Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 02.08.2018 Exécuté par user (administrateur) sur USER-PC (14-08-2018 01:38:26) Exécuté depuis C:\Users\user\Desktop Profils chargés: user (Profils disponibles: user) Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: FF) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Microsoft Corporation) C:\Windows\System32\wisptis.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\avp.exe (Microsoft Corporation) C:\Windows\System32\wisptis.exe (Amazon Services LLC) C:\Users\user\AppData\Local\Amazon Music\Amazon Music Helper.exe () C:\Program Files (x86)\NordVPN\nordvpn-service.exe (NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Privax Limited) C:\Program Files (x86)\HMA! Pro VPN\Vpn.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\avpui.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe (Privax Limited) C:\Program Files (x86)\HMA! Pro VPN\VpnUpdate.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM-x32\...\Run: [mbot_fr_11] => [X] HKU\S-1-5-21-4268732833-2078672349-1973945886-1000\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [5908432 2018-06-22] (NordVPN) HKU\S-1-5-18\...\Run: [] => [X] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HMA! Pro VPN.lnk [2017-11-15] ShortcutTarget: HMA! Pro VPN.lnk -> C:\Program Files (x86)\HMA! Pro VPN\Vpn.exe (Privax Limited) GroupPolicy: Restriction - Chrome <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{09E9C6D0-FEA1-42AD-A8E3-7211F5B60B87}: [NameServer] 77.234.40.79 Tcpip\..\Interfaces\{5DD29B8C-90B3-48C4-89C7-7439BE4F50B7}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{A3F7E054-43B2-4CDF-9450-1EFDA09382A8}: [NameServer] 8.8.8.8,8.8.4.4 Internet Explorer: ================== HKU\S-1-5-21-4268732833-2078672349-1973945886-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130885644248971417&GUID=00000000-0000-0000-0000-000000000000 HKU\S-1-5-21-4268732833-2078672349-1973945886-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D111617-A9FCDBB39EF&form=CONMHP&conlogo=CT3335799 SearchScopes: HKLM -> DefaultScope la valeur est absente SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_secureddownload_15_08&cd=2XzuyEtN2Y1L1Qzu0CtDyE0AtDtDtCtCyCtAtDtByB0D0F0CtN0D0Tzu0StCtCyEzztN1L2XzutAtFzztFtCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDyB0ByByCtDyE0EtGyDyDyCtBtG0Dzy0EtBtG0E0DyCtDtGyDyEtB0EzytA0FtA0Dzy0A0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzytCtB0EzztD0CyDtGyE0AzztBtGyEtBzzyBtG0AzztC0CtGtD0D0Azyzz0EyB0C0ByEtB0C2QtN1B2Z1V1T1S1NzuyDtCyC&cr=139962688&ir= SearchScopes: HKLM -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_tele_14_50_ie&cd=2XzuyEtN2Y1L1Qzu0CtDyE0AtDtDtCtCyCtAtDtByB0D0F0CtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0AzztA0FtA0AtG0BtCyB0FtG0AtAzyzytG0A0B0DyEtGtCzyyE0CyCyEzytCtByD0Czy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzytCtB0EzztD0CyDtGyE0AzztBtGyEtBzzyBtG0AzztC0CtGtD0D0Azyzz0EyB0C0ByEtB0C2Q&cr=752274906&ir= SearchScopes: HKLM -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-4268732833-2078672349-1973945886-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKU\S-1-5-21-4268732833-2078672349-1973945886-1000 -> ${searchCLSID} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKU\S-1-5-21-4268732833-2078672349-1973945886-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xux0ohQkUyHV_-uVqn14U4DjFUms4TSz4dqKb7tQLWIMz60xFA6bdT-A6UFnSFAkg50bwxRnVGOkn3bzgPeMSsJlo7hcE3PPYg0UTcey5yrvx-0HfQS3Q9cjHGnkJU2m6AuwwQ84dwFubOxmhpvbpSWpA,,&q={searchTerms} SearchScopes: HKU\S-1-5-21-4268732833-2078672349-1973945886-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D111617-A9FCDBB39EF&form=CONBDF&conlogo=CT3335799&q={searchTerms} SearchScopes: HKU\S-1-5-21-4268732833-2078672349-1973945886-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_tele_14_50_ie&cd=2XzuyEtN2Y1L1Qzu0CtDyE0AtDtDtCtCyCtAtDtByB0D0F0CtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0AzztA0FtA0AtG0BtCyB0FtG0AtAzyzytG0A0B0DyEtGtCzyyE0CyCyEzytCtByD0Czy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzytCtB0EzztD0CyDtGyE0AzztBtGyEtBzzyBtG0AzztC0CtGtD0D0Azyzz0EyB0C0ByEtB0C2Q&cr=752274906&ir= SearchScopes: HKU\S-1-5-21-4268732833-2078672349-1973945886-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331316&octid=EB_ORIGINAL_CTID&ISID=MCAD6F594-8277-416A-954B-D6E8FEB4AC28&SearchSource=58&CUI=&UM=6&UP=SPA585C33A-0265-470F-88D9-F717DAF326A1&q={searchTerms}&SSPV= BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\IEExt\ie_plugin.dll [2018-07-17] (AO Kaspersky Lab) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll [2018-07-27] (Oracle Corporation) BHO-x32: Programme d’aide de l’Assistant de connexion au compte Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: PDF Architect 5 Helper -> {AEA429F3-D2D4-4BD7-A03E-5357DA017733} -> C:\Program Files (x86)\PDF Architect 5\creator\plugins\IEAddin\creator-ie-helper.dll [2017-11-29] (pdfforge GmbH) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-07-27] (Oracle Corporation) BHO-x32: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\IEExt\ie_plugin.dll [2018-07-17] (AO Kaspersky Lab) Toolbar: HKLM - Pas de nom - {ae07101b-46d4-4a98-af68-0333ea26e113} - Pas de fichier Toolbar: HKLM - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\IEExt\ie_plugin.dll [2018-07-17] (AO Kaspersky Lab) Toolbar: HKLM-x32 - Pas de nom - {ae07101b-46d4-4a98-af68-0333ea26e113} - Pas de fichier Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\IEExt\ie_plugin.dll [2018-07-17] (AO Kaspersky Lab) Toolbar: HKLM-x32 - PDF Architect 5 Toolbar - {84F23192-A475-4038-B5C0-8584777F2DF4} - C:\Program Files (x86)\PDF Architect 5\creator\plugins\IEAddin\creator-ie-plugin.dll [2017-11-29] (pdfforge GmbH) Toolbar: HKU\S-1-5-21-4268732833-2078672349-1973945886-1000 -> Pas de nom - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Pas de fichier DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab FireFox: ======== FF DefaultProfile: k0s9law2.default-1525778861036 FF ProfilePath: C:\Users\user\AppData\Roaming\TomTom\HOME\Profiles\ixib978t.default [2017-05-30] FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\k0s9law2.default-1525778861036 [2018-08-14] FF Extension: (Context DuckDuckGo) - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\k0s9law2.default-1525778861036\Extensions\context-duckduckgo@addons.mozilla.org.xpi [2018-05-08] FF Extension: (Dictionnaire français) - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\k0s9law2.default-1525778861036\Extensions\fr-dicollecte@dictionaries.addons.mozilla.org [2018-06-11] [Legacy] FF Extension: (DuckDuckGo Privacy Essentials) - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\k0s9law2.default-1525778861036\Extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi [2018-08-13] FF Extension: (Français Language Pack) - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\k0s9law2.default-1525778861036\Extensions\langpack-fr@firefox.mozilla.org.xpi [2018-07-09] FF HKLM\...\Firefox\Extensions: [light_plugin_F363A72DD7B6435783A76E5F612C9006@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi => non trouvé(e) FF HKLM\...\Firefox\Extensions: [light_plugin_F88CEF8523DE460F9FA1D6E48BF8D340@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2018-06-04] FF HKLM-x32\...\Firefox\Extensions: [shortcutff@gmail.com] - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\a458wpa0.default\extensions\shortcutff@gmail.com => non trouvé(e) FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\a458wpa0.default\extensions\faststartff@gmail.com => non trouvé(e) FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F363A72DD7B6435783A76E5F612C9006@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi => non trouvé(e) FF HKLM-x32\...\Firefox\Extensions: [light_plugin_F88CEF8523DE460F9FA1D6E48BF8D340@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_30_0_0_134.dll [2018-07-10] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN) FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-06-22] (Adobe Systems) FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_134.dll [2018-07-10] () FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2009-03-03] (GARMIN Corp.) FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-07-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-07-27] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @photodex.com/PhotodexPresenter -> C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll [2017-04-16] ( ) FF Plugin-x32: @Sibelius.com/Scorch Plugin,version=6.2.0.88 -> C:\Program Files (x86)\Sibelius Software\Scorch\npsibelius.dll [2013-03-11] () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-22] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-22] (Google Inc.) FF Plugin-x32: @virtools.com/3DviaPlayer -> C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll [2012-04-05] (Dassault Systèmes) FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-06-22] (Adobe Systems) FF Plugin-x32: PDF Architect 5 -> C:\Program Files (x86)\PDF Architect 5\np-previewer.dll [2017-11-29] (pdfforge GmbH) FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) FF Plugin HKU\S-1-5-21-4268732833-2078672349-1973945886-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll [2013-01-23] (Amazon.com, Inc.) FF Plugin HKU\S-1-5-21-4268732833-2078672349-1973945886-1000: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom) Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=orcl_default CHR DefaultSearchKeyword: Default -> Yahoo CHR DefaultSuggestURL: Default -> hxxps://fr.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10 CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default [2018-08-12] CHR Extension: (Kaspersky Protection) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amkpcclbbgegoafihnpgomddadjhcadd [2018-06-04] CHR Extension: (Block Site - Website Blocker for Chrome™) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2018-06-14] CHR Extension: (Exif Meta Viewer With Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdeahmamcoanadeblogkaghaofgpflkd [2018-06-13] CHR Extension: (Flickr Exif Learnr) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\jflkhbjjhncpogfmijkcflffmmfpdmhe [2016-08-04] CHR Extension: (Ghostery – Bloqueur de publicité protégeant la vie privée) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2018-07-24] CHR Extension: (Google Play Books) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2017-12-10] CHR Extension: (EXIF Viewer) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2016-08-04] CHR Extension: (Kindle Cloud Reader) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlnambgcbojdeagknjljhiafpjaiacad [2016-12-31] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04] CHR Extension: (Chrome Media Router) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-08-11] CHR HKLM\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd CHR HKLM\...\Chrome\Extension: [Äÿ] - CHR HKU\S-1-5-21-4268732833-2078672349-1973945886-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [Äÿ] - CHR HKLM-x32\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ehhlaekjfiiojlddgndcnefflngfmhen] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [kpdmjodecdegfglgaapafjleomjjlpnh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [nbljechdpodpbchbmjcoamidppmpnmlc] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [Äÿ] - ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818128 2018-06-22] (Adobe Systems Incorporated) S4 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2321384 2018-05-11] (Adobe Systems, Incorporated) S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2128872 2018-05-11] (Adobe Systems, Incorporated) S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-03-14] (Apple Inc.) R2 AVP19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\avp.exe [619640 2018-02-28] (AO Kaspersky Lab) S4 hasplms; C:\Windows\system32\hasplms.exe [4608320 2014-11-27] (SafeNet Inc.) S4 HmaProVpn; C:\Program Files (x86)\HMA! Pro VPN\VpnSvc.exe [5864416 2018-07-26] (Privax Limited) S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Fichier non signé] S3 klvssbridge64_19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\vssbridge64.exe [416560 2018-06-04] (AO Kaspersky Lab) R2 KSDE3.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe [617016 2018-02-28] (AO Kaspersky Lab) S4 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-12-09] (Nalpeiron Ltd.) [Fichier non signé] R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [431568 2018-06-22] () S4 Olympus DVR Service; C:\Program Files (x86)\Common Files\Olympus Shared\DeviceManager\olydvrsv.exe [174592 2012-11-08] (OLYMPUS IMAGING CORP.) [Fichier non signé] S4 PDF Architect 5; C:\Program Files\PDF Architect 5\ws.exe [2832560 2017-11-29] (pdfforge GmbH) S4 PDF Architect 5 Creator; C:\Program Files\PDF Architect 5\creator\common\creator-ws.exe [874680 2017-11-29] (pdfforge GmbH) S4 PDF Architect 5 Manager; C:\Program Files (x86)\PDF Architect 5 Manager\PDF Architect 5\Architect Manager.exe [985848 2017-05-16] (© pdfforge GmbH.) S4 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [186760 2017-04-16] () R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S4 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.233\WsAppService.exe [493792 2017-11-07] (Wondershare) S4 WsDrvInst; C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe [120096 2017-11-08] (Wondershare) S4 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [672024 2015-02-27] (Wacom Technology, Corp.) S4 xrdd.exe; C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe [83312 2015-09-18] (X-Rite Inc.) ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (pas de ServiceDLL) S3 CMUSBDAC; C:\Windows\System32\DRIVERS\CMUSBDAC.sys [594944 2014-09-19] (C-MEDIA) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [243400 2018-01-27] (AO Kaspersky Lab) S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfoX64.sys [18128 2007-09-25] () S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] () R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331608 2014-11-27] (SafeNet Inc.) R3 hmatap; C:\Windows\System32\DRIVERS\hmatap.sys [45560 2017-10-31] (The OpenVPN Project) R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [528576 2018-02-20] (AO Kaspersky Lab) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [72904 2017-12-27] (AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [122056 2018-02-02] (AO Kaspersky Lab) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [87752 2018-07-17] (AO Kaspersky Lab) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [219328 2018-07-17] (AO Kaspersky Lab) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [1193160 2018-07-17] (AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1127104 2018-07-17] (AO Kaspersky Lab) R1 klim6; C:\Windows\System32\DRIVERS\klim6.sys [56520 2018-02-12] (AO Kaspersky Lab) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [58056 2018-01-15] (AO Kaspersky Lab) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [83496 2017-12-11] (AO Kaspersky Lab) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [50648 2017-05-30] (AO Kaspersky Lab) R3 kltap; C:\Windows\System32\DRIVERS\kltap.sys [48080 2018-02-12] (The OpenVPN Project) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [81632 2017-11-07] (AO Kaspersky Lab) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [161592 2018-07-17] (AO Kaspersky Lab) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [203968 2018-02-24] (AO Kaspersky Lab) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52832 2015-10-26] (hxxp://libusb-win32.sourceforge.net) R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation) R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2013-03-12] (Realtek Semiconductor Corporation ) S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2007-12-12] () [Fichier non signé] R3 tapnordvpn; C:\Windows\System32\DRIVERS\tapnordvpn.sys [35592 2018-06-07] (The OpenVPN Project) R2 WinI2C-DDC; C:\Windows\system32\drivers\DDCDrv.sys [20832 2016-07-11] (Nicomsoft Ltd.) R2 WinI2C-DDC; C:\Windows\SysWOW64\drivers\DDCDrv.sys [10240 2016-07-11] (Nicomsoft Ltd.) [Fichier non signé] S3 catchme; \??\C:\patrick\catchme.sys [X] S3 cpuz134; \??\C:\Users\user\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] <==== ATTENTION S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] S3 VIAHdAudAddService; system32\drivers\viahduaa.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) Error(1) reading file: "C:\Users\user\Downloads\ILE MAURICE 2012 " 2018-08-14 01:20 - 2018-08-14 01:34 - 000062439 _____ C:\Users\user\Desktop\Addition.txt 2018-08-14 01:17 - 2018-08-14 01:38 - 000026102 _____ C:\Users\user\Desktop\FRST.txt 2018-08-14 01:14 - 2018-08-14 01:38 - 000000000 ___DC C:\FRST 2018-08-14 01:08 - 2018-08-14 01:09 - 002412544 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe 2018-08-12 17:56 - 2018-08-12 17:56 - 000000375 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2018-08-07 01:14 - 2018-08-12 16:24 - 000001145 _____ C:\Users\user\Desktop\Adobe Photoshop CC 2018.lnk 2018-08-06 19:55 - 2018-08-06 19:55 - 000001000 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2018.lnk 2018-08-06 18:48 - 2018-08-06 18:48 - 000001185 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2018-08-06 18:48 - 2018-08-06 18:48 - 000001173 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2018-08-06 18:31 - 2018-08-06 18:31 - 002029776 _____ (Adobe Systems Incorporated) C:\Users\user\Downloads\Creative_Cloud_Set-Up(1).exe 2018-08-06 18:26 - 2018-08-06 18:26 - 007408104 _____ (Adobe System Incorporated.) C:\Users\user\Downloads\AdobeCreativeCloudCleanerTool(1).exe 2018-08-05 16:58 - 2018-08-05 16:59 - 002029824 _____ (Adobe Systems Incorporated) C:\Users\user\Downloads\Creative_Cloud_Set-Up.exe 2018-08-05 16:45 - 2018-08-05 16:45 - 000000000 ____D C:\Users\user\Desktop\GPUCache 2018-08-05 15:05 - 2018-08-05 15:05 - 000000352 _____ C:\Windows\Tasks\AdobeGCInvoker-1.0-user-PC-user.job 2018-08-05 15:04 - 2018-08-05 15:04 - 000000364 _____ C:\Windows\Tasks\AdobeAAMUpdater-1.0-user-PC-user.job 2018-08-05 13:22 - 2018-08-12 18:00 - 000001053 _____ C:\Users\user\Desktop\Adobe Lightroom Classic CC.lnk 2018-08-05 13:22 - 2018-08-05 13:22 - 000001021 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom Classic CC.lnk 2018-08-05 12:54 - 2018-08-05 12:54 - 002318608 _____ (Adobe Systems Incorporated) C:\Users\user\Downloads\Lightroom_Classic_Set-Up(1).exe 2018-08-05 12:32 - 2018-08-05 12:32 - 007408104 _____ (Adobe System Incorporated.) C:\Users\user\Downloads\AdobeCreativeCloudCleanerTool.exe 2018-08-05 11:20 - 2018-08-05 11:20 - 002318512 _____ (Adobe Systems Incorporated) C:\Users\user\Downloads\Lightroom_Classic_Set-Up.exe 2018-08-05 11:16 - 2018-08-09 19:31 - 001022334 _____ C:\Windows\ntbtlog.txt 2018-08-05 11:01 - 2018-08-05 11:06 - 331075033 _____ C:\Users\user\Downloads\ACCCx4_6_0_391.zip 2018-08-05 10:38 - 2018-08-05 12:05 - 000000000 __HDC C:\temp 2018-08-04 22:08 - 2018-08-04 22:22 - 230604519 _____ C:\Users\user\Downloads\wetransfer-5be1aa.zip 2018-08-04 22:03 - 2018-08-04 22:03 - 000000000 ____D C:\Windows\SysWOW64\GPUCache 2018-08-01 18:50 - 2018-08-01 18:51 - 007963136 _____ C:\Users\user\Desktop\ICE-2.0.3-for-64-bit-Windows.msi 2018-07-30 06:00 - 2018-07-30 06:01 - 000000000 ____D C:\Users\user\AppData\Roaming\DxO 2018-07-30 05:29 - 2018-07-30 05:36 - 000000000 ____D C:\ProgramData\DxO 2018-07-30 05:29 - 2018-07-30 05:34 - 002147609 _____ (Neat Image team, ABSoft ) C:\Users\user\Downloads\NeatSetup._6.1exe 2018-07-30 05:29 - 2018-07-30 05:29 - 000000000 ___DC C:\Program Files\DxO 2018-07-30 05:23 - 2018-07-30 05:36 - 000000000 ____D C:\Users\user\AppData\Local\DxO 2018-07-30 04:17 - 2018-07-30 04:55 - 406182200 _____ C:\Users\user\Downloads\DxO_Nik_Collection.exe 2018-07-30 03:53 - 2018-07-30 03:53 - 000000000 ____D C:\Users\user\Documents\Neat Image v8 for Photoshop 2018-07-30 03:53 - 2018-07-30 03:53 - 000000000 ____D C:\Users\user\AppData\Roaming\NeatImage8 PS 64 2018-07-30 03:37 - 2018-07-30 03:37 - 000000000 ___DC C:\Program Files\Neat Image v8 for Photoshop 2018-07-30 03:37 - 2018-07-30 03:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neat Image v8 for Photoshop 2018-07-30 03:36 - 2018-07-30 03:36 - 010157944 _____ (Neat Image team, ABSoft ) C:\Users\user\Downloads\NeatPSSetupDemo64.exe 2018-07-29 06:26 - 2018-07-29 06:26 - 000003454 _____ C:\Windows\System32\Tasks\AdobeGCInvoker-1.0-user-PC-user 2018-07-29 06:26 - 2018-07-29 06:26 - 000000040 ___HC C:\4E4F59890ADB 2018-07-28 19:44 - 2018-08-12 18:00 - 000001186 _____ C:\Users\Public\Desktop\Adobe Photoshop Elements 2018.lnk 2018-07-28 19:44 - 2018-07-28 19:44 - 000001154 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 2018.lnk 2018-07-28 19:13 - 2018-08-13 18:52 - 000007597 _____ C:\Users\user\AppData\Local\Resmon.ResmonCfg 2018-07-28 10:56 - 2018-07-28 10:56 - 000000000 ____D C:\ProgramData\boost_interprocess 2018-07-28 10:08 - 2018-07-28 10:08 - 001262996 _____ C:\Users\user\Downloads\FRANCAIS - BROWNING SPEC OPS EXTREME MODELE BTC-8FHD-PX -copyright.pdf 2018-07-28 05:37 - 2018-07-28 05:38 - 039179002 _____ C:\Users\user\Downloads\The_genera_of_Nematinae_Hymenoptera_Tent.pdf 2018-07-22 17:27 - 2018-07-22 17:27 - 002394889 _____ C:\Users\user\Downloads\8-mzucca_0.pdf 2018-07-22 17:26 - 2018-07-22 17:26 - 011603211 _____ C:\Users\user\Downloads\rencontres_naturalistes_web_1.pdf 2018-07-22 11:21 - 2018-07-22 11:21 - 000000000 ____D C:\Users\user\Downloads\drive-download-20180722T091921Z-001 2018-07-22 11:19 - 2018-07-22 11:20 - 034932764 _____ C:\Users\user\Downloads\drive-download-20180722T091921Z-001.zip 2018-07-22 09:56 - 2018-08-04 22:57 - 000001577 _____ C:\Users\user\.youtube-upload-credentials.json ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2018-08-14 01:31 - 2014-12-11 05:31 - 000000288 _____ C:\Windows\Tasks\WSE_Vosteran.job 2018-08-14 01:18 - 2014-11-16 08:40 - 000000000 ____D C:\Program Files (x86)\Opera 2018-08-14 01:13 - 2016-12-06 19:04 - 000000000 ____D C:\Users\user\AppData\LocalLow\Mozilla 2018-08-14 01:13 - 2009-07-14 06:45 - 000024016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2018-08-14 01:13 - 2009-07-14 06:45 - 000024016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2018-08-14 01:03 - 2011-10-18 19:08 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2018-08-14 00:57 - 2016-07-28 18:43 - 000001368 ____H C:\Windows\Tasks\{1E18A923-CDF1-4D1C-93B2-AD4CC5BD33EA}.job 2018-08-14 00:57 - 2016-07-28 18:18 - 000001328 ____H C:\Windows\Tasks\{D374D242-D5B3-4B1F-BA0F-1DC075FF3BF4}.job 2018-08-14 00:57 - 2014-11-16 08:42 - 000001334 _____ C:\Windows\Tasks\FJPZBC.job 2018-08-14 00:57 - 2014-11-16 08:42 - 000001330 _____ C:\Windows\Tasks\UBEJ.job 2018-08-14 00:57 - 2012-08-14 19:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-08-14 00:57 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2018-08-13 19:30 - 2011-10-13 15:00 - 000003928 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{EE96685B-6D89-416A-9E23-FF8E9589FAD2} 2018-08-13 18:59 - 2016-06-27 23:26 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2018-08-12 21:16 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF 2018-08-12 20:58 - 2009-07-14 05:20 - 000000000 __RHD C:\Users\Public\Libraries 2018-08-12 20:42 - 2017-11-15 08:09 - 000004158 _____ C:\Windows\System32\Tasks\HMA! Pro VPN Update 2018-08-12 20:15 - 2014-08-19 17:50 - 000000000 ____D C:\Users\user\AppData\Local\Adobe 2018-08-12 18:18 - 2012-11-04 05:17 - 000000000 ____D C:\Users\user\AppData\Local\ElevatedDiagnostics 2018-08-12 18:00 - 2018-06-24 11:26 - 000001733 _____ C:\Users\Public\Desktop\Zerene Stacker (64-bit).lnk 2018-08-12 18:00 - 2018-06-10 10:20 - 000000908 _____ C:\Users\Public\Desktop\Windows Movie Maker.lnk 2018-08-12 18:00 - 2018-01-19 12:37 - 000001117 _____ C:\Users\Public\Desktop\RisingView.lnk 2018-08-12 18:00 - 2018-01-05 18:33 - 000000840 _____ C:\Users\Public\Desktop\PDFCreator.lnk 2018-08-12 18:00 - 2017-10-28 03:18 - 000001087 _____ C:\Users\user\Desktop\Helicon 3D Viewer.lnk 2018-08-12 18:00 - 2017-10-28 03:18 - 000001072 _____ C:\Users\user\Desktop\Helicon Focus 6.lnk 2018-08-12 18:00 - 2017-04-16 17:13 - 000000875 _____ C:\Users\Public\Desktop\VLC media player.lnk 2018-08-12 18:00 - 2017-04-15 07:13 - 000001954 _____ C:\Users\Public\Desktop\LRTimelapse 4.7.5.lnk 2018-08-12 18:00 - 2016-11-17 00:39 - 000000705 _____ C:\Users\Public\Desktop\Mycocle.lnk 2018-08-12 18:00 - 2016-05-22 14:33 - 000001108 _____ C:\Users\Public\Desktop\Studio One 3 x64.lnk 2018-08-12 18:00 - 2016-02-02 07:36 - 000002083 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2018-08-12 18:00 - 2013-05-26 07:50 - 000002091 _____ C:\Users\Public\Desktop\Lightroom 4.4 64-bits.lnk 2018-08-12 18:00 - 2013-02-13 21:31 - 000000686 _____ C:\Users\Public\Desktop\Flora Bellissima.lnk 2018-08-12 18:00 - 2011-11-16 21:39 - 000001721 _____ C:\Users\user\Desktop\MapSource.lnk 2018-08-12 18:00 - 2011-10-18 19:39 - 000001323 _____ C:\Users\Public\Desktop\Adobe Premiere Elements 9.lnk 2018-08-12 17:59 - 2009-07-14 17:24 - 000747644 _____ C:\Windows\system32\perfh00C.dat 2018-08-12 17:59 - 2009-07-14 17:24 - 000150168 _____ C:\Windows\system32\perfc00C.dat 2018-08-12 17:59 - 2009-07-14 07:13 - 001669584 _____ C:\Windows\system32\PerfStringBackup.INI 2018-08-12 17:59 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf 2018-08-12 16:20 - 2011-10-18 19:31 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2018-08-11 08:00 - 2016-07-28 18:18 - 000000390 _____ C:\Windows\Tasks\X-Rite Device Services Software Updater.job 2018-08-10 19:37 - 2016-02-01 21:45 - 000002182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-08-10 19:37 - 2016-02-01 21:45 - 000002141 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-08-08 20:21 - 2014-10-29 17:18 - 000000000 ____D C:\Users\user\AppData\Roaming\Audacity 2018-08-06 22:19 - 2011-10-18 20:01 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2018-08-06 19:55 - 2011-11-10 13:08 - 000000000 ____D C:\Users\user\Documents\Adobe 2018-08-06 19:55 - 2011-10-18 19:30 - 000000000 ____D C:\Users\user\AppData\Roaming\Adobe 2018-08-06 19:21 - 2013-05-26 07:49 - 000000000 ___DC C:\Program Files\Adobe 2018-08-06 19:03 - 2011-10-18 19:25 - 000000000 ____D C:\ProgramData\Adobe 2018-08-06 18:48 - 2011-10-18 19:25 - 000000000 ___DC C:\Program Files (x86)\Adobe 2018-08-05 17:28 - 2012-04-22 20:54 - 000000000 ____D C:\Users\user\AppData\Roaming\vlc 2018-08-04 22:57 - 2018-06-10 10:20 - 000000000 ____D C:\Users\user\AppData\Roaming\XMovieMaker 2018-08-04 16:39 - 2013-12-30 09:08 - 000000000 ____D C:\ProgramData\Package Cache 2018-08-01 18:52 - 2017-12-04 01:32 - 000000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image Composite Editor 2018-07-31 00:57 - 2009-07-14 07:08 - 000032482 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2018-07-30 18:10 - 2018-05-08 15:58 - 000003870 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1525787912 2018-07-30 05:34 - 2011-10-18 22:16 - 000000000 ____D C:\Users\user\AppData\Local\Google 2018-07-30 05:32 - 2011-10-20 19:59 - 000000000 ____D C:\ProgramData\Nik Software 2018-07-30 05:32 - 2011-10-18 22:16 - 000000000 ____D C:\ProgramData\Google 2018-07-29 18:25 - 2013-05-26 07:50 - 000000000 ___DC C:\Program Files\Common Files\Adobe 2018-07-28 10:56 - 2018-01-05 18:38 - 000000000 ____D C:\Users\user\AppData\Roaming\PDF Architect 5 2018-07-28 10:09 - 2018-06-06 18:51 - 000000000 ____D C:\Users\user\Documents\piège photo 2018-07-27 06:13 - 2018-01-19 11:32 - 000000000 ___DC C:\Program Files (x86)\Java 2018-07-27 06:12 - 2018-01-19 11:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2018-07-27 06:11 - 2018-01-19 11:32 - 000098680 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2018-07-27 04:31 - 2017-11-15 08:09 - 000000000 ___DC C:\Program Files (x86)\HMA! Pro VPN 2018-07-23 20:47 - 2018-06-24 11:26 - 000000000 ____D C:\Users\user\AppData\Roaming\ZereneStacker 2018-07-22 17:29 - 2016-03-05 12:30 - 000000000 ____D C:\Users\user\Documents\Nature 2018-07-22 10:40 - 2018-06-10 10:21 - 000000000 ____D C:\Users\user\Documents\XMovieMaker 2018-07-22 10:39 - 2018-06-10 10:20 - 000000000 ___DC C:\Program Files\Windows Movie Maker 2018-07-22 10:39 - 2018-06-10 10:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2018-07-17 18:31 - 2018-06-04 18:30 - 001127104 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys 2018-07-17 18:31 - 2018-06-04 18:30 - 000219328 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys 2018-07-17 18:31 - 2018-04-25 21:41 - 000087752 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\kldisk.sys 2018-07-17 18:31 - 2018-02-17 02:50 - 000161592 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwtp.sys 2018-07-17 18:29 - 2018-04-25 21:41 - 001193160 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys 2018-07-17 18:29 - 2018-04-17 18:22 - 000152360 _____ (AO Kaspersky Lab) C:\Windows\system32\klhkum.dll 2018-07-17 00:02 - 2011-10-14 10:47 - 000563832 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Fichiers à la racine de certains dossiers ======= 2014-08-01 18:53 - 2014-11-16 08:39 - 000003801 _____ () C:\Users\user\AppData\Roaming\Bubble Dock.boostrap.log 2014-08-01 18:54 - 2014-11-16 08:39 - 000024516 _____ () C:\Users\user\AppData\Roaming\Bubble Dock.installation.log 2014-09-01 10:18 - 2014-12-27 21:52 - 000000935 _____ () C:\Users\user\AppData\Roaming\FJPZBC 2018-01-15 20:59 - 2018-01-15 21:16 - 000571168 _____ () C:\Users\user\AppData\Roaming\Scorch_Install.log 2014-09-01 10:18 - 2014-09-01 10:18 - 000001248 _____ () C:\Users\user\AppData\Roaming\UBEJ 2017-09-07 05:06 - 2017-09-07 05:06 - 000023849 _____ () C:\Users\user\AppData\Roaming\UserTile.png 2014-12-11 06:31 - 2014-12-27 10:31 - 000000160 _____ () C:\Users\user\AppData\Roaming\WB.CFG 2014-08-01 18:53 - 2014-11-16 08:38 - 000000291 _____ () C:\Users\user\AppData\Roaming\WindApp.boostrap.log 2014-11-16 08:39 - 2014-11-16 08:39 - 000000374 _____ () C:\Users\user\AppData\Roaming\WindApp.installation.log 2012-01-30 18:04 - 2017-06-09 17:03 - 000009728 _____ () C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-12 19:31 - 2014-12-17 19:31 - 000000002 _____ () C:\Users\user\AppData\Local\DSI.DAT 2016-12-16 10:42 - 2016-12-16 10:42 - 000002427 _____ () C:\Users\user\AppData\Local\recently-used.xbel 2018-07-28 19:13 - 2018-08-13 18:52 - 000007597 _____ () C:\Users\user\AppData\Local\Resmon.ResmonCfg 2018-01-06 17:41 - 2018-01-06 20:20 - 000000184 _____ () C:\Users\user\AppData\Local\uts.ini 2011-10-18 19:09 - 2011-10-18 19:09 - 000017408 _____ () C:\Users\user\AppData\Local\WebpageIcons.db 2018-06-01 19:48 - 2018-06-01 19:50 - 000000000 _____ () C:\Users\user\AppData\Local\{D87522CA-C3A0-4067-A87B-4A0F96D4E33B} Fichiers à déplacer ou supprimer: ==================== C:\Windows\Tasks\{1E18A923-CDF1-4D1C-93B2-AD4CC5BD33EA}.job C:\Windows\Tasks\{D374D242-D5B3-4B1F-BA0F-1DC075FF3BF4}.job Certains fichiers dans TEMP: ==================== 2018-06-09 17:32 - 2017-03-30 16:22 - 009968704 _____ (© pdfforge GmbH.) C:\Users\user\AppData\Local\Temp\318ff7f5-cf95-4eff-bb79-babe5fbd2e80.exe 2018-06-09 17:32 - 2018-06-09 17:32 - 010062000 _____ (© pdfforge GmbH.) C:\Users\user\AppData\Local\Temp\a1bb0f10-fdac-429f-89d9-8e207b218ebd.exe 2016-12-22 18:41 - 2016-12-22 18:43 - 008650280 _____ (Adobe Systems Incorporated) C:\Users\user\AppData\Local\Temp\ade.exe 2016-12-01 21:38 - 2018-01-06 16:20 - 000360600 _____ (Apowersoft) C:\Users\user\AppData\Local\Temp\ApowersoftAutoUpdater.exe 2015-11-12 18:55 - 2015-11-12 18:55 - 000144008 _____ (© 2015 Microsoft Corporation) C:\Users\user\AppData\Local\Temp\BingSvc.exe 2015-11-12 18:55 - 2015-11-12 18:55 - 001118360 _____ (© 2015 Microsoft Corporation) C:\Users\user\AppData\Local\Temp\BSvcProcessor.exe 2015-11-12 18:55 - 2015-11-12 18:55 - 000170128 _____ (© 2015 Microsoft Corporation) C:\Users\user\AppData\Local\Temp\BSvcUpdater.exe 2018-01-06 16:38 - 2018-01-06 16:38 - 001721368 _____ (Apowersoft Ltd. ) C:\Users\user\AppData\Local\Temp\bu234rss.5zr.exe 2015-10-31 19:04 - 2015-10-31 19:04 - 001918920 _____ () C:\Users\user\AppData\Local\Temp\CopyTransManagerMDHelper(1).exe 2015-11-11 11:12 - 2015-11-11 11:12 - 001918920 _____ () C:\Users\user\AppData\Local\Temp\CopyTransManagerMDHelper(2).exe 2015-11-13 20:24 - 2015-11-13 20:24 - 001918920 _____ () C:\Users\user\AppData\Local\Temp\CopyTransManagerMDHelper(3).exe 2016-03-09 22:50 - 2016-03-09 22:50 - 001918920 _____ () C:\Users\user\AppData\Local\Temp\CopyTransManagerMDHelper(4).exe 2016-05-14 14:59 - 2016-05-14 14:59 - 001918920 _____ () C:\Users\user\AppData\Local\Temp\CopyTransManagerMDHelper(5).exe 2015-10-31 19:02 - 2015-10-31 19:02 - 001918920 _____ () C:\Users\user\AppData\Local\Temp\CopyTransManagerMDHelper.exe 2016-07-26 18:45 - 2016-07-26 18:45 - 000741440 _____ (Oracle Corporation) C:\Users\user\AppData\Local\Temp\jre-8u101-windows-au.exe 2016-11-04 19:47 - 2016-11-04 19:47 - 000737856 _____ (Oracle Corporation) C:\Users\user\AppData\Local\Temp\jre-8u111-windows-au.exe 2017-01-23 19:22 - 2017-01-23 19:22 - 000739904 _____ (Oracle Corporation) C:\Users\user\AppData\Local\Temp\jre-8u121-windows-au.exe 2017-04-24 18:21 - 2017-04-24 18:21 - 000739904 _____ (Oracle Corporation) C:\Users\user\AppData\Local\Temp\jre-8u131-windows-au.exe 2017-07-24 13:22 - 2017-07-24 13:22 - 000739904 _____ (Oracle Corporation) C:\Users\user\AppData\Local\Temp\jre-8u141-windows-au.exe 2018-04-17 19:58 - 2018-04-17 19:58 - 001884616 _____ (Oracle Corporation) C:\Users\user\AppData\Local\Temp\jre-8u171-windows-au.exe 2018-07-27 06:09 - 2018-07-27 06:09 - 001906040 _____ (Oracle Corporation) C:\Users\user\AppData\Local\Temp\jre-8u181-windows-au.exe 2014-12-18 19:29 - 2014-12-18 19:29 - 000641448 ____N (Oracle Corporation) C:\Users\user\AppData\Local\Temp\jre-8u31-windows-au.exe 2015-04-27 18:48 - 2015-04-27 18:48 - 150622864 _____ () C:\Users\user\AppData\Local\Temp\mpa05660.exe 2018-05-08 15:58 - 2018-05-08 15:58 - 001876480 _____ (Opera Software) C:\Users\user\AppData\Local\Temp\Opera_installer_180508135813327.dll 2018-05-08 15:58 - 2018-05-08 15:58 - 001876480 _____ (Opera Software) C:\Users\user\AppData\Local\Temp\Opera_installer_180508135813602.dll 2018-05-08 15:58 - 2018-05-08 15:58 - 001876480 _____ (Opera Software) C:\Users\user\AppData\Local\Temp\Opera_installer_180508135815971.dll 2018-05-08 15:58 - 2018-05-08 15:58 - 001876480 _____ (Opera Software) C:\Users\user\AppData\Local\Temp\Opera_installer_180508135823485.dll 2018-05-08 15:58 - 2018-05-08 15:58 - 001876480 _____ (Opera Software) C:\Users\user\AppData\Local\Temp\Opera_installer_180508135831918.dll 2016-07-28 18:38 - 2016-07-28 18:38 - 000007168 _____ () C:\Users\user\AppData\Local\Temp\res1.tmp.exe 2015-04-27 18:48 - 2015-04-27 18:49 - 150622864 _____ () C:\Users\user\AppData\Local\Temp\Setup-Wacom.exe 2016-11-01 19:02 - 2015-01-22 17:01 - 000032768 _____ () C:\Users\user\AppData\Local\Temp\shutdown1478019736.exe 2017-05-23 14:58 - 2017-05-23 14:58 - 014157672 _____ (Microsoft Corporation) C:\Users\user\AppData\Local\Temp\vcredist_x86.exe 2017-08-05 15:29 - 2017-08-05 15:29 - 032100680 _____ () C:\Users\user\AppData\Local\Temp\vlc-2.2.6-win64.exe 2018-07-22 09:00 - 2018-07-22 09:01 - 041465128 _____ () C:\Users\user\AppData\Local\Temp\vlc-3.0.3-win64.exe 2014-12-11 05:31 - 2014-12-11 05:31 - 000334336 _____ () C:\Users\user\AppData\Local\Temp\wme.dll ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement