cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2022
Exécuté par Gide.NKOUKA (administrateur) sur CG-BRA-01IT34 (Hewlett-Packard HP 15 Notebook PC) (14-11-2022 14:46:11)
Exécuté depuis C:\Users\gide.nkouka\Desktop
Profils chargés: Gide.NKOUKA & Azur
Plate-forme: Microsoft Windows 10 Professionnel N Version 21H2 19044.2251 (X64) Langue: Français (France)
Navigateur par défaut: FF
Mode d'amorçage: Normal

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\66.0.3.0\crashpad_handler.exe <3>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <23>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\66.0.3.0\GoogleDriveFS.exe <7>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\Office16\WINWORD.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\gide.nkouka\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe
(explorer.exe ->) (Opera Software AS -> Opera Software) C:\Users\gide.nkouka\AppData\Local\Programs\Opera\assistant\browser_assistant.exe
(explorer.exe ->) (暇光软件科技(上海)有限公司 -> Free Time Co., Ltd.) [Fichier non signé] C:\Program Files (x86)\PicosmosTools\PicosmosTools.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(services.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mobsync.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(svchost.exe ->) (WhatsApp Inc.) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2242.6.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

==================== Registre (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Fichier non signé]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard Company -> Hewlett-Packard)
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813 Group Policy restriction on software: C:\Program Files\Skype <==== ATTENTION
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813 Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813 Group Policy restriction on software: C:\Program Files\Mozilla Firefox <==== ATTENTION
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813 Group Policy restriction on software: C:\Program Files\Yahoo!\Messenger <==== ATTENTION
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813 Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\66.0.3.0\GoogleDriveFS.exe [52475672 2022-11-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\66.0.3.0\GoogleDriveFS.exe [52475672 2022-11-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626480 2022-11-09] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813\...\Run: [GoogleDriveSync] => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart (Pas de fichier)
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813\...\Run: [Opera Browser Assistant] => C:\Users\gide.nkouka\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [2264152 2019-01-03] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813\...\Run: [com.squirrel.Teams.Teams] => C:\Users\gide.nkouka\AppData\Local\Microsoft\Teams\Update.exe [1777776 2019-06-11] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813\...\Run: [Picosmos] => C:\Program Files (x86)\PicosmosTools\PicosmosTools.exe [7511728 2020-02-18] (暇光软件科技(上海)有限公司 -> Free Time Co., Ltd.) [Fichier non signé]
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\66.0.3.0\GoogleDriveFS.exe [52475672 2022-11-08] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-2987775730-2434628737-2840101130-3813\...\Run: [BingWallpaperApp] => C:\Users\gide.nkouka\AppData\Local\Microsoft\BingWallpaperApp\BingWallpaperApp.exe [13998496 2022-06-06] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3371038503-1723060537-3163575906-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2626480 2022-11-09] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\66.0.3.0\GoogleDriveFS.exe [52475672 2022-11-08] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp101: C:\Windows\System32\spool\prtprocs\x64\hpcpp101.dll [323584 2010-09-23] (Hewlett-Packard Corporation) [Fichier non signé]
HKLM\...\Windows x64\Print Processors\hpcpp160: C:\Windows\System32\spool\prtprocs\x64\hpcpp160.dll [602912 2013-12-04] (Hewlett-Packard Company -> Hewlett-Packard Corporation)
HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\WINDOWS\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [Fichier non signé]
HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\WINDOWS\system32\HPMPW081.DLL [74016 2013-12-04] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM\...\Print\Monitors\HPMLM135: C:\WINDOWS\system32\hpmlm135.dll [237344 2013-12-04] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\107.0.5304.107\Installer\chrmstp.exe [2022-11-11] (Google LLC -> Google LLC)
BootExecute: autocheck autochk * icarus_rvrt.exe
GroupPolicy: Restriction ? <==== ATTENTION

==================== Tâches planifiées (Avec liste blanche) ============

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

Task: {15D1D6C6-5931-41B3-9E56-66E93DB13944} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {28D6BBF5-1550-4F44-BAE5-098F792BBC68} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-12-27] (Google Inc -> Google Inc.)
Task: {364FAA22-D350-412B-BC22-E016C31C8EA5} - System32\Tasks\VSPXService_LG => WDCloud.exe t (Pas de fichier)
Task: {3B27905D-C0CF-43C2-BF0A-44AA54B0BBCB} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {3E190574-362C-44AB-90AC-1DEE14182306} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3371038503-1723060537-3163575906-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189064 2022-11-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {4472C4AB-5D6F-4161-8965-C7FD1DB5BE3D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
Task: {49293829-21C5-4C64-AA0C-1E36BF4BE9E0} - System32\Tasks\Microsoft\Windows\UpdateAssistant\UpdateAssistantAllUsersRun => C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV20:{} /AllUsersRun (Pas de fichier)
Task: {5A693E8D-6074-4FFB-947B-F5D6A661DC4E} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe do-task "E7CF176E110C211B"
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA}" a été déverrouillé. <==== ATTENTION
Task: {6350FA09-DB1F-4DD4-819B-E60531266B9F} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\WINDOWS\system32\gpupdate.exe [30720 2021-06-28] (Microsoft Windows -> Microsoft Corporation)
Task: {6577A5F9-D629-406D-A31C-008202E683B4} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\Explorer.EXE /NOUACCHECK
Task: {658919A7-46C9-42B7-8903-0E38A46E9A95} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2987775730-2434628737-2840101130-3813 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189064 2022-11-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {6FB8DDDD-8073-4713-A0B4-362671FBF937} - System32\Tasks\Opera scheduled Autoupdate 1544808997 => C:\Users\gide.nkouka\AppData\Local\Programs\Opera\launcher.exe [2333904 2022-02-15] (Opera Software AS -> Opera Software)
Task: {71B7C2A7-9F5A-4432-8CF4-A4FA261291F7} - System32\Tasks\Microsoft\Windows\termsrv\RemoteFX\RemoteFXvGPUDisableTask => C:\WINDOWS\System32\RemoteFXvGPUDisablement.exe Disable (Pas de fichier)
Task: {7BE1A32D-AD04-46FF-A1E0-F9B6AD0E1271} - System32\Tasks\Mozilla\Firefox Background Update E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\E7CF176E110C211B\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {8051AF40-1A43-4EE1-B4DB-A171B18D3B86} - System32\Tasks\RSS Feed PTX LG => C:\Users\gide.nkouka\AppData\Local\Packages\PXT\v1-0\rhc.exe [1536 2022-08-14] () [Fichier non signé]
Task: {88F21920-2667-4A67-8C1C-160F9D9472F1} - System32\Tasks\Microsoft\Windows\UpdateAssistant\UpdateAssistantCalendarRun => C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV20:{} /CalendarRun (Pas de fichier)
Task: {A10FC635-B4E8-49AD-9C0D-7E22CE01761C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {A326B4BA-ACBF-4264-AAB6-C9B01E4CF2A2} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4189064 2022-11-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {B5B8DFF3-C121-4300-83F7-F140030317F1} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\UpdateAssistantCalendarRun => C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:EosWu:{} /CalendarRun (Pas de fichier)
Task: {BB4BA46D-2CFD-47A4-9F9D-29F5C537C512} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-12-27] (Google Inc -> Google Inc.)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202}" a été déverrouillé. <==== ATTENTION
Task: {BD1CADD4-48B6-4FCC-B8BE-667D31EE622C} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\WINDOWS\system32\gpupdate.exe [30720 2021-06-28] (Microsoft Windows -> Microsoft Corporation)
Task: {C62E6FB7-3F1D-4BA6-B745-66D4B50FC411} - System32\Tasks\Microsoft\Windows\UpdateAssistant\UpdateAssistantWakeupRun => C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV20:{} /WakeupRun (Pas de fichier)
Task: {C7D1AD23-77ED-4EC0-A990-B9D3D7C6A9F5} - System32\Tasks\VSPXService => WDCloud.exe s (Pas de fichier)
Task: {CF0CC787-B1F6-4E8D-AB37-B785EF029CA1} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\UpdateAssistant => C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:EosWu:{} (Pas de fichier)
Task: {E18B72AD-B1C0-4537-A514-CF205BF6141F} - System32\Tasks\npcapwatchdog => C:\Program Files\Npcap\CheckStatus.bat [815 2021-09-08] () [Fichier non signé]
Task: {E38C5BCE-16F6-4211-B0F0-1AF2C39DEA2A} - System32\Tasks\Microsoft\Windows\UpdateAssistant\UpdateAssistant => C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV20:{} (Pas de fichier)
Task: {E75FF40D-17F3-4C0B-BE4E-A87E8EA08881} - System32\Tasks\RSS Feed PTX => C:\Users\gide.nkouka\AppData\Local\Packages\PXT\v1-0\rhc.exe [1536 2022-08-14] () [Fichier non signé]
Task: {EBD09F1C-F628-47D7-B2EF-8A5715F10808} - System32\Tasks\RSS Feed PTX UD => C:\Users\gide.nkouka\AppData\Local\Packages\PXT\v1-0\rhc.exe [1536 2022-08-14] () [Fichier non signé]
Task: {EEDD25E2-BB78-454E-9926-07BD5EE01BA5} - System32\Tasks\Opera scheduled assistant Autoupdate 1547468255 => C:\Users\gide.nkouka\AppData\Local\Programs\Opera\launcher.exe [2333904 2022-02-15] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\gide.nkouka\AppData\Local\Programs\Opera\assistant" $(Arg0)

(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)


==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{61a449a3-fdd2-4483-be3b-8ea987272869}: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{fabb8791-dd19-415b-91d0-863440429f7f}: [DhcpNameServer] 172.16.0.141 172.16.0.145

Edge:
=======
Edge Notifications: HKU\S-1-5-21-2987775730-2434628737-2840101130-3813 -> hxxps://web.skype.com
Edge DefaultProfile: Default
Edge Profile: C:\Users\gide.nkouka\AppData\Local\Microsoft\Edge\User Data\Default [2022-11-10]
Edge Notifications: Default -> hxxps://www.facebook.com; hxxps://www.instagram.com; hxxps://www.youtube.com
Edge Extension: (Halo – Master Chief) - C:\Users\gide.nkouka\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\inbgjjehigpmekicfkpbkiblipimbjfi [2022-05-21]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

FireFox:
========
FF DefaultProfile: 5qe08omz.default-1521556690407-1551945239472
FF ProfilePath: C:\Users\gide.nkouka\AppData\Roaming\Mozilla\Firefox\Profiles\5qe08omz.default-1521556690407-1551945239472 [2022-11-14]
FF Homepage: Mozilla\Firefox\Profiles\5qe08omz.default-1521556690407-1551945239472 -> hxxps://www.bing.com/?pc=W037
FF Notifications: Mozilla\Firefox\Profiles\5qe08omz.default-1521556690407-1551945239472 -> hxxps://www.bestcours.com; hxxps://community.ovh.com; hxxps://mail.yahoo.com; hxxps://www.instagram.com; hxxps://olymptrade.com
FF Extension: (Malwarebytes Browser Guard) - C:\Users\gide.nkouka\AppData\Roaming\Mozilla\Firefox\Profiles\5qe08omz.default-1521556690407-1551945239472\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2022-10-10]
FF HKU\S-1-5-21-2987775730-2434628737-2840101130-3813\...\Firefox\Extensions: [fdm_ffext@freedownloadmanager.org] - C:\ProgramData\Free Download Manager\Firefox\Extensions\2.1.13
FF Extension: (Free Download Manager extension) - C:\ProgramData\Free Download Manager\Firefox\Extensions\2.1.13 [2017-02-20] []
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-10-16] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.15.2 -> C:\WINDOWS\SysWOW64\npDeployJava1.dll [2018-10-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-02-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0-git-20130801-0003 -> E:\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> E:\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> E:\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> E:\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> E:\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> E:\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> E:\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)

Chrome:
=======
CHR Profile: C:\Users\gide.nkouka\AppData\Local\Google\Chrome\User Data\Default [2022-11-14]
CHR Notifications: Default -> hxxps://forums.commentcamarche.net; hxxps://web.whatsapp.com; hxxps://www.youtube.com
CHR Extension: (Adobe Acrobat : outils de modification, de conversion et de signature de PDF) - C:\Users\gide.nkouka\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-11-03]
CHR Extension: (Google Docs hors connexion) - C:\Users\gide.nkouka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-11-04]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\gide.nkouka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-05-21]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

Opera:
=======
OPR Profile: C:\Users\gide.nkouka\AppData\Roaming\Opera Software\Opera Stable [2022-11-14]
OPR Notifications: Opera Stable -> hxxps://notube.net; hxxps://web.skype.com; hxxps://www.facebook.com; hxxps://www.youtube.com
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\gide.nkouka\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2022-03-28]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\gide.nkouka\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-09-24]

==================== Services (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2022-11-14] (Avast Software s.r.o. -> AVAST Software)
S3 dcsvc; C:\WINDOWS\system32\dcsvc.dll [785408 2022-11-10] (Microsoft Windows -> Microsoft Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.225.1026.0001\FileSyncHelper.exe [3476368 2022-11-09] (Microsoft Corporation -> Microsoft Corporation)
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-25] (HP) [Fichier non signé]
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2013-11-14] (Hewlett-Packard) [Fichier non signé]
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.225.1026.0001\OneDriveUpdaterService.exe [3842480 2022-11-09] (Microsoft Corporation -> Microsoft Corporation)
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [66048 2013-11-14] (Hewlett-Packard) [Fichier non signé]
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [224216 2022-11-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Fichier non signé]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [14814520 2022-10-12] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 wampapache64; c:\wamp\bin\apache\apache2.4.9\bin\httpd.exe [24576 2014-05-01] (Apache Software Foundation) [Fichier non signé]
S3 wampmysqld64; c:\wamp\bin\mysql\mysql5.6.17\bin\mysqld.exe [12942848 2014-05-01] () [Fichier non signé]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\NisSrv.exe [3191272 2022-11-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MsMpEng.exe [133544 2022-11-11] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Pilotes (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 googledrivefs3758; C:\WINDOWS\System32\DRIVERS\googledrivefs3758.sys [384584 2022-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 int0800; C:\WINDOWS\System32\drivers\flashud.sys [51712 2009-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
R1 npcap; C:\WINDOWS\system32\DRIVERS\npcap.sys [72792 2021-12-01] (Insecure.Com LLC -> Insecure.Com LLC.)
R2 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 pelmouse; C:\WINDOWS\system32\DRIVERS\pelmouse.sys [26880 2016-07-11] (WDKTestCert idd,131110062695071623 -> TPMX Electronics Ltd.)
S3 pelusblf; C:\WINDOWS\system32\DRIVERS\pelusblf.sys [33048 2016-07-11] (WDKTestCert idd,131110062695071623 -> )
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [338368 2018-05-28] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2021-05-26] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
U5 vsock; C:\Windows\System32\Drivers\vsock.sys [105912 2020-08-11] (VMware, Inc. -> VMware, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49616 2022-11-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [469288 2022-11-11] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [95520 2022-11-11] (Microsoft Windows -> Microsoft Corporation)
S3 WinDivert1.1; C:\Program Files\KMSpico\WinDivert.sys [35376 2022-05-10] (Nemea Mjukvaruutveckling AB -> Basil Projects)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34944 2018-05-11] (HP Inc. -> HP)
U4 npcap_wifi; pas de ImagePath

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

NETSVC: DcSvc -> C:\Windows\system32\dcsvc.dll (Microsoft Corporation)

==================== Un mois (créés) (Avec liste blanche) =========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2022-11-14 14:46 - 2022-11-14 14:53 - 000027497 _____ C:\Users\gide.nkouka\Desktop\FRST.txt
2022-11-14 14:44 - 2022-11-14 14:44 - 002375168 _____ (Farbar) C:\Users\gide.nkouka\Downloads\FRST64.exe
2022-11-14 14:44 - 2022-11-14 14:44 - 002375168 _____ (Farbar) C:\Users\gide.nkouka\Desktop\FRST64.exe
2022-11-14 14:06 - 2022-11-14 14:32 - 000812588 _____ C:\WINDOWS\Minidump\111422-50546-01.dmp
2022-11-14 14:06 - 2022-11-14 14:06 - 787689844 _____ C:\WINDOWS\MEMORY.DMP
2022-11-14 12:59 - 2022-11-14 12:59 - 000495977 _____ C:\Users\gide.nkouka\Downloads\calendrier-coupe-du-monde-fifa-2022-qatar.pdf
2022-11-14 12:07 - 2022-11-14 12:07 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\Avast Software
2022-11-14 12:00 - 2022-11-14 12:00 - 000065944 _____ (Avast Software) C:\WINDOWS\system32\Drivers\asw0a4d15fdb64e4078.tmp
2022-11-14 11:54 - 2022-11-14 11:52 - 000038624 _____ (Avast Software) C:\WINDOWS\system32\icarus_rvrt.exe
2022-11-14 11:49 - 2022-11-14 11:50 - 000382528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswba96cf729a8ea238.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000672272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbb14ba968d286487.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000327896 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswe5623c952ed8db6d.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000306128 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw698e38d88af34746.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000276520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswed8ff2eb39fcb037.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000221944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswf25c8d22a73b3df0.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000114464 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw461321b3ec172a91.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000105936 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswd3a5cf7d07c61f12.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000090008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw41cacb9436992838.tmp
2022-11-14 11:49 - 2022-11-14 11:49 - 000025576 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw1791c33d08207471.tmp
2022-11-14 11:49 - 2022-11-14 11:48 - 000862936 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswd4e76e12d8c0cb8f.tmp
2022-11-14 11:49 - 2022-11-14 11:48 - 000564304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw08655079892c3f98.tmp
2022-11-14 11:49 - 2022-11-14 11:48 - 000270552 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2022-11-14 11:49 - 2022-11-14 11:48 - 000238152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw0af8b4c4f9ff41e4.tmp
2022-11-14 11:49 - 2022-11-14 11:48 - 000048512 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbda948262dfe6a5d.tmp
2022-11-14 11:49 - 2022-11-14 11:48 - 000042304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswf87d15e27c76e59f.tmp
2022-11-14 11:44 - 2022-11-14 14:30 - 000000000 ____D C:\Program Files\Avast Software
2022-11-14 11:28 - 2022-11-14 11:52 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2022-11-14 11:01 - 2022-11-14 11:01 - 001551360 _____ (Microsoft Corporation) C:\Users\gide.nkouka\Downloads\d63b6d8f-7a96-4514-8055-d3869fe4599a.tmp
2022-11-14 09:07 - 2022-11-14 09:07 - 000000000 ____D C:\WINDOWS\Panther
2022-11-13 17:46 - 2022-11-12 18:12 - 000268488 _____ (AVAST Software) C:\Users\gide.nkouka\Desktop\avast_one_free_antivirus.exe
2022-11-12 18:21 - 2022-11-12 18:21 - 000000000 ____D C:\WINDOWS\system32\gf2engine
2022-11-12 17:59 - 2022-11-12 20:40 - 000000000 ____D C:\Users\gide.nkouka\AppData\Local\FSDART
2022-11-12 17:59 - 2022-11-12 18:10 - 000000000 ____D C:\ProgramData\F-Secure
2022-11-11 17:01 - 2022-11-11 18:12 - 000005336 _____ C:\Users\gide.nkouka\Desktop\membres2.txt
2022-11-11 16:57 - 2022-11-11 16:57 - 000005357 _____ C:\Users\gide.nkouka\Desktop\membre.txt
2022-11-10 12:54 - 2022-11-10 12:54 - 000000000 ___HD C:\$WinREAgent
2022-11-10 12:11 - 2022-11-10 12:11 - 000688128 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2022-11-10 12:11 - 2022-11-10 12:11 - 000073216 _____ C:\WINDOWS\system32\nettraceex.dll
2022-11-10 12:10 - 2022-11-10 12:10 - 000012253 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-11-10 12:08 - 2022-11-10 12:08 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-11-09 13:22 - 2022-11-09 16:25 - 000000000 ____D C:\Users\gide.nkouka\oarh
2022-11-08 17:58 - 2022-11-14 09:11 - 000003842 _____ C:\WINDOWS\system32\Tasks\VSPXService
2022-11-08 17:58 - 2022-11-08 17:58 - 000003396 _____ C:\WINDOWS\system32\Tasks\VSPXService_LG
2022-11-08 17:57 - 2022-11-08 17:57 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\CSPX
2022-11-08 10:07 - 2022-11-08 10:07 - 000000903 _____ C:\Users\gide.nkouka\Desktop\FileZilla.lnk
2022-11-08 09:47 - 2022-11-09 19:16 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\FileZilla
2022-11-08 09:47 - 2022-11-08 10:32 - 000000000 ____D C:\Users\gide.nkouka\AppData\Local\FileZilla
2022-11-08 09:47 - 2022-11-08 09:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2022-11-08 09:19 - 2022-11-08 14:01 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2022-11-07 07:22 - 2022-11-07 07:31 - 000000000 ____D C:\Users\TEMP
2022-10-29 12:47 - 2022-10-29 12:48 - 000000132 _____ C:\Users\gide.nkouka\Desktop\Accès OARH16.txt
2022-10-25 09:38 - 2022-10-25 09:38 - 000002286 _____ C:\Users\gide.nkouka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navigation privée de Firefox.lnk
2022-10-21 10:41 - 2022-10-22 17:57 - 000000000 ____D C:\Program Files\Sublime Text 3
2022-10-20 20:04 - 2022-10-21 10:41 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\Sublime Text 3
2022-10-20 17:27 - 2022-10-20 17:31 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visual Studio Code
2022-10-20 17:27 - 2022-10-20 17:27 - 000001465 _____ C:\Users\gide.nkouka\Desktop\Visual Studio Code.lnk
2022-10-17 13:20 - 2022-10-17 13:20 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\MPC-HC

==================== Un mois (modifiés) ==================

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2022-11-14 14:54 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-11-14 14:50 - 2022-04-08 14:41 - 000000000 ____D C:\FRST
2022-11-14 14:34 - 2017-12-27 10:56 - 000000000 ____D C:\Program Files (x86)\Google
2022-11-14 14:33 - 2021-07-03 16:38 - 000000000 ____D C:\WINDOWS\Minidump
2022-11-14 14:33 - 2019-12-07 10:12 - 000000000 ____D C:\WINDOWS\INF
2022-11-14 14:30 - 2018-12-18 15:55 - 000000000 ____D C:\Users\gide.nkouka\AppData\Local\CrashDumps
2022-11-14 14:30 - 2017-01-10 13:30 - 000000000 ____D C:\ProgramData\AVAST Software
2022-11-14 14:14 - 2017-01-10 14:53 - 000000000 ___RD C:\Users\gide.nkouka\OneDrive
2022-11-14 14:09 - 2017-01-10 14:51 - 000000000 __SHD C:\Users\gide.nkouka\IntelGraphicsProfiles
2022-11-14 14:08 - 2018-05-10 11:44 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2022-11-14 14:06 - 2021-06-28 17:53 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-11-14 14:06 - 2021-06-28 15:07 - 000008192 ___SH C:\DumpStack.log.tmp
2022-11-14 14:06 - 2021-06-28 15:07 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-11-14 13:24 - 2021-06-28 15:15 - 000000000 ____D C:\Users\gide.nkouka
2022-11-14 13:24 - 2018-05-16 17:13 - 000000000 ____D C:\Users\gide.nkouka\AppData\LocalLow\Mozilla
2022-11-14 12:53 - 2022-02-09 13:09 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-11-14 12:09 - 2018-12-18 15:57 - 000000000 ____D C:\Users\gide.nkouka\AppData\Local\AVAST Software
2022-11-14 11:49 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2022-11-14 11:35 - 2019-12-07 10:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2022-11-14 11:13 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-11-14 11:12 - 2020-05-30 13:21 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-11-14 11:12 - 2020-05-30 13:21 - 000002280 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2022-11-14 11:12 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-11-14 10:24 - 2021-06-28 17:53 - 000003690 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-11-14 10:24 - 2021-06-28 17:53 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-11-13 07:11 - 2019-01-03 08:52 - 000000000 ____D C:\Users\gide.nkouka\AppData\Local\D3DSCache
2022-11-11 11:56 - 2022-05-21 14:01 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-11-11 11:22 - 2018-12-19 00:33 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-11-10 18:37 - 2022-03-23 16:28 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\obs-studio
2022-11-10 16:23 - 2017-01-10 16:07 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\vlc
2022-11-10 15:25 - 2021-06-28 15:13 - 001975034 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-11-10 15:25 - 2019-12-07 15:50 - 000867650 _____ C:\WINDOWS\system32\perfh00C.dat
2022-11-10 15:25 - 2019-12-07 15:50 - 000183408 _____ C:\WINDOWS\system32\perfc00C.dat
2022-11-10 13:54 - 2021-06-28 15:07 - 005123352 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-11-10 13:50 - 2019-12-07 15:53 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-11-10 13:50 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2022-11-10 13:50 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-11-10 13:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-11-10 13:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-11-10 13:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-11-10 13:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-11-10 13:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-11-10 13:41 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-11-10 12:08 - 2021-06-28 15:11 - 003014656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-11-10 09:42 - 2018-12-20 11:41 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-11-10 09:42 - 2018-07-06 11:42 - 146960040 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-11-09 13:08 - 2021-08-26 09:50 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-11-09 10:56 - 2017-01-10 14:51 - 000000000 ____D C:\Users\gide.nkouka\AppData\Local\Packages
2022-11-09 10:23 - 2022-01-26 18:04 - 000003596 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3371038503-1723060537-3163575906-1001
2022-11-09 10:23 - 2021-12-11 13:57 - 000003596 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2987775730-2434628737-2840101130-3813
2022-11-09 10:23 - 2021-06-28 17:53 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-11-09 10:23 - 2021-06-28 15:15 - 000000000 ____D C:\Users\Azur
2022-11-09 10:22 - 2022-05-27 16:58 - 000002170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-11-08 14:01 - 2017-01-10 14:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-11-08 12:56 - 2021-10-11 12:23 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-11-08 12:55 - 2018-07-30 15:55 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-11-08 11:14 - 2021-09-22 16:16 - 000002057 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2022-11-08 11:14 - 2021-09-22 16:16 - 000001899 _____ C:\Users\Default\Desktop\Google Slides.lnk
2022-11-08 11:14 - 2021-09-22 16:16 - 000001899 _____ C:\Users\Default\Desktop\Google Sheets.lnk
2022-11-08 11:14 - 2021-09-22 16:16 - 000001887 _____ C:\Users\Default\Desktop\Google Docs.lnk
2022-11-07 07:23 - 2017-01-10 11:49 - 000000000 __RHD C:\Users\Public\AccountPictures
2022-11-01 12:24 - 2020-03-27 12:17 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\Code
2022-10-24 10:42 - 2022-10-14 11:07 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2022-10-24 10:42 - 2022-10-14 11:07 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2022-10-24 10:42 - 2021-06-29 07:33 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-10-21 13:39 - 2017-01-10 13:34 - 000000000 ____D C:\ProgramData\Adobe
2022-10-21 11:08 - 2017-01-10 14:51 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\Adobe
2022-10-20 14:00 - 2018-05-08 15:24 - 000000000 ____D C:\Users\gide.nkouka\AppData\Roaming\WhatsApp
2022-10-18 09:22 - 2018-12-07 12:05 - 000001544 _____ C:\Users\gide.nkouka\Desktop\Command Prompt.lnk
2022-10-16 07:54 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports

==================== Fichiers à la racine de certains dossiers ========

2018-02-16 14:27 - 2018-02-16 14:29 - 000000132 _____ () C:\Users\gide.nkouka\AppData\Roaming\Préfs Format BMP Adobe CS6
2020-04-30 14:10 - 2020-05-10 23:20 - 000000132 _____ () C:\Users\gide.nkouka\AppData\Roaming\Préfs Format GIF Adobe CS6
2017-02-08 08:50 - 2022-06-26 08:55 - 000000132 _____ () C:\Users\gide.nkouka\AppData\Roaming\Préfs Format PNG Adobe CS6
2019-02-19 17:11 - 2019-05-28 09:54 - 000038532 _____ () C:\Users\gide.nkouka\AppData\Roaming\Valeurs séparées par une virgule.ADR
2017-02-03 18:03 - 2020-05-05 15:22 - 000001456 _____ () C:\Users\gide.nkouka\AppData\Local\Adobe Enregistrer pour le Web 13.0 Prefs
2019-03-31 20:40 - 2019-03-31 20:40 - 000000000 _____ () C:\Users\gide.nkouka\AppData\Local\BIT7EE8.tmp
2019-03-26 07:20 - 2019-03-26 07:20 - 000000000 _____ () C:\Users\gide.nkouka\AppData\Local\BITBE49.tmp
2019-03-23 14:49 - 2019-03-23 14:49 - 000000000 _____ () C:\Users\gide.nkouka\AppData\Local\BITC63B.tmp
2019-03-23 14:49 - 2019-03-23 14:49 - 000000000 _____ () C:\Users\gide.nkouka\AppData\Local\BITC66B.tmp
2018-05-11 18:52 - 2019-07-30 13:56 - 000000600 _____ () C:\Users\gide.nkouka\AppData\Local\PUTTY.RND
2018-10-25 20:09 - 2018-11-22 10:40 - 000017408 _____ () C:\Users\gide.nkouka\AppData\Local\WebpageIcons.db

==================== SigCheck ============================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

==================== Fin de FRST.txt ========================

Publicité


Signaler le contenu de ce document

Publicité