cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 15-04-2020
Exécuté par stephane (administrateur) sur STEPHANE-PC (SAMSUNG ELECTRONICS CO., LTD. 300E4C/300E5C/300E7C) (17-04-2020 11:43:03)
Exécuté depuis C:\Users\stephane\Contacts\Desktop
Profils chargés: stephane & UpdatusUser & postgres (Profils disponibles: stephane & UpdatusUser & postgres)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: FF)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Atheros Communications Inc. -> Atheros Commnucations) [Fichier non signé] C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Atheros Communications Inc. -> Atheros Commnucations) [Fichier non signé] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Atheros Communications Inc. -> Atheros Communications) [Fichier non signé] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Communications Inc. -> Atheros) [Fichier non signé] C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(CyberLink -> ) [Fichier non signé] C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <15>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation -> ) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel® Upgrade Service -> Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe <2>
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(PLARIUM GLOBAL LTD. -> Plarium) C:\Users\stephane\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe <4>
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Tenorshare Co.,Ltd. -> Tenorshare Co,Ltd) C:\Program Files (x86)\ReiBoot\TenorshareReibootService.exe
(TomTom) [Fichier non signé] C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe
(Windscribe Limited -> Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\drfone\Library\DriverInstaller\DriverInstall.exe

==================== Registre (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12460136 2012-03-29] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1020064 2012-02-13] (Atheros Communications Inc. -> Atheros Communications) [Fichier non signé]
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800416 2012-02-13] (Atheros Communications Inc. -> Atheros Commnucations) [Fichier non signé]
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2816816 2012-03-12] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [108216 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-01-22] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-11-19] (Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67896 2018-01-05] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\Run: [Windscribe] => C:\Program Files (x86)\Windscribe\Windscribe.exe [10601064 2017-05-09] (Windscribe Limited -> Windscribe Limited)
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [18630056 2018-09-10] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\Run: [TomTom MySports Connect.exe] => C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe [638464 2018-09-03] (TomTom) [Fichier non signé]
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [53646912 2019-05-24] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [31740816 2020-04-17] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\Run: [Discord] => C:\Users\stephane\AppData\Local\Discord\app-0.0.306\Discord.exe [90950968 2020-02-24] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3370272 2020-03-27] (Valve -> Valve Corporation)
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\Run: [PlariumPlay] => C:\Users\stephane\AppData\Local\Plarium\PlariumPlay\PlariumPlay --args -tray-start
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\...\MountPoints2: {6bd281c9-a0dd-11e1-bf9a-806e6f6e6963} - D:\LangSelector.exe
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\windows\system32\cmd.exe /D /C start C:\windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-03] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\windows\system32\cmd.exe /D /C start C:\windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\80.1.3901.162\Installer\chrmstp.exe [2020-04-16] (Avast Software s.r.o. -> AVAST Software)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-08-21] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\windows\system32\AthCredentialProvider.dll [2012-02-13] (Atheros Communications Inc. -> Atheros Commnucations) [Fichier non signé]
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\windows\system32\AthCredentialProvider.dll [2012-02-13] (Atheros Communications Inc. -> Atheros Commnucations) [Fichier non signé]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast Cleanup Premium.lnk [2017-11-22]
ShortcutTarget: Avast Cleanup Premium.lnk -> C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe (AVAST Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAndroidAppHelper.lnk [2019-08-21]
ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\drfone\Addins\SocialApps\WSAndroidAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAppHelper.lnk [2019-08-21]
ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\drfone\Addins\SocialApps\WSAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft)
Startup: C:\Users\stephane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 - Capture d'écran et lancement.lnk [2020-01-27]
ShortcutTarget: OneNote 2007 - Capture d'écran et lancement.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Tâches planifiées (Avec liste blanche) ============

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

Task: {0AF51545-65FD-48BF-AD2D-989BE8305EA4} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
Task: {0E2E5D91-345A-4580-82F5-65BE1E875114} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {1833BB71-3A8C-4FEC-B8C1-9DFEB6B5628F} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
Task: {193C2D4B-5346-4611-8A19-5EDF56D5EA41} - System32\Tasks\{71CAEFB1-1C1E-423A-BC7B-F196C5DB8F89} => C:\windows\system32\pcalua.exe -a "C:\Users\stephane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XFHNOYCF\Win64_152812.exe" -d C:\Users\stephane\Desktop
Task: {1D1D29E5-0E12-4E3B-893A-7F5571B41F7C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc -> Google Inc.)
Task: {2093D69F-4A7D-4B00-8A96-D0802C96B3C0} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {232ECCAC-2BFA-4430-9E57-40766A21552F} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1875592 2020-04-02] (Avast Software s.r.o. -> AVAST Software)
Task: {276E697C-51BF-4A6A-9E2B-A4E08C7C92CD} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
Task: {39E9EA66-4B6B-4981-BFB7-3AAA8CB4A751} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [233224 2011-11-25] (Intel® Services Manager -> Intel Corporation)
Task: {46FE340C-F090-464D-BC63-07540A969E45} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2017-10-12] (Apple Inc. -> Apple Inc.)
Task: {56D72166-D16F-4F53-BE55-E09BBD987336} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {58F9CF61-8C51-441E-9920-4F63BE407649} - System32\Tasks\EasySupportCenter => C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe [5459536 2012-04-06] (Samsung Electronics CO., LTD. -> Samsung Electronics CO., LTD.)
Task: {631F3166-00BE-4551-A8F3-3332C9F43F6F} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_153_Plugin.exe [1456128 2018-11-30] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {6498D57F-4723-44BE-8B0F-5804DBF3988C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [538952 2018-09-10] (Piriform Ltd -> Piriform Ltd)
Task: {910C7647-DC1B-421F-9EFE-93C23829B24E} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-04] (AVAST Software s.r.o. -> AVAST Software)
Task: {9324EA30-E3AF-49D7-A359-693E9E1F2103} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe
Task: {9A50A909-864D-4CFA-9D36-BA4CA8B13EB4} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1875592 2020-04-02] (Avast Software s.r.o. -> AVAST Software)
Task: {9AE3E1DF-C10C-4FC3-985D-35DCD92B0D97} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335872 2018-11-30] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {BD563868-8813-48AC-B05F-4B23B39D6A82} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3325032 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
Task: {C27453DA-B357-4AC3-8774-25847C3E102E} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1660520 2020-02-28] (Avast Software s.r.o. -> Avast Software)
Task: {C69C1DF5-60EB-4D73-84E6-DEF50BB1A22B} - System32\Tasks\TNTClientUpdater => C:\Program Files (x86)\GameforgeLogin\updater.exe [505496 2018-10-08] (Gameforge 4D GmbH -> )
Task: {C6C6F887-30E1-48EE-924C-E0476C8B1CED} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [4466256 2012-01-28] (Samsung Electronics CO., LTD. -> SEC)
Task: {CA002EA8-1BC3-40D6-B9DC-19B6A9968DA5} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe
Task: {D083094E-C348-47F7-B367-BC40BEDA0B57} - System32\Tasks\Easy Software Manager Agent => C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe
Task: {D5EF2B14-CA65-414B-A156-54AB66BE8463} - System32\Tasks\Avast TUNEUP Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [1659000 2019-07-25] (AVAST Software s.r.o. -> AVAST Software)
Task: {D6991795-0536-44AF-B734-30E594C6D1C0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [233224 2011-11-25] (Intel® Services Manager -> Intel Corporation)
Task: {D8373D40-245E-40A9-9F17-B011F6F2E38E} - System32\Tasks\{185D4385-9047-46A7-874F-B54C95DFC7D9} => C:\windows\system32\pcalua.exe -a "C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\uninstbb.exe"
Task: {E39D47F6-C179-4882-9648-7AC8D284C20C} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-04] (AVAST Software s.r.o. -> AVAST Software)
Task: {E5E81808-4679-41E5-B62C-0AFC740C6E7B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [13797712 2018-09-10] (Piriform Ltd -> Piriform Ltd)
Task: {EA89B33E-5E70-4701-8057-0B0BD2BBFC22} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe do-task
Task: {F417C94C-451C-40CD-83AE-DF33E59D285B} - System32\Tasks\avastBCLRestartS-1-5-21-2286804812-472341844-2148522555-1001 => C:\PROGRAM FILES (X86)\Mozilla Firefox\firefox.exe
Task: {F82DEED0-077D-4C55-B58E-F6C52AAA8255} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc -> Google Inc.)
Task: {FC7CB299-5C3F-427A-A29E-5CCEAC31C0D7} - System32\Tasks\{A5EF18BE-919C-4325-8D3E-E1DCA4FA9DEC} => C:\windows\system32\pcalua.exe -a "E:\office 2007\office 2007 français\Office 2007 Pro. FR {final v12 + serial - Windows 2003, XP & Vista}\SETUP.EXE" -d "E:\office 2007\office 2007 français\Office 2007 Pro. FR {final v12 + serial - Windows 2003, XP & Vista}"

(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)

Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 10 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392 2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392 2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 10 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{3272B08B-5EE4-4CDF-B4C9-931159581A85}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{70EB4B2E-E3F4-43B5-8E0B-D414C17E0376}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{C1FD785B-7E99-48FE-A41B-9A4A6791255C}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{FCF57504-DE47-49CE-A8D7-BD0BA8C1DADB}: [DhcpNameServer] 172.20.10.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.fr/?q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.fr/?q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.fr/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.fr/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.fr/
HKU\S-1-5-21-2286804812-472341844-2148522555-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://google.fr/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2018-10-27] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-02-21] (Google Inc -> Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2018-10-27] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-02-21] (Google Inc -> Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-02-21] (Google Inc -> Google Inc.)
Toolbar: HKU\S-1-5-21-2286804812-472341844-2148522555-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-02-21] (Google Inc -> Google Inc.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF DefaultProfile: op5a5d0t.default-1399321501552
FF ProfilePath: C:\Users\stephane\AppData\Roaming\Mozilla\Firefox\Profiles\op5a5d0t.default-1399321501552 [2020-04-16]
FF Notifications: Mozilla\Firefox\Profiles\op5a5d0t.default-1399321501552 -> hxxps://www.facebook.com
FF Extension: (Avast SafePrice | Comparaison, offres, coupons) - C:\Users\stephane\AppData\Roaming\Mozilla\Firefox\Profiles\op5a5d0t.default-1399321501552\Extensions\sp@avast.com.xpi [2020-04-15]
FF Extension: (Avast Online Security) - C:\Users\stephane\AppData\Roaming\Mozilla\Firefox\Profiles\op5a5d0t.default-1399321501552\Extensions\wrc@avast.com.xpi [2020-04-15] [UpdateUrl:hxxps://firefoxext.avcdn.net/firefoxext/avast/aos/update.json]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_31_0_0_153.dll [2018-11-30] (Adobe Systems Incorporated -> )
FF Plugin: @ma-config.com/HardwareDetection -> C:\Program Files\ma-config.com\x64\nphardwaredetection.dll [2013-02-05] (Cybelsoft -> Cybelsoft)
FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_153.dll [2018-11-30] (Adobe Systems Incorporated -> )
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2018-10-27] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2018-10-27] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @ma-config.com/HardwareDetection -> C:\Program Files\ma-config.com\nphardwaredetection.dll [2013-02-05] (Cybelsoft -> Cybelsoft)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) [Fichier non signé]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2286804812-472341844-2148522555-1001: @eximion.com/KalydoPlayer -> C:\Users\stephane\AppData\Roaming\Kalydo\KalydoPlayer\bin2\npkalydo.dll [2013-01-17] (Eximion B.V. -> Eximion B.V.)
FF Plugin HKU\S-1-5-21-2286804812-472341844-2148522555-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\stephane\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2017-05-18] (Unity Technologies SF -> Unity Technologies ApS)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\stephane\AppData\Local\Google\Chrome\User Data\Default [2020-04-17]
CHR Notifications: Default -> hxxps://www.cnetfrance.fr
CHR Extension: (Avast Online Security) - C:\Users\stephane\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2020-03-30]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\stephane\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-03-30]
CHR Extension: (Chrome Media Router) - C:\Users\stephane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-15]
CHR Profile: C:\Users\stephane\AppData\Local\Google\Chrome\User Data\System Profile [2020-04-16]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx

==================== Services (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-01-05] (Apple Inc. -> Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5504928 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [106144 2012-02-13] (Atheros Communications Inc. -> Atheros Commnucations) [Fichier non signé]
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-04] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [345384 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-04] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\80.1.3901.162\elevation_service.exe [973760 2020-04-02] (Avast Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-07-23] (BattlEye Innovations e.K. -> )
R2 CleanupPSvc; C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe [10287216 2019-07-25] (AVAST Software s.r.o. -> AVAST Software)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [802432 2020-01-25] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 GameforgeClientService; C:\Program Files (x86)\GameforgeClient\gfservice.exe [529568 2020-03-04] (Gameforge 4D GmbH -> )
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-08] (Intel Corporation -> )
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-04-16] (Malwarebytes Inc -> Malwarebytes)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation -> Symantec Corporation)
S2 Plarium Play Client Service; C:\Users\stephane\AppData\Local\Plarium\PlariumPlay\PlariumPlayClientService.exe [89048 2020-02-15] (PLARIUM GLOBAL LTD. -> )
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] (CyberLink -> ) [Fichier non signé]
R2 TenorshareReibootService; C:\Program Files (x86)\ReiBoot\TenorshareReibootService.exe [33208 2017-11-09] (Tenorshare Co.,Ltd. -> Tenorshare Co,Ltd)
S3 TNTClientDaemonMS2; C:\Program Files (x86)\GameforgeLoginMS2\daemon.exe [406184 2019-02-28] (Gameforge 4D GmbH -> )
S3 wampapache; c:\wamp\bin\apache\apache2.2.22\bin\httpd.exe [18432 2012-05-13] (Apache Software Foundation) [Fichier non signé]
S3 wampmysqld; c:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe [8177664 2012-04-19] () [Fichier non signé]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [71272 2017-05-09] (Windscribe Limited -> Windscribe Limited)
R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292096 2011-03-28] (Microsoft Corporation -> Microsoft Corp.)
S2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [83232 2019-06-26] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 WsDrvInst; C:\Program Files (x86)\Wondershare\drfone\Library\DriverInstaller\DriverInstall.exe [130336 2019-06-26] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2012-02-13] (Atheros Communications Inc. -> Atheros) [Fichier non signé]
S2 pgsql-8.3; "C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe" runservice -w -N "pgsql-8.3" -D "C:\Program Files (x86)\PostgreSQL\8.3\data\"
S2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [X]

===================== Pilotes (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R0 aswArDisk; C:\windows\System32\drivers\aswArDisk.sys [37856 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\windows\System32\drivers\aswArPot.sys [206120 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\windows\System32\drivers\aswbidsdriver.sys [234776 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\windows\System32\drivers\aswbidsh.sys [178968 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\windows\System32\drivers\aswbuniv.sys [60696 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\windows\System32\drivers\aswKbd.sys [42984 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\windows\System32\drivers\aswMonFlt.sys [175920 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; C:\windows\System32\drivers\aswNetHub.sys [492144 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\windows\System32\drivers\aswRdr2.sys [109480 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\windows\System32\drivers\aswRvrt.sys [85056 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\windows\System32\drivers\aswSnx.sys [851808 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\windows\System32\drivers\aswSP.sys [459408 2020-04-16] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\windows\System32\drivers\aswStm.sys [235696 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
S3 aswTap; C:\windows\System32\DRIVERS\aswTap.sys [44640 2014-09-05] (AVAST Software a.s. -> The OpenVPN Project)
R0 aswVmm; C:\windows\System32\drivers\aswVmm.sys [317280 2020-04-15] (Avast Software s.r.o. -> AVAST Software)
R3 athr; C:\windows\System32\DRIVERS\athrx.sys [2797056 2011-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Atheros Communications, Inc.)
R3 clwvd; C:\windows\System32\DRIVERS\clwvd.sys [31216 2012-04-16] (CyberLink -> CyberLink Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [153312 2020-04-16] (Malwarebytes Corporation -> Malwarebytes)
R0 iaStorF; C:\windows\System32\DRIVERS\iaStorF.sys [28216 2012-11-19] (Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation)
R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [214496 2020-04-16] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\DRIVERS\farflt.sys [195432 2020-04-17] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\windows\system32\DRIVERS\mbam.sys [73584 2020-04-17] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [248968 2020-04-16] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\windows\System32\DRIVERS\mwac.sys [112752 2020-04-17] (Malwarebytes Inc -> Malwarebytes)
S3 Netaapl; C:\windows\System32\DRIVERS\netaapl64.sys [23040 2013-07-25] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
R1 SABI; C:\windows\system32\Drivers\SABI.sys [13824 2012-04-06] (Microsoft Windows Hardware Compatibility Publisher -> SAMSUNG ELECTRONICS)
R3 tapwindscribe0901; C:\windows\System32\DRIVERS\tapwindscribe0901.sys [45560 2017-04-21] (Windscribe Limited -> The OpenVPN Project)
S3 USBAAPL64; C:\windows\System32\Drivers\usbaapl64.sys [54784 2016-03-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 usbrndis6; C:\windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois (créés) ===================

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2020-04-17 08:17 - 2020-04-17 08:17 - 000073584 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2020-04-17 08:16 - 2020-04-17 08:16 - 000195432 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2020-04-17 08:16 - 2020-04-17 08:16 - 000112752 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2020-04-17 08:13 - 2020-04-17 08:13 - 003431296 _____ (Nicolas Coolman) C:\Users\stephane\Downloads\ZHPSuite.exe
2020-04-17 08:06 - 2020-04-17 08:06 - 000000000 ___RD C:\Users\stephane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2020-04-17 07:49 - 2020-04-17 07:54 - 000000000 ____D C:\AdwCleaner
2020-04-17 07:47 - 2020-04-17 07:48 - 008196784 _____ (Malwarebytes) C:\Users\stephane\Downloads\adwcleaner_8.0.4.exe
2020-04-16 18:12 - 2020-04-16 18:12 - 000248968 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2020-04-16 17:46 - 2020-04-17 11:43 - 000000000 ____D C:\Users\stephane\AppData\LocalLow\IGDump
2020-04-16 17:37 - 2020-04-16 17:37 - 000001908 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-04-16 17:37 - 2020-04-16 17:37 - 000001908 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-04-16 17:37 - 2020-04-16 17:37 - 000000000 ____D C:\Users\stephane\AppData\Local\mbamtray
2020-04-16 17:37 - 2020-04-16 17:37 - 000000000 ____D C:\Users\stephane\AppData\Local\mbam
2020-04-16 17:37 - 2020-04-16 17:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-04-16 17:36 - 2020-04-16 17:36 - 000214496 _____ (Malwarebytes) C:\windows\system32\Drivers\MbamChameleon.sys
2020-04-16 17:35 - 2020-04-16 17:34 - 000153312 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2020-04-16 17:32 - 2020-04-16 17:32 - 001965536 _____ (Malwarebytes) C:\Users\stephane\Downloads\MBSetup.exe
2020-04-16 17:32 - 2020-04-16 17:32 - 001965536 _____ (Malwarebytes) C:\Users\stephane\Downloads\MBSetup (1).exe
2020-04-16 17:32 - 2020-04-16 17:32 - 000000000 ____D C:\Program Files\Malwarebytes
2020-04-16 16:27 - 2020-04-17 08:14 - 000000000 ____D C:\Users\stephane\AppData\Local\ZHP
2020-04-16 16:25 - 2020-04-16 16:26 - 003297152 _____ (Nicolas Coolman) C:\Users\stephane\Downloads\ZHPCleaner.exe
2020-04-16 16:17 - 2020-04-16 16:17 - 000000000 ____D C:\windows\system32\Tasks\Mozilla
2020-04-15 21:45 - 2020-04-15 21:45 - 000044568 _____ () C:\windows\system32\Drivers\staport.sys
2020-04-15 21:44 - 2020-04-15 21:46 - 000028311 _____ C:\Users\stephane\Downloads\FRST.txt
2020-04-15 21:43 - 2020-04-17 11:44 - 000000000 ____D C:\FRST
2020-04-15 21:42 - 2020-04-15 21:42 - 002009600 _____ (Farbar) C:\Users\stephane\Downloads\FRST(1).exe
2020-04-15 21:41 - 2020-04-15 21:41 - 000000000 _____ C:\Users\stephane\Downloads\FRST.exe
2020-04-15 21:39 - 2020-04-16 16:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-04-15 13:50 - 2020-04-15 21:45 - 000492144 _____ (AVAST Software) C:\windows\system32\Drivers\aswNetHub.sys
2020-04-15 13:50 - 2020-04-15 13:48 - 000235696 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2020-04-15 13:50 - 2020-04-15 13:48 - 000175920 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2020-04-15 13:50 - 2020-04-15 13:46 - 000337048 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2020-03-30 12:02 - 2020-04-03 12:04 - 000002182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-03-30 12:02 - 2020-04-03 12:04 - 000002141 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-03-30 12:02 - 2020-04-03 12:04 - 000002141 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-03-28 18:24 - 2020-03-28 18:24 - 000000697 _____ C:\Users\stephane\stephane - Raccourci.lnk
2020-03-26 16:45 - 2020-03-26 16:45 - 000935446 _____ C:\Users\stephane\Documents\biographie de Michel Tournier Samaël Leblond 604.odt
2020-03-22 23:36 - 2020-03-22 23:36 - 000021792 _____ C:\Users\stephane\Documents\Français Production écrite 2100 Samaël LEBLOND 604.odt
2020-03-21 18:16 - 2020-03-22 23:33 - 000021801 _____ C:\Users\stephane\Documents\Français Production écrite 2100.odt

==================== Un mois (modifiés) ==================

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2020-04-17 08:40 - 2015-11-21 17:40 - 000000000 ____D C:\Users\stephane\AppData\Roaming\ZHP
2020-04-17 08:29 - 2009-07-14 06:45 - 000028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-04-17 08:29 - 2009-07-14 06:45 - 000028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-04-17 08:14 - 2013-02-17 14:53 - 000000000 ____D C:\Users\UpdatusUser
2020-04-17 08:10 - 2019-12-24 16:02 - 000000000 ____D C:\Users\stephane\AppData\Roaming\Discord
2020-04-17 08:07 - 2020-01-25 18:45 - 000000000 ____D C:\Program Files (x86)\Steam
2020-04-17 08:05 - 2009-07-14 07:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2020-04-17 07:54 - 2012-05-18 12:56 - 000000000 ____D C:\ProgramData\Samsung
2020-04-17 07:54 - 2012-05-18 12:55 - 000000000 ____D C:\Program Files (x86)\Samsung
2020-04-17 07:46 - 2017-02-21 21:50 - 000004168 _____ C:\windows\system32\Tasks\Avast Emergency Update
2020-04-16 17:37 - 2017-05-10 21:21 - 000459408 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2020-04-16 17:34 - 2015-02-22 12:51 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-04-16 17:07 - 2013-03-30 00:00 - 000000000 ____D C:\Users\stephane\AppData\LocalLow\Temp
2020-04-16 16:59 - 2017-04-30 09:51 - 000000000 ____D C:\Users\stephane\AppData\LocalLow\Mozilla
2020-04-16 16:43 - 2019-04-20 11:20 - 000003732 _____ C:\windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2020-04-16 16:43 - 2019-04-20 11:20 - 000003150 _____ C:\windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2020-04-16 16:43 - 2018-05-04 18:53 - 000002387 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2020-04-16 16:43 - 2018-05-04 18:53 - 000002344 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2020-04-16 16:43 - 2018-05-04 18:53 - 000002344 _____ C:\ProgramData\Desktop\Avast Secure Browser.lnk
2020-04-16 16:24 - 2015-02-22 12:51 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2020-04-16 16:17 - 2017-05-08 19:51 - 000003376 _____ C:\windows\wininit.ini
2020-04-16 16:17 - 2017-04-30 09:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-04-15 21:48 - 2012-10-06 17:05 - 000000000 ____D C:\Users\stephane\Documents\Bluetooth Folder
2020-04-15 15:31 - 2018-05-04 18:49 - 000000000 ____D C:\Users\stephane\AppData\Local\AVAST Software
2020-04-15 13:48 - 2013-03-21 01:38 - 000317280 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2020-04-15 13:48 - 2013-03-21 01:38 - 000085056 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2020-04-15 13:48 - 2012-10-28 10:56 - 000109480 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2020-04-15 13:47 - 2018-10-27 18:25 - 000042984 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2020-04-15 13:44 - 2019-01-06 16:03 - 000037856 _____ (AVAST Software) C:\windows\system32\Drivers\aswArDisk.sys
2020-04-15 13:44 - 2017-11-22 18:49 - 000206120 _____ (AVAST Software) C:\windows\system32\Drivers\aswArPot.sys
2020-04-15 13:44 - 2017-05-10 21:19 - 000851808 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2020-04-15 13:43 - 2019-01-14 20:17 - 000234776 _____ (AVAST Software) C:\windows\system32\Drivers\aswbidsdriver.sys
2020-04-15 13:43 - 2019-01-06 16:03 - 000178968 _____ (AVAST Software) C:\windows\system32\Drivers\aswbidsh.sys
2020-04-15 13:43 - 2019-01-06 16:03 - 000060696 _____ (AVAST Software) C:\windows\system32\Drivers\aswbuniv.sys
2020-04-08 20:11 - 2019-02-08 17:49 - 001506578 _____ C:\windows\ntbtlog.txt
2020-04-08 11:32 - 2012-10-28 10:55 - 000000000 ____D C:\ProgramData\AVAST Software
2020-04-07 19:00 - 2013-02-02 14:28 - 000000000 ____D C:\Users\stephane\AppData\Roaming\vlc
2020-04-07 18:06 - 2012-05-19 04:11 - 000748948 _____ C:\windows\system32\perfh00C.dat
2020-04-07 18:06 - 2012-05-19 04:11 - 000150938 _____ C:\windows\system32\perfc00C.dat
2020-04-07 18:06 - 2009-07-14 07:13 - 001673078 _____ C:\windows\system32\PerfStringBackup.INI
2020-04-07 18:06 - 2009-07-14 05:20 - 000000000 ____D C:\windows\inf
2020-04-05 18:33 - 2012-11-13 21:36 - 000002778 _____ C:\windows\system32\Tasks\CCleanerSkipUAC
2020-04-05 10:24 - 2019-03-27 21:02 - 000001963 _____ C:\Users\Public\Desktop\Avast Antivirus Gratuit.lnk
2020-04-05 10:24 - 2019-03-27 21:02 - 000001963 _____ C:\ProgramData\Desktop\Avast Antivirus Gratuit.lnk
2020-04-05 01:15 - 2013-02-18 21:50 - 000000000 ____D C:\Users\postgres.stephane-PC
2020-04-05 01:15 - 2012-10-28 18:03 - 000000000 ____D C:\Users\postgres
2020-04-05 01:14 - 2009-07-14 05:20 - 000000000 ____D C:\windows\registration
2020-04-04 16:55 - 2012-10-06 14:18 - 000000000 ____D C:\Users\stephane
2020-03-29 02:59 - 2017-06-14 14:05 - 000004476 _____ C:\windows\system32\Tasks\Adobe Acrobat Update Task
2020-03-29 02:59 - 2015-12-09 22:19 - 000000000 ____D C:\windows\system32\Tasks\AVAST Software
2020-03-29 02:59 - 2012-10-28 10:56 - 000003504 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-29 02:59 - 2012-10-28 10:56 - 000003376 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-28 20:44 - 2019-04-08 21:26 - 000000256 _____ C:\Users\stephane\AppData\LocalLow\rbxcsettings.rbx
2020-03-28 20:41 - 2019-04-08 21:26 - 000000000 ____D C:\Users\stephane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2020-03-26 16:44 - 2020-03-12 21:20 - 000935446 _____ C:\Users\stephane\Documents\biographie de Michel Tournier.odt
2020-03-25 20:23 - 2019-07-23 13:36 - 000000000 ____D C:\ProgramData\Wondershare Filmora
2020-03-22 13:06 - 2019-07-23 13:36 - 000000000 ____D C:\Users\stephane\Documents\Wondershare Filmora 9
2020-03-21 20:21 - 2019-05-10 20:30 - 000000000 ____D C:\Users\stephane\Documents\Youcam
2020-03-21 20:02 - 2019-07-23 13:30 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2020-03-21 20:02 - 2019-07-23 13:30 - 000000000 ____D C:\ProgramData\Documents\Wondershare
2020-03-18 15:37 - 2017-07-19 21:32 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk

==================== Fichiers à la racine de certains dossiers ========

2015-11-23 19:22 - 2016-01-23 12:07 - 002015744 _____ () C:\Users\stephane\ZHPCleaner.exe
2015-11-22 10:45 - 2015-11-26 21:40 - 001976320 _____ () C:\Users\stephane\ZHPDiag3.exe
2015-07-16 14:18 - 2015-07-16 14:18 - 006420480 _____ () C:\Program Files (x86)\GUT8961.tmp
2017-04-27 17:41 - 2017-04-27 17:41 - 007639040 _____ () C:\Program Files (x86)\GUT954D.tmp
2017-09-19 10:34 - 2017-09-19 10:34 - 000003584 _____ () C:\Users\stephane\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-02-15 20:07 - 2020-02-15 20:13 - 000012349 _____ () C:\Users\stephane\AppData\Local\PlariumPlay.log
2015-11-18 23:22 - 2015-11-18 23:22 - 000007605 _____ () C:\Users\stephane\AppData\Local\Resmon.ResmonCfg
2015-08-19 21:47 - 2015-08-19 21:47 - 000000000 _____ () C:\Users\stephane\AppData\Local\{CF406E31-08B6-42E4-A553-4608E3B6FD35}

==================== SigCheck ============================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)


LastRegBack: 2020-04-08 11:50
==================== Fin de FRST.txt ========================

Publicité


Signaler le contenu de ce document

Publicité