Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 25-06-2017 01 Exécuté par smits (administrateur) sur LAPTOP-UD6HVOF1 (28-06-2017 12:29:39) Exécuté depuis C:\Users\smits\Desktop Profils chargés: smits (Profils disponibles: defaultuser0 & smits) Platform: Windows 10 Home Version 1607 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (AMD) C:\Windows\System32\atiesrxx.exe (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTDevMgr.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (pdfforge GmbH) C:\Program Files\PDF Architect 5\creator-ws.exe (© pdfforge GmbH.) C:\Program Files (x86)\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe (HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe () C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (AMD) C:\Windows\System32\atieclxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartProvider.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTServer.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe (HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe (Google Inc.) C:\Users\smits\AppData\Local\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Users\smits\AppData\Local\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (Google Inc.) C:\Users\smits\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\smits\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\smits\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\smits\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe (Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe (Google Inc.) C:\Users\smits\AppData\Local\Google\Chrome\Application\chrome.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.1439_none_7efe016621f50bd0\TiWorker.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\backgroundTaskHost.exe (Google Inc.) C:\Users\smits\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registre (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843784 2016-08-08] (Realtek Semiconductor) HKLM\...\Run: [StartCN] => c:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6625672 2016-08-09] (Advanced Micro Devices, Inc.) HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [231640 2016-05-13] (Realtek Semiconductor Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [4168296 2016-08-22] (Synaptics Incorporated) HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-06-15] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [263232 2017-05-31] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [705784 2016-06-20] (HP Inc.) HKU\S-1-5-21-1035901381-1415117216-1648240756-1001\...\Run: [Google Update] => C:\Users\smits\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.) ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP JumpStart Launch.lnk [2016-11-03] ShortcutTarget: HP JumpStart Launch.lnk -> c:\Windows\Installer\{B90CB0DE-2E60-41C4-9857-466EB98192BF}\HPlogo_blue.ico () ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{1277975b-c26c-4be4-9450-f603b9c4ebe1}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{a609ffe5-4d6c-4590-8188-3e05d91768de}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE HKU\S-1-5-21-1035901381-1415117216-1648240756-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE HKU\S-1-5-21-1035901381-1415117216-1648240756-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE SearchScopes: HKLM -> {1B294157-BB19-47E4-8219-8E52325D75B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 -> {1B294157-BB19-47E4-8219-8E52325D75B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-21-1035901381-1415117216-1648240756-1001 -> {1B294157-BB19-47E4-8219-8E52325D75B9} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-20] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-20] (Microsoft Corporation) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-08-05] (HP Inc.) BHO-x32: PDF Architect 5 Helper -> {AEA429F3-D2D4-4BD7-A03E-5357DA017733} -> C:\Program Files (x86)\PDF Architect 5\creator-ie-helper.dll [2017-05-08] (pdfforge GmbH) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-08-05] (HP Inc.) Toolbar: HKLM-x32 - PDF Architect 5 Toolbar - {84F23192-A475-4038-B5C0-8584777F2DF4} - C:\Program Files (x86)\PDF Architect 5\creator-ie-plugin.dll [2017-05-08] (pdfforge GmbH) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-20] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-20] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-20] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-20] (Microsoft Corporation) FireFox: ======== FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2017-04-21] () FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [2017-05-08] (pdfforge GmbH) FF Plugin HKU\S-1-5-21-1035901381-1415117216-1648240756-1001: @tools.google.com/Google Update;version=3 -> C:\Users\smits\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin HKU\S-1-5-21-1035901381-1415117216-1648240756-1001: @tools.google.com/Google Update;version=9 -> C:\Users\smits\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) Chrome: ======= CHR Profile: C:\Users\smits\AppData\Local\Google\Chrome\User Data\Default [2017-06-28] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\smits\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-23] CHR Extension: (Chrome Media Router) - C:\Users\smits\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-23] ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AdaptiveSleepService; c:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [138752 2016-08-09] () [Fichier non signé] R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [264432 2017-05-31] (AVG Technologies CZ, s.r.o.) R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [7396872 2017-05-31] (AVG Technologies CZ, s.r.o.) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-06-15] (AVG Technologies CZ, s.r.o.) R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [125656 2016-05-13] (Realtek Semiconductor Corp.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4122816 2017-06-10] (Microsoft Corporation) S3 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-01-07] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-01-07] (Dropbox, Inc.) S2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [350576 2017-04-21] (WildTangent) R2 HPJumpStartBridge; c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [461848 2016-08-05] (HP Inc.) S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [33640 2017-04-07] (HP Inc.) R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [631800 2016-06-20] (HP Inc.) S3 PDF Architect 5; C:\Program Files\PDF Architect 5\ws.exe [2706720 2017-05-08] (pdfforge GmbH) S3 PDF Architect 5 CrashHandler; C:\Program Files\PDF Architect 5\crash-handler-ws.exe [1048864 2017-05-08] (pdfforge GmbH) R2 PDF Architect 5 Creator; C:\Program Files\PDF Architect 5\creator-ws.exe [856864 2017-05-08] (pdfforge GmbH) R2 PDF Architect 5 Manager; C:\Program Files (x86)\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe [985848 2017-05-16] (© pdfforge GmbH.) S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2016-03-23] (CyberLink) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [314624 2016-08-08] (Realtek Semiconductor) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [258152 2016-08-22] (Synaptics Incorporated) R2 tbaseprovisioning; C:\windows\SysWOW64\tbaseprovisioning.exe [51224 2016-08-24] (Advanced Micro Devices, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation) ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 AmdAS4; C:\windows\System32\drivers\AmdAS4.sys [27384 2016-08-24] (Advanced Micro Devices, INC.) S3 amdkmcsp; C:\windows\system32\DRIVERS\amdkmcsp.sys [109488 2016-08-24] (Advanced Micro Devices, Inc. ) R0 amdkmpfd; C:\windows\System32\drivers\amdkmpfd.sys [78064 2016-08-24] (Advanced Micro Devices, Inc.) R0 amdpsp; C:\windows\System32\DRIVERS\amdpsp.sys [260520 2016-08-24] (Advanced Micro Devices, Inc. ) R3 AtiHDAudioService; C:\windows\system32\drivers\AtihdWT6.sys [118848 2016-08-24] (Advanced Micro Devices) R1 avgbdisk; C:\windows\system32\drivers\avgbdiska.sys [166624 2017-05-31] (AVG Technologies CZ, s.r.o.) R1 avgbidsdriver; C:\windows\system32\drivers\avgbidsdrivera.sys [314128 2017-05-31] (AVG Technologies CZ, s.r.o.) R0 avgbidsh; C:\windows\system32\drivers\avgbidsha.sys [192584 2017-05-31] (AVG Technologies CZ, s.r.o.) R0 avgblog; C:\windows\system32\drivers\avgbloga.sys [336896 2017-05-31] (AVG Technologies CZ, s.r.o.) R0 avgbuniv; C:\windows\system32\drivers\avgbuniva.sys [51336 2017-05-31] (AVG Technologies CZ, s.r.o.) S3 avgHwid; C:\windows\system32\drivers\avgHwid.sys [39424 2017-05-31] (AVG Technologies CZ, s.r.o.) R2 avgMonFlt; C:\windows\system32\drivers\avgMonFlt.sys [129776 2017-05-31] (AVG Technologies CZ, s.r.o.) R1 avgRdr; C:\windows\system32\drivers\avgRdr2.sys [102280 2017-05-31] (AVG Technologies CZ, s.r.o.) R0 avgRvrt; C:\windows\system32\drivers\avgRvrt.sys [76832 2017-05-31] (AVG Technologies CZ, s.r.o.) R1 avgSnx; C:\windows\system32\drivers\avgSnx.sys [1008288 2017-05-31] (AVG Technologies CZ, s.r.o.) R1 avgSP; C:\windows\system32\drivers\avgSP.sys [570320 2017-05-31] (AVG Technologies CZ, s.r.o.) R2 avgStm; C:\windows\system32\drivers\avgStm.sys [160008 2017-05-31] (AVG Technologies CZ, s.r.o.) R0 avgVmm; C:\windows\system32\drivers\avgVmm.sys [340824 2017-05-31] (AVG Technologies CZ, s.r.o.) S3 dg_ssudbus; C:\windows\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) S3 NetAdapterCx; C:\windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 rt640x64; C:\windows\System32\drivers\rt640x64.sys [943112 2016-08-22] (Realtek ) R3 RtkBtFilter; C:\windows\system32\DRIVERS\RtkBtfilter.sys [709376 2016-03-16] (Realtek Semiconductor Corporation) S3 RTSUER; C:\windows\system32\Drivers\RtsUer.sys [416472 2016-07-27] (Realsil Semiconductor Corporation) R3 RTWlanE; C:\windows\System32\drivers\rtwlane.sys [6804480 2017-05-03] (Realtek Semiconductor Corporation ) R3 SmbDrv; C:\windows\system32\DRIVERS\Smb_driver_AMDASF.sys [60008 2016-08-22] (Synaptics Incorporated) S3 SmbDrvI; C:\windows\System32\drivers\Smb_driver_Intel.sys [64104 2016-08-22] (Synaptics Incorporated) S3 ssudmdm; C:\windows\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 WdBoot; C:\windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R3 WirelessButtonDriver64; C:\windows\system32\DRIVERS\WirelessButtonDriver64.sys [32832 2016-07-31] (HP) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-06-28 12:29 - 2017-06-28 12:30 - 00017761 _____ C:\Users\smits\Desktop\FRST.txt 2017-06-28 12:27 - 2017-06-28 12:28 - 00037654 _____ C:\Users\smits\Downloads\Addition.txt 2017-06-28 12:25 - 2017-06-28 12:28 - 00046574 _____ C:\Users\smits\Downloads\FRST.txt 2017-06-28 12:24 - 2017-06-28 12:29 - 00000000 ____D C:\FRST 2017-06-28 12:23 - 2017-06-28 12:24 - 02441216 _____ (Farbar) C:\Users\smits\Desktop\FRST64.exe 2017-06-26 19:55 - 2017-06-26 19:55 - 00001334 _____ C:\Users\smits\Desktop\ZHPFixReport.txt 2017-06-26 19:54 - 2017-06-26 19:54 - 00000000 ____D C:\Users\smits\Downloads\Quarantine 2017-06-26 19:53 - 2017-06-26 19:53 - 03067264 _____ (Nicolas Coolman) C:\Users\smits\Downloads\zhpfix_2017-6-13-1.exe 2017-06-23 22:02 - 2017-06-23 22:02 - 00001205 _____ C:\Users\smits\Desktop\AdwCleaner[C2].txt 2017-06-23 21:15 - 2017-06-23 21:19 - 00010266 _____ C:\Users\smits\Desktop\ZHPCleaner.txt 2017-06-23 21:07 - 2017-06-23 21:07 - 00000916 _____ C:\Users\smits\Desktop\ZHPCleaner.lnk 2017-06-23 21:06 - 2017-06-23 21:07 - 02789888 _____ C:\Users\smits\Downloads\zhpcleaner_2017.06.17.100.exe 2017-06-23 14:03 - 2017-06-26 20:02 - 00251155 _____ C:\Users\smits\Desktop\ZHPDiag.txt 2017-06-23 13:59 - 2017-06-26 19:59 - 00000000 ____D C:\Users\smits\AppData\Roaming\ZHP 2017-06-23 13:59 - 2017-06-26 19:59 - 00000000 ____D C:\Users\smits\AppData\Local\ZHP 2017-06-23 13:59 - 2017-06-23 22:04 - 00000918 _____ C:\Users\smits\Desktop\ZHPDiag.lnk 2017-06-23 13:58 - 2017-06-23 13:59 - 02752896 _____ C:\Users\smits\Downloads\ZHPDiag3.exe 2017-06-23 10:32 - 2017-06-23 10:32 - 00000000 ____D C:\Users\smits\AppData\Local\PDFCreator 2017-06-23 10:32 - 2017-06-23 10:32 - 00000000 ____D C:\Program Files (x86)\PDF Architect 5 Manager 2017-06-23 10:31 - 2017-06-23 10:31 - 00000848 _____ C:\Users\Public\Desktop\PDF Architect 5.lnk 2017-06-23 10:30 - 2017-06-23 10:35 - 00000000 ____D C:\Users\smits\AppData\Roaming\PDF Architect 5 2017-06-23 10:30 - 2017-06-23 10:31 - 00000000 ____D C:\Program Files\PDF Architect 5 2017-06-23 10:30 - 2017-06-23 10:31 - 00000000 ____D C:\Program Files (x86)\PDF Architect 5 2017-06-23 10:30 - 2017-06-23 10:30 - 00000000 ____D C:\Users\smits\OneDrive\Documents\PDF Architect 2017-06-23 10:30 - 2017-06-23 10:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 5 2017-06-23 10:27 - 2017-06-23 10:35 - 00000000 ____D C:\ProgramData\PDF Architect 5 2017-06-23 10:27 - 2017-06-23 10:33 - 00000000 ____D C:\Program Files\PDFCreator 2017-06-23 10:27 - 2017-06-23 10:27 - 00116224 _____ (pdfforge GmbH) C:\windows\system32\pdfcmon.dll 2017-06-23 10:27 - 2017-06-23 10:27 - 00000884 _____ C:\Users\Public\Desktop\PDFCreator.lnk 2017-06-23 10:27 - 2017-06-23 10:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator 2017-06-23 10:22 - 2017-06-23 10:26 - 29032240 _____ (pdfforge GmbH ) C:\Users\smits\Downloads\PDFCreator-2_5_2-Setup.exe 2017-06-23 10:06 - 2017-06-23 10:06 - 00795631 _____ C:\Users\smits\Downloads\Bulletin d%27inscription réserve de recrutement 2017 - FB TMS.pdf 2017-06-20 13:03 - 2017-06-20 13:03 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WUDFUsbccidDriver_01_11_00.Wdf 2017-06-16 19:12 - 2017-06-16 19:12 - 00000000 ___SD C:\windows\UpdateAssistantV2 2017-06-16 13:36 - 2017-06-03 12:50 - 00315744 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll 2017-06-16 13:36 - 2017-06-03 12:16 - 00279904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys 2017-06-16 13:36 - 2017-06-03 12:11 - 01706488 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll 2017-06-16 13:36 - 2017-06-03 12:06 - 02048496 _____ C:\windows\SysWOW64\CoreUIComponents.dll 2017-06-16 13:36 - 2017-06-03 11:58 - 00340832 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll 2017-06-16 13:36 - 2017-06-03 11:55 - 00780640 _____ (Microsoft Corporation) C:\windows\SysWOW64\WWAHost.exe 2017-06-16 13:36 - 2017-06-03 11:54 - 00187232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys 2017-06-16 13:36 - 2017-06-03 11:52 - 01021784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxPackaging.dll 2017-06-16 13:36 - 2017-06-03 11:52 - 00607072 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupEngine.dll 2017-06-16 13:36 - 2017-06-03 11:52 - 00111968 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupApi.dll 2017-06-16 13:36 - 2017-06-03 11:50 - 00857440 _____ (Microsoft Corporation) C:\windows\system32\WWAHost.exe 2017-06-16 13:36 - 2017-06-03 11:50 - 00381792 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBXHCI.SYS 2017-06-16 13:36 - 2017-06-03 11:49 - 20967840 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll 2017-06-16 13:36 - 2017-06-03 11:44 - 01412640 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32full.dll 2017-06-16 13:36 - 2017-06-03 11:44 - 00545944 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontdrvhost.exe 2017-06-16 13:36 - 2017-06-03 11:39 - 05686272 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll 2017-06-16 13:36 - 2017-06-03 11:33 - 00095232 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataTimeUtil.dll 2017-06-16 13:36 - 2017-06-03 11:32 - 00002560 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll 2017-06-16 13:36 - 2017-06-03 11:31 - 00224256 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExSMime.dll 2017-06-16 13:36 - 2017-06-03 11:31 - 00037376 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll 2017-06-16 13:36 - 2017-06-03 11:28 - 00285184 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.BlockedShutdown.dll 2017-06-16 13:36 - 2017-06-03 11:28 - 00232448 _____ (Microsoft Corporation) C:\windows\SysWOW64\edputil.dll 2017-06-16 13:36 - 2017-06-03 11:26 - 00231936 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2017-06-16 13:36 - 2017-06-03 11:26 - 00100352 _____ (Microsoft Corporation) C:\windows\SysWOW64\AuthBrokerUI.dll 2017-06-16 13:36 - 2017-06-03 11:22 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupShim.dll 2017-06-16 13:36 - 2017-06-03 11:22 - 00327168 _____ (Microsoft Corporation) C:\windows\SysWOW64\netcorehc.dll 2017-06-16 13:36 - 2017-06-03 11:22 - 00181760 _____ (Microsoft Corporation) C:\windows\SysWOW64\tcpipcfg.dll 2017-06-16 13:36 - 2017-06-03 11:20 - 00755712 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll 2017-06-16 13:36 - 2017-06-03 11:19 - 01164288 _____ (Microsoft Corporation) C:\windows\SysWOW64\certutil.exe 2017-06-16 13:36 - 2017-06-03 11:16 - 00709120 _____ (Microsoft Corporation) C:\windows\SysWOW64\CPFilters.dll 2017-06-16 13:36 - 2017-06-03 11:16 - 00119808 _____ (Microsoft Corporation) C:\windows\system32\UserDataTimeUtil.dll 2017-06-16 13:36 - 2017-06-03 11:15 - 00886272 _____ (Microsoft Corporation) C:\windows\SysWOW64\aadtb.dll 2017-06-16 13:36 - 2017-06-03 11:15 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\Drivers\BasicRender.sys 2017-06-16 13:36 - 2017-06-03 11:14 - 00124416 _____ (Microsoft Corporation) C:\windows\system32\mssprxy.dll 2017-06-16 13:36 - 2017-06-03 11:12 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\fdProxy.dll 2017-06-16 13:36 - 2017-06-03 11:08 - 02643968 _____ (Microsoft Corporation) C:\windows\SysWOW64\tquery.dll 2017-06-16 13:36 - 2017-06-03 11:08 - 01221120 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Audio.dll 2017-06-16 13:36 - 2017-06-03 11:07 - 00552960 _____ (Microsoft Corporation) C:\windows\system32\MusUpdateHandlers.dll 2017-06-16 13:36 - 2017-06-03 11:05 - 01883648 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Logon.dll 2017-06-16 13:36 - 2017-06-03 11:05 - 00295424 _____ (Microsoft Corporation) C:\windows\SysWOW64\hnetcfg.dll 2017-06-16 13:36 - 2017-06-03 11:04 - 02006528 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll 2017-06-16 13:36 - 2017-06-03 11:04 - 00773120 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchIndexer.exe 2017-06-16 13:36 - 2017-06-03 11:03 - 01988096 _____ (Microsoft Corporation) C:\windows\SysWOW64\mssrch.dll 2017-06-16 13:36 - 2017-06-03 11:02 - 02997760 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32kfull.sys 2017-06-16 13:36 - 2017-06-03 10:54 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Audio.dll 2017-06-16 13:36 - 2017-06-03 10:52 - 03403264 _____ (Microsoft Corporation) C:\windows\system32\tquery.dll 2017-06-16 13:36 - 2017-06-03 10:50 - 02538496 _____ (Microsoft Corporation) C:\windows\system32\mssrch.dll 2017-06-16 13:36 - 2017-06-03 10:49 - 00903680 _____ (Microsoft Corporation) C:\windows\system32\SearchIndexer.exe 2017-06-16 13:36 - 2017-06-03 10:48 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\wuuhext.dll 2017-06-16 13:36 - 2017-06-03 10:40 - 00483840 _____ (Microsoft Corporation) C:\windows\SysWOW64\CoreMessaging.dll 2017-06-16 13:36 - 2017-03-04 08:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\puiobj.dll 2017-06-16 13:36 - 2016-09-07 06:53 - 00118272 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppointmentActivation.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 01564512 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 01214816 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 00629088 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 00544096 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 00379232 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 00335712 _____ (Microsoft Corporation) C:\windows\system32\dcntel.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 00334176 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 00233824 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 00136032 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll 2017-06-16 13:35 - 2017-06-03 12:14 - 00096608 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe 2017-06-16 13:35 - 2017-06-03 12:09 - 02213760 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2017-06-16 13:35 - 2017-06-03 12:08 - 07783256 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2017-06-16 13:35 - 2017-06-03 12:01 - 02681200 _____ C:\windows\system32\CoreUIComponents.dll 2017-06-16 13:35 - 2017-06-03 11:59 - 01181024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys 2017-06-16 13:35 - 2017-06-03 11:59 - 00764392 _____ (Microsoft Corporation) C:\windows\system32\CoreMessaging.dll 2017-06-16 13:35 - 2017-06-03 11:59 - 00118112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys 2017-06-16 13:35 - 2017-06-03 11:53 - 00404824 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2017-06-16 13:35 - 2017-06-03 11:51 - 02187104 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys 2017-06-16 13:35 - 2017-06-03 11:51 - 00402272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys 2017-06-16 13:35 - 2017-06-03 11:49 - 00624048 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2017-06-16 13:35 - 2017-06-03 11:48 - 01112416 _____ (Microsoft Corporation) C:\windows\system32\AppxPackaging.dll 2017-06-16 13:35 - 2017-06-03 11:48 - 01100128 _____ (Microsoft Corporation) C:\windows\system32\hvix64.exe 2017-06-16 13:35 - 2017-06-03 11:48 - 00989024 _____ (Microsoft Corporation) C:\windows\system32\hvax64.exe 2017-06-16 13:35 - 2017-06-03 11:48 - 00857952 _____ (Microsoft Corporation) C:\windows\system32\NetSetupEngine.dll 2017-06-16 13:35 - 2017-06-03 11:48 - 00148832 _____ (Microsoft Corporation) C:\windows\system32\NetSetupApi.dll 2017-06-16 13:35 - 2017-06-03 11:45 - 22220864 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2017-06-16 13:35 - 2017-06-03 11:44 - 01600624 _____ (Microsoft Corporation) C:\windows\system32\sppobjs.dll 2017-06-16 13:35 - 2017-06-03 11:40 - 01566552 _____ (Microsoft Corporation) C:\windows\system32\gdi32full.dll 2017-06-16 13:35 - 2017-06-03 11:40 - 00628552 _____ (Microsoft Corporation) C:\windows\system32\fontdrvhost.exe 2017-06-16 13:35 - 2017-06-03 11:39 - 02532192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2017-06-16 13:35 - 2017-06-03 11:39 - 00455520 _____ (Microsoft Corporation) C:\windows\system32\securekernel.exe 2017-06-16 13:35 - 2017-06-03 11:23 - 00306688 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieproxy.dll 2017-06-16 13:35 - 2017-06-03 11:22 - 07217152 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll 2017-06-16 13:35 - 2017-06-03 11:18 - 22569984 _____ (Microsoft Corporation) C:\windows\system32\edgehtml.dll 2017-06-16 13:35 - 2017-06-03 11:15 - 19414016 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2017-06-16 13:35 - 2017-06-03 11:15 - 18364928 _____ (Microsoft Corporation) C:\windows\SysWOW64\edgehtml.dll 2017-06-16 13:35 - 2017-06-03 11:15 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\musdialoghandlers.dll 2017-06-16 13:35 - 2017-06-03 11:14 - 00238592 _____ (Microsoft Corporation) C:\windows\system32\MusNotification.exe 2017-06-16 13:35 - 2017-06-03 11:14 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\MusNotificationUx.exe 2017-06-16 13:35 - 2017-06-03 11:11 - 00353792 _____ (Microsoft Corporation) C:\windows\system32\cloudAP.dll 2017-06-16 13:35 - 2017-06-03 11:10 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.BlockedShutdown.dll 2017-06-16 13:35 - 2017-06-03 11:09 - 00489472 _____ (Microsoft Corporation) C:\windows\system32\NetSetupShim.dll 2017-06-16 13:35 - 2017-06-03 11:09 - 00441344 _____ (Microsoft Corporation) C:\windows\system32\netcorehc.dll 2017-06-16 13:35 - 2017-06-03 11:09 - 00337408 _____ (Microsoft Corporation) C:\windows\system32\NetworkBindingEngineMigPlugin.dll 2017-06-16 13:35 - 2017-06-03 11:08 - 12187648 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2017-06-16 13:35 - 2017-06-03 11:08 - 00691200 _____ (Microsoft Corporation) C:\windows\system32\ieproxy.dll 2017-06-16 13:35 - 2017-06-03 11:08 - 00324608 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.LockScreen.dll 2017-06-16 13:35 - 2017-06-03 11:08 - 00147456 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll 2017-06-16 13:35 - 2017-06-03 11:07 - 00456192 _____ (Microsoft Corporation) C:\windows\system32\puiobj.dll 2017-06-16 13:35 - 2017-06-03 11:06 - 03664384 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2017-06-16 13:35 - 2017-06-03 11:04 - 06042624 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakra.dll 2017-06-16 13:35 - 2017-06-03 11:03 - 00932864 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2017-06-16 13:35 - 2017-06-03 11:01 - 00856064 _____ (Microsoft Corporation) C:\windows\system32\efscore.dll 2017-06-16 13:35 - 2017-06-03 11:00 - 23677440 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2017-06-16 13:35 - 2017-06-03 10:56 - 13091840 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2017-06-16 13:35 - 2017-06-03 10:53 - 08125440 _____ (Microsoft Corporation) C:\windows\system32\Chakra.dll 2017-06-16 13:35 - 2017-06-03 10:52 - 02510848 _____ (Microsoft Corporation) C:\windows\system32\NetworkMobileSettings.dll 2017-06-16 13:35 - 2017-06-03 10:52 - 00975872 _____ (Microsoft Corporation) C:\windows\HelpPane.exe 2017-06-16 13:35 - 2017-06-03 10:52 - 00886784 _____ (Microsoft Corporation) C:\windows\system32\CPFilters.dll 2017-06-16 13:35 - 2017-06-03 10:51 - 00266752 _____ (Microsoft Corporation) C:\windows\system32\NetSetupSvc.dll 2017-06-16 13:35 - 2017-06-03 10:50 - 04744704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2017-06-16 13:35 - 2017-06-03 10:49 - 03615744 _____ (Microsoft Corporation) C:\windows\system32\win32kfull.sys 2017-06-16 13:35 - 2017-06-03 10:49 - 02691072 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Logon.dll 2017-06-16 13:35 - 2017-06-03 10:49 - 02475520 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll 2017-06-16 13:35 - 2017-06-03 10:49 - 02318848 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2017-06-16 13:35 - 2017-06-03 10:49 - 01845248 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll 2017-06-16 13:35 - 2017-06-03 10:49 - 01513472 _____ (Microsoft Corporation) C:\windows\system32\win32kbase.sys 2017-06-16 13:35 - 2017-06-03 10:49 - 00351744 _____ (Microsoft Corporation) C:\windows\system32\hnetcfg.dll 2017-06-16 13:35 - 2017-06-03 10:48 - 01490432 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2017-06-16 13:35 - 2017-06-03 10:48 - 01131008 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll 2017-06-16 13:35 - 2017-06-03 10:48 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll 2017-06-16 13:35 - 2017-06-03 10:46 - 01121280 _____ (Microsoft Corporation) C:\windows\system32\aadtb.dll 2017-06-16 13:35 - 2017-05-25 07:56 - 00038752 _____ (Microsoft Corporation) C:\windows\system32\OOBEUpdater.exe 2017-06-16 13:35 - 2017-03-04 08:22 - 00822784 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakradiag.dll 2017-06-16 13:35 - 2017-03-04 08:19 - 00635904 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2017-06-16 13:35 - 2017-03-04 08:16 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\wpninprc.dll 2017-06-16 13:34 - 2017-06-03 12:50 - 00192856 _____ (Microsoft Corporation) C:\windows\SysWOW64\aepic.dll 2017-06-16 13:34 - 2017-06-03 12:14 - 00136024 _____ (Microsoft Corporation) C:\windows\system32\ImplatSetup.dll 2017-06-16 13:34 - 2017-06-03 12:14 - 00034648 _____ (Microsoft Corporation) C:\windows\system32\DeviceCensus.exe 2017-06-16 13:34 - 2017-06-03 12:11 - 00128864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tm.sys 2017-06-16 13:34 - 2017-06-03 11:49 - 00509280 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2017-06-16 13:34 - 2017-06-03 11:16 - 00002560 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2017-06-16 13:34 - 2017-06-03 11:14 - 00045056 _____ (Adobe Systems) C:\windows\system32\atmlib.dll 2017-06-16 13:34 - 2017-06-03 11:10 - 00252928 _____ (Microsoft Corporation) C:\windows\system32\edputil.dll 2017-06-16 13:34 - 2017-06-03 11:10 - 00117760 _____ (Microsoft Corporation) C:\windows\system32\AuthBrokerUI.dll 2017-06-16 13:34 - 2017-06-03 11:07 - 00255488 _____ (Microsoft Corporation) C:\windows\system32\HNetCfgClient.dll 2017-06-16 13:34 - 2017-06-03 11:06 - 00198144 _____ (Microsoft Corporation) C:\windows\system32\dpapisrv.dll 2017-06-16 13:34 - 2017-06-03 10:58 - 00064512 _____ (Microsoft Corporation) C:\windows\system32\fdProxy.dll 2017-06-16 13:34 - 2017-06-03 10:51 - 01418240 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe 2017-06-16 13:34 - 2017-06-03 08:08 - 00080078 _____ C:\windows\system32\normidna.nls 2017-06-08 21:51 - 2017-06-08 22:04 - 370447962 _____ C:\Users\smits\Downloads\[WwW.VoirFilms.co]-Greys.Anatomy.S12E12.PROPER.VOSTFR.WEB-DL.XviD.avi 2017-06-06 19:40 - 2017-06-06 19:40 - 00002631 _____ C:\Users\smits\Desktop\AdwCleaner[C0].txt 2017-06-06 19:31 - 2017-06-23 21:59 - 00000000 ____D C:\AdwCleaner 2017-06-06 19:31 - 2017-06-06 19:31 - 04110280 _____ C:\Users\smits\Downloads\adwcleaner_6.047 (1).exe 2017-06-06 19:29 - 2017-06-06 19:30 - 00049310 _____ C:\Users\smits\Downloads\adwcleaner_6.047.exe 2017-06-06 19:25 - 2017-06-06 19:25 - 09551280 _____ (Piriform Ltd) C:\Users\smits\Downloads\ccsetup530.exe 2017-06-05 22:55 - 2017-06-16 19:14 - 00321304 _____ C:\windows\system32\FNTCACHE.DAT 2017-06-02 11:26 - 2017-06-02 11:26 - 00078454 _____ C:\Users\smits\OneDrive\Documents\Demande plan de paiement taxes mitsu.pdf 2017-05-31 18:47 - 2017-05-31 18:47 - 00000000 ____D C:\Users\smits\AppData\Roaming\AVG 2017-05-31 18:46 - 2017-06-25 08:49 - 00004282 _____ C:\windows\System32\Tasks\Antivirus Emergency Update 2017-05-31 18:46 - 2017-05-31 18:46 - 00160008 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgstm.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 01008288 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgSnx.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00570320 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgSP.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00401584 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\avgBoot.exe 2017-05-31 18:46 - 2017-05-31 18:45 - 00340824 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgVmm.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00336896 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbloga.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00314128 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbidsdrivera.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00192584 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbidsha.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00166624 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbdiska.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00129776 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgMonFlt.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00102280 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgRdr2.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00076832 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgRvrt.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00051336 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgbuniva.sys 2017-05-31 18:46 - 2017-05-31 18:45 - 00039424 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgHwid.sys 2017-05-31 18:41 - 2017-06-28 12:22 - 00000955 _____ C:\Users\Public\Desktop\AVG.lnk 2017-05-31 18:41 - 2017-06-28 12:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2017-05-31 18:38 - 2017-06-28 12:19 - 00003668 _____ C:\windows\System32\Tasks\AVG EUpdate Task 2017-05-31 18:38 - 2017-05-31 18:41 - 00000000 ____D C:\Program Files (x86)\AVG 2017-05-31 18:32 - 2017-05-31 18:26 - 00565416 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe 2017-05-31 18:31 - 2017-05-31 18:31 - 00000000 ____D C:\Users\smits\AppData\Local\CEF 2017-05-31 18:29 - 2017-05-31 20:22 - 00000000 ____D C:\ProgramData\Avg 2017-05-31 18:29 - 2017-05-31 18:41 - 00000000 ____D C:\Users\smits\AppData\Local\AvgSetupLog 2017-05-31 18:29 - 2017-05-31 18:29 - 00000000 ____D C:\Users\smits\AppData\Local\Avg 2017-05-31 18:28 - 2017-05-31 18:29 - 03449440 _____ (AVG Technologies CZ, s.r.o.) C:\Users\smits\Downloads\Antivirus_Free_1858.exe 2017-05-30 20:47 - 2017-05-30 20:47 - 00018361 _____ C:\Users\smits\OneDrive\Documents\modification loi dis.odt 2017-05-30 20:47 - 2017-05-30 20:47 - 00011669 _____ C:\Users\smits\OneDrive\Documents\rcd.odt 2017-05-30 19:57 - 2017-05-30 19:57 - 00166927 _____ C:\Users\smits\OneDrive\Documents\Manuel DIS.odt 2017-05-30 19:52 - 2017-05-30 19:52 - 00018367 _____ C:\Users\smits\OneDrive\Documents\demande mi temps thérapeutique.odt 2017-05-30 19:44 - 2017-05-30 19:44 - 05944042 _____ C:\Users\smits\OneDrive\Documents\LEGISLATION RCD + JP.pdf 2017-05-30 19:41 - 2017-05-30 19:41 - 00280829 _____ C:\Users\smits\OneDrive\Documents\RCD impossib remise amendes pénales et dettes alim).pdf 2017-05-30 19:39 - 2017-05-30 19:39 - 00193341 _____ C:\Users\smits\Downloads\CENTRE PME LIEGE TEAM GESTION PME ET AGPR version 092016.xlsx 2017-05-30 19:36 - 2017-05-30 19:36 - 05012253 _____ C:\Users\smits\OneDrive\Documents\Guide complet droit sociaux juin 2016.pdf ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-06-28 12:29 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-06-28 12:28 - 2016-07-16 13:47 - 00000000 ____D C:\windows\AppReadiness 2017-06-28 12:28 - 2016-07-16 13:45 - 00000000 ____D C:\windows\INF 2017-06-28 12:22 - 2017-02-02 18:03 - 00004178 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{65ECB1BF-444F-427F-B1C5-C903DE5528F7} 2017-06-28 12:17 - 2017-01-07 12:21 - 00000000 ____D C:\Users\smits 2017-06-26 20:03 - 2016-09-22 14:57 - 00924328 _____ C:\windows\system32\perfh00C.dat 2017-06-26 20:03 - 2016-09-22 14:57 - 00226372 _____ C:\windows\system32\perfc00C.dat 2017-06-26 20:03 - 2016-07-29 14:37 - 02385714 _____ C:\windows\system32\PerfStringBackup.INI 2017-06-26 19:56 - 2017-02-06 12:08 - 00000364 _____ C:\windows\Tasks\HPCeeScheduleForsmits.job 2017-06-26 19:56 - 2016-11-03 08:08 - 00065536 _____ C:\windows\system32\spu_storage.bin 2017-06-26 19:56 - 2016-07-29 14:32 - 00000006 ____H C:\windows\Tasks\SA.DAT 2017-06-26 19:56 - 2016-07-16 08:04 - 00786432 _____ C:\windows\system32\config\BBI 2017-06-26 19:51 - 2016-07-16 13:47 - 00000000 ____D C:\windows\system32\NDF 2017-06-25 09:44 - 2016-07-29 14:32 - 00000000 ____D C:\windows\system32\SleepStudy 2017-06-24 13:08 - 2017-02-06 12:08 - 00003256 _____ C:\windows\System32\Tasks\HPCeeScheduleForsmits 2017-06-23 16:46 - 2016-07-16 13:47 - 00000000 ____D C:\windows\rescache 2017-06-23 12:48 - 2016-09-22 05:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-06-23 12:47 - 2017-01-07 12:30 - 00003290 _____ C:\windows\System32\Tasks\OneDrive Standalone Update Task v2 2017-06-23 12:47 - 2017-01-07 12:28 - 00002464 _____ C:\Users\smits\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-06-23 12:47 - 2017-01-07 12:28 - 00000000 ___RD C:\Users\smits\OneDrive 2017-06-21 11:12 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-06-16 20:41 - 2016-07-29 14:33 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-06-16 19:12 - 2016-07-16 13:47 - 00000000 ___RD C:\windows\ImmersiveControlPanel 2017-06-16 19:12 - 2016-07-16 13:47 - 00000000 ____D C:\windows\system32\appraiser 2017-06-16 19:12 - 2016-07-16 13:47 - 00000000 ____D C:\windows\ShellExperiences 2017-06-16 16:40 - 2017-01-08 12:12 - 00000000 ____D C:\windows\system32\MRT 2017-06-16 16:35 - 2017-01-08 12:11 - 133627792 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe 2017-06-16 16:35 - 2016-07-16 13:36 - 00000000 ____D C:\windows\CbsTemp 2017-06-06 09:34 - 2017-01-07 11:17 - 00000000 ____D C:\Users\defaultuser0 2017-06-05 22:55 - 2017-02-28 19:00 - 00000000 ____D C:\Program Files (x86)\360 2017-06-03 08:36 - 2017-02-28 14:56 - 00835576 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2017-06-03 08:36 - 2017-02-28 14:56 - 00177656 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-06-02 23:44 - 2017-04-20 13:21 - 00067301 _____ C:\Users\smits\OneDrive\Documents\Notre Budget 2017.ods 2017-06-01 16:06 - 2017-01-07 12:23 - 00000000 ____D C:\Users\smits\AppData\Local\Packages ==================== Fichiers à la racine de certains dossiers ======= 2017-01-07 12:24 - 2017-06-28 12:18 - 0781535 _____ () C:\Users\smits\AppData\Local\BTServer.log ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\windows\system32\winlogon.exe => Le fichier est signé numériquement C:\windows\system32\wininit.exe => Le fichier est signé numériquement C:\windows\explorer.exe => Le fichier est signé numériquement C:\windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\windows\system32\svchost.exe => Le fichier est signé numériquement C:\windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\windows\system32\services.exe => Le fichier est signé numériquement C:\windows\system32\User32.dll => Le fichier est signé numériquement C:\windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\windows\system32\userinit.exe => Le fichier est signé numériquement C:\windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\windows\system32\rpcss.dll => Le fichier est signé numériquement C:\windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2017-06-22 10:11 ==================== Fin de FRST.txt ============================