cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 17.02.2018
Exécuté par arnau_000 (administrateur) sur ARNODINATEUR (18-02-2018 13:06:59)
Exécuté depuis C:\Users\arnau_000\Downloads
Profils chargés: arnau_000 (Profils disponibles: arnau_000)
Platform: Windows 10 Home Version 1703 15063.786 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Edge)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
(Razer Inc) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Windows\System32\wimserv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
() C:\Program Files\ByteFence\rtop\bin\rtop_bg.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\Beats64.exe
(© 2015 Microsoft Corporation) C:\Users\arnau_000\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Valve Corporation) C:\Users\arnau_000\Desktop\Steam\Steam.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Overwolf LTD) C:\Program Files (x86)\Overwolf\Overwolf.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.110.2.28\OverwolfHelper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1803.279.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.110.2.28\OverwolfHelper64.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.110.2.28\OverwolfBrowser.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.110.2.28\OverwolfBrowser.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.110.2.28\OverwolfBrowser.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Byte Technologies LLC) C:\Program Files\ByteFence\ByteFence.exe
() C:\Program Files\ByteFence\rsLggr.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.724_none_9e8a868b2d8a538d\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [16293496 2016-09-29] (Logitech Inc.)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2012-08-22] (Hewlett-Packard )
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-10-06] (Oracle Corporation)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2016-11-04] (Razer Inc.)
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1 [433752 2016-02-16] ()
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1 [433752 2016-02-16] ()
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\...\Run: [Google Update] => C:\Users\arnau_000\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-15] (Google Inc.)
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\...\Run: [BingSvc] => C:\Users\arnau_000\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-12] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\...\Run: [Steam] => C:\Users\arnau_000\Desktop\Steam\steam.exe [3102496 2017-10-31] (Valve Corporation)
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [1206600 2018-02-07] ()
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4701888 2017-04-24] (Disc Soft Ltd)
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\...\Run: [Hearthstone Deck Tracker] => C:\Users\arnau_000\AppData\Local\HearthstoneDeckTracker\Update.exe [1530144 2017-05-02] (GitHub)
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\...\Run: [Chromium] => "c:\users\arnau_000\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory=Default --restore-last-session
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [150016 2017-03-18] (Microsoft Corporation)
Startup: C:\Users\arnau_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Envoyer à OneNote.lnk [2017-01-10]
ShortcutTarget: Envoyer à OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-3286503035-1535481467-653880807-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

