86)\Overwatch Test
2017-12-08 17:44 - 2017-03-06 17:28 - 000000000 ____D C:\Program Files (x86)\Overwatch
2017-12-08 17:42 - 2017-05-29 14:50 - 000000000 ____D C:\Program Files (x86)\Blizzard App
2017-12-08 11:00 - 2017-11-03 12:36 - 000000000 ____D C:\Program Files\rempl
2017-12-06 20:01 - 2017-06-15 14:34 - 000000000 ____D C:\Users\fabienne\AppData\Roaming\TS3Client
2017-12-06 19:51 - 2016-07-16 12:47 - 000000167 _____ C:\Windows\win.ini
2017-12-03 17:46 - 2016-09-27 12:04 - 000000000 ____D C:\ProgramData\Package Cache
2017-11-26 19:03 - 2016-10-03 13:16 - 000000000 ____D C:\Users\fabienne\AppData\Roaming\Audacity
2017-11-26 17:05 - 2017-11-18 16:20 - 000000000 ____D C:\Users\fabienne\AppData\Local\NVIDIA Corporation
2017-11-26 17:04 - 2016-09-27 17:23 - 000545440 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

==================== Fichiers à la racine de certains dossiers =======

2017-07-10 15:51 - 2017-07-10 15:51 - 000000096 _____ () C:\Users\fabienne\AppData\Roaming\version2.xml
2017-07-12 08:07 - 2017-07-16 15:28 - 000000070 _____ () C:\Users\fabienne\AppData\Roaming\WB.CFG

Certains fichiers dans TEMP:
====================
2017-07-26 09:48 - 2017-09-07 07:03 - 001887408 _____ (Microsoft Corporation) C:\Users\fabienne\AppData\Local\Temp\dllnt_dump.dll
2017-10-09 18:09 - 2017-10-09 18:06 - 071089112 _____ (Malwarebytes ) C:\Users\fabienne\AppData\Local\Temp\mb3-setup-35891.35891-3.2.2.2029-1.0.207-1.0.2899.exe

==================== Bamital & volsnap ======================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement
C:\Windows\system32\wininit.exe => Le fichier est signé numériquement
C:\Windows\explorer.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\Windows\system32\svchost.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\Windows\system32\services.exe => Le fichier est signé numériquement
C:\Windows\system32\User32.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\Windows\system32\userinit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement
C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

LastRegBack: 2017-12-17 12:47

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité