Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 17-04-2017 01 Exécuté par Utilisateur (administrateur) sur DIVET (18-04-2017 13:14:24) Exécuté depuis C:\Users\Utilisateur\Desktop Profils chargés: Utilisateur (Profils disponibles: Utilisateur) Platform: Windows 10 Home Version 1703 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: "C:\Users\Utilisateur\Downloads\FirefoxPortable\App\Firefox64\firefox.exe" -osint -url "%1") Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (LULU SOFTWARE LIMITED) C:\Program Files\Soda PDF Desktop\creator-ws.exe (Microsoft Corporation) C:\Windows\System32\SecurityHealthService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Piriform Ltd) C:\Users\Utilisateur\AppData\Local\Temp\Rar$EXa0.925\CCleaner64.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Opera Software) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registre (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15794160 2014-08-01] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80368 2014-08-01] (Lenovo(beijing) Limited) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1804432 2015-11-16] (NVIDIA Corporation) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated) HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [561672 2015-06-12] (Vimicro) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare) HKU\S-1-5-21-2708153018-1850461473-996183158-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin Ltd. or its subsidiaries) HKU\S-1-5-21-2708153018-1850461473-996183158-1001\...\Run: [HP ENVY 4520 series (NET)] => C:\Program Files\HP\HP ENVY 4520 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP) HKU\S-1-5-21-2708153018-1850461473-996183158-1001\...\Run: [Fjvsmys] => C:\Users\Utilisateur\AppData\Roaming\DLNMTpt\ie4uinit.exe [224256 2017-03-18] (Microsoft Corporation) HKU\S-1-5-21-2708153018-1850461473-996183158-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft) ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2015-02-23] ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fjvsmys.lnk [2017-04-18] ShortcutTarget: Fjvsmys.lnk -> C:\Users\Utilisateur\AppData\Roaming\DLNMTpt\ie4uinit.exe (Microsoft Corporation) Startup: C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Veynjf.lnk [2017-04-13] ShortcutTarget: Veynjf.lnk -> C:\Users\UTILIS~1\AppData\Roaming\uRg6u\ie4uinit.exe (Pas de fichier) GroupPolicy: Restriction - Chrome <======= ATTENTION GroupPolicy-x32: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{2f6262e7-50ec-461a-a268-117062789bb4}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKU\S-1-5-21-2708153018-1850461473-996183158-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-2708153018-1850461473-996183158-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp:/// SearchScopes: HKLM -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-2708153018-1850461473-996183158-1001 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-2708153018-1850461473-996183158-1001 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft) BHO-x32: Soda PDF Desktop Helper -> {A2792EEC-6618-4C4C-8ECF-B51ECB5DC2A1} -> C:\Program Files (x86)\Soda PDF Desktop\creator-ie-helper.dll [2016-10-21] (LULU SOFTWARE LIMITED) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll => Pas de fichier BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft) Toolbar: HKLM-x32 - Soda PDF Desktop Toolbar - {D53D09FE-B1AC-4EE8-AE26-FD43D8B4B62F} - C:\Program Files (x86)\Soda PDF Desktop\creator-ie-plugin.dll [2016-10-21] (LULU SOFTWARE LIMITED) FireFox: ======== FF ProfilePath: C:\Users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\f0w77nbj.default-1491829850359 [2017-04-18] FF Homepage: Mozilla\Firefox\Profiles\f0w77nbj.default-1491829850359 -> hxxps://www.google.com/ FF Extension: (Disable Prefetch) - C:\Users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\f0w77nbj.default-1491829850359\features\{dee456e5-1291-490d-9980-ac3b5b990211}\disable-prefetch@mozilla.org.xpi [2017-04-10] FF Extension: (Site Deployment Checker) - C:\Program Files\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-24] [non signé] FF HKLM\...\Firefox\Extensions: [soda_pdf_desktop_conv@sodapdf.com] - C:\Program Files\Soda PDF Desktop\resources\sodapdfdesktopfirefoxextension FF Extension: (Soda PDF Desktop Creator) - C:\Program Files\Soda PDF Desktop\resources\sodapdfdesktopfirefoxextension [2016-12-03] [non signé] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-13] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-13] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.) FF Plugin-x32: Soda PDF Desktop -> C:\Program Files (x86)\Soda PDF Desktop\np-previewer.dll [2016-10-21] (LULU SOFTWARE LIMITED) FF Plugin HKU\.DEFAULT: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [Pas de fichier] FF Plugin HKU\S-1-5-21-2708153018-1850461473-996183158-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Utilisateur\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-12-07] (Citrix Online) FF Plugin HKU\S-1-5-21-2708153018-1850461473-996183158-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [Pas de fichier] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 DevicesFlowUserSvc; C:\WINDOWS\System32\DevicesFlowBroker.dll [689152 2017-03-18] (Microsoft Corporation) S3 DevicesFlowUserSvc_4624c; C:\WINDOWS\system32\svchost.exe [47664 2017-03-18] (Microsoft Corporation) S3 DevicesFlowUserSvc_4624c; C:\WINDOWS\SysWOW64\svchost.exe [40904 2017-03-18] (Microsoft Corporation) R2 DusmSvc; C:\WINDOWS\System32\dusmsvc.dll [302592 2017-03-18] (Microsoft Corporation) S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1099280 2017-03-28] (Garmin Ltd. or its subsidiaries) R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [Fichier non signé] S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company) R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-02] (Intel Corporation) R2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2016-10-28] (IObit) S3 IpxlatCfgSvc; C:\WINDOWS\System32\IpxlatCfg.dll [64000 2017-03-18] (Microsoft Corporation) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) S3 NaturalAuthentication; C:\WINDOWS\System32\NaturalAuth.dll [723968 2017-03-18] (Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Fichier non signé] R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation) R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Fichier non signé] R2 SecurityHealthService; C:\WINDOWS\system32\SecurityHealthService.exe [335808 2017-03-18] (Microsoft Corporation) S3 SEMgrSvc; C:\WINDOWS\system32\SEMgrSvc.dll [1191424 2017-03-18] (Microsoft Corporation) S3 Soda PDF Desktop; C:\Program Files\Soda PDF Desktop\ws.exe [2529744 2016-10-21] (LULU SOFTWARE LIMITED) S3 Soda PDF Desktop CrashHandler; C:\Program Files\Soda PDF Desktop\crash-handler-ws.exe [925648 2016-10-21] (LULU SOFTWARE LIMITED) R2 Soda PDF Desktop Creator; C:\Program Files\Soda PDF Desktop\creator-ws.exe [733648 2016-10-21] (LULU SOFTWARE LIMITED) S3 spectrum; C:\WINDOWS\system32\spectrum.exe [891904 2017-03-18] (Microsoft Corporation) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated) R3 TokenBroker; C:\WINDOWS\System32\TokenBroker.dll [1054720 2017-03-18] (Microsoft Corporation) R3 TokenBroker; C:\WINDOWS\SysWOW64\TokenBroker.dll [799232 2017-03-18] (Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WFDSConMgrSvc; C:\WINDOWS\System32\wfdsconmgrsvc.dll [555008 2017-03-18] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) S3 wlpasvc; C:\WINDOWS\System32\lpasvc.dll [1295360 2017-03-18] (Microsoft Corporation) S3 xbgm; C:\WINDOWS\System32\xbgmsvc.dll [301216 2017-03-18] (Microsoft Corporation) S3 XboxGipSvc; C:\WINDOWS\System32\XboxGipSvc.dll [18944 2017-03-18] (Microsoft Corporation) ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 BthLEEnum; C:\WINDOWS\system32\DRIVERS\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [96768 2017-03-18] (Microsoft Corporation) R3 CAD; C:\WINDOWS\System32\drivers\CAD.sys [53664 2017-03-18] (Microsoft Corporation) S2 CldFlt; C:\WINDOWS\System32\drivers\cldflt.sys [12288 2017-03-18] (Microsoft Corporation) S3 iaLPSS2i_GPIO2_BXT_P; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [85504 2017-03-18] (Intel Corporation) S3 iaLPSS2i_I2C_BXT_P; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [168448 2017-03-18] (Intel Corporation) R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [74344 2013-07-03] (Intel Corporation) S3 mausbhost; C:\WINDOWS\System32\drivers\mausbhost.sys [405408 2017-03-18] (Microsoft Corporation) S3 mausbip; C:\WINDOWS\System32\drivers\mausbip.sys [51104 2017-03-18] (Microsoft Corporation) R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [251832 2017-04-09] (Malwarebytes) R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [122368 2017-03-18] (Microsoft Corporation) S3 nvdimmn; C:\WINDOWS\System32\drivers\nvdimmn.sys [80896 2017-03-18] (Microsoft Corporation) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvltwu.inf_amd64_0221ce4ec0827f74\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation) S3 pmem; C:\WINDOWS\System32\drivers\pmem.sys [101376 2017-03-18] (Microsoft Corporation) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated) S3 SpatialGraphFilter; C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [40352 2017-03-20] (Microsoft Corporation) R3 vm331avs; C:\WINDOWS\System32\Drivers\vm331avs.sys [802312 2015-06-12] (Vimicro Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) S3 WinNat; C:\WINDOWS\System32\drivers\winnat.sys [217088 2017-03-18] (Microsoft Corporation) S3 catchme; \??\C:\Users\UTILIS~1\AppData\Local\Temp\catchme.sys [X] <==== ATTENTION ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) NETSVC: NaturalAuthentication -> C:\Windows\System32\NaturalAuth.dll (Microsoft Corporation) NETSVC: xbgm -> C:\Windows\System32\xbgmsvc.dll (Microsoft Corporation) NETSVC: TokenBroker -> C:\Windows\System32\TokenBroker.dll (Microsoft Corporation) NETSVC: XboxGipSvc -> C:\Windows\System32\XboxGipSvc.dll (Microsoft Corporation) NETSVCx32: TokenBroker -> C:\Windows\SysWOW64\TokenBroker.dll (Microsoft Corporation) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-04-18 13:14 - 2017-04-18 13:15 - 00019143 _____ C:\Users\Utilisateur\Desktop\FRST.txt 2017-04-18 13:14 - 2017-04-18 13:14 - 00000000 ____D C:\FRST 2017-04-18 13:13 - 2017-04-18 13:13 - 02424832 _____ (Farbar) C:\Users\Utilisateur\Desktop\FRST64.exe 2017-04-18 11:26 - 2017-04-18 11:27 - 08217746 _____ C:\Users\Utilisateur\Downloads\ccsetup528.zip 2017-04-18 08:11 - 2017-04-18 08:11 - 00205312 _____ C:\Users\Utilisateur\Downloads\triplette_veteran_Resultats Poules.xls 2017-04-18 07:17 - 2017-04-18 07:17 - 00000000 ____D C:\WINDOWS\system32\6143 2017-04-18 07:17 - 2017-04-18 07:17 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\DLNMTpt 2017-04-17 21:24 - 2017-04-17 21:24 - 00045568 _____ C:\Users\Utilisateur\Downloads\demande licence 2017 (sur GESLICO) 6 (2).xls 2017-04-17 17:37 - 2017-04-17 17:37 - 00045568 _____ C:\Users\Utilisateur\Downloads\demande licence 2017 (sur GESLICO) 6 (1).xls 2017-04-17 17:35 - 2017-04-17 17:36 - 00019968 _____ C:\Users\Utilisateur\Downloads\demande licence 2017 (sur GESLICO) 6.xls 2017-04-15 13:01 - 2017-04-15 13:01 - 00136406 _____ C:\Users\Utilisateur\Desktop\ZHPDiag.txt 2017-04-15 12:52 - 2017-04-15 12:56 - 00000906 _____ C:\Users\Utilisateur\Desktop\ZHPDiag.lnk 2017-04-14 21:16 - 2017-04-14 21:16 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-04-14 21:16 - 2017-04-14 21:16 - 00002124 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2017-04-13 19:25 - 2017-04-13 19:25 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\DBG 2017-04-13 13:36 - 2017-04-18 12:55 - 00002830 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2017-04-13 13:33 - 2017-04-13 13:33 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2017-04-13 13:30 - 2017-04-13 13:30 - 00000020 ___SH C:\Users\Utilisateur\ntuser.ini 2017-04-13 12:15 - 2017-04-13 12:15 - 00000000 ____D C:\Windows.old 2017-04-13 12:14 - 2017-04-13 12:14 - 23680512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 23675392 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 20505600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 19334144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 11869696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 08319392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-04-13 12:14 - 2017-04-13 12:14 - 08247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 06756920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 05477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 03672064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-04-13 12:14 - 2017-04-13 12:14 - 02957824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-04-13 12:14 - 2017-04-13 12:14 - 02444184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-04-13 12:14 - 2017-04-13 12:14 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01604312 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01411640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01356800 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01323880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-04-13 12:14 - 2017-04-13 12:14 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 01024416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-04-13 12:14 - 2017-04-13 12:14 - 00986592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2017-04-13 12:14 - 2017-04-13 12:14 - 00626520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2017-04-13 12:14 - 2017-04-13 12:14 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2017-04-13 12:14 - 2017-04-13 12:14 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2017-04-13 12:14 - 2017-04-13 12:14 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-04-13 12:14 - 2017-04-13 12:14 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00205728 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2017-04-13 12:14 - 2017-04-13 12:14 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys 2017-04-13 12:14 - 2017-04-13 12:14 - 00032004 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin 2017-04-13 12:12 - 2017-04-13 12:12 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-04-13 12:12 - 2017-04-13 12:12 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2017-04-13 12:11 - 2017-04-13 12:11 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2017-04-13 12:11 - 2017-04-13 11:19 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2017-04-13 12:08 - 2017-04-13 12:08 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2017-04-13 12:08 - 2017-04-13 12:08 - 00000000 ____D C:\Program Files\Reference Assemblies 2017-04-13 12:08 - 2017-04-13 12:08 - 00000000 ____D C:\Program Files\MSBuild 2017-04-13 12:08 - 2017-04-13 12:08 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2017-04-13 12:08 - 2017-04-13 12:08 - 00000000 ____D C:\Program Files (x86)\MSBuild 2017-04-13 12:07 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2017-04-13 12:07 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2017-04-13 12:07 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2017-04-13 12:07 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2017-04-13 12:07 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2017-04-13 12:07 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2017-04-13 11:51 - 2017-04-13 11:54 - 00007623 _____ C:\WINDOWS\diagwrn.xml 2017-04-13 11:51 - 2017-04-13 11:54 - 00007623 _____ C:\WINDOWS\diagerr.xml 2017-04-13 11:44 - 2017-04-18 12:57 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-04-13 11:44 - 2017-04-18 12:55 - 00003542 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2017-04-13 11:44 - 2017-04-18 12:55 - 00003510 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2017-04-13 11:44 - 2017-04-18 12:55 - 00003384 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1481112355 2017-04-13 11:44 - 2017-04-18 12:55 - 00002762 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask 2017-04-13 11:44 - 2017-04-18 12:55 - 00002720 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP ENVY 4520 series 2017-04-13 11:44 - 2017-04-18 12:55 - 00002612 _____ C:\WINDOWS\System32\Tasks\Heums 2017-04-13 11:44 - 2017-04-18 12:55 - 00002306 _____ C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_Utilisateur 2017-04-13 11:44 - 2017-04-18 11:26 - 00004172 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{826B327A-D8CC-4917-8726-056161E47E54} 2017-04-13 11:44 - 2017-04-13 11:44 - 00002810 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2708153018-1850461473-996183158-1001 2017-04-13 11:44 - 2017-04-13 11:44 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD 2017-04-13 11:44 - 2014-04-16 00:47 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2101346286-3973201258-1926398258-1001 2017-04-13 11:42 - 2017-04-18 13:04 - 01960346 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-04-13 11:32 - 2017-04-13 11:32 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-04-13 11:30 - 2017-04-13 11:30 - 00000000 ____D C:\ProgramData\USOShared 2017-04-13 11:28 - 2017-04-13 11:34 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate 2017-04-13 11:25 - 2017-04-14 22:03 - 00000000 ____D C:\Users\Utilisateur 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\Voisinage réseau 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\Voisinage d'impression 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\Modèles 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\Mes documents 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\Menu Démarrer 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\Documents\Mes vidéos 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\Documents\Mes images 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\Documents\Ma musique 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes 2017-04-13 11:25 - 2017-04-13 11:25 - 00000000 _SHDL C:\Users\Utilisateur\AppData\Local\Historique 2017-04-13 11:24 - 2017-04-13 11:24 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf 2017-04-13 11:24 - 2017-04-13 11:24 - 00000000 ____D C:\Program Files\Common Files\Atheros 2017-04-13 11:24 - 2017-04-13 11:24 - 00000000 ____D C:\Program Files (x86)\USB Camera 2017-04-13 11:24 - 2016-12-29 15:16 - 06384576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2017-04-13 11:24 - 2016-12-29 15:16 - 02475968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2017-04-13 11:24 - 2016-12-29 15:16 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2017-04-13 11:24 - 2016-12-29 15:16 - 00546752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2017-04-13 11:24 - 2016-12-29 15:16 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2017-04-13 11:24 - 2016-12-29 15:16 - 00147000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll 2017-04-13 11:24 - 2016-12-29 15:16 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2017-04-13 11:24 - 2016-12-29 15:16 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2017-04-13 11:24 - 2016-12-22 01:59 - 07651057 _____ C:\WINDOWS\system32\nvcoproc.bin 2017-04-13 11:23 - 2017-04-18 12:58 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2017-04-13 11:23 - 2017-04-13 11:28 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-04-13 11:23 - 2017-04-13 11:23 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat 2017-04-13 11:23 - 2017-04-13 11:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-04-13 11:23 - 2017-04-13 11:23 - 00000000 ____D C:\Program Files\Intel 2017-04-13 11:23 - 2017-04-13 11:23 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin 2017-04-13 11:23 - 2016-11-02 00:05 - 00103952 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL 2017-04-13 11:23 - 2016-11-02 00:05 - 00099848 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL 2017-04-13 11:22 - 2017-04-13 11:22 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf 2017-04-13 11:22 - 2017-03-18 22:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2017-04-13 11:21 - 2017-04-13 11:21 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2017-04-13 11:21 - 2017-04-13 11:21 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf 2017-04-13 11:21 - 2017-04-13 11:21 - 00000000 ____D C:\Program Files\Synaptics 2017-04-13 11:19 - 2017-04-18 12:22 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-04-13 11:19 - 2017-04-15 19:41 - 00397672 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-04-13 10:03 - 2017-04-13 13:30 - 00000000 ___DC C:\WINDOWS\Panther 2017-04-13 10:03 - 2017-04-13 10:17 - 00000000 ___HD C:\$WINDOWS.~BT 2017-04-13 09:59 - 2017-04-13 10:03 - 00000036 _____ C:\WINDOWS\progress.ini 2017-04-13 09:23 - 2017-04-13 13:30 - 00000000 ____D C:\Windows10Upgrade 2017-04-13 09:23 - 2017-04-13 13:29 - 00000000 ___HD C:\$GetCurrent 2017-04-13 09:23 - 2017-04-13 09:23 - 00000731 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assistant Mise à niveau de Windows 10.lnk 2017-04-13 09:23 - 2017-04-13 09:23 - 00000719 _____ C:\Users\Utilisateur\Desktop\Assistant Mise à niveau de Windows 10.lnk 2017-04-13 09:22 - 2017-04-13 09:23 - 06581904 _____ (Microsoft Corporation) C:\Users\Utilisateur\Downloads\Windows10Upgrade9252.exe 2017-04-13 05:17 - 2017-04-15 19:26 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\uRg6u 2017-04-13 05:17 - 2017-04-13 11:29 - 00000000 ____D C:\WINDOWS\system32\0731 2017-04-12 21:19 - 2017-03-28 07:28 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2017-04-12 21:18 - 2017-03-28 07:37 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DdcWnsListener.dll 2017-04-10 08:06 - 2017-04-15 19:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2017-04-10 08:06 - 2017-04-15 19:19 - 00000000 ____D C:\Program Files (x86)\ZHPFix 2017-04-10 08:05 - 2017-04-10 08:05 - 03521617 _____ (Nicolas Coolman ) C:\Users\Utilisateur\Downloads\ZHPFix.exe 2017-04-10 07:57 - 2017-04-10 07:57 - 14257832 _____ (SimpleStar) C:\Users\Utilisateur\Downloads\SimpleDriverUpdaterSetup_ppc2.exe 2017-04-10 05:58 - 2017-04-15 12:59 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\ZHP 2017-04-10 05:53 - 2017-04-10 05:58 - 02716672 _____ C:\Users\Utilisateur\Downloads\ZHPDiag3.exe 2017-04-09 17:09 - 2017-04-09 18:09 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\jbM6R6P 2017-04-09 14:02 - 2017-04-09 14:02 - 00000000 ____D C:\Users\Utilisateur\Downloads\FirefoxPortable 2017-04-09 13:57 - 2017-04-09 13:59 - 96193320 _____ (PortableApps.com) C:\Users\Utilisateur\Downloads\FirefoxPortable_52.0.2_French.paf.exe 2017-04-07 07:28 - 2017-04-07 07:28 - 00000000 ____D C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A} 2017-04-06 07:04 - 2017-04-06 07:04 - 00001175 _____ C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Mozilla Firefox.lnk 2017-04-06 07:01 - 2017-04-06 07:01 - 00000000 ____D C:\Program Files\Mozilla Firefox 2017-04-06 06:57 - 2017-04-06 06:57 - 47716112 _____ C:\Users\Utilisateur\Downloads\Firefox Setup 52.0.2.exe 2017-04-06 05:50 - 2017-04-06 05:50 - 00151792 _____ C:\Users\Utilisateur\Downloads\firefox 2017-04-06 05:47 - 2017-04-06 05:47 - 57929396 _____ C:\Users\Utilisateur\Downloads\firefox-52.0.2.tar.bz2 2017-04-01 06:27 - 2017-04-13 11:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2017-03-28 13:03 - 2017-03-28 13:03 - 00196593 _____ C:\Users\Utilisateur\Documents\Lettre du mois de mars.odt 2017-03-22 23:15 - 2017-04-13 11:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.2 2017-03-22 23:14 - 2017-03-22 23:15 - 00000000 ____D C:\Program Files (x86)\LibreOffice 5 2017-03-20 07:12 - 2017-03-18 22:59 - 00034390 _____ C:\WINDOWS\Core.xml 2017-03-20 07:11 - 2017-04-13 11:45 - 00000000 ____D C:\WINDOWS\HoloShell 2017-03-20 07:11 - 2017-03-20 07:11 - 00000000 ____D C:\WINDOWS\system32\Hydrogen 2017-03-20 07:11 - 2017-03-20 07:11 - 00000000 ____D C:\WINDOWS\SKB 2017-03-20 07:11 - 2017-03-20 07:11 - 00000000 ____D C:\WINDOWS\OCR 2017-03-20 07:11 - 2017-03-20 07:11 - 00000000 ____D C:\ProgramData\WindowsHolographicDevices 2017-03-20 07:10 - 2017-04-18 13:04 - 00883216 _____ C:\WINDOWS\system32\perfh00C.dat 2017-03-20 07:10 - 2017-04-18 13:04 - 00172286 _____ C:\WINDOWS\system32\perfc00C.dat 2017-03-20 07:10 - 2017-03-20 07:10 - 00351124 _____ C:\WINDOWS\system32\perfi00C.dat 2017-03-20 07:10 - 2017-03-20 07:10 - 00040694 _____ C:\WINDOWS\system32\perfd00C.dat 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\SysWOW64\fr 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\SysWOW64\0409 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\system32\winrm 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\system32\WCN 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\system32\slmgr 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\system32\fr 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\system32\0409 2017-03-20 07:10 - 2017-03-20 07:10 - 00000000 ____D C:\WINDOWS\DigitalLocker 2017-03-20 07:10 - 2017-03-18 07:54 - 02021680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2017-03-20 07:10 - 2017-03-18 07:40 - 00387416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll 2017-03-20 07:10 - 2017-03-18 07:40 - 00276400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll 2017-03-20 07:10 - 2017-03-18 07:11 - 01339352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll 2017-03-20 07:10 - 2017-03-18 07:00 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx 2017-03-20 07:10 - 2017-03-18 07:00 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll 2017-03-20 07:10 - 2017-03-18 06:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll 2017-03-20 07:10 - 2017-03-18 06:59 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmerror.dll 2017-03-20 07:10 - 2017-03-18 06:58 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll 2017-03-20 07:10 - 2017-03-18 06:57 - 00249016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll 2017-03-20 07:10 - 2017-03-18 06:57 - 00153976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpps.dll 2017-03-20 07:10 - 2017-03-18 06:56 - 09261568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL 2017-03-20 07:10 - 2017-03-18 06:56 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll 2017-03-20 07:10 - 2017-03-18 06:55 - 00566272 _____ (Microsoft Corporation) C:\WINDOWS\system32\quickassist.exe 2017-03-20 07:10 - 2017-03-18 06:54 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\unregmp2.exe 2017-03-20 07:10 - 2017-03-18 06:45 - 13381120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2017-03-20 07:10 - 2017-03-18 06:44 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll 2017-03-20 07:10 - 2017-03-18 06:44 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx 2017-03-20 07:10 - 2017-03-18 06:44 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll 2017-03-20 07:10 - 2017-03-18 06:44 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmerror.dll 2017-03-20 07:10 - 2017-03-18 06:42 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll 2017-03-20 07:10 - 2017-03-18 06:41 - 09261568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL 2017-03-20 07:10 - 2017-03-18 06:41 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll 2017-03-20 07:10 - 2017-03-18 06:40 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quickassist.exe 2017-03-20 07:10 - 2017-03-18 06:39 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unregmp2.exe 2017-03-20 07:10 - 2017-03-18 06:37 - 12227072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2017-03-20 07:10 - 2017-03-18 05:00 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.tlb 2017-03-20 07:10 - 2017-03-18 05:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\amcompat.tlb 2017-03-20 07:10 - 2017-03-18 04:52 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.tlb 2017-03-20 07:10 - 2017-03-18 04:52 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\amcompat.tlb ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-04-18 13:13 - 2015-11-27 18:15 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\ClassicShell 2017-04-18 12:58 - 2014-07-30 18:26 - 00000000 __SHD C:\Users\Utilisateur\IntelGraphicsProfiles 2017-04-18 12:57 - 2017-03-18 13:40 - 00524288 _____ C:\WINDOWS\system32\config\BBI 2017-04-18 12:57 - 2016-09-25 04:25 - 00000000 ____D C:\ProgramData\NVIDIA 2017-04-18 12:57 - 2015-04-19 14:17 - 00000302 _____ C:\WINDOWS\Tasks\Uninstaller_SkipUac_Utilisateur.job 2017-04-18 12:24 - 2017-03-18 23:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-04-18 12:24 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-04-18 08:29 - 2015-11-16 11:41 - 00000000 ____D C:\ProgramData\ProductData 2017-04-18 05:18 - 2014-08-01 12:56 - 00000000 ____D C:\ProgramData\Energy Manager 2017-04-17 21:41 - 2015-04-25 06:32 - 00000000 ____D C:\Users\Utilisateur\Documents\PETANQUE 2017-04-17 08:04 - 2016-11-16 19:01 - 00000000 ____D C:\Users\Utilisateur\AppData\LocalLow\Mozilla 2017-04-15 20:12 - 2015-10-26 18:41 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\Windows Live 2017-04-15 19:39 - 2014-09-30 13:24 - 00000290 __RSH C:\ProgramData\ntuser.pol 2017-04-15 19:36 - 2015-04-19 10:07 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\ZHP 2017-04-14 21:31 - 2017-03-18 23:01 - 00000000 ____D C:\WINDOWS\INF 2017-04-14 05:17 - 2017-03-18 22:51 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-04-14 04:59 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\appcompat 2017-04-13 15:46 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-04-13 15:46 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-04-13 13:48 - 2014-04-15 17:57 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\Packages 2017-04-13 13:36 - 2015-11-26 10:46 - 00002460 _____ C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-04-13 13:36 - 2015-11-26 10:46 - 00000000 ___RD C:\Users\Utilisateur\OneDrive 2017-04-13 13:30 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-04-13 13:30 - 2015-11-26 10:40 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-04-13 12:19 - 2017-03-18 23:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2017-04-13 12:15 - 2017-03-18 23:06 - 00000000 ____D C:\WINDOWS\Setup 2017-04-13 12:08 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2017-04-13 12:08 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\MUI 2017-04-13 11:56 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\rescache 2017-04-13 11:55 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows NT 2017-04-13 11:55 - 2017-03-18 13:40 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2017-04-13 11:54 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2017-04-13 11:51 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Registration 2017-04-13 11:51 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2017-04-13 11:44 - 2015-11-26 09:53 - 00023208 _____ C:\WINDOWS\system32\emptyregdb.dat 2017-04-13 11:42 - 2017-03-18 23:03 - 00000000 __RHD C:\Users\Public\Libraries 2017-04-13 11:34 - 2017-01-23 14:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashPeak Slimjet 2017-04-13 11:34 - 2016-12-26 06:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-04-13 11:34 - 2016-12-03 08:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soda PDF Desktop 2017-04-13 11:34 - 2016-11-25 13:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller 2017-04-13 11:34 - 2016-09-05 22:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell 2017-04-13 11:34 - 2015-10-26 18:44 - 00000000 ____D C:\WINDOWS\fr 2017-04-13 11:34 - 2015-05-19 17:18 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-04-13 11:34 - 2015-05-19 17:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-04-13 11:34 - 2015-03-02 13:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2017-04-13 11:34 - 2015-02-23 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2017-04-13 11:34 - 2014-07-30 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2017-04-13 11:34 - 2014-04-15 18:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-04-13 11:34 - 2014-04-15 18:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy Burner 2017-04-13 11:31 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-04-13 11:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2017-04-13 11:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\spool 2017-04-13 11:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-04-13 11:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-04-13 11:30 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2017-04-13 11:30 - 2017-03-18 23:03 - 00000000 ____D C:\ProgramData\USOPrivate 2017-04-13 11:30 - 2015-02-23 11:17 - 00000000 ____D C:\WINDOWS\SysWOW64\spool 2017-04-13 11:30 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared 2017-04-13 11:30 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared 2017-04-13 11:29 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-04-13 11:29 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\InputMethod 2017-04-13 11:29 - 2016-12-09 18:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashIntegro 2017-04-13 11:29 - 2015-11-16 07:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft 2017-04-13 11:29 - 2014-08-01 12:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo 2017-04-13 11:28 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-04-13 11:28 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy 2017-04-13 11:27 - 2017-01-23 10:48 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Avanquest 2017-04-13 11:24 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\System 2017-04-13 11:24 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\Help 2017-04-13 11:24 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2017-04-13 11:24 - 2014-09-03 21:15 - 00000000 ____D C:\Temp 2017-04-13 06:56 - 2015-03-11 15:30 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\CrashDumps 2017-04-12 22:07 - 2014-07-30 17:58 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2017-04-12 22:07 - 2014-07-30 17:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2017-04-12 21:59 - 2014-04-15 18:43 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-04-12 21:57 - 2014-04-15 18:43 - 148601744 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-04-11 05:28 - 2015-11-16 11:41 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\IObit 2017-04-09 20:37 - 2016-12-26 06:59 - 00251832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2017-04-09 14:15 - 2014-04-15 18:14 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\Mozilla 2017-04-08 20:25 - 2015-11-16 11:41 - 00000000 ____D C:\ProgramData\IObit 2017-04-08 20:02 - 2015-11-16 11:41 - 00000000 ____D C:\Program Files (x86)\IObit 2017-04-08 05:25 - 2014-04-15 18:39 - 00532136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2017-04-07 07:28 - 2015-11-16 11:41 - 00000000 ____D C:\Users\Utilisateur\AppData\LocalLow\IObit 2017-04-06 07:01 - 2014-04-15 18:12 - 00000965 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-04-04 21:21 - 2017-03-15 22:45 - 00000000 ____D C:\Users\Utilisateur\Documents\ETIQUETTES POTAGER 2017-04-04 17:46 - 2016-05-13 10:29 - 00000000 ____D C:\Users\Utilisateur\Documents\PDF ET AUTRES DOCUMENTS JARDINAGE 2017-04-03 18:56 - 2017-03-18 23:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-04-03 18:56 - 2017-03-18 23:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-04-01 13:06 - 2016-12-26 06:59 - 00077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2017-04-01 06:28 - 2015-08-28 14:01 - 00000000 ____D C:\Program Files (x86)\Garmin 2017-04-01 06:28 - 2014-08-04 07:03 - 00000000 ____D C:\ProgramData\Package Cache 2017-04-01 06:27 - 2015-08-28 14:01 - 00000000 ____D C:\ProgramData\Garmin 2017-03-20 07:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SystemResources 2017-03-20 07:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SystemApps 2017-03-20 07:11 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2017-03-20 07:11 - 2017-03-18 22:59 - 20414976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 17048064 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 07138816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Havok.Physics.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 06238208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons000c.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 06238208 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons000c.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 03162112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SnippingTool.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000c.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 02264064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000c.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsCpl.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 01311744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsCpl.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 01161216 ____R (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.Capture.UX.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00867328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mblctr.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msTextPrediction.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_HoloLens_Environment.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00528896 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Feedback.Analog.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00299624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpendp.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicRuntimes.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellAPI.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00269640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpendp.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialStore.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\svf.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSHExtensions.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreShellAPI.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\hwrreg.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpdr.sys 2017-03-20 07:11 - 2017-03-18 22:59 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinput.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00137112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipRenew.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsClassExtension.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00128200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Display.BrightnessOverride.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00125015 ____R C:\WINDOWS\system32\CaptureCountdown.hcp 2017-03-20 07:11 - 2017-03-18 22:59 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopView.Internal.Broker.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00119017 ____R C:\WINDOWS\system32\CaptureBrackets.hcp 2017-03-20 07:11 - 2017-03-18 22:59 - 00108032 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00099784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Display.BrightnessOverride.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00094624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\datamarketsvc.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShellCompositor.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00052224 ____R (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.Capture.Pipeline.ProxyStub.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\DFDWiz.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RotMgr.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hwrcomp.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfdts.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.ProxyStub.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00040352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SpatialGraphFilter.sys 2017-03-20 07:11 - 2017-03-18 22:59 - 00035840 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetppui.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00030624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys 2017-03-20 07:11 - 2017-03-18 22:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorPerformanceEvents.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Feedback.Analog.ProxyStub.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnpinst.exe 2017-03-20 07:11 - 2017-03-18 22:59 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorCustomAdbAlgorithm.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopView.Internal.Broker.ProxyStub.dll 2017-03-20 07:11 - 2017-03-18 22:59 - 00017806 ____R C:\WINDOWS\system32\CaptureToast.hcp 2017-03-20 07:11 - 2017-03-18 22:59 - 00014336 _____ C:\WINDOWS\system32\HolographicShareInterop.ProxyStub.dll 2017-03-20 07:11 - 2017-03-18 22:56 - 00037280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\terminpt.sys 2017-03-20 07:11 - 2017-03-18 22:56 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpbus.sys 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\dsc 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\PrintDialog 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ___RD C:\WINDOWS\MiracastView 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\setup 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\es-MX 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Com 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\setup 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\migwiz 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\lv-LV 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\lt-LT 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\et-EE 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\es-MX 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\en-GB 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\system32\Com 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\WINDOWS\IME 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Windows Defender 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files\Common Files\System 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-03-20 07:10 - 2017-03-18 23:03 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2017-03-20 07:10 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\system32\Dism 2017-03-20 07:10 - 2017-03-18 13:40 - 00000000 ____D C:\WINDOWS\servicing ==================== Fichiers à la racine de certains dossiers ======= 2017-01-01 18:25 - 2017-01-19 14:04 - 0004608 _____ () C:\Users\Utilisateur\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-02-25 21:29 - 2015-02-25 21:29 - 0000017 _____ () C:\Users\Utilisateur\AppData\Local\resmon.resmoncfg 2015-02-23 11:07 - 2016-11-03 10:32 - 0004218 _____ () C:\ProgramData\hpzinstall.log 2015-10-25 14:06 - 2015-10-25 14:06 - 0000016 _____ () C:\ProgramData\mntemp 2015-10-25 14:06 - 2015-10-25 14:06 - 0005050 _____ () C:\ProgramData\wmzddnmb.cix Fichiers à déplacer ou supprimer: ==================== C:\Users\Utilisateur\DropboxInstaller.exe ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2017-04-13 11:19 ==================== Fin de FRST.txt ============================