ProxyServer: [S-1-5-21-3286503035-1535481467-653880807-1001] => 127.0.0.1:8080
Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{2b91d8ff-bbd0-4f24-b13b-d4b092b5ef29}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{7a1df697-5f9f-4d49-af51-d2de6cfb44a2}: [DhcpNameServer] 212.27.40.241 212.27.40.240
Tcpip\..\Interfaces\{ffc1fa07-2d42-4dcb-8573-11e2061dcb3a}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130905219190542388&GUID=02C6BE4A-798D-4A6F-B575-1343204FCBB7
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
HKU\S-1-5-21-3286503035-1535481467-653880807-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM -> {8354D569-1A13-4AEB-AE0A-1B873B0178DB} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/709-29563-11896-9/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {5A3E4EF3-107D-4A42-A1E0-986C4CFD74A2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\.DEFAULT -> {5A3E4EF3-107D-4A42-A1E0-986C4CFD74A2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> DefaultScope {62E8E561-64AB-4DF5-B764-0F2ECB87A6DD} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3320133&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP7EF9FAE0-9F56-4867-A672-87D9CF04C917&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> {62E8E561-64AB-4DF5-B764-0F2ECB87A6DD} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-02-17] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-21] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-21] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
Toolbar: HKLM - Pas de nom - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Pas de fichier
Toolbar: HKU\S-1-5-21-3286503035-1535481467-653880807-1001 -> Pas de nom - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Pas de fichier
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-17] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-17] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-17] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-17] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: nrzvw581.default
FF ProfilePath: C:\Users\arnau_000\AppData\Roaming\Mozilla\Firefox\Profiles\nrzvw581.default [2018-02-18]
FF Homepage: Mozilla\Firefox\Profiles\nrzvw581.default -> hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_17_17¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CyC0A0DzztB0CtCtBtN0D0Tzu0StCzyyEyDtN1L2XzutAtFtBzytFtAtFyCzytN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyE0FzztDzy0DtDzztGtDtDtByCtGtC0FtC0EtGtA0FyC0FtGtA0A0EyDtC0E0B0A0B0EyB0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0AyDyEyB0FzzyCtGtA0DtAtCtGyE0AtC0AtG0BtByDtAtG0Azyzy0EzytBtAzyyE0F0Azy2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtByBzzyC%26cr%3D1938377034%26a%3Dwbf_ir_17_17%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
FF SearchPlugin: C:\Users\arnau_000\AppData\Roaming\Mozilla\Firefox\Profiles\nrzvw581.default\searchplugins\yahoo! powered.xml [2017-04-29]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-07-18] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-07-18] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-02-17] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-12-26] (Pando Networks)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll [2013-12-26] ()
FF Plugin HKU\S-1-5-21-3286503035-1535481467-653880807-1001: @tools.google.com/Google Update;version=3 -> C:\Users\arnau_000\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-3286503035-1535481467-653880807-1001: @tools.google.com/Google Update;version=9 -> C:\Users\arnau_000\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-3286503035-1535481467-653880807-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-12-26] (Pando Networks)
StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome:
=======
CHR DefaultProfile: Default
CHR dev: Chrome dev build détecté(e)! <==== ATTENTION
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Profile: C:\Users\arnau_000\AppData\Local\Google\Chrome\User Data\Default [2018-02-18]
CHR Extension: (Mendeleev) - C:\Users\arnau_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmbmmigkebmnhneojhjcphnccfijlmlc [2016-12-21]
CHR Extension: (Skype) - C:\Users\arnau_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-01-17]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\arnau_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-25]
CHR Extension: (Chrome Media Router) - C:\Users\arnau_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-17]
CHR HKLM\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3286503035-1535481467-653880807-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2017-12-30] ()
S2 ByteFenceService; C:\Program Files\ByteFence\ByteFenceService.exe [145888 2017-07-20] (Byte Technologies LLC)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7968432 2018-01-30] (Microsoft Corporation)
R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-09-27] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-09-27] (CyberLink)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-04-24] (Disc Soft Ltd)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-02-05] (WildTangent)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [323952 2017-09-27] (HP Inc.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193656 2016-09-29] (Logitech Inc.)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1452360 2018-02-07] (Overwolf LTD)
S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] ()
R2 rtop; C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe [302920 2017-08-25] ()
R2 RzSurroundVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe [4261344 2016-11-04] (Razer Inc)
S3 wampapache64; c:\wamp64\bin\apache\apache2.4.23\bin\httpd.exe [29696 2016-07-01] (Apache Software Foundation) [Fichier non signé]
S3 wampmysqld64; c:\wamp64\bin\mysql\mysql5.7.14\bin\mysqld.exe [39885824 2016-07-12] () [Fichier non signé]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-02-18] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-02-18] (Microsoft Corporation)
S2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"

===================== Pilotes (Avec liste blanche) ======================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
S3 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [36096 2013-05-22] (Advanced Micro Devices, Inc.)
S3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-15] (CyberLink)
S3 CV2K1; C:\WINDOWS\system32\DRIVERS\cv2k1.sys [21544 2009-06-17] (TamoSoft)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [129152 2016-04-24] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-02-21] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-02-21] (Disc Soft Ltd)
S3 ElgatoGC658Y; C:\WINDOWS\System32\Drivers\ElgatoGC658.sys [50288 2012-11-12] (UB658)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)
R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2016-09-29] (Logitech Inc.)
R1 MpKsle58f0280; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D05ABB6A-2AE9-4B42-A450-EE5352AB38EE}\MpKsle58f0280.sys [58120 2018-01-17] (Microsoft Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-01-20] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48064 2017-09-19] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [896752 2015-08-07] (Realtek )
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [137840 2016-09-07] (Razer, Inc.)
R3 RZSURROUNDVADService; C:\WINDOWS\system32\drivers\RzSurroundVAD.sys [49176 2016-10-16] (Windows (R) Win 7 DDK provider)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [221824 2016-04-24] (Samsung Electronics Co., Ltd.)
R3 tilfilter; C:\WINDOWS\System32\drivers\TIxHCIlfilter.sys [34424 2016-08-19] (Texas Instruments, Inc.)
R3 tiufilter; C:\WINDOWS\System32\drivers\TIxHCIufilter.sys [39032 2016-08-19] (Texas Instruments, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2018-02-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2018-02-18] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2018-02-18] (Microsoft Corporation)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [36808 2016-11-21] (Wellbia.com Co., Ltd.)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2018-02-18 13:08 - 2018-02-18 13:08 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-02-18 13:06 - 2018-02-18 13:09 - 000031506 _____ C:\Users\arnau_000\Downloads\FRST.txt
2018-02-18 13:05 - 2018-02-18 13:06 - 000000000 ____D C:\FRST
2018-02-18 13:03 - 2018-02-18 13:04 - 002403840 _____ (Farbar) C:\Users\arnau_000\Downloads\FRST64.exe
2018-02-18 11:41 - 2018-02-18 11:41 - 000000046 _____ C:\Users\arnau_000\AppData\Roaming\WB.CFG
2018-02-18 11:11 - 2018-02-18 11:11 - 000000000 ____D C:\Users\arnau_000\AppData\Local\Chromium
2018-02-17 13:46 - 2018-02-17 13:46 - 000002404 _____ C:\Users\arnau_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium.lnk
2018-02-17 13:41 - 2018-02-17 13:41 - 000000000 ____D C:\WINDOWS\System32\Tasks\Rulaf
2018-02-17 13:41 - 2018-02-17 13:41 - 000000000 ____D C:\Users\arnau_000\AppData\Roaming\15806A95-4646-1262-A088-5CA15B4A712A
2018-02-17 13:40 - 2018-02-17 13:48 - 000000000 ____D C:\Users\arnau_000\AppData\Local\{2F8919D5-0B21-756D-66B9-508542D1AC1D}
2018-02-17 13:40 - 2018-02-17 13:40 - 000004088 _____ C:\WINDOWS\System32\Tasks\Secured Yahoo Powered fanol
2018-02-17 13:40 - 2018-02-17 13:40 - 000000988 _____ C:\WINDOWS\Tasks\Secured Yahoo Powered fanol.job
2018-02-17 13:40 - 2018-02-17 13:40 - 000000000 ____D C:\ProgramData\{1815DD76-9257-57B0-1491-C9F28ED3423C}
2018-02-17 12:03 - 2018-02-17 12:03 - 000000000 ___HD C:\OneDriveTemp

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2018-02-18 13:09 - 2018-01-17 16:18 - 000000000 ____D C:\Program Files\rempl
2018-02-18 13:07 - 2016-12-26 19:24 - 000000000 _____ C:\WINDOWS\system32\RzSurroundVADAudioDeviceManager_log.txt
2018-02-18 13:06 - 2017-04-29 10:43 - 000000000 ____D C:\Program Files\ByteFence
2018-02-18 12:59 - 2017-07-27 13:00 - 000000000 ___DC C:\WINDOWS\Panther
2018-02-18 12:49 - 2017-04-29 10:49 - 000000000 ____D C:\ProgramData\{1BFADE99-91B8-545F-177E-CA1D8D3C41D3}
2018-02-18 12:22 - 2017-07-28 11:52 - 000024768 _____ C:\WINDOWS\diagwrn.xml
2018-02-18 12:22 - 2017-07-28 11:52 - 000024768 _____ C:\WINDOWS\diagerr.xml
2018-02-18 11:46 - 2017-03-18 22:01 - 000000000 ____D C:\WINDOWS\INF
2018-02-18 11:18 - 2017-03-18 21:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-02-18 11:17 - 2016-12-04 11:59 - 000000000 ____D C:\Program Files (x86)\Overwolf
2018-02-18 11:14 - 2017-07-28 11:26 - 000000000 ____D C:\Users\arnau_000
2018-02-18 11:13 - 2016-12-04 11:57 - 000000000 ____D C:\Users\arnau_000\AppData\Local\Overwolf
2018-02-18 11:12 - 2015-01-05 21:19 - 000000000 __RDO C:\Users\arnau_000\OneDrive
2018-02-18 11:11 - 2017-07-28 11:24 - 000000000 ____D C:\ProgramData\NVIDIA
2018-02-18 11:10 - 2016-01-28 19:47 - 000000000 ____D C:\Users\arnau_000\Desktop\Steam
2018-02-17 19:15 - 2017-07-28 11:21 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-02-17 19:14 - 2014-01-20 19:32 - 000000000 ____D C:\Users\arnau_000\AppData\Local\Battle.net
2018-02-17 19:00 - 2017-03-18 12:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-02-17 18:51 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\Registration
2018-02-17 18:50 - 2017-09-30 16:03 - 000000000 ___HD C:\$WINDOWS.~BT
2018-02-17 18:16 - 2014-01-20 19:34 - 000000000 ____D C:\Program Files (x86)\Hearthstone
2018-02-17 18:06 - 2014-01-20 19:32 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-02-17 17:50 - 2017-12-30 13:16 - 000000000 ____D C:\Users\arnau_000\AppData\Local\UnrealEngine
2018-02-17 17:01 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
2018-02-17 17:01 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-02-17 13:03 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\rescache
2018-02-17 12:59 - 2017-03-18 22:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-02-17 12:56 - 2013-11-06 12:18 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-02-17 12:20 - 2017-05-03 12:24 - 000000000 ____D C:\Users\arnau_000\AppData\Local\HearthstoneDeckTracker
2018-02-17 12:20 - 2016-01-24 18:47 - 000000000 ____D C:\Users\arnau_000\AppData\Local\SquirrelTemp
2018-02-17 12:07 - 2015-01-11 10:07 - 000548000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-02-17 12:03 - 2017-07-28 11:47 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3286503035-1535481467-653880807-1001
2018-02-17 12:03 - 2016-04-15 19:37 - 000002469 _____ C:\Users\arnau_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-02-17 11:56 - 2016-02-13 14:18 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-02-17 11:39 - 2017-07-28 11:25 - 002416450 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-02-17 11:39 - 2017-03-20 06:10 - 001090202 _____ C:\WINDOWS\system32\perfh00C.dat
2018-02-17 11:39 - 2017-03-20 06:10 - 000245816 _____ C:\WINDOWS\system32\perfc00C.dat
2018-02-17 11:33 - 2017-07-28 11:47 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-02-17 11:33 - 2017-07-28 11:21 - 000407888 _____ C:\WINDOWS\system32\FNTCACHE.DAT

