Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 29-11-2017 Exécuté par NIKOO (administrateur) sur NIKO (29-11-2017 23:48:15) Exécuté depuis C:\Users\NIKOO\Downloads Profils chargés: UpdatusUser & NIKOO (Profils disponibles: UpdatusUser & NIKOO) Platform: Windows 8.1 (Update) (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe (Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Validity Sensors, Inc.) C:\Windows\System32\valWBFPolicyService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-08-16] (IDT, Inc.) HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2252536 2014-08-13] (Hewlett-Packard) HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [151608 2013-08-23] (Hewlett-Packard) HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [151608 2013-08-23] (Hewlett-Packard) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-02] (Synaptics Incorporated) HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe" HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-07-24] (Hewlett-Packard Company) HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2013-08-01] (CyberLink Corp.) HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-07-23] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1871344 2017-11-04] (Adobe Systems Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-05-22] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\System32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2497458167-863793282-2099140305-1002\...\Run: [uTorrent] => C:\Users\NIKOO\AppData\Roaming\uTorrent\uTorrent.exe [1982144 2017-10-11] (BitTorrent Inc.) HKU\S-1-5-21-2497458167-863793282-2099140305-1002\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [886768 2017-11-04] (Adobe Systems Incorporated) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk [2014-06-25] ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation) GroupPolicy: Restriction - Chrome <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 10.188.0.1 Tcpip\..\Interfaces\{D4DCDDEF-73AC-40B2-800A-869F520D3663}: [DhcpNameServer] 10.188.0.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/3 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/3 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/3 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/3 HKU\S-1-5-21-2497458167-863793282-2099140305-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131440762065348725&GUID=E1BF1C10-8B42-4CA3-891B-F3A4895EAA23 HKU\S-1-5-21-2497458167-863793282-2099140305-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/3 URLSearchHook: [S-1-5-21-2497458167-863793282-2099140305-1001] ATTENTION => URLSearchHook par défaut est absent SearchScopes: HKLM -> {69A252D5-526C-4AFE-B0F7-931A644847E4} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 -> {69A252D5-526C-4AFE-B0F7-931A644847E4} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-21-2497458167-863793282-2099140305-1002 -> {69A252D5-526C-4AFE-B0F7-931A644847E4} URL = hxxp://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll [2017-11-29] (Oracle Corporation) BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2017-07-31] (Adobe Systems Incorporated) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-11-29] (Oracle Corporation) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard) BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2017-07-31] (Adobe Systems Incorporated) BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-07-31] (Adobe Systems Incorporated) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard) BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-07-31] (Adobe Systems Incorporated) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2017-07-31] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-07-31] (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-2497458167-863793282-2099140305-1002 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2017-07-31] (Adobe Systems Incorporated) FireFox: ======== FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2017-11-04] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Plugin: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-11-29] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-11-29] (Oracle Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [Pas de fichier] FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll [2013-06-26] (Adobe Systems, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-09] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-09] (Intel Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-29] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-29] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2017-11-04] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\NIKOO\AppData\Local\Google\Chrome\User Data\Default [2017-11-29] CHR Extension: (Adobe Acrobat) - C:\Users\NIKOO\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-11-29] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\NIKOO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-11-29] CHR Extension: (Chrome Media Router) - C:\Users\NIKOO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-29] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2257016 2017-08-23] (Adobe Systems, Incorporated) R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [Fichier non signé] R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-08-23] () [Fichier non signé] R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-10-18] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-10-18] (CyberLink) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-12-16] (Hewlett-Packard Company) [Fichier non signé] R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-07-23] (Hewlett-Packard Development Company, L.P.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [Fichier non signé] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-08-09] (Intel Corporation) R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-08-29] (Intel Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-12] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-09] (Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-08] () R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-08-23] (Softex Inc.) [Fichier non signé] R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-08-16] (IDT, Inc.) [Fichier non signé] R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [32768 2013-08-01] (Validity Sensors, Inc.) [Fichier non signé] R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2014-01-08] (Intel® Corporation) ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S1 ASPI32; pas de ImagePath R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132920 2013-04-23] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1386296 2013-08-19] (Motorola Solutions, Inc.) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77432 2017-11-01] () R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [117192 2013-08-29] (Intel Corporation) R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-08] () R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-08] () R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-07] () R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-07] () R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193464 2017-11-29] (Malwarebytes) R3 MBAMFarflt; C:\Windows\system32\DRIVERS\farflt.sys [110016 2017-11-29] (Malwarebytes) R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [46008 2017-11-29] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2017-11-29] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [94144 2017-11-29] (Malwarebytes) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-09] (Intel Corporation) R1 MpKsl605e1068; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0100F94-9DF7-459D-9E7C-29D746166E1A}\MpKsl605e1068.sys [58120 2017-11-29] (Microsoft Corporation) R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3610592 2014-01-28] (Intel Corporation) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [429272 2013-08-22] (Realsil Semiconductor Corporation) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-08-02] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-02] (Synaptics Incorporated) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-11-29 23:48 - 2017-11-29 23:48 - 002391552 _____ (Farbar) C:\Users\NIKOO\Downloads\FRST64.exe 2017-11-29 23:48 - 2017-11-29 23:48 - 000022095 _____ C:\Users\NIKOO\Downloads\FRST.txt 2017-11-29 23:48 - 2017-11-29 23:48 - 000000000 ____D C:\Users\NIKOO\Downloads\FRST-OlderVersion 2017-11-29 23:47 - 2017-11-29 23:48 - 000000000 ____D C:\FRST 2017-11-29 23:39 - 2017-11-29 23:39 - 000001704 _____ C:\Users\NIKOO\Desktop\ZHPCleaner.txt 2017-11-29 23:28 - 2017-11-29 23:30 - 000094144 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-11-29 23:28 - 2017-11-29 23:28 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2017-11-29 23:28 - 2017-11-29 23:28 - 000193464 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2017-11-29 23:28 - 2017-11-29 23:28 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-11-29 23:28 - 2017-11-29 23:28 - 000046008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-11-29 23:28 - 2017-11-29 23:28 - 000001883 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-11-29 23:28 - 2017-11-29 23:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-11-29 23:28 - 2017-11-29 23:28 - 000000000 ____D C:\ProgramData\Malwarebytes 2017-11-29 23:28 - 2017-11-29 23:28 - 000000000 ____D C:\Program Files\Malwarebytes 2017-11-29 23:28 - 2017-11-01 08:54 - 000077432 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-11-29 23:27 - 2017-11-29 23:28 - 078346672 _____ (Malwarebytes ) C:\Users\NIKOO\Downloads\mb3-setup-35891.35891-3.3.1.2183.exe 2017-11-29 23:25 - 2017-11-29 23:25 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-11-29 23:25 - 2017-11-29 23:25 - 000002233 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-11-29 23:22 - 2017-11-29 23:22 - 000003500 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-11-29 23:22 - 2017-11-29 23:22 - 000003372 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-11-29 22:00 - 2017-11-29 22:00 - 002983296 _____ C:\Users\NIKOO\Downloads\ZHPCleaner.exe 2017-11-29 21:57 - 2017-11-29 23:39 - 000000000 ____D C:\Users\NIKOO\AppData\Roaming\ZHP 2017-11-29 21:57 - 2017-11-29 21:57 - 002937728 _____ C:\Users\NIKOO\Downloads\ZHPDiag3.exe 2017-11-29 21:56 - 2017-11-29 22:30 - 000000000 ____D C:\Users\NIKOO\AppData\Local\ZHP 2017-11-29 21:56 - 2017-11-29 21:56 - 002900480 _____ C:\Users\NIKOO\Downloads\zhpdiag_v2017.10.9.179.exe 2017-11-29 19:46 - 2017-11-29 19:46 - 000579645 _____ ( ) C:\Users\NIKOO\Downloads\XMind_8_Pro_Crack_License_Key_Sneak_Peek.exe 2017-11-29 19:46 - 2017-11-29 19:46 - 000015610 _____ C:\Users\NIKOO\Downloads\BILAN FS JANV V29_11.xlsx 2017-11-29 19:45 - 2017-11-29 19:45 - 000000290 __RSH C:\ProgramData\ntuser.pol 2017-11-29 00:49 - 2017-11-29 00:49 - 000000191 _____ C:\Users\NIKOO\AppData\Roaming\.lirecouleur 2017-11-29 00:44 - 2017-11-29 00:44 - 000355353 _____ C:\Users\NIKOO\Downloads\lirecouleur.oxt 2017-11-29 00:42 - 2017-11-29 00:42 - 000110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2017-11-29 00:42 - 2017-11-29 00:42 - 000000000 ____D C:\Users\NIKOO\AppData\Roaming\Sun 2017-11-29 00:42 - 2017-11-29 00:42 - 000000000 ____D C:\Users\NIKOO\AppData\LocalLow\Sun 2017-11-29 00:42 - 2017-11-29 00:42 - 000000000 ____D C:\ProgramData\Oracle 2017-11-29 00:42 - 2017-11-29 00:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-11-29 00:42 - 2017-11-29 00:42 - 000000000 ____D C:\Program Files\Java 2017-11-29 00:40 - 2017-11-29 19:27 - 000000000 ____D C:\Users\NIKOO\AppData\Roaming\Freeplane 2017-11-29 00:40 - 2017-11-29 00:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freeplane 2017-11-28 10:02 - 2017-11-28 12:24 - 000000000 ____D C:\Users\NIKOO\Desktop\12 CALCUL MENTAL 2017-11-27 21:59 - 2017-11-27 21:59 - 000000517 _____ C:\Users\NIKOO\AppData\Local\77BA43DACA444129AA058DDCE0BDD205.Sans titre 2017-11-27 12:58 - 2017-11-27 12:58 - 000000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.4 2017-11-27 12:58 - 2017-11-27 12:58 - 000000000 ____D C:\Users\Public\Documents\sun 2017-11-26 18:29 - 2017-11-26 18:29 - 000140189 _____ C:\Users\NIKOO\Downloads\Séances l'ogre .pdf 2017-11-26 17:08 - 2017-11-26 17:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices 2017-11-25 23:12 - 2017-11-25 23:12 - 000001892 _____ C:\Users\NIKOO\AppData\Local\086F655BD1EE48b7A13D384D778C4C2F.Sans titre 2017-11-24 01:23 - 2017-11-24 01:23 - 006554291 _____ C:\Users\NIKOO\Downloads\Noël des Enfants du Monde.mp4 2017-11-22 22:44 - 2017-11-22 22:44 - 005997523 _____ C:\Users\NIKOO\Downloads\videoplayback (1).m4a 2017-11-22 22:16 - 2017-11-22 22:16 - 002228683 _____ C:\Users\NIKOO\Downloads\videoplayback.m4a 2017-11-20 20:56 - 2017-11-20 20:56 - 000059082 _____ C:\Users\NIKOO\Downloads\tunnel-french-dvdrip-2017.torrent 2017-11-20 20:55 - 2017-11-28 20:11 - 734453728 _____ C:\Users\NIKOO\Downloads\The.Nile.Hilton.Incident.2017.FRENCH.BDRip.XviD-GZR.WwW.Torrent9.tv.avi 2017-11-20 20:55 - 2017-11-28 20:11 - 734370932 _____ C:\Users\NIKOO\Downloads\Marjorie.Prime.2017.FRENCH.BDRip.XviD-GZR.WwW.Torrent9.tv.avi 2017-11-20 20:55 - 2017-11-28 20:11 - 734115850 _____ C:\Users\NIKOO\Downloads\Wind.River.2017.FRENCH.BDRip.XviD-GZR.WwW.Torrent9.tv.avi 2017-11-20 20:55 - 2017-11-20 20:55 - 000058965 _____ C:\Users\NIKOO\Downloads\wind-river-french-dvdrip-2017.torrent 2017-11-20 20:55 - 2017-11-20 20:55 - 000030979 _____ C:\Users\NIKOO\Downloads\le-caire-confidentiel-french-dvdrip-2017.torrent 2017-11-20 20:54 - 2017-11-20 20:54 - 000058989 _____ C:\Users\NIKOO\Downloads\marjorie-prime-french-dvdrip-2017.torrent 2017-11-20 20:54 - 2017-11-20 20:54 - 000000000 ____D C:\Users\NIKOO\Downloads\The Escort 2015 FRENCH BDRip XviD-EXTREME 2017-11-20 20:53 - 2017-11-28 20:11 - 729034520 _____ C:\Users\NIKOO\Downloads\Your.Name.2016.FRENCH.BDRip.XviD-EXTREME.WwW.Torrent9.tv.avi 2017-11-20 20:53 - 2017-11-20 20:53 - 000058764 _____ C:\Users\NIKOO\Downloads\the-escort-french-dvdrip-2017.torrent 2017-11-20 20:53 - 2017-11-20 20:53 - 000030768 _____ C:\Users\NIKOO\Downloads\your-name-french-dvdrip-2017.torrent 2017-11-14 20:40 - 2017-10-17 20:11 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2017-11-14 20:40 - 2017-10-16 19:38 - 002013016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-11-14 20:40 - 2017-10-14 14:04 - 001548624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-11-14 20:40 - 2017-10-14 09:38 - 025731584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-11-14 20:40 - 2017-10-14 09:23 - 004168704 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-11-14 20:40 - 2017-10-14 09:13 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-11-14 20:40 - 2017-10-14 09:11 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-11-14 20:40 - 2017-10-14 09:09 - 005979648 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-11-14 20:40 - 2017-10-14 09:01 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-11-14 20:40 - 2017-10-14 08:36 - 001033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2017-11-14 20:40 - 2017-10-14 08:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-11-14 20:40 - 2017-10-14 08:30 - 015266816 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-11-14 20:40 - 2017-10-14 08:30 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-11-14 20:40 - 2017-10-14 08:30 - 000380416 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-11-14 20:40 - 2017-10-14 08:29 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-11-14 20:40 - 2017-10-14 08:27 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-11-14 20:40 - 2017-10-14 08:21 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-11-14 20:40 - 2017-10-14 08:14 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-11-14 20:40 - 2017-10-14 08:09 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-11-14 20:40 - 2017-10-14 08:05 - 015431680 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2017-11-14 20:40 - 2017-10-14 07:58 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-11-14 20:40 - 2017-10-14 07:53 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-11-14 20:40 - 2017-10-14 07:50 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-11-14 20:40 - 2017-10-14 07:45 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-11-14 20:40 - 2017-10-14 07:33 - 004542464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-11-14 20:40 - 2017-10-14 07:28 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-11-14 20:40 - 2017-10-14 07:28 - 000880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2017-11-14 20:40 - 2017-10-14 07:25 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-11-14 20:40 - 2017-10-14 07:24 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-11-14 20:40 - 2017-10-14 07:24 - 000331776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-11-14 20:40 - 2017-10-14 07:23 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-11-14 20:40 - 2017-10-14 07:14 - 013317632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2017-11-14 20:40 - 2017-10-14 07:10 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-11-14 20:40 - 2017-10-14 07:07 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-11-14 20:40 - 2017-10-14 07:04 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-11-14 20:40 - 2017-10-10 17:36 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys 2017-11-14 20:40 - 2017-10-10 16:38 - 003631616 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-11-14 20:40 - 2017-10-10 16:38 - 000425984 _____ (Microsoft Corporation) C:\Windows\system32\PCPTpm12.dll 2017-11-14 20:40 - 2017-10-10 16:11 - 002749952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-11-14 20:40 - 2017-10-10 16:08 - 000367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPTpm12.dll 2017-11-14 20:40 - 2017-10-05 08:17 - 000380248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2017-11-14 20:40 - 2017-09-15 00:52 - 000986968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2017-11-14 20:40 - 2017-09-08 18:14 - 003084288 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2017-11-14 20:40 - 2017-09-08 17:50 - 002471424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2017-11-14 20:40 - 2017-09-08 04:31 - 000685440 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-11-14 20:40 - 2017-09-08 04:28 - 000507176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-11-14 20:40 - 2017-09-07 22:31 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\mgmtapi.dll 2017-11-14 20:40 - 2017-09-07 20:20 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mgmtapi.dll 2017-11-14 20:40 - 2017-09-07 18:20 - 000513456 _____ C:\Windows\SysWOW64\locale.nls 2017-11-14 20:40 - 2017-09-07 18:20 - 000513456 _____ C:\Windows\system32\locale.nls 2017-11-14 20:40 - 2017-09-07 14:40 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-11-14 20:40 - 2017-09-07 14:40 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-11-14 20:40 - 2017-09-07 00:07 - 000158552 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2017-11-14 20:40 - 2017-09-06 22:17 - 000461144 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2017-11-14 20:40 - 2017-09-06 22:17 - 000443224 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2017-11-14 20:40 - 2017-09-06 15:14 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\regsvc.dll 2017-11-14 20:40 - 2017-08-11 02:39 - 002779136 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2017-11-14 20:40 - 2017-08-11 02:30 - 002464256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2017-11-14 20:30 - 2017-10-11 08:35 - 000143016 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-11-14 20:30 - 2017-10-10 16:21 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2017-11-14 20:30 - 2017-10-10 14:18 - 002023936 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2017-11-14 20:30 - 2017-10-10 14:18 - 001570304 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-11-14 20:30 - 2017-10-10 14:18 - 000670208 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-11-14 20:30 - 2017-10-10 14:18 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-11-14 20:30 - 2017-10-10 14:18 - 000603648 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-11-14 20:30 - 2017-10-10 14:18 - 000402944 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-11-14 20:30 - 2017-10-10 14:18 - 000370688 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-11-14 20:30 - 2017-10-10 14:18 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-11-14 20:30 - 2017-10-10 14:18 - 000181760 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-11-07 22:30 - 2017-11-07 22:30 - 000000571 _____ C:\Users\NIKOO\AppData\Local\CDA8FBB133604717813C6B8631B23E96.Sans titre 2017-11-07 22:06 - 2017-11-07 22:06 - 000001756 _____ C:\Users\NIKOO\AppData\Local\recently-used.xbel 2017-11-07 22:03 - 2017-11-07 22:05 - 000000000 ____D C:\Users\NIKOO\AppData\Local\gtk-2.0 2017-11-07 22:03 - 2017-11-07 22:03 - 000000000 ____D C:\Users\NIKOO\.thumbnails 2017-11-07 22:01 - 2017-11-07 22:06 - 000000000 ____D C:\Users\NIKOO\.gimp-2.8 2017-11-07 22:01 - 2017-11-07 22:01 - 000000000 ____D C:\Users\NIKOO\AppData\Local\gegl-0.2 2017-11-07 22:01 - 2017-11-07 22:01 - 000000000 ____D C:\Users\NIKOO\AppData\Local\fontconfig 2017-11-05 00:23 - 2017-11-05 00:23 - 000002818 _____ C:\Users\NIKOO\AppData\Local\72A228180971414a85326BA01844FA39.Sans-titre1 ( 8 Oct. 17 10h53m ) 2017-11-04 01:07 - 2017-11-04 01:07 - 000002917 _____ C:\Users\NIKOO\AppData\Local\D1F08C67A88A4163B5C1C0119D8BE3A9.Sans titre ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-11-29 23:40 - 2017-08-21 14:12 - 000003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2497458167-863793282-2099140305-1002 2017-11-29 23:24 - 2017-08-21 14:07 - 000003920 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{BADFC73D-BF4A-40AB-BDBA-3359B89AAABD} 2017-11-29 23:22 - 2017-08-21 18:52 - 000000000 ____D C:\Program Files (x86)\Google 2017-11-29 23:22 - 2017-08-21 18:51 - 000000000 ____D C:\Users\NIKOO\AppData\Local\Deployment 2017-11-29 23:21 - 2017-08-25 13:52 - 000000000 ___RD C:\Users\NIKOO\OneDrive 2017-11-29 23:20 - 2017-08-21 14:26 - 000000000 ____D C:\Program Files (x86)\OpenOffice 4 2017-11-29 23:16 - 2017-08-21 14:11 - 000000000 __SHD C:\Users\NIKOO\AppData\LocalLow\EmieUserList 2017-11-29 23:16 - 2017-08-21 14:09 - 000000000 __SHD C:\Users\NIKOO\AppData\LocalLow\EmieSiteList 2017-11-29 22:45 - 2017-10-05 01:38 - 000000000 ____D C:\Users\NIKOO\Desktop\17 FICHES DE PREP 2017-11-29 22:32 - 2017-08-21 14:09 - 000000000 __SHD C:\Users\NIKOO\AppData\Local\EmieUserList 2017-11-29 22:32 - 2017-08-21 14:09 - 000000000 __SHD C:\Users\NIKOO\AppData\Local\EmieSiteList 2017-11-29 19:45 - 2013-08-22 16:36 - 000000000 ___HD C:\Windows\system32\GroupPolicy 2017-11-29 19:45 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy 2017-11-29 19:18 - 2017-08-23 16:59 - 000000000 ____D C:\Users\NIKOO\Desktop\6 GRANDEURS ET MESURES 2017-11-29 19:13 - 2017-10-16 12:04 - 000000000 ____D C:\Users\NIKOO\Desktop\15 FICHES AUTONOMIE 2017-11-29 11:01 - 2017-08-22 22:34 - 000000000 ____D C:\Users\NIKOO\Desktop\GENERALITES 2017-11-28 20:11 - 2017-08-23 23:41 - 000000000 ____D C:\Users\NIKOO\AppData\Roaming\uTorrent 2017-11-28 09:47 - 2017-10-16 12:05 - 000000000 ____D C:\Users\NIKOO\Desktop\16 APC 2017-11-28 08:58 - 2017-08-22 22:55 - 000000000 ____D C:\Users\NIKOO\AppData\Roaming\vlc 2017-11-27 23:35 - 2017-08-22 14:56 - 000000000 ____D C:\Users\NIKOO\Desktop\8 EMC 2017-11-27 22:19 - 2017-09-09 22:26 - 000000000 ____D C:\Users\NIKOO\Desktop\4 RESOLUTION DE PROBLEMES 2017-11-27 22:18 - 2017-08-23 11:28 - 000000000 ____D C:\Users\NIKOO\Desktop\2 LECTURE COMPREHENSIO 2017-11-27 22:06 - 2017-10-08 09:47 - 000000002 ____H C:\Users\Public\Documents\.sys 2017-11-27 22:04 - 2017-10-08 09:47 - 000000002 ____H C:\.win7 2017-11-27 22:04 - 2017-08-24 00:27 - 000000000 ____D C:\Users\NIKOO\AppData\Local\CrashDumps 2017-11-27 12:39 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\system32\NDF 2017-11-27 12:33 - 2013-08-22 14:36 - 000000000 ____D C:\Windows\Inf 2017-11-27 00:29 - 2017-08-21 14:07 - 000000000 ____D C:\Users\NIKOO 2017-11-26 19:19 - 2017-09-06 17:47 - 000000000 ____D C:\Users\NIKOO\Desktop\18 CAHIER JOURNAL 2017-11-26 19:07 - 2014-06-25 08:52 - 000848410 _____ C:\Windows\system32\perfh00C.dat 2017-11-26 19:07 - 2014-06-25 08:52 - 000175438 _____ C:\Windows\system32\perfc00C.dat 2017-11-26 19:07 - 2014-03-18 10:53 - 001973224 _____ C:\Windows\system32\PerfStringBackup.INI 2017-11-24 23:16 - 2014-06-25 00:33 - 000000000 ____D C:\Users\UpdatusUser 2017-11-24 23:13 - 2013-08-22 15:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-11-22 21:57 - 2017-08-22 14:55 - 000000000 ____D C:\Users\NIKOO\Desktop\9 EDUCATION MUSICALE 2017-11-22 01:26 - 2017-08-22 14:56 - 000000000 ____D C:\Users\NIKOO\Desktop\11 EPS 2017-11-20 21:32 - 2017-08-22 19:34 - 000545440 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2017-11-19 17:11 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\rescache 2017-11-18 17:58 - 2017-08-24 01:09 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-11-18 17:58 - 2017-08-24 01:09 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-11-18 10:59 - 2013-08-22 15:44 - 000381720 _____ C:\Windows\system32\FNTCACHE.DAT 2017-11-18 10:57 - 2013-08-22 14:25 - 000262144 ___SH C:\Windows\system32\config\BBI 2017-11-18 10:55 - 2017-08-24 00:49 - 000000000 ____D C:\Windows\system32\appraiser 2017-11-16 22:05 - 2013-08-22 16:36 - 000000000 ___HD C:\Program Files\WindowsApps 2017-11-16 22:05 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\AppReadiness 2017-11-16 21:40 - 2017-08-23 11:28 - 000000000 ____D C:\Users\NIKOO\Desktop\13 POESIE 2017-11-16 21:38 - 2017-08-24 01:19 - 000002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk 2017-11-16 21:38 - 2017-08-24 01:19 - 000002017 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk 2017-11-15 14:19 - 2017-09-02 21:42 - 000000000 ____D C:\Users\NIKOO\Desktop\MEMOIRE 2017-11-14 22:40 - 2017-08-22 20:15 - 000000000 ____D C:\Windows\system32\MRT 2017-11-14 22:40 - 2013-08-22 16:20 - 000000000 ____D C:\Windows\CbsTemp 2017-11-14 22:35 - 2017-10-10 23:17 - 127017032 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2017-11-14 22:35 - 2017-08-22 20:14 - 127017032 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-11-11 22:23 - 2017-10-23 16:22 - 000000000 ____D C:\Users\NIKOO\AppData\Local\PokerStars.FR 2017-11-11 02:29 - 2017-08-21 14:12 - 000000000 ____D C:\Users\NIKOO\Desktop\DOSSIER 2017-11-09 01:26 - 2017-08-23 11:27 - 000000000 ____D C:\Users\NIKOO\Desktop\1 MOTS ET PHRASE 2017-11-08 00:38 - 2017-10-16 11:58 - 000000000 ____D C:\Users\NIKOO\Desktop\3 ETUDE DE LA LANGUE 2017-11-05 11:59 - 2017-09-06 17:48 - 000000000 ____D C:\Users\NIKOO\Desktop\19 PROGRESSIONS 2017-11-05 11:50 - 2017-08-21 14:07 - 000000000 ____D C:\Users\NIKOO\AppData\Local\Packages 2017-11-04 01:41 - 2017-08-24 00:59 - 000835568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-11-04 01:41 - 2017-08-24 00:59 - 000177648 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Fichiers à la racine de certains dossiers ======= 2017-11-29 00:49 - 2017-11-29 00:49 - 000000191 _____ () C:\Users\NIKOO\AppData\Roaming\.lirecouleur 2017-11-25 23:12 - 2017-11-25 23:12 - 000001892 _____ () C:\Users\NIKOO\AppData\Local\086F655BD1EE48b7A13D384D778C4C2F.Sans titre 2017-10-19 06:19 - 2017-10-19 06:19 - 000005095 _____ () C:\Users\NIKOO\AppData\Local\2540CE6E7F1D4bf190A2510968DAAB5B.Sans titre 2017-11-05 00:23 - 2017-11-05 00:23 - 000002818 _____ () C:\Users\NIKOO\AppData\Local\72A228180971414a85326BA01844FA39.Sans-titre1 ( 8 Oct. 17 10h53m ) 2017-11-27 21:59 - 2017-11-27 21:59 - 000000517 _____ () C:\Users\NIKOO\AppData\Local\77BA43DACA444129AA058DDCE0BDD205.Sans titre 2017-10-08 11:23 - 2017-10-08 11:23 - 000001844 _____ () C:\Users\NIKOO\AppData\Local\88BE70FA7B31439eA195566F04853DB0.Sans titre 2017-11-07 22:30 - 2017-11-07 22:30 - 000000571 _____ () C:\Users\NIKOO\AppData\Local\CDA8FBB133604717813C6B8631B23E96.Sans titre 2017-11-04 01:07 - 2017-11-04 01:07 - 000002917 _____ () C:\Users\NIKOO\AppData\Local\D1F08C67A88A4163B5C1C0119D8BE3A9.Sans titre 2017-11-07 22:06 - 2017-11-07 22:06 - 000001756 _____ () C:\Users\NIKOO\AppData\Local\recently-used.xbel Certains fichiers dans TEMP: ==================== 2017-08-23 19:28 - 2017-08-23 19:28 - 000040448 _____ () C:\Users\NIKOO\AppData\Local\Temp\CmdLineExt03.dll 2017-08-23 19:28 - 2017-08-23 19:28 - 000012305 _____ () C:\Users\NIKOO\AppData\Local\Temp\SIntf16.dll 2017-08-23 19:28 - 2017-08-23 19:28 - 000017320 _____ () C:\Users\NIKOO\AppData\Local\Temp\SIntf32.dll 2017-08-23 19:28 - 2017-08-23 19:28 - 000022068 _____ () C:\Users\NIKOO\AppData\Local\Temp\SIntfNT.dll 2017-09-29 00:02 - 2017-09-29 00:02 - 000238295 _____ () C:\Users\NIKOO\AppData\Local\Temp\_inst1.exe 2017-09-02 10:25 - 2006-05-24 18:10 - 000455600 ____R (Macrovision Corporation) C:\Users\NIKOO\AppData\Local\Temp\_is6B4F.exe 2017-09-28 23:04 - 2006-05-24 18:10 - 000455600 ____R (Macrovision Corporation) C:\Users\NIKOO\AppData\Local\Temp\_isD654.exe 2017-09-13 22:32 - 2006-05-24 18:10 - 000455600 ____R (Macrovision Corporation) C:\Users\NIKOO\AppData\Local\Temp\_isDF2A.exe ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2017-11-25 00:00 ==================== Fin de FRST.txt ============================