cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 18-11-2022
Exécuté par kelle (administrateur) sur DESKTOP-V4KV8DE (Micro-Star International Co., Ltd MS-7B86) (22-11-2022 17:00:05)
Exécuté depuis C:\Users\kelle\Desktop
Profils chargés: kelle
Plate-forme: Microsoft Windows 10 Famille Version 21H1 19043.2130 (X64) Langue: Français (France)
Navigateur par défaut: FF
Mode d'amorçage: Normal

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MpCopyAccelerator.exe
(Discord Inc. -> Discord Inc.) C:\Users\kelle\AppData\Local\Discord\app-1.0.9007\Discord.exe <6>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe
(explorer.exe ->) (TradingView, Inc.) C:\Program Files\WindowsApps\TradingView.Desktop_1.0.17.3495_x64__n534cwy3pjxzj\TradingView.exe <13>
(H:\Games\Riot Games\Riot Client\RiotClientServices.exe ->) () [Fichier non signé] H:\Games\Riot Games\Riot Client\RiotClientCrashHandler.exe
(H:\Games\Riot Games\Riot Client\RiotClientServices.exe ->) (Riot Games, Inc. -> Riot Games) H:\Games\Riot Games\VALORANT\live\VALORANT.exe
(H:\Games\Riot Games\VALORANT\live\ShooterGame\Binaries\Win64\VALORANT-Win64-Shipping.exe ->) (Riot Games, Inc. -> Epic Games, Inc.) H:\Games\Riot Games\VALORANT\live\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(H:\Games\Riot Games\VALORANT\live\VALORANT.exe ->) (Riot Games, Inc. -> CN) H:\Games\Riot Games\VALORANT\live\ShooterGame\Binaries\Win64\VALORANT-Win64-Shipping.exe
(Mozilla Corporation -> Mozilla Corporation) H:\Mozilla Firefox\firefox.exe <13>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Riot Games, Inc. -> Riot Games, Inc.) H:\Games\Riot Games\Riot Client\RiotClientServices.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_df0bee9f4cb9436e\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_74518f403e753586\RtkAudUService64.exe <2>
(services.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgc.exe
(services.exe ->) (Scarlet.Crush Productions) [Fichier non signé] H:\Games\Manette PS3\ScpServer\bin\ScpService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registre (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_74518f403e753586\RtkAudUService64.exe [1219312 2020-12-23] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [3089288 2022-11-10] (Riot Games, Inc. -> Riot Games, Inc.)
HKLM-x32\...\Run: [TeamsMachineUninstallerLocalAppData] => C:\Users\kelle\AppData\Local\Microsoft\Teams\Update.exe [2452136 2020-09-30] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKLM-x32\...\Run: [TeamsMachineUninstallerProgramData] => %ProgramData%\Microsoft\Teams\Update.exe --uninstall --msiUninstall --source=default (Pas de fichier)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [711288 2022-09-15] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1979507956-2582305970-3245874469-1001\...\Run: [Discord] => C:\Users\kelle\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub)
HKU\S-1-5-21-1979507956-2582305970-3245874469-1001\...\Run: [SearchFilter] => C:\ProgramData\SearchFilter\SearchFilter.vbs [157 2017-08-27] () [Fichier non signé]
HKU\S-1-5-21-1979507956-2582305970-3245874469-1001\...\Run: [BakkesMod] => "H:\Games\Bakkesmod\BakkesMod\BakkesMod.exe" (Pas de fichier)
HKU\S-1-5-21-1979507956-2582305970-3245874469-1001\...\Run: [WallpaperEngine] => "C:\Users\kelle\AppData\Local\Temp\Rar$EXa11768.10022\Wallpaper.Engine.v1.4.140\wallpaper_engine\wallpaper32.exe" -silent (Pas de fichier) <==== ATTENTION
HKU\S-1-5-21-1979507956-2582305970-3245874469-1001\...\Run: [MicrosoftEdgeAutoLaunch_7463FF2906FF297BC5194F0B09A1BF9F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3892168 2022-11-17] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1979507956-2582305970-3245874469-1001\...\MountPoints2: {bbd4b841-fb48-11ea-b6a9-309c23e45921} - "D:\HiSuiteDownLoader.exe"
HKLM\...\Windows x64\Print Processors\Canon TS5000 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDDF.DLL [30720 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\LogMeIn Print Processor: C:\Windows\System32\spool\prtprocs\x64\LMIproc.dll [60416 2016-01-29] (LogMeIn, Inc. -> LogMeIn, Inc.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS5000 series: C:\Windows\system32\CNMLMDF.DLL [485376 2017-12-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\LogMeIn Printer Port Monitor: C:\Windows\system32\LMIport.dll [35328 2016-01-29] (LogMeIn, Inc. -> LogMeIn, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\107.0.5304.107\Installer\chrmstp.exe [2022-11-11] (Google LLC -> Google LLC)
HKLM\Software\...\Authentication\Credential Providers: [{65CD7F9B-E8F3-4bb0-82EB-6F6875B745DF}] -> C:\Windows\system32\LMIinit.dll [2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
GroupPolicy: Restriction ? <==== ATTENTION

==================== Tâches planifiées (Avec liste blanche) ============

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

Task: {1D377BC4-1DF0-4841-9D16-F82E4A399F69} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6637512 2022-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {27C52124-48F6-486B-AB82-8AE161D8BD8F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2021-12-20] (Google LLC -> Google LLC)
Task: {327FBBD5-A5A3-420F-B6FE-7C74457C10D9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MpCmdRun.exe [1567360 2022-11-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {46C2BC55-00F6-4FF3-BA76-D453A8F5401E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114600 2022-11-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {4B5C61BE-4943-4E46-9C54-86A7A4BB0F55} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6637512 2022-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {5350562E-EDA3-46C4-82D7-582989FEDAE7} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26154376 2022-11-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {5DC10197-B4C4-4F1B-B300-FEDC60FC681B} - System32\Tasks\Mozilla\Firefox Default Browser Agent CBADBBDFE4DA1F50 => H:\Mozilla Firefox\default-browser-agent.exe do-task "CBADBBDFE4DA1F50"
Task: {9804A093-7370-47A6-A1EB-0CEC9F22C6F9} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26154376 2022-11-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {9CDF84C1-0082-438D-B6F2-EB3EF6496F7E} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe /from_scheduler:1 (Pas de fichier)
Task: {BBBCB6C3-4502-4394-9657-6E4E18DB826A} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [3834520 2022-11-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {BCC688DA-A3BD-48A7-A9D0-97330DCFBAF4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MpCmdRun.exe [1567360 2022-11-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C071DB37-627B-4F0E-9F3E-123F7F42E1C2} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114600 2022-11-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {D555922B-6983-4E1F-85FF-E7CC6BF58345} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MpCmdRun.exe [1567360 2022-11-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E67BF6F0-E0D0-4BF2-B7C7-E7B94D6B00BD} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_156_Plugin.exe -check plugin (Pas de fichier)
Task: {E8E20773-8CA0-430E-B372-3083D2207A63} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MpCmdRun.exe [1567360 2022-11-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {FB86AAD2-4055-4C2A-96DF-4CF20966A3B4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2021-12-20] (Google LLC -> Google LLC)

(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)


==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.232.67
Tcpip\..\Interfaces\{117107b0-b4e6-4c9c-9245-2cdae42dce4f}: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{8c4fca97-ac4c-4fbe-a184-e92db23294cb}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{a5db6c36-0197-4072-8489-8354738b4bca}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{c003e04c-e91c-48a5-a2d4-7b0dfd871528}: [DhcpNameServer] 192.168.232.67

Edge:
=======
Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)]
Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)]
Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)]
Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)]
Edge Profile: C:\Users\kelle\AppData\Local\Microsoft\Edge\User Data\Default [2022-11-22]

FireFox:
========
FF DefaultProfile: dlz0eoz9.default
FF ProfilePath: C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\tblig8wg.default-release [2022-11-22]
FF Notifications: Mozilla\Firefox\Profiles\tblig8wg.default-release -> hxxps://fr.tradingview.com; hxxps://twitter.com
FF Extension: (Dark Reader) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\tblig8wg.default-release\Extensions\addon@darkreader.org.xpi [2022-10-27]
FF Extension: (Ghostery – Bloqueur de publicité protégeant la vie privée) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\tblig8wg.default-release\Extensions\firefox@ghostery.com.xpi [2022-11-21]
FF Extension: (MetaMask) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\tblig8wg.default-release\Extensions\webextension@metamask.io.xpi [2022-11-16]
FF Extension: (polkadot extension) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\tblig8wg.default-release\Extensions\{7e3ce1f0-15fb-4fb1-99c6-25774749ec6d}.xpi [2022-06-06]
FF Extension: (hide-scrollbars) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\tblig8wg.default-release\Extensions\{a250ed19-05b9-4486-b2c3-535044766b8c}.xpi [2021-06-07]
FF Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\tblig8wg.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-08-30]
FF Extension: (Dark Fox) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\tblig8wg.default-release\Extensions\{e7fe4ffe-f256-4f85-906d-072fdd698585}.xpi [2020-01-13]
FF ProfilePath: C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\dlz0eoz9.default [2022-11-19]
FF DownloadDir: C:\Users\kelle\Downloads
FF NewTab: Mozilla\Firefox\Profiles\dlz0eoz9.default -> hxxp://www.bing.com/?pc=COS2&ptag=D102019-N0600AB91A1A2A71DC4AF78EF&form=CONMHP&conlogo=CT3331955
FF Notifications: Mozilla\Firefox\Profiles\dlz0eoz9.default -> hxxps://0.nextyourcontent.com; hxxps://premium-news-notify.icu
FF Extension: (Ghostery – Bloqueur de publicité protégeant la vie privée) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\dlz0eoz9.default\Extensions\firefox@ghostery.com.xpi [2019-12-04]
FF Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\dlz0eoz9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-10-22]
FF Extension: (Dark Fox) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\dlz0eoz9.default\Extensions\{e7fe4ffe-f256-4f85-906d-072fdd698585}.xpi [2019-05-13]
FF Extension: (wanteeed) - C:\Users\kelle\AppData\Roaming\Mozilla\Firefox\Profiles\dlz0eoz9.default\Extensions\{EDB6A15C-5F8C-4531-92FA-98E988CF233C}.xpi [2019-11-14] [UpdateUrl:hxxps://app.wanteeed.com/extensions/update_firefox.json]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_171.dll [2019-04-13] (Adobe Inc. -> )
FF Plugin: @java.com/DTPlugin,version=11.351.2 -> C:\Program Files\Java\jre1.8.0_351\bin\dtplugin\npDeployJava1.dll [2022-10-22] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.351.2 -> C:\Program Files\Java\jre1.8.0_351\bin\plugin2\npjp2.dll [2022-10-22] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_171.dll [2019-04-13] (Adobe Inc. -> )
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-11-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-03] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR Profile: C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default [2022-11-19]
CHR Extension: (Google Docs hors connexion) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-06-27]
CHR Extension: (XDEFI Wallet) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmeobnfnfcmdkdcmlblgagmfpfboieaf [2022-11-19]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\kelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-12-20]

==================== Services (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8901968 2021-02-24] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12515768 2022-11-15] (Microsoft Corporation -> Microsoft Corporation)
R2 Ds3Service; H:\Games\Manette PS3\ScpServer\bin\ScpService.exe [381952 2014-04-03] (Scarlet.Crush Productions) [Fichier non signé]
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-07-21] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 OfficeSvcManagerAddons; C:\WINDOWS\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [21312 2020-10-14] (Microsoft Windows -> Microsoft Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2575624 2022-07-18] (Electronic Arts, Inc. -> Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3494672 2022-07-18] (Electronic Arts, Inc. -> Electronic Arts)
R3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [10430256 2022-11-10] (Riot Games, Inc. -> Riot Games, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\NisSrv.exe [3191272 2022-11-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2210.6-0\MsMpEng.exe [133544 2022-11-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_df0bee9f4cb9436e\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_df0bee9f4cb9436e\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem

===================== Pilotes (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Fichier non signé]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Fichier non signé]
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 Hamachi; C:\WINDOWS\System32\drivers\Hamdrv.sys [45680 2019-02-11] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
R2 LMIInfo; C:\Windows\system32\drivers\LMIInfo.sys [30432 2017-01-10] (LogMeIn, Inc. -> LogMeIn, Inc.)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S3 tap-tb-0901; C:\WINDOWS\System32\drivers\tap-tb-0901.sys [38656 2019-05-13] (TunnelBear, Inc. -> The OpenVPN Project)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [44896 2018-07-24] (TEFINCOM S.A. -> The OpenVPN Project)
S3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [54896 2018-07-06] (Windscribe Limited -> The OpenVPN Project)
R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [22216888 2022-11-10] (Riot Games, Inc. -> Riot Games, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49616 2022-11-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [469288 2022-11-11] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [95520 2022-11-11] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois (créés) (Avec liste blanche) =========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2022-11-22 17:00 - 2022-11-22 17:00 - 000022106 ____C C:\Users\kelle\Desktop\FRST.txt
2022-11-22 16:59 - 2022-11-22 17:00 - 000000000 ____D C:\FRST
2022-11-22 16:57 - 2022-11-22 16:57 - 002375680 ____C (Farbar) C:\Users\kelle\Desktop\FRST64.exe
2022-11-22 15:50 - 2022-11-22 15:50 - 008791352 ____C (Malwarebytes) C:\Users\kelle\Downloads\adwcleaner_8.4.0.exe
2022-11-22 15:44 - 2022-11-22 15:48 - 000000000 ___DC C:\Users\kelle\AppData\Roaming\ZHP
2022-11-22 15:44 - 2022-11-22 15:44 - 000000906 ____C C:\Users\kelle\Desktop\ZHPDiag.lnk
2022-11-22 15:44 - 2022-11-22 15:44 - 000000000 ___DC C:\Users\kelle\AppData\Local\ZHP
2022-11-22 15:43 - 2022-11-22 15:43 - 003311304 ____C (Nicolas Coolman) C:\Users\kelle\zhpcleaner_2022-11-13-84_fr_433513.exe
2022-11-22 15:41 - 2022-11-22 15:41 - 003305160 ____C (Nicolas Coolman) C:\Users\kelle\Downloads\ZHPCleaner.exe
2022-11-22 15:26 - 2022-11-22 15:26 - 010092544 ____C C:\Users\kelle\Downloads\hamachi.msi
2022-11-22 14:54 - 2022-11-22 14:54 - 000319426 ____C C:\Users\kelle\Downloads\relevé_14 nov. 04 h.pdf
2022-11-22 14:44 - 2022-11-22 14:44 - 000054779 ____C C:\Users\kelle\Downloads\MP Attestation de loyer recto_Attestation résidence verso (homologué 11_2013)_MP Attestation de loyer Recto_Attestation résiden - Attestation de loyer et de résidence en foyer.pdf
2022-11-20 11:09 - 2022-11-20 11:09 - 009776866 ____C C:\Users\kelle\Downloads\7B86vAH.zip
2022-11-18 06:16 - 2022-11-18 06:16 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2022-11-17 17:01 - 2022-11-21 18:19 - 000011372 _____ C:\Users\kelle\Desktop\Comptes.xlsx
2022-11-07 21:26 - 2022-11-07 21:26 - 000000000 ___HD C:\$WinREAgent
2022-10-23 21:40 - 2022-10-23 21:40 - 002260480 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-10-23 21:40 - 2022-10-23 21:40 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2022-10-23 21:40 - 2022-10-23 21:40 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-10-23 21:40 - 2022-10-23 21:40 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2022-10-23 21:40 - 2022-10-23 21:40 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2022-10-23 21:40 - 2022-10-23 21:40 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2022-10-23 21:40 - 2022-10-23 21:40 - 000012253 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-10-23 15:39 - 2022-06-03 05:15 - 001905936 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2022-10-23 15:39 - 2022-06-03 05:15 - 001905936 _____ C:\WINDOWS\system32\vulkaninfo.exe
2022-10-23 15:39 - 2022-06-03 05:15 - 001478416 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2022-10-23 15:39 - 2022-06-03 05:15 - 001478416 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2022-10-23 15:39 - 2022-06-03 05:15 - 001467840 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2022-10-23 15:39 - 2022-06-03 05:15 - 001432320 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2022-10-23 15:39 - 2022-06-03 05:15 - 001432320 _____ C:\WINDOWS\system32\vulkan-1.dll
2022-10-23 15:39 - 2022-06-03 05:15 - 001209408 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2022-10-23 15:39 - 2022-06-03 05:15 - 001145616 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2022-10-23 15:39 - 2022-06-03 05:15 - 001145616 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2022-10-23 15:39 - 2022-06-03 05:12 - 002121696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2022-10-23 15:39 - 2022-06-03 05:12 - 001529920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2022-10-23 15:39 - 2022-06-03 05:12 - 001175712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2022-10-23 15:39 - 2022-06-03 05:12 - 000795736 _____ C:\WINDOWS\system32\nvofapi64.dll
2022-10-23 15:39 - 2022-06-03 05:12 - 000715944 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll
2022-10-23 15:39 - 2022-06-03 05:12 - 000712640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe
2022-10-23 15:39 - 2022-06-03 05:12 - 000636504 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2022-10-23 15:39 - 2022-06-03 05:12 - 000057440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhdap64.dll
2022-10-23 15:39 - 2022-06-03 05:11 - 008610448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2022-10-23 15:39 - 2022-06-03 05:11 - 007713848 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2022-10-23 15:39 - 2022-06-03 05:11 - 005101520 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2022-10-23 15:39 - 2022-06-03 05:11 - 002931872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2022-10-23 15:39 - 2022-06-03 05:11 - 001600672 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2022-10-23 15:39 - 2022-06-03 05:11 - 000981672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2022-10-23 15:39 - 2022-06-03 05:11 - 000792232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2022-10-23 15:39 - 2022-06-03 05:11 - 000456848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe
2022-10-23 15:39 - 2022-06-03 05:10 - 005729744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2022-10-23 15:39 - 2022-06-03 05:09 - 006458880 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2022-10-23 15:39 - 2022-06-03 05:09 - 000850080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe
2022-10-23 15:39 - 2022-06-03 04:42 - 000089337 _____ C:\WINDOWS\system32\nvinfo.pb

==================== Un mois (modifiés) ==================

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2022-11-22 16:59 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2022-11-22 16:40 - 2018-10-14 10:46 - 000000000 ___DC C:\Users\kelle\AppData\Roaming\discord
2022-11-22 16:36 - 2021-05-23 11:44 - 000002517 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2022-11-22 16:36 - 2021-05-23 11:44 - 000002490 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2022-11-22 16:36 - 2021-04-29 19:11 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-11-22 16:36 - 2021-01-09 02:42 - 000000783 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BakkesMod.lnk
2022-11-22 16:36 - 2020-11-08 16:15 - 000002490 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2022-11-22 16:36 - 2020-11-08 16:15 - 000002478 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2022-11-22 16:36 - 2020-06-02 15:29 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2022-11-22 16:36 - 2019-09-11 09:13 - 000001270 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2022-11-22 16:35 - 2020-06-02 15:23 - 000000000 ____D C:\ProgramData\Riot Games
2022-11-22 16:25 - 2021-12-01 22:59 - 000000000 ____D C:\Program Files (x86)\Google
2022-11-22 16:11 - 2020-06-26 21:57 - 001770910 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-11-22 16:11 - 2019-12-07 15:49 - 000791762 _____ C:\WINDOWS\system32\perfh00C.dat
2022-11-22 16:11 - 2019-12-07 15:49 - 000149928 _____ C:\WINDOWS\system32\perfc00C.dat
2022-11-22 16:08 - 2022-02-11 13:25 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-11-22 16:07 - 2018-10-15 18:10 - 000000000 ___DC C:\Users\kelle\AppData\Local\Discord
2022-11-22 16:07 - 2018-10-13 19:30 - 000000000 ___DC C:\Users\kelle\AppData\LocalLow\Mozilla
2022-11-22 16:06 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-11-22 16:04 - 2020-06-26 21:58 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-11-22 16:04 - 2020-06-26 21:53 - 000008192 ___SH C:\DumpStack.log.tmp
2022-11-22 16:04 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-11-22 16:04 - 2018-10-14 08:43 - 000000000 ____D C:\ProgramData\NVIDIA
2022-11-22 16:03 - 2018-10-14 17:18 - 000000000 ___DC C:\Users\kelle\AppData\Roaming\vlc
2022-11-22 15:43 - 2020-06-26 21:35 - 000000000 ___DC C:\Users\kelle
2022-11-22 13:27 - 2020-06-26 21:53 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-11-22 09:09 - 2022-08-11 16:56 - 000000000 ____D C:\Program Files\Riot Vanguard
2022-11-21 09:53 - 2021-12-20 15:55 - 000002248 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-11-21 09:53 - 2020-11-08 16:15 - 000002517 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2022-11-21 09:28 - 2020-04-14 19:56 - 000000000 ___DC C:\Users\kelle\AppData\Local\NitroxLauncher
2022-11-20 19:10 - 2018-10-13 19:37 - 000000000 ___DC C:\Users\kelle\AppData\Local\D3DSCache
2022-11-20 18:32 - 2021-03-16 20:54 - 000000000 ___DC C:\Users\kelle\Downloads\Musique
2022-11-19 11:55 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-11-19 11:54 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-11-19 05:37 - 2022-08-03 13:39 - 000000000 ___DC C:\Users\kelle\AppData\Roaming\.tlauncher
2022-11-19 05:37 - 2022-08-03 13:39 - 000000000 ___DC C:\Users\kelle\AppData\Roaming\.minecraft
2022-11-15 14:59 - 2020-10-02 16:51 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2022-11-13 18:20 - 2018-10-14 12:00 - 000000000 ___DC C:\Users\kelle\AppData\Roaming\obs-studio
2022-11-13 02:43 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-11-12 16:03 - 2020-07-11 13:27 - 000000000 ___DC C:\Users\kelle\Documents\Vie
2022-11-12 01:17 - 2020-07-18 11:33 - 000003690 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-11-12 01:17 - 2020-07-18 11:33 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-11-11 09:50 - 2018-09-15 06:44 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-11-11 00:27 - 2021-12-20 15:55 - 000002207 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-11-10 05:46 - 2021-11-17 08:35 - 000022344 ____C C:\Users\kelle\Desktop\Tableur Crypto .xlsx
2022-11-07 21:27 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-10-23 22:51 - 2020-06-26 21:53 - 000442192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-10-23 22:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-10-23 21:42 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2022-10-23 21:42 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2022-10-23 21:40 - 2020-06-26 21:57 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-10-23 15:40 - 2022-05-17 11:00 - 000000000 ___DC C:\Users\kelle\AppData\Local\NVIDIA
2022-10-23 15:40 - 2018-10-14 08:42 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2022-10-23 01:46 - 2018-10-15 12:24 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-10-23 01:44 - 2018-10-15 12:24 - 147398024 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

==================== Fichiers à la racine de certains dossiers ========

2022-11-22 15:43 - 2022-11-22 15:43 - 003311304 ____C (Nicolas Coolman) C:\Users\kelle\zhpcleaner_2022-11-13-84_fr_433513.exe
2018-10-18 11:17 - 2018-10-18 11:17 - 000000048 ____H () C:\Program Files (x86)\eyvufqwdd8.dat
2021-06-22 22:52 - 2021-11-02 00:19 - 000000032 ____C () C:\Users\kelle\AppData\Roaming\.machineId
2021-06-04 20:42 - 2021-06-04 20:43 - 000005435 ____C () C:\Users\kelle\AppData\Roaming\SpeedRunnersLog.txt
2019-10-14 16:21 - 2019-10-23 11:59 - 000000600 ____C () C:\Users\kelle\AppData\Roaming\winscp.rnd
2019-02-07 19:46 - 2022-03-06 00:54 - 000007620 ____C () C:\Users\kelle\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

==================== Fin de FRST.txt ========================

Publicité


Signaler le contenu de ce document

Publicité