==================== Fichiers à la racine de certains dossiers =======

2016-01-01 21:04 - 2016-01-01 21:04 - 001980928 _____ () C:\Users\arnau_000\ZHPCleaner.exe
2016-11-22 12:38 - 2016-11-22 12:38 - 000000095 _____ () C:\Users\arnau_000\AppData\Roaming\LauncherSettings_live.cfg
2016-11-22 12:37 - 2016-11-22 12:37 - 000010369 _____ () C:\Users\arnau_000\AppData\Roaming\TheHunterSettings_live.bin
2016-11-22 12:36 - 2016-11-22 12:36 - 000000042 _____ () C:\Users\arnau_000\AppData\Roaming\TheHunterSettings_steam_live.cfg
2018-02-18 11:41 - 2018-02-18 11:41 - 000000046 _____ () C:\Users\arnau_000\AppData\Roaming\WB.CFG
2016-11-03 18:45 - 2017-09-27 20:20 - 000000600 _____ () C:\Users\arnau_000\AppData\Local\PUTTY.RND
2017-03-12 15:50 - 2017-03-12 15:50 - 000007599 _____ () C:\Users\arnau_000\AppData\Local\Resmon.ResmonCfg
2015-12-06 08:50 - 2015-12-06 08:50 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{082F548B-9623-440D-B420-92446C01E7A7}
2015-12-12 12:39 - 2015-12-12 12:39 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{1BDA9A6E-76D8-4357-AA53-D0B64A9223A3}
2015-12-05 20:04 - 2015-12-05 20:04 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{22AF4487-6681-48B5-8AC5-74015A862E46}
2015-12-05 20:32 - 2015-12-05 20:32 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{2E3871A9-1DEB-4EF4-82F8-591FA076D3C8}
2015-12-05 20:10 - 2015-12-05 20:10 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{3AFD651C-FDE5-44E7-A057-5B22A81A7609}
2015-12-05 20:29 - 2015-12-05 20:29 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{437188D8-B994-4E4B-A68B-2445F3CA6411}
2015-12-20 18:57 - 2015-12-20 18:57 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{45099D8D-10D0-4917-ABAC-2B37FC75AD5A}
2015-12-03 19:52 - 2015-12-03 19:52 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{63F433A1-4573-482F-92D9-FD44A5431CB4}
2015-12-03 19:37 - 2015-12-03 19:37 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{73EC62DD-832A-468F-BF6B-CF022B6F3773}
2015-12-21 19:37 - 2015-12-21 19:37 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{B9E3C77A-E106-4C50-8ACC-D8DA6459128C}
2015-12-05 18:40 - 2015-12-05 18:40 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{D15E3F54-C696-448C-9C52-3F0A51B1ED75}
2015-12-19 10:40 - 2015-12-19 10:40 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{EB6B45CA-6E33-46C6-8226-87FF07736B80}
2015-12-13 14:51 - 2015-12-13 14:51 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{EC049CFC-A2C7-48E6-9CE1-CF0D65DBDE7D}
2015-12-21 19:48 - 2015-12-21 19:48 - 000000000 _____ () C:\Users\arnau_000\AppData\Local\{F5903ECC-B97F-4047-9094-506E5B400868}

==================== Bamital & volsnap ======================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement
C:\WINDOWS\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

LastRegBack: 2018-02-17 11:43

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité