Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 02.01.2018 Exécuté par admin (administrateur) sur DESKTOP-QHBK41D (05-01-2018 22:29:25) Exécuté depuis C:\Users\admin\Downloads Profils chargés: admin (Profils disponibles: simon & admin) Platform: Windows 10 Pro Version 1607 14393.1944 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Edge) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120510.inf_amd64_0f15706cfddd3491\igfxCUIService.exe (HP) C:\Windows\System32\hpservice.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Conexant Systems, Inc) C:\Windows\CxSvc\CxMonSvc.exe (Conexant Systems, Inc.) C:\Windows\CxSvc\CxUtilSvc.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe (HP) C:\Program Files (x86)\HP\HP Hotkey Support\HotkeyService.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe () C:\Program Files (x86)\NETGEAR\WNA3100M\WifiSvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (eVenture Limited) C:\Program Files (x86)\hide.me VPN\hidemesvc.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpCardEngine.exe (HP) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (HP) C:\Program Files (x86)\HP\HP Hotkey Support\QLBController.exe (DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120510.inf_amd64_0f15706cfddd3491\igfxEM.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe (Conexant) C:\Windows\System32\MicTray64.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\HP-NB-AIO\SmartAudio3.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (RaMMicHaeL) C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (MY.COM B.V.) C:\Users\admin\AppData\Local\MyComGames\MyComGames.exe (Guillaume Ryder (hxxp://utilfr42.free.fr)) C:\Users\admin\AppData\Local\Clavier+\Clavier.exe (HP) C:\Program Files (x86)\HP\HP Notifications\HPNotifications.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe (HP) C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe (HP) C:\Program Files (x86)\HP\HP Touchpoint Manager\Discover HP Touchpoint Manager\LHBeacon.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki120510.inf_amd64_0f15706cfddd3491\IntelCpHeciSvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [DeliveryAndStatusCheck] => C:\Program Files\HP\HP ePrint\HP.DeliveryAndStatus.Desktop.App.exe [301832 2015-11-10] (HP) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323040 2015-10-10] (Intel Corporation) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-28] (Microsoft Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [HPNotifications] => C:\Program Files (x86)\HP\HP Notifications\HPNotifications.exe [853728 2015-10-20] (HP) HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127528 2015-07-08] (Hewlett-Packard Company) HKLM-x32\...\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [258600 2016-01-05] (HP) HKLM-x32\...\Run: [Discover HP Touchpoint Manager] => C:\Program Files (x86)\HP\HP Touchpoint Manager\Discover HP Touchpoint Manager\LHBeacon.exe [426208 2015-10-22] (HP) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [110008 2015-12-16] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [500152 2015-12-16] (CyberLink Corp.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5885352 2017-06-29] (LogMeIn Inc.) HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [uTorrent] => C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe [1982144 2017-09-30] (BitTorrent Inc.) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Steam] => C:\Program Files (x86)\steam2\steam.exe [3111712 2017-12-21] (Valve Corporation) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Discord] => C:\Users\admin\AppData\Local\Discord\app-0.0.299\Discord.exe [57954808 2017-12-11] (Discord Inc.) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [7 Taskbar Tweaker] => C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe [423424 2017-05-19] (RaMMicHaeL) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9818328 2017-06-30] (Piriform Ltd) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Chromium] => c:\users\admin\appdata\local\chromium\application\chrome.exe --auto-launch-at-startup --profile-directory=Default --restore-last-session HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [PSwitch] => C:\Program Files (x86)\Proxy Switcher Standard\ProxySwitcher.exe [5921848 2015-01-10] (Proxy Switcher) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4836032 2017-08-14] (Disc Soft Ltd) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [5345672 2017-12-21] (Nota Inc.) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [MyComGames] => C:\Users\admin\AppData\Local\MyComGames\MyComGames.exe [6086544 2017-12-29] (MY.COM B.V.) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Gadwin PrintScreen (64-bit)] => C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe [15216928 2017-07-30] (Gadwin Systems) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Clavier+] => C:\Users\admin\AppData\Local\Clavier+\Clavier.exe [157696 2017-09-09] (Guillaume Ryder (hxxp://utilfr42.free.fr)) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\Run: [Sound Pilot] => C:\Program Files\Sound Pilot\SoundPilot.exe [243208 2016-11-11] (Two Pilots) HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\MountPoints2: {08f9c7e9-ac74-11e7-bb6c-ec8eb59f5ec4} - "I:\setup.exe" HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\...\MountPoints2: {b8799c35-aa77-11e7-bb6b-ec8eb59f5ec4} - "H:\setup.exe" Lsa: [Notification Packages] DPPassFilter scecli Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2017-06-21] ShortcutTarget: MEGAsync.lnk -> C:\Users\admin\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited) Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2017-10-14] ShortcutTarget: Twitch.lnk -> C:\Users\admin\AppData\Roaming\Twitch\Bin\Twitch.exe (Twitch Interactive, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA3100M Genie.lnk [2017-04-29] ShortcutTarget: NETGEAR WNA3100M Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNA3100M\WNA3100M.exe () GroupPolicy: Restriction - Chrome <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{55ea8d57-91ca-46e9-90e6-bea64a04e267}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{e2c0e5be-6a45-4d0c-9e99-b3445c2cdac9}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dpchi_17_30¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0Czz0E0ByDzy0FyD0E0CyEyBtDzz0CtN0D0Tzu0StBtDtAtBtN1L2XzutAtFtBzytFtCtDyEtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyB0B0CtAyDzz0BtGtC0CyC0BtGzy0C0ByEtGtAyD0DyBtG0CyC0CtBtCzy0CyBtB0B0C0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzyyD0C0AtAtCyCtGzy0EzyyEtGyE0BzztDtG0AtCtAtDtGzz0Fzy0CyDyE0DtCzyyC0B0F2QtN0A0LzuyE%26cr%3D9175879%26a%3Dwbf_dpchi_17_30%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dpchi_17_30¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0Czz0E0ByDzy0FyD0E0CyEyBtDzz0CtN0D0Tzu0StBtDtAtBtN1L2XzutAtFtBzytFtCtDyEtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyB0B0CtAyDzz0BtGtC0CyC0BtGzy0C0ByEtGtAyD0DyBtG0CyC0CtBtCzy0CyBtB0B0C0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzyyD0C0AtAtCyCtGzy0EzyyEtGyE0BzztDtG0AtCtAtDtGzz0Fzy0CyDyE0DtCzyyC0B0F2QtN0A0LzuyE%26cr%3D9175879%26a%3Dwbf_dpchi_17_30%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dpchi_17_30¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0E0Czz0E0ByDzy0FyD0E0CyEyBtDzz0CtN0D0Tzu0StBtDtAtBtN1L2XzutAtFtBzytFtCtDyEtFyDtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyB0B0CtAyDzz0BtGtC0CyC0BtGzy0C0ByEtGtAyD0DyBtG0CyC0CtBtCzy0CyBtB0B0C0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzyyD0C0AtAtCyCtGzy0EzyyEtGyE0BzztDtG0AtCtAtDtGzz0Fzy0CyDyE0DtCzyyC0B0F2QtN0A0LzuyE%26cr%3D9175879%26a%3Dwbf_dpchi_17_30%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-01] (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-01] (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF Extension: (Site Deployment Checker) - C:\Program Files\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-24] [Legacy] [non signé] FF HKLM-x32\...\Firefox\Extensions: [dpmaxz_ng@jetpack] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome FF Extension: (HP Client Security Manager) - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome [2016-07-26] [Legacy] [non signé] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2017-12-12] () FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-01] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-01] (Oracle Corporation) FF Plugin-x32: @4game.com/plugin -> C:\Program Files (x86)\4game\3.6.2.254\npplugin4game.dll [Pas de fichier] FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2017-12-12] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-11] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-11] (Foxit Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-08-24] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-08-24] (Intel Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-05] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-05] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.) FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll [2015-09-28] (DigitalPersona, Inc.) StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default CHR DefaultSearchKeyword: Default -> Yahoo CHR DefaultSuggestURL: Default -> hxxps://fr.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10 CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2018-01-05] CHR Extension: (Slides) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13] CHR Extension: (Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13] CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-21] CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-21] CHR Extension: (Adblock Plus) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-09-26] CHR Extension: (YouTube Notifications) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cilgbgkmanbbecbjihnbpeaoodmgchom [2017-11-20] CHR Extension: (Jeremysadi Live Extension) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\daogbelhijghbcaiedbcoeiifolghehe [2017-06-27] CHR Extension: (Chatango Extender) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfeinllkceneabfakchfljicjpfacefb [2017-06-01] CHR Extension: (Sheets) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13] CHR Extension: (EditThisCookie) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2017-12-29] CHR Extension: (Google Docs hors connexion) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-21] CHR Extension: (Obu's Chatango Improvements) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kppmmpajlakpalhigmmkbaikoklhgmnb [2017-05-30] CHR Extension: (TubeBuddy for YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkhmbddkmdggbhaaaodilponhnccicb [2018-01-04] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-22] CHR Extension: (TunnelBear Inc.) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\omdakjcmkglenbhjadbccaookpfjihpa [2017-11-18] CHR Extension: (Warcraft-Alliance-HD Theme) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\onmabcbofdhckooclinckijfdiaflahh [2018-01-05] CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-21] CHR Extension: (Chrome Media Router) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-14] CHR HKLM\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3891560280-1250424028-3305681315-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ccjleegmemocfpghkhpjmiccjcacackp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fabhkdeopjkcpkmofliimbjckmocfiom] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome.crx CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1530376 2017-04-13] () R2 CxMonSvc; C:\WINDOWS\CxSvc\CxMonSvc.exe [22648 2016-06-07] (Conexant Systems, Inc) R2 CxUtilSvc; C:\WINDOWS\CxSvc\CxUtilSvc.exe [141432 2016-07-30] (Conexant Systems, Inc.) S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2291904 2017-08-14] (Disc Soft Ltd) R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [502232 2015-09-28] (DigitalPersona, Inc.) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [526888 2017-10-23] (EasyAntiCheat Ltd) R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3418024 2017-06-29] (LogMeIn Inc.) U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-09-19] (Hi-Rez Studios) [Fichier non signé] R2 hmevpnsvc; C:\Program Files (x86)\hide.me VPN\hidemesvc.exe [136864 2017-09-28] (eVenture Limited) R2 HP Hotkey Service; C:\Program Files (x86)\HP\HP Hotkey Support\HotkeyService.exe [781864 2015-12-21] (HP) R3 hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [1102560 2015-10-19] (HP) R2 hpsrv; C:\WINDOWS\system32\Hpservice.exe [38728 2016-10-11] (HP) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [332144 2017-11-21] (HP Inc.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19424 2015-10-10] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-07-06] (Intel Corporation) [Fichier non signé] S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-07-06] () [Fichier non signé] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2016-01-07] (Intel Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.) R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [Fichier non signé] S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [8028304 2017-01-24] (INCA Internet Co., Ltd.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2017-08-08] (Microsoft Corporation) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [256224 2017-09-06] (Synaptics Incorporated) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103704 2017-10-09] (Microsoft Corporation) R2 WSWNA3100M; C:\Program Files (x86)\NETGEAR\WNA3100M\WifiSvc.exe [316120 2014-08-18] () S2 4game-service; "C:\Program Files (x86)\4game\3.6.2.254\4game-service.exe" [X] S3 BstHdLogRotatorSvc; "C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe" [X] S2 TeamViewer; "C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe" [X] ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [56128 2016-10-11] (HP) R3 bcbtums; C:\WINDOWS\system32\DRIVERS\bcbtums.sys [186152 2015-12-18] (Broadcom Corporation.) S3 BCM43XX; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [11794376 2017-07-13] (Broadcom Corp) R3 BCMWL63A; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [11794376 2017-07-13] (Broadcom Corp) R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [100624 2015-06-08] (CyberLink) R3 CnxtHdAudService; C:\WINDOWS\system32\drivers\CHDRT64ISST.sys [1656856 2017-05-14] (Conexant Systems Inc.) R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-10-08] (Disc Soft Ltd) R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-10-08] (Disc Soft Ltd) S3 FairplayKD; C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [82440 2017-10-29] (Multi Theft Auto) R3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2017-06-29] (LogMeIn Inc.) R0 hpdskflt; C:\WINDOWS\System32\DRIVERS\hpdskflt.sys [42312 2016-10-11] (HP) R1 MpKsl05c474ff; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{47087370-1413-401E-A2AC-A4B4A50F1A2D}\MpKsl05c474ff.sys [58120 2018-01-05] (Microsoft Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R0 PinFile; C:\WINDOWS\System32\DRIVERS\PinFile.sys [56864 2015-11-15] (WinMagic Inc.) S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [3409096 2014-09-04] (Realtek Semiconductor Corporation ) R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [769752 2015-12-18] (Realsil Semiconductor Corporation) S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [413912 2015-12-22] (Realsil Semiconductor Corporation) R0 SDDisk2K; C:\WINDOWS\System32\DRIVERS\SDDisk2K.sys [232480 2015-11-15] (WinMagic Inc.) R0 SDDToki; C:\WINDOWS\System32\DRIVERS\SDDToki.sys [138272 2015-11-15] (WinMagic Inc.) R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [51936 2017-09-06] (Synaptics Incorporated) S3 SNP2UVCW10; C:\WINDOWS\system32\DRIVERS\snp2uvcW10.sys [2530920 2015-12-21] (Sonix Tech. Co., Ltd.) U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-07-23] () S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30544 2015-08-13] (HP) S3 xhunter1; C:\WINDOWS\xhunter1.sys [37344 2017-07-24] (Wellbia.com Co., Ltd.) U3 aspnet_state; pas de ImagePath S3 BstkDrv; \??\C:\Program Files (x86)\BlueStacks\BstkDrv.sys [X] S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) Error(1) reading file: "C:\Users\admin\Downloads\ " 2018-01-05 22:29 - 2018-01-05 22:32 - 000028820 _____ C:\Users\admin\Downloads\FRST.txt 2018-01-05 22:09 - 2018-01-05 22:30 - 001388448 _____ C:\Users\Public\VOIP.dat 2018-01-05 21:51 - 2018-01-05 21:51 - 000209536 _____ C:\Users\admin\Desktop\ZHPDiag.txt 2018-01-05 21:37 - 2018-01-05 21:37 - 001388448 _____ C:\Users\Public\ASR.dat 2018-01-05 21:34 - 2018-01-05 22:10 - 000083933 _____ C:\Users\admin\Desktop\Addition.txt 2018-01-05 21:25 - 2018-01-05 22:29 - 000000000 ____D C:\FRST 2018-01-05 21:25 - 2018-01-05 21:51 - 000062215 _____ C:\Users\admin\Desktop\FRST.txt 2018-01-05 21:24 - 2018-01-05 21:24 - 002961280 _____ C:\Users\admin\Downloads\ZHPDiag3.exe 2018-01-05 21:24 - 2018-01-05 21:24 - 002393088 _____ (Farbar) C:\Users\admin\Downloads\FRST64.exe 2018-01-05 21:24 - 2018-01-05 21:24 - 000000872 _____ C:\Users\admin\Desktop\ZHPDiag.lnk 2018-01-05 21:18 - 2018-01-05 21:18 - 000002353 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-01-05 21:18 - 2018-01-05 21:18 - 000002341 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-01-05 21:17 - 2018-01-05 21:17 - 000003586 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2018-01-05 21:17 - 2018-01-05 21:17 - 000003462 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2018-01-05 21:16 - 2018-01-05 21:17 - 001129816 _____ (Google Inc.) C:\Users\admin\Downloads\ChromeSetup.exe 2018-01-05 21:04 - 2018-01-05 21:06 - 083316440 _____ (Malwarebytes ) C:\Users\admin\Downloads\mb3-setup-35891.35891-3.3.1.2183-1.0.262-1.0.3374.exe 2018-01-05 20:32 - 2018-01-05 20:36 - 000013350 _____ C:\Users\admin\Desktop\ZHPCleaner.txt 2018-01-05 20:05 - 2018-01-05 22:24 - 000000000 ____D C:\Users\admin\AppData\Roaming\ZHP 2018-01-05 20:05 - 2018-01-05 21:24 - 000000000 ____D C:\Users\admin\AppData\Local\ZHP 2018-01-05 20:05 - 2018-01-05 20:05 - 000000882 _____ C:\Users\admin\Desktop\ZHPCleaner.lnk 2018-01-05 20:04 - 2018-01-05 20:05 - 003004288 _____ C:\Users\admin\Downloads\ZHPCleaner.exe 2018-01-05 15:25 - 2018-01-05 15:25 - 000029678 _____ C:\Users\admin\Downloads\22.html 2018-01-04 23:33 - 2018-01-04 23:33 - 000000000 ____D C:\Users\admin\AppData\Roaming\Oxyda-tion 2018-01-04 23:25 - 2018-01-04 23:32 - 000000000 ____D C:\Users\admin\Desktop\Oxyda-tion 2018-01-04 23:14 - 2018-01-04 23:17 - 2521967728 _____ C:\Users\admin\Downloads\OxdyaPrime.rar 2018-01-04 22:14 - 2018-01-05 20:49 - 000000000 ____D C:\AdwCleaner 2018-01-04 22:13 - 2018-01-04 22:14 - 008198432 _____ (Malwarebytes) C:\Users\admin\Downloads\adwcleaner_7.0.6.0.exe 2018-01-04 17:23 - 2018-01-04 17:27 - 000578121 _____ ( ) C:\Users\admin\Downloads\All_roblox_dll_scripts.exe 2018-01-04 17:11 - 2018-01-04 17:11 - 000000000 ____D C:\Users\admin\Documents\My Nopde Tables 2018-01-04 17:09 - 2018-01-04 17:09 - 009319570 _____ C:\Users\admin\Downloads\Nopde Engine 6.4.rar 2018-01-04 17:07 - 2018-01-04 17:19 - 000319488 _____ C:\Users\admin\Downloads\dllinjector.exe 2018-01-04 16:54 - 2018-01-04 16:54 - 000645632 _____ (AN Soft) C:\Users\admin\Downloads\DLLInjector v2.exe 2018-01-04 16:53 - 2018-01-04 16:53 - 001552016 _____ ( ) C:\Users\admin\Downloads\DLLInjector v2.0 Installer_0411596536.exe 2018-01-02 14:08 - 2018-01-02 14:08 - 000000000 ____D C:\Users\admin\Documents\FeedbackHub 2018-01-01 20:44 - 2018-01-01 20:44 - 000782336 _____ () C:\Users\admin\Downloads\Multiple_ROBLOX.exe 2018-01-01 20:34 - 2018-01-01 20:37 - 000822328 _____ (Roblox Corporation) C:\Users\admin\Downloads\RobloxPlayerLauncher.exe 2018-01-01 18:03 - 2018-01-01 18:03 - 000031545 _____ C:\Users\admin\Downloads\LumberT2_INSANE_SCRIPT.txt 2017-12-31 19:54 - 2017-12-31 19:55 - 000008144 _____ C:\Users\admin\Desktop\Nouveau Archive WinRAR ZIP.zip 2017-12-31 17:46 - 2017-12-31 17:46 - 000006330 _____ C:\Users\admin\Downloads\lt2moneyfarmgui2.txt 2017-12-31 13:02 - 2017-12-31 13:03 - 005079763 _____ C:\Users\admin\Downloads\Script Pack's.zip 2017-12-31 01:49 - 2017-12-31 01:49 - 000000410 _____ C:\Users\admin\Downloads\Lumber Tycoon 2 Hack.txt 2017-12-31 01:42 - 2017-12-31 01:44 - 000000000 ____D C:\Users\admin\Desktop\Nouveau dossier (3) 2017-12-31 01:41 - 2018-01-05 12:44 - 000000000 ____D C:\Users\admin\Desktop\Nouveau dossier (2) 2017-12-31 01:41 - 2017-12-31 17:50 - 000028881 _____ C:\Users\admin\Desktop\script.lua.lua.txt 2017-12-31 01:34 - 2017-12-31 01:34 - 000321703 _____ C:\Users\admin\Downloads\Calu.zip 2017-12-30 23:02 - 2018-01-05 12:42 - 000000000 _____ C:\Users\admin\AppData\Roaming\rbx_hook 2017-12-30 23:02 - 2018-01-05 12:39 - 000000024 _____ C:\Users\admin\AppData\Roaming\version 2017-12-30 23:00 - 2017-12-31 01:36 - 002782226 _____ C:\Users\admin\Downloads\Exploit and Script.zip 2017-12-30 18:53 - 2017-12-30 18:53 - 000856300 _____ C:\WINDOWS\Minidump\123017-31843-01.dmp 2017-12-29 19:22 - 2017-12-29 19:22 - 000000000 ____D C:\ProgramData\Gyazo 2017-12-24 01:36 - 2013-07-20 19:42 - 000000000 ____D C:\Users\admin\Desktop\, 2017-12-24 01:35 - 2017-12-24 01:36 - 000373879 _____ C:\Users\admin\Downloads\Armax2001 - AutoClick v1.0 (1).rar 2017-12-18 22:58 - 2017-12-18 22:58 - 747427983 _____ C:\Users\admin\Downloads\CSS Content Addon 2017.zip 2017-12-18 22:49 - 2017-12-18 22:49 - 107456607 _____ C:\Users\admin\Downloads\CSS Maps Addon 2017.zip 2017-12-18 01:46 - 2017-12-18 01:48 - 2417354154 _____ C:\Users\admin\Downloads\Client Sylea Complet.rar 2017-12-17 19:42 - 2017-12-17 19:42 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossout 2017-12-17 00:54 - 2017-12-17 00:54 - 000000068 _____ C:\Users\admin\AppData\Local\u7hu7hu7hu 2017-12-17 00:37 - 2017-12-17 00:37 - 000001529 _____ C:\Users\admin\Desktop\app - Raccourci.lnk 2017-12-17 00:36 - 2017-12-17 18:58 - 000000000 ____D C:\Users\admin\AppData\Roaming\Nefilya 2017-12-17 00:36 - 2017-12-17 00:36 - 000000000 ____D C:\Users\admin\Desktop\Nouveau dossier 2017-12-16 15:21 - 2017-12-17 00:37 - 000000000 ____D C:\Users\admin\AppData\Local\Nefilya 2017-12-16 15:21 - 2017-12-17 00:34 - 000000000 ____D C:\Users\admin\Desktop\Nefilya 2017-12-16 15:18 - 2017-12-17 19:40 - 000000000 ____D C:\Users\admin\Desktop\Dossiers en vrac 2017-12-16 15:13 - 2017-12-16 15:21 - 003950080 _____ (Nefilya) C:\Users\admin\Desktop\Nefilya.exe 2017-12-16 15:10 - 2017-12-16 15:11 - 029380120 _____ C:\Users\admin\Downloads\i18n_fr.d2i 2017-12-15 23:40 - 2017-12-15 23:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sound Pilot 2017-12-15 23:40 - 2017-12-15 23:40 - 000000000 ____D C:\Program Files\Sound Pilot 2017-12-15 23:38 - 2017-12-15 23:40 - 006763256 _____ (Two Pilots ) C:\Users\admin\Downloads\sound.exe 2017-12-15 23:27 - 2017-12-15 23:27 - 000000000 ____D C:\Users\admin\Documents\Lightshot 2017-12-15 23:24 - 2017-12-17 13:10 - 000000420 _____ C:\WINDOWS\Tasks\update-sys.job 2017-12-15 23:24 - 2017-12-15 23:24 - 000003346 _____ C:\WINDOWS\System32\Tasks\update-sys 2017-12-15 23:24 - 2017-12-15 23:24 - 000000425 _____ C:\Users\admin\AppData\Local\UserProducts.xml 2017-12-15 23:24 - 2017-12-15 23:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot 2017-12-15 23:24 - 2017-12-15 23:24 - 000000000 ____D C:\Program Files (x86)\Skillbrains 2017-12-15 13:34 - 2017-12-15 13:34 - 000000000 ____D C:\Users\admin\AppData\Local\UnrealEngine 2017-12-15 13:34 - 2017-12-15 13:34 - 000000000 ____D C:\Users\admin\AppData\Local\Rage_Simulator 2017-12-15 13:31 - 2017-12-15 13:32 - 186877700 _____ C:\Users\admin\Downloads\Rage Simulator.zip 2017-12-14 02:03 - 2017-11-16 20:42 - 000000000 ____D C:\Users\admin\Downloads\PS3 Super Slim Jailbreak 4.82 OFW To CFW 2017-12-14 01:53 - 2017-12-14 01:54 - 205671588 _____ C:\Users\admin\Downloads\PS3 Super Slim Jailbreak 4.82 OFW To CFW.zip 2017-12-13 22:14 - 2017-12-13 22:14 - 001288406 _____ C:\Users\admin\Downloads\table_craft_v2.xlsm 2017-12-13 16:50 - 2017-11-30 10:33 - 005688320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2017-12-13 16:50 - 2017-11-30 10:29 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2017-12-13 16:50 - 2017-11-30 10:28 - 007625728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-12-13 16:50 - 2017-11-30 10:28 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll 2017-12-13 16:50 - 2017-11-30 10:28 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll 2017-12-13 16:50 - 2017-11-30 10:26 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll 2017-12-13 16:50 - 2017-11-30 10:25 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll 2017-12-13 16:50 - 2017-11-30 10:25 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll 2017-12-13 16:50 - 2017-11-30 10:25 - 000103424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx 2017-12-13 16:50 - 2017-11-30 10:24 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll 2017-12-13 16:50 - 2017-11-30 10:17 - 000858624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll 2017-12-13 16:50 - 2017-11-30 10:17 - 000579072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll 2017-12-13 16:50 - 2017-11-30 10:15 - 001599488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2017-12-13 16:50 - 2017-11-30 10:15 - 000711168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll 2017-12-13 16:50 - 2017-11-30 10:14 - 002028032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2017-12-13 16:50 - 2017-11-30 10:14 - 000859136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll 2017-12-13 16:49 - 2017-11-30 10:45 - 000982392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll 2017-12-13 16:49 - 2017-11-30 10:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2017-12-13 16:49 - 2017-11-30 10:25 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe 2017-12-13 16:49 - 2017-11-30 10:25 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe 2017-12-13 16:49 - 2017-11-30 10:24 - 000822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2017-12-13 16:49 - 2017-11-30 10:24 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll 2017-12-13 16:49 - 2017-11-30 10:24 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshext.dll 2017-12-13 16:49 - 2017-11-30 10:23 - 000670208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.PointOfService.dll 2017-12-13 16:49 - 2017-11-30 10:23 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll 2017-12-13 16:49 - 2017-11-30 10:23 - 000205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll 2017-12-13 16:49 - 2017-11-30 10:22 - 019411968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-12-13 16:49 - 2017-11-30 10:22 - 018366976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-12-13 16:49 - 2017-11-30 10:22 - 012205056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2017-12-13 16:49 - 2017-11-30 10:21 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2017-12-13 16:49 - 2017-11-30 10:16 - 006066688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-12-13 16:49 - 2017-11-30 10:16 - 003662848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2017-12-13 16:49 - 2017-11-30 10:16 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2017-12-13 16:49 - 2017-11-30 10:16 - 000238080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll 2017-12-13 16:49 - 2017-11-30 10:14 - 000656896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2017-12-13 16:49 - 2017-03-04 07:19 - 000635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2017-12-13 16:10 - 2017-11-30 08:45 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2017-12-13 16:10 - 2017-11-30 08:41 - 009129984 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-12-13 16:10 - 2017-11-30 08:39 - 000187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll 2017-12-13 16:10 - 2017-11-30 08:37 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll 2017-12-13 16:10 - 2017-11-30 08:37 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll 2017-12-13 16:10 - 2017-11-30 08:36 - 001146880 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll 2017-12-13 16:10 - 2017-11-30 08:36 - 000761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll 2017-12-13 16:10 - 2017-11-30 08:33 - 001013760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll 2017-12-13 16:10 - 2017-11-30 08:32 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll 2017-12-13 16:10 - 2016-09-07 05:56 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll 2017-12-13 16:09 - 2017-11-30 08:42 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe 2017-12-13 16:09 - 2017-11-30 08:40 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe 2017-12-13 16:09 - 2017-11-30 08:38 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2017-12-13 16:09 - 2017-11-30 08:38 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll 2017-12-13 16:09 - 2017-11-30 08:37 - 008118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-12-13 16:09 - 2017-11-30 08:37 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2017-12-13 16:09 - 2017-11-30 08:37 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll 2017-12-13 16:09 - 2017-11-30 08:37 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshext.dll 2017-12-13 16:09 - 2017-11-30 08:36 - 004749824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-12-13 16:09 - 2017-11-30 08:34 - 004739584 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2017-12-13 16:09 - 2017-11-30 08:33 - 000583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2017-12-13 16:09 - 2017-11-30 08:32 - 000799744 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2017-12-13 16:08 - 2017-11-30 08:42 - 000862208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2017-12-13 16:08 - 2017-11-30 08:37 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll 2017-12-13 16:07 - 2017-11-30 09:22 - 007780184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-12-13 16:05 - 2017-11-30 09:15 - 001072240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll 2017-12-13 16:02 - 2017-11-30 08:53 - 022571520 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-12-13 16:02 - 2017-11-30 08:38 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2017-12-13 16:02 - 2017-11-30 08:36 - 013108224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2017-12-13 16:02 - 2017-11-30 08:36 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll 2017-12-13 16:01 - 2017-11-30 08:45 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2017-12-13 16:01 - 2017-11-30 08:44 - 000173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll 2017-12-13 16:01 - 2017-11-30 08:36 - 023674880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-12-13 16:01 - 2017-11-30 08:33 - 002097664 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2017-12-13 16:01 - 2017-11-30 08:33 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2017-12-13 16:00 - 2017-11-30 08:50 - 007219200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2017-12-13 16:00 - 2017-11-30 08:37 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll 2017-12-13 15:58 - 2017-11-30 09:17 - 000983896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2017-12-13 15:58 - 2017-11-30 09:16 - 001090904 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2017-12-13 15:58 - 2017-11-30 09:16 - 000947544 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi 2017-12-13 15:58 - 2017-11-30 09:16 - 000811864 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe 2017-12-12 20:25 - 2017-12-12 20:50 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_13 2017-12-12 20:25 - 2017-12-12 20:25 - 000000000 ____D C:\Users\admin\AppData\Roaming\Dofus-13 2017-12-12 14:55 - 2017-12-12 16:43 - 000000413 _____ C:\Users\admin\Desktop\Nouveau document texte (4).txt 2017-12-10 01:26 - 2017-12-10 01:26 - 000053320 _____ C:\Users\admin\Downloads\DMLr58_nmm_nodisc.elf 2017-12-08 23:43 - 2017-12-12 03:35 - 000000085 _____ C:\Users\admin\Desktop\ordre.txt 2017-12-08 21:24 - 2017-12-08 21:24 - 003943138 _____ C:\Users\admin\Downloads\Doftabula2.0.xlsx 2017-12-08 13:54 - 2017-12-08 13:55 - 004493922 _____ C:\Users\admin\Downloads\nAiO.zip 2017-12-08 00:10 - 2017-12-08 00:10 - 000000000 ____D C:\Users\admin\AppData\Local\Clavier+ 2017-12-08 00:10 - 2017-12-08 00:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clavier+ 2017-12-08 00:09 - 2017-12-08 00:10 - 000578492 _____ (Guillaume Ryder (hxxp://utilfr42.free.fr) ) C:\Users\admin\Downloads\ClavierSetup64.exe 2017-12-08 00:09 - 2017-12-08 00:10 - 000578492 _____ (Guillaume Ryder (hxxp://utilfr42.free.fr) ) C:\Users\admin\Downloads\ClavierSetup64 (3).exe 2017-12-08 00:09 - 2017-12-08 00:10 - 000578492 _____ (Guillaume Ryder (hxxp://utilfr42.free.fr) ) C:\Users\admin\Downloads\ClavierSetup64 (2).exe 2017-12-08 00:09 - 2017-12-08 00:10 - 000578492 _____ (Guillaume Ryder (hxxp://utilfr42.free.fr) ) C:\Users\admin\Downloads\ClavierSetup64 (1).exe ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2018-01-05 22:30 - 2017-11-22 20:02 - 000000000 ____D C:\Users\admin\AppData\Local\MyComGames 2018-01-05 22:27 - 2017-05-19 23:04 - 000000000 ____D C:\Users\admin\AppData\Roaming\Skype 2018-01-05 22:18 - 2016-07-16 12:36 - 000000000 ____D C:\WINDOWS\CbsTemp 2018-01-05 21:18 - 2016-12-22 20:10 - 000000000 ____D C:\Program Files (x86)\Google 2018-01-05 21:03 - 2016-07-16 12:45 - 000000000 ____D C:\WINDOWS\INF 2018-01-05 20:52 - 2016-12-29 19:50 - 000000000 __SHD C:\Users\admin\IntelGraphicsProfiles 2018-01-05 20:51 - 2017-10-30 15:21 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios 2018-01-05 20:51 - 2016-12-04 20:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2018-01-05 20:50 - 2016-07-16 07:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2018-01-05 20:37 - 2016-12-29 19:50 - 000000000 ____D C:\Users\admin 2018-01-05 20:35 - 2016-10-29 22:31 - 000000000 ____D C:\Users\simon\AppData\Local\Akamai 2018-01-05 20:25 - 2016-12-04 20:24 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2018-01-05 20:01 - 2016-12-29 19:50 - 000000000 ____D C:\Users\admin\AppData\Local\Google 2018-01-05 19:03 - 2017-05-19 23:03 - 000004178 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{54038C03-FB3F-44E8-BAF7-28F61588CFE5} 2018-01-05 12:42 - 2017-06-02 22:30 - 000000000 ____D C:\Users\admin\AppData\Local\CrashDumps 2018-01-05 00:52 - 2017-07-26 01:52 - 000000000 ____D C:\ProgramData\{47648207-CD26-08C1-4BE0-9683D1A21D4D} 2018-01-04 23:55 - 2017-06-02 21:48 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox 2018-01-04 23:51 - 2017-06-30 22:36 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_7 2018-01-04 23:51 - 2017-06-30 22:36 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_6 2018-01-04 23:51 - 2017-06-22 14:16 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_5 2018-01-04 23:51 - 2017-06-21 21:43 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_4 2018-01-04 23:51 - 2017-06-20 20:12 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_3 2018-01-04 23:51 - 2017-06-18 21:39 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_2 2018-01-04 23:34 - 2017-06-18 21:38 - 000000117 _____ C:\Users\admin\AppData\Roaming\D2Info0 2018-01-04 23:34 - 2017-06-18 21:38 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_1 2018-01-04 22:19 - 2017-05-23 23:26 - 000000364 _____ C:\WINDOWS\Tasks\HPCeeScheduleForadmin.job 2018-01-04 22:17 - 2017-07-26 01:52 - 000000000 ____D C:\Users\admin\AppData\Roaming\7d680b9aa3c0beadce4348fc5af0debb 2018-01-04 17:28 - 2017-07-26 01:51 - 000001740 __RSH C:\ProgramData\ntuser.pol 2018-01-04 02:51 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\AppReadiness 2018-01-03 16:56 - 2017-05-23 23:26 - 000003256 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForadmin 2018-01-03 02:24 - 2016-07-16 12:47 - 000000000 ___HD C:\Program Files\WindowsApps 2018-01-02 00:21 - 2017-06-25 22:58 - 000000000 ____D C:\Program Files (x86)\steam2 2018-01-01 20:54 - 2016-12-29 19:50 - 000000000 ____D C:\Users\admin\AppData\Local\Packages 2017-12-31 12:58 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\system32\NDF 2017-12-30 18:53 - 2017-09-01 00:40 - 573316482 _____ C:\WINDOWS\MEMORY.DMP 2017-12-30 18:53 - 2017-02-02 19:52 - 000000000 ____D C:\WINDOWS\Minidump 2017-12-30 18:32 - 2017-10-24 20:33 - 000000000 ____D C:\ProgramData\TrackMania 2017-12-30 18:32 - 2017-10-24 20:31 - 000000000 ____D C:\Users\admin\Documents\TrackMania 2017-12-30 14:58 - 2017-07-05 19:33 - 000000000 ____D C:\Users\admin\AppData\Roaming\TS3Client 2017-12-30 00:52 - 2017-07-26 23:52 - 000000386 _____ C:\Users\admin\AppData\Roaming\WB.CFG 2017-12-29 19:23 - 2017-11-19 01:50 - 000003544 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachineDaily 2017-12-29 19:23 - 2017-11-19 01:50 - 000003408 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachine 2017-12-29 19:23 - 2017-11-19 01:49 - 000000000 ____D C:\Program Files (x86)\Gyazo 2017-12-24 02:21 - 2017-10-21 00:59 - 000007606 _____ C:\Users\admin\AppData\Local\Resmon.ResmonCfg 2017-12-23 21:57 - 2017-07-16 21:32 - 000001270 _____ C:\Users\admin\Desktop\nativelog.txt 2017-12-23 19:00 - 2017-06-18 22:31 - 000000000 ____D C:\Users\admin\AppData\Roaming\.minecraft 2017-12-22 23:06 - 2017-06-18 20:56 - 000233100 _____ C:\Users\admin\AppData\Localtransition_c5ea1a0f4e99f0e619093c059dbff7b7.ini 2017-12-22 00:08 - 2017-10-13 13:53 - 000000000 ____D C:\Users\admin\AppData\Roaming\Hide.me 2017-12-19 18:29 - 2017-10-17 13:03 - 000000000 ____D C:\Users\admin\AppData\Roaming\Dofus 2017-12-18 16:05 - 2017-03-21 00:54 - 000000000 ____D C:\Program Files (x86)\NCSOFT 2017-12-18 01:31 - 2017-06-17 17:32 - 000000000 ____D C:\Users\admin\AppData\Local\ElevatedDiagnostics 2017-12-17 19:47 - 2017-12-02 15:53 - 000000000 ____D C:\Users\admin\AppData\Local\Warframe 2017-12-17 19:45 - 2017-11-23 18:18 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My.com 2017-12-17 19:45 - 2017-11-22 20:02 - 000000000 ____D C:\MyGames 2017-12-17 19:42 - 2017-07-26 02:48 - 000000000 ____D C:\Users\admin\AppData\Local\Crossout 2017-12-17 17:45 - 2017-06-27 21:45 - 000000000 ____D C:\Users\admin\AppData\Roaming\discord 2017-12-17 00:46 - 2017-10-06 13:48 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_10 2017-12-17 00:46 - 2017-09-22 18:32 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_9 2017-12-17 00:45 - 2017-06-30 22:37 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_8 2017-12-17 00:39 - 2017-07-25 16:29 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3891560280-1250424028-3305681315-1003 2017-12-17 00:39 - 2017-05-19 23:04 - 000002418 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-12-17 00:39 - 2017-05-19 23:04 - 000000000 ___RD C:\Users\admin\OneDrive 2017-12-16 23:45 - 2017-01-31 18:19 - 000000000 ____D C:\Program Files (x86)\FirestormLauncher 2017-12-15 21:34 - 2017-08-09 17:33 - 000000000 ____D C:\Users\admin\AppData\Local\LogMeIn Hamachi 2017-12-15 04:20 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\rescache 2017-12-14 13:59 - 2017-06-16 03:16 - 000000000 ___SD C:\WINDOWS\UpdateAssistantV2 2017-12-13 18:37 - 2016-10-11 17:12 - 000000000 ____D C:\WINDOWS\system32\MRT 2017-12-13 18:28 - 2017-10-11 18:12 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe 2017-12-13 18:28 - 2016-10-11 17:11 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-12-13 16:52 - 2017-06-22 01:07 - 000013346 _____ C:\Users\admin\AppData\Localtransition_5d582b6549b06724c3ee7993af1b7c74.ini 2017-12-12 19:38 - 2017-10-31 22:59 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_12 2017-12-12 19:38 - 2017-10-31 22:59 - 000000008 _____ C:\Users\admin\AppData\Roaming\DofusAppId0_11 2017-12-12 16:24 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-12-12 16:24 - 2016-07-16 12:47 - 000000000 ____D C:\WINDOWS\system32\Macromed 2017-12-12 03:47 - 2017-06-27 21:45 - 000000000 ____D C:\Users\admin\AppData\Local\Discord 2017-12-12 02:27 - 2017-12-05 17:53 - 000000068 _____ C:\Users\admin\AppData\Local\crGPYhwLUd 2017-12-09 22:22 - 2017-07-26 09:21 - 000000000 ____D C:\Program Files (x86)\Elsword 2017-12-07 23:22 - 2017-09-29 19:55 - 000000000 ____D C:\Program Files\rempl ==================== Fichiers à la racine de certains dossiers ======= 2018-01-05 21:37 - 2018-01-05 21:37 - 001388448 _____ () C:\Users\Public\ASR.dat 2018-01-05 22:09 - 2018-01-05 22:30 - 001388448 _____ () C:\Users\Public\VOIP.dat 2017-06-18 21:38 - 2018-01-04 23:34 - 000000117 _____ () C:\Users\admin\AppData\Roaming\D2Info0 2017-07-26 03:21 - 2017-07-26 03:21 - 000000008 ___SH () C:\Users\admin\AppData\Roaming\date 2017-06-18 21:38 - 2018-01-04 23:34 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_1 2017-10-06 13:48 - 2017-12-17 00:46 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_10 2017-10-31 22:59 - 2017-12-12 19:38 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_11 2017-10-31 22:59 - 2017-12-12 19:38 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_12 2017-12-12 20:25 - 2017-12-12 20:50 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_13 2017-06-18 21:39 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_2 2017-06-20 20:12 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_3 2017-06-21 21:43 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_4 2017-06-22 14:16 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_5 2017-06-30 22:36 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_6 2017-06-30 22:36 - 2018-01-04 23:51 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_7 2017-06-30 22:37 - 2017-12-17 00:45 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_8 2017-09-22 18:32 - 2017-12-17 00:46 - 000000008 _____ () C:\Users\admin\AppData\Roaming\DofusAppId0_9 2017-07-26 03:21 - 2017-07-26 03:21 - 000000002 ___SH () C:\Users\admin\AppData\Roaming\evf9 2017-06-19 23:45 - 2016-07-28 07:26 - 000000701 _____ () C:\Users\admin\AppData\Roaming\pdfCodec.dll 2017-12-30 23:02 - 2018-01-05 12:42 - 000000000 _____ () C:\Users\admin\AppData\Roaming\rbx_hook 2017-12-30 23:02 - 2018-01-05 12:39 - 000000024 _____ () C:\Users\admin\AppData\Roaming\version 2017-07-26 23:52 - 2017-12-30 00:52 - 000000386 _____ () C:\Users\admin\AppData\Roaming\WB.CFG 2017-08-17 23:30 - 2017-08-17 23:30 - 000000600 _____ () C:\Users\admin\AppData\Roaming\winscp.rnd 2017-12-05 17:53 - 2017-12-12 02:27 - 000000068 _____ () C:\Users\admin\AppData\Local\crGPYhwLUd 2017-11-20 04:54 - 2017-11-20 04:54 - 000003950 _____ () C:\Users\admin\AppData\Local\recently-used.xbel 2017-10-21 00:59 - 2017-12-24 02:21 - 000007606 _____ () C:\Users\admin\AppData\Local\Resmon.ResmonCfg 2017-12-17 00:54 - 2017-12-17 00:54 - 000000068 _____ () C:\Users\admin\AppData\Local\u7hu7hu7hu 2017-12-15 23:24 - 2017-12-15 23:24 - 000000003 _____ () C:\Users\admin\AppData\Local\updater.log 2017-12-15 23:24 - 2017-12-15 23:24 - 000000425 _____ () C:\Users\admin\AppData\Local\UserProducts.xml Fichiers à déplacer ou supprimer: ==================== C:\Windows\Tasks\{7D680B9A-A3C0-BEAD-CE43-48FC5AF0DEBB}.job Certains fichiers dans TEMP: ==================== 2017-08-15 22:54 - 2017-09-15 21:53 - 058881488 _____ (Skype Technologies S.A.) C:\Users\admin\AppData\Local\Temp\SkypeSetup.exe 2017-08-24 06:52 - 2017-05-14 02:48 - 004819328 _____ (Conexant Systems, Inc.) C:\Users\admin\AppData\Local\Temp\UCI64A152.dll 2017-07-06 08:54 - 2017-07-06 08:54 - 013767776 _____ (Microsoft Corporation) C:\Users\admin\AppData\Local\Temp\vcredist_x86.exe 2017-05-19 22:16 - 2017-02-25 22:48 - 006207144 _____ (Ankama Studio) C:\Users\simon\AppData\Local\Temp\AnkCBA0.tmp.exe 2017-03-10 20:51 - 2017-03-10 20:51 - 007850088 _____ (Microsoft Corporation) C:\Users\simon\AppData\Local\Temp\BingBarSetup-Partner.exe 2017-03-23 02:19 - 2016-11-11 11:13 - 001886344 _____ (Microsoft Corporation) C:\Users\simon\AppData\Local\Temp\dllnt_dump.dll 2017-04-17 22:05 - 2017-04-17 22:05 - 030403752 _____ (ArenaNet) C:\Users\simon\AppData\Local\Temp\Gw2.exe 2017-01-29 18:13 - 2017-01-29 18:13 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-1985485331588977498.dll 2017-01-29 17:55 - 2017-01-29 17:55 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-2086715013686853229.dll 2017-05-19 10:04 - 2017-05-19 10:04 - 000019968 _____ (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-2385520288476598190.dll 2017-01-28 13:35 - 2017-01-28 13:35 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-3558720170433754775.dll 2017-05-19 20:12 - 2017-05-19 20:12 - 000019968 _____ (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-390670231083036671.dll 2017-05-19 20:38 - 2017-05-19 20:38 - 000019968 _____ (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-4252402690600377242.dll 2017-01-30 16:42 - 2017-01-30 16:42 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-4889808334455093373.dll 2017-01-31 15:47 - 2017-01-31 15:47 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-5014849079598785681.dll 2017-01-30 19:56 - 2017-01-30 19:56 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-5437877589607001702.dll 2017-01-31 00:42 - 2017-01-31 00:42 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-6349078996772930603.dll 2017-01-27 12:30 - 2017-01-27 12:30 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-7090333953204794317.dll 2017-01-30 14:00 - 2017-01-30 14:00 - 000019968 ____N (Red Hat®, Inc.) C:\Users\simon\AppData\Local\Temp\jansi-64-713178486336768923.dll 2017-02-22 16:05 - 2017-02-22 16:05 - 000739904 _____ (Oracle Corporation) C:\Users\simon\AppData\Local\Temp\jre-8u121-windows-au.exe 2017-04-15 19:52 - 2017-04-15 19:52 - 014456872 _____ (Microsoft Corporation) C:\Users\simon\AppData\Local\Temp\vc_redist.x86.exe 2017-03-24 18:31 - 2017-03-24 18:32 - 013767776 _____ (Microsoft Corporation) C:\Users\simon\AppData\Local\Temp\vsredistsetup.exe ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2017-12-30 02:34 ==================== Fin de FRST.txt ============================