cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 02.01.2018
Exécuté par admin (administrateur) sur DESKTOP-QHBK41D (05-01-2018 22:29:25)
Exécuté depuis C:\Users\admin\Downloads
Profils chargés: admin (Profils disponibles: simon & admin)
Platform: Windows 10 Pro Version 1607 14393.1944 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Edge)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120510.inf_amd64_0f15706cfddd3491\igfxCUIService.exe
(HP) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Conexant Systems, Inc) C:\Windows\CxSvc\CxMonSvc.exe
(Conexant Systems, Inc.) C:\Windows\CxSvc\CxUtilSvc.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(HP) C:\Program Files (x86)\HP\HP Hotkey Support\HotkeyService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
() C:\Program Files (x86)\NETGEAR\WNA3100M\WifiSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(eVenture Limited) C:\Program Files (x86)\hide.me VPN\hidemesvc.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpCardEngine.exe
(HP) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(HP) C:\Program Files (x86)\HP\HP Hotkey Support\QLBController.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120510.inf_amd64_0f15706cfddd3491\igfxEM.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe
(Conexant) C:\Windows\System32\MicTray64.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\HP-NB-AIO\SmartAudio3.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(RaMMicHaeL) C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(MY.COM B.V.) C:\Users\admin\AppData\Local\MyComGames\MyComGames.exe
(Guillaume Ryder (hxxp://utilfr42.free.fr)) C:\Users\admin\AppData\Local\Clavier+\Clavier.exe
(HP) C:\Program Files (x86)\HP\HP Notifications\HPNotifications.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(HP) C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe
(HP) C:\Program Files (x86)\HP\HP Touchpoint Manager\Discover HP Touchpoint Manager\LHBeacon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120510.inf_amd64_0f15706cfddd3491\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [DeliveryAndStatusCheck] => C:\Program Files\HP\HP ePrint\HP.DeliveryAndStatus.Desktop.App.exe [301832 2015-11-10] (HP)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323040 2015-10-10] (Intel Corporation)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-28] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPNotifications] => C:\Program Files (x86)\HP\HP Notifications\HPNotifications.exe [853728 2015-10-20] (HP)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127528 2015-07-08] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [258600 2016-01-05] (HP)
HKLM-x32\...\Run: [Discover HP Touchpoint Manager] => C:\Program Files (x86)\HP\HP Touchpoint Manager\Discover HP Touchpoint Manager\LHBeacon.exe [426208 2015-10-22] (HP)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [110008 2015-12-16] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [500152 2015-12-16] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5885352 2017-06-29] (LogMeIn Inc.)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [uTorrent] => C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe [1982144 2017-09-30] (BitTorrent Inc.)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Steam] => C:\Program Files (x86)\steam2\steam.exe [3111712 2017-12-21] (Valve Corporation)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Discord] => C:\Users\admin\AppData\Local\Discord\app-0.0.299\Discord.exe [57954808 2017-12-11] (Discord Inc.)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [7 Taskbar Tweaker] => C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe [423424 2017-05-19] (RaMMicHaeL)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9818328 2017-06-30] (Piriform Ltd)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Chromium] => c:\users\admin\appdata\local\chromium\application\chrome.exe --auto-launch-at-startup --profile-directory=Default --restore-last-session
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [PSwitch] => C:\Program Files (x86)\Proxy Switcher Standard\ProxySwitcher.exe [5921848 2015-01-10] (Proxy Switcher)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4836032 2017-08-14] (Disc Soft Ltd)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [5345672 2017-12-21] (Nota Inc.)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [MyComGames] => C:\Users\admin\AppData\Local\MyComGames\MyComGames.exe [6086544 2017-12-29] (MY.COM B.V.)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Gadwin PrintScreen (64-bit)] => C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe [15216928 2017-07-30] (Gadwin Systems)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Clavier+] => C:\Users\admin\AppData\Local\Clavier+\Clavier.exe [157696 2017-09-09] (Guillaume Ryder (hxxp://utilfr42.free.fr))
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Sound Pilot] => C:\Program Files\Sound Pilot\SoundPilot.exe [243208 2016-11-11] (Two Pilots)
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\MountPoints2: {08f9c7e9-ac74-11e7-bb6c-ec8eb59f5ec4} - "I:\setup.exe"
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\MountPoints2: {b8799c35-aa77-11e7-bb6b-ec8eb59f5ec4} - "H:\setup.exe"
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2017-06-21]
ShortcutTarget: MEGAsync.lnk -> C:\Users\admin\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited)
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2017-10-14]
ShortcutTarget: Twitch.lnk -> C:\Users\admin\AppData\Roaming\Twitch\Bin\Twitch.exe (Twitch Interactive, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA3100M Genie.lnk [2017-04-29]
ShortcutTarget: NETGEAR WNA3100M Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNA3100M\WNA3100M.exe ()
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{55ea8d57-91ca-46e9-90e6-bea64a04e267}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{e2c0e5be-6a45-4d0c-9e99-b3445c2cdac9}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dpchi_17_30¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0Czz0E0ByDzy0FyD0E0CyEyBtDzz0CtN0D0Tzu0StBtDtAtBtN1L2XzutAtFtBzytFtCtDyEtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyB0B0CtAyDzz0BtGtC0CyC0BtGzy0C0ByEtGtAyD0DyBtG0CyC0CtBtCzy0CyBtB0B0C0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzyyD0C0AtAtCyCtGzy0EzyyEtGyE0BzztDtG0AtCtAtDtGzz0Fzy0CyDyE0DtCzyyC0B0F2QtN0A0LzuyE%26cr%3D9175879%26a%3Dwbf_dpchi_17_30%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dpchi_17_30¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0Czz0E0ByDzy0FyD0E0CyEyBtDzz0CtN0D0Tzu0StBtDtAtBtN1L2XzutAtFtBzytFtCtDyEtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyB0B0CtAyDzz0BtGtC0CyC0BtGzy0C0ByEtGtAyD0DyBtG0CyC0CtBtCzy0CyBtB0B0C0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzyyD0C0AtAtCyCtGzy0EzyyEtGyE0BzztDtG0AtCtAtDtGzz0Fzy0CyDyE0DtCzyyC0B0F2QtN0A0LzuyE%26cr%3D9175879%26a%3Dwbf_dpchi_17_30%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dpchi_17_30¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0Czz0E0ByDzy0FyD0E0CyEyBtDzz0CtN0D0Tzu0StBtDtAtBtN1L2XzutAtFtBzytFtCtDyEtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyB0B0CtAyDzz0BtGtC0CyC0BtGzy0C0ByEtGtAyD0DyBtG0CyC0CtBtCzy0CyBtB0B0C0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzyyD0C0AtAtCyCtGzy0EzyyEtGyE0BzztDtG0AtCtAtDtGzz0Fzy0CyDyE0DtCzyyC0B0F2QtN0A0LzuyE%26cr%3D9175879%26a%3Dwbf_dpchi_17_30%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-01] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-01] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF Extension: (Site Deployment Checker) - C:\Program Files\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-24] [Legacy] [non signé]
