Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 11-09-2017 02 Exécuté par clips (administrateur) sur DESKTOP-BCUPR2E (12-09-2017 16:39:08) Exécuté depuis C:\Users\clips\Desktop Profils chargés: clips (Profils disponibles: clips) Platform: Windows 10 Home Version 1703 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.2.2.524\AsusWSWinService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS GIFTBOX Desktop\ASUSGiftBoxDesktop.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\PixelMaster Video HDR\DriverMFTService.exe (Intel Corporation) C:\Windows\System32\ibtsiva.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (McAfee, Inc.) C:\Program Files\mcafee\vul\McV12B8.tmp (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe () C:\Windows\System32\igfxTray.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe () C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\FIRSTRUN.EXE (ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.2.6.547\AsusWSPanel.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_7\mcapexe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\McCSPServiceHost.exe (Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Program Files\mcafee\MfeAV\MfeAVSvc.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8500.40725.0_x64__8wekyb3d8bbwe\HxOutlook.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8500.40725.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Spotify Ltd) C:\Users\clips\AppData\Roaming\Spotify\SpotifyWebHelper.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe ==================== Registre (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-24] (NVIDIA Corporation) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.2.6.547\ASUSWSLoader.exe [63272 2015-12-24] () HKLM-x32\...\Run: [ROGNB] => C:\Program Files (x86)\ASUS Gaming Mouse\hid.exe [463872 2013-05-15] () HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-12] (Oracle Corporation) HKU\S-1-5-21-1086667615-2688694175-826190078-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2860832 2016-10-13] (Valve Corporation) HKU\S-1-5-21-1086667615-2688694175-826190078-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9832152 2017-08-03] (Piriform Ltd) HKU\S-1-5-21-1086667615-2688694175-826190078-1001\...\Run: [Spotify] => C:\Users\clips\AppData\Roaming\Spotify\Spotify.exe [7111792 2017-07-25] (Spotify Ltd) HKU\S-1-5-21-1086667615-2688694175-826190078-1001\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [912480 2015-09-02] (Microsoft Corporation) HKU\S-1-5-21-1086667615-2688694175-826190078-1001\...\Run: [Spotify Web Helper] => C:\Users\clips\AppData\Roaming\Spotify\Spotify.exe [7111792 2017-07-25] (Spotify Ltd) HKU\S-1-5-21-1086667615-2688694175-826190078-1001\...\RunOnce: [FlashPlayerUpdate] => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_151_pepper.exe [1281024 2017-08-08] (Adobe Systems Incorporated) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2016-07-11] ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) GroupPolicy: Restriction - Chrome <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 Tcpip\..\Interfaces\{d7e68dd5-e9d4-462e-9c95-2023963b006c}: [DhcpNameServer] 192.168.0.254 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1086667615-2688694175-826190078-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1086667615-2688694175-826190078-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus15.msn.com/?pc=ASTE SearchScopes: HKU\S-1-5-21-1086667615-2688694175-826190078-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3333673&octid=EB_ORIGINAL_CTID&ISID=BE8CB65E-FB6F-4ECD-A263-293F946E8840&SearchSource=58&CUI=&UM=8&UP=SPFD16B58F-B0CB-484D-8530-D0CB4C5A074D&D=110416&q={searchTerms}&SSPV= BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-07-25] (McAfee, Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\ssv.dll [2017-07-26] (Oracle Corporation) BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-04-30] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-07-25] (McAfee, Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\jp2ssv.dll [2017-07-26] (Oracle Corporation) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-07-25] (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-07-25] (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-07-25] (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-07-25] (McAfee, Inc.) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2017-08-08] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2017-08-08] (McAfee, Inc.) FireFox: ======== FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-07-20] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2017-09-12] [non signé] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-08] () FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-08-08] () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-08] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.141.2 -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\dtplugin\npDeployJava1.dll [2017-07-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.141.2 -> C:\Program Files (x86)\Java\jre1.8.0_141\bin\plugin2\npjp2.dll [2017-07-26] (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-08-08] () FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-15] () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-01] (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.fr/ CHR StartupUrls: Default -> "hxxp://www.google.fr/" CHR Profile: C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default [2017-09-12] CHR Extension: (Google Slides) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-24] CHR Extension: (Google Docs) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-25] CHR Extension: (Google Drive) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-24] CHR Extension: (YouTube) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-24] CHR Extension: (Spotify - Music for every moment) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2017-07-16] CHR Extension: (Google Agenda) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-01-09] CHR Extension: (Google Sheets) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-24] CHR Extension: (Word Online) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\fiombgjlkfpdpkbhfioofeeinbehmajg [2016-03-24] CHR Extension: (Google Docs hors connexion) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-25] CHR Extension: (Google Sites) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmandedkgonhldbnjpikffdnneenijnd [2017-08-06] CHR Extension: (Google Keep – Notes et listes) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2017-09-12] CHR Extension: (Excel Online) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljnkagajgfdmfnnidjijobijlfjfgnb [2016-03-24] CHR Extension: (Google Maps) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-03-24] CHR Extension: (Extension Google Keep pour Chrome) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2016-08-05] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-27] CHR Extension: (Picasa) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2016-03-24] CHR Extension: (Gmail) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-24] CHR Extension: (Chrome Media Router) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-26] CHR Extension: (Always Weather) - C:\Users\clips\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmcboldhlmhecoigccicmippjglnhhic [2017-09-08] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-06-17] CHR HKLM-x32\...\Chrome\Extension: [clgckgfbhciacomhlchmgdnplmdiadbj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-06-17] ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.2.2.524\AsusWSWinService.exe [71168 2015-05-31] (ASUS Cloud Corporation) [Fichier non signé] R2 ASUSGiftBoxDekstop; C:\Program Files (x86)\ASUS\ASUS GIFTBOX Desktop\ASUSGIFTBOXDesktop.exe [315704 2015-07-20] (ASUS) S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1511728 2017-08-10] (McAfee, Inc.) R2 DriverMFTService; C:\Program Files (x86)\Asus\PixelMaster Video HDR\DriverMFTService.exe [20992 2015-05-19] (ASUSTek Computer Inc.) [Fichier non signé] R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373312 2015-04-14] (WildTangent) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [Fichier non signé] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [321896 2017-07-06] (HP Inc.) R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373728 2016-11-30] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Fichier non signé] S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Fichier non signé] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation) S2 Kingsoft_WPS_UpdateService; C:\Program Files (x86)\Kingsoft\WPS Office\9.1.0.4947\wtoolex\wpsupdatesvr.exe [133480 2015-07-21] (Zhuhai Kingsoft Office Software Co.,Ltd) R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [590880 2017-07-25] (McAfee, Inc.) R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe [993256 2017-08-07] (McAfee, Inc.) S3 McAWFwk; C:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [338208 2015-03-19] (McAfee, Inc.) R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\\McCSPServiceHost.exe [2139832 2017-05-31] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [242640 2017-06-21] (McAfee, Inc.) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [394704 2017-06-21] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [350160 2017-06-21] (McAfee, Inc.) R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1546904 2017-08-17] (McAfee, Inc.) R3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2016-10-06] () S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Fichier non signé] R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1043864 2017-07-31] (Intel Security, Inc.) S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Fichier non signé] R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3732896 2016-10-06] (Intel® Corporation) R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X] ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [128024 2017-03-09] (ASUS Corporation) R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77800 2017-06-26] (McAfee, Inc.) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [209608 2017-08-07] (McAfee, Inc.) R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230144 2016-11-11] (Intel Corporation) R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [88256 2015-06-26] (Intel Corporation) S3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [487408 2017-06-26] (McAfee, Inc.) U3 mfeaack01; pas de ImagePath R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [355312 2017-06-26] (McAfee, Inc.) U3 mfeavfk02; pas de ImagePath S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [84544 2017-06-26] (McAfee, Inc.) R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [506352 2017-06-26] (McAfee, Inc.) R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [933360 2017-06-26] (McAfee, Inc.) U3 mfehidk01; pas de ImagePath R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [504792 2017-06-27] (McAfee LLC.) S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [108504 2017-06-27] (McAfee LLC.) R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [116208 2017-06-26] (McAfee, Inc.) R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.) R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [253424 2017-06-26] (McAfee, Inc.) R3 NETwNb64; C:\WINDOWS\system32\DRIVERS\Netwbw02.sys [3525896 2016-11-09] (Intel Corporation) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvamwu.inf_amd64_d4715679184092a8\nvlddmkm.sys [13754936 2016-09-12] (NVIDIA Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [887552 2015-07-15] (Realtek ) R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [753368 2015-06-15] (Realsil Semiconductor Corporation) S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-09-12 16:39 - 2017-09-12 16:40 - 000028230 _____ C:\Users\clips\Desktop\FRST.txt 2017-09-12 16:39 - 2017-09-12 16:39 - 000000000 ____D C:\FRST 2017-09-12 16:32 - 2017-09-12 16:33 - 002397184 _____ (Farbar) C:\Users\clips\Desktop\FRST64.exe 2017-09-12 13:24 - 2017-09-12 13:53 - 000000000 ____D C:\Users\clips\Downloads\analized 17 09 11 sarah banks can take it as hard as you can give it tk 480p 2017-09-12 13:24 - 2017-09-12 13:48 - 000000000 ____D C:\Users\clips\Downloads\assparade 17 09 11 jynx maze tk 480p 2017-09-12 12:55 - 2017-09-12 13:17 - 000000000 ____D C:\Users\clips\Downloads\ExposedCasting - Lucia Denville 2017-09-12 12:42 - 2017-09-12 12:42 - 000110080 _____ C:\Users\clips\Downloads\COPIE - Tableaux promouvables SUEP RAEP BIER 2018 (1).xls 2017-09-12 12:21 - 2017-09-12 12:21 - 000012173 _____ C:\Users\clips\Desktop\Avancement MAJOR 2018 LUDO D2.xlsx 2017-09-12 11:42 - 2017-09-12 11:42 - 000066048 _____ C:\Users\clips\Downloads\COPIE - TableauxPromouvablesSUEP_Major_2018 (1).xls 2017-09-12 11:41 - 2017-09-12 11:41 - 000066048 _____ C:\Users\clips\Downloads\COPIE - TableauxPromouvablesSUEP_Major_2018.xls 2017-09-12 11:41 - 2017-09-12 11:41 - 000012459 _____ C:\Users\clips\Desktop\Avancement BC 2018 D2 LUDO.xlsx 2017-09-12 11:26 - 2017-09-12 11:26 - 000068608 _____ C:\Users\clips\Downloads\COPIE - TableauxPromouvablesSUEP_BC_2018.xls 2017-09-12 11:25 - 2017-09-12 11:26 - 000014318 _____ C:\Users\clips\Desktop\AVANCEMENT BRIGADIER 2018 LUDO D2.xlsx 2017-09-12 10:35 - 2017-09-12 10:35 - 000110080 _____ C:\Users\clips\Downloads\COPIE - Tableaux promouvables SUEP RAEP BIER 2018.xls 2017-09-12 10:29 - 2017-09-12 10:29 - 000011450 _____ C:\Users\clips\Desktop\Avancement BC 2018 modele vierge.xlsx 2017-09-12 10:29 - 2017-09-12 10:29 - 000011335 _____ C:\Users\clips\Desktop\Avancement MAJOR 2018 modele vierge.xlsx 2017-09-12 10:27 - 2017-09-12 10:27 - 000013281 _____ C:\Users\clips\Desktop\AVANCEMENT BRIGADIER 2018 modele vierge.xlsx 2017-09-12 01:10 - 2017-09-12 01:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2017-09-12 00:46 - 2017-09-12 00:46 - 000000000 ___HD C:\OneDriveTemp 2017-09-08 19:42 - 2017-09-12 13:29 - 000000000 ____D C:\Users\clips\Downloads\HerLimit European hottie Gabriella Lati enjoys hardcore anal and gets facial 02 09 2017 rq 2017-09-08 19:42 - 2017-09-12 12:47 - 000004034 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse 2017-09-08 19:42 - 2017-09-12 01:00 - 000004222 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse 2017-09-08 19:41 - 2017-09-12 01:42 - 000000000 ____D C:\Users\clips\Downloads\BackroomCastingCouch Elizabeth 11 09 2017 rq 2017-09-08 19:40 - 2017-09-12 01:42 - 000000000 ____D C:\Users\clips\Downloads\BackroomCastingCouch Jessi 04 09 2017 rq 2017-09-08 19:38 - 2017-09-12 13:22 - 000000000 ____D C:\Users\clips\Downloads\WoodmanCastingX Anna Swix Casting X 170 Updated - 02 09 2017 rq 480p 2017-09-08 19:37 - 2017-09-12 12:55 - 000000000 ____D C:\Users\clips\Downloads\Alex Grey 2017-09-08 19:36 - 2017-09-12 01:42 - 000000000 ____D C:\Users\clips\Downloads\Maddy O Reilly 2017-09-08 19:35 - 2017-09-12 01:37 - 000000000 ____D C:\Users\clips\Downloads\Nelya 2017-09-08 19:23 - 2017-09-08 19:48 - 000000000 ____D C:\Users\clips\Downloads\TeenErotica xxx Selvaggia Babe - Interracial Creampie for a Teen 04 09 2017 rq 2017-09-08 19:16 - 2017-09-08 19:46 - 000000000 ____D C:\Users\clips\Downloads\DaneJones Sofi Goldfinger - Anal creampie for gorgeous blonde 05 09 2017 rq 2017-09-08 19:10 - 2017-09-08 19:35 - 000000000 ____D C:\Users\clips\Downloads\BigButtsLikeItBig Lena Paul - Lay Her Over 07 09 2017 rq 1k 2017-09-08 18:53 - 2017-09-08 19:23 - 000000000 ____D C:\Users\clips\Downloads\MassiveBootyAnalCutie s01 MickBlue DaisyStone 480p 2017-09-08 18:18 - 2017-09-12 12:54 - 000000000 ____D C:\Users\clips\Downloads\Legal Curvy spanish slut Nekane Sweet anal POV SZ1389 29 08 2017 rq 2017-09-08 18:18 - 2017-09-12 12:54 - 000000000 ____D C:\Users\clips\Downloads\JacquieEtMichelTV Kate 29 08 2017 rq 2017-09-08 18:18 - 2017-09-08 19:16 - 000000000 ____D C:\Users\clips\Downloads\Legal Adelle Booty ass banged creampied NR361 01 09 2017 rq 2017-09-08 18:18 - 2017-09-08 19:10 - 000000000 ____D C:\Users\clips\Downloads\Analized Maxim Law Is A Submissive Anal Whore 27 08 2017 rq 2017-09-08 18:13 - 2017-09-08 18:53 - 000000000 ____D C:\Users\clips\Downloads\AmateurAllure Ashly Anderson Returns 01 09 2017 rq 2017-09-08 17:54 - 2017-09-08 17:54 - 000547291 _____ C:\Users\clips\Desktop\PJ 1 TG 1378 - TABLE POSTES.pdf 2017-09-08 17:54 - 2017-09-08 17:54 - 000547291 _____ C:\Users\clips\Desktop\PJ 1 TG 1378 - TABLE POSTES(1).pdf 2017-09-08 17:48 - 2017-09-08 17:48 - 000536315 _____ ( ) C:\Users\clips\Downloads\file (1).exe 2017-09-08 17:48 - 2017-09-08 17:48 - 000000290 __RSH C:\ProgramData\ntuser.pol 2017-09-08 17:47 - 2017-09-08 17:47 - 000536315 _____ ( ) C:\Users\clips\Downloads\file.exe 2017-09-08 17:46 - 2017-09-08 17:46 - 000536315 _____ ( ) C:\Users\clips\Downloads\McAfee_Total_Protection_2017_Crack.exe 2017-09-07 01:59 - 2017-09-08 18:37 - 000000000 ____D C:\Users\clips\Downloads\Assholefever Lilu Moon - Wonder Ass 02 09 2017 rq 2017-09-05 02:29 - 2017-09-08 18:13 - 000000000 ____D C:\Users\clips\Downloads\AmateurAllure Nina Skye 25 08 2017 rq 2017-09-05 02:16 - 2017-09-07 01:59 - 000000000 ____D C:\Users\clips\Downloads\ATKGirlfriends Lyra Law - Her asshole felt good but you came in her pussy instead 27 08 2017 rq 2017-09-05 02:04 - 2017-09-05 02:29 - 000000000 ____D C:\Users\clips\Downloads\AssParade 17 08 28 Mia Malkova 2017-09-05 02:03 - 2017-09-08 18:16 - 000000000 ____D C:\Users\clips\Downloads\PornDoePedia - Nekane 720p 2017-09-05 01:43 - 2017-09-05 02:16 - 000000000 ____D C:\Users\clips\Downloads\AnalTeenAngels Michelle Carr - Plug My Asshole 29 08 2017 rq 2017-09-05 01:26 - 2017-09-05 01:27 - 000047400 _____ C:\Users\clips\Documents\cc_20170905_012655.reg 2017-09-05 01:17 - 2017-09-05 01:18 - 009791816 _____ (Piriform Ltd) C:\Users\clips\Downloads\ccsetup533.exe 2017-09-03 01:24 - 2017-09-05 02:04 - 000000000 ____D C:\Users\clips\Downloads\Holed Kira Thorn - Backdoor Blonde 29 08 2017 rq 2017-09-03 00:56 - 2017-09-05 02:03 - 000000000 ____D C:\Users\clips\Downloads\WakeUpNFuck Alexa Nova WUNF 224 - 14 08 2017 rq 2017-09-03 00:56 - 2017-09-05 01:43 - 000000000 ____D C:\Users\clips\Downloads\FirstAnalQuest First anal sex with sexy Cassie Fire 28 08 2017 rq 2017-09-03 00:39 - 2017-09-03 00:51 - 000000000 ____D C:\Users\clips\Downloads\DollsPorn Anita - Passionate Anal Fucking 29 08 2017 rq 2017-09-03 00:27 - 2017-09-03 00:44 - 000000000 ____D C:\Users\clips\Downloads\Alex Harper 2017-09-03 00:16 - 2017-09-03 01:24 - 000000000 ____D C:\Users\clips\Downloads\Analized JamesDeen Jojo Kiss Anal Schoolgirl Slave 05 09 2017 rq 2017-09-01 02:05 - 2017-09-01 02:05 - 000640252 _____ C:\Users\clips\Downloads\2016_12_13_fichetechnique_gpbi.pdf 2017-08-29 10:41 - 2017-08-29 10:41 - 000084130 _____ C:\Users\clips\Downloads\Relevᅢᄅ d'informations (1).pdf 2017-08-29 10:38 - 2017-08-29 10:38 - 000084130 _____ C:\Users\clips\Downloads\Relevᅢᄅ d'informations.pdf ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-09-12 16:37 - 2017-04-03 11:38 - 000000000 ____D C:\Users\clips\AppData\Roaming\WhatsApp 2017-09-12 16:37 - 2016-03-25 02:47 - 000000000 ____D C:\Users\clips\AppData\Local\JDownloader v2.0 2017-09-12 16:37 - 2016-03-25 02:18 - 000000000 ____D C:\Users\clips\AppData\Roaming\vlc 2017-09-12 16:32 - 2016-03-24 21:07 - 000000165 _____ C:\Users\clips\AppData\Roaming\sp_data.sys 2017-09-12 15:55 - 2017-06-05 02:13 - 000004176 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{45A5A744-D4A7-45CE-B814-DB8E59DEB89C} 2017-09-12 15:11 - 2017-06-05 01:50 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2017-09-12 13:01 - 2016-03-25 01:03 - 000000000 ____D C:\Users\clips\AppData\Local\Spotify 2017-09-12 12:58 - 2016-03-25 01:02 - 000000000 ____D C:\Users\clips\AppData\Roaming\Spotify 2017-09-12 01:05 - 2017-06-05 02:13 - 000003126 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon 2017-09-12 01:05 - 2015-09-01 10:12 - 000000000 ____D C:\Program Files\Common Files\McAfee 2017-09-12 01:02 - 2017-03-18 23:03 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2017-09-12 01:01 - 2017-06-05 02:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\McAfee 2017-09-12 00:50 - 2017-03-18 23:03 - 000000000 ___HD C:\Program Files\WindowsApps 2017-09-12 00:50 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\AppReadiness 2017-09-12 00:46 - 2017-08-09 13:49 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture 2017-09-12 00:46 - 2017-06-05 01:54 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2017-09-12 00:46 - 2016-03-24 21:10 - 000000000 ___RD C:\Users\clips\OneDrive 2017-09-12 00:46 - 2016-03-24 21:07 - 000000000 __SHD C:\Users\clips\IntelGraphicsProfiles 2017-09-08 19:46 - 2015-09-01 10:12 - 000000000 ____D C:\ProgramData\McAfee 2017-09-08 19:42 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\rescache 2017-09-08 17:48 - 2017-03-18 23:03 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2017-09-08 17:48 - 2017-03-18 23:01 - 000000000 ____D C:\WINDOWS\INF 2017-09-08 17:48 - 2015-07-10 13:04 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2017-09-08 17:34 - 2017-07-27 00:39 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1086667615-2688694175-826190078-1001 2017-09-08 17:34 - 2016-03-24 21:10 - 000002409 _____ C:\Users\clips\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-09-07 01:39 - 2017-04-03 11:38 - 000000000 ____D C:\Users\clips\AppData\Local\WhatsApp 2017-09-07 01:38 - 2017-04-03 11:38 - 000002240 _____ C:\Users\clips\Desktop\WhatsApp.lnk 2017-09-07 01:38 - 2017-04-03 11:38 - 000000000 ____D C:\Users\clips\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2017-09-07 01:38 - 2017-04-03 11:38 - 000000000 ____D C:\Users\clips\AppData\Local\SquirrelTemp 2017-09-05 01:28 - 2016-03-24 21:07 - 000000000 ____D C:\Users\clips\AppData\Local\Packages 2017-09-05 01:19 - 2017-05-12 00:38 - 000000865 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-09-01 02:07 - 2017-06-05 02:13 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2017-09-01 02:07 - 2017-04-18 00:24 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-09-01 02:07 - 2017-04-18 00:24 - 000002126 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2017-08-30 03:29 - 2017-06-05 01:50 - 000415432 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-08-30 03:28 - 2017-06-05 02:13 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-08-29 10:48 - 2017-03-18 13:40 - 001048576 _____ C:\WINDOWS\system32\config\BBI 2017-08-29 10:43 - 2017-06-05 01:56 - 000000000 ____D C:\Users\clips 2017-08-29 10:42 - 2016-09-28 16:37 - 000000000 ____D C:\Users\clips\Desktop\chloé 2017-08-29 10:42 - 2016-03-24 21:13 - 000002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-08-27 01:15 - 2016-03-30 01:08 - 000000000 ____D C:\Users\clips\AppData\Roaming\Skype 2017-08-27 00:24 - 2017-08-06 16:43 - 000544424 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe ==================== Fichiers à la racine de certains dossiers ======= 2016-03-24 21:07 - 2017-09-12 16:32 - 000000165 _____ () C:\Users\clips\AppData\Roaming\sp_data.sys 2017-06-05 01:54 - 2017-06-05 01:54 - 000000000 ____H () C:\ProgramData\DP45977C.lfl 2016-07-11 00:34 - 2017-07-02 23:06 - 000001347 _____ () C:\ProgramData\hpzinstall.log Certains fichiers dans TEMP: ==================== 2017-09-12 01:12 - 2017-09-12 01:12 - 000040448 ____N () C:\Users\clips\AppData\Local\Temp\proxy_vole7765123168898697648.dll ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2017-09-08 19:36 ==================== Fin de FRST.txt ============================