Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 06.05.2018 01 Exécuté par NGOC TRAC LE (administrateur) sur ACER (10-05-2018 08:54:57) Exécuté depuis C:\Users\NGOC TRAC LE\Desktop Profils chargés: NGOC TRAC LE (Profils disponibles: NGOC TRAC LE) Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: Chrome) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe () C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfemms.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe (McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\acrotray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.717\SSScheduler.exe () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe () C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McUICnt.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe (McAfee, Inc.) C:\Program Files\mcafee\MfeAV\MfeAVSvc.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\CSP\2.5.312.0\McCSPServiceHost.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\VSCore_15_6\mcapexe.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe (Intel Security) C:\Program Files\Common Files\mcafee\ClientAnalytics\Legacy\McClientAnalytics.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11580520 2010-11-11] (Realtek Semiconductor) HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [140568 2007-10-30] (Acronis) HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [134160 2007-11-29] (Logitech, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [556288 2017-05-31] (McAfee, Inc.) HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340848 2011-04-02] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [202608 2011-03-29] (Egis Technology Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-24] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2595616 2007-10-30] (Acronis) HKLM-x32\...\Run: [AcronisTimounterMonitor] => C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [909208 2007-10-30] (Acronis) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 7.0] => C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [483328 2008-04-23] (Adobe Systems Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Run: [NBJ] => C:\Program Files (x86)\Ahead\Nero BackItUp\NBJ.exe [1957888 2005-06-02] (Ahead Software AG) HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248176 2014-06-05] (TomTom) HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Run: [Dropbox Update] => C:\Users\NGOC TRAC LE\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.) HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Run: [IOB5WWHJOK] => "C:\Users\NGOC TRAC LE\AppData\Roaming\Colis-disponible.vbs" HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Run: [Microsoft.vbs] => "C:\ProgramData\Microsoft.vbs" <==== ATTENTION HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Run: [LDSnMvWFYp] => wscript.exe //B "C:\Users\NGOC TRAC LE\LDSnMvWFYp.vbs" HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Run: [Ver.vbs] => "C:\ProgramData\Ver.vbs" <==== ATTENTION HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Run: [Les Etudes.vbs] => "C:\ProgramData\Les Etudes.vbs" <==== ATTENTION HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Policies\system: [NoDispCPL] 0 HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Policies\Explorer: [NoInstrumentation] 1 HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid} Lsa: [Authentication Packages] msv1_0 relog_ap Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk [2016-08-23] ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -> C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk [2012-01-09] ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2018-04-01] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.717\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Hosts: 0.0.0.1 mssplus.mcafee.com Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 Tcpip\..\Interfaces\{9E7B2044-FFFF-45B5-B4BA-BC5F5EE9193D}: [DhcpNameServer] 192.168.0.254 Internet Explorer: ================== HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://google.com HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank URLSearchHook: HKU\S-1-5-21-1488127205-2302878940-3680074537-1001 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKU\S-1-5-21-1488127205-2302878940-3680074537-1001 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1 SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1 SearchScopes: HKU\S-1-5-21-1488127205-2302878940-3680074537-1001 -> DefaultScope 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = SearchScopes: HKU\S-1-5-21-1488127205-2302878940-3680074537-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U453DF&PC=U453&q={searchTerms}&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1488127205-2302878940-3680074537-1001 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-1488127205-2302878940-3680074537-1001 -> {E3C16A9F-6B77-427D-955C-C50AEB540FF6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1 BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-09-25] (Intel Security) BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-04-30] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26] (SEIKO EPSON CORPORATION) BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-04-26] (McAfee, Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2018-04-30] (Microsoft Corporation) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2014-04-22] (DVDVideoSoft Ltd.) BHO-x32: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14] (Adobe Systems Incorporated) BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-09-25] (Intel Security) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-03-08] (Oracle Corporation) BHO-x32: Programme d'aide de l'Assistant de connexion Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> c:\program files (x86)\google\googletoolbar1.dll [2012-01-09] (Google Inc.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18] (Adobe Systems Incorporated) BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-04-26] (McAfee, Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2018-04-30] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-08] (Oracle Corporation) BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2014-04-30] (DVDVideoSoft Ltd.) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26] (SEIKO EPSON CORPORATION) Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-09-25] (Intel Security) Toolbar: HKLM-x32 - &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\google\googletoolbar1.dll [2012-01-09] (Google Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-09-25] (Intel Security) DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-04-26] (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-04-26] (McAfee, Inc.) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - Pas de fichier Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - Pas de fichier Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-04-30] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-04-30] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-04-30] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-04-30] (Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-04-26] (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-04-26] (McAfee, Inc.) Handler: WSWSVCUchrome - Pas de valeur CLSID Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2017-05-31] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2017-05-31] (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\NGOC TRAC LE\AppData\Roaming\TomTom\HOME\Profiles\xq79z3lv.default [2016-05-23] FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2014-10-06] [Legacy] [non signé] FF ProfilePath: C:\Users\NGOC TRAC LE\AppData\Roaming\Mozilla\Firefox\Profiles\k81a9m75.default-1455887542950 [2018-05-06] FF Homepage: Mozilla\Firefox\Profiles\k81a9m75.default-1455887542950 -> hxxps://www.google.fr FF SearchPlugin: C:\Users\NGOC TRAC LE\AppData\Roaming\Mozilla\Firefox\Profiles\k81a9m75.default-1455887542950\searchplugins\McSiteAdvisor.xml [2016-03-08] FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi FF Extension: (McAfee® WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [2018-05-02] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2017-07-01] [Legacy] [non signé] FF HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: (Download videos and MP3s from YouTube) - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-05-04] [Legacy] [non signé] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_29_0_0_171.dll [2018-05-08] () FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-05-31] () FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_171.dll [2018-05-08] () FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Windows\SysWOW64\npdeployJava1.dll [2016-03-08] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-08] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-08] (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-05-31] () FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-03-03] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\adslTV\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2012-01-09] () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1488127205-2302878940-3680074537-1001: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\NGOC TRAC LE\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1702150-0-npoctoshape.dll [2017-02-15] (Octoshape ApS) FF Plugin ProgramFiles/Appdata: C:\Users\NGOC TRAC LE\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2014-08-13] (Octoshape ApS) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxps://www.google.fr/ CHR StartupUrls: Default -> "hxxps://www.google.fr/" CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?fr=mcafee&type=D211FR662G0&p={searchTerms} CHR DefaultSearchKeyword: Default -> mcafee CHR Profile: C:\Users\NGOC TRAC LE\AppData\Local\Google\Chrome\User Data\Default [2018-05-10] CHR Extension: (McAfee® WebAdvisor) - C:\Users\NGOC TRAC LE\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2018-05-05] CHR Extension: (Skype) - C:\Users\NGOC TRAC LE\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-12-01] CHR Extension: (True Key™ by Intel Security) - C:\Users\NGOC TRAC LE\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbeldjopgciegccabfohnefghfpinncn [2018-04-05] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\NGOC TRAC LE\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03] CHR Extension: (Chrome Media Router) - C:\Users\NGOC TRAC LE\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-23] CHR Profile: C:\Users\NGOC TRAC LE\AppData\Local\Google\Chrome\User Data\System Profile [2018-05-09] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-05-28] CHR HKU\S-1-5-21-1488127205-2302878940-3680074537-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2014-05-04] CHR HKLM-x32\...\Chrome\Extension: [fdloijijlkoblmigdofommgnheckmaki] - CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2016-05-28] CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [mfkamignjaneflbgdjegpidckhjdiibj] - ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [69632 2012-09-24] (Adobe Systems) [Fichier non signé] R2 AdobeActiveFileMonitor4.0; C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe [102400 2005-09-09] () [Fichier non signé] R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8566440 2018-04-23] (Microsoft Corporation) R3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1752992 2017-03-29] (Intel Security) R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes) R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [604824 2018-04-26] (McAfee, Inc.) R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe [984480 2017-06-03] (McAfee, Inc.) S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [224704 2011-03-09] (McAfee, Inc.) S2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exe [405392 2018-03-27] (McAfee, Inc.) R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\\McCSPServiceHost.exe [2139832 2017-05-31] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) S2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [241656 2017-04-30] (McAfee, Inc.) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [390656 2017-04-30] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [343544 2017-04-30] (McAfee, Inc.) S4 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1543248 2017-05-31] (McAfee, Inc.) S3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1042288 2017-05-22] (Intel Security, Inc.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Fichier non signé] R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [1001920 2018-03-29] (McAfee, Inc.) R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16928 2018-03-29] (McAfee, Inc.) S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [87760 2018-03-29] (McAfee, Inc.) R2 TryAndDecideService; C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [492720 2007-10-30] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 [X] ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [76824 2017-05-02] (McAfee, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [209608 2017-05-31] (McAfee, Inc.) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-05-10] (Malwarebytes) R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [476176 2017-05-02] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [353808 2017-05-02] (McAfee, Inc.) U3 mfeavfk01; pas de ImagePath R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [504336 2017-05-02] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [918544 2017-05-02] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [495632 2017-04-07] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [107544 2017-04-07] (McAfee, Inc.) R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [109072 2017-05-02] (McAfee, Inc.) R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [252432 2017-05-02] (McAfee, Inc.) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) Error(1) reading file: "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office " 2018-05-10 08:54 - 2018-05-10 08:57 - 000032695 _____ C:\Users\NGOC TRAC LE\Desktop\FRST.txt 2018-05-10 08:53 - 2018-05-10 08:54 - 000000000 ____D C:\FRST 2018-05-10 08:51 - 2018-05-10 08:51 - 002406912 _____ (Farbar) C:\Users\NGOC TRAC LE\Desktop\FRST64.exe 2018-05-10 07:33 - 2018-05-10 07:33 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{9D2D9C02-5142-45E0-82CD-656AB42FD253} 2018-05-10 07:26 - 2018-05-10 07:26 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2018-05-09 14:00 - 2018-05-09 14:00 - 000207789 _____ C:\Users\NGOC TRAC LE\Desktop\ZHPDiag 09-05-2018.txt 2018-05-09 11:46 - 2018-05-09 11:46 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{385C3706-9D55-4F43-B2C3-A9B8A6B8E67B} 2018-05-09 09:32 - 2018-05-09 09:32 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2018-05-08 22:23 - 2018-05-08 22:23 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{B0C4BF57-F5ED-47BE-8CF8-6D5633D148BE} 2018-05-08 20:58 - 2018-05-08 21:21 - 000000290 __RSH C:\ProgramData\ntuser.pol 2018-05-08 09:10 - 2018-05-08 21:37 - 000208152 _____ C:\Users\NGOC TRAC LE\Desktop\ZHPDiag 08-05-2018.txt 2018-05-08 08:47 - 2018-05-08 08:47 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{3B953D52-E902-4B99-BC60-37753F900A90} 2018-05-08 08:37 - 2018-05-08 08:37 - 003090816 _____ C:\Users\NGOC TRAC LE\Downloads\ZHPDiag3 (1).exe 2018-05-07 20:46 - 2018-05-07 20:46 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{43F1B671-0798-4CB8-A10B-7D550BD2441E} 2018-05-07 18:59 - 2018-05-07 19:12 - 073524488 _____ (Malwarebytes ) C:\Users\NGOC TRAC LE\Downloads\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.5006 (3).exe 2018-05-07 18:56 - 2018-05-07 19:13 - 073524488 _____ (Malwarebytes ) C:\Users\NGOC TRAC LE\Downloads\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.5006.exe 2018-05-07 18:52 - 2018-05-07 18:52 - 000001831 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2018-05-07 18:52 - 2018-05-07 18:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2018-05-07 18:52 - 2018-03-19 12:57 - 000076192 _____ C:\Windows\system32\Drivers\mbae64.sys 2018-05-07 18:51 - 2018-05-07 18:51 - 000000000 ____D C:\ProgramData\Malwarebytes 2018-05-07 17:00 - 2018-05-07 17:14 - 073524488 _____ (Malwarebytes ) C:\Users\NGOC TRAC LE\Downloads\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.5006 (2).exe 2018-05-07 16:58 - 2018-05-07 17:16 - 073524488 _____ (Malwarebytes ) C:\Users\NGOC TRAC LE\Downloads\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.5006 (1).exe 2018-05-07 16:32 - 2018-05-07 16:32 - 000000000 ____D C:\Program Files\Malwarebytes 2018-05-07 09:20 - 2018-05-07 09:29 - 073524488 _____ (Malwarebytes ) C:\Users\NGOC TRAC LE\Downloads\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.5006-premium-try.exe 2018-05-07 08:52 - 2018-05-08 18:51 - 000000000 ____D C:\AdwCleaner 2018-05-07 08:48 - 2018-05-07 08:49 - 007271632 _____ (Malwarebytes) C:\Users\NGOC TRAC LE\Downloads\adwcleaner_7.1.1.exe 2018-05-07 08:46 - 2018-05-07 08:46 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{BD7BA197-7610-4A53-8289-4860CA11CBA1} 2018-05-07 06:51 - 2018-05-07 07:44 - 000120096 _____ C:\Users\NGOC TRAC LE\Desktop\ZHPCleaner.txt 2018-05-06 23:38 - 2018-05-06 23:46 - 879169024 _____ C:\Users\NGOC TRAC LE\Backup PQservice 06-05-2018.tib 2018-05-06 23:01 - 2018-05-06 23:01 - 005351424 _____ C:\Users\NGOC TRAC LE\backup system 06-05-2018.tib 2018-05-06 12:43 - 2018-05-06 12:43 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{14907B23-4559-4046-B525-E59267B88370} 2018-05-05 22:16 - 2018-05-05 22:16 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{31B968F6-1B23-46A0-8D48-AFC79C4023C5} 2018-05-05 01:08 - 2018-05-05 01:08 - 000690168 _____ (Dropbox, Inc.) C:\Users\NGOC TRAC LE\Downloads\DropboxInstaller.exe 2018-05-05 00:17 - 2018-05-05 00:17 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{00724E56-A658-4C66-AA15-C32383921C2E} 2018-05-04 16:30 - 2018-05-04 16:30 - 000000837 _____ C:\Users\NGOC TRAC LE\Desktop\ZHPCleaner.lnk 2018-05-04 16:29 - 2018-05-04 16:29 - 003146112 _____ C:\Users\NGOC TRAC LE\Downloads\ZHPCleaner.exe 2018-05-03 22:33 - 2018-05-04 14:25 - 000000000 ___RD C:\Users\NGOC TRAC LE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup-spam 2018-05-03 11:43 - 2018-05-04 14:57 - 000226741 _____ C:\Users\NGOC TRAC LE\Desktop\ZHPDiag 04-05-2018.txt 2018-05-03 11:03 - 2018-05-09 13:32 - 000000220 _____ C:\Users\NGOC 2018-05-03 11:00 - 2018-05-09 14:00 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\ZHP 2018-05-03 11:00 - 2018-05-08 21:05 - 000000827 _____ C:\Users\NGOC TRAC LE\Desktop\ZHPDiag.lnk 2018-05-03 11:00 - 2018-05-04 16:30 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\ZHP 2018-05-03 10:58 - 2018-05-03 10:59 - 003086720 _____ C:\Users\NGOC TRAC LE\Downloads\ZHPDiag3.exe 2018-05-03 08:26 - 2018-05-03 08:26 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{8042D30A-64B8-43EB-97DA-1297195C9DCB} 2018-05-03 08:24 - 2018-05-08 19:08 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\Viber 2018-05-02 13:26 - 2018-05-02 13:26 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\Google 2018-05-02 12:16 - 2018-05-02 12:16 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{BE6A76FD-4D88-463A-8228-2FE0667E6E34} 2018-05-01 09:33 - 2018-05-01 09:33 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{D832E24B-CF33-4C26-8886-DA11CA8630F7} 2018-04-30 11:55 - 2018-04-30 11:55 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{084AEE8A-48B3-4420-AEC1-2C4A6066E084} 2018-04-29 12:14 - 2018-04-29 12:14 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{C2E47C49-3590-4A62-B247-CDF16D3A8FE1} 2018-04-28 20:26 - 2018-04-28 20:26 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{3A615241-9BBD-4B18-8A29-D9AC699B667A} 2018-04-28 08:25 - 2018-04-28 08:25 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{39069B01-3965-430A-931C-BF32E890DF5A} 2018-04-27 11:12 - 2018-04-27 11:12 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{4FFE3639-8460-489D-9FE5-1C12ED3D8660} 2018-04-26 11:45 - 2018-04-26 11:45 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{29B93B23-E9E4-4522-B46E-1C7787BF50E3} 2018-04-25 19:55 - 2018-04-25 19:55 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{F37CA126-371E-4F1A-B1DA-6C9110D6D8F2} 2018-04-25 13:16 - 2018-04-26 19:51 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\Playstation 2018-04-25 13:16 - 2018-04-26 19:51 - 000000000 ____D C:\Playstation 2018-04-25 07:54 - 2018-04-25 07:54 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{C7A6FF50-D0D7-4B70-AE31-EDB4F46672A1} 2018-04-24 08:02 - 2018-04-24 08:02 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{7D950FFD-E32D-4C17-B457-494804E73B11} 2018-04-23 09:01 - 2018-04-23 09:01 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{4528DD8B-837B-47BE-ABEA-A48CF010DD7D} 2018-04-22 11:32 - 2018-04-22 11:32 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{419CA386-19E8-4464-BC50-54CA8A1EF9B8} 2018-04-21 11:43 - 2018-04-21 11:43 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{87279225-D958-4A89-87B8-93DD72074088} 2018-04-20 22:38 - 2018-04-20 22:38 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{26B8E85B-213F-4131-88A2-62C6DCC8D874} 2018-04-20 09:07 - 2018-04-20 09:07 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{81B7C8DF-2405-4FF8-916F-9E34338692A2} 2018-04-19 12:05 - 2018-04-19 12:05 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{F22F3CFA-97E8-4B10-913F-2B15AB06CDB9} 2018-04-19 12:01 - 2018-04-19 12:01 - 000281239 _____ C:\Users\NGOC TRAC LE\Downloads\docapost_0284148333418-04-165184483813260565636.pdf 2018-04-19 11:57 - 2018-04-19 11:58 - 000435769 _____ C:\Users\NGOC TRAC LE\Downloads\docapost_84148331619248818-04-166156088676686169148.pdf 2018-04-18 10:52 - 2018-04-18 10:52 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{3EA91DCB-E4F1-4949-AF7F-F55FC2C35C5D} 2018-04-17 11:32 - 2018-04-17 11:32 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{7D18DEE0-0167-4482-8436-E49FBC9B4DE7} 2018-04-16 13:45 - 2018-04-16 13:45 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{F5F52D61-3C23-4EB9-B625-F6A5511805FB} 2018-04-15 14:04 - 2018-04-15 14:04 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{671048E7-7657-40C0-A3FF-974B68ED6C6C} 2018-04-14 09:06 - 2018-04-14 09:06 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{526508FC-7376-4417-9D72-60914E81B2DF} 2018-04-13 14:13 - 2018-04-13 14:13 - 000001665 _____ C:\Users\NGOC TRAC LE\Desktop\Viber.lnk 2018-04-13 12:13 - 2018-04-13 12:13 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{131E8F78-FC9B-440F-872E-30D65A515E05} 2018-04-12 22:49 - 2018-04-12 22:49 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{89AA22A1-4A85-4139-8141-D2B9441A0959} 2018-04-12 09:35 - 2018-04-12 09:35 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{B28B5208-F82E-44B4-98AB-9308C6C6AE2F} 2018-04-11 11:21 - 2018-04-11 11:21 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{42BA14B0-E3AD-4753-9EBE-7AA8D1C274BC} 2018-04-10 10:27 - 2018-04-10 10:27 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\{F30DEFB1-FBC3-4AF1-91A4-8A098005FECA} ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2018-05-10 08:56 - 2014-05-09 05:39 - 000001070 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf6b38532c3385.job 2018-05-10 08:16 - 2015-06-28 11:48 - 000001224 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1488127205-2302878940-3680074537-1001UA.job 2018-05-10 07:41 - 2009-07-14 06:45 - 000024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2018-05-10 07:41 - 2009-07-14 06:45 - 000024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2018-05-10 07:31 - 2011-10-13 22:45 - 000747660 _____ C:\Windows\system32\perfh00C.dat 2018-05-10 07:31 - 2011-10-13 22:45 - 000150184 _____ C:\Windows\system32\perfc00C.dat 2018-05-10 07:31 - 2009-07-14 07:13 - 001669656 _____ C:\Windows\system32\PerfStringBackup.INI 2018-05-10 07:31 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf 2018-05-10 07:23 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2018-05-09 21:21 - 2018-04-01 11:06 - 000000000 ____D C:\ProgramData\McAfee Security Scan 2018-05-09 09:32 - 2012-12-20 11:57 - 000007705 _____ C:\Windows\wininit.ini 2018-05-09 09:30 - 2012-07-26 17:56 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\Dropbox 2018-05-08 22:16 - 2015-06-28 11:48 - 000001172 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1488127205-2302878940-3680074537-1001Core.job 2018-05-08 19:08 - 2018-04-07 17:14 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\ViberPC 2018-05-08 18:51 - 2012-01-07 22:40 - 000000000 ____D C:\Users\NGOC TRAC LE 2018-05-08 15:46 - 2017-02-02 21:53 - 000004628 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2018-05-08 15:46 - 2012-05-17 21:37 - 000804864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2018-05-08 15:46 - 2012-05-17 21:37 - 000004484 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2018-05-08 15:46 - 2012-02-02 13:12 - 000000000 ____D C:\Windows\system32\Macromed 2018-05-08 15:46 - 2011-07-08 10:29 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2018-05-08 15:46 - 2011-07-08 10:29 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2018-05-08 14:47 - 2018-03-14 11:47 - 000004640 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier 2018-05-08 13:38 - 2013-01-16 23:37 - 000000483 _____ C:\Users\NGOC TRAC LE\AppData\Roaming\Microsoft\Windows\Start Menu\Google.website 2018-05-07 22:22 - 2012-08-14 12:39 - 007554560 ___SH C:\Users\NGOC TRAC LE\Downloads\Thumbs.db 2018-05-03 08:32 - 2017-03-17 00:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2018-05-03 08:32 - 2015-02-21 20:05 - 000002044 _____ C:\Users\Public\Desktop\Google Sheets.lnk 2018-05-02 12:52 - 2017-03-08 12:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2018-05-02 12:52 - 2012-01-07 22:47 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\PowerCinema 2018-05-02 12:51 - 2018-04-07 17:13 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Local\Package Cache 2018-05-02 12:51 - 2018-04-01 11:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2018-05-02 12:51 - 2017-02-02 21:53 - 000000000 ____D C:\Program Files\TrueKey 2018-05-02 12:51 - 2016-12-21 00:08 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2018-05-02 12:51 - 2016-10-07 09:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office 2016 2018-05-02 12:51 - 2016-01-09 15:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-05-02 12:51 - 2015-11-17 12:11 - 000000000 ____D C:\Program Files\McAfee Security Scan 2018-05-02 12:51 - 2012-01-07 22:47 - 000000000 ____D C:\ProgramData\clear.fi 2018-05-02 12:50 - 2018-04-07 17:14 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber 2018-05-02 12:50 - 2018-03-26 12:52 - 000000000 ____D C:\Users\NGOC TRAC LE\Downloads\FR-Suivi 2018-05-02 12:50 - 2012-07-26 17:59 - 000000000 ___RD C:\Users\NGOC TRAC LE\Dropbox 2018-05-02 12:50 - 2012-01-19 18:46 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\vlc 2018-05-02 12:50 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\registration 2018-04-30 12:24 - 2016-07-01 12:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2018-04-30 12:19 - 2011-10-13 13:06 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2018-04-27 11:13 - 2018-03-28 15:30 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-04-27 11:13 - 2018-03-28 15:30 - 000002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-04-24 17:14 - 2018-04-07 17:15 - 000000000 ____D C:\Users\NGOC TRAC LE\Documents\ViberDownloads 2018-04-19 17:14 - 2018-03-26 14:00 - 000000000 ____D C:\Windows Azure 2018-04-19 17:14 - 2018-03-26 14:00 - 000000000 ____D C:\Users\NGOC TRAC LE\AppData\Roaming\Windows Azure 2018-04-13 19:23 - 2009-07-14 07:32 - 000000000 ____D C:\Windows\system32\FxsTmp 2018-04-11 20:09 - 2011-07-08 10:21 - 000000000 ____D C:\Program Files (x86)\EgisTec IPS ==================== Fichiers à la racine de certains dossiers ======= 2017-12-23 23:34 - 2017-12-23 23:34 - 000000132 _____ () C:\Users\NGOC TRAC LE\AppData\Roaming\Adobe BMP Format CS5 Prefs 2014-11-13 14:11 - 2017-12-23 23:30 - 000000132 _____ () C:\Users\NGOC TRAC LE\AppData\Roaming\Adobe GIF Format CS5 Prefs 2014-11-13 14:12 - 2014-11-13 14:12 - 000000132 _____ () C:\Users\NGOC TRAC LE\AppData\Roaming\Adobe PNG Format CS5 Prefs 2013-11-30 20:35 - 2013-12-24 22:49 - 000007859 _____ () C:\Users\NGOC TRAC LE\AppData\Roaming\pcouffin.cat 2013-11-30 20:35 - 2013-12-24 22:49 - 000001167 _____ () C:\Users\NGOC TRAC LE\AppData\Roaming\pcouffin.inf 2013-11-30 20:38 - 2013-12-24 22:49 - 000000033 _____ () C:\Users\NGOC TRAC LE\AppData\Roaming\pcouffin.log 2013-11-30 20:35 - 2013-12-24 22:49 - 000082816 _____ (VSO Software) C:\Users\NGOC TRAC LE\AppData\Roaming\pcouffin.sys 2013-11-30 20:42 - 2013-11-30 20:43 - 000000057 _____ () C:\Users\NGOC TRAC LE\AppData\Roaming\Printer.ini 2014-01-06 15:44 - 2016-09-19 06:44 - 000000274 _____ () C:\Users\NGOC TRAC LE\AppData\Roaming\WB.CFG 2012-09-30 09:09 - 2012-09-30 09:38 - 000000600 _____ () C:\Users\NGOC TRAC LE\AppData\Local\PUTTY.RND 2016-08-27 21:41 - 2016-08-27 21:41 - 000001658 _____ () C:\Users\NGOC TRAC LE\AppData\Local\recently-used.xbel ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2018-05-08 10:59 ==================== Fin de FRST.txt ============================