Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016 Exécuté par besmellah (administrateur) sur BESMELLAH-PC (10-12-2016 19:41:55) Exécuté depuis C:\Users\besmellah\Desktop Profils chargés: besmellah (Profils disponibles: besmellah) Platform: Windows 7 Ultimate Service Pack 1 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: FF) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registre (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2650576 2016-11-15] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3907152 2015-08-29] (Tonec Inc.) HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Run: [uTorrent] => C:\Users\besmellah\AppData\Roaming\uTorrent\uTorrent.exe [2145984 2016-12-05] (BitTorrent Inc.) HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2016-12-06] (SUPERAntiSpyware) HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Run: [EasyHideIPVPN] => C:\Program Files (x86)\Easy-Hide-IP VPN\vpn.client.exe ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.) GroupPolicy: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Winsock: Catalog9-x64 01 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech) Winsock: Catalog9-x64 02 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech) Winsock: Catalog9-x64 03 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech) Winsock: Catalog9-x64 04 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech) Winsock: Catalog9-x64 16 C:\Windows\system32\EasyRedirect64.dll [547544 2016-07-01] (EasyTech) Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 8.8.8.8 Tcpip\..\Interfaces\{3B2B300C-B9DD-4A1D-AD0C-08AE295DEFAB}: [NameServer] 208.67.222.222,8.8.8.8 Tcpip\..\Interfaces\{AC5BADE8-21FD-4530-9866-D65771C99DAA}: [DhcpNameServer] 208.67.222.222 8.8.8.8 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\S-1-5-21-79894898-3895581772-2634441730-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-79894898-3895581772-2634441730-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-11-30] (Internet Download Manager, Tonec Inc.) BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-11-30] (Internet Download Manager, Tonec Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-09] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-09] (Oracle Corporation) Toolbar: HKU\S-1-5-21-79894898-3895581772-2634441730-1000 -> Pas de nom - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Pas de fichier FireFox: ======== FF DefaultProfile: eeli9j4q.default-1418442691211 FF ProfilePath: C:\Users\besmellah\AppData\Roaming\Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211 [2016-12-10] FF user.js: detected! => C:\Users\besmellah\AppData\Roaming\Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211\user.js [2016-12-09] FF NetworkProxy: Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211 -> socks_remote_dns", true FF NetworkProxy: Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211 -> type", 0 FF Extension: (Adblock Plus) - C:\Users\besmellah\AppData\Roaming\Mozilla\Firefox\Profiles\eeli9j4q.default-1418442691211\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-12-05] FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-11-16] FF HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF HKU\S-1-5-21-79894898-3895581772-2634441730-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\besmellah\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\besmellah\AppData\Roaming\IDM\idmmzcc5 [2015-08-31] [non signé] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-12-05] () FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [Pas de fichier] FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-12-05] () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [Pas de fichier] FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-09] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-09] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-27] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL [2003-07-14] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-10-27] (Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default [2016-12-10] CHR Extension: (عروض Google التقديمية) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-17] CHR Extension: (محرّر مستندات Google) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-17] CHR Extension: (Google Drive) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-17] CHR Extension: (Youtube) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-17] CHR Extension: (آدبلوك بلس) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-12-05] CHR Extension: (بحث Google) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-17] CHR Extension: (جداول بيانات Google ) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-17] CHR Extension: (مستندات Google في وضع عدم الاتصال) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18] CHR Extension: (آدبلوك بلس) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-05] CHR Extension: (IDM Integration Module) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2016-12-09] CHR Extension: (Chrome Web Store Payments) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-06] CHR Extension: (Gmail) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-17] CHR Extension: (Chrome Media Router) - C:\Users\besmellah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-07] CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-11-30] CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-11-30] ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com) S3 EHttpSrv; C:\Program Files\ESET\ESET Endpoint Security\ehttpsrv.exe [51872 2016-05-24] (ESET) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2815520 2016-10-11] (ESET) S3 eshasrv; C:\Program Files\ESET\ESET Endpoint Security\eshasrv.exe [193696 2016-05-24] (ESET) R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [155600 2016-11-15] (Malwarebytes Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10216688 2016-11-28] (TeamViewer GmbH) R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [Fichier non signé] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S3 vssbrigde64; "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\x64\vssbridge64.exe" [X] S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X] ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [35496 2000-01-01] (Advanced Micro Devices, Inc.) S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-09-28] (Disc Soft Ltd) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [232072 2016-10-07] (ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [212096 2016-10-07] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [177792 2016-10-07] (ESET) R2 ekbdflt; C:\Windows\System32\DRIVERS\ekbdflt.sys [48768 2016-10-07] (ESET) R1 epfw; C:\Windows\System32\DRIVERS\epfw.sys [76416 2016-10-07] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59528 2016-10-13] (ESET) R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [91784 2016-10-07] (ESET) R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [77408 2016-11-15] () R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-02-06] (REALiX(tm)) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-12-10] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2015-09-29] () [Fichier non signé] U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2016-12-09] () S1 AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X] S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-12-10 19:41 - 2016-12-10 19:43 - 00017504 _____ C:\Users\besmellah\Desktop\FRST.txt 2016-12-10 19:41 - 2016-12-10 19:41 - 00000000 ____D C:\FRST 2016-12-10 19:40 - 2016-12-10 19:40 - 02420224 _____ (Farbar) C:\Users\besmellah\Desktop\FRST64.exe 2016-12-10 19:33 - 2016-12-10 19:33 - 00000000 _____ C:\Users\besmellah\Desktop\Nouveau document texte (4).txt 2016-12-10 19:20 - 2016-12-10 19:20 - 00000000 _____ C:\Users\besmellah\Desktop\Nouveau document texte (3).txt 2016-12-10 19:03 - 2016-12-10 19:03 - 00001965 _____ C:\Users\besmellah\Desktop\ESET Smart Security.lnk 2016-12-10 18:50 - 2016-12-10 18:51 - 03137664 _____ (ESET) C:\Users\besmellah\Desktop\eset_smart_security_live_installer.exe 2016-12-10 18:46 - 2016-12-10 18:46 - 00000000 _____ C:\Users\besmellah\Desktop\Nouveau document texte (2).txt 2016-12-10 18:16 - 2016-12-10 18:16 - 00001003 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk 2016-12-10 18:16 - 2016-12-10 18:16 - 00000991 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk 2016-12-10 18:14 - 2016-12-10 18:15 - 14386888 _____ (TeamViewer GmbH) C:\Users\besmellah\Desktop\TeamViewer_Setup.exe 2016-12-10 17:02 - 2016-12-10 17:43 - 00000786 _____ C:\Users\besmellah\Desktop\ZHPDiag.lnk 2016-12-10 17:01 - 2016-12-10 17:02 - 02567680 _____ C:\Users\besmellah\Desktop\ZHPDiag3.exe 2016-12-10 14:55 - 2016-12-10 14:55 - 00001550 _____ C:\Users\besmellah\Desktop\ZHPCleaner.txt 2016-12-10 14:47 - 2016-12-10 14:47 - 00000796 _____ C:\Users\besmellah\Desktop\ZHPCleaner.lnk 2016-12-10 13:23 - 2016-12-10 19:03 - 00000000 ____D C:\ProgramData\ESET 2016-12-10 13:23 - 2016-12-10 19:03 - 00000000 ____D C:\Program Files\ESET 2016-12-09 21:36 - 2016-12-09 21:36 - 00002288 _____ C:\Windows\SysWOW64\EasyRedirectOff.ini 2016-12-09 21:36 - 2016-12-09 21:36 - 00002288 _____ C:\Windows\system32\EasyRedirectOff.ini 2016-12-09 21:36 - 2016-12-09 21:36 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\Easy-Hide-IP VPN 2016-12-09 21:34 - 2016-12-09 21:38 - 00000000 ____D C:\Program Files (x86)\Easy-Hide-IP VPN 2016-12-09 21:34 - 2016-12-09 21:37 - 00000000 ____D C:\Program Files\TAP-Windows 2016-12-09 21:34 - 2016-07-01 00:07 - 00547544 _____ (EasyTech) C:\Windows\system32\EasyRedirect64.dll 2016-12-09 21:34 - 2016-07-01 00:07 - 00388312 _____ (EasyTech) C:\Windows\SysWOW64\EasyRedirect.dll 2016-12-09 21:33 - 2016-12-09 21:33 - 07113208 _____ (Easy-Hide-IP VPN ) C:\Users\besmellah\Downloads\easy-hide-ip-vpn-4.4.exe 2016-12-09 19:14 - 2016-12-10 07:12 - 00000000 ____D C:\Users\besmellah\Desktop\فساتين 2016-12-09 18:08 - 2016-12-10 14:47 - 00000000 ____D C:\Users\besmellah\Desktop\برامج حماية 2016-12-09 17:59 - 2016-12-09 17:59 - 00013972 _____ C:\ComboFix.txt 2016-12-09 17:50 - 2016-12-09 17:59 - 00000000 ____D C:\Qoobox 2016-12-09 14:26 - 2016-12-09 14:26 - 00000000 ____D C:\KVRT_Data 2016-12-09 14:19 - 2016-12-09 14:28 - 00324540 _____ C:\Windows\ntbtlog.txt 2016-12-07 23:27 - 2016-12-07 23:27 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\SUPERAntiSpyware.com 2016-12-07 23:26 - 2016-12-09 18:01 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2016-12-07 23:26 - 2016-12-08 20:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2016-12-07 23:26 - 2016-12-07 23:26 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2016-12-06 19:27 - 2016-12-06 12:26 - 07122944 _____ C:\Users\besmellah\Desktop\ICONE_I2020_20161206.bin 2016-12-06 04:31 - 2016-12-10 19:00 - 00000000 ____D C:\Users\besmellah\AppData\LocalLow\Mozilla 2016-12-05 22:14 - 2016-12-06 06:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-11-30 16:21 - 2016-10-17 16:35 - 00223464 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-12-10 19:33 - 2016-08-07 00:44 - 00000075 _____ C:\Users\besmellah\Desktop\Nouveau document texte.txt 2016-12-10 19:22 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-12-10 19:22 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-12-10 19:18 - 2014-08-04 20:34 - 00000000 ____D C:\Users\besmellah\AppData\Local\CrashDumps 2016-12-10 19:15 - 2016-07-01 17:13 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-12-10 19:15 - 2015-01-29 22:14 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\uTorrent 2016-12-10 19:13 - 2014-12-27 09:54 - 00000840 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-12-10 19:12 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-12-10 19:11 - 2014-03-30 19:56 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\DMCache 2016-12-10 19:10 - 2014-12-25 18:33 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-12-10 19:04 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2016-12-10 18:55 - 2015-07-30 00:11 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-12-10 18:44 - 2015-07-30 00:41 - 00001064 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-12-10 18:37 - 2013-11-15 00:55 - 00179016 _____ C:\Users\besmellah\AppData\Local\GDIPFONTCACHEV1.DAT 2016-12-10 18:20 - 2009-07-14 05:45 - 05279152 _____ C:\Windows\system32\FNTCACHE.DAT 2016-12-10 18:16 - 2014-12-25 18:33 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\TeamViewer 2016-12-10 17:43 - 2014-12-12 20:04 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\ZHP 2016-12-10 16:49 - 2014-01-17 14:33 - 00003968 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{373C4E0F-773C-46C5-9411-725193941D68} 2016-12-10 13:58 - 2016-02-22 13:42 - 00000000 ____D C:\Users\besmellah\AppData\Local\ESET 2016-12-10 13:23 - 2016-02-22 13:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET 2016-12-10 13:03 - 2015-06-27 01:37 - 00000803 _____ C:\Users\besmellah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk 2016-12-09 19:20 - 2015-03-14 11:31 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\IDM 2016-12-09 18:42 - 2015-09-30 11:24 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit 2016-12-09 17:57 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2016-12-09 07:30 - 2015-12-12 15:55 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys 2016-12-07 20:01 - 2015-06-27 01:42 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware 2016-12-06 22:54 - 2015-11-04 18:12 - 00046840 _____ C:\Windows\ZAM_Guard.krnl.trace 2016-12-06 19:16 - 2015-11-04 18:12 - 00055702 _____ C:\Windows\ZAM.krnl.trace 2016-12-06 19:13 - 2011-04-12 10:16 - 00735468 _____ C:\Windows\system32\perfh00C.dat 2016-12-06 19:13 - 2011-04-12 10:16 - 00148390 _____ C:\Windows\system32\perfc00C.dat 2016-12-06 19:13 - 2009-07-14 06:13 - 01662566 _____ C:\Windows\system32\PerfStringBackup.INI 2016-12-06 06:47 - 2014-07-30 12:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-12-05 23:10 - 2015-12-17 21:12 - 00002155 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-12-05 20:02 - 2015-07-30 00:41 - 00004074 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2016-12-05 20:02 - 2015-07-30 00:11 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-12-05 20:02 - 2015-07-30 00:11 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-12-05 20:02 - 2015-07-30 00:11 - 00003940 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-12-05 20:02 - 2014-01-18 17:50 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2016-12-05 20:02 - 2014-01-18 17:49 - 00000000 ____D C:\Windows\system32\Macromed 2016-12-05 18:44 - 2016-08-02 22:14 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-12-05 18:10 - 2014-12-25 15:38 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2016-12-05 17:57 - 2015-03-14 11:30 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager 2016-12-05 17:55 - 2015-09-30 11:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit 2016-12-05 17:55 - 2015-09-30 11:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit 2016-11-30 12:46 - 2013-12-22 18:21 - 00000000 ____D C:\Users\besmellah\AppData\Roaming\vlc ==================== Fichiers à la racine de certains dossiers ======= 2014-08-14 12:53 - 2014-08-14 12:53 - 0000132 _____ () C:\Users\besmellah\AppData\Roaming\Adobe PNG Format CS6 Prefs 2013-11-15 22:12 - 2013-11-15 22:12 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Certains fichiers dans TEMP: ==================== C:\Users\besmellah\AppData\Local\Temp\SpOrder.dll ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2016-12-05 19:35 ==================== Fin de FRST.txt ============================