Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 25-09-2016 Exécuté par Jonas_P (administrateur) sur JONAS (28-09-2016 07:55:20) Exécuté depuis C:\Users\Jonas_P\Desktop Profils chargés: Jonas_P (Profils disponibles: Jonas_P & Administrateur) Platform: Windows 8.1 (Update) (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: FF) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (Intel Corporation) C:\Windows\Temp\DPTF\esif_assist.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe () C:\Windows\System32\igfxTray.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Druide informatique inc.) C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe (Druide informatique inc.) C:\Program Files (x86)\Druide\Antidote 8\Programmes64\AgentAntidote.exe () C:\Program Files (x86)\RocketDock\RocketDock.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-05-22] (NVIDIA Corporation) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-10-13] (Conexant Systems, Inc.) HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [AgentAntidote32] => C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe [1130280 2012-11-07] (Druide informatique inc.) HKLM\...\Run: [AgentAntidote64] => C:\Program Files (x86)\Druide\Antidote 8\Programmes64\AgentAntidote.exe [1275176 2012-11-07] (Druide informatique inc.) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7408312 2016-07-17] (AVAST Software) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [331344 2015-07-22] (HP Development Company, L.P.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation) HKU\S-1-5-21-1241292235-3512266450-238808139-1001\...\Run: [Spotify Web Helper] => C:\Users\Jonas_P\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1554032 2016-07-17] (Spotify Ltd) HKU\S-1-5-21-1241292235-3512266450-238808139-1001\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] () HKU\S-1-5-21-1241292235-3512266450-238808139-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8912088 2016-08-26] (Piriform Ltd) HKU\S-1-5-21-1241292235-3512266450-238808139-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd) HKU\S-1-5-21-1241292235-3512266450-238808139-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1241292235-3512266450-238808139-1001\...\MountPoints2: {4fedf14b-a04b-11e5-826f-cde4c80485d8} - "F:\LaunchU3.exe" -a HKU\S-1-5-21-1241292235-3512266450-238808139-1001\...\MountPoints2: {e1de71ee-70c5-11e5-8262-5ce0c5c49fc7} - "G:\SETUP.EXE" HKU\S-1-5-18\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-05-12] (AVAST Software) ShellIconOverlayIdentifiers: [ID de superposition d'icônes des signatures numériques AutoCAD] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2011-02-04] (Autodesk, Inc.) ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft) ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 130.79.200.200 Tcpip\..\Interfaces\{3347529E-6B7C-4B4C-9A7E-B822FABD0C4A}: [DhcpNameServer] 209.222.18.222 209.222.18.218 Tcpip\..\Interfaces\{9975F9BF-F32E-43F5-86F5-23EB4FBFD177}: [DhcpNameServer] 130.79.200.200 ManualProxies: Internet Explorer: ================== HKU\S-1-5-21-1241292235-3512266450-238808139-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://1.loadblanks.ru/c/aedd5b2a1a6eeeb4 HKU\S-1-5-21-1241292235-3512266450-238808139-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1241292235-3512266450-238808139-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1241292235-3512266450-238808139-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1241292235-3512266450-238808139-1001 -> {FDEF52C6-4572-4A12-A5DA-6A11431A7CDA} URL = hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-05-12] (AVAST Software) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-22] (Microsoft Corporation) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-07-21] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-05-12] (AVAST Software) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-23] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-07-21] (Oracle Corporation) BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft) FireFox: ======== FF ProfilePath: C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default FF DefaultSearchEngine: Qwant FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll [2016-09-13] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-13] () FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [Pas de fichier] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [Pas de fichier] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [Pas de fichier] FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-02-25] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-02-25] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-07-21] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-07-21] (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-01-23] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-06-30] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\searchplugins\qwant.xml [2016-04-03] FF Extension: (Adblock Plus Pop-up Addon) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\extensions\adblockpopups@jessehakanen.net.xpi [2016-04-27] FF Extension: (HTTPS Everywhere) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\extensions\https-everywhere@eff.org.xpi [2016-09-23] FF Extension: (WOT) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2016-09-27] FF Extension: (NoScript) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-09-27] FF Extension: (Testapic) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\090F329C-487C-11E4-94B9-22DE1D5D46B0@jetpack.xpi [2016-04-28] FF Extension: (Blur) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\donottrackplus@abine.com.xpi [2016-09-21] FF Extension: (Ghostery) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\firefox@ghostery.com.xpi [2016-09-21] FF Extension: (Deezer feed cleaner) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\jid1-B2OCAPQSTAzqMQ@jetpack.xpi [2016-05-23] FF Extension: (Lightbeam) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2016-07-16] FF Extension: (British English Dictionary (Marco Pinto)) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\marcoagpinto@mail.telepac.pt [2016-09-23] FF Extension: (Qwant for Firefox) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\qwantcomforfirefox@jetpack.xpi [2016-09-23] FF Extension: (uBlock Origin) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\uBlock0@raymondhill.net.xpi [2016-09-25] FF Extension: (Zotero) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\zotero@chnm.gmu.edu.xpi [2016-09-19] FF Extension: (Adblock Plus) - C:\Users\Jonas_P\AppData\Roaming\Mozilla\Firefox\Profiles\9pqqk9p4.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-05-12] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-05-12] FF HKLM-x32\...\Firefox\Extensions: [jid1-r1tDuNiNb4SEww@jetpack] - C:\Program Files\AVAST Software\Avast\pam\FF FF Extension: (Avast Passwords) - C:\Program Files\AVAST Software\Avast\pam\FF [2016-05-18] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-05-12] Opera: ======= OPR Extension: (Zotero Connector) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\aglkdfckbibjdkdoconjbdggodkdchbn [2015-11-12] OPR Extension: (AdBlock) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\aobdicepooefnbaeokijohmhjlleamfj [2016-06-07] OPR Extension: (Ghostery) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg [2016-02-23] OPR Extension: (ZenMate VPN - Sécurité internet & Unblock) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnhbkkedmelfmalgjpkngiaoifpdfcnl [2016-07-01] OPR Extension: (HTTPS Everywhere) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\edaplhobcmdaneconioghljnnopmkhgm [2016-07-01] OPR Extension: (uBlock Origin) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2016-08-22] OPR Extension: (History Eraser) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\lfpoajlbkhlfoeeokbppmecpplmieedm [2015-11-04] OPR Extension: (Adblock Plus) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-07-21] OPR Extension: (Fast search) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\pbdpajcdgknpendpmecafmopknefafha [2016-09-24] OPR Extension: (adblockforopera) - C:\Users\Jonas_P\AppData\Roaming\Opera Software\Opera Stable\Extensions\pcdbekffgfnmjeacgnmdbekgjffgfckb [2016-03-01] ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 Aracity; C:\Program Files (x86)\Coejershgiduph\RepacooleiedCch.dll [275968 2016-09-26] () [Fichier non signé] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-12] (AVAST Software) S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd) R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1037568 2015-02-03] (Intel Corporation) R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [176128 2014-06-24] (HP) [Fichier non signé] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [26168 2015-12-20] (Hewlett-Packard Company) S2 ibtsiva; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [125168 2014-12-12] (Intel Corporation) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344976 2015-02-13] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2014-10-03] (Intel(R) Corporation) S2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [395744 2015-01-14] (Intel) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [156960 2015-02-25] (Intel Corporation) R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-03-19] () S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2013-11-14] (Hewlett-Packard) [Fichier non signé] S3 OpenVPNService; C:\Program Files (x86)\HMA! Pro VPN\bin\openvpnserv.exe [37176 2015-03-17] (The OpenVPN Project) S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2013-11-14] (Hewlett-Packard) [Fichier non signé] S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Fichier non signé] S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2014-11-22] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3820960 2015-03-19] (Intel® Corporation) S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-05-12] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-05-12] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-05-12] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-05-12] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-05-12] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-05-12] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-05-12] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-05-12] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-08-06] (AVAST Software) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [69904 2015-03-18] (ASUS Corporation) S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.) S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.) R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [38720 2015-02-03] (Intel Corporation) R3 dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [38208 2015-02-03] (Intel Corporation) R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-10-12] (Disc Soft Ltd) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) R3 esif_lf; C:\Windows\System32\drivers\esif_lf.sys [216904 2015-02-03] (Intel Corporation) S3 GeneStor; C:\Windows\system32\DRIVERS\GeneStor.sys [107488 2015-01-29] (GenesysLogic) R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [231152 2014-12-12] (Intel Corporation) R0 IntelHSWPcc; C:\Windows\System32\drivers\IntelPcc.sys [79528 2014-10-16] (Intel Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2015-02-25] (Intel Corporation) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80160 2015-02-13] (McAfee, Inc.) R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3497240 2015-03-23] (Intel Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [226304 2014-11-22] (Microsoft Corporation) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.) R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [212056 2015-01-14] (Windows (R) Win 7 DDK provider) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation) R3 WirelessKeyboardFilter; C:\Windows\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation) U3 catchme; \??\C:\Users\Jonas_P\AppData\Local\Temp\catchme.sys [X] U0 msahci; system32\drivers\msahci.sys [X] S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-09-28 07:55 - 2016-09-28 07:56 - 00025491 _____ C:\Users\Jonas_P\Desktop\FRST.txt 2016-09-28 07:55 - 2016-09-28 07:55 - 00000000 ____D C:\FRST 2016-09-28 07:54 - 2016-09-28 07:54 - 02403328 _____ (Farbar) C:\Users\Jonas_P\Desktop\FRST64.exe 2016-09-27 13:21 - 2016-09-27 13:21 - 02416128 _____ C:\Users\Jonas_P\Downloads\ZHPCleaner.exe 2016-09-27 13:21 - 2016-09-27 13:21 - 00000842 _____ C:\Users\Jonas_P\Desktop\ZHPCleaner.lnk 2016-09-27 13:19 - 2016-09-27 13:20 - 02367488 _____ C:\Users\Jonas_P\ZHPDiag3.exe 2016-09-27 13:18 - 2016-09-27 13:18 - 00616483 _____ C:\Users\Jonas_P\Downloads\Fiche fournisseur.pdf 2016-09-27 13:14 - 2016-09-27 13:15 - 00000000 ____D C:\Program Files (x86)\ZHPFix 2016-09-27 13:14 - 2016-09-27 13:14 - 03521617 _____ (Nicolas Coolman ) C:\Users\Jonas_P\Downloads\ZHPFix.exe 2016-09-27 13:14 - 2016-09-27 13:14 - 00001863 _____ C:\Users\Public\Desktop\ZHPFix.lnk 2016-09-27 13:14 - 2016-09-27 13:14 - 00000085 _____ C:\Windows\wininit.ini 2016-09-27 13:14 - 2016-09-27 13:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2016-09-26 20:19 - 2016-09-27 13:19 - 00000832 _____ C:\Users\Jonas_P\Desktop\ZHPDiag.lnk 2016-09-26 20:18 - 2016-09-26 20:19 - 02365952 _____ C:\Users\Jonas_P\Downloads\ZHPDiag3.exe 2016-09-26 18:34 - 2016-09-26 18:34 - 00000000 ____D C:\Users\Jonas_P\AppData\Local\ElevatedDiagnostics 2016-09-26 18:32 - 2016-09-26 19:27 - 00635450 _____ C:\Windows\ntbtlog.txt 2016-09-26 18:25 - 2016-09-26 18:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BSD Concept 2016-09-26 18:25 - 2016-09-26 18:25 - 00000000 ____D C:\Program Files\Bonjour 2016-09-26 18:25 - 2016-09-26 18:25 - 00000000 ____D C:\Program Files (x86)\BSD Concept 2016-09-26 18:25 - 2016-09-26 18:25 - 00000000 ____D C:\Program Files (x86)\Bonjour 2016-09-26 11:36 - 2016-09-26 16:44 - 00259550 _____ C:\Users\Jonas_P\Desktop\OK.ai 2016-09-26 09:53 - 2016-09-26 09:53 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2016-09-26 09:39 - 2016-09-26 09:40 - 00312912 _____ C:\Windows\Minidump\092616-21828-01.dmp 2016-09-26 09:39 - 2016-09-26 09:39 - 634959275 _____ C:\Windows\MEMORY.DMP 2016-09-26 08:30 - 2016-09-26 08:30 - 00000000 ___HD C:\Program Files (x86)\xrft4odb 2016-09-26 08:28 - 2016-09-26 09:33 - 00000000 ____D C:\Program Files (x86)\Coejershgiduph 2016-09-26 08:27 - 2016-09-26 08:44 - 00000000 ____D C:\Users\Jonas_P\AppData\Local\GeoLocator 2016-09-25 12:58 - 2016-09-25 12:58 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\ProductData 2016-09-25 12:58 - 2016-09-25 12:58 - 00000000 ____D C:\ProgramData\ProductData 2016-09-25 11:24 - 2016-09-27 15:47 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\ZHP 2016-09-25 01:40 - 2016-09-26 09:38 - 00000000 ____D C:\AdwCleaner 2016-09-24 14:13 - 2016-09-26 08:27 - 00000000 ____D C:\Users\Jonas_P\ReportSender 2016-09-24 14:13 - 2016-09-24 14:13 - 00000000 ____D C:\Users\Default\Documents\SmartScreen 2016-09-24 14:13 - 2016-09-24 14:13 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ClientProtocol 2016-09-24 14:13 - 2016-09-24 14:13 - 00000000 ____D C:\Users\Default\AppData\Local\AutoUpdate 2016-09-24 14:13 - 2016-09-24 14:13 - 00000000 ____D C:\Users\Default\Act 2016-09-24 14:13 - 2016-09-24 14:13 - 00000000 ____D C:\Users\Default User\Documents\SmartScreen 2016-09-24 14:13 - 2016-09-24 14:13 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ClientProtocol 2016-09-24 14:13 - 2016-09-24 14:13 - 00000000 ____D C:\Users\Default User\AppData\Local\AutoUpdate 2016-09-24 14:12 - 2016-09-24 14:12 - 00002046 ___RS C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Аvast SаfeZоnе Brоwser.lnk 2016-09-24 14:12 - 2016-09-24 14:12 - 00001478 ___RS C:\Users\Jonas_P\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Еxplorеr.lnk 2016-09-24 14:12 - 2016-09-24 14:12 - 00001263 ___RS C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Мozillа Firеfоx.lnk 2016-09-24 14:12 - 2016-09-24 14:12 - 00001227 ___RS C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Оpеrа.lnk 2016-09-24 00:37 - 2016-09-24 17:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-09-20 10:27 - 2016-09-20 10:27 - 06488584 _____ C:\Users\Jonas_P\Downloads\GROS, Les étapes de l'aménagement monumental du forum observations comparatives (Italie, Gaule Narbonnaise, Tarraconaise).pdf 2016-09-20 10:23 - 2016-09-20 10:23 - 06418727 _____ C:\Users\Jonas_P\Downloads\ULRICH, Julius Caesar and the creation of the Forum Iulium.pdf 2016-09-19 13:43 - 2016-09-19 13:43 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\EPSON 2016-09-19 13:41 - 2016-09-19 13:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2016-09-19 13:41 - 2016-09-19 13:41 - 00000000 ____D C:\Program Files (x86)\epson 2016-09-19 13:41 - 2009-05-01 00:00 - 00128392 _____ (Seiko Epson Corporation) C:\Windows\system32\esdevapp.exe 2016-09-19 13:41 - 2009-05-01 00:00 - 00017408 _____ (SEIKO EPSON CORP.) C:\Windows\system32\esxcdev.dll 2016-09-19 13:41 - 2007-11-20 00:00 - 00055808 _____ (SEIKO EPSON CORP.) C:\Windows\system32\esxcwiab.dll 2016-09-16 16:25 - 2016-09-16 16:25 - 04891389 _____ C:\Users\Jonas_P\Downloads\mom_1955-4982_2009_act_52_1_2743.pdf 2016-09-16 16:25 - 2016-09-16 16:25 - 01697929 _____ C:\Users\Jonas_P\Downloads\dha_0755-7256_1997_num_23_2_2353.pdf 2016-09-15 07:58 - 2016-09-01 05:08 - 20312064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-09-15 07:58 - 2016-09-01 02:45 - 25770496 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-09-15 07:58 - 2016-09-01 02:06 - 06047232 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-09-15 07:58 - 2016-08-21 01:45 - 07076864 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll 2016-09-15 07:58 - 2016-08-21 01:27 - 01445376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-09-15 07:58 - 2016-08-21 01:22 - 00435200 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-09-15 07:58 - 2016-08-21 01:05 - 05273600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll 2016-09-15 07:58 - 2016-08-21 00:50 - 00360448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-09-15 07:58 - 2016-08-21 00:42 - 07795712 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll 2016-09-15 07:58 - 2016-08-21 00:27 - 05268480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll 2016-09-15 07:58 - 2016-08-10 00:47 - 00803176 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2016-09-15 07:58 - 2016-08-10 00:47 - 00611576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2016-09-15 07:58 - 2016-08-04 16:17 - 00416768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2016-09-15 07:58 - 2016-08-03 20:06 - 00675328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2016-09-15 07:58 - 2016-08-03 20:05 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2016-09-15 07:58 - 2016-06-11 05:44 - 00107984 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2016-09-15 07:58 - 2016-06-11 05:44 - 00091416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2016-09-15 07:57 - 2016-09-08 23:51 - 00443224 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-09-15 07:57 - 2016-09-08 23:51 - 00332632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-09-15 07:57 - 2016-09-01 04:46 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-09-15 07:57 - 2016-09-01 04:24 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-09-15 07:57 - 2016-09-01 03:39 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2016-09-15 07:57 - 2016-09-01 03:30 - 00692736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-09-15 07:57 - 2016-09-01 03:27 - 13808128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-09-15 07:57 - 2016-09-01 03:24 - 04607488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-09-15 07:57 - 2016-09-01 02:43 - 02445824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-09-15 07:57 - 2016-09-01 02:42 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-09-15 07:57 - 2016-09-01 02:38 - 01316352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-09-15 07:57 - 2016-09-01 02:24 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-09-15 07:57 - 2016-09-01 02:10 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-09-15 07:57 - 2016-09-01 01:38 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2016-09-15 07:57 - 2016-09-01 01:28 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-09-15 07:57 - 2016-09-01 01:15 - 15411712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-09-15 07:57 - 2016-09-01 01:10 - 02921472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-09-15 07:57 - 2016-09-01 00:58 - 01550848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-09-15 07:57 - 2016-09-01 00:47 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-09-15 07:57 - 2016-08-26 07:51 - 02894336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-09-15 07:57 - 2016-08-26 06:44 - 02286592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-09-15 07:57 - 2016-08-26 06:41 - 02881536 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2016-09-15 07:57 - 2016-08-26 06:00 - 01049600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2016-09-15 07:57 - 2016-08-22 18:06 - 00179248 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-09-15 07:57 - 2016-08-22 18:06 - 00100184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-09-15 07:57 - 2016-08-21 03:03 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-09-15 07:57 - 2016-08-21 03:01 - 00401408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-09-15 07:57 - 2016-08-21 03:01 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-09-15 07:57 - 2016-08-21 02:17 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2016-09-15 07:57 - 2016-08-21 01:26 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2016-09-15 07:57 - 2016-08-21 00:55 - 00104960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-09-15 07:57 - 2016-08-14 21:34 - 01541248 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2016-09-15 07:57 - 2016-08-14 20:25 - 04171264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-09-15 07:57 - 2016-08-14 18:14 - 01376768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2016-09-15 07:57 - 2016-08-13 09:41 - 07445848 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-09-15 07:57 - 2016-08-13 09:40 - 01737080 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-09-15 07:57 - 2016-08-13 09:40 - 01663184 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2016-09-15 07:57 - 2016-08-13 09:40 - 01523208 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2016-09-15 07:57 - 2016-08-13 09:40 - 01490120 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2016-09-15 07:57 - 2016-08-13 09:40 - 01358952 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2016-09-15 07:57 - 2016-08-13 02:04 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-09-15 07:57 - 2016-08-11 18:26 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll 2016-09-15 07:57 - 2016-08-11 18:17 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll 2016-09-15 07:57 - 2016-08-11 18:16 - 00455680 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll 2016-09-14 18:09 - 2016-09-14 18:09 - 00133432 _____ C:\Users\Jonas_P\Downloads\Déclaration trimestrielle.pdf 2016-09-14 18:07 - 2016-09-14 18:08 - 00131936 _____ C:\Users\Jonas_P\Downloads\Déclaration annuelle nominative.pdf 2016-09-14 14:36 - 2016-09-14 14:36 - 00000000 ____D C:\Users\Public\Documents\Hewlett-Packard 2016-09-13 06:15 - 2016-09-13 06:15 - 00000040 _____ C:\Users\Default\Downloads\Thankyou.bat 2016-09-13 06:15 - 2016-09-13 06:15 - 00000040 _____ C:\Users\Default User\Downloads\Thankyou.bat 2016-09-05 15:12 - 2016-09-05 15:17 - 00000000 ____D C:\Users\Jonas_P\Documents\Université 2016-09-01 12:22 - 2016-09-02 08:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2016-08-31 22:58 - 2016-08-31 22:58 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\FastStone 2016-08-31 22:58 - 2016-08-31 22:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer 2016-08-31 22:58 - 2016-08-31 22:58 - 00000000 ____D C:\Program Files (x86)\FastStone Image Viewer ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-09-28 07:54 - 2015-10-12 11:53 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1241292235-3512266450-238808139-1001 2016-09-28 07:50 - 2015-10-12 11:49 - 00000165 _____ C:\Users\Jonas_P\AppData\Roaming\sp_data.sys 2016-09-28 07:50 - 2015-10-12 11:48 - 00000000 ____D C:\ProgramData\ASUS Smart Gesture 2016-09-28 07:49 - 2015-10-12 11:46 - 00000000 __SHD C:\Users\Jonas_P\IntelGraphicsProfiles 2016-09-27 22:08 - 2015-11-03 23:18 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\vlc 2016-09-27 22:08 - 2015-10-12 15:02 - 00000000 ____D C:\Users\Jonas_P\AppData\Local\ClassicShell 2016-09-27 21:59 - 2015-10-12 18:43 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\MediaMonkey 2016-09-27 18:38 - 2016-07-18 15:40 - 00000000 ____D C:\Users\Jonas_P\Documents\Divers 2016-09-27 18:30 - 2015-11-04 22:09 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-09-27 18:17 - 2015-10-14 12:57 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\uTorrent 2016-09-27 18:15 - 2016-08-15 12:06 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-09-27 17:26 - 2016-07-17 00:14 - 00000000 ___HD C:\Users\Jonas_P\Documents\Vuze Downloads 2016-09-27 17:26 - 2016-07-17 00:14 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\Azureus 2016-09-27 16:35 - 2015-10-12 11:47 - 00000000 ____D C:\Users\Jonas_P\AppData\Local\Packages 2016-09-27 13:20 - 2015-10-12 11:46 - 00000000 ____D C:\Users\Jonas_P 2016-09-27 11:13 - 2015-10-12 14:37 - 00000000 ____D C:\Program Files (x86)\Opera 2016-09-26 19:35 - 2015-10-12 11:47 - 00000000 ____D C:\Users\Jonas_P\AppData\Local\VirtualStore 2016-09-26 19:34 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-09-26 19:29 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf 2016-09-26 18:25 - 2015-11-09 18:17 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\BSD Concept 2016-09-26 18:14 - 2013-08-22 16:44 - 05246392 _____ C:\Windows\system32\FNTCACHE.DAT 2016-09-26 18:06 - 2015-10-12 17:47 - 00002063 ____H C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-09-26 16:25 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache 2016-09-26 14:34 - 2016-01-25 08:35 - 00000000 ____D C:\Users\Jonas_P\ownCloud 2016-09-26 14:34 - 2016-01-25 08:34 - 00000000 ____D C:\Users\Jonas_P\AppData\Local\ownCloud 2016-09-26 11:49 - 2015-12-04 15:16 - 00000000 ____D C:\Program Files\Common Files\AV 2016-09-26 10:23 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp 2016-09-26 09:56 - 2015-11-05 13:22 - 00000000 ____D C:\Windows\system32\MRT 2016-09-26 09:51 - 2015-11-05 13:22 - 144199024 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-09-26 09:39 - 2016-01-08 19:59 - 00000000 ____D C:\Windows\Minidump 2016-09-25 16:54 - 2015-04-11 14:12 - 00813786 _____ C:\Windows\system32\perfh00C.dat 2016-09-25 16:54 - 2015-04-11 14:12 - 00159832 _____ C:\Windows\system32\perfc00C.dat 2016-09-25 16:54 - 2014-11-22 03:01 - 01824010 _____ C:\Windows\system32\PerfStringBackup.INI 2016-09-25 16:51 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps 2016-09-25 16:51 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness 2016-09-25 16:46 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI 2016-09-25 12:58 - 2015-10-12 14:43 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2016-09-25 12:54 - 2015-12-29 16:03 - 00000000 ____D C:\Users\Jonas_P\Desktop\A classer 2016-09-25 11:23 - 2016-07-16 23:39 - 00000000 ____D C:\Program Files\pia_manager 2016-09-25 01:48 - 2015-11-04 22:09 - 00001064 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-09-24 18:06 - 2015-12-25 13:48 - 00000000 ___HD C:\Users\Jonas_P\Downloads\The.Walking.Dead.S01.x264.[AC3.ENG.FR].[ST.FR.ENG] 2016-09-24 17:30 - 2016-07-21 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-09-24 17:29 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\ModemLogs 2016-09-24 14:12 - 2015-11-09 18:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite 2016-09-24 14:10 - 2015-11-09 18:13 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\DAEMON Tools Lite 2016-09-24 13:28 - 2016-02-21 10:58 - 00000000 ___HD C:\Users\Jonas_P\Downloads\Les.Sims.2.Double.Deluxe.avec.disques.additionnels.Kits.d.extensions-MDZ 2016-09-23 23:53 - 2015-12-19 12:56 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\Skype 2016-09-23 22:41 - 2016-06-14 22:40 - 00000000 ____D C:\ProgramData\Skype 2016-09-23 18:27 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF 2016-09-23 12:26 - 2015-11-04 19:32 - 00000000 ____D C:\Users\Jonas_P\AppData\Roaming\BankPerfect 2016-09-22 10:07 - 2015-10-12 14:38 - 00003866 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1444653452 2016-09-22 10:07 - 2015-10-12 14:37 - 00001065 ____H C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2016-09-19 20:18 - 2015-11-09 15:19 - 00000000 ____D C:\Users\Jonas_P\testapic 2016-09-18 12:09 - 2015-10-12 14:50 - 00001384 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk 2016-09-18 12:09 - 2015-10-12 14:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller 2016-09-18 11:54 - 2015-10-12 14:50 - 00000000 ____D C:\ProgramData\IObit 2016-09-16 08:02 - 2015-10-12 18:28 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2016-09-13 13:31 - 2016-04-08 17:30 - 20448960 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2016-09-13 13:31 - 2015-11-04 22:09 - 00004026 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2016-09-13 13:31 - 2015-11-04 22:09 - 00003890 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-09-13 13:31 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2016-09-13 13:31 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\Macromed 2016-09-09 11:10 - 2016-07-17 00:14 - 00001862 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk 2016-09-09 11:10 - 2016-07-17 00:14 - 00000000 ____D C:\Program Files (x86)\Vuze 2016-09-07 03:11 - 2016-07-21 11:32 - 00828408 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-09-07 03:11 - 2016-07-21 11:32 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-09-06 19:03 - 2016-05-19 10:42 - 00000000 ____D C:\HP_LaserJet_Pro_MFP_M225-M226 2016-08-30 21:10 - 2015-12-19 12:56 - 00000000 ___RD C:\Program Files (x86)\Skype ==================== Fichiers à la racine de certains dossiers ======= 2016-03-28 19:20 - 2016-03-29 09:11 - 0000132 _____ () C:\Users\Jonas_P\AppData\Roaming\Préfs Format BMP Adobe CS6 2016-02-21 16:06 - 2016-02-22 10:49 - 0000132 _____ () C:\Users\Jonas_P\AppData\Roaming\Préfs Format PNG Adobe CS6 2015-10-12 11:49 - 2016-09-28 07:50 - 0000165 _____ () C:\Users\Jonas_P\AppData\Roaming\sp_data.sys 2016-02-21 16:10 - 2016-02-22 10:54 - 0001456 _____ () C:\Users\Jonas_P\AppData\Local\Adobe Enregistrer pour le Web 13.0 Prefs 2016-01-22 13:48 - 2016-01-22 13:48 - 0000057 _____ () C:\ProgramData\Ament.ini 2016-08-19 10:23 - 2016-08-19 10:23 - 4980736 _____ () C:\ProgramData\ClassicShellSetup64_4_3_0.msi 2016-01-23 17:39 - 2016-01-23 17:39 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2015-04-11 06:36 - 2012-09-07 13:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd 2015-04-11 06:36 - 2009-07-22 12:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe 2015-04-11 06:36 - 2012-09-07 13:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS Fichiers à déplacer ou supprimer: ==================== C:\Users\Jonas_P\ZHPDiag3.exe Certains fichiers dans TEMP: ==================== C:\Users\Administrateur\AppData\Local\Temp\AcDeltree.exe C:\Users\Jonas_P\AppData\Local\Temp\i4jdel0.exe ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2016-09-26 10:34 ==================== Fin de FRST.txt ============================