Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016 Exécuté par HANIN (administrateur) sur HANIN-HP (07-02-2016 08:09:04) Exécuté depuis C:\Users\HANIN\Desktop Profils chargés: HANIN (Profils disponibles: HANIN) Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: IE) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Green search security) C:\ProgramData\Internet Helper Anti-phishing\internetHelper_antiphishingb.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe () C:\Program Files (x86)\MagnoPlayer\MagnoPlayerUpdaterService.exe () C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe () C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ArcSoft, Inc.) C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe () C:\Users\HANIN\AppData\Local\30441562-1424651605-11DE-BCEA-00117F19704B\cnslA335.tmp (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Dropbox, Inc.) C:\Users\HANIN\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Microsoft Corporation) C:\Windows\System32\Wat\WatUX.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_16_0_0_305_ActiveX.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X] AppInit_DLLs-x32: c:/progra~3/{0176e~1/191~1.1/noni.dll => Pas de fichier Lsa: [Notification Packages] EpePcNp64 DPPassFilter scecli ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\HANIN\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-09] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\HANIN\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-09] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\HANIN\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-09] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\HANIN\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-09] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\HANIN\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-09] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\HANIN\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-09] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\HANIN\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-09] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\HANIN\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-09] (Dropbox, Inc.) CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Winsock: Catalog9 01 C:\windows\SysWOW64\BDL.dll [318808 2015-02-24] (OM Inc.) Winsock: Catalog9 02 C:\windows\SysWOW64\BDL.dll [318808 2015-02-24] (OM Inc.) Winsock: Catalog9 03 C:\windows\SysWOW64\BDL.dll [318808 2015-02-24] (OM Inc.) Winsock: Catalog9 04 C:\windows\SysWOW64\BDL.dll [318808 2015-02-24] (OM Inc.) Winsock: Catalog9 15 C:\windows\SysWOW64\BDL.dll [318808 2015-02-24] (OM Inc.) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\..\Interfaces\{19039960-629B-45A7-89DE-41AC85279850}: [NameServer] 8.8.8.8 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchy.easylifeapp.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchy.easylifeapp.com/ HKU\S-1-5-21-2759324722-2794864247-3545256636-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchy.easylifeapp.com/ HKU\S-1-5-21-2759324722-2794864247-3545256636-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1424641957&from=cmi&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1424641957&from=cmi&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&q={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1424641957&from=cmi&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&q={searchTerms} SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1424641957&from=cmi&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1424641957&from=cmi&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&q={searchTerms} SearchScopes: HKLM-x32 -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM-x32 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.look-for-it.info/?l=1&q={searchTerms}&pid=21735&r=2015/02/22&hid=3144305426815075165&lg=EN&cc=GB&unqvl=82 SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3323129&octid=EB_ORIGINAL_CTID&ISID=ME47508DD-D3F8-42D2-A149-094FB67D54CB&SearchSource=58&CUI=&UM=8&UP=SPD095320D-DAB7-47E3-A4DA-4523A43E8D52&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3323129&octid=EB_ORIGINAL_CTID&ISID=ME47508DD-D3F8-42D2-A149-094FB67D54CB&SearchSource=58&CUI=&UM=8&UP=SPD095320D-DAB7-47E3-A4DA-4523A43E8D52&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&ts=1424635432&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&ts=1424635432&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_cmi_15_08&cd=2XzuyEtN2Y1L1Qzu0EyEtCtCyD0ByD0ByC0EzytAyDyCyBzztN0D0Tzu0StCtCyEzztN1L2XzutAtFzztFtCtFtCtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2SyD0Fzzzy0CtCtDyEtGtB0A0B0EtGyDtAtAtAtGzz0Azy0EtGyCtCtCyByBzyzztB0CzzyCzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0A0A0EyDyCtB0EtG0ByCtAyBtGyEyE0EtDtG0AzzyEyCtGtDtA0ByEyDtB0DtAtAzz0CtD2QtN1B2Z1V1T1S1NzuyDtByC&cr=958194390&ir= SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&ts=1424635432&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1424641957&from=cmi&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&q={searchTerms} SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&ts=1424635432&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&ts=1424635432&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&ts=1424635432&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&ts=1424635432&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=HitachiXHTS547550A9E384_J2160051E30N2DE30N2DX&ts=1424635432&type=default&q={searchTerms} BHO-x32: Symantec NCO BHO -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll [2012-06-07] (Symantec Corporation) BHO-x32: Symantec Intrusion Prevention -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\IPS\IPSBHO.DLL [2011-03-31] (Symantec Corporation) BHO-x32: PriceFountain -> {b608cc98-54de-4775-96c9-097de398500c} -> Pas de fichier BHO-x32: GoReaTSave4U -> {df4f4b1a-fcbd-4cf1-8380-b45e792798e0} -> C:\Program Files (x86)\GoReaTSave4U\smYs7xTtLelNb3.dll [2015-03-21] () BHO-x32: FuiinDBestDEal -> {ef981013-7b5e-4538-8ca6-9fdba376c039} -> C:\Program Files (x86)\FuiinDBestDEal\KvkY1s64rKl0AR.dll [2015-03-16] () Toolbar: HKU\S-1-5-21-2759324722-2794864247-3545256636-1001 -> Pas de nom - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Pas de fichier Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) FireFox: ======== FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-02-22] (globalUpdate) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-02-22] (globalUpdate) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-06] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-06] (Google Inc.) FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2011-12-22] [non signé] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn FF Extension: Symantec IPS - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn [2014-10-30] [non signé] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 [2016-02-06] [non signé] Chrome: ======= CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=fr-fr CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3323129&octid=EB_ORIGINAL_CTID&ISID=ME47508DD-D3F8-42D2-A149-094FB67D54CB&SearchSource=55&CUI=&UM=8&UP=SPD095320D-DAB7-47E3-A4DA-4523A43E8D52&SSPV=" CHR DefaultSearchURL: Default -> hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3323129&octid=EB_ORIGINAL_CTID&ISID=ME47508DD-D3F8-42D2-A149-094FB67D54CB&SearchSource=58&CUI=&UM=8&UP=SPD095320D-DAB7-47E3-A4DA-4523A43E8D52&q={searchTerms}&SSPV= CHR DefaultSearchKeyword: Default -> trovi.search CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms} CHR Profile: C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-07] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (Page up top) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\bipjgknmljicpokknhomnlfkadapjaeh [2015-05-29] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (YouTube) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-05] CHR Extension: (Recherche Google) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-23] CHR Extension: (binkiland New Tab) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\elggllhppljlljkgfeokjpehmdamkejk [2015-02-23] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (elioihkkcdgakfbahdoddophfngopipi) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2015-02-26] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (Bookmarks Button) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffieaadkkhencgelmgbbmkkipeocbcbg [2015-02-22] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (gpbepnljaakggeobkclonlkhbdgccfek) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpbepnljaakggeobkclonlkhbdgccfek [2015-02-26] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (1click timer) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\igloknlllonknnbkfgggfkigmeegmakf [2015-05-14] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (Spreed speed read the web) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipikiaejjblmdopojhpejjmbedhlibno [2015-03-21] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (Hey Girl) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcpmmhaffdebnmkjelaohgjmndeongip [2015-04-24] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (Google Wallet) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-23] [UpdateUrl: hxxps://epicunitscan.info/00service/update2/crx] <==== ATTENTION CHR Extension: (Gmail) - C:\Users\HANIN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-23] CHR Extension: (AllCHoeaapPrice) - C:\ProgramData\mjafboekelbfhpfnonpihacdfgpohhpd\ [] CHR HKLM\...\Chrome\Extension: [elggllhppljlljkgfeokjpehmdamkejk] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-2759324722-2794864247-3545256636-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [elggllhppljlljkgfeokjpehmdamkejk] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-2759324722-2794864247-3545256636-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [elggllhppljlljkgfeokjpehmdamkejk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S4 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53832 2014-11-25] (Just Develop It) <==== ATTENTION S3 bthserv; C:\Windows\system32\bthserv.dll [83968 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S2 cilovucu; C:\Users\HANIN\AppData\Roaming\VOPackage\VOsrv.exe [141312 2015-02-23] () [Fichier non signé] <==== ATTENTION S3 defragsvc; C:\Windows\System32\defragsvc.dll [291328 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [481104 2011-02-12] (DigitalPersona, Inc.) R3 EapHost; C:\Windows\System32\eapsvc.dll [111104 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 EventSystem; C:\Windows\system32\es.dll [402944 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 EventSystem; C:\windows\SysWOW64\es.dll [271360 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 fdPHost; C:\Windows\system32\fdPHost.dll [16384 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 FDResPub; C:\Windows\system32\fdrespub.dll [34816 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [464440 2011-05-10] (Hewlett-Packard Company) S3 hidserv; C:\Windows\system32\hidserv.dll [38912 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 hidserv; C:\windows\SysWOW64\hidserv.dll [49152 2009-07-14] (Microsoft Corporation) [Fichier non signé] S4 HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [36864 2011-01-12] (Hewlett-Packard Development Company, L.P) [Fichier non signé] S4 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company) S4 HPFSService; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [320000 2011-02-07] (Hewlett-Packard) [Fichier non signé] S4 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [281656 2011-01-29] (Hewlett-Packard Company) S4 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] () [Fichier non signé] R2 internethelper_antiphishing; C:\ProgramData\Internet Helper Anti-phishing\internetHelper_antiphishingb.exe [297272 2014-09-23] (Green search security) S3 IPBusEnum; C:\Windows\system32\ipbusenum.dll [101888 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 KtmRm; C:\Windows\system32\msdtckrm.dll [368640 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 lltdsvc; C:\Windows\System32\lltdsvc.dll [300032 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 MagnoPlayerUpdaterService; C:\Program Files (x86)\MagnoPlayer\MagnoPlayerUpdaterService.exe [11776 2015-02-20] () [Fichier non signé] R2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1318912 2011-02-09] () [Fichier non signé] R2 MMCSS; C:\Windows\system32\mmcss.dll [67584 2009-07-14] (Microsoft Corporation) [Fichier non signé] R3 Netman; C:\Windows\System32\netman.dll [360448 2009-07-14] (Microsoft Corporation) [Fichier non signé] R3 netprofm; C:\Windows\System32\netprofm.dll [459776 2009-07-14] (Microsoft Corporation) [Fichier non signé] R3 netprofm; C:\windows\SysWOW64\netprofm.dll [360448 2009-07-14] (Microsoft Corporation) [Fichier non signé] S2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation) R2 nsi; C:\Windows\system32\nsisvc.dll [25600 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1127448 2011-02-01] (PDF Complete Inc) R2 Power; C:\Windows\system32\umpo.dll [163840 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 ProfSvc; C:\Windows\system32\profsvc.dll [210432 2014-12-19] (Microsoft Corporation) [Fichier non signé] S3 RasAuto; C:\Windows\System32\rasauto.dll [99328 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7410024 2015-01-14] (Reimage®) S3 RemoteRegistry; C:\Windows\system32\regsvc.dll [159232 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 RpcEptMapper; C:\Windows\System32\RpcEpMap.dll [67072 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 SENS; C:\Windows\System32\sens.dll [64512 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 SENS; C:\windows\SysWOW64\sens.dll [49664 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 SharedAccess; C:\Windows\System32\ipnathlp.dll [359424 2009-07-14] (Microsoft Corporation) [Fichier non signé] R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [193024 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 swprv; C:\Windows\System32\swprv.dll [524288 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 TBS; C:\Windows\System32\tbssvc.dll [65536 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 THREADORDER; C:\Windows\system32\mmcss.dll [67584 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 TrkWks; C:\Windows\System32\trkwks.dll [119808 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.) S2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [126568 2015-02-23] (RaMMicHaeL) [Fichier non signé] S3 upnphost; C:\Windows\System32\upnphost.dll [353792 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 upnphost; C:\windows\SysWOW64\upnphost.dll [266752 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 vupudugo; C:\Users\HANIN\AppData\Local\30441562-1424651605-11DE-BCEA-00117F19704B\cnslA335.tmp [82432 2015-02-23] () [Fichier non signé] R3 W32Time; C:\Windows\system32\w32time.dll [381952 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 Wecsvc; C:\Windows\system32\wecsvc.dll [237568 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 WerSvc; C:\Windows\System32\WerSvc.dll [76800 2009-07-14] (Microsoft Corporation) [Fichier non signé] S2 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-03-07] (Xobni Corporation) S4 globalUpdate; [X] <==== ATTENTION S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc [X] <==== ATTENTION S3 PCTSFileEnum; C:\Program Files (x86)\PC Tools Security\PCTSFiles.exe [X] S4 qrsvc_1.10.0.9; [X] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.) S3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [23040 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20141209.001\BHDrvx64.sys [1587416 2014-10-16] (Symantec Corporation) S4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [92160 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [64312 2011-05-10] (Hewlett-Packard Company) R1 discache; C:\Windows\System32\drivers\discache.sys [40448 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-11] (Symantec Corporation) S3 exfat; C:\Windows\System32\Drivers\exfat.sys [195072 2009-07-14] (Microsoft Corporation) [Fichier non signé] R3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [204800 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [34304 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20141219.001\IDSvia64.sys [637656 2014-11-28] (Symantec Corporation) R3 internethelper_antiphishingd; C:\ProgramData\Internet Helper Anti-phishing\internethelper_antiphishingd.sys [51912 2014-05-09] (Green search security) S3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [116224 2009-07-14] (Microsoft Corporation) [Fichier non signé] R3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [20992 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [60928 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 luafv; C:\Windows\system32\drivers\luafv.sys [113152 2009-07-14] (Microsoft Corporation) [Fichier non signé] R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [168008 2011-02-09] (McAfee, Inc.) S3 Modem; C:\Windows\System32\drivers\modem.sys [40448 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 mshidkmdf; C:\Windows\System32\drivers\mshidkmdf.sys [8192 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [11136 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [7168 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [6784 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [8064 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2011-04-04] (Marvell Semiconductor, Inc.) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20141221.020\ENG64.SYS [129752 2014-10-24] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20141221.020\EX64.SYS [2137304 2014-10-24] (Symantec Corporation) S3 NdisCap; C:\Windows\System32\DRIVERS\ndiscap.sys [35328 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [44544 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [24576 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 Null; C:\Windows\System32\Drivers\Null.sys [6144 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 qrnfd_1_10_0_9; C:\Windows\System32\drivers\qrnfd_1_10_0_9.sys [58224 2015-02-06] (Quick Ref) S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [14848 2009-07-14] (Microsoft Corporation) [Fichier non signé] R3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [92672 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [7680 2009-07-14] (Microsoft Corporation) [Fichier non signé] R2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [76800 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 Smb; C:\Windows\System32\DRIVERS\smb.sys [93184 2009-07-14] (Microsoft Corporation) [Fichier non signé] R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826048 2010-12-21] () S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1207020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1207020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1207020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1207020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation) R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2014-10-24] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [171128 2011-01-27] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation) R1 VgaSave; C:\Windows\System32\drivers\vga.sys [29184 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [12800 2009-07-14] (Microsoft Corporation) [Fichier non signé] R1 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [21504 2009-07-14] (Microsoft Corporation) [Fichier non signé] S3 cpuz134; \??\C:\Users\HANIN\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-02-07 08:09 - 2016-02-07 08:09 - 00034715 _____ C:\Users\HANIN\Desktop\FRST.txt 2016-02-07 08:08 - 2016-02-07 08:09 - 00000000 ____D C:\FRST 2016-02-07 08:08 - 2016-02-07 08:08 - 02370560 _____ (Farbar) C:\Users\HANIN\Desktop\FRST64.exe 2016-02-06 16:22 - 2016-02-06 16:22 - 00000000 _____ C:\Users\HANIN\AppData\Local\{563FEF9F-546C-421F-B4DB-0CEA42A69026} 2016-02-06 16:17 - 2016-02-06 16:17 - 00399360 _____ (Trend Micro Inc.) C:\windows\RegBootClean64.exe 2016-02-06 16:16 - 2016-02-06 16:16 - 00260054 _____ C:\Users\HANIN\AppData\Local\census.cache 2016-02-06 16:15 - 2016-02-06 16:15 - 00108448 _____ C:\Users\HANIN\AppData\Local\ars.cache 2016-02-06 15:59 - 2016-02-06 15:59 - 00772016 _____ (Reimage®) C:\Users\HANIN\Desktop\ReimageRepair.exe 2016-02-06 15:58 - 2016-02-06 15:58 - 00772016 _____ (Reimage®) C:\Users\HANIN\Downloads\ReimageRepair (2).exe 2016-02-06 15:08 - 2016-02-06 15:08 - 00002631 _____ C:\Users\HANIN\Downloads\legitcheck.hta 2016-02-05 22:14 - 2016-02-05 22:14 - 00000000 _____ C:\Users\HANIN\AppData\Local\{D8032820-6202-40B1-BA77-C7CEE49A847B} 2016-02-05 22:10 - 2016-02-05 22:10 - 00002246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-02-05 22:10 - 2016-02-05 22:10 - 00002217 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-02-05 22:09 - 2016-02-07 08:03 - 00001066 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-05 22:09 - 2016-02-06 16:26 - 00001062 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-02-05 22:09 - 2016-02-06 16:21 - 00004062 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-02-05 22:09 - 2016-02-06 16:21 - 00003810 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-02-05 21:53 - 2016-02-05 21:59 - 02405672 _____ (Trend Micro Inc.) C:\Users\HANIN\Downloads\HousecallLauncher64.exe 2016-02-05 21:53 - 2016-02-05 21:53 - 00000036 _____ C:\Users\HANIN\AppData\Local\housecall.guid.cache 2016-02-05 21:49 - 2016-02-05 21:50 - 02405672 _____ (Trend Micro Inc.) C:\Users\HANIN\Desktop\HousecallLauncher64.exe 2016-02-05 21:27 - 2016-02-05 22:08 - 45868112 _____ (Google Inc.) C:\Users\HANIN\Desktop\ChromeStandaloneSetup.exe 2016-02-05 21:00 - 2016-02-05 21:00 - 00178612 _____ C:\Users\HANIN\Desktop\FixWin.zip 2016-02-05 21:00 - 2016-02-05 21:00 - 00000000 ____D C:\Users\HANIN\Desktop\FixWin 2016-02-05 20:55 - 2016-02-05 20:55 - 00000000 _____ C:\Users\HANIN\AppData\Local\{96A69721-18D5-4F7B-9D67-95843CD31B82} 2016-02-05 20:23 - 2016-02-05 20:23 - 00000000 _____ C:\Users\HANIN\AppData\Local\{39C8BAF7-73CE-423A-9D7F-E6ADF0E0FDDF} 2016-02-05 20:08 - 2016-02-05 20:16 - 00000000 ____D C:\Users\HANIN\Desktop\shexview-x64 2016-02-05 20:08 - 2016-02-05 20:08 - 00097609 _____ C:\Users\HANIN\Desktop\shexview-x64.zip 2016-02-05 19:14 - 2016-02-05 19:14 - 00000000 _____ C:\Users\HANIN\AppData\Local\{AB9836D0-8240-4AD0-AE3D-70C75229A8EE} 2016-02-05 18:00 - 2016-02-05 18:00 - 00011642 _____ C:\Users\HANIN\AppData\Local\Temp-log.txt 2016-02-05 17:51 - 2016-02-05 17:56 - 00027680 _____ C:\Users\HANIN\Desktop\advanced-systemcare-setup.5m2m19p.partial 2016-02-05 17:43 - 2016-02-05 17:43 - 00000000 ____D C:\Program Files\CCleaner 2016-02-05 17:37 - 2016-02-05 17:45 - 06565736 _____ (Piriform Ltd) C:\Users\HANIN\Desktop\ccsetup507.exe 2016-02-05 17:31 - 2016-02-05 17:31 - 00000000 ____D C:\Users\HANIN\AppData\Local\GWX 2016-02-05 17:04 - 2016-02-05 17:11 - 01693184 _____ C:\Users\HANIN\Desktop\Virus_Effect_Remover3.0.10.msi 2016-02-05 16:49 - 2016-02-05 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Window Registry Repair 2016-02-05 16:49 - 2016-02-05 17:59 - 00000000 ____D C:\Program Files (x86)\Free Window Registry Repair 2016-02-05 16:48 - 2016-02-05 17:32 - 00805841 _____ C:\Users\HANIN\Desktop\RegpairSetup.exe 2016-02-05 16:45 - 2016-02-05 16:45 - 00003386 _____ C:\windows\System32\Tasks\{FDF4A346-55D7-4B0B-A2A3-81B039731B05} 2016-02-05 16:37 - 2016-02-05 16:38 - 01364297 _____ ( ) C:\Users\HANIN\Desktop\Setup.exe 2016-02-05 16:06 - 2016-02-05 16:07 - 00021000 _____ C:\Users\HANIN\Desktop\TotalSystemCare-Setup.exe.ewmjwgh.partial 2016-02-04 23:35 - 2016-02-04 23:36 - 00725232 _____ (Opera Software) C:\Users\HANIN\Downloads\Opera_NI_stable.exe 2016-02-04 23:27 - 2016-02-04 23:27 - 00000000 ____D C:\984d1c47ba6bd03739 2016-02-04 23:25 - 2016-02-04 23:27 - 04437568 _____ C:\Users\HANIN\Downloads\Windows6.1-KB977863-x86.msu 2016-02-04 23:16 - 2016-02-04 23:16 - 00001122 _____ C:\Users\HANIN\Desktop\Evernote.lnk 2016-02-04 23:15 - 2016-02-04 23:16 - 00987728 _____ (Google Inc.) C:\Users\HANIN\Desktop\ChromeSetup.exe 2016-02-04 23:10 - 2016-02-04 23:10 - 00000000 ____D C:\Users\HANIN\Desktop\exe_fix_w7 2016-02-04 23:10 - 2016-02-04 23:10 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\WinRAR 2016-02-04 23:09 - 2016-02-04 23:09 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-02-04 23:09 - 2016-02-04 23:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-02-04 23:09 - 2016-02-04 23:09 - 00000000 ____D C:\Program Files (x86)\WinRAR 2016-02-04 23:06 - 2016-02-04 23:09 - 01878048 _____ C:\Users\HANIN\Desktop\winrar_5-30_en_9632_32.exe 2016-02-04 23:00 - 2016-02-04 23:00 - 00000886 _____ C:\Users\HANIN\Desktop\exe_fix_w7.zip 2016-02-04 22:44 - 2016-02-04 22:45 - 00481180 _____ C:\Users\HANIN\Desktop\FRST64.exe.partial 2016-02-04 21:51 - 2016-02-04 21:51 - 00000000 ____D C:\windows\pss 2016-02-04 21:42 - 2016-02-04 21:42 - 00000000 ____D C:\Users\HANIN\AppData\Local\Xobni 2016-02-04 21:42 - 2016-02-04 21:42 - 00000000 _____ C:\Users\HANIN\AppData\Local\{FF36A7D3-0CFE-4AA7-B265-491FA7826810} 2016-02-04 21:17 - 2016-02-04 21:17 - 00000000 ____D C:\ProgramData\9415261b00007a60 2016-02-04 21:17 - 2016-02-04 21:17 - 00000000 _____ C:\Users\HANIN\AppData\Local\{CF2F28E9-8C5F-4902-852A-C3FA9167EC5C} 2016-02-04 21:14 - 2016-02-04 21:14 - 00003148 _____ C:\windows\System32\Tasks\{EFA3422E-D2C7-4140-9575-48EABDF3C33B} 2016-02-04 20:47 - 2016-02-04 20:47 - 00000000 ____D C:\Users\HANIN\AppData\Local\1454608076875 2016-02-04 20:46 - 2016-02-04 20:46 - 00003152 _____ C:\windows\System32\Tasks\{BC8951AF-9569-40CB-A836-BE0C0E35F36C} 2016-02-04 20:36 - 2016-02-04 20:36 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-02-04 20:32 - 2016-02-07 08:04 - 00001196 _____ C:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2759324722-2794864247-3545256636-1001UA.job 2016-02-04 20:32 - 2016-02-06 22:40 - 00001144 _____ C:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2759324722-2794864247-3545256636-1001Core.job 2016-02-04 20:32 - 2016-02-04 20:32 - 00004166 _____ C:\windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2759324722-2794864247-3545256636-1001UA 2016-02-04 20:32 - 2016-02-04 20:32 - 00003770 _____ C:\windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2759324722-2794864247-3545256636-1001Core 2016-02-04 20:32 - 2016-02-04 20:32 - 00000000 ____D C:\Users\HANIN\AppData\Local\Dropbox 2016-02-04 20:32 - 2016-02-04 20:32 - 00000000 ____D C:\ProgramData\Dropbox 2016-02-04 20:29 - 2016-02-05 18:01 - 00000000 ____D C:\ProgramData\155a0c2e7e7b842d 2016-02-04 20:10 - 2016-02-04 20:10 - 00000000 ____D C:\Program Files (x86)\predm 2016-02-04 20:00 - 2016-02-04 20:00 - 00000000 _____ C:\Users\HANIN\AppData\Local\{68B1419D-36B5-4680-9BBF-60F07CA37590} ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-02-07 08:07 - 2015-02-22 23:07 - 00003140 _____ C:\windows\Tasks\728a2d0f-37bd-4a1f-9ac0-de31366050de-1-6.job 2016-02-07 08:07 - 2015-02-22 23:06 - 00005864 _____ C:\windows\Tasks\728a2d0f-37bd-4a1f-9ac0-de31366050de-6.job 2016-02-07 08:07 - 2014-10-26 20:25 - 00000000 ____D C:\Users\HANIN\AppData\Local\CrashDumps 2016-02-07 08:06 - 2015-02-22 23:06 - 00002114 _____ C:\windows\Tasks\728a2d0f-37bd-4a1f-9ac0-de31366050de-10_user.job 2016-02-07 08:06 - 2009-07-14 07:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-02-07 08:06 - 2009-07-14 07:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-02-07 08:03 - 2015-02-23 00:48 - 00000292 _____ C:\windows\Tasks\Binkiland.job 2016-02-07 08:03 - 2015-02-22 23:07 - 00003476 _____ C:\windows\Tasks\728a2d0f-37bd-4a1f-9ac0-de31366050de-1-7.job 2016-02-07 08:03 - 2015-02-22 23:07 - 00002792 _____ C:\windows\Tasks\728a2d0f-37bd-4a1f-9ac0-de31366050de-5_user.job 2016-02-07 08:03 - 2015-02-22 23:07 - 00002448 _____ C:\windows\Tasks\728a2d0f-37bd-4a1f-9ac0-de31366050de-5.job 2016-02-07 08:03 - 2015-02-22 23:06 - 00005520 _____ C:\windows\Tasks\728a2d0f-37bd-4a1f-9ac0-de31366050de-7.job 2016-02-07 08:03 - 2015-02-22 23:06 - 00000950 _____ C:\windows\Tasks\globalUpdateUpdateTaskMachineUA.job 2016-02-07 08:03 - 2015-02-22 23:06 - 00000946 _____ C:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job 2016-02-07 08:03 - 2014-11-01 20:17 - 00001002 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2016-02-06 22:40 - 2009-07-14 06:20 - 00000000 ____D C:\windows\tracing 2016-02-06 22:39 - 2015-03-01 22:22 - 00000000 ____D C:\ProgramData\internethelper_antiphishing 2016-02-06 22:39 - 2015-02-25 13:23 - 00000165 _____ C:\windows\Reimage.ini 2016-02-06 16:20 - 2011-12-22 22:12 - 00000000 ____D C:\ProgramData\PDFC 2016-02-06 16:19 - 2014-11-22 20:13 - 00065536 _____ C:\windows\system32\Ikeext.etl 2016-02-06 16:19 - 2009-07-14 08:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2016-02-06 16:17 - 2015-02-23 00:28 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\VOPackage 2016-02-06 16:17 - 2015-02-22 23:06 - 00000000 ____D C:\Program Files (x86)\Mediaplayersversion2.4 2016-02-06 15:24 - 2015-02-22 23:51 - 00000236 _____ C:\Users\HANIN\AppData\Roaming\WB.CFG 2016-02-05 22:09 - 2014-10-23 16:57 - 00000000 ____D C:\Program Files (x86)\Google 2016-02-05 20:45 - 2014-10-23 15:09 - 00003936 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{EB205C8D-8E8B-4BAE-B3E4-959C743AF813} 2016-02-05 20:41 - 2014-10-31 21:46 - 00000000 ____D C:\windows\System32\Tasks\Symantec 2016-02-05 20:39 - 2014-10-23 15:09 - 00001655 _____ C:\Users\HANIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-02-05 20:15 - 2014-10-23 14:11 - 00000000 ____D C:\Program Files (x86)\ArcSoft 2016-02-05 18:01 - 2015-02-22 20:28 - 00000000 ____D C:\Program Files (x86)\SaavveNewaAppz 2016-02-05 16:47 - 2011-12-22 21:02 - 00745758 _____ C:\windows\system32\perfh00C.dat 2016-02-05 16:47 - 2011-12-22 21:02 - 00148986 _____ C:\windows\system32\perfc00C.dat 2016-02-05 16:47 - 2009-07-14 08:13 - 01663326 _____ C:\windows\system32\PerfStringBackup.INI 2016-02-05 16:47 - 2009-07-14 06:20 - 00000000 ____D C:\windows\inf 2016-02-05 16:29 - 2014-10-23 14:05 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\hpqLog 2016-02-04 22:56 - 2009-07-14 06:20 - 00000000 ____D C:\windows\system32\NDF 2016-02-04 22:51 - 2011-12-22 22:08 - 00000000 ____D C:\ProgramData\HPQLOG 2016-02-04 22:29 - 2015-02-22 20:28 - 00000000 ____D C:\Program Files (x86)\SaveuLoTs 2016-02-04 22:29 - 2014-11-09 21:13 - 00000000 ____D C:\Users\HANIN\AppData\LocalLow\Unity 2016-02-04 22:29 - 2014-11-09 21:13 - 00000000 ____D C:\Users\HANIN\AppData\Local\Unity 2016-02-04 21:37 - 2014-10-23 16:56 - 00000000 ____D C:\Users\HANIN\AppData\Local\Deployment 2016-02-04 21:26 - 2015-02-22 23:02 - 00000000 ____D C:\Users\HANIN\AppData\Local\PriceFountain 2016-02-04 21:13 - 2009-07-14 06:20 - 00000000 __RHD C:\Users\Public\Libraries 2016-02-04 21:03 - 2015-02-23 00:46 - 00000000 ____D C:\Users\HANIN\AppData\Local\SmartWeb 2016-02-04 21:03 - 2015-02-22 23:03 - 00000292 _____ C:\windows\Tasks\Price Fountain.job 2016-02-04 20:39 - 2015-03-16 19:49 - 00000000 ____D C:\Program Files (x86)\AllSAVeer 2016-02-04 20:38 - 2011-12-22 22:29 - 00000000 ____D C:\ProgramData\WildTangent 2016-02-04 20:38 - 2011-12-22 22:29 - 00000000 ____D C:\Program Files (x86)\HP Games 2016-02-04 20:38 - 2009-07-14 08:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2016-02-04 20:37 - 2015-02-22 19:42 - 00000000 ____D C:\ProgramData\1538555616530498605 2016-02-04 20:36 - 2015-05-01 20:19 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\Dropbox 2016-02-04 20:35 - 2014-11-22 14:02 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\WildTangent 2016-02-04 20:04 - 2015-05-01 22:41 - 00000000 ___RD C:\Users\HANIN\Dropbox 2016-01-27 23:23 - 2014-10-23 15:12 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\SoftGrid Client 2016-01-19 23:52 - 2015-04-13 10:53 - 00000000 ___SD C:\windows\system32\GWX 2016-01-19 23:52 - 2015-02-25 13:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair 2016-01-19 23:52 - 2015-02-23 00:28 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage 2016-01-19 23:52 - 2015-02-22 23:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagnoPlayer 2016-01-19 23:52 - 2015-02-22 23:00 - 00000000 ____D C:\Users\HANIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2016-01-19 23:52 - 2014-11-13 15:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-01-19 23:52 - 2014-10-23 14:05 - 00000000 ____D C:\Users\HANIN 2016-01-19 23:52 - 2011-02-11 07:47 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-01-19 23:52 - 2009-07-14 06:20 - 00000000 ____D C:\windows\rescache 2016-01-19 17:12 - 2009-07-14 08:09 - 00000000 ____D C:\windows\System32\Tasks\WPD 2016-01-19 13:54 - 2009-07-14 06:20 - 00000000 ____D C:\windows\PolicyDefinitions ==================== Fichiers à la racine de certains dossiers ======= 2015-02-28 15:26 - 2015-02-28 15:26 - 0000020 _____ () C:\Users\HANIN\AppData\Roaming\appdataFr3.bin 2014-10-23 14:17 - 2014-10-23 14:20 - 0056112 _____ () C:\Users\HANIN\AppData\Roaming\QWInstall.log 2015-02-22 23:51 - 2016-02-06 15:24 - 0000236 _____ () C:\Users\HANIN\AppData\Roaming\WB.CFG 2016-02-06 16:15 - 2016-02-06 16:15 - 0108448 _____ () C:\Users\HANIN\AppData\Local\ars.cache 2016-02-06 16:16 - 2016-02-06 16:16 - 0260054 _____ () C:\Users\HANIN\AppData\Local\census.cache 2015-02-24 17:01 - 2015-02-24 17:01 - 0274045 _____ () C:\Users\HANIN\AppData\Local\dsi1.dat 2015-02-24 17:01 - 2015-02-24 17:01 - 0161916 _____ () C:\Users\HANIN\AppData\Local\dsi2.dat 2016-02-05 21:53 - 2016-02-05 21:53 - 0000036 _____ () C:\Users\HANIN\AppData\Local\housecall.guid.cache 2015-03-01 23:39 - 2015-03-01 23:39 - 0613067 _____ (CMI Limited) C:\Users\HANIN\AppData\Local\nsx5D4E.tmp 2016-02-05 18:00 - 2016-02-05 18:00 - 0011642 _____ () C:\Users\HANIN\AppData\Local\Temp-log.txt 2016-02-05 20:23 - 2016-02-05 20:23 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{39C8BAF7-73CE-423A-9D7F-E6ADF0E0FDDF} 2015-05-13 06:48 - 2015-05-13 06:48 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{41C7A690-0F77-487B-A86B-0E9440CA7B2B} 2016-02-06 16:22 - 2016-02-06 16:22 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{563FEF9F-546C-421F-B4DB-0CEA42A69026} 2016-02-04 20:00 - 2016-02-04 20:00 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{68B1419D-36B5-4680-9BBF-60F07CA37590} 2015-04-13 10:48 - 2015-04-13 10:48 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{725740A0-4AE6-4745-9FE1-ADA762F0DD99} 2015-04-07 18:27 - 2015-04-07 18:27 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{7EEEE040-AFB0-418A-BEB2-399BE0D35B91} 2016-02-05 20:55 - 2016-02-05 20:55 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{96A69721-18D5-4F7B-9D67-95843CD31B82} 2015-03-20 18:32 - 2015-03-20 18:32 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{9EB2C7D2-19D1-4F67-AEB5-BADCA5C111C0} 2016-02-05 19:14 - 2016-02-05 19:14 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{AB9836D0-8240-4AD0-AE3D-70C75229A8EE} 2015-05-22 08:30 - 2015-05-22 08:30 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{BEC3425B-54DB-4F2B-B656-8221453AC619} 2015-05-26 19:29 - 2015-05-26 19:29 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{CAC98787-AE69-4F60-968E-877DA202A647} 2016-02-04 21:17 - 2016-02-04 21:17 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{CF2F28E9-8C5F-4902-852A-C3FA9167EC5C} 2015-04-15 21:50 - 2015-04-15 21:50 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{D3F432A7-9E10-45C4-B5AB-565F1FFBCE7B} 2016-02-05 22:14 - 2016-02-05 22:14 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{D8032820-6202-40B1-BA77-C7CEE49A847B} 2015-04-24 20:34 - 2015-04-24 20:34 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{DEF5A0DA-42A8-49D9-A605-2CE9F5F2F157} 2015-05-29 15:42 - 2015-05-29 15:42 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{F312E81E-F7ED-4B76-A450-6C60CBE3D3B3} 2016-02-04 21:42 - 2016-02-04 21:42 - 0000000 _____ () C:\Users\HANIN\AppData\Local\{FF36A7D3-0CFE-4AA7-B265-491FA7826810} Certains fichiers dans TEMP: ==================== C:\Users\HANIN\AppData\Local\Temp\1F6EAF41-6C8A-EBD1-7E13-81E6844C6336.dll C:\Users\HANIN\AppData\Local\Temp\1F6EAF41-6C8A-EBD1-7E13-81E6844C6336.exe C:\Users\HANIN\AppData\Local\Temp\4ED0.exe C:\Users\HANIN\AppData\Local\Temp\5478.exe C:\Users\HANIN\AppData\Local\Temp\CpqMC.dll C:\Users\HANIN\AppData\Local\Temp\data.exe C:\Users\HANIN\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcb3fuv.dll C:\Users\HANIN\AppData\Local\Temp\F4C9946A-3956-9159-BBB9-66F706AF6664.exe C:\Users\HANIN\AppData\Local\Temp\GUR6473.exe C:\Users\HANIN\AppData\Local\Temp\GUR692E.exe C:\Users\HANIN\AppData\Local\Temp\GUR7F5C.exe C:\Users\HANIN\AppData\Local\Temp\HPSWF.EXE C:\Users\HANIN\AppData\Local\Temp\i499F.tmp.exe C:\Users\HANIN\AppData\Local\Temp\i4B1.tmp.exe C:\Users\HANIN\AppData\Local\Temp\i7466.tmp.exe C:\Users\HANIN\AppData\Local\Temp\i7732.tmp.exe C:\Users\HANIN\AppData\Local\Temp\iA0E1.tmp.exe C:\Users\HANIN\AppData\Local\Temp\ICReinstall_avast-free-antivirus_setup.exe C:\Users\HANIN\AppData\Local\Temp\lvycqcnc.exe C:\Users\HANIN\AppData\Local\Temp\ReimagePackage.exe C:\Users\HANIN\AppData\Local\Temp\ReiSysUpdate.exe C:\Users\HANIN\AppData\Local\Temp\setacl.exe C:\Users\HANIN\AppData\Local\Temp\siinst.exe C:\Users\HANIN\AppData\Local\Temp\SP56729.exe C:\Users\HANIN\AppData\Local\Temp\SP57555.exe C:\Users\HANIN\AppData\Local\Temp\sp58915.exe C:\Users\HANIN\AppData\Local\Temp\SP59202.exe C:\Users\HANIN\AppData\Local\Temp\SpOrder.dll C:\Users\HANIN\AppData\Local\Temp\sqlite3.exe C:\Users\HANIN\AppData\Local\Temp\strings.dll C:\Users\HANIN\AppData\Local\Temp\SWHelperQueryW.dll C:\Users\HANIN\AppData\Local\Temp\Uninstall.exe C:\Users\HANIN\AppData\Local\Temp\Web_Bar_Setup_2-0-5450-28350_3e16a056d.exe ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\windows\system32\winlogon.exe => Le fichier est signé numériquement C:\windows\system32\wininit.exe => Le fichier est signé numériquement C:\windows\SysWOW64\wininit.exe => Le fichier est signé numériquement C:\windows\explorer.exe => Le fichier est signé numériquement C:\windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\windows\system32\svchost.exe => Le fichier est signé numériquement C:\windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\windows\system32\services.exe => Le fichier est signé numériquement C:\windows\system32\User32.dll => Le fichier est signé numériquement C:\windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\windows\system32\userinit.exe => Le fichier est signé numériquement C:\windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\windows\system32\rpcss.dll => Le fichier est signé numériquement C:\windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2015-05-29 12:58 ==================== Fin de FRST.txt ============================