Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x86) Version: 27-01-2019 Exécuté par diagnostique (administrateur) sur DIAGNOSTIQUE-PC (30-01-2019 09:22:56) Exécuté depuis C:\Users\diagnostique\Desktop Profils chargés: diagnostique (Profils disponibles: diagnostique) Platform: Microsoft Windows 7 Professionnel Service Pack 1 (X86) Langue: Français (France) Internet Explorer Version 11 (Navigateur par défaut: FF) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AMD) C:\Windows\System32\atiesrxx.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (AMD) C:\Windows\System32\atieclxx.exe (Adobe Systems, Incorporated) C:\Program Files\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Systems, Incorporated) C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe (Windows (R) Win 7 DDK provider) C:\Program Files\Bluetooth Suite\AdminService.exe (CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe (The Firebird Project) C:\APP\firebird\bin\fbguard.exe (FabulaTech) C:\Windows\System32\ftspssrv.exe (Qualcomm) C:\Program Files\Bluetooth Suite\BtvStack.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Brother Industries, Ltd.) C:\Program Files\Browny02\Brother\BrStMonW.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\APP\ediag\eclipse.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (Adobe Systems Inc.) C:\Program Files\Adobe\Acrobat DC\Acrobat\acrotray.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 3.1 eXtensible Host Controller Driver\Application\iusb3mon.exe (Volkswagen AG) C:\ElsaWin\bin\LcSvrDba.exe () C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe (Volkswagen AG) C:\ElsaWin\bin\LcSvrHis.exe (Volkswagen AG) C:\ElsaWin\bin\LcSvrPas.exe () C:\APP\ddc\bin\psaAgent.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.ELSAWINDB\MSSQL\Binn\sqlservr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe () C:\Program Files\TunnelBear\TunnelBear.Maintenance.exe (Windscribe Limited) C:\Program Files\Windscribe\WindscribeService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (International Business Machines Corporation) C:\APP\ediag\importedj9\jre\bin\j9w.exe () C:\Program Files\EaseUS\Todo Backup\bin\TodoBackupService.exe (Apache Software Foundation) C:\APP\ddc\opt\apache\bin\httpd_ddc.exe (Apache Software Foundation) C:\APP\ddc\opt\apache\bin\httpd_ddc.exe (Node.js) C:\Program Files\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe (The Firebird Project) C:\APP\firebird\bin\fbserver.exe (Brother Industries, Ltd.) C:\Program Files\Browny02\BrYNSvc.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2259784 2013-05-09] (ELAN Microelectronics Corp.) HKLM\...\Run: [BrStsMon00] => C:\Program Files\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.) HKLM\...\Run: [] => [X] HKLM\...\Run: [psastart] => C:\APP\ddc\bin\psaagent.exe [178688 2014-12-04] () HKLM\...\Run: [ediagStart] => C:\APP\ediag\eDiagStart.lnk [618 2017-02-27] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated) HKLM\...\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrotray.exe [4810224 2018-12-19] (Adobe Systems Inc.) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2675176 2018-12-13] (Adobe Systems, Incorporated) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [351968 2014-09-08] () HKLM\...\Run: [USB3MON] => C:\Program Files\Intel\Intel(R) USB 3.0 3.1 eXtensible Host Controller Driver\Application\iusb3mon.exe [299520 2017-03-28] (Intel Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files\Bluetooth Suite\BtvStack.exe [128992 2017-01-18] (Qualcomm) HKU\S-1-5-21-313961326-325444610-1541499784-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3759376 2014-11-24] (Disc Soft Ltd) HKU\S-1-5-21-313961326-325444610-1541499784-1001\...\MountPoints2: I - I:\SETUP.EXE HKU\S-1-5-21-313961326-325444610-1541499784-1001\...\MountPoints2: {5d795d79-c476-11e5-ba13-806e6f6e6963} - F:\start.exe HKU\S-1-5-21-313961326-325444610-1541499784-1001\...\MountPoints2: {6f501e8a-1bbb-11e8-aba2-48d224e55024} - D:\HiSuiteDownLoader.exe HKU\S-1-5-21-313961326-325444610-1541499784-1001\...\MountPoints2: {88411dd0-fbb5-11e6-a219-806e6f6e6963} - F:\start.exe HKU\S-1-5-21-313961326-325444610-1541499784-1001\...\MountPoints2: {b2fddae7-d8d9-11e5-9613-b870f4a03baf} - G:\DiagBox_setup.exe HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2019-01-15] (Google Inc.) HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\Windows\system32\AthCredentialProvider.dll [2017-01-18] (Qualcomm) HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\Windows\system32\AthCredentialProvider.dll [2017-01-18] (Qualcomm) AppInit_DLLs: C:\Windows\system32\nvinit.dll => C:\Windows\system32\nvinit.dll [159712 2018-02-25] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2018-03-03] ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe () Startup: C:\Users\diagnostique\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RT-Updater.lnk [2017-05-23] ShortcutTarget: RT-Updater.lnk -> C:\Ross-Tech\VCDS\VCDS.EXE (Ross-Tech, LLC) Startup: C:\Users\diagnostique\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Superviser les alertes relatives aux cartouches - HP OfficeJet 200 Mobile Series.lnk [2018-05-17] BootExecute: autocheck autochk * CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 89.2.0.1 89.2.0.2 Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4 Tcpip\..\Interfaces\{64AF113B-5B1D-4031-9FBC-A63EDC0B8875}: [DhcpNameServer] 89.2.0.10 Tcpip\..\Interfaces\{AE1BD960-99B4-4926-8569-5CB6EFAC5942}: [DhcpNameServer] 89.2.0.10 Tcpip\..\Interfaces\{D6B8E5DF-541F-4BB4-89EB-7741211B5299}: [DhcpNameServer] 89.2.0.1 89.2.0.2 Tcpip\..\Interfaces\{DDA37331-921F-499B-BFCA-30925A1E96F9}: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{FF97399A-EC65-4889-8B38-1534BB03E6B1}: [DhcpNameServer] 212.27.40.241 212.27.40.240 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKU\S-1-5-21-313961326-325444610-1541499784-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/fr-fr/?ocid=iehp SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2016-03-15] (Microsoft Corporation) BHO: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_151\bin\ssv.dll [2017-11-14] (Oracle Corporation) BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-04-05] (Adobe Systems Incorporated) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation) BHO: Psa DDC SingleSignOn BHO -> {CFCCB454-80CF-481f-B50A-29112EBB0F85} -> C:\APP\ddc\bin\DdcSingleSignOnBHOu.dll [2014-12-04] () BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-04-13] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-11-14] (Oracle Corporation) BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-04-05] (Adobe Systems Incorporated) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-04-05] (Adobe Systems Incorporated) Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-04-12] (Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-04-12] (Microsoft Corporation) Handler: vw-wi - {0F3C833F-FB28-40EA-8CB9-6A55B996C3F6} - C:\ElsaWin\bin\wiprot.dll [2011-12-06] (TODO: ) FireFox: ======== FF DefaultProfile: kxkrxmz7.default-1536663727648 FF ProfilePath: C:\Users\diagnostique\AppData\Roaming\Mozilla\Firefox\Profiles\kxkrxmz7.default-1536663727648 [2019-01-30] FF Extension: (ImTranslator: Traducteur, Dictionnaire, Voix) - C:\Users\diagnostique\AppData\Roaming\Mozilla\Firefox\Profiles\kxkrxmz7.default-1536663727648\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2019-01-29] FF ProfilePath: C:\Users\diagnostique\AppData\Roaming\Actia\diagnostic2.3.4.3\Profiles\z65r9t70.default [2017-10-31] FF Homepage: Actia\diagnostic2.3.4.3\Profiles\z65r9t70.default -> about:home FF NewTab: Actia\diagnostic2.3.4.3\Profiles\z65r9t70.default -> about:newtab FF ProfilePath: C:\Users\diagnostique\AppData\Roaming\Actia\diagnostic2.3.30.0\Profiles\6hzd6a4i.default [2017-10-31] FF Homepage: Actia\diagnostic2.3.30.0\Profiles\6hzd6a4i.default -> about:home FF NewTab: Actia\diagnostic2.3.30.0\Profiles\6hzd6a4i.default -> about:newtab FF ProfilePath: C:\Users\diagnostique\AppData\Roaming\Actia\diagnostic2.16.3.0\Profiles\xcqntz9s.default [2019-01-11] FF Homepage: Actia\diagnostic2.16.3.0\Profiles\xcqntz9s.default -> about:home FF NewTab: Actia\diagnostic2.16.3.0\Profiles\xcqntz9s.default -> about:newtab FF ProfilePath: C:\Users\diagnostique\AppData\Roaming\Actia\diagnostic2.16.2.0\Profiles\pttbagee.default [2017-10-31] FF Homepage: Actia\diagnostic2.16.2.0\Profiles\pttbagee.default -> about:home FF NewTab: Actia\diagnostic2.16.2.0\Profiles\pttbagee.default -> about:newtab FF ProfilePath: C:\Users\diagnostique\AppData\Roaming\Actia\diagnostic2.15.2.0\Profiles\uxlj0e7v.default [2017-10-31] FF Homepage: Actia\diagnostic2.15.2.0\Profiles\uxlj0e7v.default -> about:home FF NewTab: Actia\diagnostic2.15.2.0\Profiles\uxlj0e7v.default -> about:newtab FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2018-10-19] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-11-26] () FF Plugin: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-11-14] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-11-14] (Oracle Corporation) FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-03-15] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-01-15] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-01-15] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2018-12-19] (Adobe Systems Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-19] (Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-01-23] (Adobe Systems) FF ExtraCheck: C:\Program Files\mozilla firefox\browser\defaults\preferences\firefox.js [2017-05-23] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.fr/ CHR Profile: C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default [2019-01-18] CHR Extension: (Docs) - C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-11] CHR Extension: (Google Drive) - C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-11-11] CHR Extension: (YouTube) - C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-11-11] CHR Extension: (Adobe Acrobat) - C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-11-11] CHR Extension: (Google Docs hors connexion) - C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-11-11] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-11-11] CHR Extension: (Gmail) - C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-11-11] CHR Extension: (Chrome Media Router) - C:\Users\diagnostique\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-11] CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AGMService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGMService.exe [2917864 2018-12-13] (Adobe Systems, Incorporated) R2 AGSService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2709480 2018-12-13] (Adobe Systems, Incorporated) R2 AtherosSvc; C:\Program Files\Bluetooth Suite\adminservice.exe [281568 2017-01-18] (Windows (R) Win 7 DDK provider) R3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [Fichier non signé] S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [279160 2017-01-24] (Intel Corporation) R3 Disc Soft Bus Service; C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe [2216208 2014-11-24] (Disc Soft Ltd) R2 EaseUS Agent; C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe [39616 2016-12-06] (CHENGDU YIWO Tech Development Co., Ltd) R2 FirebirdGuardianDefaultInstance; C:\APP\firebird\bin\fbguard.exe [65536 2008-07-03] (The Firebird Project) [Fichier non signé] R3 FirebirdServerDefaultInstance; C:\APP\firebird\bin\fbserver.exe [1527893 2008-07-03] (The Firebird Project) [Fichier non signé] R2 ftspssrv; C:\Windows\system32\ftspssrv.exe [708608 2011-03-11] (FabulaTech) [Fichier non signé] R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [291448 2017-01-24] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [728360 2016-02-19] (Intel(R) Corporation) R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [209184 2016-05-25] (Intel Corporation) S3 LcSvrAdm; C:\ElsaWin\bin\LcSvrAdm.exe [327679 2015-10-23] (Volkswagen AG) [Fichier non signé] S3 LcSvrAuf; C:\ElsaWin\bin\LcSvrAuf.exe [1417579 2015-10-23] (Volkswagen AG) [Fichier non signé] R2 LcSvrDba; C:\ElsaWin\bin\LcSvrDba.exe [435712 2015-10-23] (Volkswagen AG) [Fichier non signé] R2 LcSvrHis; C:\ElsaWin\bin\LcSvrHis.exe [387072 2015-10-23] (Volkswagen AG) [Fichier non signé] R2 LcSvrPAS; C:\ElsaWin\bin\LcSvrPas.exe [519680 2015-10-23] (Volkswagen AG) [Fichier non signé] S3 LcSvrSaz; C:\ElsaWin\bin\LcSvrSaz.exe [503735 2015-10-23] (Volkswagen AG) [Fichier non signé] S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4563920 2017-11-01] (Malwarebytes) R2 MSSQL$ELSAWINDB; C:\Program Files\Microsoft SQL Server\MSSQL10_50.ELSAWINDB\MSSQL\Binn\sqlservr.exe [43129288 2012-06-29] (Microsoft Corporation) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [467016 2018-02-24] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [467016 2018-02-24] (NVIDIA Corporation) S4 SQLAgent$ELSAWINDB; C:\Program Files\Microsoft SQL Server\MSSQL10_50.ELSAWINDB\MSSQL\Binn\SQLAGENT.EXE [379848 2012-06-29] (Microsoft Corporation) R2 TunnelBearMaintenance; C:\Program Files\TunnelBear\TunnelBear.Maintenance.exe [37248 2017-09-06] () R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2015-08-27] (Microsoft Corporation) R2 WindscribeService; C:\Program Files\Windscribe\WindscribeService.exe [401072 2018-09-07] (Windscribe Limited) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [X] ===================== Pilotes (Avec liste blanche) ====================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 ampa; C:\Windows\system32\ampa.sys [35760 2016-12-25] () R3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [80680 2017-01-18] (Qualcomm Atheros) R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3376904 2017-08-29] (Qualcomm Atheros Communications, Inc.) S3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [78848 2015-07-15] (Advanced Micro Devices) [Fichier non signé] R3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [295160 2017-01-18] (Qualcomm Atheros) R3 btath_avdt; C:\Windows\System32\drivers\btath_avdt.sys [104696 2017-01-18] (Qualcomm Atheros) R0 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [28456 2015-01-04] (Qualcomm Atheros) R3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [158688 2017-01-18] (Qualcomm Atheros) R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [66448 2017-01-18] (Qualcomm Atheros) R3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [120616 2017-01-18] (Qualcomm Atheros) R3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [518632 2017-01-18] (Qualcomm) R3 dtscsibus; C:\Windows\System32\DRIVERS\dtscsibus.sys [25000 2016-01-27] (Disc Soft Ltd) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [24232 2009-02-17] (Elaborate Bytes AG) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [329032 2013-05-09] (ELAN Microelectronics Corp.) R0 EUBAKUP; C:\Windows\System32\drivers\eubakup.sys [56824 2016-12-06] (CHENGDU YIWO Tech Development Co., Ltd) R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [46584 2016-12-06] () R1 EUDSKACS; C:\Windows\system32\drivers\eudskacs.sys [20984 2016-12-06] (CHENGDU YIWO Tech Development Co., Ltd) R1 EUFDDISK; C:\Windows\system32\drivers\EuFdDisk.sys [195576 2016-12-06] (CHENGDU YIWO Tech Development Co., Ltd) S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [53184 2007-06-27] (FTDI Ltd.) R3 ftvspenum; C:\Windows\System32\DRIVERS\ftvspenum.sys [36856 2011-01-12] (FabulaTech) S3 ftvsport; C:\Windows\system32\drivers\ftvsport.sys [45560 2011-01-12] (FabulaTech) S3 GemCCID; C:\Windows\System32\DRIVERS\GemCCID.sys [105456 2016-10-17] (Gemalto) R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [17472 2017-09-09] (Glarysoft Ltd) R2 Hardlock; C:\Windows\system32\drivers\hardlock.sys [693760 2006-11-22] (Aladdin Knowledge Systems Ltd.) R0 iaStorA; C:\Windows\System32\DRIVERS\iaStorA.sys [1991680 2015-11-12] (Intel Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28128 2015-11-12] (Intel Corporation) R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [28688 2017-04-11] (Intel Corporation) R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [411664 2017-04-11] (Intel Corporation) R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [839696 2017-04-11] (Intel Corporation) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [110280 2013-07-16] (Qualcomm Atheros Co., Ltd.) R3 MEI; C:\Windows\System32\DRIVERS\TeeDriver.sys [157752 2016-03-28] (Intel Corporation) R3 msloop; C:\Windows\System32\DRIVERS\loop.sys [5632 2009-07-14] (Microsoft Corporation) R2 NSHE; C:\Windows\system32\Drivers\NSHE.SYS [97792 2010-07-28] (Tecar Forum) [Fichier non signé] R0 nvpciflt; C:\Windows\System32\DRIVERS\nvpciflt.sys [44120 2018-02-25] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27720 2018-02-24] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [53616 2018-02-24] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [50112 2017-12-16] (NVIDIA Corporation) S4 RsFx0153; C:\Windows\System32\DRIVERS\RsFx0153.sys [249288 2012-06-29] (Microsoft Corporation) S3 RT-USB; C:\Windows\System32\drivers\RT-USB.SYS [59464 2010-06-17] (Ross-Tech LLC) S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [801896 2013-03-13] (Realtek Semiconductor Corporation ) R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2014-05-07] (Samsung Electronics) [Fichier non signé] R3 tap-tb-0901; C:\Windows\System32\DRIVERS\tap-tb-0901.sys [33280 2017-09-06] (The OpenVPN Project) R3 tapwindscribe0901; C:\Windows\System32\DRIVERS\tapwindscribe0901.sys [41976 2018-07-13] (The OpenVPN Project) S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X] S2 npf; \??\C:\Windows\system32\drivers\npf.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2019-01-30 09:22 - 2019-01-30 09:23 - 000026788 _____ C:\Users\diagnostique\Desktop\FRST.txt 2019-01-30 09:22 - 2019-01-30 09:22 - 001787904 _____ (Farbar) C:\Users\diagnostique\Desktop\FRST.exe 2019-01-30 09:22 - 2019-01-30 09:22 - 000000000 ____D C:\FRST 2019-01-30 09:18 - 2019-01-30 09:18 - 000000000 ___RD C:\Users\diagnostique\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2019-01-29 20:35 - 2019-01-29 20:35 - 000004143 _____ C:\Users\diagnostique\Desktop\AdwCleaner[C00].txt 2019-01-29 20:32 - 2019-01-29 20:52 - 000000116 _____ C:\Users\diagnostique\Desktop\Nouveau document texte.txt 2019-01-29 20:29 - 2019-01-29 20:31 - 000009044 _____ C:\Users\diagnostique\Desktop\ZHPCleaner.txt 2019-01-29 20:21 - 2019-01-29 20:21 - 000000844 _____ C:\Users\diagnostique\Desktop\ZHPCleaner.lnk 2019-01-29 20:16 - 2019-01-29 20:16 - 007320272 _____ (Malwarebytes) C:\Users\diagnostique\Desktop\adwcleaner_7.2.6.0.exe 2019-01-29 12:08 - 2019-01-29 20:41 - 000427683 _____ C:\Users\diagnostique\Desktop\ZHPDiag.txt 2019-01-29 12:05 - 2019-01-29 20:21 - 000000000 ____D C:\Users\diagnostique\AppData\Local\ZHP 2019-01-29 12:05 - 2019-01-29 12:05 - 000000834 _____ C:\Users\diagnostique\Desktop\ZHPDiag.lnk 2019-01-29 12:03 - 2019-01-29 20:35 - 000000000 ____D C:\Program Files\Windscribe 2019-01-29 12:03 - 2019-01-29 12:03 - 000001029 _____ C:\Users\Public\Desktop\Windscribe.lnk 2019-01-29 12:03 - 2019-01-29 12:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windscribe 2019-01-24 11:03 - 2019-01-24 11:03 - 000001227 _____ C:\Users\diagnostique\Desktop\Should I Remove It.lnk 2019-01-24 11:03 - 2019-01-24 11:03 - 000000000 __SHD C:\Windows\system32\AI_RecycleBin 2019-01-24 11:03 - 2019-01-24 11:03 - 000000000 ____D C:\Users\diagnostique\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Should I Remove It 2019-01-24 11:03 - 2019-01-24 11:03 - 000000000 ____D C:\Program Files\Reason 2019-01-24 11:01 - 2019-01-24 11:01 - 002178872 _____ (Reason Software Company Inc.) C:\Users\diagnostique\Desktop\should-i-remove-it_1-0-4-36591_fr_431721.exe 2019-01-24 10:43 - 2019-01-24 10:52 - 000000000 ____D C:\Program Files\HD Tune Pro 2019-01-24 10:42 - 2019-01-24 10:42 - 002246436 _____ (EFD Software ) C:\Users\diagnostique\Desktop\hdtunepro_570_trial.exe 2019-01-23 19:46 - 2019-01-23 19:46 - 000000601 _____ C:\Users\diagnostique\Desktop\ZHPFixReport.txt 2019-01-23 19:45 - 2019-01-29 20:41 - 000000000 ____D C:\Users\diagnostique\AppData\Roaming\ZHP 2019-01-23 19:45 - 2019-01-23 19:45 - 000000000 ____D C:\Users\diagnostique\Desktop\Quarantine 2019-01-23 19:43 - 2019-01-23 19:44 - 003061760 _____ (Nicolas Coolman) C:\Users\diagnostique\Desktop\ZHPFix.exe 2019-01-23 19:27 - 2019-01-23 19:27 - 000016530 _____ C:\Users\diagnostique\Desktop\cc_20190123_192702.reg 2019-01-18 20:58 - 2018-03-12 11:10 - 000000000 ____D C:\Rheingold 2019-01-18 20:55 - 2019-01-18 20:55 - 000001641 _____ C:\Users\Public\Desktop\ifhsrv32.lnk 2019-01-18 20:48 - 2017-04-27 23:50 - 003550208 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2019-01-18 20:40 - 2019-01-18 20:41 - 007419351 _____ C:\Users\diagnostique\Downloads\INSTALLATION GUIDE.pdf 2019-01-18 20:15 - 2015-11-19 15:06 - 000922432 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2019-01-18 20:15 - 2015-11-19 15:06 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2019-01-15 22:36 - 2018-03-19 18:45 - 000213757 _____ C:\Users\diagnostique\Desktop\ISTA-D 4.10.20.torrent 2019-01-15 22:22 - 2019-01-15 22:22 - 000000000 ____D C:\Users\diagnostique\AppData\Local\Windscribe 2019-01-15 22:21 - 2019-01-15 22:21 - 016895064 _____ (Windscribe Limited ) C:\Users\diagnostique\Downloads\Windscribe.exe 2019-01-15 22:21 - 2018-07-13 17:12 - 000041976 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tapwindscribe0901.sys 2019-01-15 21:45 - 2019-01-24 10:42 - 000000016 _____ C:\Windows\system32\dmlconf.dat 2019-01-15 21:43 - 2019-01-18 20:55 - 000000000 ____D C:\EDIABAS 2019-01-15 21:43 - 2019-01-15 21:43 - 000062842 _____ C:\Windows\unins000.dat 2019-01-15 21:43 - 2019-01-15 21:43 - 000001640 _____ C:\Users\Public\Desktop\INPA.lnk 2019-01-15 21:43 - 2019-01-15 21:43 - 000001620 _____ C:\Users\Public\Desktop\WinKFP.lnk 2019-01-15 21:43 - 2019-01-15 21:43 - 000001542 _____ C:\Users\Public\Desktop\NCS-Expert tool.lnk 2019-01-15 21:43 - 2019-01-15 21:43 - 000001515 _____ C:\Users\Public\Desktop\Tool32.lnk 2019-01-15 21:43 - 2019-01-15 21:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BMW Standard Tools 2019-01-15 21:43 - 2019-01-15 21:43 - 000000000 ____D C:\NFS-Backup 2019-01-15 21:43 - 2019-01-15 21:43 - 000000000 ____D C:\NCSEXPER 2019-01-15 21:43 - 2019-01-15 21:43 - 000000000 ____D C:\Entwicklungsdaten 2019-01-15 21:43 - 2019-01-15 21:43 - 000000000 ____D C:\EC-APPS 2019-01-15 21:43 - 2019-01-15 21:24 - 000630217 _____ () C:\Windows\unins000.exe 2019-01-15 21:19 - 2019-01-15 21:19 - 000000000 ____D C:\INPA_EA-90X 2019-01-15 21:15 - 2019-01-15 12:21 - 536126136 _____ C:\INPA_EA-90X.rar 2019-01-15 11:43 - 2019-01-15 11:43 - 000000000 _____ C:\Users\diagnostique\AppData\Local\{B77A0348-DB6D-4E79-8938-0C6542E2F861} ==================== Un mois (modifiés) ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2019-01-30 09:18 - 2017-02-26 23:11 - 000000000 ____D C:\Users\diagnostique\AppData\Local\CrashDumps 2019-01-30 09:18 - 2017-02-26 23:07 - 000000000 ____D C:\ProgramData\NVIDIA 2019-01-30 09:18 - 2017-02-26 23:00 - 000000000 __SHD C:\Users\diagnostique\IntelGraphicsProfiles 2019-01-30 09:18 - 2016-11-19 11:25 - 000000000 ____D C:\Users\diagnostique\AppData\LocalLow\Mozilla 2019-01-30 09:18 - 2009-07-14 05:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-01-29 22:59 - 2011-04-12 02:35 - 000814108 _____ C:\Windows\system32\perfh00C.dat 2019-01-29 22:59 - 2011-04-12 02:35 - 000175108 _____ C:\Windows\system32\perfc00C.dat 2019-01-29 22:59 - 2010-11-20 22:01 - 001855548 _____ C:\Windows\system32\PerfStringBackup.INI 2019-01-29 22:59 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\inf 2019-01-29 20:49 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\system32\NDF 2019-01-29 20:44 - 2009-07-14 05:34 - 000038976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2019-01-29 20:44 - 2009-07-14 05:34 - 000038976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2019-01-29 20:33 - 2017-05-29 01:12 - 000000000 ____D C:\AdwCleaner 2019-01-24 11:09 - 2017-03-24 14:45 - 000000000 ____D C:\found.001 2019-01-24 11:09 - 2017-02-04 23:45 - 000000000 ____D C:\found.000 2019-01-24 10:52 - 2017-01-19 01:19 - 000000000 ____D C:\Windows\system32\appmgmt 2019-01-24 10:46 - 2009-07-14 05:53 - 000032482 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2019-01-23 20:06 - 2017-02-27 20:41 - 000000290 __RSH C:\ProgramData\ntuser.pol 2019-01-18 22:45 - 2016-02-21 23:08 - 000000000 ____D C:\Users\diagnostique\Desktop\Diagbox 2019-01-18 22:41 - 2016-06-25 22:34 - 000000000 ____D C:\Users\diagnostique\AppData\Roaming\vlc 2019-01-18 20:26 - 2017-02-26 23:19 - 000000000 ____D C:\Users\diagnostique\Documents\Bluetooth Folder 2019-01-18 20:15 - 2016-01-26 22:34 - 000000000 ____D C:\ProgramData\Package Cache 2019-01-18 19:13 - 2017-11-12 21:34 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service 2019-01-18 19:13 - 2016-11-14 22:49 - 000000000 ____D C:\Program Files\Mozilla Firefox 2019-01-16 13:27 - 2016-02-14 10:42 - 000000000 ____D C:\Users\diagnostique\AppData\Roaming\uTorrent 2019-01-15 23:00 - 2017-11-19 15:22 - 000000000 ____D C:\Program Files\TunnelBear 2019-01-15 22:01 - 2017-06-20 23:47 - 000002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk 2019-01-15 22:01 - 2017-06-20 23:47 - 000002007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk 2019-01-15 12:13 - 2016-11-16 09:23 - 000000000 ____D C:\Users\diagnostique\AppData\Local\ElevatedDiagnostics 2019-01-15 11:58 - 2018-10-23 11:33 - 000002017 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2019-01-15 11:58 - 2017-04-12 13:06 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2019-01-15 11:47 - 2017-09-05 22:59 - 000002168 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-01-11 14:33 - 2017-02-27 04:41 - 000000000 ____D C:\ProgramData\firebird ==================== Fichiers à la racine de certains dossiers ======= 2005-12-09 03:57 - 2005-12-09 03:57 - 000000060 ____R () C:\Program Files\BRINST.INI 2017-10-31 00:00 - 2017-11-15 00:00 - 000000140 _____ () C:\Users\diagnostique\AppData\Roaming\WB.CFG 2017-05-23 16:54 - 2017-05-23 16:54 - 000140800 _____ () C:\Users\diagnostique\AppData\Local\installer.dat 2018-10-30 12:39 - 2018-10-30 12:39 - 000000000 _____ () C:\Users\diagnostique\AppData\Local\oobelibMkey.log 2016-06-19 13:40 - 2016-06-19 13:40 - 000000017 _____ () C:\Users\diagnostique\AppData\Local\resmon.resmoncfg 2017-05-23 16:55 - 2017-05-23 16:54 - 004031352 _____ (TODO: ) C:\Users\diagnostique\AppData\Local\Stocklax.exe 2018-12-10 16:32 - 2018-12-10 16:32 - 000000000 _____ () C:\Users\diagnostique\AppData\Local\{7BCD3E71-4816-4D9E-8BB1-1058492D1A70} 2019-01-15 11:43 - 2019-01-15 11:43 - 000000000 _____ () C:\Users\diagnostique\AppData\Local\{B77A0348-DB6D-4E79-8938-0C6542E2F861} Fichiers à déplacer ou supprimer: ==================== C:\Windows\Tasks\{4C21CE45-1A6A-2A54-7AC6-2A55A5338CF5}.job Certains fichiers dans TEMP: ==================== 2019-01-18 20:55 - 2019-01-18 20:55 - 000652814 _____ (Igor Pavlov) C:\Users\diagnostique\AppData\Local\Temp\7za.exe ==================== Bamital & volsnap ====================== (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\dllhost.exe => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2019-01-24 13:49 ==================== Fin de FRST.txt ============================