Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 07.02.2018 01 Exécuté par cylon2 (administrateur) sur CYLON2-PC (08-02-2018 17:41:58) Exécuté depuis C:\Users\cylon2\Desktop Profils chargés: cylon2 (Profils disponibles: cylon2) Platform: Windows 10 Pro Version 1709 16299.192 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: FF) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.18011-0\MsMpEng.exe () C:\Program Files (x86)\D-Link\DWA-131 revA\WlanWpsSvc.exe (Intel(R) Corporation) C:\Program Files\Intel\NCS2\WMIProv\ncs2prov.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation) HKLM\...\Run: [CmPCIaudio] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\CMICNFG3.dll,CMICtrlWnd HKLM\...\Run: [Cmaudio8768GX] => C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8768GX64] => C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-11-21] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle Corporation) HKU\S-1-5-21-3089140509-2297242534-4279767804-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10021040 2017-10-18] (Piriform Ltd) HKU\S-1-5-21-3089140509-2297242534-4279767804-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4836032 2017-08-14] (Disc Soft Ltd) HKU\S-1-5-21-3089140509-2297242534-4279767804-1000\...\MountPoints2: {091af3ce-8e3d-11e7-9fb4-806e6f6e6963} - "D:\AutoRunCD.exe" BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 212.76.224.172 89.2.0.1 89.2.0.2 Tcpip\..\Interfaces\{1dd3571a-160a-4ba3-8cd4-63fcd7457ebe}: [DhcpNameServer] 212.76.224.172 89.2.0.1 89.2.0.2 Tcpip\..\Interfaces\{2f09e672-22ea-4ada-a178-71f861465360}: [DhcpNameServer] 212.76.224.172 89.2.0.1 89.2.0.2 Internet Explorer: ================== HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-3089140509-2297242534-4279767804-1000\Software\Microsoft\Internet Explorer\Main,Start Page = SearchScopes: HKU\S-1-5-21-3089140509-2297242534-4279767804-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-01-26] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-26] (Oracle Corporation) FireFox: ======== FF DefaultProfile: dls9g3pm.default-1514730740569 FF ProfilePath: C:\Users\cylon2\AppData\Roaming\Mozilla\Firefox\Profiles\dls9g3pm.default-1514730740569 [2018-02-08] FF Homepage: Mozilla\Firefox\Profiles\dls9g3pm.default-1514730740569 -> hxxps://www.google.fr/ FF Extension: (Avast Passwords) - C:\Users\cylon2\AppData\Roaming\Mozilla\Firefox\Profiles\dls9g3pm.default-1514730740569\Extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi [2018-02-08] FF Extension: (Avast Online Security) - C:\Users\cylon2\AppData\Roaming\Mozilla\Firefox\Profiles\dls9g3pm.default-1514730740569\Extensions\wrc@avast.com.xpi [2018-01-02] FF Extension: (Adblock Plus) - C:\Users\cylon2\AppData\Roaming\Mozilla\Firefox\Profiles\dls9g3pm.default-1514730740569\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-31] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll [2018-02-06] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_161.dll [2018-02-06] () FF Plugin-x32: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-26] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-01-04] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-01-04] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.) FF Plugin HKU\S-1-5-21-3089140509-2297242534-4279767804-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\cylon2\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-05-08] (Unity Technologies ApS) Chrome: ======= CHR HomePage: Default -> hxxp://google.be/ CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms} CHR DefaultSearchKeyword: Default -> duckduckgo.com CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type=list CHR Profile: C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default [2018-02-08] CHR Extension: (Slides) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-03] CHR Extension: (Docs) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-17] CHR Extension: (Google Drive) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-03] CHR Extension: (DuckDuckGo) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2018-02-05] CHR Extension: (YouTube) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-09-13] CHR Extension: (Adblock Plus) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-02-05] CHR Extension: (Tampermonkey) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-10-10] CHR Extension: (Sheets) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-03] CHR Extension: (Google Docs hors connexion) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-04] CHR Extension: (Social Book Post Manager) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljfidlkcmdmmibngdfikhffffdmphjae [2018-01-25] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-13] CHR Extension: (Gmail) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-03] CHR Extension: (Chrome Media Router) - C:\Users\cylon2\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-22] CHR HKLM\...\Chrome\Extension: [looohgelibjoplmkhecmalapkgadkfcc] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Tampermonkey) - C:\Users\cylon2\AppData\Roaming\Opera Software\Opera Stable\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-10-09] ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7002120 2017-12-24] () S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2291904 2017-08-14] (Disc Soft Ltd) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [Fichier non signé] S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2018-01-04] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2018-01-04] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2154816 2018-01-20] (Electronic Arts) S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3024712 2018-01-20] (Electronic Arts) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2018-02-04] () S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4329952 2017-12-07] (Microsoft Corporation) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-01-20] (Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-01-20] (Microsoft Corporation) R2 WlanWpsSvc; C:\Program Files (x86)\D-Link\DWA-131 revA\WlanWpsSvc.exe [167936 2008-06-26] () [Fichier non signé] R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 cmuda3; C:\WINDOWS\system32\drivers\cmudax3.sys [2491392 2011-03-30] (C-Media Inc) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2017-08-12] (Disc Soft Ltd) R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-08-12] (Disc Soft Ltd) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5601d21ccd639df9\nvlddmkm.sys [17486096 2018-01-05] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2018-01-04] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation) R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-12-05] (NVIDIA Corporation) S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2016-10-18] () S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2018-01-20] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2018-01-20] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2018-01-20] (Microsoft Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2018-02-08 17:41 - 2018-02-08 17:42 - 000015421 _____ C:\Users\cylon2\Desktop\FRST.txt 2018-02-08 17:38 - 2018-02-08 17:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2018-02-08 17:34 - 2018-02-08 17:34 - 000000085 _____ C:\WINDOWS\wininit.ini 2018-02-08 17:30 - 2018-02-08 17:30 - 007189760 _____ (VS Revo Group ) C:\Users\cylon2\Desktop\revosetup.exe 2018-02-08 17:30 - 2018-02-08 17:30 - 000001039 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk 2018-02-08 17:30 - 2018-02-08 17:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller 2018-02-08 17:30 - 2018-02-08 17:30 - 000000000 ____D C:\Program Files\VS Revo Group 2018-02-08 17:16 - 2018-02-08 17:17 - 000000382 _____ C:\Users\cylon2\Desktop\Nouveau document texte (2).txt 2018-02-08 15:21 - 2018-02-08 17:41 - 000000000 ____D C:\FRST 2018-02-08 15:21 - 2018-02-08 15:21 - 002402304 _____ (Farbar) C:\Users\cylon2\Desktop\FRST64.exe 2018-02-08 12:30 - 2018-02-08 17:37 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2018-02-08 12:30 - 2018-02-08 17:34 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy 2018-02-08 12:30 - 2018-02-08 12:30 - 000000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking 2018-02-08 12:19 - 2018-02-08 12:19 - 008206624 _____ (Malwarebytes) C:\Users\cylon2\Desktop\adwcleaner_7.0.7.0(1).exe 2018-02-07 19:37 - 2018-02-07 19:37 - 000003668 _____ C:\WINDOWS\System32\Tasks\kotcatkcomksz 2018-02-07 17:09 - 2018-02-07 17:09 - 000000000 ____D C:\Users\cylon2\AppData\Local\Destructive_Creations 2018-02-07 17:04 - 2018-02-07 17:04 - 000000000 ____D C:\Users\cylon2\AppData\Local\Anc 2018-02-07 16:55 - 2018-02-07 16:55 - 000000222 _____ C:\Users\cylon2\Desktop\Ancestors Legacy Multiplayer Open Beta.url 2018-02-07 01:18 - 2018-02-07 01:18 - 000000000 ____D C:\WINDOWS\System32\Tasks\S-1-5-21-3089140509-2297242534-4279767804-1000 2018-02-07 01:08 - 2018-02-07 01:08 - 000000000 ____D C:\Users\cylon2\Documents\FeedbackHub 2018-02-06 22:31 - 2018-02-06 22:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eagle Dynamics 2018-02-06 22:31 - 2018-02-06 22:31 - 000000000 ____D C:\Program Files\Eagle Dynamics 2018-02-06 16:55 - 2018-02-06 16:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Benchmark Sims 2018-02-06 16:34 - 1998-10-07 13:08 - 000327168 _____ (InstallShield Software Corporation) C:\WINDOWS\IsUn040c.exe 2018-02-04 16:42 - 2018-02-04 16:47 - 000281688 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe 2018-02-04 16:42 - 2018-02-04 16:42 - 000076888 _____ C:\WINDOWS\SysWOW64\PnkBstrA.exe 2018-02-04 16:04 - 2018-02-04 16:04 - 000000222 _____ C:\Users\cylon2\Desktop\Far Cry 3.url 2018-02-01 22:31 - 2018-02-01 22:31 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\FiraxisLive 2018-02-01 22:15 - 2018-02-01 23:43 - 000000000 ____D C:\Program Files\Sid Meiers Civilization VI 2018-02-01 22:15 - 2018-02-01 23:38 - 000001099 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sid Meiers Civilization VI.lnk 2018-02-01 22:15 - 2018-02-01 22:15 - 000001087 _____ C:\Users\Public\Desktop\Sid Meiers Civilization VI.lnk 2018-02-01 15:39 - 2018-02-01 16:05 - 000000000 ____D C:\Users\cylon2\Endless Space 2 2018-02-01 15:10 - 2018-02-01 15:10 - 000000222 _____ C:\Users\cylon2\Desktop\Endless Space 2.url 2018-02-01 12:40 - 2018-02-01 18:27 - 000004764 _____ C:\Users\cylon2\Desktop\Nouveau document texte.txt 2018-01-31 13:52 - 2018-01-31 13:52 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\McAfee Safe Connect 2018-01-31 13:52 - 2018-01-31 13:52 - 000000000 ____D C:\Users\cylon2\AppData\Local\McAfee_Inc 2018-01-31 13:51 - 2018-01-31 13:54 - 000000000 ____D C:\Program Files (x86)\McAfee Safe Connect 2018-01-29 19:34 - 2018-01-29 19:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fallout Tactics [GOG.com] 2018-01-29 19:23 - 2018-01-29 21:48 - 000000000 ____D C:\Users\cylon2\Desktop\Fallout Tactics-GOG 2018-01-28 13:05 - 2018-01-28 13:20 - 000000767 _____ C:\Users\cylon2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk 2018-01-26 16:56 - 2018-01-26 16:56 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\fltk.org 2018-01-26 16:56 - 2018-01-26 16:56 - 000000000 ____D C:\ProgramData\fltk.org 2018-01-26 16:47 - 2018-01-26 16:47 - 000000221 _____ C:\Users\cylon2\Desktop\Amnesia The Dark Descent.url 2018-01-22 00:59 - 2018-01-22 01:04 - 000000000 ____D C:\Users\cylon2\AppData\Local\PlaceholderTileLogoFolder 2018-01-19 14:46 - 2018-01-19 14:46 - 000000000 ____D C:\Users\cylon2\Desktop\zelda 2018-01-19 00:04 - 2018-01-19 00:04 - 000000000 ____D C:\Users\cylon2\Documents\Stronghold Crusader 2 2018-01-18 23:55 - 2018-02-01 22:00 - 000000000 ____D C:\Program Files (x86)\Stronghold Crusader 2 2018-01-17 23:26 - 2018-01-18 02:05 - 000000000 ____D C:\Program Files (x86)\cemu 2018-01-17 23:07 - 2018-01-17 23:07 - 000000000 ____D C:\WINDOWS\SysWOW64\directx 2018-01-15 22:43 - 2018-01-26 16:50 - 000000000 ____D C:\ProgramData\Oracle 2018-01-15 22:43 - 2018-01-26 16:46 - 000097344 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2018-01-15 22:43 - 2018-01-26 16:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2018-01-15 22:43 - 2018-01-26 16:46 - 000000000 ____D C:\Program Files (x86)\Java 2018-01-15 22:43 - 2018-01-15 22:43 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\Sun 2018-01-15 22:43 - 2018-01-15 22:43 - 000000000 ____D C:\Users\cylon2\AppData\LocalLow\Sun 2018-01-15 21:37 - 2018-01-15 21:37 - 000000000 ____D C:\Program Files (x86)\VulkanRT 2018-01-15 21:37 - 2018-01-04 01:01 - 000137528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2018-01-15 21:37 - 2017-11-02 21:15 - 000928568 _____ C:\WINDOWS\system32\vulkan-1.dll 2018-01-15 21:37 - 2017-11-02 21:15 - 000798520 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2018-01-15 21:37 - 2017-11-02 21:15 - 000490808 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2018-01-15 21:37 - 2017-11-02 21:14 - 000591672 _____ C:\WINDOWS\system32\vulkaninfo.exe 2018-01-15 21:36 - 2018-01-15 21:36 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation 2018-01-15 21:34 - 2018-01-04 02:44 - 040269624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 035179080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 019796520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 016449872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 013430632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 012843496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 011015584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 010900432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 004306736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 003893792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 003707888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001975184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6439065.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001674544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6439065.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001334624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001325384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001134952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001125960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001053768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001049296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 001043128 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000988656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000938896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000885680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000795928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000740336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000635248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000618928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000616248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000599536 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000506864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2018-01-15 21:34 - 2018-01-04 02:44 - 000045600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll 2018-01-14 18:51 - 2018-01-14 18:51 - 003044224 _____ C:\Users\cylon2\Desktop\ZHPCleaner.exe 2018-01-11 13:48 - 2018-01-11 13:48 - 000025837 _____ C:\Users\cylon2\Desktop\2eab7dc2e98e45e293e8007d1eda3266.pdf ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2018-02-08 17:40 - 2017-08-04 16:56 - 000000000 ____D C:\Users\cylon2\AppData\LocalLow\Mozilla 2018-02-08 17:39 - 2017-08-04 16:55 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2018-02-08 17:39 - 2017-08-04 16:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-02-08 17:39 - 2017-08-04 16:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2018-02-08 17:38 - 2017-09-28 22:26 - 000000000 ____D C:\ProgramData\NVIDIA 2018-02-08 17:37 - 2017-12-07 00:42 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2018-02-08 17:37 - 2017-09-29 09:45 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2018-02-08 17:02 - 2017-12-07 00:17 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2018-02-08 13:38 - 2017-12-30 13:26 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\ZHP 2018-02-08 13:38 - 2017-12-30 13:19 - 000000000 ____D C:\Users\cylon2\AppData\Local\ZHP 2018-02-08 12:38 - 2017-09-13 18:47 - 000000000 ____D C:\Program Files (x86)\Origin 2018-02-08 12:20 - 2018-01-04 19:18 - 000000000 ____D C:\AdwCleaner 2018-02-08 11:34 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization 2018-02-08 11:33 - 2017-09-29 14:46 - 000000000 ___HD C:\Program Files\WindowsApps 2018-02-08 11:33 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness 2018-02-07 20:05 - 2017-12-07 00:26 - 000000000 ____D C:\Users\cylon2 2018-02-07 19:37 - 2017-08-05 19:18 - 000000000 ____D C:\Users\cylon2\AppData\Local\CrashDumps 2018-02-07 17:59 - 2017-08-04 17:57 - 000000000 ____D C:\Program Files (x86)\Steam 2018-02-07 17:04 - 2017-08-12 14:51 - 000000000 ____D C:\Users\cylon2\AppData\Local\UnrealEngine 2018-02-07 16:55 - 2017-08-04 18:04 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2018-02-07 14:06 - 2017-09-29 14:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2018-02-07 13:53 - 2017-09-29 14:44 - 000000000 ____D C:\WINDOWS\INF 2018-02-07 13:53 - 2017-08-05 17:48 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\uTorrent 2018-02-07 01:25 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\NDF 2018-02-07 01:25 - 2017-08-04 11:32 - 000000000 ____D C:\Users\cylon2\AppData\Local\ElevatedDiagnostics 2018-02-06 13:14 - 2017-12-07 00:42 - 000004762 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier 2018-02-06 13:14 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2018-02-06 13:14 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\Macromed 2018-02-06 03:49 - 2017-09-29 14:49 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2018-02-06 03:49 - 2017-09-29 14:49 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2018-02-05 23:51 - 2017-11-15 16:10 - 000000000 ____D C:\Users\cylon2\AppData\Local\Battle.net 2018-02-05 13:02 - 2017-11-15 16:09 - 000000000 ____D C:\Program Files (x86)\Battle.net 2018-02-04 16:47 - 2017-11-08 21:25 - 000281688 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr 2018-02-04 16:47 - 2017-11-08 21:25 - 000000000 ____D C:\Users\cylon2\AppData\Local\PunkBuster 2018-02-04 16:45 - 2017-11-07 18:51 - 000000000 ____D C:\Users\cylon2\AppData\Local\Ubisoft Game Launcher 2018-02-04 16:42 - 2017-11-08 21:04 - 000282512 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2018-02-04 16:32 - 2017-08-04 21:18 - 000000000 ____D C:\Users\cylon2\Documents\My Games 2018-02-01 22:11 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2018-01-31 13:46 - 2017-08-29 10:07 - 000000030 _____ C:\AVScanner.ini 2018-01-31 13:46 - 2017-08-29 10:07 - 000000000 ____D C:\ProgramData\McAfee 2018-01-31 13:46 - 2017-08-29 10:06 - 000000000 ____D C:\Users\cylon2\AppData\Local\Adobe 2018-01-31 11:29 - 2017-12-07 00:42 - 000003368 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3089140509-2297242534-4279767804-1000 2018-01-31 11:29 - 2017-09-28 22:48 - 000002414 _____ C:\Users\cylon2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-01-31 11:29 - 2017-09-28 22:48 - 000000000 ___RD C:\Users\cylon2\OneDrive 2018-01-29 21:42 - 2017-08-03 20:22 - 000000000 ____D C:\Users\cylon2\AppData\Local\VirtualStore 2018-01-29 19:32 - 2017-08-12 14:20 - 000000000 ____D C:\GOG Games 2018-01-28 14:46 - 2017-12-08 12:47 - 000000000 ____D C:\Program Files (x86)\SpellForce 3 2018-01-28 13:20 - 2018-01-06 19:47 - 000000000 ____D C:\Games 2018-01-28 13:03 - 2017-08-05 13:29 - 000000962 _____ C:\Users\cylon2\Desktop\RegCleaner.lnk 2018-01-27 00:11 - 2018-01-06 20:21 - 000000000 ____D C:\Users\cylon2\AppData\Local\Black_Tree_Gaming 2018-01-27 00:11 - 2018-01-06 20:21 - 000000000 ____D C:\Program Files\Nexus Mod Manager 2018-01-24 11:59 - 2017-08-05 12:56 - 000548000 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2018-01-22 00:59 - 2017-12-07 00:27 - 000000000 ____D C:\Users\cylon2\AppData\Local\Packages 2018-01-22 00:02 - 2017-09-28 22:44 - 000000000 ____D C:\Users\cylon2\AppData\Local\ConnectedDevicesPlatform 2018-01-21 23:06 - 2017-10-08 17:25 - 000000000 ____D C:\Program Files (x86)\Microsoft Games 2018-01-21 23:05 - 2017-08-04 16:47 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2018-01-21 23:03 - 2017-09-28 22:44 - 000000000 __RHD C:\Users\Public\AccountPictures 2018-01-20 22:38 - 2017-08-12 17:01 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\DAEMON Tools Lite 2018-01-17 23:38 - 2017-08-20 19:14 - 000000000 ____D C:\Users\cylon2\AppData\Local\NVIDIA 2018-01-17 17:21 - 2017-08-29 14:04 - 000000000 ____D C:\Users\cylon2\Desktop\Nouveau dossier (2) 2018-01-15 21:39 - 2017-09-28 22:26 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2018-01-15 21:38 - 2017-12-07 00:42 - 000004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2018-01-15 21:38 - 2017-12-07 00:42 - 000004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2018-01-15 21:38 - 2017-12-07 00:42 - 000003940 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2018-01-15 21:38 - 2017-09-28 22:26 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2018-01-15 21:37 - 2017-12-07 00:42 - 000003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2018-01-15 21:37 - 2017-12-07 00:42 - 000003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2018-01-15 21:37 - 2017-12-07 00:42 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2018-01-15 21:37 - 2017-12-07 00:42 - 000003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2018-01-15 21:37 - 2017-12-07 00:42 - 000003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2018-01-15 21:37 - 2017-09-28 22:26 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2018-01-15 21:37 - 2017-08-04 17:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2018-01-14 19:10 - 2017-12-07 00:21 - 002354698 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2018-01-14 19:10 - 2017-09-30 15:39 - 001052224 _____ C:\WINDOWS\system32\perfh00C.dat 2018-01-14 19:10 - 2017-09-30 15:39 - 000236594 _____ C:\WINDOWS\system32\perfc00C.dat 2018-01-14 19:02 - 2017-09-13 18:46 - 000000000 ____D C:\ProgramData\Origin 2018-01-14 14:42 - 2017-09-13 18:48 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\Origin 2018-01-13 16:32 - 2017-08-08 12:06 - 000000000 ____D C:\Users\cylon2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WiiU_USB_Helper 2018-01-09 21:37 - 2017-08-04 19:15 - 000000000 ____D C:\WINDOWS\system32\MRT 2018-01-09 21:35 - 2017-10-11 20:02 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe 2018-01-09 21:35 - 2017-08-04 19:15 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe ==================== Fichiers à la racine de certains dossiers ======= 2017-12-16 12:07 - 2017-12-16 12:07 - 000000094 _____ () C:\Users\cylon2\AppData\Local\fusioncache.dat ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\WINDOWS\system32\winlogon.exe => Le fichier est signé numériquement C:\WINDOWS\system32\wininit.exe => Le fichier est signé numériquement C:\WINDOWS\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\WINDOWS\system32\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\WINDOWS\system32\services.exe => Le fichier est signé numériquement C:\WINDOWS\system32\User32.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\User32.dll => Le fichier est signé numériquement C:\WINDOWS\system32\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\WINDOWS\system32\rpcss.dll => Le fichier est signé numériquement C:\WINDOWS\system32\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\WINDOWS\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2018-02-06 19:25 ==================== Fin de FRST.txt ============================