cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 09.12.2018
Exécuté par roland (administrateur) sur ROLAND-HP (09-12-2018 21:12:27)
Exécuté depuis C:\Users\roland\Desktop
Profils chargés: roland (Profils disponibles: roland)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Opera)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Orange\ma Livebox\dedicarz\DedicarzService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(IFS Informationstechnik GmbH) C:\EC-APPS\CarServer\mkp-vs\vservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\USBhostFW.exe
(The Firebird Project) C:\APP\firebird\bin\fbguard.exe
(The Firebird Project) C:\APP\firebird\bin\fbserver.exe
(ACTIA) C:\AWRoot\bin\common\rsvr\AWRSrv.exe
() C:\AWRoot\bin\common\mcc\MCComm.exe
(Opera Software) C:\Program Files (x86)\Opera\56.0.3051.116\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\56.0.3051.116\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\56.0.3051.116\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\56.0.3051.116\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\56.0.3051.116\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\56.0.3051.116\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\56.0.3051.116\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\56.0.3051.116\opera.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe

==================== Registre (Avec liste blanche) ===========================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [177928 2018-12-09] (ESET)
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-2977659287-1481995803-4227248665-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-2977659287-1481995803-4227248665-1001\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-2977659287-1481995803-4227248665-1001\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{AB2E0B03-3C4A-428A-9398-F7BC205CB211}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.fr/?q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.fr/
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2977659287-1481995803-4227248665-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope la valeur est absente
SearchScopes: HKLM-x32 -> DefaultScope la valeur est absente
SearchScopes: HKU\S-1-5-21-2977659287-1481995803-4227248665-1001 -> {2FE5BE13-8681-4404-AB74-B26F029FE89F} URL = hxxps://fr.search.yahoo.com/search?p={searchTerms}&intl=fr&fr=yset_ie_syc_oracle&type=orcl_default&partnerexternal-oracle=external-oracle
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-22] (Oracle Corporation)
BHO-x32: Pas de nom -> {CFCCB454-80CF-481f-B50A-29112EBB0F85} -> Pas de fichier
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-22] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-08-06] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-08-06] (Google Inc.)
Toolbar: HKU\S-1-5-21-2977659287-1481995803-4227248665-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-08-06] (Google Inc.)
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect1263.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)

FireFox:
========
FF ProfilePath: C:\Users\roland\AppData\Roaming\TomTom\HOME\Profiles\ldngbdme.default [2014-06-21]
FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2014-06-21] [Legacy] [non signé]
FF ProfilePath: C:\Users\roland\AppData\Roaming\Mozilla\Firefox\Profiles\q96sne8u.default [2018-12-09]
FF Homepage: Mozilla\Firefox\Profiles\q96sne8u.default -> hxxps://fr.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10454__180602__yaff
FF NewTab: Mozilla\Firefox\Profiles\q96sne8u.default -> hxxps://fr.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10454__180602__yaff
FF SearchPlugin: C:\Users\roland\AppData\Roaming\Mozilla\Firefox\Profiles\q96sne8u.default\searchplugins\yahoo-lavasoft-ff59.xml [2018-06-02]
FF ProfilePath: C:\Users\roland\AppData\Roaming\Actia\diagnostic2.3.4.3\Profiles\9dx2u6dx.default [2016-04-23]
FF ProfilePath: C:\Users\roland\AppData\Roaming\Actia\diagnostic2.3.30.0\Profiles\8416s102.default [2016-04-23]
FF ProfilePath: C:\Users\roland\AppData\Roaming\Actia\diagnostic2.15.2.0\Profiles\yx4iizmq.default [2018-08-30]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_101.dll [2018-12-05] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_101.dll [2018-12-05] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @ptc.com/IsoView -> C:\Program Files (x86)\Common Files\PTC\npisoview.dll [2015-03-16] (PTC Inc.)
FF Plugin-x32: @ptc.com/ProductViewLite -> C:\Program Files (x86)\Common Files\PTC\np6_pvapplite9.dll [2015-03-16] (PTC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2015-01-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2977659287-1481995803-4227248665-1001: lantek.com/IntegraPlugin -> C:\CADMAN\System\Common\bin\npIntegraPlugin.dll [Pas de fichier]
FF Plugin HKU\S-1-5-21-2977659287-1481995803-4227248665-1001: lantek.com/IntegraPlugin64 -> C:\CADMAN\System\Common\bin\npIntegraPlugin64.dll [Pas de fichier]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://fr.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default [2018-12-09]
CHR Extension: (Slides) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-10]
CHR Extension: (Docs) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-10]
CHR Extension: (Google Drive) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-24]
CHR Extension: (YouTube) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-24]
CHR Extension: (Adobe Acrobat) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-05-07]
CHR Extension: (Avast SafePrice) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-08-27]
CHR Extension: (Sheets) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-10]
CHR Extension: (Google Docs hors connexion) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-24]
CHR Extension: (Avast Online Security) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-08-27]
CHR Extension: (Norton Identity Safe) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2017-04-24]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-27]
CHR Extension: (Gmail) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-24]
CHR Extension: (Chrome Media Router) - C:\Users\roland\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-10]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2977659287-1481995803-4227248665-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ibbfklbaljofpaanmpaeadejijfdddco] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-12-23] (Advanced Micro Devices, Inc.) [Fichier non signé]
R2 Dedicarz Service; C:\Program Files (x86)\Orange\ma Livebox\dedicarz\DedicarzService.exe [1970544 2014-09-15] () [Fichier non signé]
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2302160 2018-12-09] (ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2302160 2018-12-09] (ESET)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [Fichier non signé]
R2 FirebirdGuardianDefaultInstance; C:\APP\firebird\bin\fbguard.exe [65536 2008-07-03] (The Firebird Project) [Fichier non signé]
R3 FirebirdServerDefaultInstance; C:\APP\firebird\bin\fbserver.exe [1527893 2008-07-03] (The Firebird Project) [Fichier non signé]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc.)
S4 mgod; c:\windows\mgod.exe [408576 2015-10-08] () [Fichier non signé]
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7534864 2016-08-25] (TeamViewer GmbH)
R2 USBhostFRM; C:\Windows\USBhostFW.exe [3188224 2013-04-12] (Microsoft Corporation) [Fichier non signé]
R2 VServer; c:\ec-apps\carserver\mkp-vs\vservice.exe [598016 2017-06-12] (IFS Informationstechnik GmbH) [Fichier non signé]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Pilotes (Avec liste blanche) ======================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [62152 2014-10-28] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (pas de ServiceDLL)
S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [58368 2009-06-02] (www.winchiphead.com)
S2 DirectNT; pas de ImagePath
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [143448 2018-12-09] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [107896 2018-12-09] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [188832 2018-12-09] (ESET)
R2 ekbdflt; C:\Windows\System32\DRIVERS\ekbdflt.sys [50144 2018-12-09] (ESET)
R1 epfw; C:\Windows\System32\DRIVERS\epfw.sys [82304 2018-12-09] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [61528 2018-12-09] (ESET)
R1 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [109864 2018-12-09] (ESET)
R2 inpoutx64; C:\Windows\System32\Drivers\inpoutx64.sys [15008 2012-11-01] (Highresolution Enterprises [www.highrez.co.uk])
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52320 2011-11-22] (hxxp://libusb-win32.sourceforge.net)
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [258664 2011-09-22] (Realtek Semiconductor Corp.)
S3 RT-USB; C:\Windows\System32\drivers\RT-USB64.SYS [70984 2010-06-16] (Ross-Tech LLC)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2014-08-15] (Apple, Inc.) [Fichier non signé]
R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [106760 2014-09-18] (WIBU-SYSTEMS AG)
S3 Wibukey2_64; C:\Windows\System32\drivers\wibukey2_64.sys [22320 2014-09-18] (WIBU-SYSTEMS AG)
S1 WINIO; C:\Electrique\prog\winio.sys [4944 2002-03-01] () [Fichier non signé]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S0 iukbnfy; System32\drivers\cxmwa.sys [X]

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois - Créés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2099-03-03 19:37 - 2112-03-03 19:37 - 002565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2099-03-03 19:37 - 2112-03-03 19:37 - 001699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2099-03-03 19:37 - 2112-03-03 19:37 - 000410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2099-03-03 19:37 - 2112-03-03 19:37 - 000166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2099-03-03 19:37 - 2112-03-03 19:37 - 000148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2099-03-03 19:37 - 2112-03-03 19:37 - 000107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2099-03-03 19:37 - 2112-03-03 19:37 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2099-03-03 19:37 - 2112-03-03 19:37 - 000091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2099-03-03 19:37 - 2112-03-03 19:37 - 000074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2099-03-03 19:37 - 2112-03-03 19:37 - 000027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2099-03-03 19:36 - 2112-03-03 19:36 - 000501248 _____ (Microsoft Corporation) C:\Windows\system32\WinSATAPI.dll
2099-03-03 19:36 - 2112-03-03 19:36 - 000335872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSATAPI.dll
2099-03-03 19:35 - 2112-03-03 19:35 - 000723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2099-03-03 19:35 - 2112-03-03 19:35 - 000534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2099-03-03 19:31 - 2112-03-03 19:31 - 000613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2099-03-03 19:31 - 2112-03-03 19:31 - 000465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2099-03-03 19:31 - 2112-03-03 19:31 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2099-03-03 19:31 - 2112-03-03 19:31 - 000075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2099-03-03 19:30 - 2112-03-03 19:30 - 000331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2099-03-03 19:30 - 2112-03-03 19:30 - 000233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2099-03-03 19:29 - 2112-03-03 19:29 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2099-03-03 19:27 - 2112-03-03 19:27 - 000404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2099-03-03 19:27 - 2112-03-03 19:27 - 000252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2099-03-03 19:27 - 2112-03-03 19:27 - 000246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2099-03-03 19:27 - 2112-03-03 19:27 - 000202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2099-03-03 19:27 - 2112-03-03 19:27 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2099-03-03 19:27 - 2112-03-03 19:27 - 000064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2099-03-03 19:27 - 2112-03-03 19:27 - 000044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 002315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 002223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 001549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2099-03-03 19:26 - 2112-03-03 19:26 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2099-03-03 19:26 - 2112-03-03 19:26 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2099-03-03 19:26 - 2112-03-03 19:26 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2099-03-03 19:26 - 2112-03-03 19:26 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2099-03-03 19:26 - 2112-03-03 19:26 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2099-03-03 19:26 - 2112-03-03 19:26 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2099-03-03 19:26 - 2112-03-03 19:26 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2099-03-03 19:25 - 2112-03-03 19:25 - 000467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2099-03-03 19:25 - 2112-03-03 19:25 - 000410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2099-03-03 19:25 - 2112-03-03 19:25 - 000288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2099-03-03 19:25 - 2112-03-03 19:25 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2099-03-03 19:25 - 2112-03-03 19:25 - 000158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2099-03-03 19:25 - 2112-03-03 19:25 - 000128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2099-03-03 19:24 - 2112-03-03 19:24 - 000080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2099-03-03 19:22 - 2112-03-03 19:22 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbrpm.sys
2099-03-03 19:21 - 2112-03-03 19:21 - 002871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2099-03-03 19:21 - 2112-03-03 19:21 - 002616320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2099-03-03 19:21 - 2112-03-03 19:21 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2099-03-03 19:20 - 2112-03-03 19:20 - 000357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2099-03-03 19:20 - 2112-03-03 19:20 - 000270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2099-03-03 19:20 - 2112-03-03 19:20 - 000183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2099-03-03 19:20 - 2112-03-03 19:20 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2099-03-03 19:20 - 2112-03-03 19:20 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2099-03-03 19:19 - 2112-03-03 19:19 - 001395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2099-03-03 19:19 - 2112-03-03 19:19 - 001359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2099-03-03 19:19 - 2112-03-03 19:19 - 001164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2099-03-03 19:19 - 2112-03-03 19:19 - 001137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2099-03-03 19:19 - 2112-03-03 19:19 - 000031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2099-03-03 19:19 - 2112-03-03 19:19 - 000031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2099-03-03 19:19 - 2112-03-03 19:19 - 000020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2099-03-03 19:19 - 2112-03-03 19:19 - 000019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2099-03-03 19:19 - 2112-03-03 19:19 - 000017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2099-03-03 19:18 - 2112-03-03 19:18 - 000296320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2099-03-03 19:17 - 2112-03-03 19:17 - 000180736 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2099-03-03 19:17 - 2112-03-03 19:17 - 000148992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ifsutil.dll
2099-03-03 19:17 - 2112-03-03 19:17 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTAM.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAL.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINDEV.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007680 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBEN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTAM.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINORI.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINMAR.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINMAL.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINKAN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINHIN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINDEV.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBEN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTEL.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINPUN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINORI.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAR.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINKAN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINHIN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINGUJ.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINEN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBE2.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBE1.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDINASA.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINTEL.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINPUN.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINGUJ.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBE2.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINBE1.DLL
2099-03-03 19:17 - 2112-03-03 19:17 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDINASA.DLL
2099-03-03 19:16 - 2112-03-03 19:16 - 000267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2099-03-03 19:14 - 2112-03-03 19:14 - 001118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2099-03-03 19:14 - 2112-03-03 19:14 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2099-03-03 19:14 - 2112-03-03 19:14 - 000850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2099-03-03 19:14 - 2112-03-03 19:14 - 000642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2099-03-03 19:14 - 2112-03-03 19:14 - 000259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2099-03-03 19:14 - 2112-03-03 19:14 - 000199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2099-03-03 19:11 - 2112-03-03 19:11 - 000344522 _____ C:\Windows\system32\perfi00C.dat
2099-03-03 19:11 - 2112-03-03 19:11 - 000038160 _____ C:\Windows\system32\perfd00C.dat
2099-03-03 19:11 - 2112-03-03 19:11 - 000000000 ____D C:\Windows\SysWOW64\XPSViewer
2099-03-03 19:11 - 2112-03-03 19:11 - 000000000 ____D C:\Windows\SysWOW64\fr
2099-03-03 19:11 - 2112-03-03 19:11 - 000000000 ____D C:\Windows\SysWOW64\040C
2099-03-03 19:11 - 2112-03-03 19:11 - 000000000 ____D C:\Windows\system32\fr
2099-03-03 19:11 - 2112-03-03 19:11 - 000000000 ____D C:\Windows\system32\040C
2099-03-03 19:11 - 2018-12-08 23:51 - 000747894 _____ C:\Windows\system32\perfh00C.dat
2099-03-03 19:11 - 2018-12-08 23:51 - 000150324 _____ C:\Windows\system32\perfc00C.dat
2018-12-09 21:12 - 2018-12-09 21:13 - 000019945 _____ C:\Users\roland\Desktop\FRST.txt
2018-12-09 21:10 - 2018-12-09 21:10 - 002417152 _____ (Farbar) C:\Users\roland\Desktop\FRST64.exe
2018-12-09 20:41 - 2018-12-09 20:41 - 000001939 _____ C:\Users\roland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DiagBox v9.23 - MrRorry.lnk
2018-12-09 20:08 - 2018-12-09 20:41 - 000000000 ____D C:\APP
2018-12-09 20:05 - 2018-12-09 20:41 - 000000000 ____D C:\AWRoot
2018-12-09 18:57 - 2018-12-09 18:57 - 000000844 _____ C:\Users\roland\Desktop\ZHPCleaner.lnk
2018-12-09 18:50 - 2018-12-09 18:50 - 000000000 ____D C:\Users\roland\AppData\Roaming\ESET
2018-12-09 18:43 - 2018-12-09 18:43 - 000000834 _____ C:\Users\roland\Desktop\ZHPDiag.lnk
2018-12-09 18:30 - 2018-12-09 18:30 - 000000000 ____D C:\Users\roland\AppData\Local\ESET
2018-12-09 18:27 - 2018-12-09 18:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2018-12-09 18:27 - 2018-12-09 18:27 - 000000000 ____D C:\ProgramData\ESET
2018-12-09 18:27 - 2018-12-09 18:27 - 000000000 ____D C:\Program Files\ESET
2018-12-08 22:14 - 2018-12-08 22:14 - 000000790 _____ C:\Users\roland\Downloads\ISTA 4.09.13 (1).txt
2018-12-08 22:02 - 2018-12-08 22:02 - 000000790 _____ C:\Users\roland\Downloads\ISTA 4.09.13.txt
2018-12-05 23:27 - 2018-12-09 20:59 - 000000000 ____D C:\Users\roland\AppData\LocalLow\Mozilla
2018-12-03 20:44 - 2018-12-03 20:44 - 000004102 _____ C:\Users\roland\Downloads\justificatif.pdf
2018-12-01 11:10 - 2018-12-01 11:10 - 004244514 _____ C:\Users\roland\Downloads\NOTICE_M300_FR.pdf
2018-11-19 20:32 - 2018-11-19 20:32 - 000052328 _____ () C:\Windows\system32\Drivers\staport.sys
2018-11-11 12:35 - 2018-11-11 12:35 - 000000000 ____D C:\Users\roland\AppData\Local\mbam
2018-11-11 12:34 - 2018-11-11 12:34 - 000000000 ____D C:\Users\roland\AppData\Local\mbamtray

==================== Un mois - Modifiés - fichiers et dossiers ========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2099-03-03 19:11 - 2009-07-14 06:37 - 000000000 ____D C:\Windows\DigitalLocker
2099-03-03 19:11 - 2009-07-14 06:32 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2099-03-03 19:11 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\servicing
2099-03-03 19:11 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\IME
2099-03-03 19:04 - 2009-07-14 05:45 - 000000000 ____D C:\Windows\Setup
2018-12-09 21:12 - 2015-10-17 12:35 - 000000000 ____D C:\FRST
2018-12-09 21:10 - 2014-08-10 10:25 - 000000000 ___RD C:\Users\roland\Desktop\Diag auto
2018-12-09 21:00 - 2018-09-16 18:29 - 000000000 ____D C:\ProgramData\firebird
2018-12-09 21:00 - 2012-10-02 23:05 - 000000000 ____D C:\Users\roland\AppData\Local\CrashDumps
2018-12-09 20:42 - 2016-04-23 21:29 - 000000000 ____D C:\TEMP
2018-12-09 19:52 - 2015-09-09 22:32 - 000000000 ____D C:\Users\roland\AppData\Roaming\ZHP
2018-12-09 19:46 - 2009-07-14 05:45 - 000031472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-12-09 19:46 - 2009-07-14 05:45 - 000031472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-12-09 19:37 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-12-09 19:36 - 2015-01-19 22:41 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-12-09 19:28 - 2016-05-06 07:28 - 000000000 ____D C:\AdwCleaner
2018-12-09 19:26 - 2011-01-01 00:15 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-12-09 19:21 - 2016-03-04 20:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPPS
2018-12-09 19:21 - 2016-03-04 20:51 - 000000000 ____D C:\MPPS
2018-12-09 19:13 - 2015-05-24 17:41 - 000000000 ____D C:\ProgramData\AVAST Software
2018-12-09 18:56 - 2017-08-16 09:31 - 000000000 ____D C:\Users\roland\AppData\Local\ZHP
2018-12-09 18:42 - 2012-10-03 21:15 - 000000000 ___RD C:\Users\roland\Desktop\Nettoyage
2018-12-09 18:32 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2018-12-09 18:31 - 2018-09-04 12:23 - 000188832 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys
2018-12-09 18:31 - 2018-09-04 12:23 - 000143448 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys
2018-12-09 18:31 - 2018-09-04 12:23 - 000109864 _____ (ESET) C:\Windows\system32\Drivers\epfwwfp.sys
2018-12-09 18:31 - 2018-09-04 12:23 - 000107896 _____ (ESET) C:\Windows\system32\Drivers\edevmon.sys
2018-12-09 18:31 - 2018-09-04 12:23 - 000082304 _____ (ESET) C:\Windows\system32\Drivers\epfw.sys
2018-12-09 18:31 - 2018-09-04 12:23 - 000061528 _____ (ESET) C:\Windows\system32\Drivers\EpfwLWF.sys
2018-12-09 18:31 - 2018-09-04 12:23 - 000050144 _____ (ESET) C:\Windows\system32\Drivers\ekbdflt.sys
2018-12-09 17:30 - 2018-04-04 21:36 - 000000000 ____D C:\Users\roland\AppData\Local\AVAST Software
2018-12-09 17:00 - 2015-11-24 22:48 - 000000000 ____D C:\Users\roland\AppData\Roaming\vlc
2018-12-09 13:13 - 2014-09-13 09:53 - 000003944 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3348DA17-B05A-4611-B8FB-1F11B761B441}
2018-12-09 11:02 - 2018-09-16 17:10 - 000000000 __SHD C:\AI_RecycleBin
2018-12-09 00:38 - 2016-04-23 21:25 - 000000000 ____D C:\Users\roland\AppData\Roaming\Mozilla
2018-12-08 23:51 - 2009-07-14 06:13 - 001669522 _____ C:\Windows\system32\PerfStringBackup.INI
2018-12-08 22:14 - 2016-01-31 15:20 - 000003188 _____ C:\Windows\System32\Tasks\HPCeeScheduleForroland
2018-12-08 22:14 - 2016-01-31 15:20 - 000000336 _____ C:\Windows\Tasks\HPCeeScheduleForroland.job
2018-12-08 08:41 - 2018-05-04 19:55 - 000003874 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1525460099
2018-12-08 08:41 - 2018-03-15 21:37 - 000004638 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-12-08 08:41 - 2018-02-03 10:54 - 000003238 _____ C:\Windows\System32\Tasks\{75856C45-E8FD-40DF-8C3D-F367CC8D3CB4}
2018-12-08 08:41 - 2017-10-21 17:08 - 000004496 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-12-08 08:41 - 2017-08-17 20:24 - 000004650 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-12-08 08:41 - 2016-06-19 14:50 - 000002794 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2018-12-08 08:41 - 2016-03-20 17:37 - 000003294 _____ C:\Windows\System32\Tasks\{122A8C6D-DA5E-4EDA-9A3B-AA921CFC939E}
2018-12-08 08:41 - 2015-12-04 13:55 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2018-12-08 08:41 - 2015-10-09 13:12 - 000003944 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{D3768AF1-5E20-47DB-AEA1-03DF758B0E00}
2018-12-08 08:41 - 2015-07-25 12:07 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-12-08 08:41 - 2012-05-16 02:30 - 000003234 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2018-12-05 23:38 - 2015-01-19 20:56 - 000000000 ____D C:\Users\roland\AppData\Roaming\BitTorrent
2018-12-05 23:37 - 2011-01-01 00:15 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-12-05 23:37 - 2011-01-01 00:15 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-12-05 23:37 - 2011-01-01 00:15 - 000000000 ____D C:\Windows\system32\Macromed
2018-12-05 23:35 - 2013-07-09 19:23 - 000000000 ____D C:\Windows\Minidump
2018-11-27 22:51 - 2016-11-26 09:09 - 000000000 ____D C:\Program Files (x86)\Opera
2018-11-23 13:08 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\NDF
2018-11-18 13:18 - 2012-10-01 22:24 - 000000000 ____D C:\Users\roland\Documents\Roland
2018-11-16 07:52 - 2015-04-06 08:56 - 000000000 ___SD C:\Windows\system32\GWX
2018-11-16 07:52 - 2012-09-29 23:29 - 000000000 ____D C:\Users\roland
2018-11-16 07:52 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\registration
2018-11-15 23:42 - 2013-08-14 09:50 - 000000000 ____D C:\Windows\system32\MRT
2018-11-15 23:33 - 2012-10-02 11:35 - 137810048 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-11-15 23:28 - 2012-10-02 22:53 - 001644590 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-11-11 18:12 - 2018-03-18 10:07 - 000000000 ____D C:\Program Files\Malwarebytes
2018-11-11 12:29 - 2009-07-14 06:08 - 000032496 _____ C:\Windows\Tasks\SCHEDLGU.TXT

==================== Fichiers à la racine de certains dossiers =======

2012-10-01 23:00 - 2014-06-13 22:20 - 000007600 _____ () C:\Users\roland\AppData\Local\resmon.resmoncfg
2015-11-23 15:23 - 2015-11-23 15:23 - 009276713 _____ () C:\Users\roland\AppData\Local\SelfExtractible.zip

Certains de taille zéro octet fichiers/dossiers:
==========================
C:\Windows\god.exe

==================== Bamital & volsnap ======================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement
C:\Windows\system32\wininit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement
C:\Windows\explorer.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\Windows\system32\svchost.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\Windows\system32\services.exe => Le fichier est signé numériquement
C:\Windows\system32\User32.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\Windows\system32\userinit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement
C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement

LastRegBack: 2018-12-04 00:20

==================== Fin de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité