Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:17-12-2015 Exécuté par Kevin Clickoo (administrateur) sur CLICKOO-KEVIN (17-12-2015 10:34:39) Exécuté depuis C:\Users\Kevin Clickoo\Desktop Profils chargés: Kevin Clickoo (Profils disponibles: Kevin Clickoo) Platform: Windows 10 Home (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (PointGrab LTD) C:\Program Files (x86)\PointGrab\Hand Gesture Control\PGService.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Key Suite\AsKeySuite.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\NFC Express\DTNFCServer.exe (ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Power Manager\Power Manager_background.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{9AF45D7C-34F1-4BA0-B799-825C8C04494C}\AiChargerDT.exe (ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Ai Charger II\Ai_ChargerII_TrayIcon(ASUS_Manager).exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\SyncUp\Server\SyncUp Server.exe () C:\Program Files (x86)\ASUS\ASUS Manager\PC Cleanup\SecureDeleteBackground.exe () C:\Program Files (x86)\ASUS\ASUS Manager\NFC Express\DT_NFCExpressDesktops.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6416.42001.0_x64__8wekyb3d8bbwe\HxTsr.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe () C:\Windows\System32\igfxTray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Atheros) C:\Program Files (x86)\Qualcomm Atheros\AWiCMgr.exe (Flux Software LLC) C:\Users\Kevin Clickoo\AppData\Local\FluxSoftware\Flux\flux.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Elias Fotinis) C:\Program Files (x86)\DeskPins\DeskPins.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor) HKLM\...\Run: [AWiC] => C:\Program Files (x86)\Qualcomm Atheros\AWiCMgr.exe [179840 2014-05-14] (Atheros) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3216032 2014-12-25] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-09] (AVAST Software) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\Run: [GSEUUT_2216] => 0 HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\Run: [f.lux] => C:\Users\Kevin Clickoo\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC) HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\Run: [Google Update] => C:\Users\Kevin Clickoo\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-11-20] (Google Inc.) HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [465920 2015-07-10] (Microsoft Corporation) HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\RunOnce: [Uninstall C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64" HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\RunOnce: [Uninstall C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5892.0626" HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\RunOnce: [Uninstall C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64" HKU\S-1-5-21-2915926479-3701056459-1286684747-1001\...\RunOnce: [Uninstall C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5907.0716] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Kevin Clickoo\AppData\Local\Microsoft\OneDrive\17.3.5907.0716" ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-09-28] (AVAST Software) Startup: C:\Users\Kevin Clickoo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeskPins.lnk [2015-10-14] ShortcutTarget: DeskPins.lnk -> C:\Program Files (x86)\DeskPins\DeskPins.exe (Elias Fotinis) GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{329e73ab-10db-471d-81be-d5bf795138cd}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{6af7ed1e-7068-4b4c-841d-c7145bdf149f}: [DhcpNameServer] 212.27.40.241 212.27.40.240 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = SearchScopes: HKU\S-1-5-21-2915926479-3701056459-1286684747-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-10] (AVAST Software) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-10] (AVAST Software) Edge: ====== Edge HomeButtonPage: HKU\S-1-5-21-2915926479-3701056459-1286684747-1001 -> hxxp://www.delta-homes.com/?type=hp&ts=1444640317&z=9e5433ab3419e96b59d1d2bg6z7zaz5q2z5e5c0g3z&from=wpm07163&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX FireFox: ======== FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-09-03] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-09-03] (Intel Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-04-01] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-16] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2915926479-3701056459-1286684747-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Kevin Clickoo\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-07] (Google Inc.) FF Plugin HKU\S-1-5-21-2915926479-3701056459-1286684747-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Kevin Clickoo\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-07] (Google Inc.) FF HKLM-x32\...\Firefox\Extensions: [PointGrab@PointGrab.com] - C:\Program Files (x86)\PointGrab\Hand Gesture Control\PointGrab.xpi FF Extension: PointGrab - C:\Program Files (x86)\PointGrab\Hand Gesture Control\PointGrab.xpi [2014-04-23] [non signé] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-11] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.fr/ CHR StartupUrls: Default -> "hxxp://www.oursurfing.com/?type=hp&ts=1437587005&z=a5b143e3ee3eaa42171c144g3z6c1m2wbb4cazbz1m&from=2sq&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX","hxxp://www.delta-homes.com/?type=hp&ts=1444640317&z=9e5433ab3419e96b59d1d2bg6z7zaz5q2z5e5c0g3z&from=wpm07163&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX","hxxp://www.omniboxes.com/?type=hp&ts=1448619136&z=e043e86710b0ed414f5a960gcz0z0bdq7gbtbg4cfc&from=ient07021&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX","hxxp://www.yoursites123.com/?type=hp&ts=1449832221&z=fc3734f2d096e2de1c1d623gdz5z5t4b7c6o6oag8b&from=ient07021&uid=TOSHIBAXDT01ACA100_84VRHL0NSXX84VRHL0NSX" CHR Profile: C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Deezer Control) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmkmelneeccijablfclenghkcbopdemg [2015-12-17] CHR Extension: (Facebook™ Messenger) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecmfchgfmbbddembehpkopmhjiepcckd [2015-12-17] CHR Extension: (Avast SafePrice) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-12-16] CHR Extension: (Vérificateur de messages Google) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-12-17] CHR Extension: (Ghostery) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-12-17] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Kevin Clickoo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-16] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-07-16] ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-28] (AVAST Software) S3 AWiCSrvc; C:\Program Files (x86)\Qualcomm Atheros\AWiCSrvc.exe [50816 2014-05-14] (Atheros Communications) [Fichier non signé] R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-07-18] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-09-03] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-09-03] (Intel Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes) R2 PGService; C:\Program Files (x86)\PointGrab\Hand Gesture Control\PGService.exe [64776 2014-04-23] (PointGrab LTD) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-01-02] (Atheros) [Fichier non signé] U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] () R0 assdv2; C:\Windows\System32\Drivers\assdv2.sys [21816 2013-12-05] () R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] () R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-09-28] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-09-28] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-09-28] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-09-28] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-09] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-09] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-09-28] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-09-28] (AVAST Software) R3 athr; C:\Windows\System32\drivers\athwbx.sys [4226560 2014-10-17] (Qualcomm Atheros Communications, Inc.) R3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [165376 2015-07-10] (Microsoft Corporation) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek ) S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] () S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation) R3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation) R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation) U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X] S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2015-12-17 10:34 - 2015-12-17 10:35 - 00017314 _____ C:\Users\Kevin Clickoo\Desktop\FRST.txt 2015-12-17 10:34 - 2015-12-17 10:34 - 02370048 _____ (Farbar) C:\Users\Kevin Clickoo\Desktop\FRST64.exe 2015-12-17 10:34 - 2015-12-17 10:34 - 00000000 ____D C:\FRST 2015-12-17 10:30 - 2015-12-17 10:30 - 00016148 _____ C:\WINDOWS\system32\CLICKOO-KEVIN_Kevin Clickoo_HistoryPrediction.bin 2015-12-16 17:49 - 2015-12-16 17:49 - 00001069 _____ C:\Users\Kevin Clickoo\Desktop\malware.txt 2015-12-16 17:31 - 2015-12-16 17:47 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-12-16 17:31 - 2015-12-16 17:31 - 00001182 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-12-16 17:31 - 2015-12-16 17:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-12-16 17:31 - 2015-12-16 17:31 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-12-16 17:31 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2015-12-16 17:31 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2015-12-16 17:31 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2015-12-16 17:30 - 2015-12-16 17:30 - 00001842 _____ C:\Users\Kevin Clickoo\Desktop\AdwCleaner[C2].txt 2015-12-16 17:24 - 2015-12-16 17:24 - 00010489 _____ C:\Users\Kevin Clickoo\Desktop\ZHPCleaner.txt 2015-12-16 17:17 - 2015-12-16 17:17 - 22908888 _____ (Malwarebytes ) C:\Users\Kevin Clickoo\Desktop\mbam-setup-2.2.0.1024.exe 2015-12-16 17:16 - 2015-12-16 17:16 - 01740288 _____ C:\Users\Kevin Clickoo\Desktop\adwcleaner_5.025 (1).exe 2015-12-16 17:14 - 2015-12-16 17:19 - 00000934 _____ C:\Users\Kevin Clickoo\Desktop\ZHPCleaner.lnk 2015-12-16 17:14 - 2015-12-16 17:14 - 01946112 _____ C:\Users\Kevin Clickoo\Desktop\ZHPCleaner.exe 2015-12-16 16:58 - 2015-12-16 17:54 - 00079660 _____ C:\Users\Kevin Clickoo\Desktop\ZHPDiag.txt 2015-12-16 16:54 - 2015-12-16 17:51 - 00000214 _____ C:\Users\Kevin 2015-12-16 16:53 - 2015-12-16 17:51 - 00000924 _____ C:\Users\Kevin Clickoo\Desktop\ZHPDiag.lnk 2015-12-16 16:53 - 2015-12-16 17:51 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\ZHP 2015-12-16 16:53 - 2015-12-16 16:53 - 02019328 _____ C:\Users\Kevin Clickoo\Downloads\ZHPDiag3.exe 2015-12-16 16:19 - 2015-12-16 17:27 - 00000000 ____D C:\AdwCleaner 2015-12-16 16:19 - 2015-12-16 16:19 - 01740288 _____ C:\Users\Kevin Clickoo\Downloads\adwcleaner_5.025.exe 2015-12-16 16:16 - 2015-12-16 16:16 - 00002341 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-12-16 16:16 - 2015-12-16 16:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-12-16 16:15 - 2015-12-17 10:31 - 00001106 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-12-16 16:15 - 2015-12-16 18:20 - 00001110 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-12-16 16:15 - 2015-12-16 16:15 - 00927824 _____ (Google Inc.) C:\Users\Kevin Clickoo\Downloads\ChromeSetup.exe 2015-12-16 16:15 - 2015-12-16 16:15 - 00004168 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-12-16 16:15 - 2015-12-16 16:15 - 00003936 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-12-16 16:10 - 2015-12-16 16:10 - 00032987 _____ C:\Users\Kevin Clickoo\Documents\favoris_16_12_2015.html 2015-12-16 15:58 - 2015-12-16 17:42 - 00018338 _____ C:\Users\Kevin Clickoo\Desktop\Sans nom 1.odt 2015-12-16 15:37 - 2015-12-16 15:37 - 00000290 __RSH C:\ProgramData\ntuser.pol 2015-12-16 14:32 - 2015-12-16 15:12 - 00030720 _____ C:\Users\Kevin Clickoo\Downloads\traduction ndtwi.xls 2015-12-16 14:32 - 2015-12-16 14:32 - 00034518 _____ C:\Users\Kevin Clickoo\Downloads\Rapport sur les mots clés.csv 2015-12-16 14:23 - 2015-12-16 14:23 - 00010240 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Mot clés control.xls 2015-12-16 11:23 - 2015-12-16 11:23 - 00000000 ____D C:\Users\Kevin Clickoo\Documents\sonoscanner 2015-12-15 18:23 - 2015-12-15 18:23 - 00010444 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Mots clés QAQC.csv 2015-12-15 18:22 - 2015-12-16 14:21 - 00008896 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Mot clés control.csv 2015-12-15 18:22 - 2015-12-16 14:12 - 00014086 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Annonces control.csv 2015-12-15 18:22 - 2015-12-15 18:23 - 00015136 _____ C:\Users\Kevin Clickoo\Downloads\NDTWI Annonces QAQC.csv 2015-12-15 18:17 - 2015-12-15 18:17 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\OpenOffice 2015-12-15 18:15 - 2015-12-15 18:16 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.2 2015-12-15 18:15 - 2015-12-15 18:15 - 00001092 _____ C:\Users\Public\Desktop\OpenOffice 4.1.2.lnk 2015-12-15 18:14 - 2015-12-15 18:15 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2015-12-15 18:02 - 2015-12-15 18:02 - 00000000 ____D C:\Users\Kevin Clickoo\Desktop\OpenOffice 4.1.2 (fr) Installation Files 2015-12-11 12:10 - 2015-12-16 17:23 - 00000000 ____D C:\ProgramData\rWdMr 2015-12-09 12:01 - 2015-12-11 12:41 - 00363008 _____ C:\Users\Kevin Clickoo\Downloads\Bulletin d'inscription FF.XLS 2015-11-25 18:33 - 2015-11-25 18:33 - 00000512 _____ C:\Users\Kevin Clickoo\Downloads\700AAE40 2015-11-25 15:13 - 2015-11-25 15:13 - 00023433 _____ C:\Users\Kevin Clickoo\Desktop\sonoscanner deutsch avec caracteres.xlsx 2015-11-20 14:11 - 2015-11-20 14:11 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AdWords Editor 2015-11-20 14:10 - 2015-12-16 18:20 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2915926479-3701056459-1286684747-1001UA.job 2015-11-20 14:10 - 2015-12-16 11:20 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2915926479-3701056459-1286684747-1001Core.job 2015-11-20 14:10 - 2015-12-07 11:15 - 00004272 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2915926479-3701056459-1286684747-1001UA 2015-11-20 14:10 - 2015-12-07 11:15 - 00003896 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2915926479-3701056459-1286684747-1001Core 2015-11-18 12:09 - 2015-11-18 12:09 - 00000000 ____D C:\Users\Kevin Clickoo\Desktop\crea ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2015-12-17 10:34 - 2015-07-10 10:05 - 00000000 ____D C:\Windows 2015-12-17 10:30 - 2015-08-06 15:43 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2015-12-17 10:30 - 2015-07-17 05:23 - 00000000 __SHD C:\Users\Kevin Clickoo\IntelGraphicsProfiles 2015-12-16 18:33 - 2015-07-16 14:41 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\Google 2015-12-16 17:46 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-12-16 17:46 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\Vss 2015-12-16 17:45 - 2015-07-10 10:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2015-12-16 17:42 - 2015-09-25 16:09 - 00565248 ___SH C:\Users\Kevin Clickoo\Desktop\Thumbs.db 2015-12-16 16:51 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps 2015-12-16 16:51 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness 2015-12-16 16:50 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-12-16 16:15 - 2015-07-17 05:37 - 00000000 ____D C:\Program Files (x86)\Google 2015-12-16 16:00 - 2015-07-10 13:20 - 00488296 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2015-12-16 15:44 - 2015-07-17 05:40 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Roaming\Skype 2015-12-16 15:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2015-12-16 15:37 - 2013-08-22 16:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy 2015-12-16 11:21 - 2015-10-22 14:08 - 00000000 ____D C:\Users\Kevin Clickoo\Downloads\acceor 2015-12-16 11:21 - 2015-08-03 16:18 - 00000000 ____D C:\install 2015-12-15 18:02 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2015-12-11 18:31 - 2015-08-07 15:31 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-12-11 18:31 - 2015-08-07 15:31 - 00000000 ____D C:\Program Files\Microsoft Office 2015-12-11 18:30 - 2015-07-10 17:28 - 00000000 ____D C:\WINDOWS\ShellNew 2015-12-11 18:29 - 2015-08-07 15:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2015-12-11 18:29 - 2015-07-10 12:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2015-12-11 18:28 - 2015-07-10 12:04 - 00000000 ____D C:\Program Files\Common Files\System 2015-12-11 18:28 - 2013-08-22 14:25 - 00000108 _____ C:\WINDOWS\win.ini 2015-12-09 12:02 - 2015-07-17 05:23 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Local\Packages 2015-12-01 10:36 - 2015-08-06 16:01 - 01839260 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-12-01 10:36 - 2015-07-10 17:24 - 00819778 _____ C:\WINDOWS\system32\perfh00C.dat 2015-12-01 10:36 - 2015-07-10 17:24 - 00154144 _____ C:\WINDOWS\system32\perfc00C.dat 2015-12-01 10:36 - 2015-07-10 12:02 - 00000000 ____D C:\WINDOWS\INF 2015-11-30 12:40 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache 2015-11-30 11:53 - 2015-08-10 11:42 - 00005368 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for CLICKOO-KEVIN-Kevin Clickoo Clickoo-Kevin 2015-11-30 10:37 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\appraiser 2015-11-26 10:43 - 2015-08-06 18:12 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-11-25 16:33 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2015-11-20 14:13 - 2015-07-17 10:16 - 00001484 _____ C:\Users\Kevin Clickoo\Desktop\Google AdWords Editor.lnk 2015-11-20 14:10 - 2015-07-17 05:37 - 00000000 ____D C:\Users\Kevin Clickoo\AppData\Local\Google ==================== Fichiers à la racine de certains dossiers ======= 2015-07-17 15:17 - 2015-08-11 09:59 - 0000600 _____ () C:\Users\Kevin Clickoo\AppData\Local\PUTTY.RND 2015-08-06 15:44 - 2015-08-06 15:44 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Certains fichiers dans TEMP: ==================== C:\Users\Kevin Clickoo\AppData\Local\Temp\2g20seak.cquBingAdsEditor.exe C:\Users\Kevin Clickoo\AppData\Local\Temp\GoogleAdWordsEditorSetup.exe C:\Users\Kevin Clickoo\AppData\Local\Temp\sqlite3.dll C:\Users\Kevin Clickoo\AppData\Local\Temp\wwspvfek.uhjBingAdsEditor.exe ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2015-11-30 11:15 ==================== Fin de FRST.txt ============================