FF HKLM-x32\...\Firefox\Extensions: [dpmaxz_ng@jetpack] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome
FF Extension: (HP Client Security Manager) - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome [2016-07-26] [Legacy] [non signé]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2017-12-12] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-01] (Oracle Corporation)
FF Plugin-x32: @4game.com/plugin -> C:\Program Files (x86)\4game\3.6.2.254\npplugin4game.dll [Pas de fichier]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2017-12-12] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-08-24] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-08-24] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-05] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll [2015-09-28] (DigitalPersona, Inc.)
StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome:
=======
CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://fr.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2018-01-05]
CHR Extension: (Slides) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-21]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-21]
CHR Extension: (Adblock Plus) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-09-26]
CHR Extension: (YouTube Notifications) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cilgbgkmanbbecbjihnbpeaoodmgchom [2017-11-20]
CHR Extension: (Jeremysadi Live Extension) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\daogbelhijghbcaiedbcoeiifolghehe [2017-06-27]
CHR Extension: (Chatango Extender) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfeinllkceneabfakchfljicjpfacefb [2017-06-01]
CHR Extension: (Sheets) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (EditThisCookie) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2017-12-29]
CHR Extension: (Google Docs hors connexion) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-21]
CHR Extension: (Obu's Chatango Improvements) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kppmmpajlakpalhigmmkbaikoklhgmnb [2017-05-30]
CHR Extension: (TubeBuddy for YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkhmbddkmdggbhaaaodilponhnccicb [2018-01-04]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22]
CHR Extension: (TunnelBear Inc.) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\omdakjcmkglenbhjadbccaookpfjihpa [2017-11-18]
CHR Extension: (Warcraft-Alliance-HD Theme) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\onmabcbofdhckooclinckijfdiaflahh [2018-01-05]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-21]
CHR Extension: (Chrome Media Router) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-14]
CHR HKLM\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ccjleegmemocfpghkhpjmiccjcacackp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fabhkdeopjkcpkmofliimbjckmocfiom] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome.crx
CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1530376 2017-04-13] ()
R2 CxMonSvc; C:\WINDOWS\CxSvc\CxMonSvc.exe [22648 2016-06-07] (Conexant Systems, Inc)
R2 CxUtilSvc; C:\WINDOWS\CxSvc\CxUtilSvc.exe [141432 2016-07-30] (Conexant Systems, Inc.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2291904 2017-08-14] (Disc Soft Ltd)
R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [502232 2015-09-28] (DigitalPersona, Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [526888 2017-10-23] (EasyAntiCheat Ltd)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3418024 2017-06-29] (LogMeIn Inc.)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-09-19] (Hi-Rez Studios) [Fichier non signé]
R2 hmevpnsvc; C:\Program Files (x86)\hide.me VPN\hidemesvc.exe [136864 2017-09-28] (eVenture Limited)
R2 HP Hotkey Service; C:\Program Files (x86)\HP\HP Hotkey Support\HotkeyService.exe [781864 2015-12-21] (HP)
R3 hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [1102560 2015-10-19] (HP)
R2 hpsrv; C:\WINDOWS\system32\Hpservice.exe [38728 2016-10-11] (HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [332144 2017-11-21] (HP Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19424 2015-10-10] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-07-06] (Intel Corporation) [Fichier non signé]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-07-06] () [Fichier non signé]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2016-01-07] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [Fichier non signé]
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [8028304 2017-01-24] (INCA Internet Co., Ltd.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2017-08-08] (Microsoft Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [256224 2017-09-06] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103704 2017-10-09] (Microsoft Corporation)
R2 WSWNA3100M; C:\Program Files (x86)\NETGEAR\WNA3100M\WifiSvc.exe [316120 2014-08-18] ()
S2 4game-service; "C:\Program Files (x86)\4game\3.6.2.254\4game-service.exe" [X]
S3 BstHdLogRotatorSvc; "C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe" [X]
S2 TeamViewer; "C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe" [X]

===================== Pilotes (Avec liste blanche) ======================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R3 Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [56128 2016-10-11] (HP)
R3 bcbtums; C:\WINDOWS\system32\DRIVERS\bcbtums.sys [186152 2015-12-18] (Broadcom Corporation.)
S3 BCM43XX; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [11794376 2017-07-13] (Broadcom Corp)
R3 BCMWL63A; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [11794376 2017-07-13] (Broadcom Corp)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [100624 2015-06-08] (CyberLink)
R3 CnxtHdAudService; C:\WINDOWS\system32\drivers\CHDRT64ISST.sys [1656856 2017-05-14] (Conexant Systems Inc.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-10-08] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-10-08] (Disc Soft Ltd)
S3 FairplayKD; C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [82440 2017-10-29] (Multi Theft Auto)
R3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2017-06-29] (LogMeIn Inc.)
