cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 17-05-2021
Exécuté par manep (administrateur) sur DESKTOP-8T33STQ (19-05-2021 06:47:52)
Exécuté depuis C:\Users\manep\Downloads
Profils chargés: manep
Platform: Windows 10 Home Version 2004 19041.985 (X64) Langue: Français (France)
Navigateur par défaut: Edge
Mode d'amorçage: Normal

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

() [Fichier non signé] C:\Program Files (x86)\Wondershare\drfone\Addins\Clone\ElevationService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe <2>
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
(Corel Corporation -> WinZip Computing) C:\Program Files\WinZip\WzPreloader.exe
(Corel Corporation -> WinZip Computing, S.L.) C:\Program Files\WinZip\FAHWindow64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2cec8fd58a80e6ea\igfxCUIService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2cec8fd58a80e6ea\igfxEM.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2cec8fd58a80e6ea\IntelCpHDCPSvc.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_2cec8fd58a80e6ea\IntelCpHeciSvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <22>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\manep\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MsMpEng.exe
(Open Source Developer, Robin Krom -> Greenshot) C:\Program Files\Greenshot\Greenshot.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.236\WsAppService.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\ProgramData\Wondershare\Service\InstallAssistService.exe

==================== Registre (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [527792 2017-08-09] (Open Source Developer, Robin Krom -> Greenshot)
HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2020-02-25] (Corel Corporation -> Corel Corporation)
HKLM\...\Run: [WinZip FAH] => C:\Program Files\WinZip\FAHConsole.exe [436704 2020-02-25] (Corel Corporation -> WinZip Computing, S.L.)
HKU\S-1-5-21-1644168496-700387399-703654843-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [33698888 2021-04-22] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1644168496-700387399-703654843-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [90952568 2020-10-09] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-1644168496-700387399-703654843-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5536440 2021-04-27] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-1644168496-700387399-703654843-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-1644168496-700387399-703654843-1001\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-1644168496-700387399-703654843-1001\...\Policies\Explorer: [NoLogoff] 0
HKLM\...\Print\Monitors\HP E311 Status Monitor: C:\WINDOWS\system32\hpinkstsE311LM.dll [388792 2016-02-23] (Hewlett Packard -> Hewlett-Packard Development Company, LP)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.212\Installer\chrmstp.exe [2021-05-13] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Préchargeur.lnk [2020-07-26]
ShortcutTarget: WinZip Préchargeur.lnk -> C:\Program Files\WinZip\WzPreloader.exe (Corel Corporation -> WinZip Computing)
Startup: C:\Users\manep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Envoyer à OneNote.lnk [2018-01-21]
ShortcutTarget: Envoyer à OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Tâches planifiées (Avec liste blanche) ============

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

Task: {0BAE0314-F368-441E-B081-4D84B24F1B70} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {11A13201-F86D-412A-89F5-89E82BF78707} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [28082760 2021-04-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {167B5956-1BBD-4C00-A239-7E891C129ACC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {16B3FE32-BB8A-4E2B-A12D-B77BD6C205E4} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114000 2021-05-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {1931B139-3C49-4610-A389-B1F7D2265110} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2020-02-25] (Corel Corporation -> Corel Corporation)
Task: {52C7A64E-E947-4F82-95C4-7859489524A4} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2020-02-25] (Corel Corporation -> Corel Corporation)
Task: {69D52C4A-FA05-4A17-BF29-D396B92EE6E2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6ECC2CC1-B861-49EF-97BF-1D4F33F1D709} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7E72859D-D7F5-44C7-BA27-12C11A831155} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114000 2021-05-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {8244BAD3-A9EB-485A-9BCA-D6D640289D4A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-05-20] (Google LLC -> Google LLC)
Task: {96E2286A-EA88-4614-8F90-CB32CE363450} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
Task: {A18E26F1-9272-4F7B-B21A-B8C6BEFA129C} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [126152 2020-04-03] (Mozilla Corporation -> Mozilla Foundation)
Task: {D3C6574C-95B2-45F8-A640-8106F0B11383} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-05-20] (Google LLC -> Google LLC)
Task: {DD15E5A5-88D0-4EEF-AA9C-A10435E1A407} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-17] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E2E97A39-7B95-4A9F-A78C-EDDA7E1873DC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {E3BCB5B2-EC1F-4BCA-9913-FABBA448698F} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-04-22] (Piriform Software Ltd -> Piriform)
Task: {E5A83541-021B-4CF9-A525-80402D3AB7E3} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe)
Task: {E6EB7AD7-2878-49C3-8642-F6A30E9E1646} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2020-02-25] (Corel Corporation -> Corel Corporation)
Task: {FA9C4892-B206-469C-9D0D-EFE01E9A354A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {FEA6D845-04A5-42DB-965C-F396CF414E70} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe [918288 2020-04-22] (Intel(R) Trust Services -> Intel(R) Corporation)

(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)

Task: C:\WINDOWS\Tasks\Intel PTT EK Recertification.job => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{955156f4-2a3b-4b72-a5f7-f7dfca1baba1}: [DhcpNameServer] 192.168.0.1 0.0.0.0
Tcpip\..\Interfaces\{e75a763c-8843-4194-b8b6-028b62ce47ee}: [DhcpNameServer] 192.168.0.1 0.0.0.0

Edge:
=======
DownloadDir: C:\Users\manep\Downloads
Edge Notifications: HKU\S-1-5-21-1644168496-700387399-703654843-1001 -> hxxps://fr.investing.com; hxxps://hintigo.fr; hxxps://www.lynxbroker.fr; hxxps://fr.windows10updater.com; hxxps://wallstreetenglish.fr; hxxps://www.750g.com; hxxps://support.zaful.com; hxxps://sg.zaful.com; hxxps://all3dp.com
Edge Extension: (Adblock Plus) -> 10_EyeoGmbHAdblockPlus_d55gg7py3s0m0 => C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.19.0_neutral__d55gg7py3s0m0 [2020-02-13]
Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)]
Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)]
Edge Extension: (Microsoft S/MIME Control) -> EdgeExtension_MicrosoftOutlookEdgeExtensionSmime_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.Outlook.EdgeExtension.Smime_20.19.814.2_x64__8wekyb3d8bbwe [2019-12-05]
Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)]
Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)]
Edge DefaultProfile: Default
Edge Profile: C:\Users\manep\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-19]

FireFox:
========
FF DefaultProfile: mjm04esl.default
FF ProfilePath: C:\Users\manep\AppData\Roaming\Mozilla\Firefox\Profiles\mjm04esl.default [2021-05-19]
FF Notifications: Mozilla\Firefox\Profiles\mjm04esl.default -> hxxps://wallstreetenglish.fr
FF Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\manep\AppData\Roaming\Mozilla\Firefox\Profiles\mjm04esl.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-04-22]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_465.dll [2020-12-09] (Adobe Inc. -> )
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_465.dll [2020-12-09] (Adobe Inc. -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-27] (Adobe Inc. -> Adobe Systems Inc.)

==================== Services (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-12-09] (Adobe Inc. -> Adobe)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8798600 2021-04-28] (Microsoft Corporation -> Microsoft Corporation)
R2 ElevationService; C:\Program Files (x86)\Wondershare\drfone\Addins\Clone\ElevationService.exe [913408 2021-01-20] () [Fichier non signé]
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [288360 2021-05-12] (HP Inc. -> HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7456464 2021-04-28] (Malwarebytes Inc -> Malwarebytes)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-11-26] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [919992 2020-11-26] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\NisSrv.exe [2599328 2021-05-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MsMpEng.exe [128376 2021-05-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 Wondershare InstallAssist; C:\ProgramData\Wondershare\Service\InstallAssistService.exe [262312 2021-02-26] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.236\WsAppService.exe [495840 2018-01-26] (Wondershare Technology Co.,Ltd -> Wondershare)

===================== Pilotes (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [161288 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-05-18] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-09-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-05-15] (Malwarebytes Inc -> Malwarebytes)
R3 MpKsl005a8c2a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{879D0BDF-983B-41FC-AA70-B831E89BE210}\MpKslDrv.sys [47336 2021-05-18] (Microsoft Windows -> Microsoft Corporation)
R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2017-08-03] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R3 nuviocir; C:\WINDOWS\system32\DRIVERS\nuviocir_x64.sys [40464 2015-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Nuvoton Technology Corp.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [168968 2020-12-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-05-17] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [421112 2021-05-17] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [73960 2021-05-17] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois (créés) (Avec liste blanche) =========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2021-05-19 06:47 - 2021-05-19 06:48 - 000019744 _____ C:\Users\manep\Downloads\FRST.txt
2021-05-19 06:47 - 2021-05-19 06:47 - 002299392 _____ (Farbar) C:\Users\manep\Downloads\FRST64.exe
2021-05-18 20:45 - 2021-05-19 06:48 - 000000000 ____D C:\FRST
2021-05-18 20:45 - 2021-05-18 20:45 - 000000000 ____D C:\Users\manep\Downloads\FRST-OlderVersion
2021-05-18 20:44 - 2021-05-18 20:45 - 002299392 _____ (Farbar) C:\Users\manep\Downloads\FRST64-2.1.exe
2021-05-18 18:35 - 2021-05-18 18:35 - 000004982 _____ C:\Users\manep\Documents\cc_20210518_183531.reg
2021-05-18 18:26 - 2021-05-18 18:26 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-05-18 18:12 - 2021-05-18 18:12 - 000098342 _____ C:\Users\manep\Desktop\ZHPCleaner (R).html
2021-05-18 18:09 - 2021-05-18 18:40 - 000008219 _____ C:\Users\manep\Desktop\ZHPCleaner (S).html
2021-05-18 18:01 - 2021-05-18 18:01 - 003327128 _____ (Nicolas Coolman) C:\Users\manep\Downloads\ZHPCleaner.exe
2021-05-18 18:01 - 2021-05-18 18:01 - 000000875 _____ C:\Users\manep\Desktop\ZHPCleaner.lnk
2021-05-18 14:47 - 2021-05-18 18:35 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2021-05-17 07:26 - 2021-05-17 07:25 - 004146112 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgremoverx.exe
2021-05-17 07:25 - 2021-05-17 07:25 - 014354752 _____ (AVG Technologies CZ, s.r.o.) C:\Users\manep\Downloads\avgclear.exe
2021-05-16 11:59 - 2021-05-18 18:19 - 000362037 _____ C:\Users\manep\Desktop\ZHPDiag.html
2021-05-16 11:54 - 2021-05-16 11:54 - 003469464 _____ (Nicolas Coolman) C:\Users\manep\Downloads\ZHPSuite.exe
2021-05-16 11:54 - 2021-05-16 11:54 - 000000865 _____ C:\Users\manep\Desktop\ZHPSuite.lnk
2021-05-16 11:46 - 2021-05-16 11:46 - 003275416 _____ (Nicolas Coolman) C:\Users\manep\Downloads\ZHPDiag3 (2).exe
2021-05-16 11:43 - 2021-05-16 11:43 - 000081548 _____ C:\Users\manep\Documents\cc_20210516_114329.reg
2021-05-15 16:23 - 2021-05-15 16:23 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-05-15 10:06 - 2021-05-15 10:06 - 000143528 _____ C:\Users\manep\Downloads\doc22862296.pdf
2021-05-13 19:16 - 2021-05-13 19:16 - 000147865 _____ C:\Users\manep\Downloads\E_IFU_2020(31_12_2020)_1680931640_bqWAI7sF.pdf
2021-05-13 19:15 - 2021-05-13 19:15 - 000130463 _____ C:\Users\manep\Downloads\pdf_KAvdzn.pdf
2021-05-13 19:14 - 2021-05-13 19:14 - 000130353 _____ C:\Users\manep\Downloads\pdf_xeJqm2.pdf
2021-05-12 17:00 - 2021-05-12 17:00 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-05-12 17:00 - 2021-05-12 17:00 - 001687040 _____ C:\WINDOWS\system32\libcrypto.dll
2021-05-12 16:59 - 2021-05-12 16:59 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-05-12 16:59 - 2021-05-12 16:59 - 001823816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-05-12 16:59 - 2021-05-12 16:59 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-05-12 16:59 - 2021-05-12 16:59 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-05-12 16:59 - 2021-05-12 16:59 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-05-12 16:59 - 2021-05-12 16:59 - 000700928 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-05-12 16:59 - 2021-05-12 16:59 - 000165888 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-05-12 16:59 - 2021-05-12 16:59 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-05-12 16:59 - 2021-05-12 16:59 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe
2021-05-12 16:59 - 2021-05-12 16:59 - 000011351 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-05-12 09:38 - 2021-05-12 09:38 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2021-05-06 07:47 - 2021-05-06 07:47 - 000079219 _____ C:\Users\manep\Desktop\dermatopath facture.pdf
2021-05-05 09:31 - 2021-05-05 09:31 - 000107090 _____ C:\Users\manep\Desktop\6fb55540-aa52-4548-808a-0426616a791e.pdf
2021-05-04 21:24 - 2021-05-04 21:24 - 000096469 _____ C:\Users\manep\Desktop\facture cerba.pdf
2021-04-30 20:18 - 2021-05-16 21:13 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2021-04-28 22:14 - 2020-09-30 07:10 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-04-28 20:30 - 2021-04-28 20:30 - 000522520 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgNetHub.sys.162097281631201
2021-04-28 20:29 - 2021-04-28 20:29 - 000259344 _____ (AVG Technologies CZ, s.r.o.) C:\Users\manep\Downloads\avg_antivirus_free_setup.exe
2021-04-25 16:39 - 2021-04-25 16:39 - 000005207 _____ C:\Users\manep\Downloads\CA20210425_163931.xlsx
2021-04-24 10:55 - 2021-04-24 10:55 - 000379171 _____ C:\Users\manep\Desktop\CARTE JEUNE CHARLOTTE SNCF.jpeg
2021-04-24 10:53 - 2021-04-24 10:53 - 000170895 _____ C:\Users\manep\Downloads\Paris_LA ROCHELLE_202104250905_UYPIHN.pdf
2021-04-21 12:14 - 2021-04-21 12:14 - 000186996 _____ C:\Users\manep\Desktop\FACTURE.jpeg
2021-04-19 12:39 - 2021-04-19 12:39 - 000148062 _____ C:\Users\manep\Desktop\notes code charlotte.pdf
2021-04-19 12:33 - 2021-04-19 12:34 - 001859123 _____ C:\Users\manep\Desktop\code charlotte.pdf

==================== Un mois (modifiés) ==================

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2021-05-19 06:44 - 2020-11-15 09:45 - 000004174 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{2326B1D5-FD59-470D-B97D-7F09692DE9F6}
2021-05-19 06:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-05-19 06:44 - 2018-03-19 19:28 - 000000000 ____D C:\Program Files\CCleaner
2021-05-19 06:41 - 2019-07-04 13:21 - 000000000 ____D C:\Users\manep\AppData\Local\CrashDumps
2021-05-19 06:41 - 2017-04-04 00:14 - 000000000 ___RD C:\Users\manep\OneDrive
2021-05-19 06:41 - 2017-04-04 00:12 - 000000000 __SHD C:\Users\manep\IntelGraphicsProfiles
2021-05-18 21:28 - 2017-04-04 00:29 - 000000000 ____D C:\Users\manep\AppData\LocalLow\Mozilla
2021-05-18 21:24 - 2020-11-15 09:37 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-05-18 21:24 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-18 18:40 - 2019-03-24 08:16 - 000000000 ____D C:\Users\manep\AppData\Roaming\ZHP
2021-05-18 18:35 - 2017-04-04 19:31 - 000001278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2021-05-18 18:35 - 2017-04-04 00:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-05-18 18:32 - 2020-11-15 09:39 - 001681370 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-05-18 18:32 - 2019-12-07 16:49 - 000755174 _____ C:\WINDOWS\system32\perfh00C.dat
2021-05-18 18:32 - 2019-12-07 16:49 - 000141980 _____ C:\WINDOWS\system32\perfc00C.dat
2021-05-18 18:32 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2021-05-18 18:26 - 2020-11-15 09:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-05-18 18:26 - 2020-11-15 09:37 - 000008192 ___SH C:\DumpStack.log.tmp
2021-05-18 18:26 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-05-18 18:26 - 2017-04-04 00:12 - 000000000 ____D C:\Intel
2021-05-18 18:03 - 2017-04-04 22:03 - 000000000 ____D C:\Users\manep\Documents\Money
2021-05-17 21:12 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-05-17 16:14 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Windows Defender
2021-05-17 16:14 - 2018-06-24 10:48 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-05-17 13:42 - 2017-12-03 20:44 - 000000000 ____D C:\Users\manep\AppData\Local\Packages
2021-05-17 09:20 - 2017-04-04 22:05 - 000000000 ____D C:\Users\manep\Documents\Ecole
2021-05-17 08:17 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-05-16 21:13 - 2020-11-28 08:13 - 000003368 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6bb22c357d25e
2021-05-16 21:13 - 2020-11-15 09:45 - 000003618 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2021-05-16 21:13 - 2020-11-15 09:45 - 000003562 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-05-16 21:13 - 2020-11-15 09:45 - 000003516 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-05-16 21:13 - 2020-11-15 09:45 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-05-16 21:13 - 2020-11-15 09:45 - 000003338 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-05-16 21:13 - 2020-11-15 09:45 - 000003292 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-05-16 21:13 - 2020-11-15 09:45 - 000003220 _____ C:\WINDOWS\system32\Tasks\Intel PTT EK Recertification
2021-05-16 21:13 - 2020-11-15 09:45 - 000002988 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-05-16 21:13 - 2020-11-15 09:45 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1644168496-700387399-703654843-1001
2021-05-16 21:13 - 2020-11-15 09:45 - 000002694 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 2
2021-05-16 21:13 - 2020-11-15 09:45 - 000002692 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 3
2021-05-16 21:13 - 2020-11-15 09:45 - 000002692 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 1
2021-05-16 21:13 - 2020-11-15 09:45 - 000002216 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2021-05-16 11:58 - 2020-03-20 16:13 - 000000000 ____D C:\Users\manep\Documents\Généalogie
2021-05-16 11:54 - 2019-04-17 19:01 - 000000000 ____D C:\Users\manep\AppData\Local\ZHP
2021-05-16 09:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-05-15 21:02 - 2017-04-03 20:31 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-05-14 20:23 - 2020-06-15 00:30 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-14 20:23 - 2020-06-15 00:30 - 000002280 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-05-12 20:26 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-05-12 20:24 - 2020-11-15 09:37 - 000299760 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-05-12 20:23 - 2019-12-07 16:51 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2021-05-12 20:23 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-05-12 17:02 - 2019-12-07 16:53 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2021-05-12 16:54 - 2017-04-03 21:19 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-05-12 16:52 - 2017-04-03 21:19 - 132732536 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-05-12 11:21 - 2017-04-17 13:32 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-05-12 09:38 - 2021-04-13 22:41 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2021-05-12 07:48 - 2021-02-05 19:11 - 000000000 ____D C:\Users\manep\AppData\Roaming\vlc
2021-05-09 19:34 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-05-09 10:02 - 2018-04-12 20:59 - 000000000 ____D C:\Users\manep\AppData\Local\PlaceholderTileLogoFolder
2021-05-07 07:31 - 2017-04-04 22:05 - 000000000 ____D C:\Users\manep\Documents\Famille
2021-05-06 09:10 - 2020-11-15 09:38 - 000002401 _____ C:\Users\manep\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-03 07:29 - 2017-04-04 00:12 - 000000000 ____D C:\Users\manep\AppData\Local\ConnectedDevicesPlatform
2021-04-29 07:15 - 2017-12-03 21:00 - 000000000 ____D C:\Users\manep\AppData\Local\ElevatedDiagnostics
2021-04-28 22:14 - 2020-08-26 00:41 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-04-28 22:14 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-04-28 22:13 - 2019-07-11 12:42 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-04-28 20:28 - 2017-04-04 00:20 - 000000000 ____D C:\ProgramData\Avira
2021-04-28 20:28 - 2017-04-04 00:20 - 000000000 ____D C:\Program Files (x86)\Avira
2021-04-28 20:27 - 2019-12-07 11:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-04-28 20:27 - 2019-02-28 21:40 - 000799104 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2021-04-28 20:27 - 2017-04-04 00:20 - 000000000 ____D C:\ProgramData\Package Cache
2021-04-28 14:10 - 2017-04-23 09:29 - 000000000 ____D C:\Users\manep\AppData\Local\Greenshot
2021-04-28 08:03 - 2017-10-08 12:10 - 000000000 _____ C:\WINDOWS\system32\Drivers\lvuvc.hs
2021-04-24 10:55 - 2017-05-08 15:38 - 000000000 ___RD C:\Users\manep\Documents\Scanned Documents
2021-04-21 03:24 - 2020-08-25 18:02 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools

==================== Fichiers à la racine de certains dossiers ========

2021-01-13 21:18 - 2021-01-13 21:18 - 000000855 _____ () C:\Users\manep\AppData\Local\recently-used.xbel

==================== SigCheck ============================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

==================== Fin de FRST.txt ========================

Publicité


Signaler le contenu de ce document

Publicité