Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:21-02-2016 01 Exécuté par Ahmet (administrateur) sur WIN-9PFFMPKBSTH (22-02-2016 14:30:14) Exécuté depuis C:\Users\Responsable\Desktop Profils chargés: Ahmet (Profils disponibles: Ahmet & Administrateur) Platform: Windows 10 Pro Version 1511 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe (Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\VsHub.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\Microsoft.VsHub.Server.HttpHost.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\Microsoft.VsHub.Server.HttpHostx64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8466136 2015-05-08] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3952832 2015-08-21] (Synaptics Incorporated) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508104 2015-10-30] (Adobe Systems Incorporated) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [220704 2015-09-14] (Geek Software GmbH) HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127528 2015-07-08] (Hewlett-Packard Company) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2072928 2014-10-31] (Wondershare) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-12-17] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-12-22] (Oracle Corporation) HKU\S-1-5-21-511945228-3084827621-2135989165-1002\...\Run: [C] => C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol [750 2016-02-22] () HKU\S-1-5-21-511945228-3084827621-2135989165-1002\...\RunOnce: [Uninstall C:\Users\Responsable\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Responsable\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64" HKU\S-1-5-21-511945228-3084827621-2135989165-1002\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 Startup: C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\system.pif [2016-02-22] () Startup: C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wscanner.lnk [2016-02-22] ShortcutTarget: wscanner.lnk -> C:\Program Files (x86)\Wscanner\wscanner.exe (Pas de fichier) Startup: C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\system.pif [2016-02-22] () Startup: C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wscanner.lnk [2016-02-22] ShortcutTarget: wscanner.lnk -> C:\Program Files (x86)\Wscanner\wscanner.exe (Pas de fichier) GroupPolicy: Restriction - Chrome <======= ATTENTION GroupPolicyScripts\User: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 212.27.40.241 212.27.40.240 Tcpip\..\Interfaces\{01b4a9db-58eb-4046-bae7-bf60142c3f56}: [DhcpNameServer] 192.168.8.1 8.8.8.8 Tcpip\..\Interfaces\{86d0d1c1-43e7-4848-b3ed-3943d8a123b5}: [DhcpNameServer] 212.27.40.241 212.27.40.240 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr HKU\S-1-5-21-511945228-3084827621-2135989165-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr HKU\S-1-5-21-511945228-3084827621-2135989165-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.fr HKU\S-1-5-21-511945228-3084827621-2135989165-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.fr URLSearchHook: [S-1-5-21-511945228-3084827621-2135989165-1002] ATTENTION => URLSearchHook par défaut est absent SearchScopes: HKU\S-1-5-21-511945228-3084827621-2135989165-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-511945228-3084827621-2135989165-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-511945228-3084827621-2135989165-1002 -> {55087B7B-CD89-4B11-93A4-0754E4458915} URL = hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-26] (Oracle Corporation) BHO-x32: Wscanner -> {822B88F2-D7D8-473C-9C82-1A1EDB255268} -> C:\Program Files (x86)\Wscanner\secure\Wscanner.dll [2015-11-27] (Wscanner) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-26] (Oracle Corporation) FireFox: ======== FF ProfilePath: C:\Users\Responsable\AppData\Roaming\Mozilla\Firefox\Profiles\z7jfasuq.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-09] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-09] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-26] (Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-22] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-22] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-511945228-3084827621-2135989165-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Responsable\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-01-22] (Unity Technologies ApS) FF SearchPlugin: C:\Users\Responsable\AppData\Roaming\Mozilla\Firefox\Profiles\z7jfasuq.default\searchplugins\yahoo-ysp.xml [2016-01-26] FF Extension: iMacros for Firefox - C:\Users\Responsable\AppData\Roaming\Mozilla\Firefox\Profiles\z7jfasuq.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2016-01-01] FF Extension: New Tab by Yahoo - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\jid1-G80Ec8LLEbK5fQ@jetpack.xpi [2016-01-07] FF Extension: js4mt - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{9746ad1f-7f2a-4bc8-a61c-2f73d969472d} [2016-02-22] [non signé] FF HKLM-x32\...\Firefox\Extensions: [fiddlerhook@fiddler2.com] - C:\Program Files (x86)\Fiddler2\FiddlerHook FF Extension: FiddlerHook - C:\Program Files (x86)\Fiddler2\FiddlerHook [2015-12-10] [non signé] FF HKLM-x32\...\Firefox\Extensions: [{9746ad1f-7f2a-4bc8-a61c-2f73d969472d}] - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{9746ad1f-7f2a-4bc8-a61c-2f73d969472d} Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=orcl_default CHR DefaultSearchKeyword: Default -> Yahoo CHR DefaultSuggestURL: Default -> hxxps://fr.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10 CHR Profile: C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-22] CHR Extension: (Google Docs) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-22] CHR Extension: (Google Drive) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-22] CHR Extension: (YouTube) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-22] CHR Extension: (Adblock Plus) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-22] CHR Extension: (Recherche Google) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-22] CHR Extension: (Google Docs hors connexion) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-22] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-22] CHR Extension: (Gmail) - C:\Users\Responsable\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-22] CHR HKLM-x32\...\Chrome\Extension: [kpdmjodecdegfglgaapafjleomjjlpnh] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2020056 2016-02-09] (Adobe Systems, Incorporated) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.) S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [441976 2015-10-09] (BlueStack Systems, Inc.) S3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [421496 2015-10-09] (BlueStack Systems, Inc.) S3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [867960 2015-10-09] (BlueStack Systems, Inc.) R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [108248 2015-02-04] () R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1332184 2015-03-31] (Intel Corporation) S3 FBackup5Srv; C:\Program Files (x86)\Softland\FBackup 5\bService.exe [4678680 2015-08-04] (Softland) R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-07-18] (Intel Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [295128 2015-05-08] (Realtek Semiconductor) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2015-08-21] (Synaptics Incorporated) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2015-12-14] (TeamViewer GmbH) R3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [X] S2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe" [X] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [146040 2015-10-09] (BlueStack Systems) S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [165376 2015-10-30] (Microsoft Corporation) S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [36864 2015-10-30] (Microsoft Corporation) R3 dptf_acpi; C:\Windows\System32\drivers\dptf_acpi.sys [45648 2015-03-31] (Intel Corporation) R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [41552 2015-03-31] (Intel Corporation) R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [243792 2015-03-31] (Intel Corporation) R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-11-12] (LogMeIn Inc.) R3 iagpioe; C:\Windows\System32\drivers\iagpioe.sys [32256 2015-03-28] (Intel(R) Corporation) R3 igfxLP; C:\Windows\system32\DRIVERS\igdkmd64lp.sys [5864888 2015-07-18] (Intel Corporation) S3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv.sys [49272 2014-12-29] (Visicom Media Inc.) S3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (Visicom Media Inc.) R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [624424 2015-10-30] (Realtek Semiconductor Corporation) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [4549360 2015-08-21] (Realtek Semiconductor Corporation ) R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [33448 2015-03-19] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [52912 2015-08-21] (Synaptics Incorporated) R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [114976 2015-03-31] (Intel Corporation) R3 VirtualButtons; C:\Windows\System32\drivers\VirtualButtons.sys [31512 2015-04-08] (Intel Corporation) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-08-07] (Hewlett-Packard Development Company, L.P.) S3 xhunter1; C:\WINDOWS\xhunter1.sys [35880 2016-01-13] (Wellbia.com Co., Ltd.) R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [202144 2016-02-22] (Zemana Ltd.) R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [202144 2016-02-22] (Zemana Ltd.) S3 zttap300; C:\Windows\System32\drivers\zttap300.sys [30488 2015-08-13] (ZeroTier Networks LLC) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-02-22 14:31 - 2016-02-22 14:31 - 00544768 _____ ( ) C:\Users\Responsable\Desktop\yeni.exe 2016-02-22 14:30 - 2016-02-22 14:31 - 00019079 _____ C:\Users\Responsable\Desktop\FRST.txt 2016-02-22 14:30 - 2016-02-22 14:30 - 00069120 _____ C:\Users\Responsable\Desktop\Icon Changer and Extension Spoofer.exe 2016-02-22 14:30 - 2015-02-06 20:13 - 00000000 ____D C:\Users\Responsable\Desktop\Icon Changer and Extension Spoofer 2016-02-22 14:21 - 2016-02-22 14:21 - 00000022 _____ C:\WINDOWS\SysWOW64\mseixml.sei 2016-02-22 14:21 - 2016-02-22 14:21 - 00000022 _____ C:\WINDOWS\mseixml.sei 2016-02-22 14:21 - 2016-02-22 14:21 - 00000002 _____ C:\Users\Responsable\Documents\eisavedicon.bmp 2016-02-22 14:17 - 2016-02-22 14:17 - 00372736 _____ ( ) C:\Users\Responsable\Desktop\yeni.exe.(1).bak 2016-02-22 14:11 - 2016-02-22 14:11 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\nBinder Limited 2016-02-22 13:35 - 2016-02-22 13:59 - 00352256 _____ C:\Users\Responsable\Desktop\SpamBot By InterAhmet.exe 2016-02-22 13:34 - 2015-01-31 22:53 - 00352256 _____ C:\Users\Responsable\Desktop\SpamBot By InterAhmet orj.exe 2016-02-22 13:32 - 2016-02-22 13:43 - 00396802 ___SH C:\Users\Responsable\AppData\Local\CSIDL_ 2016-02-22 13:32 - 2016-02-22 13:32 - 00396802 ___SH C:\Users\Responsable\AppData\Local\CSIDL_X 2016-02-22 13:30 - 2016-02-22 13:43 - 00000000 ____D C:\Users\Responsable\Desktop\AegisCrypter8.1 2016-02-22 12:46 - 2016-02-22 12:46 - 00001294 _____ C:\RstHosts.txt 2016-02-22 12:32 - 2016-02-22 12:42 - 00000000 ____D C:\Users\Responsable\Desktop\rapports 2016-02-22 12:29 - 2016-02-22 12:29 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2016-02-22 12:27 - 2016-02-22 12:27 - 00000620 _____ C:\WINDOWS\ZAM.krnl.trace 2016-02-22 12:27 - 2016-02-22 12:27 - 00000119 _____ C:\WINDOWS\ZAM_Guard.krnl.trace 2016-02-22 12:12 - 2016-02-22 12:12 - 00000890 _____ C:\Users\Responsable\Desktop\ZHPCleaner.lnk 2016-02-22 12:10 - 2016-02-22 12:29 - 00353632 _____ C:\Users\Responsable\Desktop\rsthosts_2.0.exe 2016-02-22 12:06 - 2016-02-22 12:06 - 00202144 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys 2016-02-22 12:06 - 2016-02-22 12:06 - 00202144 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam64.sys 2016-02-22 12:06 - 2016-02-22 12:06 - 00000000 ____D C:\Users\Responsable\AppData\Local\Zemana 2016-02-22 11:36 - 2016-02-22 11:36 - 00000000 ____D C:\Users\Responsable\Desktop\Peid 2016-02-22 11:17 - 2016-02-22 12:34 - 00000878 _____ C:\Users\Responsable\Desktop\ZHPDiag.lnk 2016-02-22 10:54 - 2016-02-22 14:30 - 00000000 ____D C:\FRST 2016-02-22 10:52 - 2016-02-22 10:54 - 02371072 _____ (Farbar) C:\Users\Responsable\Desktop\FRST64.exe 2016-02-22 10:49 - 2016-02-22 12:55 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\ZHP 2016-02-22 10:49 - 2016-02-22 10:50 - 00000000 ____D C:\Program Files (x86)\ZHPFix 2016-02-22 10:49 - 2016-02-22 10:49 - 00001925 _____ C:\Users\Public\Desktop\ZHPFix.lnk 2016-02-22 10:49 - 2016-02-22 10:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2016-02-22 10:32 - 2016-02-22 13:37 - 00001108 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-22 10:32 - 2016-02-22 12:29 - 00001104 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-02-22 10:32 - 2016-02-22 10:32 - 00004166 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-02-22 10:32 - 2016-02-22 10:32 - 00003934 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-02-22 10:32 - 2016-02-22 10:32 - 00002279 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-02-22 10:32 - 2016-02-22 10:32 - 00002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-02-22 10:28 - 2016-02-22 10:28 - 01622528 _____ C:\Users\Responsable\Desktop\ResetBrowser.exe 2016-02-22 10:16 - 2016-02-22 10:16 - 00001032 __RSH C:\ProgramData\ntuser.pol 2016-02-22 10:16 - 2016-02-22 10:16 - 00000110 _____ C:\WINDOWS\SysWOW64\L 2016-02-22 10:12 - 2016-02-22 10:18 - 00000000 ____D C:\AdwCleaner 2016-02-22 10:11 - 2016-02-22 10:12 - 01511936 _____ C:\Users\Responsable\Downloads\adwcleaner_5.036.exe 2016-02-22 09:48 - 2016-02-22 10:29 - 00000000 ____D C:\Program Files (x86)\Wscanner 2016-02-22 09:48 - 2016-02-22 09:48 - 00003134 _____ C:\WINDOWS\System32\Tasks\Wscanner Secure 2016-02-22 09:48 - 2016-02-22 09:48 - 00002636 _____ C:\Users\Responsable\AppData\Local\cookies.bin 2016-02-22 09:48 - 2016-02-22 09:48 - 00000000 ____D C:\Program Files (x86)\WCNT 2016-02-22 09:46 - 2016-02-22 09:46 - 00000008 __RSH C:\Users\Responsable\ntuser.pol 2016-02-21 23:21 - 2016-02-21 23:21 - 00004949 _____ C:\ProgramData\rugqgaaw.ekm 2016-02-21 23:14 - 2016-02-21 23:14 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vbkodbank 2016-02-21 23:05 - 2016-02-21 23:05 - 00953856 _____ (CanHit) C:\Users\Responsable\Desktop\Hit Programi.exe 2016-02-21 23:04 - 2016-02-21 23:04 - 00964608 _____ (CanHit) C:\Users\Responsable\Desktop\Hit Programi.exe.(2).bak 2016-02-21 22:59 - 2016-02-21 22:59 - 00809984 _____ (CanHit) C:\Users\Responsable\Desktop\Hit Programi.exe.(1).bak 2016-02-21 22:07 - 2016-02-21 22:07 - 00001219 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\High Proxy Finder.lnk 2016-02-21 22:07 - 2016-02-21 22:07 - 00001207 _____ C:\Users\Public\Desktop\High Proxy Finder.lnk 2016-02-21 22:07 - 2016-02-21 22:07 - 00000000 ____D C:\Program Files (x86)\High Proxy Finder 2016-02-21 22:01 - 2016-02-21 22:01 - 00000000 __HDC C:\ProgramData\{28D47069-C8EF-4BCE-ACD5-7F6FC6BED689} 2016-02-21 22:01 - 2016-02-21 22:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\.NET Reactor 2016-02-21 22:01 - 2016-02-21 22:01 - 00000000 ____D C:\Program Files (x86)\Eziriz 2016-02-20 10:11 - 2016-02-20 10:11 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-02-19 