R0 hpdskflt; C:\WINDOWS\System32\DRIVERS\hpdskflt.sys [42312 2016-10-11] (HP)
R1 MpKsl05c474ff; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{47087370-1413-401E-A2AC-A4B4A50F1A2D}\MpKsl05c474ff.sys [58120 2018-01-05] (Microsoft Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R0 PinFile; C:\WINDOWS\System32\DRIVERS\PinFile.sys [56864 2015-11-15] (WinMagic Inc.)
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [3409096 2014-09-04] (Realtek Semiconductor Corporation )
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [769752 2015-12-18] (Realsil Semiconductor Corporation)
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [413912 2015-12-22] (Realsil Semiconductor Corporation)
R0 SDDisk2K; C:\WINDOWS\System32\DRIVERS\SDDisk2K.sys [232480 2015-11-15] (WinMagic Inc.)
R0 SDDToki; C:\WINDOWS\System32\DRIVERS\SDDToki.sys [138272 2015-11-15] (WinMagic Inc.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [51936 2017-09-06] (Synaptics Incorporated)
S3 SNP2UVCW10; C:\WINDOWS\system32\DRIVERS\snp2uvcW10.sys [2530920 2015-12-21] (Sonix Tech. Co., Ltd.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-07-23] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30544 2015-08-13] (HP)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [37344 2017-07-24] (Wellbia.com Co., Ltd.)
U3 aspnet_state; pas de ImagePath
S3 BstkDrv; \??\C:\Program Files (x86)\BlueStacks\BstkDrv.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

Error(1) reading file: "C:\Users\admin\Downloads\ "
2018-01-05 22:29 - 2018-01-05 22:32 - 000028820 _____ C:\Users\admin\Downloads\FRST.txt
2018-01-05 22:09 - 2018-01-05 22:30 - 001388448 _____ C:\Users\Public\VOIP.dat
2018-01-05 21:51 - 2018-01-05 21:51 - 000209536 _____ C:\Users\admin\Desktop\ZHPDiag.txt
2018-01-05 21:37 - 2018-01-05 21:37 - 001388448 _____ C:\Users\Public\ASR.dat
2018-01-05 21:34 - 2018-01-05 22:10 - 000083933 _____ C:\Users\admin\Desktop\Addition.txt
2018-01-05 21:25 - 2018-01-05 22:29 - 000000000 ____D C:\FRST
2018-01-05 21:25 - 2018-01-05 21:51 - 000062215 _____ C:\Users\admin\Desktop\FRST.txt
2018-01-05 21:24 - 2018-01-05 21:24 - 002961280 _____ C:\Users\admin\Downloads\ZHPDiag3.exe
2018-01-05 21:24 - 2018-01-05 21:24 - 002393088 _____ (Farbar) C:\Users\admin\Downloads\FRST64.exe
2018-01-05 21:24 - 2018-01-05 21:24 - 000000872 _____ C:\Users\admin\Desktop\ZHPDiag.lnk
2018-01-05 21:18 - 2018-01-05 21:18 - 000002353 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-05 21:18 - 2018-01-05 21:18 - 000002341 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-01-05 21:17 - 2018-01-05 21:17 - 000003586 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-01-05 21:17 - 2018-01-05 21:17 - 000003462 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-01-05 21:16 - 2018-01-05 21:17 - 001129816 _____ (Google Inc.) C:\Users\admin\Downloads\ChromeSetup.exe
2018-01-05 21:04 - 2018-01-05 21:06 - 083316440 _____ (Malwarebytes ) C:\Users\admin\Downloads\mb3-setup-35891.35891-3.3.1.2183-1.0.262-1.0.3374.exe
2018-01-05 20:32 - 2018-01-05 20:36 - 000013350 _____ C:\Users\admin\Desktop\ZHPCleaner.txt
2018-01-05 20:05 - 2018-01-05 22:24 - 000000000 ____D C:\Users\admin\AppData\Roaming\ZHP
2018-01-05 20:05 - 2018-01-05 21:24 - 000000000 ____D C:\Users\admin\AppData\Local\ZHP
2018-01-05 20:05 - 2018-01-05 20:05 - 000000882 _____ C:\Users\admin\Desktop\ZHPCleaner.lnk
2018-01-05 20:04 - 2018-01-05 20:05 - 003004288 _____ C:\Users\admin\Downloads\ZHPCleaner.exe
2018-01-05 15:25 - 2018-01-05 15:25 - 000029678 _____ C:\Users\admin\Downloads\22.html
2018-01-04 23:33 - 2018-01-04 23:33 - 000000000 ____D C:\Users\admin\AppData\Roaming\Oxyda-tion
2018-01-04 23:25 - 2018-01-04 23:32 - 000000000 ____D C:\Users\admin\Desktop\Oxyda-tion
2018-01-04 23:14 - 2018-01-04 23:17 - 2521967728 _____ C:\Users\admin\Downloads\OxdyaPrime.rar
2018-01-04 22:14 - 2018-01-05 20:49 - 000000000 ____D C:\AdwCleaner
2018-01-04 22:13 - 2018-01-04 22:14 - 008198432 _____ (Malwarebytes) C:\Users\admin\Downloads\adwcleaner_7.0.6.0.exe
2018-01-04 17:23 - 2018-01-04 17:27 - 000578121 _____ ( ) C:\Users\admin\Downloads\All_roblox_dll_scripts.exe
2018-01-04 17:11 - 2018-01-04 17:11 - 000000000 ____D C:\Users\admin\Documents\My Nopde Tables
2018-01-04 17:09 - 2018-01-04 17:09 - 009319570 _____ C:\Users\admin\Downloads\Nopde Engine 6.4.rar
2018-01-04 17:07 - 2018-01-04 17:19 - 000319488 _____ C:\Users\admin\Downloads\dllinjector.exe
2018-01-04 16:54 - 2018-01-04 16:54 - 000645632 _____ (AN Soft) C:\Users\admin\Downloads\DLLInjector v2.exe
2018-01-04 16:53 - 2018-01-04 16:53 - 001552016 _____ ( ) C:\Users\admin\Downloads\DLLInjector v2.0 Installer_0411596536.exe
2018-01-02 14:08 - 2018-01-02 14:08 - 000000000 ____D C:\Users\admin\Documents\FeedbackHub
2018-01-01 20:44 - 2018-01-01 20:44 - 000782336 _____ () C:\Users\admin\Downloads\Multiple_ROBLOX.exe
2018-01-01 20:34 - 2018-01-01 20:37 - 000822328 _____ (Roblox Corporation) C:\Users\admin\Downloads\RobloxPlayerLauncher.exe
2018-01-01 18:03 - 2018-01-01 18:03 - 000031545 _____ C:\Users\admin\Downloads\LumberT2_INSANE_SCRIPT.txt
2017-12-31 19:54 - 2017-12-31 19:55 - 000008144 _____ C:\Users\admin\Desktop\Nouveau Archive WinRAR ZIP.zip
2017-12-31 17:46 - 2017-12-31 17:46 - 000006330 _____ C:\Users\admin\Downloads\lt2moneyfarmgui2.txt
2017-12-31 13:02 - 2017-12-31 13:03 - 005079763 _____ C:\Users\admin\Downloads\Script Pack's.zip
2017-12-31 01:49 - 2017-12-31 01:49 - 000000410 _____ C:\Users\admin\Downloads\Lumber Tycoon 2 Hack.txt
2017-12-31 01:42 - 2017-12-31 01:44 - 000000000 ____D C:\Users\admin\Desktop\Nouveau dossier (3)
2017-12-31 01:41 - 2018-01-05 12:44 - 000000000 ____D C:\Users\admin\Desktop\Nouveau dossier (2)
2017-12-31 01:41 - 2017-12-31 17:50 - 000028881 _____ C:\Users\admin\Desktop\script.lua.lua.txt
2017-12-31 01:34 - 2017-12-31 01:34 - 000321703 _____ C:\Users\admin\Downloads\Calu.zip
2017-12-30 23:02 - 2018-01-05 12:42 - 000000000 _____ C:\Users\admin\AppData\Roaming\rbx_hook
2017-12-30 23:02 - 2018-01-05 12:39 - 000000024 _____ C:\Users\admin\AppData\Roaming\version
2017-12-30 23:00 - 2017-12-31 01:36 - 002782226 _____ C:\Users\admin\Downloads\Exploit and Script.zip
2017-12-30 18:53 - 2017-12-30 18:53 - 000856300 _____ C:\WINDOWS\Minidump\123017-31843-01.dmp
2017-12-29 19:22 - 2017-12-29 19:22 - 000000000 ____D C:\ProgramData\Gyazo
2017-12-24 01:36 - 2013-07-20 19:42 - 000000000 ____D C:\Users\admin\Desktop\,
2017-12-24 01:35 - 2017-12-24 01:36 - 000373879 _____ C:\Users\admin\Downloads\Armax2001 - AutoClick v1.0 (1).rar
2017-12-18 22:58 - 2017-12-18 22:58 - 747427983 _____ C:\Users\admin\Downloads\CSS Content Addon 2017.zip
2017-12-18 22:49 - 2017-12-18 22:49 - 107456607 _____ C:\Users\admin\Downloads\CSS Maps Addon 2017.zip
2017-12-18 01:46 - 2017-12-18 01:48 - 2417354154 _____ C:\Users\admin\Downloads\Client Sylea Complet.rar
2017-12-17 19:42 - 2017-12-17 19:42 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossout
2017-12-17 00:54 - 2017-12-17 00:54 - 000000068 _____ C:\Users\admin\AppData\Local\u7hu7hu7hu
2017-12-17 00:37 - 2017-12-17 00:37 - 000001529 _____ C:\Users\admin\Desktop\app - Raccourci.lnk
2017-12-17 00:36 - 2017-12-17 18:58 - 000000000 ____D C:\Users\admin\AppData\Roaming\Nefilya
2017-12-17 00:36 - 2017-12-17 00:36 - 000000000 ____D C:\Users\admin\Desktop\Nouveau dossier
2017-12-16 15:21 - 2017-12-17 00:37 - 000000000 ____D C:\Users\admin\AppData\Local\Nefilya
2017-12-16 15:21 - 2017-12-17 00:34 - 000000000 ____D C:\Users\admin\Desktop\Nefilya
2017-12-16 15:18 - 2017-12-17 19:40 - 000000000 ____D C:\Users\admin\Desktop\Dossiers en vrac
2017-12-16 15:13 - 2017-12-16 15:21 - 003950080 _____ (Nefilya) C:\Users\admin\Desktop\Nefilya.exe
2017-12-16 15:10 - 2017-12-16 15:11 - 029380120 _____ C:\Users\admin\Downloads\i18n_fr.d2i
2017-12-15 23:40 - 2017-12-15 23:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sound Pilot
2017-12-15 23:40 - 2017-12-15 23:40 - 000000000 ____D C:\Program Files\Sound Pilot
2017-12-15 23:38 - 2017-12-15 23:40 - 006763256 _____ (Two Pilots ) C:\Users\admin\Downloads\sound.exe
2017-12-15 23:27 - 2017-12-15 23:27 - 000000000 ____D C:\Users\admin\Documents\Lightshot
2017-12-15 23:24 - 2017-12-17 13:10 - 000000420 _____ C:\WINDOWS\Tasks\update-sys.job
2017-12-15 23:24 - 2017-12-15 23:24 - 000003346 _____ C:\WINDOWS\System32\Tasks\update-sys
2017-12-15 23:24 - 2017-12-15 23:24 - 000000425 _____ C:\Users\admin\AppData\Local\UserProducts.xml
2017-12-15 23:24 - 2017-12-15 23:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2017-12-15 23:24 - 2017-12-15 23:24 - 000000000 ____D C:\Program Files (x86)\Skillbrains
2017-12-15 13:34 - 2017-12-15 13:34 - 000000000 ____D C:\Users\admin\AppData\Local\UnrealEngine
2017-12-15 13:34 - 2017-12-15 13:34 - 000000000 ____D C:\Users\admin\AppData\Local\Rage_Simulator
2017-12-15 13:31 - 2017-12-15 13:32 - 186877700 _____ C:\Users\admin\Downloads\Rage Simulator.zip
2017-12-14 02:03 - 2017-11-16 20:42 - 000000000 ____D C:\Users\admin\Downloads\PS3 Super Slim Jailbreak 4.82 OFW To CFW
2017-12-14 01:53 - 2017-12-14 01:54 - 205671588 _____ C:\Users\admin\Downloads\PS3 Super Slim Jailbreak 4.82 OFW To CFW.zip
2017-12-13 22:14 - 2017-12-13 22:14 - 001288406 _____ C:\Users\admin\Downloads\table_craft_v2.xlsm
2017-12-13 16:50 - 2017-11-30 10:33 - 005688320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-12-13 16:50 - 2017-11-30 10:29 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-12-13 16:50 - 2017-11-30 10:28 - 007625728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-12-13 16:50 - 2017-11-30 10:28 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-12-13 16:50 - 2017-11-30 10:28 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2017-12-13 16:50 - 2017-11-30 10:26 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2017-12-13 16:50 - 2017-11-30 10:25 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2017-12-13 16:50 - 2017-11-30 10:25 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2017-12-13 16:50 - 2017-11-30 10:25 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx
2017-12-13 16:50 - 2017-11-30 10:24 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2017-12-13 16:50 - 2017-11-30 10:17 - 000858624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2017-12-13 16:50 - 2017-11-30 10:17 - 000579072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2017-12-13 16:50 - 2017-11-30 10:15 - 001599488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-12-13 16:50 - 2017-11-30 10:15 - 000711168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2017-12-13 16:50 - 2017-11-30 10:14 - 002028032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-12-13 16:50 - 2017-11-30 10:14 - 000859136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2017-12-13 16:49 - 2017-11-30 10:45 - 000982392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-12-13 16:49 - 2017-11-30 10:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-12-13 16:49 - 2017-11-30 10:25 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2017-12-13 16:49 - 2017-11-30 10:25 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2017-12-13 16:49 - 2017-11-30 10:24 - 000822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-12-13 16:49 - 2017-11-30 10:24 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-12-13 16:49 - 2017-11-30 10:24 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshext.dll
2017-12-13 16:49 - 2017-11-30 10:23 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll
2017-12-13 16:49 - 2017-11-30 10:23 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-12-13 16:49 - 2017-11-30 10:23 - 000205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2017-12-13 16:49 - 2017-11-30 10:22 - 019411968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-12-13 16:49 - 2017-11-30 10:22 - 018366976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-12-13 16:49 - 2017-11-30 10:22 - 012205056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-12-13 16:49 - 2017-11-30 10:21 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-12-13 16:49 - 2017-11-30 10:16 - 006066688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-12-13 16:49 - 2017-11-30 10:16 - 003662848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-12-13 16:49 - 2017-11-30 10:16 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-12-13 16:49 - 2017-11-30 10:16 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2017-12-13 16:49 - 2017-11-30 10:14 - 000656896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-12-13 16:49 - 2017-03-04 07:19 - 000635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-12-13 16:10 - 2017-11-30 08:45 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-12-13 16:10 - 2017-11-30 08:41 - 009129984 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-12-13 16:10 - 2017-11-30 08:39 - 000187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2017-12-13 16:10 - 2017-11-30 08:37 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2017-12-13 16:10 - 2017-11-30 08:37 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2017-12-13 16:10 - 2017-11-30 08:36 - 001146880 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2017-12-13 16:10 - 2017-11-30 08:36 - 000761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2017-12-13 16:10 - 2017-11-30 08:33 - 001013760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2017-12-13 16:10 - 2017-11-30 08:32 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2017-12-13 16:10 - 2016-09-07 05:56 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2017-12-13 16:09 - 2017-11-30 08:42 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2017-12-13 16:09 - 2017-11-30 08:40 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2017-12-13 16:09 - 2017-11-30 08:38 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-12-13 16:09 - 2017-11-30 08:38 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2017-12-13 16:09 - 2017-11-30 08:37 - 008118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-12-13 16:09 - 2017-11-30 08:37 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2017-12-13 16:09 - 2017-11-30 08:37 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-12-13 16:09 - 2017-11-30 08:37 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshext.dll
2017-12-13 16:09 - 2017-11-30 08:36 - 004749824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-12-13 16:09 - 2017-11-30 08:34 - 004739584 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-12-13 16:09 - 2017-11-30 08:33 - 000583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-12-13 16:09 - 2017-11-30 08:32 - 000799744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-12-13 16:08 - 2017-11-30 08:42 - 000862208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-12-13 16:08 - 2017-11-30 08:37 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-12-13 16:07 - 2017-11-30 09:22 - 007780184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-12-13 16:05 - 2017-11-30 09:15 - 001072240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-12-13 16:02 - 2017-11-30 08:53 - 022571520 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-12-13 16:02 - 2017-11-30 08:38 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-12-13 16:02 - 2017-11-30 08:36 - 013108224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-12-13 16:02 - 2017-11-30 08:36 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2017-12-13 16:01 - 2017-11-30 08:45 