Farbar Recovery Scan Tool (x64) Version: 13-05-2020 01 Exécuté par Elève (14-05-2020 08:37:38) Exécuté depuis C:\Users\Elève\Desktop Mode d'amorçage: Normal ================== Chercher Fichiers: "searchall: clover" ============= Fichier: ======== C:\Windows\Prefetch\CLOVER.EXE-1EF7F334.pf [2020-05-11 13:51][2020-05-12 09:09] 000014197 _____ () 21995B56B41A626595E15F0D7EB36C62 [Fichier non signé] C:\Windows\Prefetch\SETUP_CLOVER@3.5.4.EXE-81C36E54.pf [2020-05-11 13:50][2020-05-11 13:51] 000018762 _____ () 7C2C74C0250D6259537C2720E0264692 [Fichier non signé] C:\Users\Elève\Documents\My Games\Binding of Isaac Afterbirth+ Mods\895960454\resources\items\collectibles\SatanicFourLeafClover.png [2018-12-12 06:08][2020-01-06 23:25] 000000532 _____ () 2ADDCE1BCD5147F20B89B10A0A2C85E5 [Fichier non signé] C:\Users\Elève\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Clover_CloverAss_exe [2020-05-12 08:59][2020-05-12 08:59] 000037014 _____ () 64858579E41F1D7057F04E5F8F38DB8F [Fichier non signé] C:\Users\Elève\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Clover_Clover_exe [2020-05-12 08:59][2020-05-12 08:59] 000037014 _____ () 64858579E41F1D7057F04E5F8F38DB8F [Fichier non signé] C:\Users\Elève\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Clover_SoftUpd_exe [2020-05-12 08:59][2020-05-12 08:59] 000037014 _____ () 64858579E41F1D7057F04E5F8F38DB8F [Fichier non signé] C:\Users\Elève\AppData\Local\Clover\User Data\Default\CloverPref [2020-05-11 13:51][2020-05-12 09:09] 000000030 _____ () 482C92C81B0100221E3C1068E3E90D07 [Fichier non signé] C:\Program Files (x86)\Common Files\Clover\Clover.ini [2020-05-11 13:50][2020-05-11 13:50] 000000070 _____ () 33B672D4B29D2386009FC75842C50579 [Fichier non signé] C:\Program Files (x86)\Clover\CloverAss.exe [2020-05-11 13:51][2020-05-11 13:51] 000380632 _____ () 50FF7918A774A05589D83A9FDD763100 [Le fichier est signé numériquement] C:\Program Files (x86)\Clover\CloverInfo.ini [2020-05-11 13:50][2020-05-12 09:04] 000000320 _____ () BBF5B1D93BE82559703D4E413BDF7DF4 [Fichier non signé] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12624.20368.0_x64__8wekyb3d8bbwe\images\Theme_Photo_GreenClovers_Background.jpg [2020-04-02 20:04][2020-04-02 20:04] 000000000 _____ () D41D8CD98F00B204E9800998ECF8427E [Fichier non signé] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12624.20368.0_x64__8wekyb3d8bbwe\images\Theme_Photo_GreenClovers_Thumbnail.jpg [2020-04-02 20:04][2020-04-02 20:04] 000000000 _____ () D41D8CD98F00B204E9800998ECF8427E [Fichier non signé] dossier: ======== 2020-05-11 13:51 - 2020-05-11 13:51 _____ C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Clover.users 2020-05-11 13:51 - 2020-05-11 13:51 _____ C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Clover 2020-05-11 13:50 - 2020-05-11 13:51 _____ C:\Users\Elève\AppData\LocalLow\Clover 2020-05-11 13:51 - 2020-05-11 13:51 _____ C:\Users\Elève\AppData\LocalLow\Clover.users 2020-05-11 13:51 - 2020-05-11 13:51 _____ C:\Users\Elève\AppData\Local\Clover 2020-05-11 13:50 - 2020-05-12 10:37 _____ C:\Program Files (x86)\Clover 2020-05-11 13:50 - 2020-05-11 13:50 _____ C:\Program Files (x86)\Common Files\Clover Registre: ======== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8A6CAA2-533D-4AED-9E05-8EB19A4021AB}\InprocServer32] ""="C:\Program Files (x86)\Clover\TabHelper64.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{63F1F5B5-238F-4205-B166-D1BF6E351BDC}\1.0\0\win32] ""="C:\Program Files (x86)\Clover\TabHelper32.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{63F1F5B5-238F-4205-B166-D1BF6E351BDC}\1.0\0\win64] ""="C:\Program Files (x86)\Clover\TabHelper64.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{63F1F5B5-238F-4205-B166-D1BF6E351BDC}\1.0\HELPDIR] ""="C:\Program Files (x86)\Clover" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F8A6CAA2-533D-4AED-9E05-8EB19A4021AB}\InprocServer32] ""="C:\Program Files (x86)\Clover\TabHelper32.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Clover] [HKEY_LOCAL_MACHINE\SOFTWARE\Clover] "InstallPath"="C:\Program Files (x86)\Clover\" [HKEY_LOCAL_MACHINE\SOFTWARE\Clover\AppInfo] "Spreader"="clover200200511" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CompatMarkers\20H1] "BlockedByCloverTrail"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clover] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clover] "InstallPath"="C:\Program Files (x86)\Clover\" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clovermgr] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clovermgr] "ServiceName"="HCloverService" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clovermgr] "ServiceDisplayName"="clover_service" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clovermgr] "ServiceDescription"="Clover 自动更新服务" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clovermgr] "ServiceDll"="C:\Program Files (x86)\Clover\CloverSvc.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Clover] [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Clover] "DisplayName"="Clover V3.5" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Clover] "UninstallString"="C:\Program Files (x86)\Clover\Uninst.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Clover] "DisplayIcon"="C:\Program Files (x86)\Clover\Clover.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Svchost] "HCloverService"="HCloverService" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-374379745-121950057-888177057-1001] "\Device\HarddiskVolume3\Program Files (x86)\Clover\Uninst.exe"="0x8BB98E902A28D60100000000000000000000000002000000" [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Clover] [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched] "C:\Users\Elève\Downloads\setup_clover@3.5.4.exe"="3" [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched] "{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Clover\Clover.exe"="13" [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Microsoft\Windows\CurrentVersion\UFH\SHC] "47"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clover.lnk C:\Program Files (x86)\Clover\Clover.exe " [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Microsoft\Windows\CurrentVersion\UFH\SHC] "48"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clover\Clover.lnk C:\Program Files (x86)\Clover\Clover.exe " [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Microsoft\Windows\CurrentVersion\UFH\SHC] "50"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clover\在线升级.lnk C:\Program Files (x86)\Clover\SoftUpd.exe " [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Users\Elève\Downloads\setup_clover@3.5.4.exe"="0x5341435001000000000000000700000028000000D894BD006280BE0001000000000000000000010600010000631F6E6F0EDED401000000000000000002000000280000000000000000000040000000000000000000000000000000003EC60000000000000200000002000000" [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Program Files (x86)\Clover\ClvUtility.exe"="0x5341435001000000000000000700000028000000D8420F009701100001000000000000000000000A71220000631F6E6F0EDED40100000000000000000200000028000000000000000000004000000000000000000000000000000000120A0000000000000100000001000000" [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\Program Files (x86)\Clover\Uninst.exe"="0x5341435001000000000000000700000028000000D84413005727140003000000000000000000010600010000631F6E6F0EDED401000000000000000001000000040000000100000006000000080000000000800000000000050000001000000000000000000000000000000000000000020000005000000000000000000000000000800000000000000080000000000068020200000000000500000003000000000000000000004000008000000000000000800000000000632E0000000000000400000000000000" [HKEY_USERS\S-1-5-21-374379745-121950057-888177057-1001\Software\WindowPop\Clover] ====== Fin de Chercher ======