Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 16-09-2017 Exécuté par Muller (administrateur) sur PCDEFLORIAN (17-09-2017 18:04:51) Exécuté depuis C:\Users\Muller\Desktop Profils chargés: Muller (Profils disponibles: Muller) Platform: Windows 10 Pro Version 1511 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe (Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe (Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe (pdfforge GmbH) C:\Program Files\PDF Architect 5\creator-ws.exe (© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe (Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe () C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe () C:\Program Files\ByteFence\rtop\bin\rtop_bg.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHTE.EXE (Flux Software LLC) C:\Users\Muller\AppData\Local\FluxSoftware\Flux\flux.exe (Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken_Driver\Drivers\SysAudio\KrakenHelper.exe () C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken71Chroma_Driver\Drivers\SysAudio\Kraken71ChromaHelper.exe (Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe (Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe (Razer, Inc.) C:\Users\Muller\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\rzcefrenderprocess.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe ==================== Registre (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-05-09] (Apple Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2017-04-13] (Razer Inc.) HKLM-x32\...\Run: [KrakenLauncher] => C:\Program Files (x86)\Razer\Razer_Kraken_Driver\Drivers\SysAudio\KrakenHelper.exe [1599808 2015-08-14] (Razer Inc) HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [75776 2017-01-09] () HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [97512 2017-05-22] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [919032 2017-09-14] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Kraken71ChromaHelper] => C:\Program Files (x86)\Razer\Razer_Kraken71Chroma_Driver\Drivers\SysAudio\Kraken71ChromaHelper.exe [1600096 2017-02-14] (Razer Inc) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [568904 2016-01-24] () HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTE.EXE [241280 2016-04-03] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2851408 2016-07-09] (Valve Corporation) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [f.lux] => C:\Users\Muller\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [Reflector2] => [X] HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [Discord] => C:\Users\Muller\AppData\Local\Discord\app-0.0.298\Discord.exe [57477112 2017-08-08] (Discord Inc.) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1951336 2017-05-09] (Lavasoft) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [Spotify] => C:\Users\Muller\AppData\Roaming\Spotify\Spotify.exe [20644976 2017-09-16] (Spotify Ltd) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-05-09] (Apple Inc.) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1092920 2017-02-16] (Apple Inc.) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2017-05-09] (Apple Inc.) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2017-05-09] (Apple Inc.) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2017-05-09] (Apple Inc.) HKU\S-1-5-21-34950723-3622257856-1134976912-1001\...\Run: [Spotify Web Helper] => C:\Users\Muller\AppData\Roaming\Spotify\SpotifyWebHelper.exe [777840 2017-09-16] (Spotify Ltd) HKU\S-1-5-18\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1951336 2017-05-09] (Lavasoft) GroupPolicy: Restriction <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{0ff3647f-a817-4c6c-b160-85bae090d5a9}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{d734db0d-9a6e-48ea-8126-c59fae198a5f}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKU\S-1-5-21-34950723-3622257856-1134976912-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/fr-fr/?ocid=iehp HKU\S-1-5-21-34950723-3622257856-1134976912-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D042817-A8D15A5DDE3&form=CONMHP&conlogo=CT3335578 SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-34950723-3622257856-1134976912-1001 -> DefaultScope {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-07-07] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-07] (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-04-23] (Oracle Corporation) BHO-x32: PDF Architect 5 Helper -> {AEA429F3-D2D4-4BD7-A03E-5357DA017733} -> C:\Program Files (x86)\PDF Architect 5\creator-ie-helper.dll [2017-02-10] (pdfforge GmbH) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-23] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect 5 Toolbar - {84F23192-A475-4038-B5C0-8584777F2DF4} - C:\Program Files (x86)\PDF Architect 5\creator-ie-plugin.dll [2017-02-10] (pdfforge GmbH) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Muller\AppData\Roaming\Mozilla\Firefox\Profiles\frJDfj6B.default [2017-04-28] FF NewTab: Mozilla\Firefox\Profiles\frJDfj6B.default -> hxxp://www.bing.com/?pc=COSP&ptag=D042817-A8D15A5DDE3&form=CONMHP&conlogo=CT3335578 FF DefaultSearchEngine: Mozilla\Firefox\Profiles\frJDfj6B.default -> Bing® FF SelectedSearchEngine: Mozilla\Firefox\Profiles\frJDfj6B.default -> Bing® FF Homepage: Mozilla\Firefox\Profiles\frJDfj6B.default -> hxxp://www.bing.com/?pc=COSP&ptag=D042817-A8D15A5DDE3&form=CONMHP&conlogo=CT3335578 FF Extension: (Protection Web Avira) - C:\Users\Muller\AppData\Roaming\Mozilla\Firefox\Profiles\frJDfj6B.default\Extensions\abs@avira.com.xpi [2017-04-16] FF SearchPlugin: C:\Users\Muller\AppData\Roaming\Mozilla\Firefox\Profiles\frJDfj6B.default\searchplugins\bing-lavasoft.xml [2017-04-28] FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-07] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-07] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1228198.dll [2017-02-27] (Adobe Systems, Inc.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-23] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-23] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-02-23] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-02-23] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-29] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-29] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [2017-02-10] (pdfforge GmbH) Chrome: ======= CHR DefaultSearchURL: Default -> hxxp://securedsearch.xyz/{searchTerms} CHR DefaultSearchKeyword: Default -> sse CHR DefaultSuggestURL: Default -> hxxp://securedsearch.xyz/?s={searchTerms} CHR Profile: C:\Users\Muller\AppData\Local\Google\Chrome\User Data\Default [2017-09-17] CHR Extension: (wanteeed) - C:\Users\Muller\AppData\Local\Google\Chrome\User Data\Default\Extensions\emnoomldgleagdjapdeckpmebokijail [2017-06-28] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Muller\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-24] CHR Extension: (Adblock Pro) - C:\Users\Muller\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2016-11-10] CHR Extension: (Chrome Media Router) - C:\Users\Muller\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-27] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ilnidodcffjfecahcfiihlhiohnaobic] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-34950723-3622257856-1134976912-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ilnidodcffjfecahcfiihlhiohnaobic] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ilnidodcffjfecahcfiihlhiohnaobic] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [1128432 2017-09-14] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [490968 2017-09-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [490968 2017-09-14] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1525240 2017-09-14] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.) S2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [374352 2017-05-22] (Avira Operations GmbH & Co. KG) S2 ByteFenceService; C:\Program Files\ByteFence\ByteFenceService.exe [145888 2017-07-20] (Byte Technologies LLC) R2 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2017-02-24] (Foxit Software Inc.) R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2759784 2017-05-09] (Lavasoft Limited) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-13] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-02-23] (NVIDIA Corporation) R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-11-17] (NVIDIA Corporation) S3 PDF Architect 5; C:\Program Files\PDF Architect 5\ws.exe [2706824 2017-02-10] (pdfforge GmbH) S3 PDF Architect 5 CrashHandler; C:\Program Files\PDF Architect 5\crash-handler-ws.exe [1048976 2017-02-10] (pdfforge GmbH) R2 PDF Architect 5 Creator; C:\Program Files\PDF Architect 5\creator-ws.exe [856976 2017-02-10] (pdfforge GmbH) R2 PDF Architect 5 Manager; C:\ProgramData\pdfforge\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe [985904 2017-02-28] (© pdfforge GmbH.) R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [401024 2017-06-16] (Razer Inc.) R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [178824 2017-06-16] (Razer Inc.) S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] () R2 rtop; C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe [302920 2017-08-26] () R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7500048 2016-09-20] (TeamViewer GmbH) S2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25192 2017-05-09] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) S2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.2.221\WsAppService.exe [459408 2017-02-10] (Wondershare) S2 WsDrvInst; C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone pour iOS\Library\DriverInstaller\DriverInstall.exe [X] ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [60920 2017-06-20] (Avira Operations GmbH & Co. KG) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [176856 2017-09-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [167464 2017-09-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [44488 2017-02-17] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [88488 2017-02-17] (Avira Operations GmbH & Co. KG) R0 avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [38048 2017-06-20] (Avira Operations GmbH & Co. KG) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-11-17] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46016 2016-12-13] (NVIDIA Corporation) S3 PVUSB; C:\Windows\System32\drivers\CESG64.sys [63808 2007-02-19] (CASIO COMPUTER CO.,LTD.) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) S3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [3870464 2015-10-01] (Realtek Semiconductor Corporation ) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [130880 2015-12-15] (Razer, Inc.) R3 VCSVADHWSer; C:\Windows\system32\DRIVERS\vcsvad.sys [21504 2008-12-26] (Avnex) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) U0 aswVmm; pas de ImagePath ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-09-17 18:04 - 2017-09-17 18:06 - 000022246 _____ C:\Users\Muller\Desktop\FRST.txt 2017-09-17 18:04 - 2017-09-17 18:04 - 000000000 ____D C:\FRST 2017-09-17 18:03 - 2017-09-17 18:04 - 002398720 _____ (Farbar) C:\Users\Muller\Desktop\FRST64.exe 2017-09-17 18:02 - 2017-09-17 18:03 - 002398720 _____ (Farbar) C:\Users\Muller\Downloads\FRST64.exe 2017-09-17 15:16 - 2014-08-18 21:37 - 001025399 _____ C:\Users\Muller\Desktop\Huxley, Aldous - Le Meilleur Des Mondes Texte intégral.pdf 2017-09-17 14:08 - 2017-09-17 14:08 - 000001128 _____ C:\Users\Public\Desktop\paint.net.lnk 2017-09-09 14:24 - 2017-09-09 14:24 - 000006876 _____ C:\Users\Muller\AppData\Localtransition_141e712e61cf469e20686e3e77860fb0.ini 2017-09-09 14:24 - 2017-09-09 14:24 - 000001119 _____ C:\Users\Muller\AppData\Roaming\Microsoft\Windows\Start Menu\Dofus.lnk 2017-09-09 14:24 - 2017-09-09 14:24 - 000001117 _____ C:\Users\Muller\Desktop\Dofus.lnk 2017-09-09 14:24 - 2017-09-09 14:24 - 000000000 ____D C:\Users\Muller\AppData\Local\Ankama 2017-09-09 14:23 - 2017-09-09 14:24 - 006456928 _____ (Ankama Studio) C:\Users\Muller\Downloads\dofus.exe 2017-09-06 18:47 - 2017-09-06 18:48 - 000000000 ____D C:\Users\Muller\_ 2017-09-04 19:40 - 2017-09-04 19:40 - 000013809 _____ C:\Users\Muller\Downloads\flvto.zip 2017-09-04 16:43 - 2017-09-04 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IsoBuster 2017-09-04 16:43 - 2017-09-04 16:43 - 000000000 ____D C:\Program Files (x86)\Smart Projects 2017-09-04 16:42 - 2017-09-04 16:43 - 004844712 _____ (Smart Projects ) C:\Users\Muller\Downloads\isobuster_install.exe 2017-09-04 16:40 - 2017-09-04 16:40 - 001556480 _____ C:\Windows\is-CD5HA.exe 2017-09-04 16:40 - 2017-09-04 16:40 - 000029613 _____ C:\Windows\is-CD5HA.msg 2017-09-04 16:40 - 2017-09-04 16:40 - 000001787 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk 2017-09-04 16:40 - 2017-09-04 16:40 - 000000293 _____ C:\Windows\is-CD5HA.lst 2017-08-31 15:02 - 2017-08-31 15:02 - 000000000 ____D C:\Users\Muller\Desktop\Divers - Copie 2017-08-27 12:32 - 2017-08-27 12:34 - 000455988 _____ C:\Windows\Minidump\082717-22031-01.dmp 2017-08-27 12:32 - 2017-08-27 12:32 - 920304061 _____ C:\Windows\MEMORY.DMP 2017-08-26 15:13 - 2017-08-26 15:13 - 000000000 ____D C:\Users\Muller\AppData\Local\{D3B0E5EC-F718-8954-9A80-ACBCBEE85024} 2017-08-26 15:12 - 2017-08-26 15:12 - 000003548 _____ C:\Windows\System32\Tasks\ByteFence Scan 2017-08-26 15:12 - 2017-08-26 15:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware 2017-08-26 14:22 - 2017-08-26 14:22 - 000000000 ____D C:\ProgramData\ByteFence 2017-08-26 14:11 - 2017-08-27 02:13 - 000000000 ____D C:\Program Files\ByteFence 2017-08-26 14:11 - 2017-08-26 14:42 - 000000000 ____D C:\FFOutput 2017-08-26 14:11 - 2017-08-26 14:11 - 000003440 _____ C:\Windows\System32\Tasks\ByteFence 2017-08-26 14:10 - 2017-08-26 14:10 - 000001136 _____ C:\Users\Muller\Desktop\Format Factory.lnk 2017-08-26 14:10 - 2017-08-26 14:10 - 000000000 ____D C:\Users\Muller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2017-08-26 14:10 - 2017-08-26 14:10 - 000000000 ____D C:\Program Files (x86)\FormatFactory 2017-08-26 14:07 - 2017-08-26 14:10 - 047616432 _____ (Free Time Co., Ltd) C:\Users\Muller\Downloads\format-factory_4-0-0-0_fr_223920.exe 2017-08-25 19:32 - 2017-08-25 20:43 - 1354612816 _____ C:\Users\Muller\Downloads\Deadpool.Multi.TrueFrench.1080p.HDLight.x265.mkv 2017-08-23 13:18 - 2017-08-23 13:51 - 734610004 _____ C:\Users\Muller\Downloads\Annabelle.2014.TRUEFRENCH.SUBFORCED.BRRip.XviD-SVR.www.zone-telechargement.ws.avi ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-09-17 17:22 - 2017-07-19 20:41 - 000000000 ___RD C:\Users\Muller\iCloudDrive 2017-09-17 17:21 - 2016-01-21 16:11 - 000000000 ____D C:\ProgramData\NVIDIA 2017-09-17 14:45 - 2015-10-30 21:00 - 000824258 _____ C:\Windows\system32\perfh00C.dat 2017-09-17 14:45 - 2015-10-30 21:00 - 000155558 _____ C:\Windows\system32\perfc00C.dat 2017-09-17 14:45 - 2015-10-30 09:21 - 000000000 ____D C:\Windows\INF 2017-09-17 14:45 - 2015-10-30 04:33 - 001848398 _____ C:\Windows\system32\PerfStringBackup.INI 2017-09-17 14:08 - 2016-01-21 16:52 - 000001140 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2017-09-17 14:08 - 2016-01-21 16:52 - 000000000 ____D C:\Program Files\paint.net 2017-09-16 22:53 - 2017-07-07 23:36 - 000000000 ____D C:\Users\Muller\AppData\Roaming\.minecraft 2017-09-16 22:48 - 2016-03-28 14:19 - 000000000 ____D C:\Users\Muller\Documents\The Crew 2017-09-16 22:48 - 2016-03-27 22:11 - 000000000 ____D C:\Users\Muller\AppData\Local\Ubisoft Game Launcher 2017-09-16 22:46 - 2016-03-28 14:19 - 000000000 ____D C:\Users\Muller\Documents\ProfileCache 2017-09-16 21:33 - 2016-10-21 12:44 - 000000000 ____D C:\Users\Muller\AppData\Local\Spotify 2017-09-16 21:25 - 2016-10-21 12:43 - 000000000 ____D C:\Users\Muller\AppData\Roaming\Spotify 2017-09-16 21:25 - 2015-10-30 09:24 - 000000000 ____D C:\Windows\system32\FxsTmp 2017-09-14 17:14 - 2017-03-18 10:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2017-09-14 17:13 - 2017-03-18 12:56 - 000176856 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2017-09-14 17:13 - 2017-03-18 12:56 - 000167464 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2017-09-10 22:52 - 2015-10-30 04:32 - 000000000 ____D C:\Users\Muller 2017-09-06 18:48 - 2016-01-27 13:48 - 000000000 ____D C:\Users\Muller\AppData\Roaming\FileZilla 2017-09-06 12:36 - 2016-01-21 16:37 - 000002270 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-09-06 12:13 - 2016-01-21 16:51 - 000000000 ____D C:\Program Files\CDBurnerXP 2017-09-06 12:13 - 2015-10-30 04:28 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-09-04 16:40 - 2016-01-21 16:51 - 000001733 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2017-08-27 12:54 - 2016-01-23 10:20 - 000000000 ____D C:\Users\Muller\AppData\Local\CrashDumps 2017-08-27 12:32 - 2016-01-27 16:34 - 000000000 ____D C:\Windows\Minidump 2017-08-26 14:50 - 2016-04-12 23:22 - 000000000 ____D C:\Users\Muller\AppData\Roaming\vlc 2017-08-26 13:31 - 2015-10-30 09:24 - 000000000 ____D C:\Windows\LiveKernelReports 2017-08-25 19:47 - 2017-04-20 20:04 - 000000000 ____D C:\ProgramData\TEMP ==================== Fichiers à la racine de certains dossiers ======= 2016-03-29 21:36 - 2016-03-29 21:36 - 000000054 _____ () C:\Users\Muller\AppData\Roaming\updater.cfg 2017-01-16 11:01 - 2017-01-16 11:21 - 000004608 _____ () C:\Users\Muller\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-11-26 13:02 - 2016-11-26 21:49 - 001307648 _____ () C:\Users\Muller\AppData\Local\file__0.localstorage 2016-02-02 23:16 - 2017-05-06 22:24 - 000000600 _____ () C:\Users\Muller\AppData\Local\PUTTY.RND 2016-05-30 18:45 - 2016-11-08 21:42 - 000007626 _____ () C:\Users\Muller\AppData\Local\Resmon.ResmonCfg 2016-10-05 21:15 - 2016-10-05 21:15 - 000000003 _____ () C:\Users\Muller\AppData\Local\updater.log 2016-10-05 21:15 - 2016-10-05 21:15 - 000000424 _____ () C:\Users\Muller\AppData\Local\UserProducts.xml Certains fichiers dans TEMP: ==================== 2017-09-06 12:17 - 2017-09-17 17:21 - 000619616 _____ () C:\Users\Muller\AppData\Local\Temp\0Kraken71ChromaDevProps.dll 2017-09-06 12:17 - 2017-09-17 17:21 - 000619840 _____ () C:\Users\Muller\AppData\Local\Temp\0KrakenDevProps.dll 2017-09-17 12:44 - 2017-09-17 12:44 - 007235264 _____ () C:\Users\Muller\AppData\Local\Temp\paint.net.4.0.17.install.exe ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2016-06-03 17:13 ==================== Fin de FRST.txt ============================