17:01 - 2016-02-19 17:03 - 00000000 ____D C:\Users\Responsable\Source 2016-02-19 16:43 - 2016-02-19 16:43 - 00000000 ____D C:\ProgramData\Microsoft Team Foundation Local Workspaces 2016-02-17 15:57 - 2016-02-17 15:57 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Rugland Digital Systems 2016-02-17 14:51 - 2016-02-17 14:51 - 00000000 ____D C:\WINDOWS\%LOCALAPPDATA% 2016-02-17 13:56 - 2016-02-22 10:24 - 00000000 __SHD C:\bot 2016-02-17 13:56 - 2016-02-22 09:53 - 00003102 _____ C:\WINDOWS\System32\Tasks\Bot Updater 2016-02-17 13:50 - 2016-02-22 10:02 - 00000000 __SHD C:\fix 2016-02-17 13:50 - 2016-02-22 09:53 - 00003100 _____ C:\WINDOWS\System32\Tasks\Coc Updater 2016-02-17 13:50 - 2016-02-17 13:50 - 00000000 ____D C:\Program Files (x86)\WIN-9PFFMPKBSTH 2016-02-16 21:13 - 2016-02-21 12:56 - 00000000 ____D C:\Program Files (x86)\High Yazilim Soft 2016-02-16 21:13 - 2016-02-16 21:13 - 00001243 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Youtube MP3 Converter BETA.lnk 2016-02-16 21:13 - 2016-02-16 21:13 - 00001231 _____ C:\Users\Public\Desktop\Youtube MP3 Converter BETA.lnk 2016-02-16 20:23 - 2016-02-22 09:52 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chrome 2016-02-16 19:13 - 2016-02-16 19:13 - 00001946 _____ C:\Users\Public\Desktop\FileZilla Client.lnk 2016-02-15 22:22 - 2016-02-15 22:23 - 01081616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSCOMCTL.OCX 2016-02-15 22:21 - 2016-02-15 22:21 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldUnlock Calculator 2016-02-13 10:40 - 2016-02-13 10:40 - 00000000 ____D C:\Users\Responsable\Documents\OverZ 2016-02-13 10:40 - 2016-02-13 10:40 - 00000000 ____D C:\Users\Responsable\Documents\Infestation 2016-02-12 21:35 - 2016-02-12 21:36 - 01153284 _____ C:\WINDOWS\Minidump\021216-25078-01.dmp 2016-02-12 21:35 - 2016-02-12 21:35 - 00000000 ____D C:\WINDOWS\Minidump 2016-02-11 21:24 - 2016-02-11 21:26 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Web Traffic Generator 2 2016-02-11 21:22 - 2016-02-11 21:22 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Bold Proxy Checker 2016-02-11 20:33 - 2016-02-11 20:47 - 00000000 ____D C:\ProgramData\Magic Submitter 2016-02-11 17:24 - 2016-02-11 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Money Robot 2016-02-10 22:39 - 2016-02-10 22:39 - 00000829 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3 YAPICI.lnk 2016-02-10 22:30 - 2016-02-10 22:30 - 00001200 _____ C:\Users\Public\Desktop\Inno Setup Compiler.lnk 2016-02-10 22:30 - 2016-02-10 22:30 - 00000000 ____D C:\Program Files (x86)\Inno Setup 5 2016-02-09 20:55 - 2016-02-09 20:55 - 00000000 ____D C:\ProgramData\dbg 2016-02-09 20:11 - 2016-02-09 20:11 - 08817344 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe 2016-02-08 19:22 - 2016-02-16 22:51 - 00000000 ____D C:\Users\Responsable\AppData\Local\ArborSoft 2016-02-05 19:44 - 2016-02-05 19:44 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Unity 2016-02-05 19:37 - 2016-02-05 19:37 - 00000000 ____D C:\Users\Responsable\AppData\LocalLow\Unity 2016-02-05 19:37 - 2016-02-05 19:37 - 00000000 ____D C:\Users\Responsable\AppData\Local\Unity 2016-02-05 19:14 - 2016-02-05 19:14 - 00000000 ____D C:\Users\Responsable\AppData\Local\https___facebook.com_mano 2016-02-04 21:27 - 2016-02-04 21:27 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Crypto Obfuscator For .Net v2015 2016-02-04 21:21 - 2016-02-04 21:21 - 00034308 _____ C:\WINDOWS\SysWOW64\bassmod.dll 2016-02-04 21:19 - 2016-02-04 21:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogicNP Software 2016-02-04 21:19 - 2016-02-04 21:19 - 00000000 ____D C:\Program Files (x86)\LogicNP Software 2016-02-03 15:53 - 2016-02-03 15:54 - 00000000 ____D C:\Users\Responsable\AppData\Local\Vivaldi 2016-02-03 15:53 - 2016-02-03 15:53 