Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 20-08-2017 Exécuté par ac (administrateur) sur ACER (20-08-2017 17:05:31) Exécuté depuis C:\Users\ac\Desktop Profils chargés: ac (Profils disponibles: UpdatusUser & ac) Platform: Windows 8.1 (Update) (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe () C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corporation) C:\Windows\System32\alg.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Windows\System32\igfxTray.exe () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe () C:\Program Files (x86)\Acer\Live Updater\updater.exe (Farbar) C:\Users\ac\Desktop\FRST64 (3).exe ==================== Registre (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor) HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [457616 2014-10-03] () HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation) HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [414856 2017-02-02] (Power Software Ltd) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4174464 2017-05-23] (Safer-Networking Ltd.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [131712 2013-01-25] (Qualcomm Atheros Commnucations) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [Facebook Update] => C:\Users\ac\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-09-11] (Facebook Inc.) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [BingSvc] => C:\Users\ac\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [39376 2015-03-12] (Alcohol Soft Development Team) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [uTorrent] => C:\Users\ac\AppData\Roaming\uTorrent\uTorrent.exe [2146496 2017-07-19] (BitTorrent Inc.) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [5583120 2015-02-27] (Disc Soft Ltd) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-04-26] (Valve Corporation) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [Spotify] => C:\Users\ac\AppData\Roaming\Spotify\Spotify.exe [15866480 2017-08-07] (Spotify Ltd) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\Run: [Spotify Web Helper] => C:\Users\ac\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1580144 2017-08-07] (Spotify Ltd) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1301848 2017-08-11] (Google Inc.) HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\MountPoints2: G - "G:\setup.exe" HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\MountPoints2: {8ddb2488-2395-11e7-814b-0c84dcbafbd8} - "G:\setup.exe" HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\MountPoints2: {c621e0ac-fcc6-11e4-bfda-0c84dcbafbd8} - "E:\install.exe" HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\MountPoints2: {c621e1fc-fcc6-11e4-bfda-0c84dcbafbd8} - "F:\autorun.exe" HKU\S-1-5-21-1975831795-1492635413-771006052-1002\...\MountPoints2: {ec1e1a61-00b3-11e5-bfdc-806e6f6e6963} - "E:\autorun.exe" AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [181488 2016-08-11] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [159352 2016-08-11] (NVIDIA Corporation) Startup: C:\Users\ac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2016-07-19] ShortcutTarget: Curse.lnk -> C:\Users\ac\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc) Startup: C:\Users\ac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2015-05-29] () BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy: Restriction - Chrome <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION CHR HKU\S-1-5-21-1975831795-1492635413-771006052-1002\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1 Tcpip\..\Interfaces\{05786EB9-CCB9-4184-A078-5AC85EE1DFFE}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{096DE182-B18C-4CD2-BD8E-5BCA51067692}: [NameServer] 37.187.23.23,37.187.99.178 Tcpip\..\Interfaces\{0AD7290B-9752-41AB-BD2E-CF8D8101529E}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{0AD7290B-9752-41AB-BD2E-CF8D8101529E}: [DhcpNameServer] 192.168.0.254 Tcpip\..\Interfaces\{A2EBDAC1-1A8A-42F2-A475-B187C391C271}: [NameServer] 37.187.23.23,37.187.99.178 Tcpip\..\Interfaces\{CA5D4929-3E50-4B94-B8EA-A7446294D5EC}: [NameServer] 208.67.222.222,208.67.220.220,192.168.0.254 Tcpip\..\Interfaces\{CA5D4929-3E50-4B94-B8EA-A7446294D5EC}: [DhcpNameServer] 192.168.8.1 192.168.8.1 Internet Explorer: ================== HKU\S-1-5-21-1975831795-1492635413-771006052-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-1975831795-1492635413-771006052-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset SearchScopes: HKU\S-1-5-21-1975831795-1492635413-771006052-1002 -> DefaultScope {F9F7B04C-0F1F-488C-9C37-D6BE077E03F2} URL = SearchScopes: HKU\S-1-5-21-1975831795-1492635413-771006052-1002 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = SearchScopes: HKU\S-1-5-21-1975831795-1492635413-771006052-1002 -> {BDE1CF29-86C0-46AF-8EB2-C09F04808F54} URL = hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default SearchScopes: HKU\S-1-5-21-1975831795-1492635413-771006052-1002 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = SearchScopes: HKU\S-1-5-21-1975831795-1492635413-771006052-1002 -> {F9F7B04C-0F1F-488C-9C37-D6BE077E03F2} URL = BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2013-01-25] (Qualcomm Atheros Commnucations) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-10-07] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-10-07] (Oracle Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => non trouvé(e) FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-09] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-09] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-01-23] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-01-23] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-10-07] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-10-07] (Oracle Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [Pas de fichier] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-04] (Google Inc.) FF Plugin HKU\S-1-5-21-1975831795-1492635413-771006052-1002: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\ac\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited) FF Plugin HKU\S-1-5-21-1975831795-1492635413-771006052-1002: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [Pas de fichier] Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp CHR Profile: C:\Users\ac\AppData\Local\Google\Chrome\User Data\Default [2017-08-20] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\ac\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-13] CHR Extension: (Chrome Media Router) - C:\Users\ac\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08] CHR HKU\S-1-5-21-1975831795-1492635413-771006052-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227456 2013-01-25] (Qualcomm Atheros Commnucations) [Fichier non signé] R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-19] (Acer Incorporated) S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-16] (Acer Incorporated) S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-27] (Disc Soft Ltd) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2625368 2017-07-20] (ESET) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated) S2 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] () R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [329104 2014-10-03] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [Fichier non signé] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-01-30] (Intel Corporation) R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-03-15] (Acer Incorporate) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [492480 2017-03-28] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [492480 2017-03-28] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-03-28] (NVIDIA Corporation) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1776864 2017-05-23] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2131760 2017-05-23] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233936 2017-05-23] (Safer-Networking Ltd.) R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Fichier non signé] R2 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [118424 2016-03-09] () S3 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation) ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) U3 axscsidrv; C:\Windows\System32\Drivers\axscsidrv.sys [304296 2015-05-22] (Alcohol Soft Development Team) S3 BTATH_LWFLT; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-24] (Qualcomm Atheros) R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30352 2017-04-17] (Disc Soft Ltd) R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132848 2017-07-20] (ESET) R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [251632 2015-07-14] (ESET) S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [14880 2017-03-09] (ESET) R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [178056 2017-03-09] (ESET) R1 epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [77224 2017-03-09] (ESET) R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47552 2017-03-28] (NVIDIA Corporation) R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-03-28] (NVIDIA Corporation) R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated) S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2016-03-09] () R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [381608 2015-05-22] (Duplex Secure Ltd.) R1 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [119712 2016-04-28] (Oracle Corporation) R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [192352 2016-04-28] (Oracle Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation) R2 WinisoCDBus; C:\WINDOWS\System32\drivers\WinisoCDBus.sys [204032 2016-10-20] (WinISO.com) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-08-20 17:05 - 2017-08-20 17:05 - 000020910 _____ C:\Users\ac\Desktop\FRST.txt 2017-08-20 17:04 - 2017-08-20 17:04 - 002395648 _____ (Farbar) C:\Users\ac\Desktop\FRST64 (3).exe 2017-08-20 17:01 - 2017-08-20 17:05 - 000000000 ____D C:\FRST 2017-08-20 17:00 - 2017-08-20 17:01 - 002395648 _____ (Farbar) C:\Users\ac\Downloads\FRST64 (2).exe 2017-08-20 16:58 - 2017-08-20 17:01 - 002395648 _____ (Farbar) C:\Users\ac\Downloads\FRST64 (1).exe 2017-08-20 16:55 - 2017-08-20 16:55 - 000000829 _____ C:\Users\ac\Desktop\ZHPDiag.lnk 2017-08-20 16:55 - 2017-08-20 16:55 - 000000000 ____D C:\Users\ac\AppData\Roaming\ZHP 2017-08-20 16:55 - 2017-08-20 16:55 - 000000000 ____D C:\Users\ac\AppData\Local\ZHP 2017-08-20 16:53 - 2017-08-20 16:55 - 002812800 _____ C:\Users\ac\Downloads\ZHPDiag3 (1).exe 2017-08-20 16:52 - 2017-08-20 16:55 - 002812800 _____ C:\Users\ac\Downloads\ZHPDiag3.exe 2017-08-19 22:29 - 2017-08-19 22:41 - 3860745651 ____R C:\Users\ac\Downloads\Zero.III.2017.1080.WEB-DL.H264.mkv 2017-08-19 22:28 - 2017-08-19 22:28 - 000037025 _____ C:\Users\ac\Downloads\011ADF556B91837B6A4838C436589BCFFF90987B.torrent 2017-08-19 22:09 - 2017-08-19 22:09 - 010893992 _____ (Adobe Systems Inc.) C:\Users\ac\Downloads\AdobeAIRInstaller (1).exe 2017-08-19 21:08 - 2017-08-19 21:08 - 000001039 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft Logs Uploader.lnk 2017-08-19 21:08 - 2017-08-19 21:08 - 000001027 _____ C:\Users\Public\Desktop\Warcraft Logs Uploader.lnk 2017-08-19 21:08 - 2017-08-19 21:08 - 000000000 ____D C:\Users\ac\AppData\Roaming\com.warcraft.logs 2017-08-19 21:08 - 2017-08-19 21:08 - 000000000 ____D C:\ProgramData\Adobe 2017-08-19 21:08 - 2017-08-19 21:08 - 000000000 ____D C:\Program Files (x86)\Warcraft Logs Uploader 2017-08-19 21:07 - 2017-08-19 21:07 - 010893992 _____ (Adobe Systems Inc.) C:\Users\ac\Downloads\AdobeAIRInstaller.exe 2017-08-19 21:07 - 2017-08-19 21:07 - 000000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2017-08-19 21:07 - 2017-08-19 21:07 - 000000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2017-08-19 21:07 - 2017-08-19 21:07 - 000000000 ____D C:\Users\ac\AppData\Local\Adobe 2017-08-19 21:07 - 2017-08-19 21:07 - 000000000 ____D C:\Program Files (x86)\Adobe 2017-08-19 21:06 - 2017-08-19 21:06 - 000947938 _____ C:\Users\ac\Downloads\warcraftlogs.air 2017-08-19 20:12 - 2017-08-19 20:12 - 002395648 _____ (Farbar) C:\Users\ac\Downloads\FRST64.exe 2017-08-19 20:09 - 2017-08-19 20:09 - 000448512 _____ (OldTimer Tools) C:\Users\ac\Downloads\TFC.exe 2017-08-15 13:34 - 2017-08-15 13:34 - 000000000 __SHD C:\found.000 2017-08-13 20:55 - 2017-08-13 20:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack 2017-08-13 20:55 - 2017-08-13 20:55 - 000000000 ____D C:\Program Files (x86)\K-Lite Codec Pack 2017-08-13 20:55 - 2013-12-01 14:10 - 000257624 _____ C:\WINDOWS\system32\unrar64.dll 2017-08-13 19:33 - 2017-04-21 23:53 - 000029376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll 2017-08-13 19:33 - 2017-04-21 23:50 - 000030912 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll 2017-08-13 19:32 - 2017-04-21 23:53 - 000018600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr100_clr0400.dll 2017-08-13 19:32 - 2017-04-21 23:50 - 000018592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr100_clr0400.dll 2017-08-13 19:32 - 2017-04-11 20:27 - 000485576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp120_clr0400.dll 2017-08-13 19:32 - 2017-03-15 20:15 - 000690008 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp120_clr0400.dll 2017-08-13 19:31 - 2017-04-11 20:27 - 000987840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll 2017-08-13 19:31 - 2017-03-15 20:15 - 000993632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll 2017-08-09 19:25 - 2017-08-02 05:17 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2017-08-09 19:25 - 2017-07-21 15:40 - 000518144 _____ C:\WINDOWS\SysWOW64\msjetoledb40.dll 2017-08-09 19:25 - 2017-07-21 15:40 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjtes40.dll 2017-08-09 19:25 - 2017-07-15 12:10 - 000536688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2017-08-09 19:25 - 2017-07-15 12:10 - 000140016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2017-08-09 19:25 - 2017-07-15 12:06 - 000449840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2017-08-09 19:25 - 2017-07-15 12:06 - 000136832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2017-08-09 19:25 - 2017-07-14 08:49 - 025733632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-08-09 19:25 - 2017-07-14 07:35 - 005981184 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-08-09 19:25 - 2017-07-14 06:40 - 015254016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-08-09 19:25 - 2017-07-14 04:54 - 020270080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-08-09 19:25 - 2017-07-14 04:17 - 004546048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-08-09 19:25 - 2017-07-08 22:14 - 000376672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2017-08-09 19:25 - 2017-07-08 21:12 - 004169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2017-08-09 19:25 - 2017-07-08 19:45 - 007078912 _____ (Microsoft Corporation) C:\WINDOWS\system32\glcndFilter.dll 2017-08-09 19:25 - 2017-07-08 19:05 - 003631616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-08-09 19:25 - 2017-07-08 18:39 - 005274624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glcndFilter.dll 2017-08-09 19:25 - 2017-07-08 18:37 - 007797248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-08-09 19:25 - 2017-07-08 18:23 - 002749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2017-08-09 19:25 - 2017-07-08 17:59 - 005270016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-08-09 19:25 - 2017-07-08 05:46 - 000377688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgrx.sys 2017-08-09 19:25 - 2017-07-08 05:16 - 007440728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-08-09 19:25 - 2017-07-01 15:47 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswdat10.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000641536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000616448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrepl40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspbde40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstext40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll 2017-08-09 19:25 - 2017-07-01 15:47 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjter40.dll 2017-08-09 19:25 - 2017-06-24 18:46 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll 2017-08-09 19:25 - 2017-06-24 18:16 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprapi.dll 2017-08-09 19:25 - 2017-06-13 19:23 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll 2017-08-09 19:25 - 2017-06-13 19:19 - 000383488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll 2017-08-09 19:25 - 2017-06-13 19:11 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll 2017-08-09 19:25 - 2017-06-13 19:07 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll 2017-08-09 19:25 - 2017-06-13 16:17 - 000656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll 2017-08-09 19:25 - 2017-06-13 16:16 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll 2017-08-09 19:25 - 2017-06-13 11:47 - 000445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2017-08-09 19:25 - 2017-06-13 10:22 - 001436160 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2017-08-09 19:25 - 2017-06-13 10:03 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2017-08-09 19:25 - 2017-06-13 09:50 - 001547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2017-08-09 19:25 - 2017-06-12 02:14 - 000276320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys 2017-08-09 19:25 - 2017-06-11 22:13 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\umrdp.dll 2017-08-09 19:25 - 2017-06-11 22:11 - 000346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll 2017-08-09 19:25 - 2017-06-11 22:02 - 002778112 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2017-08-09 19:25 - 2017-06-11 22:02 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll 2017-08-09 19:25 - 2017-06-11 21:52 - 002463744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2017-08-09 19:25 - 2017-06-08 03:48 - 002457936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2017-08-09 19:25 - 2017-06-07 06:25 - 000428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2017-08-09 19:25 - 2017-06-06 20:38 - 000607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll 2017-08-09 19:25 - 2017-06-06 19:44 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll 2017-08-09 19:25 - 2017-05-27 18:42 - 001115136 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2017-08-09 19:24 - 2017-07-14 22:08 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2017-08-09 19:24 - 2017-07-14 20:44 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2017-08-09 19:24 - 2017-07-14 08:44 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-08-09 19:24 - 2017-07-14 08:19 - 000817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2017-08-09 19:24 - 2017-07-14 07:26 - 001033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2017-08-09 19:24 - 2017-07-14 07:10 - 000806912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2017-08-09 19:24 - 2017-07-14 06:23 - 003240960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-08-09 19:24 - 2017-07-14 06:07 - 001545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-08-09 19:24 - 2017-07-14 05:58 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2017-08-09 19:24 - 2017-07-14 04:48 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-08-09 19:24 - 2017-07-14 04:38 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2017-08-09 19:24 - 2017-07-14 04:17 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2017-08-09 19:24 - 2017-07-14 04:12 - 000693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2017-08-09 19:24 - 2017-07-14 04:09 - 013663744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-08-09 19:24 - 2017-07-14 03:53 - 002767872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2017-08-09 19:24 - 2017-07-14 03:50 - 001314816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-08-09 19:24 - 2017-07-14 03:48 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2017-08-09 19:24 - 2017-07-08 05:16 - 001674520 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2017-08-09 19:24 - 2017-07-08 05:16 - 001534072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2017-08-09 19:24 - 2017-07-08 05:16 - 001499920 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2017-08-09 19:24 - 2017-07-08 05:16 - 001370328 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2017-08-09 19:24 - 2017-07-08 05:16 - 000086360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2017-08-09 19:24 - 2017-06-15 16:17 - 002551808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2017-08-09 19:24 - 2017-06-15 16:16 - 001920000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2017-08-09 19:24 - 2017-06-13 19:51 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2017-08-09 19:24 - 2017-06-13 19:16 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll 2017-08-09 19:24 - 2017-06-13 11:09 - 000445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2017-08-09 19:24 - 2017-06-13 10:16 - 000445952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll 2017-08-09 19:24 - 2017-06-13 10:10 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll 2017-08-09 19:24 - 2017-06-13 10:07 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll 2017-08-09 19:24 - 2017-06-13 09:54 - 000374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 2017-08-09 19:24 - 2017-06-09 15:47 - 000448629 _____ C:\WINDOWS\system32\ApnDatabase.xml 2017-08-09 19:24 - 2017-06-08 19:01 - 001737600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2017-08-09 19:24 - 2017-06-08 19:01 - 001502000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2017-08-09 19:24 - 2017-05-27 18:38 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdsdwmdr.dll 2017-08-03 17:07 - 2017-08-03 17:07 - 008185288 _____ (Malwarebytes) C:\Users\ac\Downloads\adwcleaner_7.0.1.0 (2).exe 2017-08-03 16:54 - 2017-08-03 16:55 - 008185288 _____ (Malwarebytes) C:\Users\ac\Downloads\adwcleaner_7.0.1.0 (1).exe 2017-08-03 16:52 - 2017-08-03 16:55 - 008185288 _____ (Malwarebytes) C:\Users\ac\Downloads\adwcleaner_7.0.1.0.exe 2017-08-03 16:51 - 2017-08-03 16:51 - 000000000 ____D C:\ProgramData\Samsung ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-08-20 16:56 - 2014-09-24 17:26 - 000005646 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-08-20 16:56 - 2014-09-24 16:41 - 002005256 _____ C:\WINDOWS\system32\perfh00C.dat 2017-08-20 16:56 - 2014-09-24 16:41 - 000629036 _____ C:\WINDOWS\system32\perfc00C.dat 2017-08-20 16:55 - 2014-10-26 01:23 - 000000000 ____D C:\ProgramData\NVIDIA 2017-08-20 16:54 - 2013-10-30 23:49 - 000003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1975831795-1492635413-771006052-1002 2017-08-20 16:50 - 2015-06-06 14:29 - 000000505 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics 2017-08-20 16:50 - 2014-11-12 14:35 - 000000000 __RDO C:\Users\ac\OneDrive 2017-08-20 16:50 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\Inf 2017-08-20 16:48 - 2013-08-22 16:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-08-20 16:47 - 2013-08-22 15:25 - 000524288 ___SH C:\WINDOWS\system32\config\BBI 2017-08-19 23:31 - 2017-04-15 19:48 - 000000000 ____D C:\Users\ac\AppData\Roaming\uTorrent 2017-08-19 22:26 - 2014-06-06 19:01 - 000000000 ____D C:\Users\ac\AppData\Local\Battle.net 2017-08-19 21:10 - 2015-05-21 20:19 - 000000000 ____D C:\Users\ac\Documents\My Games 2017-08-19 21:08 - 2013-10-23 17:26 - 000000000 ____D C:\Users\ac\AppData\Roaming\Adobe 2017-08-19 20:19 - 2014-06-06 19:02 - 000000000 ____D C:\Program Files (x86)\World of Warcraft 2017-08-19 20:18 - 2014-06-06 19:01 - 000000000 ____D C:\Program Files (x86)\Battle.net 2017-08-19 13:57 - 2014-11-14 15:15 - 000007592 _____ C:\Users\ac\AppData\Local\Resmon.ResmonCfg 2017-08-19 13:14 - 2015-05-29 04:10 - 000000000 ____D C:\Users\ac\AppData\Local\Deployment 2017-08-18 20:37 - 2014-10-26 01:28 - 000000000 ____D C:\Users\ac 2017-08-18 12:04 - 2014-06-06 18:45 - 000002217 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-08-18 12:04 - 2014-06-06 18:45 - 000002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-08-18 11:14 - 2013-08-22 17:36 - 000000000 ___HD C:\Program Files\WindowsApps 2017-08-18 11:14 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\AppReadiness 2017-08-18 11:09 - 2015-05-26 02:56 - 000000000 ____D C:\Program Files (x86)\Hearthstone 2017-08-16 23:02 - 2016-06-20 02:32 - 000000000 ____D C:\Users\ac\AppData\Roaming\Spotify 2017-08-16 20:25 - 2016-06-20 02:32 - 000000000 ____D C:\Users\ac\AppData\Local\Spotify 2017-08-15 19:39 - 2017-04-17 21:28 - 000000000 ____D C:\Program Files (x86)\Steam 2017-08-15 13:43 - 2013-08-22 16:44 - 000550736 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-08-13 19:58 - 2012-07-26 09:59 - 000000000 ____D C:\WINDOWS\CbsTemp 2017-08-13 19:50 - 2014-06-08 10:34 - 000000000 ____D C:\WINDOWS\system32\MRT 2017-08-13 19:43 - 2014-06-08 10:34 - 140394280 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-08-09 21:47 - 2014-06-09 15:48 - 000004460 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2017-08-09 21:46 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-08-09 21:46 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\system32\Macromed 2017-08-03 16:57 - 2014-10-12 01:44 - 000000000 ____D C:\AdwCleaner 2017-08-03 16:56 - 2013-10-23 17:25 - 000000000 ____D C:\Users\ac\AppData\Local\Packages 2017-08-01 19:45 - 2013-10-30 23:46 - 000000000 ____D C:\Users\ac\AppData\Local\CrashDumps 2017-07-29 02:03 - 2017-07-09 01:10 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-07-29 02:03 - 2017-07-09 01:10 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-07-21 12:18 - 2014-12-28 00:27 - 000000000 ____D C:\WINDOWS\system32\appraiser ==================== Fichiers à la racine de certains dossiers ======= 2015-02-15 20:14 - 2015-02-15 20:14 - 000000109 _____ () C:\Users\ac\AppData\Roaming\D2Info0 2015-02-15 20:14 - 2015-02-15 21:34 - 000000008 _____ () C:\Users\ac\AppData\Roaming\DofusAppId0_1 2014-06-07 17:04 - 2014-06-07 17:04 - 000000043 _____ () C:\Users\ac\AppData\Roaming\WB.CFG 2014-11-14 15:15 - 2017-08-19 13:57 - 000007592 _____ () C:\Users\ac\AppData\Local\Resmon.ResmonCfg 2013-07-24 06:53 - 2013-07-24 06:53 - 000000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2016-12-30 17:58 ==================== Fin de FRST.txt ============================