Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x86) Version:01-05-2016 Exécuté par h (administrateur) sur H-PC (02-05-2016 17:11:24) Exécuté depuis C:\Users\h\Desktop Profils chargés: h (Profils disponibles: h) Platform: Microsoft Windows 7 Édition Intégrale (X86) Langue: Français (France) Internet Explorer Version 8 (Navigateur par défaut: FF) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe (AMD) C:\Windows\System32\atieclxx.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AEstSrv.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avpui.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) C:\Program Files\Brother\Brother Help\BrotherHelp.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (SFX TEAM) C:\Program Files\SuperCopier2\SuperCopier2.exe (Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (BitTorrent Inc.) C:\Users\h\AppData\Roaming\uTorrent\uTorrent.exe (Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.) C:\Program Files\ControlCenter4\BrCcUxSys.exe () C:\Program Files\WebcamMax\wcmmon.exe (Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Tonec Inc.) C:\Program Files\Internet Download Manager\IEMonitor.exe (BitTorrent Inc.) C:\Users\h\AppData\Roaming\uTorrent\updates\3.4.7_42300\utorrentie.exe (BitTorrent Inc.) C:\Users\h\AppData\Roaming\uTorrent\updates\3.4.7_42300\utorrentie.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Nico Mak Computing) C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing) C:\Program Files\WinZip\FAHWindow32.exe (WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [1433692 2012-08-09] (IDT, Inc.) HKLM\...\Run: [StartCCC] => c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-12-05] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKLM\...\Run: [ControlCenter4] => C:\Program Files\ControlCenter4\BrCcBoot.exe [139264 2013-05-14] (Brother Industries, Ltd.) HKLM\...\Run: [BrStsMon00] => C:\Program Files\Browny02\Brother\BrStMonW.exe [4522496 2012-12-27] (Brother Industries, Ltd.) HKLM\...\Run: [BrHelp] => C:\Program Files\Brother\Brother Help\BrotherHelp.exe [2009088 2013-01-18] (Brother Industries, Ltd.) HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [6852608 2012-04-05] (Dell Inc.) HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\Run: [SuperCopier2.exe] => C:\Program Files\SuperCopier2\SuperCopier2.exe [955392 2009-08-16] (SFX TEAM) HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\Run: [uTorrent] => C:\Users\h\AppData\Roaming\uTorrent\uTorrent.exe [1984512 2016-04-28] (BitTorrent Inc.) HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\Run: [WebcamMaxAutoRun] => C:\Program Files\WebcamMax\wcmmon.exe [1038848 2011-07-17] () HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [3931728 2015-12-12] (Tonec Inc.) HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [51662464 2016-04-08] (Skype Technologies S.A.) HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\MountPoints2: {96112e01-1aae-11e5-b0b2-c01885c43032} - F:\autorun.exe Lsa: [Notification Packages] scecli c:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2015-08-14] (Tonec Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Pas de fichier Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-11-20] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2015-12-28] ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2015-12-28] ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2015-12-28] ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.) CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0 Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4 Tcpip\..\Interfaces\{BA22A75F-6F7A-43A0-8496-38323052393F}: [DhcpNameServer] 192.168.1.1 0.0.0.0 ManualProxies: Internet Explorer: ================== BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2015-12-08] (Internet Download Manager, Tonec Inc.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-07-01] (Oracle Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2015-12-29] (AO Kaspersky Lab) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-01] (Oracle Corporation) Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\IEExt\ie_plugin.dll [2015-12-29] (AO Kaspersky Lab) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\h\AppData\Roaming\Mozilla\Firefox\Profiles\ryw9sgdk.default FF NewTab: FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_22_0_0_137.dll [2016-04-28] () FF Plugin: @divx.com/DivX Content Upload Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Content Uploader\npUpload.dll [Pas de fichier] FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation) FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation) FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-01] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-01] (Oracle Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation) FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08] FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF => non trouvé(e) FF HKLM\...\Firefox\Extensions: [light_plugin_D772DC8D6FAF43A29B25C4EBAA5AD1DE@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox FF Extension: Kaspersky Protection - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\FFExt\light_plugin_firefox [2016-02-29] FF HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi FF Extension: IDM integration - C:\Program Files\Internet Download Manager\idmmzcc2.xpi [2015-11-09] FF HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi FF HKU\S-1-5-21-989404677-1115508600-2588192600-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\h\AppData\Roaming\IDM\idmmzcc5 FF Extension: IDM CC - C:\Users\h\AppData\Roaming\IDM\idmmzcc5 [2016-05-02] [non signé] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxp://www.google.dz/" CHR Profile: C:\Users\h\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Kaspersky Protection) - C:\Users\h\AppData\Local\Google\Chrome\User Data\Default\Extensions\eahebamiopdhefndnmappcihfajigkka [2015-12-28] CHR Extension: (IDM Integration Module) - C:\Users\h\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2016-04-19] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\h\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03] CHR Extension: (Facebook Font Changer) - C:\Users\h\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkmjdncgblppfakdnmcbljlngaodoaf [2015-07-20] CHR HKLM\...\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08] CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2015-12-10] ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AVP16.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe [194000 2015-12-29] (Kaspersky Lab ZAO) R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [282112 2012-10-26] (Brother Industries, Ltd.) [Fichier non signé] R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [279024 2014-04-09] (Intel Corporation) S3 Lenovo EasyPlus Hotspot; C:\Program Files\Common Files\LENOVO\easyplussdk\bin\EPHotspot.exe [505088 2015-01-15] (Lenovo) S3 ShareItSvc; C:\Program Files\Lenovo\SHAREit\Shareit.Service.exe [31704 2016-03-31] (SHAREit Technologies Co.Ltd) R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [303186 2012-08-09] (IDT, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation) R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [5620224 2012-04-05] (Dell Inc.) [Fichier non signé] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [147112 2012-03-05] (Broadcom Corporation.) R3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18496 2012-04-05] (Broadcom Corporation) R3 BcmVWL; C:\Windows\System32\DRIVERS\bcmvwl32.sys [17728 2012-03-16] (Broadcom Corporation) S3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [521768 2012-03-05] (Broadcom Corporation.) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [201912 2015-07-06] (Kaspersky Lab ZAO) R3 intelkmd; C:\Windows\System32\DRIVERS\igdpmd32.sys [10542080 2011-03-25] (Intel Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [153784 2015-06-22] (Kaspersky Lab ZAO) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [46776 2015-06-06] (Kaspersky Lab ZAO) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [58224 2015-06-27] (Kaspersky Lab ZAO) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [66976 2016-02-29] (AO Kaspersky Lab) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [147328 2015-12-29] (AO Kaspersky Lab) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [44728 2015-12-29] (AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [776088 2016-02-29] (AO Kaspersky Lab) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [33976 2015-06-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [37048 2015-06-06] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [38072 2015-06-07] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [39304 2015-12-29] (AO Kaspersky Lab) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54328 2015-06-11] (Kaspersky Lab ZAO) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [87736 2015-06-16] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [156856 2015-06-23] (Kaspersky Lab ZAO) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project) S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2015-06-10] (Apple, Inc.) [Fichier non signé] R2 WCMVCAM; C:\Windows\System32\DRIVERS\wcmvcam.sys [1068216 2012-04-15] (Windows (R) Win 7 DDK provider) S0 PxHelp20; System32\Drivers\PxHelp20.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-05-02 17:11 - 2016-05-02 17:11 - 00017798 _____ C:\Users\h\Desktop\FRST.txt 2016-05-02 17:11 - 2016-05-02 17:11 - 00000000 ____D C:\FRST 2016-05-02 17:09 - 2016-05-02 17:09 - 01728000 _____ (Farbar) C:\Users\h\Desktop\FRST.exe 2016-05-02 16:57 - 2016-05-02 16:57 - 00000000 ____D C:\Users\h\AppData\Local\Nico Mak Computing 2016-05-02 16:53 - 2016-05-02 16:53 - 00008242 _____ C:\Users\h\Desktop\ZHPCleaner.txt 2016-05-02 16:44 - 2016-05-02 16:58 - 00000822 _____ C:\Users\h\Desktop\ZHPCleaner.lnk 2016-05-02 16:43 - 2016-05-02 16:43 - 02252288 _____ C:\Users\h\Desktop\ZHPCleaner.exe 2016-05-02 15:11 - 2016-05-02 15:11 - 00000000 ____D C:\Users\Public\Documents\PC Faster 2016-05-02 14:43 - 2016-05-02 14:49 - 00000000 ____D C:\AdwCleaner 2016-05-02 04:07 - 2016-05-02 17:04 - 00000000 ____D C:\Users\h\AppData\Roaming\ZHP 2016-05-02 03:21 - 2016-05-02 03:23 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-05-02 03:08 - 2016-05-02 03:08 - 00001060 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-05-02 03:08 - 2016-05-02 03:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-05-02 03:08 - 2016-03-10 14:09 - 00053120 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-05-02 03:08 - 2016-03-10 14:08 - 00126336 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-05-02 03:08 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-05-02 02:59 - 2016-05-02 03:00 - 00412432 _____ C:\Windows\system32\FNTCACHE.DAT 2016-05-02 02:48 - 2016-05-02 03:08 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware 2016-05-02 02:48 - 2016-05-02 02:48 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-05-02 02:47 - 2016-05-02 03:07 - 00000000 ____D C:\Users\h\Desktop\Nouveau dossier (5) 2016-05-02 02:47 - 2016-05-02 02:47 - 00108824 _____ C:\Users\h\AppData\Local\GDIPFONTCACHEV1.DAT 2016-05-01 16:37 - 2016-05-02 16:58 - 00000000 ____D C:\Users\h\Desktop\hghghghgh 2016-04-30 23:13 - 2016-04-30 23:13 - 00001024 _____ C:\Users\Public\Desktop\VLC media player.lnk 2016-04-30 23:13 - 2016-04-30 23:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2016-04-30 22:46 - 2016-05-02 14:49 - 00001019 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-04-30 22:46 - 2016-05-02 14:49 - 00001007 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-04-30 22:46 - 2016-04-30 22:46 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2016-04-28 20:03 - 2016-04-28 20:03 - 00121176 _____ C:\Users\h\Downloads\game-of-thrones-sixth-season_arabic-1321380.zip 2016-04-28 09:33 - 2016-04-28 09:33 - 00000000 ____D C:\Users\h\AppData\Local\SHAREit 2016-04-28 09:33 - 2016-04-28 09:33 - 00000000 ____D C:\ProgramData\Lenovo 2016-04-28 09:32 - 2016-04-28 09:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LenovoSHAREit 2016-04-28 08:57 - 2016-04-28 09:32 - 00001064 _____ C:\Users\Public\Desktop\SHAREit.lnk 2016-04-28 08:57 - 2016-04-28 08:57 - 00000000 ____D C:\Program Files\Common Files\LENOVO 2016-04-28 07:28 - 2016-05-02 17:06 - 00000000 ____D C:\Users\h\AppData\LocalLow\uTorrent 2016-04-20 16:48 - 2016-05-02 03:40 - 00000290 __RSH C:\ProgramData\ntuser.pol 2016-04-20 16:41 - 2016-04-20 17:19 - 00000000 ____D C:\Users\h\AppData\Roaming\Opera Software 2016-04-20 16:41 - 2016-04-20 17:19 - 00000000 ____D C:\Users\h\AppData\Local\Opera Software 2016-04-20 16:36 - 2016-04-20 17:20 - 00000000 ____D C:\Program Files\Opera 2016-04-17 23:50 - 2016-04-17 23:55 - 26409340 _____ C:\Users\h\Downloads\Kabylie News - Prise de parole d'un Oranais.mp4 2016-04-15 04:12 - 2016-04-15 04:12 - 00000641 _____ C:\Users\h\Desktop\h - Raccourci.lnk 2016-04-12 04:59 - 2016-04-12 04:59 - 00008971 _____ C:\Users\h\Downloads\the-big-bang-theory-ninth-season_arabic-1310587.zip 2016-04-12 01:15 - 2016-04-12 01:16 - 03041914 _____ C:\Users\h\Downloads\Tizi Ouzou ⵣ(1).mp4 2016-04-09 21:11 - 2016-04-09 21:11 - 00001176 _____ C:\Users\h\Desktop\Counter-Strike_Source.exe - Raccourci.lnk 2016-04-09 02:37 - 2016-04-28 20:03 - 00000000 ____D C:\Users\h\Desktop\Nouveau dossier (4) 2016-04-08 15:25 - 2016-04-08 15:25 - 00000800 _____ C:\Users\h\Desktop\Midou med - Raccourci (2).lnk 2016-04-04 01:12 - 2016-04-04 01:12 - 00000000 ____D C:\Users\h\Desktop\Nouveau dossier (3) 2016-04-02 15:34 - 2016-04-02 15:34 - 00000000 ____D C:\Users\h\AppData\Roaming\SmartSteamEmu 2016-04-02 15:34 - 2016-04-02 15:34 - 00000000 ____D C:\Users\h\AppData\Roaming\BADLAND 2016-04-02 15:33 - 2016-04-02 15:33 - 00000000 ____D C:\ProgramData\Package Cache 2016-04-02 15:32 - 2016-04-02 15:32 - 00000000 ____D C:\Windows\system32\directx ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-05-02 17:11 - 2015-06-21 14:54 - 00000000 ____D C:\Users\h\AppData\Roaming\uTorrent 2016-05-02 17:06 - 2015-10-29 17:06 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-05-02 17:06 - 2015-10-04 11:25 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2016-05-02 17:06 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-05-02 17:05 - 2015-06-21 01:57 - 00000000 ____D C:\Users\h\AppData\Roaming\DMCache 2016-05-02 17:04 - 2009-07-14 06:34 - 00017136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-05-02 17:04 - 2009-07-14 06:34 - 00017136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-05-02 17:00 - 2015-06-20 14:19 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-05-02 16:22 - 2015-10-29 17:06 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-05-02 15:47 - 2015-09-24 00:22 - 00000000 ____D C:\Users\h\AppData\Roaming\Skype 2016-05-02 14:49 - 2015-10-29 17:10 - 00001256 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-05-02 14:49 - 2015-06-20 13:45 - 00001148 _____ C:\Users\h\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-05-02 03:50 - 2015-08-21 20:23 - 00000000 ____D C:\Users\h\Downloads\torrent fichier 2016-05-02 03:40 - 2009-07-14 04:37 - 00000000 __RSD C:\Windows\Media 2016-05-02 03:01 - 2015-09-23 01:00 - 00000000 ___SD C:\Users\h\AppData\LocalLow\Temp 2016-05-02 03:00 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\inf 2016-05-02 02:46 - 2015-09-07 00:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mask My IP 2016-05-02 02:46 - 2015-06-20 20:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Keyboard 2016-05-01 22:29 - 2015-12-15 23:53 - 00000000 ____D C:\Users\h\AppData\Roaming\IDM 2016-05-01 22:26 - 2015-10-26 12:18 - 00000000 ____D C:\Users\h\AppData\Roaming\vlc 2016-05-01 20:21 - 2015-06-21 01:57 - 00000000 ____D C:\Users\h\Downloads\Compressed 2016-04-30 22:57 - 2016-01-07 00:16 - 00000000 ____D C:\Program Files\Mozilla Firefox 2016-04-30 22:12 - 2015-06-20 14:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2016-04-30 22:12 - 2015-06-20 14:18 - 00000000 ____D C:\Program Files\DivX 2016-04-28 14:49 - 2015-06-20 13:48 - 01660386 _____ C:\Windows\system32\PerfStringBackup.INI 2016-04-28 14:49 - 2009-07-14 10:39 - 00734756 _____ C:\Windows\system32\perfh00C.dat 2016-04-28 14:49 - 2009-07-14 10:39 - 00147678 _____ C:\Windows\system32\perfc00C.dat 2016-04-28 08:58 - 2015-10-27 09:49 - 00000000 ____D C:\Users\h\AppData\Local\Lenovo 2016-04-28 08:50 - 2015-10-27 09:48 - 00000000 ____D C:\Program Files\Lenovo 2016-04-28 04:01 - 2015-06-20 14:19 - 00800448 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2016-04-28 04:01 - 2015-06-20 14:19 - 00143040 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2016-04-24 20:16 - 2015-06-30 02:19 - 00015798 _____ C:\Windows\BRRBCOM.INI 2016-04-24 20:06 - 2015-11-20 00:40 - 00000000 ____D C:\Users\h\Documents\Dossier Echanges Bluetooth 2016-04-23 06:37 - 2009-07-14 06:53 - 00032482 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-04-23 06:32 - 2015-10-22 09:59 - 00262144 _____ C:\Windows\system32\config\elam 2016-04-23 04:14 - 2015-12-28 22:24 - 00002394 _____ C:\Users\h\Desktop\Protection bancaire.lnk 2016-04-21 21:28 - 2015-09-24 00:22 - 00000000 ___RD C:\Program Files\Skype 2016-04-21 21:28 - 2015-09-24 00:21 - 00000000 ____D C:\ProgramData\Skype 2016-04-20 16:47 - 2015-06-20 16:27 - 00000000 ____D C:\Users\h\AppData\Local\Adobe 2016-04-20 16:38 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\GroupPolicy ==================== Fichiers à la racine de certains dossiers ======= 2015-08-22 02:46 - 2015-08-22 02:46 - 0000056 _____ () C:\Users\h\AppData\Roaming\coreavc.ini Fichiers à déplacer ou supprimer: ==================== C:\ProgramData\C__Users_h_Downloads_Programs_Auto Hide IP_Crack staraziz_AutoHideIP.exe Certains fichiers dans TEMP: ==================== C:\Users\h\AppData\Local\Temp\libeay32.dll C:\Users\h\AppData\Local\Temp\msvcr120.dll C:\Users\h\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2016-04-28 07:30 ==================== Fin de FRST.txt ============================