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-12-13 16:01 - 2017-11-30 08:44 - 000173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2017-12-13 16:01 - 2017-11-30 08:36 - 023674880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-12-13 16:01 - 2017-11-30 08:33 - 002097664 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-12-13 16:01 - 2017-11-30 08:33 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-12-13 16:00 - 2017-11-30 08:50 - 007219200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-12-13 16:00 - 2017-11-30 08:37 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-12-13 15:58 - 2017-11-30 09:17 - 000983896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-12-13 15:58 - 2017-11-30 09:16 - 001090904 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-12-13 15:58 - 2017-11-30 09:16 - 000947544 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-12-13 15:58 - 2017-11-30 09:16 - 000811864 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-12-12 20:25 - 2017-12-12 20:50 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_13
2017-12-12 20:25 - 2017-12-12 20:25 - 000000000 ____D C:\Users\admin\AppData\Roaming\Dofus-13
2017-12-12 14:55 - 2017-12-12 16:43 - 000000413 _____ C:\Users\admin\Desktop\Nouveau document texte (4).txt
2017-12-10 01:26 - 2017-12-10 01:26 - 000053320 _____ C:\Users\admin\Downloads\DMLr58_nmm_nodisc.elf
2017-12-08 23:43 - 2017-12-12 03:35 - 000000085 _____ C:\Users\admin\Desktop\ordre.txt
2017-12-08 21:24 - 2017-12-08 21:24 - 003943138 _____ C:\Users\admin\Downloads\Doftabula2.0.xlsx
2017-12-08 13:54 - 2017-12-08 13:55 - 004493922 _____ C:\Users\admin\Downloads\nAiO.zip
2017-12-08 00:10 - 2017-12-08 00:10 - 000000000 ____D C:\Users\admin\AppData\Local\Clavier+
2017-12-08 00:10 - 2017-12-08 00:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clavier+
2017-12-08 00:09 - 2017-12-08 00:10 - 000578492 _____ (Guillaume Ryder (hxxp://utilfr42.free.fr) ) C:\Users\admin\Downloads\ClavierSetup64.exe
2017-12-08 00:09 - 2017-12-08 00:10 - 000578492 _____ (Guillaume Ryder (hxxp://utilfr42.free.fr) ) C:\Users\admin\Downloads\ClavierSetup64 (3).exe
2017-12-08 00:09 - 2017-12-08 00:10 - 000578492 _____ (Guillaume Ryder (hxxp://utilfr42.free.fr) ) C:\Users\admin\Downloads\ClavierSetup64 (2).exe
2017-12-08 00:09 - 2017-12-08 00:10 - 000578492 _____ (Guillaume Ryder (hxxp://utilfr42.free.fr) ) C:\Users\admin\Downloads\ClavierSetup64 (1).exe

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2018-01-05 22:30 - 2017-11-22 20:02 - 000000000 ____D C:\Users\admin\AppData\Local\MyComGames
2018-01-05 22:27 - 2017-05-19 23:04 - 000000000 ____D C:\Users\admin\AppData\Roaming\Skype
2018-01-05 22:18 - 2016-07-16 12:36 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-01-05 21:18 - 2016-12-22 20:10 - 000000000 ____D C:\Program Files (x86)\Google
2018-01-05 21:03 - 2016-07-16 12:45 - 000000000 ____D C:\WINDOWS\INF
2018-01-05 20:52 - 2016-12-29 19:50 - 000000000 __SHD C:\Users\admin\IntelGraphicsProfiles
2018-01-05 20:51 - 2017-10-30 15:21 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2018-01-05 20:51 - 2016-12-04 20:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-01-05 20:50 - 2016-07-16 07:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-01-05 20:37 - 2016-12-29 19:50 - 000000000 ____D C:\Users\admin
2018-01-05 20:35 - 2016-10-29 22:31 - 000000000 ____D C:\Users\simon\AppData\Local\Akamai
2018-01-05 20:25 - 2016-12-04 20:24 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-01-05 20:01 - 2016-12-29 19:50 - 000000000 ____D C:\Users\admin\AppData\Local\Google
2018-01-05 19:03 - 2017-05-19 23:03 - 000004178 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{54038C03-FB3F-44E8-BAF7-28F61588CFE5}
2018-01-05 12:42 - 2017-06-02 22:30 - 000000000 ____D C:\Users\admin\AppData\Local\CrashDumps
2018-01-05 00:52 - 2017-07-26 01:52 - 000000000 ____D C:\ProgramData\{47648207-CD26-08C1-4BE0-9683D1A21D4D}
2018-01-04 23:55 - 2017-06-02 21:48 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2018-01-04 23:51 - 2017-06-30 22:36 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_7
2018-01-04 23:51 - 2017-06-30 22:36 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_6
2018-01-04 23:51 - 2017-06-22 14:16 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_5
2018-01-04 23:51 - 2017-06-21 21:43 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_4
2018-01-04 23:51 - 2017-06-20 20:12 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_3
2018-01-04 23:51 - 2017-06-18 21:39 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_2
2018-01-04 23:34 - 2017-06-18 21:38 - 000000117 _____ C:\Users\admin\AppData\Roaming\D2Info0
2018-01-04 23:34 - 2017-06-18 21:38 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_1
2018-01-04 22:19 - 2017-05-23 23:26 - 000000364 _____ C:\WINDOWS\Tasks\HPCeeScheduleForadmin.job
2018-01-04 22:17 - 2017-07-26 01:52 - 000000000 ____D C:\Users\admin\AppData\Roaming\7d680b9aa3c0beadce4348fc5af0debb
2018-01-04 17:28 - 2017-07-26 01:51 - 000001740 __RSH C:\ProgramData\ntuser.pol
2018-01-04 02:51 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-01-03 16:56 - 2017-05-23 23:26 - 000003256 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForadmin
2018-01-03 02:24 - 2016-07-16 12:47 - 000000000 ___HD C:\Program Files\WindowsApps
2018-01-02 00:21 - 2017-06-25 22:58 - 000000000 ____D C:\Program Files (x86)\steam2
2018-01-01 20:54 - 2016-12-29 19:50 - 000000000 ____D C:\Users\admin\AppData\Local\Packages
2017-12-31 12:58 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-12-30 18:53 - 2017-09-01 00:40 - 573316482 _____ C:\WINDOWS\MEMORY.DMP
2017-12-30 18:53 - 2017-02-02 19:52 - 000000000 ____D C:\WINDOWS\Minidump
2017-12-30 18:32 - 2017-10-24 20:33 - 000000000 ____D C:\ProgramData\TrackMania
2017-12-30 18:32 - 2017-10-24 20:31 - 000000000 ____D C:\Users\admin\Documents\TrackMania
2017-12-30 14:58 - 2017-07-05 19:33 - 000000000 ____D C:\Users\admin\AppData\Roaming\TS3Client
2017-12-30 00:52 - 2017-07-26 23:52 - 000000386 _____ C:\Users\admin\AppData\Roaming\WB.CFG
2017-12-29 19:23 - 2017-11-19 01:50 - 000003544 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachineDaily
2017-12-29 19:23 - 2017-11-19 01:50 - 000003408 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachine
2017-12-29 19:23 - 2017-11-19 01:49 - 000000000 ____D C:\Program Files (x86)\Gyazo
2017-12-24 02:21 - 2017-10-21 00:59 - 000007606 _____ C:\Users\admin\AppData\Local\Resmon.ResmonCfg
2017-12-23 21:57 - 2017-07-16 21:32 - 000001270 _____ C:\Users\admin\Desktop\nativelog.txt
2017-12-23 19:00 - 2017-06-18 22:31 - 000000000 ____D C:\Users\admin\AppData\Roaming\.minecraft
2017-12-22 23:06 - 2017-06-18 20:56 - 000233100 _____ C:\Users\admin\AppData\Localtransition_c5ea1a0f4e99f0e619093c059dbff7b7.ini
2017-12-22 00:08 - 2017-10-13 13:53 - 000000000 ____D C:\Users\admin\AppData\Roaming\Hide.me
2017-12-19 18:29 - 2017-10-17 13:03 - 000000000 ____D C:\Users\admin\AppData\Roaming\Dofus
2017-12-18 16:05 - 2017-03-21 00:54 - 000000000 ____D C:\Program Files (x86)\NCSOFT
2017-12-18 01:31 - 2017-06-17 17:32 - 000000000 ____D C:\Users\admin\AppData\Local\ElevatedDiagnostics
2017-12-17 19:47 - 2017-12-02 15:53 - 000000000 ____D C:\Users\admin\AppData\Local\Warframe
2017-12-17 19:45 - 2017-11-23 18:18 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My.com
2017-12-17 19:45 - 2017-11-22 20:02 - 000000000 ____D C:\MyGames
2017-12-17 19:42 - 2017-07-26 02:48 - 000000000 ____D C:\Users\admin\AppData\Local\Crossout
2017-12-17 17:45 - 2017-06-27 21:45 - 000000000 ____D C:\Users\admin\AppData\Roaming\discord
2017-12-17 00:46 - 2017-10-06 13:48 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_10
2017-12-17 00:46 - 2017-09-22 18:32 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_9
2017-12-17 00:45 - 2017-06-30 22:37 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_8
2017-12-17 00:39 - 2017-07-25 16:29 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3891560280-1250424028-3305681315-1003
2017-12-17 00:39 - 2017-05-19 23:04 - 000002418 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-12-17 00:39 - 2017-05-19 23:04 - 000000000 ___RD C:\Users\admin\OneDrive
2017-12-16 23:45 - 2017-01-31 18:19 - 000000000 ____D C:\Program Files (x86)\FirestormLauncher
2017-12-15 21:34 - 2017-08-09 17:33 - 000000000 ____D C:\Users\admin\AppData\Local\LogMeIn Hamachi
2017-12-15 04:20 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\rescache
2017-12-14 13:59 - 2017-06-16 03:16 - 000000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-12-13 18:37 - 2016-10-11 17:12 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-12-13 18:28 - 2017-10-11 18:12 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-12-13 18:28 - 2016-10-11 17:11 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-12-13 16:52 - 2017-06-22 01:07 - 000013346 _____ C:\Users\admin\AppData\Localtransition_5d582b6549b06724c3ee7993af1b7c74.ini
2017-12-12 19:38 - 2017-10-31 22:59 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_12
2017-12-12 19:38 - 2017-10-31 22:59 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_11
2017-12-12 16:24 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-12-12 16:24 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-12-12 03:47 - 2017-06-27 21:45 - 000000000 ____D C:\Users\admin\AppData\Local\Discord
2017-12-12 02:27 - 2017-12-05 17:53 - 000000068 _____ C:\Users\admin\AppData\Local\crGPYhwLUd
2017-12-09 22:22 - 2017-07-26 09:21 - 000000000 ____D C:\Program Files (x86)\Elsword
2017-12-07 23:22 - 2017-09-29 19:55 - 000000000 ____D C:\Program Files\rempl

==================== Fichiers à la racine de certains dossiers =======

2018-01-05 21:37 - 2018-01-05 21:37 - 001388448 _____ () C:\Users\Public\ASR.dat
2018-01-05 22:09 - 2018-01-05 22:30 - 001388448 _____ () C:\Users\Public\VOIP.dat
2017-06-18 21:38 - 2018-01-04 23:34 - 000000117 _____ () C:\Users\admin\AppData\Roaming\D2Info0
2017-07-26 03:21 - 2017-07-26 03:21 - 000000008 ___SH () C:\Users\admin\AppData\Roaming\date
2017-06-18 21:38 - 2018-01-04 23:34 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_1
2017-10-06 13:48 - 2017-12-17 00:46 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_10
2017-10-31 22:59 - 2017-12-12 19:38 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_11
2017-10-31 22:59 - 2017-12-12 19:38 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_12
2017-12-12 20:25 - 2017-12-12 20:50 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_13
2017-06-18 21:39 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_2
2017-06-20 20:12 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_3
2017-06-21 21:43 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_4
2017-06-22 14:16 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_5
2017-06-30 22:36 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_6
2017-06-30 22:36 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_7
2017-06-30 22:37 - 2017-12-17 00:45 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_8
2017-09-22 18:32 - 2017-12-17 00:46 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_9
2017-07-26 03:21 - 2017-07-26 03:21 - 000000002 ___SH () C:\Users\admin\AppData\Roaming\evf9
2017-06-19 23:45 - 2016-07-28 07:26 - 000000701 _____ () C:\Users\admin\AppData\Roaming\pdfCodec.dll
2017-12-30 23:02 - 2018-01-05 12:42 - 000000000 _____ () C:\Users\admin\AppData\Roaming\rbx_hook
2017-12-30 23:02 - 2018-01-05 12:39 - 000000024 _____ () C:\Users\admin\AppData\Roaming\version
2017-07-26 23:52 - 2017-12-30 00:52 - 000000386 _____ () C:\Users\admin\AppData\Roaming\WB.CFG
2017-08-17 23:30 - 2017-08-17 23:30 - 000000600 _____ () C:\Users\admin\AppData\Roaming\winscp.rnd
2017-12-05 17:53 - 2017-12-12 02:27 - 000000068 _____ () C:\Users\admin\AppData\Local\crGPYhwLUd
2017-11-20 04:54 - 2017-11-20 04:54 - 000003950 _____ () C:\Users\admin\AppData\Local\recently-used.xbel
2017-10-21 00:59 - 2017-12-24 02:21 - 000007606 _____ () C:\Users\admin\AppData\Local\Resmon.ResmonCfg
2017-12-17 00:54 - 2017-12-17 00:54 - 000000068 _____ () C:\Users\admin\AppData\Local\u7hu7hu7hu
2017-12-15 23:24 - 2017-12-15 23:24 - 000000003 _____ () C:\Users\admin\AppData\Local\updater.log
2017-12-15 23:24 - 2017-12-15 23:24 - 000000425 _____ () C:\Users\admin\AppData\Local\UserProducts.xml

Fichiers à déplacer ou supprimer:
====================
C:\Windows\Tasks\{7D680B9A-A3C0-BEAD-CE43-48FC5AF0DEBB}.job


Certains fichiers dans TEMP:
====================
2017-08-15 22:54 - 2017-09-15 21:53 - 058881488 _____ (Skype Technologies S.A.) C:\Users\admin\AppData\Local\Temp\SkypeSetup.exe
2017-08-24 06:52 - 2017-05-14 02:48 - 004819328 _____ (Conexant Systems, Inc.) C:\Users\admin\AppData\Local\Temp\UCI64A152.dll
2017-07-06 08:54 - 2017-07-06 08:54 - 013767776 _____ (Microsoft Corporation) C:\Users\admin\AppData\Local\Temp\vcredist_x86.exe
2017-05-19 22:16 - 2017-02-25 22:48 - 006207144 _____ (Ankama Studio) C:\Users\simon\AppData\Local\Temp\AnkCBA0.tmp.exe
2017-03-10 20:51 - 2017-03-10 20:51 - 007850088 _____ (Microsoft Corporation) C:\Users\simon\AppData\Local\Temp\BingBarSetup-Partner.exe
2017-03-23 02:19 - 2016-11-11 11:13 - 001886344 _____ (Microsoft Corporation) C:\Users\simon\AppData\Local\Temp\dllnt_dump.dll
2017-04-17 22:05 - 2017-04-17 22:05 - 030403752 _____ (ArenaNet) C:\Users\simon\AppData\Local\Temp\Gw2.exe
2017-01-29 18:13 - 2017-01-29 18:13 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-1985485331588977498.dll
2017-01-29 17:55 - 2017-01-29 17:55 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-2086715013686853229.dll
2017-05-19 10:04 - 2017-05-19 10:04 - 000019968 _____ (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-2385520288476598190.dll
2017-01-28 13:35 - 2017-01-28 13:35 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-3558720170433754775.dll
2017-05-19 20:12 - 2017-05-19 20:12 - 000019968 _____ (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-390670231083036671.dll
2017-05-19 20:38 - 2017-05-19 20:38 - 000019968 _____ (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-4252402690600377242.dll
2017-01-30 16:42 - 2017-01-30 16:42 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-4889808334455093373.dll
2017-01-31 15:47 - 2017-01-31 15:47 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-5014849079598785681.dll
2017-01-30 19:56 - 2017-01-30 19:56 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-5437877589607001702.dll
2017-01-31 00:42 - 2017-01-31 00:42 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-6349078996772930603.dll
2017-01-27 12:30 - 2017-01-27 12:30 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-7090333953204794317.dll
2017-01-30 14:00 - 2017-01-30 14:00 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-713178486336768923.dll
2017-02-22 16:05 - 2017-02-22 16:05 - 000739904 _____ (Oracle Corporation) C:\Users\simon\AppData\Local\Temp\jre-8u121-windows-au.exe
2017-04-15 19:52 - 2017-04-15 19:52 - 014456872 _____ (Microsoft Corporation) C:\Users\simon\AppData\Local\Temp\vc_redist.x86.exe
2017-03-24 18:31 - 2017-03-24 18:32 - 013767776 _____ (Microsoft Corporation) C:\Users\simon\AppData\Local\Temp\vsredistsetup.exe

==================== Bamital & volsnap ======================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

LastRegBack: 2017-12-30 02:34

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité