Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 26-12-2019 Exécuté par evadr (administrateur) sur DESKTOP-75CHB92 (LENOVO 80FF) (27-12-2019 06:56:47) Exécuté depuis C:\Users\evadr\Downloads Profils chargés: evadr (Profils disponibles: evadr) Platform: Windows 10 Home Version 1909 18363.535 (X64) Langue: Français (France) Navigateur par défaut: Edge Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Fortemedia Inc -> ) C:\Program Files\CONEXANT\ForteConfig\fmapp.exe (Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe (Microsoft Corporation -> Microsoft Corporation) C:\Users\evadr\AppData\Local\Microsoft\OneDrive\19.192.0926.0012\FileCoAuth.exe (Microsoft Corporation -> Microsoft Corporation) C:\Users\evadr\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windows.photos_2019.19081.22010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1911.3-0\NisSrv.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Realtek Semiconductor Corp -> Realtek semiconductor) C:\Windows\RTFTrack.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] (Fortemedia Inc -> ) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc. -> Conexant Systems, Inc.) HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc. -> Conexant Systems, Inc.) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5060864 2015-06-16] (Realtek Semiconductor Corp -> Realtek semiconductor) ==================== Tâches planifiées (Avec liste blanche) ============ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {47DD7B39-32AB-4910-9A4E-57BFC82155F7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-26] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {804B1776-13AC-41FD-B576-C7A2CBCD7728} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-26] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {81AA37E6-0CA4-4F60-98B9-8F0E7C39BA2B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-26] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {C2318EB0-E92F-4086-8E7E-F6F2E699F3A3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MpCmdRun.exe [469648 2019-12-26] (Microsoft Windows Publisher -> Microsoft Corporation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{ac1ab334-3117-4fad-a63e-1d8208957698}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{fc2ef2ee-706e-47fd-8cb6-e9ecd98b0609}: [DhcpNameServer] 192.168.1.254 Internet Explorer: ================== Edge: ====== DownloadDir: C:\Users\evadr\Downloads Edge Notifications: HKU\S-1-5-21-2404277095-3081344691-2001385833-1001 -> hxxps://www.daemon-tools.cc FireFox: ======== FF DefaultProfile: s0vfowsa.default FF ProfilePath: C:\Users\evadr\AppData\Roaming\Mozilla\Firefox\Profiles\s0vfowsa.default [2019-12-26] FF ProfilePath: C:\Users\evadr\AppData\Roaming\Mozilla\Firefox\Profiles\ibp7ndhn.default-release [2019-12-27] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [529904 2019-01-17] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [355872 2019-03-19] (Intel(R) pGFX -> Intel Corporation) R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [267328 2017-05-16] (Synaptics Incorporated -> Synaptics Incorporated) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-26] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-26] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2019-03-09] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2019-03-09] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 dtultrascsibus; C:\WINDOWS\System32\drivers\dtultrascsibus.sys [42256 2019-12-25] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 dtultrausbbus; C:\WINDOWS\System32\drivers\dtultrausbbus.sys [59344 2019-12-25] (AVB Disc Soft, SIA -> Disc Soft Ltd) R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [239608 2019-01-17] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [1093248 2019-06-06] (Kaspersky Lab -> AO Kaspersky Lab) R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3587232 2018-12-07] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek Semiconductor Corp -> Realtek ) R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [441280 2018-10-16] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation) R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) S3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions) S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2017-05-18] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45664 2019-12-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [355760 2019-12-26] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-26] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) =================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2019-12-27 06:56 - 2019-12-27 06:57 - 000010584 _____ C:\Users\evadr\Downloads\FRST.txt 2019-12-27 06:56 - 2019-12-27 06:57 - 000000000 ____D C:\FRST 2019-12-27 06:55 - 2019-12-27 06:55 - 002272256 _____ (Farbar) C:\Users\evadr\Downloads\FRST64.exe 2019-12-26 21:15 - 2019-12-26 21:21 - 000000000 ____D C:\Users\evadr\AppData\Roaming\ZHP 2019-12-26 21:15 - 2019-12-26 21:15 - 003252608 _____ (Nicolas Coolman) C:\Users\evadr\Downloads\ZHPDiag3.exe 2019-12-26 21:15 - 2019-12-26 21:15 - 000000000 ____D C:\Users\evadr\AppData\Local\ZHP 2019-12-26 21:14 - 2019-12-26 21:15 - 000000000 ____D C:\Users\evadr\AppData\Local\PackageStaging 2019-12-26 21:12 - 2019-12-26 21:12 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2019-12-26 21:12 - 2019-12-26 21:12 - 000000999 _____ C:\ProgramData\Bureau\Firefox.lnk 2019-12-26 21:11 - 2019-12-26 21:11 - 000319920 _____ (Mozilla) C:\Users\evadr\Downloads\Firefox Installer (1).exe 2019-12-26 21:09 - 2019-12-26 21:09 - 000000000 ___HD C:\OneDriveTemp 2019-12-26 20:50 - 2019-12-26 20:50 - 000748816 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2019-12-26 19:28 - 2019-12-26 19:28 - 000000000 ____D C:\Users\evadr\OneDrive\Documents\PCSX2 2019-12-26 19:24 - 2019-12-26 19:24 - 007301293 _____ C:\Users\evadr\Downloads\ps2 bios pack.zip 2019-12-26 19:19 - 2019-12-26 19:19 - 002487397 _____ C:\Users\evadr\Downloads\Bios_PS2_NTSC_SCPH_39001_8202.zip 2019-12-26 19:15 - 2019-12-26 20:35 - 000000000 ____D C:\Program Files (x86)\PCSX2 1.4.0 2019-12-26 19:15 - 2019-12-26 19:18 - 000000000 ____D C:\WINDOWS\SysWOW64\directx 2019-12-26 19:15 - 2019-12-26 19:17 - 000000000 ___HD C:\WINDOWS\msdownld.tmp 2019-12-26 19:15 - 2019-12-26 19:15 - 000000000 ____D C:\ProgramData\Package Cache 2019-12-26 19:07 - 2019-12-26 20:10 - 000007601 _____ C:\Users\evadr\AppData\Local\Resmon.ResmonCfg 2019-12-26 19:06 - 2019-12-26 21:12 - 000000000 ____D C:\Program Files\Mozilla Firefox 2019-12-26 19:06 - 2019-12-26 21:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2019-12-26 19:06 - 2019-12-26 19:06 - 000000000 ____D C:\Users\evadr\AppData\Roaming\Mozilla 2019-12-26 19:06 - 2019-12-26 19:06 - 000000000 ____D C:\Users\evadr\AppData\Local\Mozilla 2019-12-26 19:06 - 2019-12-26 19:06 - 000000000 ____D C:\ProgramData\Mozilla 2019-12-26 17:57 - 2019-12-26 20:35 - 000000000 ____D C:\Program Files (x86)\Dead Island Definitive Edition 2019-12-26 17:48 - 2019-12-26 17:50 - 000000000 ____D C:\WINDOWS\system32\MRT 2019-12-26 17:16 - 2019-12-26 17:16 - 000416529 _____ C:\Users\evadr\Downloads\msvcr100.zip 2019-12-26 15:56 - 2019-12-26 20:35 - 000000000 ____D C:\Users\evadr\Downloads\Dead.Island.Definitive.Edition-CODEX 2019-12-26 15:55 - 2019-12-26 15:56 - 000000000 ____D C:\Users\evadr\AppData\Local\BitTorrentHelper 2019-12-26 15:55 - 2019-12-26 15:55 - 000000000 ____D C:\Users\evadr\AppData\LocalLow\uTorrent 2019-12-26 15:49 - 2019-12-26 17:20 - 000000000 ____D C:\Users\evadr\AppData\Local\Opera Software 2019-12-26 15:47 - 2019-12-26 20:35 - 000000000 ____D C:\Users\evadr\AppData\Roaming\uTorrent 2019-12-26 15:47 - 2019-12-26 17:20 - 000000000 ____D C:\Users\evadr\AppData\Roaming\Opera Software 2019-12-26 14:55 - 2019-12-26 20:35 - 000000000 ____D C:\ProgramData\RogueKiller 2019-12-26 14:55 - 2019-12-26 20:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\rogue killer 2019-12-26 14:54 - 2019-12-26 20:35 - 000000000 ____D C:\Program Files\RogueKiller 2019-12-26 14:46 - 2019-12-26 14:46 - 000000000 ____D C:\Users\evadr\AppData\Local\cache 2019-12-26 14:45 - 2019-12-26 14:45 - 000000000 ____D C:\Users\evadr\AppData\Local\mbamtray 2019-12-26 14:45 - 2019-12-26 14:45 - 000000000 ____D C:\Users\evadr\AppData\Local\mbam 2019-12-26 14:44 - 2019-12-26 14:44 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-12-26 14:43 - 2019-12-26 14:43 - 000000000 ____D C:\Program Files\Malwarebytes 2019-12-26 14:25 - 2019-12-26 20:35 - 000000000 ____D C:\ProgramData\HitmanPro 2019-12-26 12:23 - 2019-12-26 12:23 - 000000000 ____D C:\Users\evadr\AppData\Local\Comms 2019-12-26 11:50 - 2019-12-26 23:09 - 000000000 ____D C:\Users\evadr\AppData\Local\PlaceholderTileLogoFolder 2019-12-26 11:43 - 2019-12-26 11:44 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2404277095-3081344691-2001385833-1001 2019-12-26 11:40 - 2019-12-26 11:48 - 000000000 ____D C:\Users\evadr\AppData\Local\MicrosoftEdge 2019-12-26 11:40 - 2019-12-26 11:40 - 000000000 ____D C:\ProgramData\Microsoft OneDrive 2019-12-26 11:39 - 2019-12-26 11:39 - 000000000 ____D C:\Users\evadr\AppData\Local\Publishers 2019-12-26 11:38 - 2019-12-26 14:38 - 000000000 ____D C:\Users\evadr\AppData\Local\Packages 2019-12-26 11:38 - 2019-12-26 14:38 - 000000000 ____D C:\ProgramData\Packages 2019-12-26 11:38 - 2019-12-26 11:38 - 000000000 ____D C:\Users\evadr\AppData\Roaming\Adobe 2019-12-26 11:38 - 2019-12-26 11:38 - 000000000 ____D C:\Users\evadr\AppData\Local\VirtualStore 2019-12-26 11:37 - 2019-12-26 11:38 - 000000000 ____D C:\Users\evadr\AppData\Local\ConnectedDevicesPlatform 2019-12-26 11:37 - 2019-12-26 11:37 - 000000020 ___SH C:\Users\evadr\ntuser.ini 2019-12-26 11:27 - 2019-12-26 20:46 - 001771406 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-12-26 11:23 - 2019-12-26 11:23 - 000000000 _SHDL C:\Users\Default\AppData\Local\Historique 2019-12-26 11:23 - 2019-12-26 11:23 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Historique 2019-12-26 11:23 - 2019-12-26 11:23 - 000000000 _SHDL C:\Users\Default User 2019-12-26 11:23 - 2019-12-26 11:23 - 000000000 _SHDL C:\Users\All Users 2019-12-26 11:23 - 2019-12-26 11:23 - 000000000 _SHDL C:\ProgramData\Modèles 2019-12-26 11:23 - 2019-12-26 11:23 - 000000000 _SHDL C:\ProgramData\Menu Démarrer 2019-12-26 11:23 - 2019-12-26 11:23 - 000000000 _SHDL C:\ProgramData\Bureau 2019-12-26 11:23 - 2019-12-26 11:23 - 000000000 _SHDL C:\Program Files\Fichiers communs 2019-12-26 11:22 - 2019-12-26 20:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-12-26 11:22 - 2019-12-26 13:40 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2019-12-26 11:16 - 2019-12-26 21:08 - 000000000 ____D C:\Users\evadr 2019-12-26 11:16 - 2019-12-26 11:44 - 000002411 _____ C:\Users\evadr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2019-12-26 11:16 - 2019-12-26 11:16 - 000000000 _SHDL C:\Users\evadr\Voisinage réseau 2019-12-26 11:16 - 2019-12-26 11:16 - 000000000 _SHDL C:\Users\evadr\Voisinage d'impression 2019-12-26 11:16 - 2019-12-26 11:16 - 000000000 _SHDL C:\Users\evadr\Modèles 2019-12-26 11:16 - 2019-12-26 11:16 - 000000000 _SHDL C:\Users\evadr\Mes documents 2019-12-26 11:16 - 2019-12-26 11:16 - 000000000 _SHDL C:\Users\evadr\Menu Démarrer 2019-12-26 11:16 - 2019-12-26 11:16 - 000000000 _SHDL C:\Users\evadr\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes 2019-12-26 11:16 - 2019-12-26 11:16 - 000000000 _SHDL C:\Users\evadr\AppData\Local\Historique 2019-12-26 11:10 - 2019-12-26 11:10 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf 2019-12-26 11:10 - 2019-12-26 11:10 - 000000000 ____D C:\WINDOWS\Cnxt 2019-12-26 11:08 - 2019-12-26 11:08 - 000000000 ____D C:\Program Files\Dolby Digital Plus 2019-12-26 11:08 - 2014-12-09 20:11 - 000423128 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe 2019-12-26 11:08 - 2014-10-20 14:54 - 000207576 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe 2019-12-26 11:08 - 2013-10-15 14:49 - 000002440 _____ C:\WINDOWS\system32\Drivers\SamSfPa.dat 2019-12-26 11:07 - 2019-12-26 11:07 - 001701376 _____ (TODO: ) C:\WINDOWS\SysWOW64\RebootPrompt.exe 2019-12-26 11:07 - 2019-12-26 11:07 - 000000000 ____H C:\ProgramData\DP45977C.lfl 2019-12-26 11:06 - 2019-12-26 21:08 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2019-12-26 11:06 - 2019-12-26 11:08 - 000000000 ____D C:\ProgramData\Conexant 2019-12-26 11:06 - 2019-12-26 11:08 - 000000000 ____D C:\Program Files\CONEXANT 2019-12-26 11:06 - 2019-12-26 11:06 - 000000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat 2019-12-26 11:06 - 2019-12-26 11:06 - 000000000 ____D C:\Program Files\Intel 2019-12-26 11:06 - 2019-12-26 11:06 - 000000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin 2019-12-26 11:06 - 2019-06-17 21:36 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2019-12-26 11:06 - 2019-03-19 02:31 - 000095328 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL 2019-12-26 11:06 - 2019-03-19 02:31 - 000091232 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL 2019-12-26 11:01 - 2019-12-26 23:37 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-12-26 11:01 - 2019-12-26 11:18 - 000258768 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-12-26 10:11 - 2019-12-26 00:00 - 000000000 ___HD C:\$SysReset 2019-12-25 23:58 - 2019-12-26 11:32 - 000000000 ____D C:\Windows.old 2019-12-25 23:57 - 2019-12-25 23:58 - 000000000 ____D C:\WINDOWS\ServiceProfiles 2019-12-25 23:57 - 2019-12-25 23:57 - 000000000 ____D C:\WINDOWS\SysWOW64\sda 2019-12-25 23:55 - 2019-12-25 23:55 - 000000000 ____D C:\Program Files\Synaptics 2019-12-25 23:54 - 2019-12-25 23:54 - 000008192 _____ C:\WINDOWS\system32\config\userdiff 2019-12-25 23:53 - 2019-12-25 23:53 - 000000000 ____D C:\WINDOWS\Setup 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\system32\OpenSSH 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\OCR 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\Program Files\Reference Assemblies 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\Program Files\MSBuild 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies 2019-12-25 23:52 - 2019-12-25 23:52 - 000000000 ____D C:\Program Files (x86)\MSBuild 2019-12-25 23:51 - 2019-12-26 20:46 - 000793010 _____ C:\WINDOWS\system32\perfh00C.dat 2019-12-25 23:51 - 2019-12-26 20:46 - 000150042 _____ C:\WINDOWS\system32\perfc00C.dat 2019-12-25 23:51 - 2019-12-25 23:51 - 000351124 _____ C:\WINDOWS\system32\perfi00C.dat 2019-12-25 23:51 - 2019-12-25 23:51 - 000040694 _____ C:\WINDOWS\system32\perfd00C.dat 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\fr 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\0409 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\winrm 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\WCN 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\slmgr 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\fr 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\0409 2019-12-25 23:51 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\DigitalLocker 2019-12-25 23:49 - 2019-09-03 15:56 - 000835480 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2019-12-25 23:49 - 2019-09-03 15:56 - 000179816 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2019-12-25 23:46 - 2019-12-27 06:53 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-12-25 23:46 - 2019-12-27 03:49 - 000000000 ____D C:\WINDOWS\appcompat 2019-12-25 23:46 - 2019-12-26 23:15 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-12-25 23:46 - 2019-12-26 23:09 - 000000000 ___HD C:\Program Files\WindowsApps 2019-12-25 23:46 - 2019-12-26 20:39 - 000000000 ____D C:\WINDOWS\system32\config\TxR 2019-12-25 23:46 - 2019-12-26 20:35 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2019-12-25 23:46 - 2019-12-26 20:23 - 000000000 ____D C:\WINDOWS\ServiceState 2019-12-25 23:46 - 2019-12-26 20:23 - 000000000 ____D C:\WINDOWS\registration 2019-12-25 23:46 - 2019-12-26 19:07 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2019-12-25 23:46 - 2019-12-26 13:40 - 000000000 ____D C:\Program Files\Windows Defender 2019-12-25 23:46 - 2019-12-26 11:33 - 000000000 ____D C:\WINDOWS\system32\spool 2019-12-25 23:46 - 2019-12-26 11:33 - 000000000 ____D C:\WINDOWS\system32\FxsTmp 2019-12-25 23:46 - 2019-12-26 11:33 - 000000000 ____D C:\ProgramData\USOPrivate 2019-12-25 23:46 - 2019-12-26 11:23 - 000000000 ____D C:\Program Files\Windows NT 2019-12-25 23:46 - 2019-12-26 11:11 - 000000000 ___RD C:\WINDOWS\PrintDialog 2019-12-25 23:46 - 2019-12-26 11:11 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2019-12-25 23:46 - 2019-12-25 23:59 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template 2019-12-25 23:46 - 2019-12-25 23:59 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2019-12-25 23:46 - 2019-12-25 23:58 - 000000000 __RHD C:\Users\Public\Libraries 2019-12-25 23:46 - 2019-12-25 23:52 - 000000000 ___RD C:\Program Files (x86) 2019-12-25 23:46 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI 2019-12-25 23:46 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\SystemResources 2019-12-25 23:46 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2019-12-25 23:46 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\system32\MUI 2019-12-25 23:46 - 2019-12-25 23:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ___SD C:\WINDOWS\system32\F12 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ___SD C:\WINDOWS\system32\dsc 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\SysWOW64\Com 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\Sysprep 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\setup 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\oobe 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\migwiz 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\Dism 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\system32\Com 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\IME 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\WINDOWS\Help 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\Program Files\Common Files\System 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2019-12-25 23:46 - 2019-12-25 23:51 - 000000000 ____D C:\Program Files (x86)\Windows Defender 2019-12-25 23:46 - 2019-12-25 23:47 - 000000000 ____D C:\WINDOWS\TextInput 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 __SHD C:\Program Files\Windows Sidebar 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 __RSD C:\WINDOWS\Media 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___SD C:\WINDOWS\system32\UNP 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___SD C:\WINDOWS\system32\Nui 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___SD C:\WINDOWS\system32\Configuration 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___RD C:\WINDOWS\Offline Web Pages 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___HD C:\WINDOWS\LanguageOverlayCache 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Web 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\WaaS 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Vss 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\tracing 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\TAPI 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\ras 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\IME 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SystemApps 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\winevt 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\ti-et 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\ta-lk 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\ta-in 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\si-lk 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\Sgrm 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\ras 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\ProximityToast 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\PointOfService 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\osa-Osge-001 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\NDF 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\my-mm 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\MsDtc 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\Macromed 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\Keywords 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\Ipmi 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\InputMethod 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\inetsrv 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\IME 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\icsxml 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\ias 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\Hydrogen 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\GroupPolicyUsers 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\ff-Adlm-SN 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\DriverState 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\downlevel 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\DDFs 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\config\RegBack 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\config\Journal 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\Bthprops 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\appraiser 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\AppLocker 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\am-et 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\System 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SKB 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\ShellExperiences 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\ShellComponents 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\security 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\schemas 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\SchCache 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Resources 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\rescache 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Provisioning 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\PLA 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Performance 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\ModemLogs 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\L2Schemas 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\InputMethod 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\IdentityCRL 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Globalization 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\DiagTrack 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Cursors 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Containers 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\Branding 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\addins 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\ProgramData\USOShared 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\Program Files\Windows Security 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\Program Files\Windows Portable Devices 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\Program Files\Windows Multimedia Platform 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\Program Files\ModifiableWindowsApps 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\Program Files\Common Files\Services 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\Program Files (x86)\Windows NT 2019-12-25 23:46 - 2019-12-25 23:46 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2019-12-25 23:46 - 2019-12-25 23:43 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat 2019-12-25 23:46 - 2019-12-25 23:43 - 000207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2019-12-25 23:46 - 2019-12-25 23:43 - 000003103 _____ C:\WINDOWS\SysWOW64\mmc.exe.config 2019-12-25 23:46 - 2019-12-25 23:43 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT 2019-12-25 23:46 - 2019-12-25 23:42 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2019-12-25 23:46 - 2019-12-25 23:42 - 000215943 _____ C:\WINDOWS\system32\dssec.dat 2019-12-25 23:46 - 2019-12-25 23:42 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll 2019-12-25 23:46 - 2019-12-25 23:42 - 000018903 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2019-12-25 23:46 - 2019-12-25 23:42 - 000017635 _____ C:\WINDOWS\system32\Drivers\etc\services 2019-12-25 23:46 - 2019-12-25 23:42 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam 2019-12-25 23:46 - 2019-12-25 23:42 - 000003103 _____ C:\WINDOWS\system32\mmc.exe.config 2019-12-25 23:46 - 2019-12-25 23:42 - 000001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol 2019-12-25 23:46 - 2019-12-25 23:42 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json 2019-12-25 23:46 - 2019-12-25 23:42 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT 2019-12-25 23:46 - 2019-12-25 23:42 - 000000407 _____ C:\WINDOWS\system32\Drivers\etc\networks 2019-12-25 23:46 - 2019-12-25 23:42 - 000000219 _____ C:\WINDOWS\system.ini 2019-12-25 23:46 - 2019-12-25 23:42 - 000000092 _____ C:\WINDOWS\win.ini 2019-12-25 23:44 - 2019-12-26 20:46 - 000000000 ____D C:\WINDOWS\INF 2019-12-25 23:35 - 2019-12-26 21:24 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-12-25 23:30 - 2019-12-26 21:23 - 000000000 ____D C:\WINDOWS\servicing 2019-12-25 23:30 - 2019-12-26 20:38 - 088604672 _____ C:\WINDOWS\system32\config\SYSTEM 2019-12-25 23:30 - 2019-12-26 20:38 - 069992448 _____ C:\WINDOWS\system32\config\SOFTWARE 2019-12-25 23:30 - 2019-12-26 11:32 - 000000000 ____D C:\WINDOWS\Panther 2019-12-25 23:30 - 2019-12-26 11:22 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2019-12-25 23:30 - 2019-12-26 11:17 - 000524288 _____ C:\WINDOWS\system32\config\DEFAULT 2019-12-25 23:30 - 2019-12-26 11:17 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2019-12-25 23:30 - 2019-12-26 11:17 - 000032768 _____ C:\WINDOWS\system32\config\SECURITY 2019-12-25 23:30 - 2019-12-26 11:17 - 000032768 _____ C:\WINDOWS\system32\config\SAM 2019-12-25 23:30 - 2019-12-25 23:46 - 000000000 ____D C:\WINDOWS\system32\SMI 2019-12-25 21:02 - 2019-12-25 21:02 - 000000000 ____D C:\Users\evadr\UniversalApps 2019-12-25 21:00 - 2019-12-26 07:42 - 000000000 ____D C:\Users\evadr\Downloads\opera autoupdate 2019-12-25 20:57 - 2019-12-25 20:57 - 000001889 _____ C:\Users\evadr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent Web.lnk 2019-12-25 20:52 - 2019-12-25 20:52 - 000059344 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtultrausbbus.sys 2019-12-25 20:51 - 2019-12-25 23:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\DAEMON Tools Ultra 2019-12-25 20:51 - 2019-12-25 20:51 - 000042256 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtultrascsibus.sys 2019-12-25 20:50 - 2019-12-25 20:51 - 033313648 _____ (Disc Soft Ltd) C:\Users\evadr\Downloads\daemon-tools-5-7-0.exe 2019-12-25 16:12 - 2019-12-26 21:10 - 000000000 ____D C:\Users\evadr\Downloads\State.of.Decay.2-CODEX 2019-12-25 15:48 - 2019-12-27 06:54 - 000000000 ____D C:\Users\evadr\AppData\LocalLow\Mozilla 2019-12-25 15:47 - 2019-12-25 15:47 - 000319920 _____ (Mozilla) C:\Users\evadr\Downloads\Firefox Installer.exe 2019-12-25 14:28 - 2019-12-25 14:28 - 018466224 _____ (BitTorrent, Inc.) C:\Users\evadr\Downloads\utweb_installer.exe 2019-12-25 13:50 - 2019-12-25 13:51 - 007867392 _____ C:\Users\evadr\Downloads\Star Wars Jedi Fallen Order Installation.exe 2019-12-24 14:45 - 2019-12-24 14:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2019-12-24 14:44 - 2019-12-24 14:44 - 042030736 _____ C:\Users\evadr\Downloads\vlc-media-player-3-0-8-64-bit.exe 2019-12-24 14:19 - 2019-12-24 14:19 - 018567144 _____ (BitTorrent, Inc.) C:\Users\evadr\Downloads\btweb_installer.exe 2019-12-19 16:11 - 2019-12-19 16:11 - 000053095 _____ C:\Users\evadr\Downloads\facture beatrice fabry.xlsx 2019-12-17 17:27 - 2019-12-17 17:27 - 000289818 _____ C:\Users\evadr\Downloads\axa 6-min (1).pdf 2019-12-17 17:27 - 2019-12-17 17:27 - 000262465 _____ C:\Users\evadr\Downloads\axa 7-min.pdf.ch8c6th.partial 2019-12-17 17:27 - 2019-12-17 17:27 - 000262465 _____ C:\Users\evadr\Downloads\axa 7-min (1).pdf 2019-12-17 17:26 - 2019-12-17 17:26 - 000289818 _____ C:\Users\evadr\Downloads\axa 6-min.pdf.f6a058o.partial 2019-12-17 17:24 - 2019-12-17 17:25 - 000191563 _____ C:\Users\evadr\Downloads\axa 5-min.pdf 2019-12-17 17:24 - 2019-12-17 17:24 - 000093015 _____ C:\Users\evadr\Downloads\axa 4-min.pdf 2019-12-17 17:23 - 2019-12-17 17:23 - 000178539 _____ C:\Users\evadr\Downloads\axa 2-min.pdf 2019-12-17 17:23 - 2019-12-17 17:23 - 000167151 _____ C:\Users\evadr\Downloads\axa 3-min.pdf 2019-12-17 17:22 - 2019-12-17 17:22 - 000178624 _____ C:\Users\evadr\Downloads\axa 1-min.pdf 2019-12-15 21:39 - 2019-12-15 21:41 - 000289782 _____ C:\TDSSKiller.3.1.0.28_15.12.2019_21.39.54_log.txt 2019-12-14 21:28 - 2019-12-14 21:29 - 000286744 _____ C:\TDSSKiller.3.1.0.28_14.12.2019_21.28.18_log.txt 2019-12-14 17:58 - 2019-12-16 21:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2019-12-14 17:35 - 2019-12-25 23:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2019-12-14 17:30 - 2019-12-14 17:30 - 024578944 _____ (Piriform Software Ltd) C:\Users\evadr\Downloads\ccsetup563.exe 2019-12-14 17:23 - 2019-12-14 17:23 - 003326336 _____ (Nicolas Coolman) C:\Users\evadr\Downloads\ZHPCleaner.exe 2019-12-14 14:47 - 2019-12-26 15:15 - 000000000 ____D C:\AdwCleaner 2019-12-14 14:47 - 2019-12-14 14:47 - 008218800 _____ (Malwarebytes) C:\Users\evadr\Downloads\adwcleaner_8.0.0.exe 2019-12-14 14:39 - 2019-12-14 14:39 - 001780224 _____ (Bleeping Computer, LLC) C:\Users\evadr\Downloads\rkill-unsigned.exe 2019-12-14 14:35 - 2019-12-14 14:37 - 000289140 _____ C:\TDSSKiller.3.1.0.28_14.12.2019_14.35.22_log.txt 2019-12-14 14:34 - 2019-12-14 14:35 - 005054744 _____ (AO Kaspersky Lab) C:\Users\evadr\Downloads\tdsskiller.exe 2019-12-14 14:28 - 2019-12-26 20:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-12-14 14:26 - 2019-12-14 14:26 - 001883976 _____ (Malwarebytes) C:\Users\evadr\Downloads\MBSetup.exe 2019-12-14 13:05 - 2019-12-26 21:10 - 000000000 ____D C:\Users\evadr\OneDrive\Documents\facture 2019 2019-12-14 13:05 - 2019-12-26 21:09 - 000000000 ___RD C:\Users\evadr\OneDrive 2019-12-14 13:05 - 2019-12-17 15:59 - 000000000 ____D C:\Users\evadr\OneDrive\Documents\kaipolanie garden 2019-12-14 13:05 - 2019-12-16 06:39 - 000000000 ____D C:\Users\evadr\OneDrive\Documents\logo 2019-12-14 13:05 - 2019-12-14 17:42 - 000000000 ____D C:\Users\evadr\OneDrive\Documents\document administratif 2019-12-14 13:05 - 2019-12-14 13:05 - 000000000 ____D C:\Users\evadr\OneDrive\Documents\Zen Studios 2019-12-14 13:05 - 2019-12-14 13:05 - 000000000 ____D C:\Users\evadr\OneDrive\Documents\mot de pass 2019-12-14 13:05 - 2019-12-14 13:05 - 000000000 ____D C:\Users\evadr\OneDrive\Documents\devis kaipolanie garden 2019-12-14 13:02 - 2019-12-14 13:02 - 000000000 ___HD C:\Users\evadr\MicrosoftEdgeBackups 2019-12-14 13:00 - 2019-12-26 21:08 - 000000000 __SHD C:\Users\evadr\IntelGraphicsProfiles 2019-12-14 13:00 - 2019-12-26 11:38 - 000000000 __RHD C:\Users\Public\AccountPictures 2019-12-14 13:00 - 2019-12-26 11:38 - 000000000 ___RD C:\Users\evadr\3D Objects 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default\Voisinage réseau 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default\Voisinage d'impression 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default\Modèles 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default\Mes documents 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default\Menu Démarrer 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default User\Voisinage réseau 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default User\Voisinage d'impression 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default User\Modèles 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default User\Mes documents 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default User\Menu Démarrer 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programmes 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programmes 2019-12-13 21:51 - 2019-12-13 21:51 - 000000000 _SHDL C:\Documents and Settings 2019-12-13 21:42 - 2019-12-25 23:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant 2019-12-13 21:41 - 2019-12-26 11:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby 2019-12-13 21:39 - 2019-12-13 21:52 - 000000000 ____D C:\Intel 2019-12-12 00:22 - 2019-12-12 00:22 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 018020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 009927992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 007600448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 007278592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 006516648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 006083832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 005943296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 005914112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 002762296 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 002716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 002698768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 002494432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 002147328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 002082208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001757304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2019-12-12 00:22 - 2019-12-12 00:22 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001743888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001656600 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001512528 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001451520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001399312 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2019-12-12 00:22 - 2019-12-12 00:22 - 001261464 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001182448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 001098928 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001054864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 001006904 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000986936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000842552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000826368 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000822416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000774456 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000674280 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000673456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000646144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000593128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000530944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000511000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000422712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000127272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdfs.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000097080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000089536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe 2019-12-12 00:22 - 2019-12-12 00:22 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000067112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelineprxy.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevQueryBroker.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000032056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys 2019-12-12 00:22 - 2019-12-12 00:22 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll 2019-12-12 00:22 - 2019-12-12 00:22 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) ==================== Fichiers à la racine de certains dossiers ======== 2019-12-26 19:07 - 2019-12-26 20:10 - 000007601 _____ () C:\Users\evadr\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================