Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x86) Version: 11-12-2017 Exécuté par Zahra (administrateur) sur PCDEZAHRA (12-12-2017 15:07:50) Exécuté depuis C:\Users\Zahra\Desktop Profils chargés: Zahra (Profils disponibles: Zahra) Platform: Microsoft Windows 10 Professionnel Version 1703 15063.726 (X86) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Edge) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe () C:\ProgramData\DatacardService\HWDeviceService.exe (DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe () C:\ProgramData\Internet Mobile\OnlineUpdate\ouc.exe (Google Inc.) C:\Program Files\Google\Update\1.3.33.7\GoogleCrashHandler.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.10.572.0_x86__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Windows\System32\wscript.exe (Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe (Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (www.IslamicFinder.org) C:\Program Files\Athan\Athan.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe (L'Aventure Multimedia) C:\Program Files\Micro Application\MediaDICO\MediaDico.exe (L'Aventure Multimedia) C:\Program Files\Micro Application\MediaDICO\RAC.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [485280 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [7545088 2015-06-24] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1024256 2015-06-24] (Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM\...\Run: [AdobeCS5ServiceManager] => C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated) HKLM\...\Run: [Athan] => C:\Program Files\Athan\Athan.exe [1216512 2014-05-04] (www.IslamicFinder.org) HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [318128 2016-11-16] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3536064 2016-04-27] (Synaptics Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-2149384820-406478696-3599574708-1000\...\Run: [MediaDico] => C:\Program Files\Micro Application\MediaDICO\LanceMediaDICO.exe [197632 2002-01-09] (L'Aventure Multimedia) HKU\S-1-5-21-2149384820-406478696-3599574708-1000\...\Run: [AdobeBridge] => C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe [12002664 2011-06-09] (Adobe Systems, Inc.) HKU\S-1-5-21-2149384820-406478696-3599574708-1000\...\Run: [FreeCoinsStartup] => C:\Users\Zahra\AppData\Local\FCM\FCMonitor.exe [20416 2014-08-12] (freecoins.co) HKU\S-1-5-21-2149384820-406478696-3599574708-1000\...\Run: [FreeCoinsUpdater] => C:\Users\Zahra\AppData\Local\FCU\FCUpdater.exe [26048 2014-08-12] (Freecoins.co) HKU\S-1-5-21-2149384820-406478696-3599574708-1000\...\Run: [BingSvc] => C:\Users\Zahra\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation) HKU\S-1-5-21-2149384820-406478696-3599574708-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7814600 2017-11-08] (Piriform Ltd) HKU\S-1-5-21-2149384820-406478696-3599574708-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [3880640 2017-07-03] (Disc Soft Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2015-10-26] ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.) Startup: C:\Users\Zahra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Alertes de surveillance de l'encre - HP Deskjet 1050 J410 series (Copie 1).lnk [2015-10-26] ShortcutTarget: Alertes de surveillance de l'encre - HP Deskjet 1050 J410 series (Copie 1).lnk -> (Pas de fichier) GroupPolicy: Restriction ? <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{fd092dcd-9bc1-4780-9a3c-510a5af78f6e}: [NameServer] 8.8.8.8,8.8.4.4,172.93.96.62,185.69.152.76,178.211.33.75 Tcpip\..\Interfaces\{fd092dcd-9bc1-4780-9a3c-510a5af78f6e}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll [2017-10-25] (Oracle Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2017-09-04] (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-25] (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2017-09-04] (Google Inc.) Toolbar: HKU\S-1-5-21-2149384820-406478696-3599574708-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2017-09-04] (Google Inc.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Pas de fichier FireFox: ======== FF ProfilePath: C:\Users\Zahra\AppData\Roaming\Mozilla\Firefox\Profiles\aumz1b5v.default-1433883299921 [2017-12-07] FF Homepage: Mozilla\Firefox\Profiles\aumz1b5v.default-1433883299921 -> hxxps://www.malwarebytes.org/restorebrowser/ FF Extension: (YouTube™ Flash® Player) - C:\Users\Zahra\AppData\Roaming\Mozilla\Firefox\Profiles\aumz1b5v.default-1433883299921\Extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi [2015-10-14] [Legacy] FF Extension: (Flashblock) - C:\Users\Zahra\AppData\Roaming\Mozilla\Firefox\Profiles\aumz1b5v.default-1433883299921\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2015-11-02] [Legacy] FF Extension: (Flash and Video Download) - C:\Users\Zahra\AppData\Roaming\Mozilla\Firefox\Profiles\aumz1b5v.default-1433883299921\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2015-11-02] [Legacy] FF HKU\S-1-5-21-2149384820-406478696-3599574708-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi FF Extension: (IDM integration) - C:\Program Files\Internet Download Manager\idmmzcc2.xpi [2016-11-16] [Legacy] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-11-15] () FF Plugin: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-25] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-25] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2149384820-406478696-3599574708-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Zahra\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-02-02] (RocketLife, LLP) Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://outlook.live.com/owa/?id=64855&owa=1&owasuffix=owa%2f&path=/mail/deleteditems CHR Profile: C:\Users\Zahra\AppData\Local\Google\Chrome\User Data\Default [2017-12-12] CHR Extension: (Skype) - C:\Users\Zahra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-07] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Zahra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-12-07] CHR Extension: (Chrome Media Router) - C:\Users\Zahra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-12] CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S4 ALCATEL; C:\Program Files\Modem OT-X080C\DataCardService.exe [167936 2011-03-12] () [Fichier non signé] S4 AtherosSvc; C:\WINDOWS\system32\AdminService.exe [174080 2012-08-29] (Atheros Commnucations) [Fichier non signé] R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2324672 2017-07-03] (Disc Soft Ltd) R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] () S2 Internet Mobile. RunOuc; C:\Program Files\Internet Mobile\UpdateDog\ouc.exe [657504 2012-11-12] () S4 RealPlayer Cloud Service; c:\program files\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-10-06] (RealNetworks, Inc.) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [263936 2015-06-24] (Realtek Semiconductor) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2545848 2017-03-19] (Microsoft Corporation) R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.) S4 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Fichier non signé] R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [227504 2016-04-27] (Synaptics Incorporated) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [265352 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [82488 2017-07-16] (Microsoft Corporation) ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 athr; C:\WINDOWS\System32\drivers\athwn.sys [3228672 2017-03-18] (Qualcomm Atheros Communications, Inc.) R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [521248 2016-06-25] (Qualcomm Atheros) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [109456 2017-05-18] (Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [26168 2017-08-14] (Disc Soft Ltd) R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [40504 2017-08-14] (Disc Soft Ltd) R3 i8042HDR; C:\WINDOWS\system32\DRIVERS\i8042HDR.sys [13224 2006-10-20] (Chicony) R3 RSPCIESTOR; C:\WINDOWS\system32\DRIVERS\RtsPStor.sys [256616 2015-12-08] (Realtek Semiconductor Corp.) R3 rt640x86; C:\WINDOWS\System32\drivers\rt640x86.sys [504832 2017-03-18] (Realtek ) R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [44216 2016-04-27] (Synaptics Incorporated) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [147344 2017-05-18] (Samsung Electronics Co., Ltd.) S3 ssudserd; C:\WINDOWS\system32\DRIVERS\ssudserd.sys [147344 2017-05-18] (Samsung Electronics Co., Ltd.) S3 taphss6; C:\WINDOWS\system32\DRIVERS\taphss6.sys [37064 2013-02-22] (Anchorfree Inc.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37464 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [243104 2017-03-18] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [96672 2017-03-18] (Microsoft Corporation) S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [160256 2017-03-18] (Microsoft Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-12-12 15:07 - 2017-12-12 15:09 - 000014961 _____ C:\Users\Zahra\Desktop\FRST.txt 2017-12-12 14:15 - 2017-12-12 14:16 - 001759744 _____ (Farbar) C:\Users\Zahra\Desktop\FRST.exe 2017-12-11 19:25 - 2017-12-11 19:25 - 000145175 _____ C:\Users\Zahra\Desktop\ZHPDiag.txt 2017-12-11 19:08 - 2017-12-11 19:08 - 002390528 _____ (Farbar) C:\Users\Zahra\Desktop\FRST64.exe 2017-12-11 09:59 - 2017-12-11 09:59 - 000000763 _____ C:\Users\Zahra\Desktop\ZHPDiag.lnk 2017-12-10 19:16 - 2017-12-10 19:16 - 000000000 ____D C:\WINDOWS\system32\Quarantine 2017-12-10 18:58 - 2017-12-10 18:58 - 003061760 _____ (Nicolas Coolman) C:\Users\Zahra\Downloads\ZHPFix.exe 2017-12-10 18:58 - 2017-12-10 18:58 - 000000000 ____D C:\Users\Zahra\Downloads\Quarantine 2017-12-07 18:58 - 2017-12-07 18:58 - 008187336 _____ (Malwarebytes) C:\Users\Zahra\Downloads\adwcleaner_7.0.5.0 (1).exe 2017-12-07 18:47 - 2017-12-07 18:47 - 008187336 _____ (Malwarebytes) C:\Users\Zahra\Downloads\adwcleaner_7.0.5.0.exe 2017-12-07 18:31 - 2017-12-07 18:31 - 002986880 _____ C:\Users\Zahra\Downloads\ZHPCleaner.exe 2017-12-06 12:27 - 2017-12-06 12:28 - 001752064 _____ (Farbar) C:\Users\Zahra\Downloads\FRST (2).exe 2017-12-05 18:46 - 2017-12-05 18:46 - 000001431 _____ C:\Users\Public\Desktop\Immortal Love 2 - The Price of a Miracle Collectors Edition.lnk 2017-12-05 18:40 - 2017-12-05 18:46 - 000000000 ____D C:\Program Files\Immortal Love 2 - The Price of a Miracle Collectors Edition 2017-12-05 16:28 - 2017-12-07 08:58 - 000000000 ____D C:\Users\Zahra\AppData\Local\FSDART 2017-12-05 16:28 - 2017-12-05 16:29 - 000000000 ____D C:\ProgramData\F-Secure 2017-12-05 16:28 - 2017-12-05 16:28 - 000524248 _____ (F-Secure Corporation) C:\Users\Zahra\Downloads\F-SecureOnlineScanner (1).exe 2017-12-05 16:28 - 2017-12-05 16:28 - 000000000 ____D C:\Users\Zahra\AppData\Local\F-Secure 2017-12-05 16:08 - 2017-12-07 18:33 - 000000000 ____D C:\Users\Zahra\AppData\Local\ZHP 2017-12-05 16:08 - 2017-12-05 16:08 - 002941824 _____ C:\Users\Zahra\Downloads\ZHPDiag3.exe 2017-12-03 11:48 - 2017-12-05 18:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immortal Love 2 - The Price of a Miracle Collectors Edition 2017-12-03 11:07 - 2017-12-03 11:08 - 001078591 _____ C:\Users\Zahra\Downloads\unlocker_1-9-2_fr_20237.exe 2017-12-02 19:13 - 2017-12-02 19:13 - 000147456 _____ (Info-ZIP) C:\WINDOWS\system32\vbzip11.dll 2017-11-16 08:11 - 2017-11-16 08:11 - 000000043 _____ C:\Users\Zahra\Downloads\hbpix (1) 2017-11-15 19:34 - 2017-11-15 19:34 - 000024963 _____ C:\WINDOWS\system32\servers.def.lkg 2017-11-15 19:34 - 2017-11-15 19:34 - 000024963 _____ C:\WINDOWS\system32\servers.def 2017-11-15 19:34 - 2017-11-15 19:34 - 000002847 _____ C:\WINDOWS\system32\servers.def.vpx 2017-11-15 19:34 - 2017-11-15 19:34 - 000001627 _____ C:\WINDOWS\system32\uat.vpx 2017-11-15 19:34 - 2017-11-15 19:34 - 000000446 _____ C:\WINDOWS\system32\prod-pgm.vpx 2017-11-15 19:34 - 2017-11-15 19:34 - 000000039 _____ C:\WINDOWS\system32\Stats.ini 2017-11-15 19:34 - 2017-11-15 19:34 - 000000000 ____D C:\WINDOWS\system32\uat.vpx.dll 2017-11-15 19:34 - 2017-11-15 19:34 - 000000000 ____D C:\ProgramData\SWCUTemp 2017-11-15 19:33 - 2017-11-15 19:33 - 000000000 _____ C:\WINDOWS\system32\last.dump 2017-11-15 19:28 - 2017-11-15 19:28 - 000055160 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys 2017-11-15 19:27 - 2017-11-15 19:27 - 001142072 _____ (Microsoft Corporation) C:\WINDOWS\ucrtbase.dll 2017-11-15 19:23 - 2017-11-15 19:27 - 000000000 ____D C:\ProgramData\AVAST Software 2017-11-15 11:37 - 2017-11-02 04:50 - 005863320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-11-15 11:37 - 2017-11-02 04:50 - 001853800 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2017-11-15 11:37 - 2017-11-02 04:49 - 001972120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2017-11-15 11:37 - 2017-11-02 04:48 - 000962456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2017-11-15 11:37 - 2017-11-02 04:46 - 000173976 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2017-11-15 11:37 - 2017-11-02 04:46 - 000075672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys 2017-11-15 11:37 - 2017-11-02 04:45 - 000613136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2017-11-15 11:37 - 2017-11-02 04:45 - 000480152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2017-11-15 11:37 - 2017-11-02 04:45 - 000362144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2017-11-15 11:37 - 2017-11-02 04:45 - 000283544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2017-11-15 11:37 - 2017-11-02 04:45 - 000172952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2017-11-15 11:37 - 2017-11-02 04:45 - 000133896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2017-11-15 11:37 - 2017-11-02 04:44 - 005808640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-11-15 11:37 - 2017-11-02 04:44 - 000519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2017-11-15 11:37 - 2017-11-02 04:31 - 020512256 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-11-15 11:37 - 2017-11-02 04:29 - 019338240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-11-15 11:37 - 2017-11-02 04:28 - 000207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll 2017-11-15 11:37 - 2017-11-02 04:27 - 000247808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2017-11-15 11:37 - 2017-11-02 04:27 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2017-11-15 11:37 - 2017-11-02 04:27 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2017-11-15 11:37 - 2017-11-02 04:27 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2017-11-15 11:37 - 2017-11-02 04:27 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll 2017-11-15 11:37 - 2017-11-02 04:26 - 002671616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2017-11-15 11:37 - 2017-11-02 04:25 - 012227072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2017-11-15 11:37 - 2017-11-02 04:25 - 011888128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-11-15 11:37 - 2017-11-02 04:25 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2017-11-15 11:37 - 2017-11-02 04:25 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2017-11-15 11:37 - 2017-11-02 04:25 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2017-11-15 11:37 - 2017-11-02 04:24 - 007598080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2017-11-15 11:37 - 2017-11-02 04:24 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-11-15 11:37 - 2017-11-02 04:24 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2017-11-15 11:37 - 2017-11-02 04:23 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2017-11-15 11:37 - 2017-11-02 04:22 - 006254080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-11-15 11:37 - 2017-11-02 04:22 - 002009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2017-11-15 11:37 - 2017-11-02 04:22 - 001884160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll 2017-11-15 11:37 - 2017-11-02 04:22 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll 2017-11-15 11:37 - 2017-11-02 04:21 - 003653120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-11-15 11:37 - 2017-11-02 04:21 - 001832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2017-11-15 11:37 - 2017-11-02 04:21 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2017-11-15 11:37 - 2017-10-15 15:09 - 002259760 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll 2017-11-15 11:37 - 2017-10-15 15:03 - 000078744 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2017-11-15 11:37 - 2017-10-15 14:49 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll 2017-11-15 11:37 - 2017-10-15 14:42 - 005225984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2017-11-15 11:37 - 2017-10-15 14:42 - 003667456 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-11-15 11:37 - 2017-10-15 14:41 - 004559360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2017-11-15 11:37 - 2017-10-15 14:38 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\olepro32.dll 2017-11-15 11:36 - 2017-11-02 05:05 - 000518040 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2017-11-15 11:36 - 2017-11-02 05:05 - 000116120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2017-11-15 11:36 - 2017-11-02 05:04 - 001927064 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2017-11-15 11:36 - 2017-11-02 05:04 - 001330072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2017-11-15 11:36 - 2017-11-02 05:04 - 001240728 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2017-11-15 11:36 - 2017-11-02 05:04 - 000550296 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2017-11-15 11:36 - 2017-11-02 05:04 - 000312216 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2017-11-15 11:36 - 2017-11-02 05:04 - 000158616 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2017-11-15 11:36 - 2017-11-02 05:03 - 000497048 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2017-11-15 11:36 - 2017-11-02 05:03 - 000364440 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll 2017-11-15 11:36 - 2017-11-02 05:03 - 000223640 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2017-11-15 11:36 - 2017-11-02 05:03 - 000030616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2017-11-15 11:36 - 2017-11-02 04:57 - 000060312 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll 2017-11-15 11:36 - 2017-11-02 04:47 - 000573504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2017-11-15 11:36 - 2017-11-02 04:46 - 002024344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2017-11-15 11:36 - 2017-11-02 04:45 - 000703056 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2017-11-15 11:36 - 2017-11-02 04:45 - 000597912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys 2017-11-15 11:36 - 2017-11-02 04:45 - 000510384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2017-11-15 11:36 - 2017-11-02 04:45 - 000354360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll 2017-11-15 11:36 - 2017-11-02 04:45 - 000023840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2017-11-15 11:36 - 2017-11-02 04:43 - 020372896 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-11-15 11:36 - 2017-11-02 04:41 - 000410520 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2017-11-15 11:36 - 2017-11-02 04:38 - 000033176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys 2017-11-15 11:36 - 2017-11-02 04:30 - 002953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-11-15 11:36 - 2017-11-02 04:30 - 001159168 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll 2017-11-15 11:36 - 2017-11-02 04:30 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll 2017-11-15 11:36 - 2017-11-02 04:30 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE 2017-11-15 11:36 - 2017-11-02 04:30 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe 2017-11-15 11:36 - 2017-11-02 04:30 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll 2017-11-15 11:36 - 2017-11-02 04:28 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll 2017-11-15 11:36 - 2017-11-02 04:28 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys 2017-11-15 11:36 - 2017-11-02 04:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2017-11-15 11:36 - 2017-11-02 04:27 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataUsageLiveTileTask.exe 2017-11-15 11:36 - 2017-11-02 04:27 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll 2017-11-15 11:36 - 2017-11-02 04:27 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertPKICmdlet.dll 2017-11-15 11:36 - 2017-11-02 04:26 - 005963776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-11-15 11:36 - 2017-11-02 04:26 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2017-11-15 11:36 - 2017-11-02 04:26 - 000243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataUsageHandlers.dll 2017-11-15 11:36 - 2017-11-02 04:26 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll 2017-11-15 11:36 - 2017-11-02 04:26 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll 2017-11-15 11:36 - 2017-11-02 04:25 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll 2017-11-15 11:36 - 2017-11-02 04:25 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2017-11-15 11:36 - 2017-11-02 04:25 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2017-11-15 11:36 - 2017-11-02 04:25 - 000313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2017-11-15 11:36 - 2017-11-02 04:25 - 000218112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2017-11-15 11:36 - 2017-11-02 04:25 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll 2017-11-15 11:36 - 2017-11-02 04:24 - 003447808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-11-15 11:36 - 2017-11-02 04:24 - 001208320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2017-11-15 11:36 - 2017-11-02 04:24 - 000529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2017-11-15 11:36 - 2017-11-02 04:24 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2017-11-15 11:36 - 2017-11-02 04:24 - 000444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll 2017-11-15 11:36 - 2017-11-02 04:24 - 000354304 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-11-15 11:36 - 2017-11-02 04:24 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe 2017-11-15 11:36 - 2017-11-02 04:23 - 002373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-11-15 11:36 - 2017-11-02 04:23 - 001513984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-11-15 11:36 - 2017-11-02 04:23 - 000680960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll 2017-11-15 11:36 - 2017-11-02 04:23 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll 2017-11-15 11:36 - 2017-11-02 04:23 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll 2017-11-15 11:36 - 2017-11-02 04:23 - 000478720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll 2017-11-15 11:36 - 2017-11-02 04:23 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll 2017-11-15 11:36 - 2017-11-02 04:22 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2017-11-15 11:36 - 2017-11-02 04:22 - 002156544 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2017-11-15 11:36 - 2017-11-02 04:22 - 001494528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll 2017-11-15 11:36 - 2017-11-02 04:22 - 000535040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-11-15 11:36 - 2017-11-02 04:21 - 004417024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2017-11-15 11:36 - 2017-11-02 04:21 - 002125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-11-15 11:36 - 2017-11-02 04:21 - 001583104 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-11-15 11:36 - 2017-11-02 04:21 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2017-11-15 11:36 - 2017-11-02 04:21 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2017-11-15 11:36 - 2017-11-02 04:21 - 000694272 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2017-11-15 11:36 - 2017-11-02 04:20 - 000316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2017-11-15 11:36 - 2017-11-02 04:16 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys 2017-11-15 11:36 - 2017-10-25 07:40 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\msexcl40.dll 2017-11-15 11:36 - 2017-10-15 15:10 - 000790816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2017-11-15 11:36 - 2017-10-15 15:08 - 000698376 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2017-11-15 11:36 - 2017-10-15 15:06 - 000582552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2017-11-15 11:36 - 2017-10-15 15:06 - 000341912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2017-11-15 11:36 - 2017-10-15 15:05 - 000777392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2017-11-15 11:36 - 2017-10-15 15:03 - 006765728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2017-11-15 11:36 - 2017-10-15 14:51 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2017-11-15 11:36 - 2017-10-15 14:45 - 001248768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-11-15 11:36 - 2017-10-15 14:45 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-11-15 11:36 - 2017-10-15 14:44 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2017-11-15 11:36 - 2017-10-15 14:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll 2017-11-15 11:36 - 2017-10-15 14:41 - 001019904 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2017-12-12 15:07 - 2016-02-01 09:33 - 000000000 ____D C:\FRST 2017-12-12 15:00 - 2017-07-16 11:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2017-12-12 09:00 - 2017-03-18 18:23 - 000000000 ___HD C:\Program Files\WindowsApps 2017-12-12 09:00 - 2017-03-18 18:23 - 000000000 ____D C:\WINDOWS\AppReadiness 2017-12-12 08:57 - 2017-05-16 11:55 - 000002164 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-12-12 08:57 - 2017-03-14 18:54 - 000002176 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-12-11 19:22 - 2016-01-29 12:12 - 000000000 ____D C:\Users\Zahra\AppData\Roaming\ZHP 2017-12-11 19:11 - 2017-07-16 11:42 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-12-11 19:10 - 2017-03-18 06:02 - 001310720 _____ C:\WINDOWS\system32\config\BBI 2017-12-11 17:07 - 2017-07-16 11:40 - 002731620 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-12-11 17:07 - 2017-03-19 08:20 - 001298316 _____ C:\WINDOWS\system32\perfh00C.dat 2017-12-11 17:07 - 2017-03-19 08:20 - 000292308 _____ C:\WINDOWS\system32\perfc00C.dat 2017-12-11 09:59 - 2017-07-16 11:22 - 000000000 ____D C:\Users\Zahra 2017-12-11 09:59 - 2016-01-29 12:12 - 002945408 _____ C:\Users\Zahra\ZHPDiag3.exe 2017-12-10 11:10 - 2017-08-01 10:59 - 000000000 ____D C:\Users\Zahra\Desktop\divers 2017-12-09 16:15 - 2016-02-26 10:33 - 000000000 ____D C:\Users\Zahra\AppData\Local\PackageStaging 2017-12-09 16:15 - 2013-02-23 16:31 - 000000000 ____D C:\Users\Zahra\AppData\Local\Packages 2017-12-09 16:08 - 2017-05-17 07:44 - 000000000 ____D C:\ProgramData\Skype 2017-12-09 16:08 - 2013-06-06 17:36 - 000000000 ___RD C:\Program Files\Skype 2017-12-09 16:07 - 2013-02-14 21:58 - 000000000 ____D C:\Users\Zahra\AppData\Roaming\Skype 2017-12-07 19:02 - 2017-07-05 17:08 - 000000000 ____D C:\AdwCleaner 2017-12-05 19:11 - 2017-05-06 11:05 - 000000000 ____D C:\Users\Zahra\Desktop\jeux1 2017-12-05 09:17 - 2017-08-10 11:25 - 000000000 ____D C:\ProgramData\TEMP 2017-12-03 12:17 - 2014-05-31 16:41 - 000000000 ____D C:\Users\Zahra\AppData\Roaming\4 Friends Games 2017-12-02 19:15 - 2013-03-13 09:12 - 000000000 ____D C:\Users\Zahra\AppData\Local\ElevatedDiagnostics 2017-12-01 09:51 - 2017-04-12 23:04 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-11-28 10:49 - 2017-07-16 11:18 - 003685720 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-11-19 15:54 - 2017-03-18 18:21 - 000000000 ____D C:\WINDOWS\INF 2017-11-17 19:03 - 2013-07-13 00:50 - 000000000 ____D C:\WINDOWS\system32\MRT 2017-11-17 18:54 - 2017-10-11 14:06 - 124282896 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe 2017-11-17 18:54 - 2013-02-15 23:56 - 124282896 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-11-16 12:33 - 2017-03-18 18:23 - 000000000 ____D C:\WINDOWS\rescache 2017-11-15 19:23 - 2015-11-24 17:17 - 000000994 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-11-15 18:13 - 2017-03-18 18:23 - 000000000 ____D C:\WINDOWS\system32\Macromed 2017-11-15 16:30 - 2013-02-23 17:14 - 000000000 __RHD C:\Users\Public\AccountPictures 2017-11-15 16:25 - 2017-03-18 18:23 - 000000000 ____D C:\WINDOWS\system32\appraiser 2017-11-15 16:25 - 2017-03-18 18:23 - 000000000 ____D C:\WINDOWS\ShellExperiences 2017-11-15 16:25 - 2017-03-18 18:23 - 000000000 ____D C:\WINDOWS\Provisioning 2017-11-15 16:25 - 2017-03-18 18:23 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2017-11-15 11:45 - 2017-03-18 18:14 - 000000000 ____D C:\WINDOWS\CbsTemp ==================== Fichiers à la racine de certains dossiers ======= 2016-01-29 12:12 - 2017-12-11 09:59 - 002945408 _____ () C:\Users\Zahra\ZHPDiag3.exe 2013-02-19 16:37 - 2013-02-07 14:06 - 000035568 _____ () C:\Program Files\Common Files\rtplugin.crx 2016-03-31 18:11 - 2016-03-31 18:11 - 000003072 _____ () C:\Users\Zahra\AppData\Roaming\.spark_db 2016-09-26 14:00 - 2016-09-30 15:42 - 000000432 _____ () C:\Users\Zahra\AppData\Roaming\apachesrvin.vbs 2015-11-23 20:22 - 2015-11-23 20:22 - 000023486 _____ () C:\Users\Zahra\AppData\Roaming\crashdump_2015_11_23_20_22_12.dmp 2015-11-23 20:22 - 2015-11-23 20:22 - 000023274 _____ () C:\Users\Zahra\AppData\Roaming\crashdump_2015_11_23_20_22_37.dmp 2015-11-23 20:23 - 2015-11-23 20:23 - 000023486 _____ () C:\Users\Zahra\AppData\Roaming\crashdump_2015_11_23_20_23_15.dmp 2015-11-23 20:31 - 2015-11-23 20:31 - 000023486 _____ () C:\Users\Zahra\AppData\Roaming\crashdump_2015_11_23_20_31_49.dmp 2016-09-26 14:00 - 2016-09-30 15:42 - 000000105 _____ () C:\Users\Zahra\AppData\Roaming\die.bat 2013-12-18 17:23 - 2014-08-29 16:38 - 000000165 _____ () C:\Users\Zahra\AppData\Roaming\WB.CFG 2017-04-30 16:15 - 2017-04-30 16:15 - 001170432 _____ () C:\Users\Zahra\AppData\Roaming\Microsoft\CiWinCng32.dll 2017-04-30 16:15 - 2017-04-30 16:16 - 005167104 _____ (Bitvise Limited) C:\Users\Zahra\AppData\Roaming\Microsoft\FlowSshC32.dll 2017-04-30 16:16 - 2017-04-30 16:16 - 000233984 _____ () C:\Users\Zahra\AppData\Roaming\Microsoft\scan.exe 2015-10-24 17:17 - 2015-10-24 17:17 - 000000187 _____ () C:\Users\Zahra\AppData\Local\Ancode.exe.config 2013-04-03 16:55 - 2013-04-03 16:55 - 000003584 _____ () C:\Users\Zahra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-02-25 18:05 - 2017-05-06 15:56 - 000007601 _____ () C:\Users\Zahra\AppData\Local\resmon.resmoncfg Certains fichiers dans TEMP: ==================== 2017-12-02 19:13 - 2017-12-05 16:32 - 000000128 _____ () C:\Users\Zahra\AppData\Local\Temp\micka.exe Certains de taille zéro octet fichiers/dossiers: ========================== C:\Windows\System32\uat.vpx.dll ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2017-12-06 12:43 ==================== Fin de FRST.txt ============================