Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:05-06-2016 Exécuté par Frederic (administrateur) sur R700V (05-06-2016 11:09:42) Exécuté depuis C:\Users\Frederic\Downloads Profils chargés: Frederic (Profils disponibles: Frederic) Platform: Windows 8.1 (Update) (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (PacketVideo) C:\Program Files (x86)\Serveur Media\twonkymediaserverwatchdog.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\WINDOWS\System32\alg.exe (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe () C:\Program Files (x86)\Serveur Media\twonkymediaserver.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\WINDOWS\System32\SkyDrive.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\WINDOWS\System32\SettingSyncHost.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe (PacketVideo) C:\Program Files (x86)\Serveur Media\twonkymediaserverconfig.exe (Microsoft Corporation) C:\WINDOWS\System32\GWX\GWX.exe (Bose Corporation) C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.4.9926.18228_x64__8wekyb3d8bbwe\glcnd.exe (Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 5530 series\Bin\HPNetworkCommunicatorCom.exe (Intel(R) Corporation) C:\Program Files\Intel\BCA\pabeSvc64.exe (McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe (McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe () C:\Program Files\Intel Security\True Key\Application\truekey.exe () C:\Program Files\Intel Security\True Key\Application\truekey.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.79\nacl64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.79\nacl64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2462536 2014-10-04] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [CheckUpdate] => fmaj5.exe HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1989920 2013-08-26] (Wondershare) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [839648 2016-03-10] (DivX, LLC) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) HKLM-x32\...\Run: [SoundTouch Music Server] => C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe [1133568 2016-03-01] (Bose Corporation) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXBannerAdPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXAccountViewPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXAccountViewPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXDCFServicesPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXDCFServicesPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXLicenseWriterPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXLicenseWriterPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXDownloadManagerPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXMediaManagerPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXMediaManagerV2Plugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXMediaManagerV2Plugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXPlayerPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXPlaybackServicesPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXPlaybackServicesPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXDevicePanePlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXDevicePanePlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXLibraryPanePlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXLibraryPanePlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXTicketManagerPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXTicketManagerPlugin.dll",DllRegisterServer HKLM-x32\...\RunOnce: [B Register C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXDFXAudioPlugin.dll] => "C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0 HKLM\...\Policies\Explorer: [HideSCAHealth] 0 HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Run: [RemoTerm.exe] => C:\Program Files (x86)\Common Files\PCTV Systems\RemoTerm\RemoTerm.exe [227200 2012-06-06] (PCTV Systems S.à r.l.) HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Run: [HP ENVY 5530 series (NET)] => C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP) HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Run: [Google Update] => C:\Users\Frederic\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-31] (Google Inc.) HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd) HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Run: [Dropbox Update] => C:\Users\Frederic\AppData\Local\Dropbox\Update\DropboxUpdate.exe [136048 2015-10-25] (Dropbox, Inc.) HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50615936 2016-01-19] (Skype Technologies S.A.) HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Run: [HP ENVY 5530 series (NET) #2] => C:\Program Files\HP\HP ENVY 5530 series\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP) HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Run: [OfficeSyncProcess] => D:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [721504 2015-09-02] (Microsoft Corporation) HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Policies\Explorer: [TaskbarNoNotification] 0 HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Policies\Explorer: [HideSCAHealth] 0 HKU\S-1-5-21-1287918758-1629660500-816410286-1001\...\Winlogon: [Shell] C:\WINDOWS\explorer.exe [2757616 2016-02-09] (Microsoft Corporation) <==== ATTENTION AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [176904 2015-08-25] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [155792 2015-08-25] (NVIDIA Corporation) AppInit_DLLs-x32: c:\progra~2\amazon\amazon~1\\amazon~3.dll => Pas de fichier AppInit_DLLs-x32: , C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [155792 2015-08-25] (NVIDIA Corporation) Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter ShellIconOverlayIdentifiers: [ AWCOverlayIconFailed] -> {807B3DE6-04E1-41CD-BE17-79259C6F287E} => C:\Program Files\Le Cloud d'Orange\WindowsCloudShellExtensions64.dll [2015-11-17] (Orange) ShellIconOverlayIdentifiers: [ AWCOverlayIconIgnored] -> {78E727AC-5F74-44D4-AB7B-1AF593CAB71A} => C:\Program Files\Le Cloud d'Orange\WindowsCloudShellExtensions64.dll [2015-11-17] (Orange) ShellIconOverlayIdentifiers: [ AWCOverlayIconUploaded] -> {6AB3E22E-6F5C-4D4A-9F00-76BB29BAEAEF} => C:\Program Files\Le Cloud d'Orange\WindowsCloudShellExtensions64.dll [2015-11-17] (Orange) ShellIconOverlayIdentifiers: [ AWCOverlayIconUploading] -> {5A062BD3-C231-4E7A-8782-D83B74BC2B08} => C:\Program Files\Le Cloud d'Orange\WindowsCloudShellExtensions64.dll [2015-11-17] (Orange) ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Frederic\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Frederic\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Frederic\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Frederic\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Frederic\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Frederic\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Frederic\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Frederic\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [KAVOverlayIcon] -> {014F27E2-6D75-4E42-A0E9-2A2C68498AFA} => Pas de fichier ShellIconOverlayIdentifiers-x32: [KAVOverlayIcon] -> {014F27E2-6D75-4E42-A0E9-2A2C68498AFA} => Pas de fichier Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Agent Serveur Média.lnk [2016-04-25] ShortcutTarget: Agent Serveur Média.lnk -> C:\Program Files (x86)\Serveur Media\twonkymediaserverconfig.exe (PacketVideo) Startup: C:\Users\Frederic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-03-11] ShortcutTarget: Dropbox.lnk -> C:\Users\Frederic\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Frederic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 - Capture d’écran et lancement.lnk [2014-02-10] ShortcutTarget: OneNote 2010 - Capture d’écran et lancement.lnk -> D:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{74359812-8267-4597-8DB5-6E14AB5E0138}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_17¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCyDyByCtN1L2XzutAtFtBtCtFtCtFtAtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyD0B0EyByEtCtCyCtGyC0B0FtBtG0FyB0B0EtGyDtBtByEtGtC0D0A0BtDyByCtCyEyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzzzyyD%26cr%3D623820031%26a%3Dwncy_ir_16_17%26os_ver%3D6.3%26os%3DWindows%2B8.1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_17¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCyDyByCtN1L2XzutAtFtBtCtFtCtFtAtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyD0B0EyByEtCtCyCtGyC0B0FtBtG0FyB0B0EtGyDtBtByEtGtC0D0A0BtDyByCtCyEyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzzzyyD%26cr%3D623820031%26a%3Dwncy_ir_16_17%26os_ver%3D6.3%26os%3DWindows%2B8.1 HKU\S-1-5-21-1287918758-1629660500-816410286-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.fr.msn.com/ HKU\S-1-5-21-1287918758-1629660500-816410286-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_17¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCyDyByCtN1L2XzutAtFtBtCtFtCtFtAtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyD0B0EyByEtCtCyCtGyC0B0FtBtG0FyB0B0EtGyDtBtByEtGtC0D0A0BtDyByCtCyEyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzzzyyD%26cr%3D623820031%26a%3Dwncy_ir_16_17%26os_ver%3D6.3%26os%3DWindows%2B8.1 SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCyDyByCtN1L2XzutAtFtBtCtFtCtFtAtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyD0B0EyByEtCtCyCtGyC0B0FtBtG0FyB0B0EtGyDtBtByEtGtC0D0A0BtDyByCtCyEyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzzzyyD%26cr%3D623820031%26a%3Dwncy_ir_16_17%26os_ver%3D6.3%26os%3DWindows%2B8.1&p={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCyDyByCtN1L2XzutAtFtBtCtFtCtFtAtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyD0B0EyByEtCtCyCtGyC0B0FtBtG0FyB0B0EtGyDtBtByEtGtC0D0A0BtDyByCtCyEyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzzzyyD%26cr%3D623820031%26a%3Dwncy_ir_16_17%26os_ver%3D6.3%26os%3DWindows%2B8.1&p={searchTerms} SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = SearchScopes: HKU\S-1-5-21-1287918758-1629660500-816410286-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCyDyByCtN1L2XzutAtFtBtCtFtCtFtAtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyD0B0EyByEtCtCyCtGyC0B0FtBtG0FyB0B0EtGyDtBtByEtGtC0D0A0BtDyByCtCyEyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzzzyyD%26cr%3D623820031%26a%3Dwncy_ir_16_17%26os_ver%3D6.3%26os%3DWindows%2B8.1&p={searchTerms} SearchScopes: HKU\S-1-5-21-1287918758-1629660500-816410286-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_17¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCyDyByCtN1L2XzutAtFtBtCtFtCtFtAtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyD0B0EyByEtCtCyCtGyC0B0FtBtG0FyB0B0EtGyDtBtByEtGtC0D0A0BtDyByCtCyEyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzzzyyD%26cr%3D623820031%26a%3Dwncy_ir_16_17%26os_ver%3D6.3%26os%3DWindows%2B8.1&p={searchTerms} BHO: Pas de nom -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> Pas de fichier BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\x64\IEExt\ie_plugin.dll [2016-03-21] (Kaspersky Lab ZAO) BHO: unisaales -> {5ee8b2dc-2ee0-44cd-9d7e-e857b12fb35e} -> Pas de fichier BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-12-04] (Oracle Corporation) BHO: youtubeadblocker -> {88b74cb3-bdad-4cb4-ab66-762ed6e30e85} -> Pas de fichier BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\x64\IEExt\ie_plugin.dll [2016-03-21] (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\x64\IEExt\ie_plugin.dll [2016-03-21] (Kaspersky Lab ZAO) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation) BHO: unniisuales -> {b3a10ec9-8528-4b0e-9be3-7345bae1d120} -> Pas de fichier BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Pas de nom -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> Pas de fichier BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-12-04] (Oracle Corporation) BHO: Pas de nom -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> Pas de fichier BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-05-17] (Intel Security) BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2016-03-21] (Kaspersky Lab ZAO) BHO-x32: Pas de nom -> {5ee8b2dc-2ee0-44cd-9d7e-e857b12fb35e} -> Pas de fichier BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> D:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-11-15] (Oracle Corporation) BHO-x32: Pas de nom -> {88b74cb3-bdad-4cb4-ab66-762ed6e30e85} -> Pas de fichier BHO-x32: Pas de nom -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> Pas de fichier BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2016-03-21] (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll [2016-03-21] (Kaspersky Lab ZAO) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation) BHO-x32: Pas de nom -> {b3a10ec9-8528-4b0e-9be3-7345bae1d120} -> Pas de fichier BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-15] (Oracle Corporation) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-05-17] (Intel Security) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Frederic\AppData\Roaming\Mozilla\Firefox\Profiles\f4yml2x6.default FF SelectedSearchEngine: Search Provided by Yahoo FF DefaultSearchEngine: Search Provided by Yahoo FF Homepage: hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_17¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCyDyByCtN1L2XzutAtFtBtCtFtCtFtAtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyD0B0EyByEtCtCyCtGyC0B0FtBtG0FyB0B0EtGyDtBtByEtGtC0D0A0BtDyByCtCyEyEyD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCzzzyyD%26cr%3D623820031%26a%3Dwncy_ir_16_17%26os_ver%3D6.3%26os%3DWindows%2B8.1 FF NewTab: about:newtab FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2016-02-22] () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-04] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-12-04] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2016-02-22] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2016-03-04] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-15] (Oracle Corporation) FF Plugin-x32: @kaspersky.com/content_blocker_663BE8 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\content_blocker@kaspersky.com [2016-05-24] () FF Plugin-x32: @kaspersky.com/online_banking_08806E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\online_banking@kaspersky.com [2016-05-24] () FF Plugin-x32: @kaspersky.com/virtual_keyboard_074028 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2016-05-24] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> D:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> D:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @samsungsmartcam.com/npwViewer -> C:\Program Files (x86)\Samsung\SmartCam\npwViewer_lib.dll [2015-11-17] (Samsung Techwin) FF Plugin-x32: @samsungsmartcam.com/npwViewer_turn -> C:\Program Files (x86)\Samsung\SmartCam\npwViewer_lib_turn.dll [2015-11-17] (Samsung Techwin) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=1.1.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-27] (Adobe Systems Inc.) FF Plugin-x32: samsungtechwin.com/SmartCamFinder -> C:\Program Files (x86)\Samsung\SmartCam\npSmartCamFinder.dll [2015-09-24] (Samsung Techwin) FF Plugin HKU\S-1-5-21-1287918758-1629660500-816410286-1001: @samsungsmartcam.com/npwViewer -> C:\Program Files (x86)\Samsung\SmartCam\npwViewer_lib.dll [2015-11-17] (Samsung Techwin) FF Plugin HKU\S-1-5-21-1287918758-1629660500-816410286-1001: @samsungsmartcam.com/npwViewer_turn -> C:\Program Files (x86)\Samsung\SmartCam\npwViewer_lib_turn.dll [2015-11-17] (Samsung Techwin) FF Plugin HKU\S-1-5-21-1287918758-1629660500-816410286-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Frederic\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.) FF Plugin HKU\S-1-5-21-1287918758-1629660500-816410286-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Frederic\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.) FF Plugin HKU\S-1-5-21-1287918758-1629660500-816410286-1001: samsungtechwin.com/SmartCamFinder -> C:\Program Files (x86)\Samsung\SmartCam\npSmartCamFinder.dll [2015-09-24] (Samsung Techwin) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-05-27] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Frederic\AppData\Roaming\Mozilla\Firefox\Profiles\f4yml2x6.default\searchplugins\Search Provided by Yahoo.xml [2016-04-25] FF Extension: Pas de nom - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\content_blocker@kaspersky.com [non trouvé(e)] FF Extension: Pas de nom - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\online_banking@kaspersky.com [non trouvé(e)] FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25] FF HKLM-x32\...\Firefox\Extensions: [content_blocker_663BE8@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\content_blocker@kaspersky.com [2016-05-24] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard_074028@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2016-05-24] FF HKLM-x32\...\Firefox\Extensions: [online_banking_08806E@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\FFExt\online_banking@kaspersky.com [2016-05-24] StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HomePage: Default -> hxxp://taplika.com/?f=1&a=tlk_cmi_15_07_ch&cd=2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCtCtAyDtN1L2XzutAtFyBtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0B0EtCtAtDyB0EtGyBtD0CyCtG0Ezy0CyDtGtByCtCyEtGtCzyzy0C0A0BzyyD0AtByCzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2Q&cr=1296608695&ir= CHR StartupUrls: Default -> "hxxp://taplika.com/?f=7&a=tlk_cmi_15_07_ch&cd=2XzuyEtN2Y1L1QzuyCzzyD0DyEtAzy0CtDyDzz0A0FtByB0DtN0D0Tzu0StCtCtAyDtN1L2XzutAtFyBtFtBtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0B0EtCtAtDyB0EtGyBtD0CyCtG0Ezy0CyDtGtByCtCyEtGtCzyzy0C0A0BzyyD0AtByCzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0B0AtC0D0BtA0DtGtA0FzytBtGyE0FtAtCtG0AyE0CzztG0FtA0DyByEzyyDtA0Czy0C0E2Q&cr=1296608695&ir=" CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms} CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms} CHR Profile: C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-19] CHR Extension: (Google Docs) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-19] CHR Extension: (Google Drive) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23] CHR Extension: (YouTube) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-19] CHR Extension: (Adblock Plus) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-06-01] CHR Extension: (Recherche Google) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29] CHR Extension: (Google Play Musique) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2016-05-26] CHR Extension: (Google Docs hors connexion) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-06] CHR Extension: (Gmail) - C:\Users\Frederic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-19] CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-1287918758-1629660500-816410286-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25] CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S2 0308481465116414mcinstcleanup; C:\WINDOWS\TEMP\030848~1.EXE [883024 2015-05-04] (McAfee, Inc.) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1074448 2016-04-14] (AVG Technologies CZ, s.r.o.) R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe [194000 2015-06-29] (Kaspersky Lab ZAO) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation) R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [388968 2016-03-29] (Digital Wave Ltd.) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2014-10-04] (NVIDIA Corporation) S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [157392 2016-05-06] (McAfee, Inc.) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation) R2 IntelBCAsvc; C:\Program Files\Intel\BCA\pabeSvc64.exe [3020440 2015-11-25] (Intel(R) Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes) S3 Microsoft SharePoint Workspace Audit Service; D:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1795912 2014-10-04] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19439944 2014-10-04] (NVIDIA Corporation) R2 Serveur Média; C:\Program Files (x86)\Serveur Media\twonkymediaserverwatchdog.exe [501336 2010-12-14] (PacketVideo) R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [878904 2016-05-16] (McAfee, Inc.) R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [15736 2016-05-16] (McAfee, Inc.) R2 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2016-05-16] (McAfee, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation) S2 fizywiqu; C:\Users\Frederic\AppData\Roaming\VOPackage\nsvF614.tmpfs [X] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 azvusb; C:\Windows\System32\drivers\azvusb.sys [54784 2009-08-24] (AzureWave Technologies, Inc.) R3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [132608 2015-01-30] (Microsoft Corporation) R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-10-15] (Motorola Solutions, Inc.) R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-06-29] (Kaspersky Lab UK Ltd) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-10-05] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2016-03-21] (Kaspersky Lab ZAO) R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [64368 2016-05-26] (Kaspersky Lab ZAO) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [159960 2015-06-29] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [238000 2016-05-24] (AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [834992 2016-05-24] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [49240 2016-05-24] (AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [49008 2016-03-21] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [48504 2016-03-21] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [24944 2015-06-29] (Kaspersky Lab ZAO) R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [77680 2016-03-21] (Kaspersky Lab ZAO) R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [89272 2016-03-21] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [190648 2015-10-06] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation) S3 mod7700; C:\Windows\system32\DRIVERS\mod7700.sys [1077840 2010-11-19] (DiBcom SA) S3 MODRC; C:\Windows\System32\drivers\modrc.sys [24272 2010-11-19] (DiBcom S.A.) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-08-31] (Intel Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19272 2014-10-04] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation) R3 Sftfs; C:\Windows\system32\DRIVERS\Sftfswin7.sys [767648 2014-10-08] (Microsoft Corporation) R3 Sftplay; C:\Windows\system32\DRIVERS\Sftplaywin7.sys [273576 2014-10-08] (Microsoft Corporation) R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29864 2014-10-08] (Microsoft Corporation) R3 Sftvol; C:\Windows\system32\DRIVERS\Sftvolwin7.sys [23208 2014-10-08] (Microsoft Corporation) S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-25] (Microsoft Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation) U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X] S1 qbthxkix; \??\C:\WINDOWS\system32\drivers\qbthxkix.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-06-05 11:09 - 2016-06-05 11:09 - 00043723 _____ C:\Users\Frederic\Downloads\FRST.txt 2016-06-05 11:09 - 2016-06-05 11:09 - 00000000 ____D C:\FRST 2016-06-05 11:08 - 2016-06-05 11:08 - 02384384 _____ (Farbar) C:\Users\Frederic\Downloads\FRST64.exe 2016-06-05 10:51 - 2016-06-05 10:38 - 00000030 _____ C:\AVScanner.ini 2016-06-05 10:49 - 2016-06-05 10:55 - 00000000 ____D C:\Users\Frederic\AppData\Local\tkdata 2016-06-05 10:48 - 2016-06-05 10:48 - 00000000 ____D C:\ProgramData\TrueKey 2016-06-05 10:48 - 2016-06-05 10:48 - 00000000 ____D C:\Program Files\Common Files\Intel 2016-06-05 10:47 - 2016-06-05 10:47 - 00001212 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Key.lnk 2016-06-05 10:47 - 2016-06-05 10:47 - 00000000 ____D C:\Program Files\Intel Security 2016-06-05 10:46 - 2016-06-05 10:46 - 00000000 ____D C:\Program Files\Common Files\McAfee 2016-06-05 10:46 - 2016-06-05 10:46 - 00000000 ____D C:\Program Files\Common Files\AV 2016-06-05 10:46 - 2016-06-05 10:46 - 00000000 ____D C:\Program Files (x86)\McAfee 2016-06-05 10:43 - 2016-06-05 10:43 - 00031003 _____ C:\Users\Frederic\Downloads\IR-AR-2015-16570243797753.pdf 2016-06-05 10:38 - 2016-06-05 10:46 - 00000000 ____D C:\ProgramData\McAfee 2016-06-05 10:37 - 2016-06-05 10:49 - 00000000 ____D C:\Program Files\TrueKey 2016-06-05 08:15 - 2016-06-05 08:15 - 00000000 ____D C:\Users\Frederic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-05-29 10:12 - 2016-05-29 10:12 - 00342121 _____ C:\Users\Frederic\Downloads\Affiche Cassin'wood Manon Delrio ok (2).pptx 2016-05-27 07:58 - 2016-05-27 08:02 - 00000000 ____D C:\Users\Frederic\Desktop\photo fraikin 2016-05-27 06:44 - 2016-05-27 06:44 - 03767117 _____ C:\Users\Frederic\Downloads\PROJET ERASMUS+ ANNEE 2015-2016.pptx 2016-05-26 17:05 - 2016-05-26 17:05 - 00028605 _____ C:\Users\Frederic\Downloads\LISTE ELEVES DNL 15-16 (6).xlsx 2016-05-24 15:36 - 2016-05-24 15:36 - 00487136 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-05-19 22:26 - 2016-05-19 22:26 - 00013804 _____ C:\Users\Frederic\Downloads\tableau de régie (3).xlsx 2016-05-19 22:25 - 2016-05-19 22:25 - 00010655 _____ C:\Users\Frederic\Downloads\NOTE DNL 20% JUIN 2016.xlsx 2016-05-18 22:31 - 2016-05-18 22:31 - 00597037 _____ C:\Users\Frederic\Downloads\PDF-Page_24-edition-de-metz-vallee-de-l-orne_20160518.pdf 2016-05-18 22:31 - 2016-05-18 22:31 - 00597037 _____ C:\Users\Frederic\Downloads\PDF-Page_24-edition-de-metz-vallee-de-l-orne_20160518 (1).pdf 2016-05-17 16:33 - 2016-05-17 16:33 - 00034304 _____ C:\Users\Frederic\Downloads\Liste des professeurs absents 16 05.xls 2016-05-17 16:33 - 2016-05-17 16:33 - 00034304 _____ C:\Users\Frederic\Downloads\Liste des professeurs absents 16 05 (1).xls 2016-05-12 18:42 - 2016-05-12 18:42 - 00750242 _____ C:\Users\Frederic\Downloads\tarif-massages-2014.pdf 2016-05-11 06:57 - 2016-04-22 22:54 - 25816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-05-11 06:57 - 2016-04-22 22:06 - 20349952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-05-11 06:57 - 2016-04-22 21:19 - 15414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-05-11 06:56 - 2016-04-22 22:15 - 00571904 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2016-05-11 06:56 - 2016-04-22 22:14 - 02893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-05-11 06:56 - 2016-04-22 22:08 - 06052864 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-05-11 06:56 - 2016-04-22 22:00 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2016-05-11 06:56 - 2016-04-22 21:35 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2016-05-11 06:56 - 2016-04-22 21:29 - 02285568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-05-11 06:56 - 2016-04-22 21:24 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2016-05-11 06:56 - 2016-04-22 21:23 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2016-05-11 06:56 - 2016-04-22 21:17 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2016-05-11 06:56 - 2016-04-22 21:14 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-05-11 06:56 - 2016-04-22 21:14 - 00725504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2016-05-11 06:56 - 2016-04-22 21:14 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2016-05-11 06:56 - 2016-04-22 21:12 - 02131968 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2016-05-11 06:56 - 2016-04-22 20:58 - 04611072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-05-11 06:56 - 2016-04-22 20:58 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2016-05-11 06:56 - 2016-04-22 20:54 - 13811200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-05-11 06:56 - 2016-04-22 20:53 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2016-05-11 06:56 - 2016-04-22 20:52 - 02596864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-05-11 06:56 - 2016-04-22 20:52 - 00693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-05-11 06:56 - 2016-04-22 20:52 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2016-05-11 06:56 - 2016-04-22 20:51 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2016-05-11 06:56 - 2016-04-22 20:40 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-05-11 06:56 - 2016-04-22 20:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2016-05-11 06:56 - 2016-04-22 20:27 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-05-11 06:56 - 2016-04-22 20:24 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-05-11 06:56 - 2016-04-22 20:23 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2016-05-11 06:55 - 2016-04-06 23:13 - 00561960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-05-11 06:55 - 2016-04-06 23:13 - 00137976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncrypt.dll 2016-05-11 06:55 - 2016-04-06 20:20 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-05-11 06:55 - 2016-04-06 20:19 - 00401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2016-05-11 06:55 - 2016-04-06 20:19 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-05-11 06:55 - 2016-04-06 19:49 - 00120384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncrypt.dll 2016-05-11 06:55 - 2016-04-06 19:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2016-05-11 06:55 - 2016-04-06 18:57 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-05-11 06:55 - 2016-04-06 18:52 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2016-05-11 06:55 - 2016-04-06 18:20 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2016-05-11 06:55 - 2016-04-06 17:48 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2016-05-11 06:55 - 2016-03-31 08:50 - 01307328 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2016-05-11 06:55 - 2016-03-31 05:40 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2016-05-11 06:54 - 2016-04-10 09:48 - 00738096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll 2016-05-11 06:54 - 2016-04-10 09:48 - 00613624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll 2016-05-11 06:54 - 2016-04-10 06:14 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2016-05-11 06:54 - 2016-04-10 00:07 - 01097728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2016-05-11 06:54 - 2016-03-29 03:42 - 07446368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-05-11 06:54 - 2016-02-27 20:28 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2016-05-11 06:54 - 2016-02-27 19:57 - 03273728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll 2016-05-11 06:54 - 2016-02-27 19:19 - 03820544 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll 2016-05-11 06:54 - 2016-02-27 18:32 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2016-05-11 06:53 - 2016-04-11 08:21 - 00074584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys 2016-05-11 06:53 - 2016-04-10 07:37 - 01549144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-05-11 06:53 - 2016-04-10 06:21 - 01763376 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-05-11 06:53 - 2016-04-10 06:21 - 01489088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-05-11 06:53 - 2016-04-10 01:29 - 04169216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-05-11 06:53 - 2016-04-09 23:58 - 00534016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2016-05-11 06:53 - 2016-04-09 23:50 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2016-05-11 06:53 - 2016-03-16 03:58 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-05-11 06:53 - 2016-03-16 03:58 - 00332632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-05-11 06:53 - 2016-03-14 18:50 - 00316760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys 2016-05-11 06:53 - 2016-03-12 02:49 - 02466136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2016-05-11 06:53 - 2016-03-12 02:47 - 00160160 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPHLPAPI.DLL 2016-05-11 06:53 - 2016-03-12 02:47 - 00121912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IPHLPAPI.DLL 2016-05-11 06:53 - 2016-03-10 19:03 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsparse.dll 2016-05-11 06:53 - 2016-03-10 18:55 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll 2016-05-11 06:53 - 2016-03-10 18:52 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll 2016-05-11 06:53 - 2016-03-10 18:48 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsparse.dll 2016-05-11 06:53 - 2016-03-10 18:42 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll 2016-05-11 06:53 - 2016-03-05 19:44 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll 2016-05-11 06:53 - 2016-03-05 19:04 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll 2016-05-11 06:40 - 2016-05-11 06:40 - 00027539 _____ C:\Users\Frederic\Downloads\LISTE ELEVES DNL 15-16 (5).xlsx 2016-05-09 17:45 - 2016-05-09 17:45 - 00140800 _____ C:\Users\Frederic\Downloads\Calendrier PFMP 2016-2017 (2).xls 2016-05-09 17:43 - 2016-05-09 17:43 - 00140800 _____ C:\Users\Frederic\Downloads\Calendrier PFMP 2016-2017 .xls 2016-05-09 17:43 - 2016-05-09 17:43 - 00140800 _____ C:\Users\Frederic\Downloads\Calendrier PFMP 2016-2017 (1).xls ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-06-05 11:12 - 2015-10-25 19:07 - 00001220 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1287918758-1629660500-816410286-1001UA.job 2016-06-05 11:03 - 2016-04-25 11:58 - 00000000 ____D C:\ProgramData\Serveur Média 2016-06-05 10:56 - 2014-02-04 18:40 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1287918758-1629660500-816410286-1001 2016-06-05 10:55 - 2016-04-25 18:55 - 00000294 _____ C:\WINDOWS\Tasks\{51BFE2E0-598F-7857-C979-559FCCD668F3}.job 2016-06-05 10:49 - 2015-02-18 22:53 - 00001102 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1287918758-1629660500-816410286-1001UA.job 2016-06-05 10:48 - 2015-09-06 16:21 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2016-06-05 10:48 - 2014-02-07 10:45 - 00000000 ____D C:\Program Files\Intel 2016-06-05 10:46 - 2014-06-09 19:52 - 00000000 ____D C:\Users\Frederic\impot 2016-06-05 10:46 - 2014-02-20 21:48 - 00035328 ___SH C:\Users\Frederic\Thumbs.db 2016-06-05 10:46 - 2014-02-07 10:49 - 00000000 ____D C:\Users\Frederic 2016-06-05 10:38 - 2014-02-06 15:32 - 00000000 ____D C:\Users\Frederic\AppData\Local\Adobe 2016-06-05 10:28 - 2016-02-22 19:05 - 00001002 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-06-05 09:33 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-06-05 08:16 - 2015-03-02 17:28 - 00000000 ____D C:\Users\Frederic\AppData\Roaming\Dropbox 2016-06-05 05:00 - 2014-04-30 20:53 - 00003792 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B143338F-3911-4FF8-85A5-17536E3757AF} 2016-06-04 09:06 - 2014-05-08 20:20 - 00000000 __RDO C:\Users\Frederic\OneDrive 2016-06-04 09:06 - 2014-02-06 15:26 - 00001084 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-06-04 09:05 - 2016-02-18 21:57 - 00000350 _____ C:\WINDOWS\Tasks\Start Registry Reviver( SR ) for R700V@Frederic at logon.job 2016-06-03 14:39 - 2015-11-23 19:51 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-06-03 01:28 - 2015-10-19 19:44 - 00002215 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-06-03 01:28 - 2015-10-19 19:44 - 00002203 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-06-02 20:25 - 2014-02-07 23:59 - 00000000 ____D C:\Users\Frederic\AppData\Roaming\Usenet.nl 2016-06-02 16:14 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-06-02 16:12 - 2015-04-08 06:26 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX 2016-06-02 16:12 - 2015-04-08 06:26 - 00000000 ___SD C:\WINDOWS\system32\GWX 2016-06-01 18:12 - 2015-10-25 19:07 - 00001168 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1287918758-1629660500-816410286-1001Core.job 2016-05-31 14:00 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps 2016-05-30 16:44 - 2015-12-02 18:35 - 00000000 ____D C:\Users\Frederic\AppData\Roaming\Skype 2016-05-29 20:09 - 2015-12-02 18:35 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-05-29 10:09 - 2016-01-12 20:22 - 00000000 ____D C:\Users\Frederic\Desktop\corinne 2016-05-27 22:49 - 2015-02-18 22:53 - 00001050 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1287918758-1629660500-816410286-1001Core.job 2016-05-27 06:46 - 2014-02-08 20:08 - 01633792 ___SH C:\Users\Frederic\Desktop\Thumbs.db 2016-05-26 17:22 - 2015-06-29 15:37 - 00064368 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kldisk.sys 2016-05-24 16:46 - 2016-04-25 11:58 - 00000000 ____D C:\Program Files (x86)\Serveur Media 2016-05-24 15:37 - 2016-04-25 13:36 - 00000374 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics 2016-05-24 15:37 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-05-24 15:36 - 2013-08-22 15:25 - 00786432 ___SH C:\WINDOWS\system32\config\BBI 2016-05-24 15:32 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\Inf 2016-05-24 15:19 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2016-05-24 15:16 - 2015-09-06 16:21 - 00834992 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys 2016-05-24 15:16 - 2015-06-29 15:37 - 00049240 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys 2016-05-24 15:08 - 2015-06-29 15:37 - 00238000 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys 2016-05-24 14:56 - 2013-11-14 09:32 - 01825586 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-05-24 14:56 - 2013-11-14 09:13 - 00812794 _____ C:\WINDOWS\system32\perfh00C.dat 2016-05-24 14:56 - 2013-11-14 09:13 - 00159598 _____ C:\WINDOWS\system32\perfc00C.dat 2016-05-23 22:07 - 2014-12-15 18:48 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-05-23 22:07 - 2013-11-14 09:16 - 00000000 ____D C:\Program Files\Windows Journal 2016-05-23 18:05 - 2015-09-03 16:31 - 00000000 ____D C:\Users\Frederic\Documents\Fichiers Outlook 2016-05-23 18:02 - 2016-01-02 16:11 - 00000000 ____D C:\Users\Frederic\Desktop\SFR 2016-05-19 22:34 - 2014-02-04 19:54 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-05-19 22:19 - 2014-02-04 19:54 - 139319312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-05-15 09:59 - 2016-04-25 18:55 - 00000000 ____D C:\Users\Frederic\AppData\Local\{46A970F5-6201-1C4D-0F99-39A52BF1C53D} 2016-05-12 10:55 - 2014-02-19 14:31 - 00000161 _____ C:\Users\Frederic\AppData\Roaming\WB.CFG 2016-05-12 04:49 - 2015-07-30 16:30 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2016-05-11 22:08 - 2016-04-22 18:34 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-05-11 22:08 - 2016-04-22 18:34 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-05-11 06:45 - 2014-02-06 15:26 - 00004060 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-05-11 06:45 - 2014-02-06 15:26 - 00003824 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-05-11 06:45 - 2014-02-06 15:26 - 00001088 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-05-10 22:44 - 2015-02-18 22:53 - 00004054 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1287918758-1629660500-816410286-1001UA 2016-05-10 22:44 - 2015-02-18 22:53 - 00003674 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1287918758-1629660500-816410286-1001Core ==================== Fichiers à la racine de certains dossiers ======= 2015-03-26 13:48 - 2015-03-26 13:48 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll 2014-04-21 15:27 - 2014-04-21 15:27 - 0000036 _____ () C:\Users\Frederic\AppData\Roaming\DOK52P4Q3J.dat 2015-03-26 21:14 - 2015-09-16 16:18 - 0000349 _____ () C:\Users\Frederic\AppData\Roaming\ILFX 2014-10-31 01:07 - 2014-11-16 22:20 - 0047906 _____ () C:\Users\Frederic\AppData\Roaming\loadit.exe 2015-03-26 21:14 - 2015-09-16 16:18 - 0000349 _____ () C:\Users\Frederic\AppData\Roaming\RNAZNEEU 2014-08-08 11:35 - 2014-08-08 11:35 - 0000036 _____ () C:\Users\Frederic\AppData\Roaming\SuYZkvrV.tmp 2015-03-26 21:14 - 2015-09-16 16:18 - 0000935 _____ () C:\Users\Frederic\AppData\Roaming\UQTGER 2014-10-12 20:40 - 2014-10-30 19:23 - 0000031 _____ () C:\Users\Frederic\AppData\Roaming\url.txt 2014-02-19 14:31 - 2016-05-12 10:55 - 0000161 _____ () C:\Users\Frederic\AppData\Roaming\WB.CFG 2015-03-26 21:14 - 2015-09-16 16:18 - 0000935 _____ () C:\Users\Frederic\AppData\Roaming\WPIOX 2016-01-24 19:47 - 2016-01-24 19:47 - 0000800 _____ () C:\Users\Frederic\AppData\Local\recently-used.xbel 2014-02-08 11:29 - 2014-02-08 11:29 - 0000057 _____ () C:\ProgramData\Ament.ini 2015-09-19 09:49 - 2015-09-19 09:49 - 0000095 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc 2015-10-01 16:41 - 2015-10-01 16:40 - 4998552 _____ ((c) PC Cleaners Inc) C:\ProgramData\pclunst.exe Fichiers à déplacer ou supprimer: ==================== C:\ProgramData\pclunst.exe C:\Windows\Tasks\{51BFE2E0-598F-7857-C979-559FCCD668F3}.job ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2015-12-01 13:27 ==================== Fin de FRST.txt ============================