Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 21.01.2018 Exécuté par Little Adelyne (administrateur) sur LITTLEADELYNE (22-01-2018 18:57:03) Exécuté depuis C:\Users\Little Adelyne\Desktop Profils chargés: Little Adelyne (Profils disponibles: Little Adelyne) Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Index Education) C:\Program Files (x86)\Index Education\Mise a jour automatique\ServiceMiseAJourIndex.exe (Promethean) C:\Program Files\Activ Software\ActivDriver\ActivControlsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Ralink Technology, Corp.) C:\Program Files (x86)\TP-LINK\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\TP-LINK\Common\RaRegistry64.exe (VTech) C:\Program Files (x86)\VTech\DownloadManager\Applications\AppAccessory\12051\VTechUSBSocketService\VTechServiceInstaller.exe (VTech) C:\Program Files (x86)\VTech\DownloadManager\Applications\AppAccessory\12051\VTechUSBSocketService\VTechUSBSocketService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (HP Inc.) C:\Program Files\hp\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe () C:\Program Files\Activ Software\ActivDriver\ActivMgr.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files\Activ Software\ActivDriver\FlashExtension\flashbridge-wrapper-crossplatform.exe (TP-LINK TECHNOLOGIES CO., LTD. ) C:\Program Files (x86)\TP-LINK\Common\TWCU.exe (Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [FullScreen] => C:\BLOCK\CFG\flexbuild\FullScreen\launchFS.cmd HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard) HKLM\...\Run: [ActivManager] => C:\Program Files\Activ Software\ActivDriver\ActivMgr.exe [689472 2013-04-25] () HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.) HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-02-03] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-08] (Hewlett-Packard) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-04-25] (EasyBits Software AS) HKLM-x32\...\Run: [QuickTime Task] => "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM-x32\...\Run: [vProt] => "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe" HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1444880 2015-11-15] (Easybits) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2018-01-08] (Dropbox, Inc.) HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [317824 2016-01-18] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\...\Run: [0221B826EC5544FB03E76E2AB56333DC49A6A6D1._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-08-18] (Google Inc.) HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\...\Policies\Explorer: [NoToolbarCustomize] 0 HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\...\Policies\Explorer: [NoFileMenu] 0 HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\...\Policies\Explorer: [NoFileUrl] 1 HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\...\MountPoints2: {7bd61669-1475-11e0-82ea-806e6f6e6963} - F:\Windows\Installer.exe HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> ShellExecuteHooks: Directory Opus Shell Execute Hook - {3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} - C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll [1356440 2012-01-10] (GP Software) ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2010-09-21] (EasyBits Software Corp.) ShellExecuteHooks-x32: Directory Opus Shell Execute Hook - {EE761688-C137-4b04-8FAB-3C9CDF0886F0} - C:\Program Files\GPSoftware\Directory Opus\dopuslib32.dll [358000 2012-01-10] (GP Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ActivSDK Flash Extension.lnk [2014-01-12] ShortcutTarget: ActivSDK Flash Extension.lnk -> C:\Windows\Installer\{2FAA5A07-F0F7-47C6-96B9-1DB4184AA7F8}\NewShortcut1_08A9BB67B3284FEA9EC29BCD3F863A4A.exe (Flexera Software, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Utility.lnk [2011-12-18] ShortcutTarget: TP-LINK Wireless Utility.lnk -> C:\Program Files (x86)\TP-LINK\Common\TWCU.exe (TP-LINK TECHNOLOGIES CO., LTD. ) Startup: C:\Users\Little Adelyne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk [2011-03-30] ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 212.27.40.240 212.27.40.241 Tcpip\..\Interfaces\{550EF880-2385-4373-A8B7-F3CFAACB3440}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{67E87110-23AF-4B34-9C1A-E2F0E66C1EC2}: [DhcpNameServer] 212.27.40.240 212.27.40.241 Tcpip\..\Interfaces\{A505891E-DAA5-4F6A-99FE-29DF89FF18E1}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/CQDSK/3 HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/CQDSK/3 HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/CQDSK/3 SearchScopes: HKLM -> DefaultScope {129A0CE9-13CF-423B-A38E-D1A6B02E2714} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {129A0CE9-13CF-423B-A38E-D1A6B02E2714} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox SearchScopes: HKLM -> {65793278-18D6-4D6D-AF3D-D81AC9B88FC6} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF SearchScopes: HKLM -> {AF5F7031-EE4E-44C6-AFF5-5C388E256810} URL = hxxp://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {129A0CE9-13CF-423B-A38E-D1A6B02E2714} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {129A0CE9-13CF-423B-A38E-D1A6B02E2714} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {65793278-18D6-4D6D-AF3D-D81AC9B88FC6} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF SearchScopes: HKLM-x32 -> {AF5F7031-EE4E-44C6-AFF5-5C388E256810} URL = hxxp://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {129A0CE9-13CF-423B-A38E-D1A6B02E2714} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox SearchScopes: HKU\.DEFAULT -> {129A0CE9-13CF-423B-A38E-D1A6B02E2714} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox SearchScopes: HKU\.DEFAULT -> {65793278-18D6-4D6D-AF3D-D81AC9B88FC6} URL = hxxp://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF SearchScopes: HKU\.DEFAULT -> {AF5F7031-EE4E-44C6-AFF5-5C388E256810} URL = hxxp://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-02-25] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-25] (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation) Handler-x32: skyline - {3a4f9195-65a8-11d5-85c1-0001023952c1} - C:\Program Files (x86)\Skyline\TerraExplorer\TerraExplorerX.dll [2012-01-04] (Skyline software systems Inc.) FireFox: ======== FF HKLM\...\Firefox\Extensions: [{c2056674-a37f-4b29-9300-2004759d74fe}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension => non trouvé(e) FF HKLM-x32\...\Firefox\Extensions: [{c2056674-a37f-4b29-9300-2004759d74fe}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension => non trouvé(e) FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-13] () FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-13] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll [2014-03-11] (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] () FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-25] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-23] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-23] (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2011-07-12] () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3569298628-1476461367-1843821321-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Little Adelyne\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2012-12-11] (Google) FF Plugin HKU\S-1-5-21-3569298628-1476461367-1843821321-1000: @talk.google.com/O3DPlugin -> C:\Users\Little Adelyne\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll [2012-12-11] () FF Plugin ProgramFiles/Appdata: C:\Users\Little Adelyne\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2012-12-11] (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Little Adelyne\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll [2012-12-11] () Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.google.com CHR StartupUrls: Default -> "hxxps://mail.google.com/mail/ca","hxxp://www.facebook.com/","hxxp://www.google.com/" CHR Profile: C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default [2018-01-22] CHR Extension: (Adblock Plus) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-10-27] CHR Extension: (Adobe Acrobat) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-04-28] CHR Extension: (AdBlock) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-04-25] CHR Extension: (Bouton Enregistrer Pinterest) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-11-21] CHR Extension: (Ookoodoo) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdllmhieocadnghoclpanmggdiffhnbh [2017-04-25] CHR Extension: (JavaScript Popup Blocker) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiajdlfgbgnnjakkbnpdhmhfhklkbiol [2017-03-03] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-23] CHR Extension: (Grass) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmiboiefncpfjihjdedpaoammipkilla [2015-08-23] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Little Adelyne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-13] CHR HKU\S-1-5-21-3569298628-1476461367-1843821321-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR crx: C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\default_apps\search.crx [2015-08-18] CHR crx: C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\default_apps\search.crx [2013-04-09] ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 ActivControl; C:\Program Files\Activ Software\ActivDriver\ActivControlsvc.exe [21328 2013-04-25] (Promethean) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-02-06] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-02-06] (Dropbox, Inc.) R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51016 2018-01-08] (Dropbox, Inc.) R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [Fichier non signé] R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [Fichier non signé] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [Fichier non signé] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [332144 2017-11-21] (HP Inc.) R2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-26] (HP Inc.) R2 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-05-19] (Hewlett-Packard Company) [Fichier non signé] R2 MajIndexEducationService; C:\Program Files (x86)\Index Education\Mise a jour automatique\ServiceMiseAJourIndex.exe [3083760 2017-09-19] (Index Education) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Fichier non signé] R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Fichier non signé] R2 RalinkRegistryWriter; C:\Program Files (x86)\TP-LINK\Common\RaRegistry.exe [185632 2010-07-30] (Ralink Technology, Corp.) R2 RalinkRegistryWriter64; C:\Program Files (x86)\TP-LINK\Common\RaRegistry64.exe [212256 2010-07-30] (Ralink Technology, Corp.) R2 VTechUSBSocketService; C:\Program Files (x86)\VTech\DownloadManager\Applications\AppAccessory\12051\VTechUSBSocketService\VTechServiceInstaller.exe [82824 2013-03-29] (VTech) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77432 2017-11-29] () R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193968 2018-01-22] (Malwarebytes) R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2018-01-22] (Malwarebytes) R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [46008 2018-01-22] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-01-22] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2018-01-22] (Malwarebytes) R2 npf; C:\Windows\System32\drivers\npf.sys [47632 2010-01-27] (CACE Technologies, Inc.) S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [748648 2010-08-12] (Realtek Semiconductor Corporation ) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2018-01-22 18:55 - 2018-01-22 18:55 - 000001561 _____ C:\Users\Little Adelyne\Desktop\rapport malwarebytes.txt 2018-01-22 13:41 - 2018-01-22 13:41 - 000001840 _____ C:\Users\Little Adelyne\Desktop\rapport.txt 2018-01-22 13:21 - 2018-01-22 18:25 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2018-01-22 13:21 - 2018-01-22 13:21 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2018-01-22 13:21 - 2018-01-22 13:21 - 000193968 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2018-01-22 13:21 - 2018-01-22 13:21 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2018-01-22 13:21 - 2018-01-22 13:21 - 000046008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2018-01-22 13:21 - 2018-01-22 13:21 - 000001873 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2018-01-22 13:21 - 2018-01-22 13:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2018-01-22 13:21 - 2018-01-22 13:21 - 000000000 ____D C:\ProgramData\Malwarebytes 2018-01-22 13:21 - 2018-01-22 13:21 - 000000000 ____D C:\Program Files\Malwarebytes 2018-01-22 13:21 - 2017-11-29 09:11 - 000077432 _____ C:\Windows\system32\Drivers\mbae64.sys 2018-01-22 13:05 - 2018-01-22 13:05 - 000000920 _____ C:\Users\Little Adelyne\Desktop\ZHPCleaner.lnk 2018-01-22 13:04 - 2018-01-22 13:05 - 003046784 _____ C:\Users\Little Adelyne\Desktop\ZHPCleaner (1).exe 2018-01-22 13:01 - 2018-01-22 13:02 - 082654512 _____ (Malwarebytes ) C:\Users\Little Adelyne\Desktop\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3747.exe 2018-01-22 12:27 - 2018-01-22 12:27 - 003046784 _____ C:\Users\Little Adelyne\Downloads\ZHPCleaner.exe 2018-01-22 12:23 - 2018-01-22 12:23 - 000008121 _____ C:\Users\Little Adelyne\Desktop\AdwCleaner[C0].txt 2018-01-22 10:47 - 2018-01-22 12:05 - 000000000 ____D C:\AdwCleaner 2018-01-22 10:46 - 2018-01-22 10:46 - 008206624 _____ (Malwarebytes) C:\Users\Little Adelyne\Desktop\adwcleaner_7.0.7.0.exe 2018-01-22 10:25 - 2018-01-22 10:32 - 000013378 _____ C:\Users\Little Adelyne\Desktop\Fixlog.txt 2018-01-22 10:25 - 2018-01-22 10:25 - 000000000 ____D C:\Users\Little Adelyne\Desktop\FRST-OlderVersion 2018-01-22 10:22 - 2018-01-22 10:42 - 000004258 _____ C:\Users\Little Adelyne\Desktop\UsbFix_Report.txt 2018-01-18 15:54 - 2018-01-18 15:55 - 000065709 _____ C:\Users\Little Adelyne\Desktop\Addition.txt 2018-01-18 15:50 - 2018-01-22 19:01 - 000023666 _____ C:\Users\Little Adelyne\Desktop\FRST.txt 2018-01-18 15:50 - 2018-01-22 18:57 - 000000000 ____D C:\FRST 2018-01-18 15:49 - 2018-01-22 10:25 - 002393088 _____ (Farbar) C:\Users\Little Adelyne\Desktop\FRST64.exe 2018-01-18 15:45 - 2018-01-18 15:47 - 225869768 _____ (Trend Micro Inc.) C:\Users\Little Adelyne\Downloads\TrendMicro_12.0_MR_Full (1).exe 2018-01-18 13:02 - 2018-01-18 13:03 - 007123976 _____ (SOSVirus) C:\Users\Little Adelyne\Desktop\UsbFix_10.006.exe 2018-01-17 14:28 - 2018-01-17 14:28 - 000480087 _____ C:\Users\Little Adelyne\Downloads\20161116_contrat_ass_mat (1).pdf 2018-01-17 13:07 - 2017-11-17 05:23 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2018-01-17 13:07 - 2017-11-15 02:27 - 000395968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2018-01-17 13:07 - 2017-11-15 01:36 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2018-01-17 13:07 - 2017-11-14 04:57 - 025731072 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2018-01-17 13:07 - 2017-11-14 04:43 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2018-01-17 13:07 - 2017-11-14 04:43 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2018-01-17 13:07 - 2017-11-14 04:32 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2018-01-17 13:07 - 2017-11-14 04:31 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2018-01-17 13:07 - 2017-11-14 04:31 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2018-01-17 13:07 - 2017-11-14 04:30 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2018-01-17 13:07 - 2017-11-14 04:30 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2018-01-17 13:07 - 2017-11-14 04:30 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2018-01-17 13:07 - 2017-11-14 04:25 - 005925888 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2018-01-17 13:07 - 2017-11-14 04:24 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2018-01-17 13:07 - 2017-11-14 04:24 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2018-01-17 13:07 - 2017-11-14 04:21 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2018-01-17 13:07 - 2017-11-14 04:20 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2018-01-17 13:07 - 2017-11-14 04:20 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2018-01-17 13:07 - 2017-11-14 04:20 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2018-01-17 13:07 - 2017-11-14 04:20 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2018-01-17 13:07 - 2017-11-14 04:15 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2018-01-17 13:07 - 2017-11-14 04:12 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2018-01-17 13:07 - 2017-11-14 04:06 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2018-01-17 13:07 - 2017-11-14 04:06 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2018-01-17 13:07 - 2017-11-14 04:05 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2018-01-17 13:07 - 2017-11-14 04:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2018-01-17 13:07 - 2017-11-14 04:02 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2018-01-17 13:07 - 2017-11-14 04:00 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2018-01-17 13:07 - 2017-11-14 03:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2018-01-17 13:07 - 2017-11-14 03:51 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2018-01-17 13:07 - 2017-11-14 03:48 - 015267328 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2018-01-17 13:07 - 2017-11-14 03:48 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2018-01-17 13:07 - 2017-11-14 03:48 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2018-01-17 13:07 - 2017-11-14 03:47 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2018-01-17 13:07 - 2017-11-14 03:46 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2018-01-17 13:07 - 2017-11-14 03:39 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2018-01-17 13:07 - 2017-11-14 03:27 - 001544192 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2018-01-17 13:07 - 2017-11-14 03:16 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2018-01-17 13:07 - 2017-11-14 02:37 - 013679616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2018-01-17 13:07 - 2017-11-14 02:15 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2018-01-17 13:07 - 2017-11-14 02:15 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2018-01-17 13:07 - 2017-11-14 02:15 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2018-01-17 13:07 - 2017-11-14 02:10 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2018-01-17 13:07 - 2017-11-14 01:32 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2018-01-17 13:07 - 2017-11-14 01:31 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2018-01-17 13:07 - 2017-11-07 21:56 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2018-01-17 13:07 - 2017-11-07 21:46 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2018-01-17 13:07 - 2017-11-07 21:46 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2018-01-17 13:07 - 2017-11-07 21:46 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2018-01-17 13:07 - 2017-11-07 21:44 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2018-01-17 13:07 - 2017-11-07 21:41 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2018-01-17 13:07 - 2017-11-07 21:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2018-01-17 13:07 - 2017-11-07 21:40 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2018-01-17 13:07 - 2017-11-07 21:39 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2018-01-17 13:07 - 2017-11-07 21:38 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2018-01-17 13:07 - 2017-11-07 21:38 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2018-01-17 13:07 - 2017-11-07 21:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2018-01-17 13:07 - 2017-11-07 21:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2018-01-17 13:07 - 2017-11-07 21:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2018-01-17 13:07 - 2017-11-07 21:27 - 004509696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2018-01-17 13:07 - 2017-11-07 21:26 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2018-01-17 13:07 - 2017-11-07 21:24 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2018-01-17 13:07 - 2017-11-07 21:19 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2018-01-17 13:07 - 2017-11-07 21:18 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2018-01-17 13:07 - 2017-11-07 21:17 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2018-01-17 13:07 - 2017-11-07 21:17 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2018-01-17 13:07 - 2017-11-07 21:04 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2018-01-17 13:07 - 2017-11-07 21:01 - 001313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2018-01-17 13:07 - 2017-11-07 20:58 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2018-01-17 13:07 - 2017-11-07 17:31 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2018-01-17 13:07 - 2017-11-07 17:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2018-01-17 13:07 - 2017-11-04 16:31 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll 2018-01-17 13:07 - 2017-11-04 16:31 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll 2018-01-17 13:07 - 2017-11-04 16:10 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll 2018-01-17 13:07 - 2017-11-04 16:10 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll 2018-01-17 13:07 - 2017-11-02 17:55 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll 2018-01-17 13:07 - 2017-11-02 17:55 - 000138240 _____ (Microsoft Corporation) C:\Windows\system32\rtm.dll 2018-01-17 13:07 - 2017-11-02 17:55 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll 2018-01-17 13:07 - 2017-11-02 17:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\iprtprio.dll 2018-01-17 13:07 - 2017-11-02 16:11 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll 2018-01-17 13:07 - 2017-11-02 16:11 - 000115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtm.dll 2018-01-17 13:07 - 2017-11-02 16:11 - 000075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll 2018-01-17 13:07 - 2017-11-02 15:56 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtprio.dll 2018-01-17 13:07 - 2017-10-17 00:04 - 001001984 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll 2018-01-17 13:07 - 2017-10-16 23:46 - 000953344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll 2018-01-17 13:07 - 2017-10-12 01:20 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2018-01-13 15:08 - 2018-01-13 15:09 - 000054872 _____ C:\Users\Little Adelyne\Desktop\facture_33685895369_20171215.pdf 2018-01-13 15:05 - 2018-01-13 15:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2018-01-08 22:15 - 2018-01-08 22:15 - 000051016 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2018-01-08 22:15 - 2018-01-08 22:15 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2018-01-08 22:15 - 2018-01-08 22:15 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2018-01-08 22:15 - 2018-01-08 22:15 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2018-01-07 15:36 - 2018-01-07 15:36 - 002104012 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (14).zip 2018-01-07 15:07 - 2018-01-07 15:07 - 001974799 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (13).zip 2018-01-07 15:06 - 2018-01-07 15:07 - 004694009 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (12).zip 2018-01-04 21:20 - 2018-01-04 21:20 - 005478990 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (11).zip 2018-01-04 21:19 - 2018-01-04 21:20 - 005887303 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (10).zip 2018-01-04 21:19 - 2018-01-04 21:19 - 005358652 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (5).zip 2018-01-04 21:19 - 2018-01-04 21:19 - 005211032 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (9).zip 2018-01-04 21:19 - 2018-01-04 21:19 - 005211032 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (8).zip 2018-01-04 21:19 - 2018-01-04 21:19 - 004959079 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (7).zip 2018-01-04 21:19 - 2018-01-04 21:19 - 004281777 _____ C:\Users\Little Adelyne\Downloads\samsungsmartcameravousaenvoylesfichiers_ (6).zip 2018-01-04 20:47 - 2018-01-04 20:47 - 000997527 _____ C:\Users\Little Adelyne\Downloads\cartoon_blocks_christmas.zip 2018-01-04 20:47 - 2018-01-04 20:47 - 000069911 _____ C:\Users\Little Adelyne\Downloads\santas_air_mail.zip 2018-01-04 16:51 - 2018-01-04 16:53 - 162475480 _____ (Trend Micro Inc.) C:\Users\Public\Desktop\TrendMicro_Download.exe 2018-01-04 16:29 - 2018-01-04 16:33 - 225869768 _____ (Trend Micro Inc.) C:\Users\Little Adelyne\Downloads\TrendMicro_12.0_MR_Full.exe 2018-01-04 16:18 - 2018-01-22 10:42 - 000001859 _____ C:\Users\Little Adelyne\Desktop\UsbFix Anti-Malware.lnk 2018-01-04 16:18 - 2018-01-22 10:15 - 000000000 ____D C:\Program Files (x86)\UsbFix 2018-01-04 16:17 - 2018-01-04 16:17 - 007123608 _____ (SOSVirus) C:\Users\Little Adelyne\Downloads\UsbFix_10.005.exe 2017-12-29 22:08 - 2017-12-29 22:08 - 001293518 _____ C:\Users\Little Adelyne\Desktop\saccouchage créenfantin.pdf 2017-12-29 14:18 - 2018-01-22 15:34 - 000000000 ____D C:\Users\Little Adelyne\Desktop\agenda Adeline 2017-12-29 13:34 - 2017-12-29 13:34 - 023901725 _____ C:\Users\Little Adelyne\Downloads\Gmail (19).zip 2017-12-29 13:33 - 2017-12-29 13:34 - 023551062 _____ C:\Users\Little Adelyne\Downloads\Gmail (15).zip 2017-12-29 13:33 - 2017-12-29 13:34 - 022420123 _____ C:\Users\Little Adelyne\Downloads\Gmail (16).zip 2017-12-29 13:33 - 2017-12-29 13:34 - 018079109 _____ C:\Users\Little Adelyne\Downloads\Gmail (18).zip 2017-12-29 13:33 - 2017-12-29 13:34 - 018069298 _____ C:\Users\Little Adelyne\Downloads\Gmail (17).zip 2017-12-29 13:33 - 2017-12-29 13:33 - 024800159 _____ C:\Users\Little Adelyne\Downloads\Gmail (13).zip 2017-12-29 13:33 - 2017-12-29 13:33 - 024702439 _____ C:\Users\Little Adelyne\Downloads\Gmail (14).zip 2017-12-29 13:32 - 2017-12-29 13:33 - 025570821 _____ C:\Users\Little Adelyne\Downloads\Gmail (12).zip 2017-12-29 13:32 - 2017-12-29 13:32 - 023853432 _____ C:\Users\Little Adelyne\Downloads\Gmail (11).zip 2017-12-28 15:49 - 2017-12-28 15:49 - 000000000 ____D C:\Windows\SysWOW64\CSP 2017-12-28 15:29 - 2017-12-28 15:29 - 000000000 ____D C:\Users\Little Adelyne\AppData\Roaming\Samsung Multimedia Viewer 2017-12-28 10:33 - 2017-12-28 10:33 - 000189472 _____ C:\Users\Little Adelyne\Downloads\POUTRE-TEMPS (1).pdf ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2018-01-22 18:54 - 2016-02-06 13:32 - 000001202 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2018-01-22 18:23 - 2013-04-21 13:18 - 000001084 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2018-01-22 18:19 - 2012-08-16 13:08 - 000001114 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3569298628-1476461367-1843821321-1000UA.job 2018-01-22 16:38 - 2017-11-26 11:28 - 000000368 _____ C:\Windows\Tasks\HPCeeScheduleForLittle Adelyne.job 2018-01-22 14:55 - 2015-11-24 19:26 - 000000000 ____D C:\Users\Little Adelyne\AppData\Roaming\com.aspexsoftware.Silhouette_Studio 2018-01-22 14:33 - 2015-11-24 19:26 - 000000000 ____D C:\ProgramData\boost_interprocess 2018-01-22 13:18 - 2017-11-18 22:52 - 000002055 _____ C:\Users\Little Adelyne\Desktop\ZHPCleaner.txt 2018-01-22 13:18 - 2017-11-18 22:00 - 000000000 ____D C:\Users\Little Adelyne\AppData\Roaming\ZHP 2018-01-22 13:05 - 2017-11-18 22:00 - 000000000 ____D C:\Users\Little Adelyne\AppData\Local\ZHP 2018-01-22 12:22 - 2016-02-06 13:32 - 000001198 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2018-01-22 12:22 - 2013-04-21 13:18 - 000001080 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2018-01-22 12:15 - 2009-07-14 05:45 - 000018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2018-01-22 12:15 - 2009-07-14 05:45 - 000018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2018-01-22 12:14 - 2010-09-22 00:02 - 000747660 _____ C:\Windows\system32\perfh00C.dat 2018-01-22 12:14 - 2010-09-22 00:02 - 000150184 _____ C:\Windows\system32\perfc00C.dat 2018-01-22 12:14 - 2009-07-14 06:13 - 001669656 _____ C:\Windows\system32\PerfStringBackup.INI 2018-01-22 12:14 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf 2018-01-22 12:07 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2018-01-22 12:04 - 2011-01-02 14:35 - 000000000 ____D C:\Users\Little Adelyne\AppData\Roaming\Yahoo! 2018-01-22 10:35 - 2016-03-20 22:57 - 001046528 ___SH C:\Users\Little Adelyne\Desktop\Thumbs.db 2018-01-22 10:34 - 2014-03-11 09:49 - 000000008 __RSH C:\ProgramData\ntuser.pol 2018-01-22 10:26 - 2009-07-14 04:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy 2018-01-19 19:19 - 2012-08-16 13:08 - 000001062 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3569298628-1476461367-1843821321-1000Core.job 2018-01-19 08:16 - 2016-02-06 13:43 - 000000000 ___RD C:\Users\Little Adelyne\Dropbox 2018-01-18 08:39 - 2009-07-14 05:45 - 000677160 _____ C:\Windows\system32\FNTCACHE.DAT 2018-01-18 08:35 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\SysWOW64\Setup 2018-01-18 08:35 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\system32\Setup 2018-01-14 11:31 - 2013-08-19 12:16 - 000000000 ____D C:\Windows\system32\MRT 2018-01-14 11:27 - 2017-10-12 20:44 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2018-01-14 11:27 - 2013-08-19 12:16 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2018-01-13 16:47 - 2014-01-12 17:40 - 000000000 ____D C:\ProgramData\Activ Software 2018-01-13 15:21 - 2011-01-01 23:41 - 000000000 ____D C:\Users\Little Adelyne\Documents\Adeline 2018-01-13 15:12 - 2013-04-21 17:04 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2018-01-13 15:12 - 2013-04-21 17:04 - 000004484 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2018-01-13 15:12 - 2013-04-21 17:04 - 000000000 ____D C:\Windows\system32\Macromed 2018-01-13 15:12 - 2011-10-31 09:28 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2018-01-13 15:12 - 2010-09-21 23:30 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2018-01-13 15:05 - 2015-09-27 11:04 - 000000000 ____D C:\Program Files (x86)\Dropbox 2018-01-05 10:38 - 2017-11-26 11:28 - 000003240 _____ C:\Windows\System32\Tasks\HPCeeScheduleForLittle Adelyne 2018-01-05 10:28 - 2010-12-31 00:46 - 000212760 _____ C:\Users\Little Adelyne\AppData\Local\GDIPFONTCACHEV1.DAT 2018-01-04 17:05 - 2014-03-11 09:53 - 000000000 ____D C:\Users\Little Adelyne\AppData\Local\Trend Micro 2018-01-04 17:05 - 2014-03-11 09:48 - 000000000 ____D C:\ProgramData\Trend Micro 2018-01-04 16:55 - 2014-03-11 09:37 - 000000000 ____D C:\Program Files (x86)\Trend Micro 2018-01-04 16:53 - 2015-10-30 21:34 - 000000000 ____D C:\ProgramData\Trend Micro Installer 2017-12-29 14:39 - 2015-07-13 15:48 - 000000000 ____D C:\Users\Little Adelyne\AppData\Roaming\iLauncher 2017-12-28 16:22 - 2010-09-21 23:28 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-12-28 15:47 - 2015-07-13 15:45 - 000000000 ____D C:\Program Files (x86)\Samsung 2017-12-28 15:30 - 2015-07-13 15:45 - 000001111 _____ C:\Users\Public\Desktop\Samsung i-Launcher.lnk ==================== Fichiers à la racine de certains dossiers ======= 2003-10-06 09:21 - 2003-10-06 09:21 - 000000000 ____H () C:\ProgramData\sdpsenv.dat 2011-07-08 22:32 - 2011-09-04 13:33 - 000001854 _____ () C:\Users\Little Adelyne\AppData\Roaming\GhostObjGAFix.xml 2014-04-08 18:39 - 2014-04-08 18:39 - 000000290 _____ () C:\Users\Little Adelyne\AppData\Roaming\RegistrationLog.log 2011-02-08 15:29 - 2014-04-08 18:52 - 000000600 _____ () C:\Users\Little Adelyne\AppData\Roaming\ReplayMusicLog.log 2012-12-11 14:17 - 2012-12-11 14:17 - 000001158 _____ () C:\Users\Little Adelyne\AppData\Roaming\ShiftN.ini 2014-01-20 19:18 - 2014-01-23 18:18 - 000000095 _____ () C:\Users\Little Adelyne\AppData\Roaming\WB.CFG 2014-03-11 09:45 - 2014-03-11 09:45 - 000000036 _____ () C:\Users\Little Adelyne\AppData\Local\housecall.guid.cache 2013-03-17 21:22 - 2013-03-17 21:22 - 000004096 ____H () C:\Users\Little Adelyne\AppData\Local\keyfile3.drm 2012-03-16 20:35 - 2012-03-16 20:35 - 000017408 _____ () C:\Users\Little Adelyne\AppData\Local\WebpageIcons.db ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2018-01-18 10:39 ==================== Fin de FRST.txt ============================