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vivaldi 2016-01-31 21:25 - 2016-02-17 22:36 - 00000000 ____D C:\Users\Responsable\Desktop\High 2016-01-31 19:55 - 2016-01-31 19:55 - 00000000 ____D C:\Users\Responsable\AppData\Local\JonathanLeger.com 2016-01-30 11:06 - 2016-02-22 09:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-01-30 09:17 - 2016-01-30 09:17 - 00000000 ____D C:\Users\Responsable\AppData\Local\Red_Gate_Software_Ltd 2016-01-29 23:07 - 2016-01-29 23:07 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\ICSharpCode 2016-01-29 22:23 - 2016-01-29 22:23 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Eziriz 2016-01-29 18:44 - 2016-01-29 18:44 - 00000000 ____D C:\Users\Responsable\Documents\Zeta Resource Editor projects 2016-01-29 18:38 - 2016-01-29 18:45 - 00000000 ____D C:\Users\Responsable\AppData\Local\Zeta Resource Editor 2016-01-29 18:30 - 2016-02-17 22:37 - 00000000 ____D C:\Users\Responsable\AppData\Local\DotNet Resolver 2016-01-29 18:17 - 2016-01-29 18:17 - 00000000 ____D C:\Users\Responsable\Documents\Reflector 2016-01-28 21:54 - 2016-01-28 21:54 - 00000000 ____D C:\Users\Responsable\AppData\Local\Deployment 2016-01-27 22:25 - 2016-01-27 22:25 - 00000000 ____D C:\Users\Responsable\AppData\Local\LogMeIn 2016-01-27 22:25 - 2016-01-27 22:25 - 00000000 ____D C:\ProgramData\LogMeIn 2016-01-26 18:12 - 2016-01-26 18:12 - 00000000 ____D C:\Program Files (x86)\Yahoo! 2016-01-26 18:09 - 2016-01-26 18:08 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2016-01-25 21:03 - 2016-01-25 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BacklinkSpeed 2016-01-24 14:00 - 2016-01-24 14:00 - 00000000 ___RD C:\Sandbox 2016-01-24 13:59 - 2016-01-24 14:01 - 00001670 _____ C:\WINDOWS\Sandboxie.ini 2016-01-24 13:26 - 2016-01-24 13:26 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2016-01-24 11:19 - 2014-08-16 15:53 - 00017920 ____H C:\Users\Responsable\Desktop\Tubro_Spinner_Console.suo 2016-01-23 23:36 - 2016-01-23 23:36 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-01-23 23:36 - 2016-01-23 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-01-23 22:44 - 2016-01-23 22:45 - 00000000 ____D C:\Program Files (x86)\Resource Tuner 2016-01-23 22:33 - 2016-01-23 22:34 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\PE Explorer 2016-01-23 22:32 - 2016-01-23 22:32 - 00000000 ____D C:\WINDOWS\Nouveau dossier 2016-01-23 22:31 - 2016-01-23 22:34 - 00000000 ____D C:\Program Files (x86)\PE Explorer ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-02-22 14:27 - 2015-12-21 10:29 - 00000000 ____D C:\Users\Responsable\AppData\Local\CrashDumps 2016-02-22 14:11 - 2015-10-06 13:21 - 00001002 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-02-22 12:33 - 2015-11-26 00:24 - 01956472 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-02-22 12:33 - 2015-10-30 20:00 - 00866682 _____ C:\WINDOWS\system32\perfh00C.dat 2016-02-22 12:33 - 2015-10-30 20:00 - 00173530 _____ C:\WINDOWS\system32\perfc00C.dat 2016-02-22 12:33 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF 2016-02-22 12:28 - 2015-11-26 00:25 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-02-22 12:27 - 2015-10-30 07:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2016-02-22 12:26 - 2015-11-26 16:53 - 00000000 ____D C:\Program Files (x86)\Skillbrains 2016-02-22 10:32 - 2015-10-06 12:53 - 00000000 ____D C:\Program Files (x86)\Google 2016-02-22 10:29 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2016-02-22 09:51 - 2015-11-02 15:23 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-02-22 09:47 - 2015-12-21 16:17 - 00001537 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-02-22 09:47 - 2015-10-06 13:20 - 00001549 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-02-22 09:46 - 2015-11-26 00:09 - 00000000 ____D C:\Users\Responsable 2016-02-22 09:46 - 2013-08-22 16:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy 2016-02-22 09:41 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\AppData\Local\Adobe 2016-02-21 22:32 - 2015-11-27 20:41 - 00000000 ____D C:\Users\Responsable\Desktop\Logiciels 2016-02-21 12:09 - 2015-11-26 16:45 - 00000000 ____D C:\Users\Responsable\Desktop\Musique 2016-02-20 10:08 - 2015-12-20 15:45 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\FileZilla 2016-02-18 21:09 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Skype 2016-02-17 22:37 - 2015-11-29 18:52 - 00000000 ____D C:\Users\Responsable\Desktop\Data 2016-02-17 15:45 - 2015-11-25 18:46 - 00000000 ____D C:\Users\Responsable\AppData\Local\VirtualStore 2016-02-17 09:54 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-02-17 09:02 - 2016-01-22 16:33 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\Free Monitor for Google 2016-02-16 19:52 - 2015-11-26 17:46 - 00000000 ____D C:\Users\Responsable\Documents\Visual Studio 2015 2016-02-16 19:13 - 2015-12-20 15:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2016-02-16 19:13 - 2015-12-20 15:39 - 00000000 ____D C:\Program Files\FileZilla FTP Client 2016-02-12 21:35 - 2015-11-02 13:16 - 670926819 _____ C:\WINDOWS\MEMORY.DMP 2016-02-04 20:50 - 2015-10-06 13:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-02-01 19:07 - 2016-01-01 15:49 - 00002250 ____H C:\Users\Responsable\Documents\Default.rdp 2016-01-29 22:23 - 2015-11-27 17:47 - 00000000 ____D C:\Users\Responsable\AppData\Local\SkinSoft 2016-01-28 21:54 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\AppData\Local\Apps\2.0 2016-01-26 18:11 - 2015-10-06 13:13 - 00000000 ____D C:\ProgramData\Oracle 2016-01-26 18:09 - 2015-10-06 13:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-01-26 18:09 - 2015-10-06 13:13 - 00000000 ____D C:\Program Files (x86)\Java 2016-01-26 18:08 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\.oracle_jre_usage 2016-01-26 17:52 - 2015-11-26 00:01 - 00278104 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-01-25 20:28 - 2016-01-17 14:11 - 00000000 ____D C:\Users\Responsable\AppData\Roaming\uTorrent 2016-01-23 23:36 - 2015-11-25 18:44 - 00000000 ____D C:\Users\Responsable\AppData\Local\Skype 2016-01-23 23:36 - 2015-10-12 10:37 - 00000000 ____D C:\ProgramData\Skype 2016-01-23 22:47 - 2016-01-01 20:02 - 00000000 ____D C:\Users\Responsable\Documents\Resource Tuner 2 ==================== Fichiers à la racine de certains dossiers ======= 2015-12-01 19:05 - 2015-12-01 19:06 - 0025593 _____ () C:\Program Files (x86)\Common Files\TV11Install.log 2015-11-25 11:57 - 2015-11-25 11:59 - 39614808 ___SH (IObit ) C:\Program Files (x86)\Common Files\~jgjjttj.ibo 2016-02-22 09:48 - 2016-02-22 09:48 - 0002636 _____ () C:\Users\Responsable\AppData\Local\cookies.bin 2016-02-22 13:32 - 2016-02-22 13:43 - 0396802 ___SH () C:\Users\Responsable\AppData\Local\CSIDL_ 2016-02-22 13:32 - 2016-02-22 13:32 - 0396802 ___SH () C:\Users\Responsable\AppData\Local\CSIDL_X 2015-11-26 16:53 - 2015-11-26 16:53 - 0000003 _____ () C:\Users\Responsable\AppData\Local\updater.log 2015-11-26 16:53 - 2015-11-26 16:53 - 0000424 _____ () C:\Users\Responsable\AppData\Local\UserProducts.xml 2016-02-21 23:21 - 2016-02-21 23:21 - 0004949 _____ () C:\ProgramData\rugqgaaw.ekm Certains fichiers dans TEMP: ==================== C:\Users\Responsable\AppData\Local\Temp\0SpamBot By InterAhmet.exe C:\Users\Responsable\AppData\Local\Temp\FB_172C.tmp.exe C:\Users\Responsable\AppData\Local\Temp\FB_1A91.tmp.exe C:\Users\Responsable\AppData\Local\Temp\FB_2321.tmp.exe C:\Users\Responsable\AppData\Local\Temp\FB_3B01.tmp.exe C:\Users\Responsable\AppData\Local\Temp\FB_498.tmp.exe C:\Users\Responsable\AppData\Local\Temp\FB_A8AF.tmp.exe C:\Users\Responsable\AppData\Local\Temp\upx.exe ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement