Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 23-07-2016 02 Exécuté par kevin (administrateur) sur KEVIN-PC (23-07-2016 22:30:41) Exécuté depuis C:\Users\kevin\Downloads Profils chargés: kevin (Profils disponibles: kevin) Platform: Windows 7 Professional Service Pack 1 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: FF) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (BitTorrent Inc.) C:\Users\kevin\AppData\Roaming\uTorrent\uTorrent.exe () C:\Users\kevin\AppData\Roaming\Atijugizs\Atijugizs.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe () C:\Users\kevin\AppData\Roaming\Atijugizs\Eeecelshp.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (BitTorrent Inc.) C:\Users\kevin\AppData\Roaming\uTorrent\updates\3.4.7_42330\utorrentie.exe (BitTorrent Inc.) C:\Users\kevin\AppData\Roaming\uTorrent\updates\3.4.7_42330\utorrentie.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (YahooChrome) C:\ProgramData\yahoochrome_D\desktop227.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe () C:\Program Files (x86)\D-Link\DWA-131\WlanWpsSvc.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel(R) Corporation) C:\Program Files\Intel\BCA\pabeSvc64.exe (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe (McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe (McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe () C:\Program Files\Intel Security\True Key\application\truekey.exe () C:\Program Files\Intel Security\True Key\application\truekey.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7288424 2011-08-15] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [gplyra] => C:\Users\kevin\AppData\Roaming\gplyra\gplyra\start.cmd HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\StartSuperCharger.exe [303104 2011-07-06] (MSI) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) HKLM-x32\...\Run: [win_en_77] => [X] HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\Run: [uTorrent] => C:\Users\kevin\AppData\Roaming\uTorrent\uTorrent.exe [2133504 2016-05-20] (BitTorrent Inc.) HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd) HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53130368 2016-05-17] (Skype Technologies S.A.) HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4299968 2016-06-22] (Disc Soft Ltd) HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\Run: [Chromium] => "c:\users\kevin\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\MountPoints2: F - F:\autorun.exe -auto HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\MountPoints2: {61028e9c-3f6d-11e4-a1f1-806e6f6e6963} - D:\DVDSetup.exe HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\MountPoints2: {633a0654-4bfb-11e6-9c57-8c89a56218d0} - F:\autorun.exe -auto HKU\S-1-5-21-3319585158-3511966730-2090625698-1000\...\MountPoints2: {a049e983-4d1c-11e6-8434-8c89a56218d0} - G:\autorun.exe -auto HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-10-23] (Microsoft Corporation) Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter Startup: C:\Users\kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Envoyer à OneNote.lnk [2016-06-20] ShortcutTarget: Envoyer à OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation) GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{D8B7E1DC-4AF8-4BA1-A45A-C054A0A1E60E}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{F8EF0DDE-5E99-4D46-B2C1-1144B60EDB38}: [DhcpNameServer] 10.188.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> DefaultScope la valeur est absente SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3319585158-3511966730-2090625698-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-20] (Microsoft Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2016-07-20] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-20] (Microsoft Corporation) BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15] (Intel Security) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-20] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-08-16] (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2016-07-20] (Microsoft Corporation) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-20] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-16] (Oracle Corporation) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15] (Intel Security) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-20] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-20] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-20] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-20] (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\kevin\AppData\Roaming\Mozilla\Firefox\Profiles\g70pj2rw.default-1469276234290 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-23] () FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-23] () FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-16] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-16] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-20] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-07-20] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-03] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-03] (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.) FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25] ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S2 0105431469304559mcinstcleanup; C:\Windows\TEMP\010543~1.EXE [922152 2016-03-02] (McAfee, Inc.) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2950856 2016-07-11] (Microsoft Corporation) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-06-22] (Disc Soft Ltd) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation) S2 GribacherqaentRenewshk.exe; C:\Program Files (x86)\Ghohech\GribacherqaentRenewshk.exe [731360 2016-07-22] () S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [157904 2016-05-26] (McAfee, Inc.) R2 IntelBCAsvc; C:\Program Files\Intel\BCA\pabeSvc64.exe [3026584 2016-05-06] (Intel(R) Corporation) R2 Minhilupe; C:\Users\kevin\AppData\Roaming\Atijugizs\Atijugizs.exe [170496 2016-07-21] () [Fichier non signé] R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation) S3 ose; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [200240 2016-07-09] (Microsoft Corporation) [Fichier non signé] R2 saiyitechnology; C:\ProgramData\yahoochrome_D\desktop227.exe [236768 2016-07-21] (YahooChrome) S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [908256 2016-07-14] (McAfee, Inc.) R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [15736 2016-07-14] (McAfee, Inc.) R2 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2016-07-14] (McAfee, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 WlanWpsSvc; C:\Program Files (x86)\D-Link\DWA-131\WlanWpsSvc.exe [167936 2008-06-26] () [Fichier non signé] S2 Tocfiga; "C:\Users\kevin\AppData\Roaming\PususiZyt\Henebi.exe" -cms [X] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-07-17] (Disc Soft Ltd) R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-07-17] (Disc Soft Ltd) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-10-03] (NVIDIA Corporation) S3 RTL8192cu; C:\Windows\System32\DRIVERS\rtwlanu.sys [986728 2012-02-10] (Realtek Semiconductor Corporation ) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [394296 2016-07-17] (Duplex Secure Ltd.) S1 cbixcxva; \??\C:\Windows\system32\drivers\cbixcxva.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-07-23 22:30 - 2016-07-23 22:31 - 00020067 _____ C:\Users\kevin\Downloads\FRST.txt 2016-07-23 22:29 - 2016-07-23 22:30 - 00000000 ____D C:\FRST 2016-07-23 22:28 - 2016-07-23 22:28 - 02394112 _____ (Farbar) C:\Users\kevin\Downloads\FRST64.exe 2016-07-23 22:28 - 2016-07-23 22:28 - 01744384 _____ (Farbar) C:\Users\kevin\Downloads\FRST.exe 2016-07-23 22:10 - 2016-07-23 22:11 - 00000000 ____D C:\Users\kevin\AppData\Local\tkdata 2016-07-23 22:10 - 2016-07-23 22:10 - 00001150 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Key.lnk 2016-07-23 22:10 - 2016-07-23 22:10 - 00001136 _____ C:\Users\Public\Desktop\True Key.lnk 2016-07-23 22:10 - 2016-07-23 22:10 - 00000000 ____D C:\ProgramData\TrueKey 2016-07-23 22:09 - 2016-07-23 22:09 - 00000000 ____D C:\Program Files\Intel Security 2016-07-23 22:09 - 2016-07-23 22:09 - 00000000 ____D C:\Program Files\Intel 2016-07-23 22:09 - 2016-07-23 22:09 - 00000000 ____D C:\Program Files\Common Files\McAfee 2016-07-23 22:09 - 2016-07-23 22:09 - 00000000 ____D C:\Program Files\Common Files\AV 2016-07-23 22:09 - 2016-07-23 22:09 - 00000000 ____D C:\Program Files (x86)\McAfee 2016-07-23 22:01 - 2016-07-23 22:00 - 00000030 _____ C:\AVScanner.ini 2016-07-23 22:00 - 2016-07-23 22:11 - 00000000 ____D C:\Program Files\TrueKey 2016-07-23 22:00 - 2016-07-23 22:00 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-07-23 22:00 - 2016-07-23 22:00 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-07-23 14:17 - 2016-07-23 14:17 - 00000000 ____D C:\Users\kevin\Desktop\Anciennes données de Firefox 2016-07-23 13:35 - 2016-07-23 13:35 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-07-23 13:35 - 2016-07-23 13:35 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-07-23 13:35 - 2016-07-23 13:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-07-23 13:32 - 2016-07-23 13:34 - 00008192 ___SH C:\Users\kevin\AppData\Roaming\Thumbs.db 2016-07-22 21:08 - 2016-07-22 21:08 - 00250912 _____ C:\Windows\SysWOW64\kz.exe 2016-07-22 20:43 - 2016-07-22 20:43 - 00000000 ____D C:\Users\kevin\AppData\Local\ElevatedDiagnostics 2016-07-22 20:21 - 2016-07-22 20:21 - 00003564 _____ C:\Windows\System32\Tasks\{5A46279E-D0A0-46AD-80C6-4290D18C9FE2} 2016-07-22 20:18 - 2016-07-22 20:18 - 00000000 ____D C:\Program Files (x86)\{516D9F5A-D8E3-485A-838A-AE688ED07E5C} 2016-07-22 20:10 - 2016-07-22 20:10 - 00000000 ____D C:\Windows\system32\banc 2016-07-22 20:03 - 2016-07-22 20:03 - 00000000 ____D C:\Users\kevin\AppData\Local\UCBrowser 2016-07-22 20:02 - 2016-07-22 20:02 - 00003084 _____ C:\Windows\System32\Tasks\{596BFDCF-B047-4F86-9832-B1483F3D818F} 2016-07-22 20:00 - 2016-07-22 20:00 - 00000000 ____D C:\Users\kevin\AppData\Roaming\Softlink 2016-07-22 20:00 - 2016-07-22 20:00 - 00000000 ____D C:\ProgramData\yahoochrome_D 2016-07-22 19:59 - 2016-07-22 20:28 - 07616340 _____ C:\Users\kevin\AppData\Roaming\setup.apk 2016-07-22 19:58 - 2016-07-23 09:11 - 00000000 ____D C:\Program Files (x86)\host 2016-07-22 19:58 - 2016-07-22 19:58 - 00003442 _____ C:\Windows\System32\Tasks\kevinOvertakenSeductiveV2 2016-07-22 19:58 - 2016-07-22 19:58 - 00001994 _____ C:\Windows\System32\Tasks\vwe3034 2016-07-22 19:57 - 2016-07-22 19:58 - 00000000 ____D C:\Users\kevin\AppData\Local\{57B961E5-7311-0D5D-1E89-28B53AE1D42D} 2016-07-22 19:57 - 2016-07-22 19:57 - 00009000 _____ C:\Windows\System32\Tasks\Gribacherqaent Renew 2016-07-22 19:57 - 2016-07-22 19:57 - 00000000 ____D C:\Users\kevin\AppData\LocalLow\Company 2016-07-22 19:56 - 2016-07-23 10:19 - 00000000 ____D C:\Users\kevin\AppData\Roaming\Atijugizs 2016-07-22 19:56 - 2016-07-22 20:12 - 00000000 ____D C:\Program Files (x86)\Ghohech 2016-07-22 19:56 - 2016-07-22 20:07 - 00000000 ____D C:\Program Files\Seunji 2016-07-22 19:56 - 2016-07-22 19:56 - 00000000 ____D C:\Users\kevin\AppData\Local\Tempfolder 2016-07-22 19:52 - 2016-07-22 19:52 - 07105536 _____ C:\Users\kevin\AppData\Roaming\agent.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 02279413 _____ C:\Users\kevin\AppData\Roaming\U-hold.bin 2016-07-22 19:52 - 2016-07-22 19:52 - 00126464 _____ C:\Users\kevin\AppData\Roaming\noah.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 00126464 _____ C:\Users\kevin\AppData\Roaming\lobby.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 00072706 _____ C:\Users\kevin\AppData\Roaming\Stimniming.tst 2016-07-22 19:52 - 2016-07-22 19:52 - 00070656 _____ C:\Users\kevin\AppData\Roaming\Config.xml 2016-07-22 19:52 - 2016-07-22 19:52 - 00054272 _____ C:\Users\kevin\AppData\Roaming\ApplicationHosting.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 00018432 _____ C:\Users\kevin\AppData\Roaming\Main.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 00005568 _____ C:\Users\kevin\AppData\Roaming\md.xml 2016-07-22 19:51 - 2016-07-22 19:51 - 00129024 _____ C:\Users\kevin\AppData\Roaming\Installer.dat 2016-07-22 19:51 - 2016-07-22 19:51 - 00018432 _____ C:\Users\kevin\AppData\Roaming\InstallationConfiguration.xml 2016-07-22 19:49 - 2016-07-22 19:49 - 30533688 _____ C:\Users\kevin\Downloads\vlc-2.2.4-win32.exe 2016-07-22 19:49 - 2016-07-22 19:49 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk 2016-07-22 19:49 - 2016-07-22 19:49 - 00000000 ____D C:\Users\kevin\AppData\Roaming\vlc 2016-07-22 19:49 - 2016-07-22 19:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2016-07-22 19:46 - 2016-07-22 19:47 - 00000000 ____D C:\Users\kevin\Downloads\Ray Donovan S04E05 2016 HDTV x264 - EVO 2016-07-22 19:45 - 2016-07-22 19:45 - 00000000 ____D C:\Users\kevin\Downloads\Suits S06E02 2016 HDTV x264 - EVO 2016-07-22 19:42 - 2016-07-22 19:42 - 00000000 ____D C:\Users\kevin\Downloads\Suits S06E03 2016 HDTV x264 - EVO 2016-07-21 22:44 - 2016-07-21 22:44 - 03992854 _____ C:\Users\kevin\Downloads\Le-lemurien-demande-des-caresses.mp4 2016-07-21 22:42 - 2016-07-21 22:43 - 00459741 _____ C:\Users\kevin\Downloads\EXCELLENT_RECOVERY.mp4 2016-07-18 22:52 - 2016-07-18 22:55 - 00000000 ____D C:\Program Files (x86)\Mass Effect 2 2016-07-18 22:00 - 2016-07-18 22:00 - 00000000 ____D C:\Windows\SysWOW64\AGEIA 2016-07-18 22:00 - 2016-07-18 22:00 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2016-07-17 23:57 - 2016-07-17 23:57 - 00000000 ____D C:\Users\kevin\Downloads\Mass.Effect.CrackFix+Key-SAVED 2016-07-17 23:49 - 2016-07-17 23:50 - 11754377 _____ C:\Users\kevin\Downloads\MASS.EFFECT.V1.0.ENG.IND.NOCD.ZIP 2016-07-17 23:02 - 2016-07-17 23:02 - 00047672 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtliteusbbus.sys 2016-07-17 23:01 - 2016-07-17 23:02 - 00000000 ____D C:\Program Files\DAEMON Tools Lite 2016-07-17 23:01 - 2016-07-17 23:01 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys 2016-07-17 23:01 - 2016-07-17 23:01 - 00001773 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2016-07-17 23:01 - 2016-07-17 23:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite 2016-07-17 22:59 - 2016-07-17 22:59 - 00692072 _____ (Disc Soft Ltd.) C:\Users\kevin\Downloads\daemon-tools-lite_10-3-0_fr_10729.exe 2016-07-17 22:17 - 2016-07-17 22:22 - 00000000 ____D C:\Users\kevin\Desktop\Mass Effect 3 2016-07-17 22:00 - 2016-07-18 22:01 - 00000000 ____D C:\Users\kevin\Desktop\Mass Effect 2 2016-07-17 21:56 - 2016-07-17 23:46 - 00000000 ____D C:\Users\kevin\Desktop\Mass Effect 2016-07-16 12:23 - 2016-07-16 12:24 - 00000000 ____D C:\Users\kevin\Downloads\Suits.S06E01.HDTV.x264-KILLERS[ettv] 2016-07-15 22:14 - 2016-07-15 22:14 - 00000000 ____D C:\Users\kevin\Downloads\La Fleuriste (Marc Dorcel) WEB-DL NEW 2016 Split Scenes 2016-07-15 21:45 - 2016-07-15 21:45 - 13095136 _____ (Microsoft Corporation) C:\Users\kevin\Downloads\Silverlight_x64(1).exe 2016-07-12 22:07 - 2016-07-12 22:14 - 00000000 ____D C:\Users\kevin\Downloads\Steve Jobs 2015 1080p BluRay x264 DTS-JYK 2016-07-12 22:06 - 2016-07-12 22:16 - 00000000 ____D C:\Users\kevin\Downloads\Mr Right 2015 1080p BluRay x264 DTS-JYK 2016-07-12 22:06 - 2016-07-12 22:13 - 00000000 ____D C:\Users\kevin\Downloads\Kung Fu Panda 3 2016 1080p BluRay x264 DTS-JYK 2016-07-12 21:56 - 2016-07-12 21:59 - 00000000 ____D C:\Users\kevin\Downloads\Marc Dorcel - The Florist (2016) WEB-DL SPLIT SCENES MP4-RARBG 2016-07-12 21:49 - 2016-07-12 21:49 - 06079168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2016-07-10 23:34 - 2016-07-11 20:57 - 1330003968 _____ C:\Users\kevin\Downloads\Section Disciplinaire.avi 2016-07-10 21:32 - 2016-07-10 21:32 - 00000000 ____D C:\Users\kevin\Downloads\Marc Dorcel - Mon Amant, Moi… Et Ma Mere (2010) DVDRip 2016-07-10 15:19 - 2016-07-10 15:25 - 00000000 ____D C:\Users\kevin\Downloads\Dorcel - Ines Escorte de Luxe XXX 2016 WebGift 2016-07-08 21:56 - 2016-07-08 21:58 - 00000000 ____D C:\Users\kevin\Downloads\Killjoys.S02E01.HDTV.x264-KILLERS[ettv] 2016-07-06 20:55 - 2016-07-06 20:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-07-06 20:55 - 2016-07-06 20:55 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2016-07-06 20:55 - 2016-07-06 20:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-07-06 20:54 - 2016-07-06 20:54 - 13166304 _____ (Microsoft Corporation) C:\Users\kevin\Downloads\Silverlight_x64.exe 2016-07-06 07:25 - 2016-07-23 13:43 - 00000000 ____D C:\AdwCleaner 2016-07-06 07:25 - 2016-07-06 07:25 - 03712064 _____ C:\Users\kevin\Downloads\adwcleaner_5.201.exe 2016-07-03 20:58 - 2016-07-03 21:03 - 2097102157 _____ C:\Users\kevin\Downloads\Game.of.Thrones.S06E10.HDTV.1080p.x264.AC-3.SSA.MKV (EUS_XA).mkv 2016-07-03 20:56 - 2016-07-03 20:57 - 00000000 ____D C:\Users\kevin\Downloads\Marc Dorcel - Luxure Epouses Obeissantes XXX 2016 mp4 2016-06-29 22:35 - 2016-06-29 22:35 - 00000000 ____D C:\Users\kevin\Downloads\[Marc Dorcel] Maximum Fitness 2016-06-28 03:12 - 2016-06-28 03:12 - 00314434 ____N C:\Users\kevin\AppData\Roaming\EYapp.apk 2016-06-25 23:34 - 2016-07-23 20:22 - 00000000 ____D C:\Users\kevin\AppData\LocalLow\uTorrent 2016-06-25 01:12 - 2016-06-25 01:22 - 1526398085 _____ C:\Users\kevin\Downloads\La Famille Bertier.mp4 ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-07-23 22:30 - 2014-09-20 02:21 - 00000000 ____D C:\Users\kevin\AppData\Roaming\uTorrent 2016-07-23 22:24 - 2015-06-05 18:51 - 00000000 ____D C:\Users\kevin\AppData\Roaming\Skype 2016-07-23 22:09 - 2015-07-01 01:52 - 00000000 ____D C:\ProgramData\McAfee 2016-07-23 22:01 - 2014-09-20 02:26 - 00000000 ____D C:\Users\kevin\AppData\Local\Adobe 2016-07-23 21:38 - 2015-08-16 02:54 - 00001020 _____ C:\Windows\Tasks\Ib6Dbh54mZVQYexashAqnDMS.job 2016-07-23 20:30 - 2009-07-14 06:45 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-07-23 20:30 - 2009-07-14 06:45 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-07-23 20:21 - 2014-09-18 22:34 - 00000000 ____D C:\ProgramData\NVIDIA 2016-07-23 20:21 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-07-23 13:35 - 2015-07-03 20:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-07-23 13:30 - 2015-08-16 03:59 - 00001305 _____ C:\Users\kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-07-23 13:29 - 2015-04-08 08:41 - 00000030 _____ C:\Users\kevin\Desktop\as.txt 2016-07-23 13:09 - 2015-08-16 01:09 - 00000350 _____ C:\Windows\Tasks\GroovyLayout.job 2016-07-23 10:38 - 2014-11-25 23:15 - 00000000 ____D C:\Users\kevin\AppData\Roaming\Notepad++ 2016-07-23 10:37 - 2014-11-25 23:15 - 00000000 ____D C:\Program Files (x86)\Notepad++ 2016-07-23 10:30 - 2014-09-20 17:30 - 00000000 ____D C:\Users\kevin\AppData\Roaming\DAEMON Tools Lite 2016-07-22 23:50 - 2016-04-08 23:05 - 00016896 _____ C:\Users\kevin\Desktop\suivi appartement.xls 2016-07-22 20:49 - 2015-12-03 16:00 - 00000000 ____D C:\Users\kevin\AppData\Local\Apps\2.0 2016-07-22 20:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2016-07-22 20:19 - 2014-10-25 03:06 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2016-07-22 20:05 - 2015-05-28 22:54 - 00000000 ____D C:\ProgramData\WinZip 2016-07-22 20:05 - 2015-05-28 22:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2016-07-22 20:00 - 2014-09-30 21:22 - 00001334 __RSH C:\ProgramData\ntuser.pol 2016-07-22 19:57 - 2014-10-09 22:46 - 00000000 ____D C:\Windows\system32\log 2016-07-22 13:53 - 2015-07-09 00:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-07-22 13:50 - 2015-07-09 00:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2016-07-22 13:47 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2016-07-18 23:01 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2016-07-18 22:02 - 2015-04-07 22:10 - 00000000 ____D C:\Users\kevin\Documents\BioWare 2016-07-18 22:00 - 2015-11-01 17:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2016-07-18 21:47 - 2012-03-06 00:02 - 00000000 ____D C:\games 2016-07-18 21:46 - 2015-04-07 20:55 - 00000000 ____D C:\ProgramData\Media Center Programs 2016-07-17 23:43 - 2012-05-08 15:08 - 00000000 ____D C:\series 2016-07-17 23:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-07-17 23:01 - 2015-08-06 23:02 - 00394296 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2016-07-17 22:03 - 2014-09-19 21:18 - 00000000 ____D C:\Users\kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2016-07-17 21:57 - 2012-08-19 21:38 - 00000000 ____D C:\Steam 2016-07-17 12:42 - 2015-03-29 02:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com 2016-07-15 21:18 - 2014-09-18 22:51 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2016-07-14 10:55 - 2009-07-14 07:08 - 00032496 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-07-13 21:18 - 2015-06-26 19:32 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2016-07-12 21:49 - 2014-09-23 23:26 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2016-07-12 21:49 - 2014-09-23 23:26 - 00000000 ____D C:\Windows\system32\Macromed 2016-07-08 22:28 - 2016-03-19 22:01 - 00000000 ____D C:\Users\kevin\AppData\Roaming\FiraxisLive 2016-07-07 02:39 - 2014-09-18 22:55 - 00485032 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Fichiers à la racine de certains dossiers ======= 2010-08-28 22:43 - 2010-08-28 22:43 - 0096256 ____N (Google, inc) C:\Users\kevin\AppData\Roaming\AdbWinApi.dll 2010-08-28 22:43 - 2010-08-28 22:43 - 0060928 ____N (Google, inc) C:\Users\kevin\AppData\Roaming\AdbWinUsbApi.dll 2016-07-22 19:52 - 2016-07-22 19:52 - 7105536 _____ () C:\Users\kevin\AppData\Roaming\agent.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 0054272 _____ () C:\Users\kevin\AppData\Roaming\ApplicationHosting.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 0070656 _____ () C:\Users\kevin\AppData\Roaming\Config.xml 2016-06-28 03:12 - 2016-06-28 03:12 - 0314434 ____N () C:\Users\kevin\AppData\Roaming\EYapp.apk 2015-04-14 18:28 - 2015-04-14 18:28 - 0001171 _____ () C:\Users\kevin\AppData\Roaming\Ib6Dbh54mZVQYexashAqnDMS 2016-07-22 19:51 - 2016-07-22 19:51 - 0018432 _____ () C:\Users\kevin\AppData\Roaming\InstallationConfiguration.xml 2016-07-22 19:51 - 2016-07-22 19:51 - 0129024 _____ () C:\Users\kevin\AppData\Roaming\Installer.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 0126464 _____ () C:\Users\kevin\AppData\Roaming\lobby.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 0018432 _____ () C:\Users\kevin\AppData\Roaming\Main.dat 2016-07-22 19:52 - 2016-07-22 19:52 - 0005568 _____ () C:\Users\kevin\AppData\Roaming\md.xml 2016-07-22 19:52 - 2016-07-22 19:52 - 0126464 _____ () C:\Users\kevin\AppData\Roaming\noah.dat 2016-07-22 19:59 - 2016-07-22 20:28 - 7616340 _____ () C:\Users\kevin\AppData\Roaming\setup.apk 2016-07-22 19:52 - 2016-07-22 19:52 - 0072706 _____ () C:\Users\kevin\AppData\Roaming\Stimniming.tst 2016-07-23 13:32 - 2016-07-23 13:34 - 0008192 ___SH () C:\Users\kevin\AppData\Roaming\Thumbs.db 2016-07-22 19:52 - 2016-07-22 19:52 - 2279413 _____ () C:\Users\kevin\AppData\Roaming\U-hold.bin 2016-07-22 19:52 - 2016-07-22 19:52 - 0032038 _____ () C:\Users\kevin\AppData\Roaming\uninstall_temp.ico Certains fichiers dans TEMP: ==================== C:\Users\kevin\AppData\Local\Temp\1469210404U1QzMtmp.exe C:\Users\kevin\AppData\Local\Temp\2DIRI9BUB5.exe C:\Users\kevin\AppData\Local\Temp\6BCE.tmp.exe C:\Users\kevin\AppData\Local\Temp\acc.exe C:\Users\kevin\AppData\Local\Temp\CodecFixDivx.exe C:\Users\kevin\AppData\Local\Temp\drm_dyndata_7370007.dll C:\Users\kevin\AppData\Local\Temp\dxdiag.exe C:\Users\kevin\AppData\Local\Temp\F2P6Q8HVA1.exe C:\Users\kevin\AppData\Local\Temp\IN18ZX7MDT.exe C:\Users\kevin\AppData\Local\Temp\libeay32.dll C:\Users\kevin\AppData\Local\Temp\MBBBP1H81X.exe C:\Users\kevin\AppData\Local\Temp\MediaPlayer__11426.exe C:\Users\kevin\AppData\Local\Temp\MPCSetup_5.exe C:\Users\kevin\AppData\Local\Temp\MR8QUEPPFV.exe C:\Users\kevin\AppData\Local\Temp\msconfig.exe C:\Users\kevin\AppData\Local\Temp\msvcr120.dll C:\Users\kevin\AppData\Local\Temp\npp.6.9.2.Installer.exe C:\Users\kevin\AppData\Local\Temp\nskC92C.tmp.exe C:\Users\kevin\AppData\Local\Temp\sdf3BAA.exe C:\Users\kevin\AppData\Local\Temp\sdf6E4E.exe C:\Users\kevin\AppData\Local\Temp\sqlite3.dll C:\Users\kevin\AppData\Local\Temp\vlc-2.2.4-win32.exe C:\Users\kevin\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2016-07-17 17:15 ==================== Fin de FRST.txt ============================