Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 09-05-2021 Exécuté par Louis (administrateur) sur LAPTOP-AQO9BFAD (Acer Nitro AN515-52) (10-05-2021 18:06:13) Exécuté depuis C:\Users\Louis\Downloads Profils chargés: Louis Platform: Windows 10 Home Version 2004 19041.928 (X64) Langue: Français (France) Navigateur par défaut: Chrome Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\NitroSense Service\PSAdminAgent.exe (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\NitroSense Service\PSAgent.exe (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\NitroSense Service\PSSvc.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1065.0\AvastBrowserCrashHandler.exe (Avast Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1065.0\AvastBrowserCrashHandler64.exe (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <13> (ICEpower a/s -> ICEpower) C:\Windows\System32\ICEsoundService64.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel(R) Extreme Tuning Utility -> Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\IntelCpHDCPSvc.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0b3e3ed3ace9602a\IntelCpHeciSvc.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_e335ebb186115025\RstMwService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Users\Louis\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dfrgui.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2011.6-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2011.6-0\NisSrv.exe (Nicolas Coolman -> Nicolas Coolman) [Fichier non signé] C:\Users\Louis\AppData\Roaming\ZHP\ZHPSuite.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2> (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2> (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.bin (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7> (Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [319544 2019-01-03] (Intel(R) Rapid Storage Technology -> Intel Corporation) HKLM\...\Run: [AvastUI.exe] => "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19677472 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_ASC] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [876032 2018-09-05] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe" HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645648 2019-10-05] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-311598115-2797514746-1928613779-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [44024 2019-07-08] (Glarysoft LTD -> Glarysoft Ltd) HKU\S-1-5-21-311598115-2797514746-1928613779-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4087528 2021-04-12] (Valve -> Valve Corporation) HKU\S-1-5-21-311598115-2797514746-1928613779-1001\...\Run: [Chromium] => "c:\users\louis\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session HKLM\...\Print\Monitors\Wondershare PDFelement Monitor: C:\WINDOWS\system32\PEPrinterMonitor.dll [285216 2021-01-28] (Wondershare Technology Co.,Ltd -> Wondershare Software) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.93\Installer\chrmstp.exe [2021-04-27] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\90.0.9316.94\Installer\chrmstp.exe [2021-05-07] (Avast Software s.r.o. -> AVAST Software) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\87.1.7549.89\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Tâches planifiées (Avec liste blanche) ============ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {0E05D834-1FD5-4A81-88F6-D87A56CEC8E4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-12] (Google Inc -> Google LLC) Task: {12C2AF0E-5E6C-4218-B9F6-AC3F335F9549} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1791712 2021-04-05] (Avast Software s.r.o. -> Avast Software) Task: {1C810A72-41D8-4C4F-B294-83190AF14FDB} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe Task: {2133608D-5027-430F-A0EC-45FD77A2B716} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security Ultra\Upgrade.exe [2162328 2020-07-24] (NortonLifeLock Inc. -> NortonLifeLock Inc.) Task: {24404663-F869-44A9-A256-C00AD72A1C2D} - System32\Tasks\Oem\AcerJumpstartTask => C:\Program Files (x86)\Acer\Acer Jumpstart\hermes.exe Task: {286EF18D-A4C5-4414-82B9-2521DDC8C4B9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-12] (Google Inc -> Google LLC) Task: {5F93FE90-4A44-48FB-A875-F9AAE68EC700} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe Task: {809BF82D-F87D-48D5-B35B-85497EC3D118} - System32\Tasks\NitroSense => C:\Program Files (x86)\Acer\NitroSense Service\PSLauncher.exe [580416 2018-09-10] (Acer Incorporated -> Acer Incorporated) Task: {983806F2-CBFC-4143-A0A9-BB0EC9398EE1} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194200 2020-09-17] (Avast Software s.r.o. -> AVAST Software) Task: {AA426E9C-CB1E-4F2B-8998-44F3926C514F} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194200 2020-09-17] (Avast Software s.r.o. -> AVAST Software) Task: {BC2AA5D0-836F-472B-A31C-1DC21D169CFC} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [473880 2020-07-16] (Acer Incorporated -> Acer Incorporated) Task: {D0A3F9EA-F994-4DC2-BC51-FA9828D79F02} - System32\Tasks\bookingDesktopAppUpdateTaskMachineUA => C:\Program Files (x86)\bookingDesktopApp\Update\bookingDesktopAppUpdate.exe Task: {DA15D2AB-975C-4785-9E21-C6EC45398D79} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2229072 2021-04-27] (Avast Software s.r.o. -> AVAST Software) Task: {E6E4F314-A9F8-4452-B220-C9C28F0BBD82} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [2229072 2021-04-27] (Avast Software s.r.o. -> AVAST Software) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{1d4a907a-384a-4a8e-b0df-b068b34bedf3}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{2c2fda16-5628-445d-a72d-bcf6406d30ed}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{4123aeb3-f47a-4032-8165-b68b223efd38}: [DhcpNameServer] 192.168.1.1 Edge: ======= DownloadDir: C:\Users\Louis\Downloads Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)] Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)] Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)] Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)] Edge Profile: C:\Users\Louis\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-10] Edge StartupUrls: Default -> "hxxps://fr.search.yahoo.com/yhs/web?hspart=ner&hsimp=yhs-001&type=aee_84d015defd161c9282¶m1=ArFaIWxoNqArQGMVADwgQGR7B7NoN9InxrFbMmYsQGMVw7ofB6poNqAqAXFaIWQBvmE4ICILNopcGWUIvmE3vGYYwVRdJaYXNVM4J6k4vmldISk4NVA3vmIWwVQ3vCILNVJdESk8NUM9Jmk4wVM4J6ILNFdbDSk8vFE9ImoVvmo9ImIVwVA4ISIXwV5cGWUWvmFcJmoUNEA4JmILNFdcIaUXNEBcGqQANFdcFCk8NoM4JmoUNVBdJ6IVNVRdJCIXwVw4IGYXNVA4JmISNVNdISIXNVQ9I6IYwVM4JqYWwVxdIWYWvmk4ICoWwVM4ICk3NVU9ISk4vFNbFCILNF9cIqUXNolcEqULNopcGWUIvmFbF6oVwVQ4ISoXNEY9ISIVvmk9I6oXvFNcFmoVwVw4IGUFwVU3vCISNEM3vqUGNEM9IaUGNENcFmoVwVI9JaUHvmo4ICIVvmpcFWQIwV5dJGYNvmE4ICILNFRbDqUDNEJcFaULvmE9GqUINolcJqUJNEQ3wCIWvFI4JmoXvFE9ISIVwVI3vmoXQGR7B6RoN9J7MaJ8MaB7LXFbMnVoN9I4ATsux81cLE1aLU08xTIuADwgxSQdCaZdCaZdQGR7y6MuwnEbQGMVNGZfNXFbMn0aQGMVE7ofAT06xbFbJqVdQGQXHT0gAJ%3D%3D¶m2=MqB9MatcMaB5" Edge DefaultSearchURL: Default -> hxxps://www.bing.com/search?q={searchTerms}&FORM={referrer:source}&PC=ACTS Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] FireFox: ======== FF DefaultProfile: 4vsp14t2.default FF ProfilePath: C:\Users\Louis\AppData\Roaming\Mozilla\Firefox\Profiles\4vsp14t2.default [2021-05-09] FF ProfilePath: C:\Users\Louis\AppData\Roaming\Mozilla\Firefox\Profiles\lhwcslnr.default-release [2021-05-10] FF Extension: (Français Language Pack) - C:\Users\Louis\AppData\Roaming\Mozilla\Firefox\Profiles\lhwcslnr.default-release\Extensions\langpack-fr@firefox.mozilla.org.xpi [2021-05-09] FF Extension: (Malwarebytes Browser Guard) - C:\Users\Louis\AppData\Roaming\Mozilla\Firefox\Profiles\lhwcslnr.default-release\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2021-05-09] FF Extension: (Amazon Assistant for Firefox) - C:\Program Files\Mozilla Firefox\distribution\extensions\abb-acer@amazon.com.xpi [2017-12-09] [UpdateUrl:hxxps://s3-us-west-2.amazonaws.com/ubp-ubpextension-us-prod/vendor-update/firefox/acer1/updates.json] FF Extension: (Français Language Pack) - C:\Program Files\Mozilla Firefox\distribution\extensions\langpack-fr@firefox.mozilla.org.xpi [2018-09-05] FF Extension: (Mozilla Partner Defaults) - C:\Program Files\Mozilla Firefox\distribution\extensions\partnerdefaults@mozilla.com [2019-04-07] [] FF Plugin-x32: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2020-01-12] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2020-01-12] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1065.0\npAvastBrowserUpdate3.dll [2020-09-17] (Avast Software s.r.o. -> AVAST Software) FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1065.0\npAvastBrowserUpdate3.dll [2020-09-17] (Avast Software s.r.o. -> AVAST Software) Chrome: ======= CHR Profile: C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default [2021-05-10] CHR Extension: (Slides) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-07-12] CHR Extension: (Docs) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-07-12] CHR Extension: (Google Drive) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-20] CHR Extension: (YouTube) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-07-12] CHR Extension: (Avast SafePrice | Comparaison, offres, coupons) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2021-05-10] CHR Extension: (Sheets) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-07-12] CHR Extension: (Manga VF) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpbbepbobgjeaklhfcnfdekallaejacl [2020-08-25] CHR Extension: (Google Docs hors connexion) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-04-14] CHR Extension: (Avast Online Security) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2021-02-17] CHR Extension: (Anime Manga VF) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhpbkipmelclpcokejciomdcmbkhfgjg [2020-08-29] CHR Extension: (Anime / Manga VF) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\iglaohlpogmnhpdpaodefcljmbdgjnpc [2019-12-23] CHR Extension: (Malwarebytes Browser Guard) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-05-09] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29] CHR Extension: (Gum Gum Streaming Anime) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojjdkdghcnilmoamakfghebejfffnphp [2020-11-25] CHR Extension: (Gmail) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22] CHR Extension: (Chrome Media Router) - C:\Users\Louis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-22] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194200 2020-09-17] (Avast Software s.r.o. -> AVAST Software) S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [194200 2020-09-17] (Avast Software s.r.o. -> AVAST Software) S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\90.0.9316.94\elevation_service.exe [1396968 2021-04-27] (Avast Software s.r.o. -> AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8894752 2021-01-28] (BattlEye Innovations e.K. -> ) R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [189464 2019-01-21] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7391408 2021-05-09] (Malwarebytes Inc -> Malwarebytes) S2 NortonSecurity; C:\Program Files\Norton Security\Engine\22.20.5.39\NortonSecurity.exe [344760 2020-07-24] (Symantec Corporation -> Symantec Corporation) S2 nsWscSvc; C:\Program Files\Norton Security\Engine\22.20.5.39\nsWscSvc.exe [1056096 2020-07-24] (NortonLifeLock Inc. -> NortonLifeLock Inc.) R3 PSSvc; C:\Program Files (x86)\Acer\NitroSense Service\PSSvc.exe [717120 2018-09-10] (Acer Incorporated -> Acer Incorporated) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\NisSrv.exe [2491880 2021-02-08] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2011.6-0\MsMpEng.exe [128376 2021-02-08] (Microsoft Windows Publisher -> Microsoft Corporation) S2 ACCSvc; "C:\Program Files (x86)\Acer\Care Center\ACCSvc.exe" [X] S3 QALSvc; "C:\Program Files\Acer\Quick Access Service\QALSvc.exe" [X] S3 QASvc; "C:\Program Files\Acer\Quick Access Service\QASvc.exe" [X] S3 UEIPSvc; "C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UBTService.exe" [X] ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 AcerAirplaneModeController; C:\WINDOWS\System32\drivers\AcerAirplaneModeController.sys [30168 2020-05-12] (Acer Incorporated -> Acer Incorporated) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S3 BEDaisy; C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys [3383936 2021-03-30] (BattlEye Innovations e.K. -> ) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Fichier non signé] S1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [28936 2019-07-12] (Glarysoft LTD -> Glarysoft Ltd) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-05-10] (Malwarebytes Inc -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-03-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-05-10] (Malwarebytes Inc -> Malwarebytes) R3 MpKslae0f8a5a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30C723AD-4DF9-4775-BC91-C88660D7C89A}\MpKslDrv.sys [47336 2021-05-10] (Microsoft Windows -> Microsoft Corporation) R3 MpKslef7570cb; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A07E5807-4EB3-4C72-B425-E2EFA88E17ED}\MpKslDrv.sys [47344 2021-05-10] (Microsoft Windows -> Microsoft Corporation) R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2021-02-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [429296 2021-02-08] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [70896 2021-02-08] (Microsoft Windows -> Microsoft Corporation) S4 SymEvnt; \??\C:\Program Files\Norton Security\NortonData\22.16.1.4\SymPlatform\SymEvnt.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2021-05-10 18:05 - 2021-05-10 18:05 - 002298880 _____ (Farbar) C:\Users\Louis\Downloads\FRST64 (1).exe 2021-05-10 17:56 - 2021-05-10 17:56 - 005170176 _____ C:\Users\Louis\Downloads\windows-defender_windows_defender_1.1.1593.0_francais_13691.msi 2021-05-10 17:54 - 2021-05-10 17:54 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2021-05-10 17:54 - 2021-05-10 17:54 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2021-05-10 17:53 - 2021-05-10 17:53 - 012612600 _____ (AVAST Software) C:\Users\Louis\Downloads\avastclear.exe 2021-05-10 16:42 - 2021-05-10 16:42 - 013036984 _____ (NortonLifeLock Inc.) C:\Users\Louis\Downloads\NRnR.exe 2021-05-10 12:26 - 2021-05-10 12:27 - 000042716 _____ C:\Users\Louis\Downloads\Addition.txt 2021-05-10 12:24 - 2021-05-10 18:06 - 000024177 _____ C:\Users\Louis\Downloads\FRST.txt 2021-05-10 12:24 - 2021-05-10 18:06 - 000000000 ____D C:\FRST 2021-05-10 12:23 - 2021-05-10 12:24 - 002298880 _____ (Farbar) C:\Users\Louis\Downloads\FRST64.exe 2021-05-10 10:15 - 2021-05-10 10:16 - 000000000 ____D C:\AdwCleaner 2021-05-10 10:01 - 2021-05-10 10:01 - 003327128 _____ (Nicolas Coolman) C:\Users\Louis\Downloads\ZHPCleaner.exe 2021-05-09 20:33 - 2021-05-10 10:01 - 000000000 ____D C:\Users\Louis\AppData\Local\ZHP 2021-05-09 20:33 - 2021-05-09 20:33 - 003469464 _____ (Nicolas Coolman) C:\Users\Louis\Downloads\ZHPSuite.exe 2021-05-09 19:42 - 2021-05-10 18:03 - 000000000 ____D C:\Users\Louis\AppData\Roaming\ZHP 2021-05-09 19:42 - 2021-05-09 19:42 - 002105344 _____ C:\Users\Louis\Downloads\ZHPDiag3.exe 2021-05-09 19:31 - 2021-05-09 19:33 - 000000000 ____D C:\Users\Louis\AppData\LocalLow\Mozilla 2021-05-09 19:31 - 2021-05-09 19:33 - 000000000 ____D C:\ProgramData\Mozilla 2021-05-09 19:31 - 2021-05-09 19:31 - 000000000 ____D C:\Users\Louis\AppData\Roaming\Mozilla 2021-05-09 19:31 - 2021-05-09 19:31 - 000000000 ____D C:\Users\Louis\AppData\Local\Mozilla 2021-05-09 19:26 - 2021-05-09 19:26 - 002078632 _____ (Malwarebytes) C:\Users\Louis\Downloads\MBSetup (2).exe 2021-05-09 19:26 - 2021-05-09 19:26 - 002078632 _____ (Malwarebytes) C:\Users\Louis\Downloads\MBSetup (1).exe 2021-05-08 17:58 - 2021-05-08 17:58 - 000000000 ____D C:\Users\Louis\AppData\Local\Activision 2021-05-07 19:43 - 2021-05-07 19:43 - 000000000 ____D C:\Users\Louis\AppData\LocalLow\SEVER 2021-04-28 17:10 - 2021-04-28 17:10 - 003006782 _____ C:\Users\Louis\Downloads\Riot.odt 2021-04-19 22:37 - 2021-04-19 22:37 - 006836330 _____ C:\Users\Louis\Downloads\emerald-kaizo-2020-03-14.zip 2021-04-15 10:36 - 2021-04-15 10:36 - 000000000 ____D C:\Users\Louis\AppData\Local\PlaceholderTileLogoFolder 2021-04-14 23:53 - 2021-05-08 08:58 - 000002446 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-04-14 23:53 - 2021-05-08 08:58 - 000002284 _____ C:\ProgramData\Bureau\Microsoft Edge.lnk 2021-04-14 19:42 - 2021-04-14 19:42 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-04-14 19:41 - 2021-04-14 19:41 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2021-04-14 19:41 - 2021-04-14 19:41 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2021-05-10 18:03 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-05-10 18:02 - 2021-02-07 22:27 - 001772726 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-05-10 18:02 - 2019-12-07 16:49 - 000793016 _____ C:\WINDOWS\system32\perfh00C.dat 2021-05-10 18:02 - 2019-12-07 16:49 - 000150146 _____ C:\WINDOWS\system32\perfc00C.dat 2021-05-10 18:02 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2021-05-10 17:55 - 2021-03-18 14:31 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2021-05-10 17:55 - 2021-02-07 22:26 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-05-10 17:55 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2021-05-10 17:55 - 2019-07-12 20:05 - 000000000 ____D C:\Program Files (x86)\Steam 2021-05-10 17:55 - 2019-07-12 19:39 - 000000000 ___RD C:\Users\Louis\OneDrive 2021-05-10 17:55 - 2019-07-12 19:38 - 000000000 __SHD C:\Users\Louis\IntelGraphicsProfiles 2021-05-10 17:55 - 2019-04-07 16:51 - 000000000 ____D C:\ProgramData\NVIDIA 2021-05-10 17:54 - 2019-07-12 19:49 - 000000000 ____D C:\ProgramData\AVAST Software 2021-05-10 17:52 - 2021-02-07 22:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-05-10 16:49 - 2019-04-07 17:06 - 000000000 ____D C:\Program Files\Norton Security 2021-05-10 16:48 - 2019-04-07 17:07 - 000000000 ____D C:\ProgramData\Acer 2021-05-10 16:45 - 2019-04-07 17:06 - 000000000 ____D C:\ProgramData\Norton 2021-05-10 16:45 - 2019-04-07 17:06 - 000000000 ____D C:\Program Files\Common Files\Symantec Shared 2021-05-10 13:04 - 2021-02-07 22:26 - 000004302 _____ C:\WINDOWS\system32\Tasks\Software Update Application 2021-05-10 13:04 - 2021-02-07 22:26 - 000003562 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-05-10 13:04 - 2021-02-07 22:26 - 000003516 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2021-05-10 13:04 - 2021-02-07 22:26 - 000003476 _____ C:\WINDOWS\system32\Tasks\bookingDesktopAppUpdateTaskMachineUA 2021-05-10 13:04 - 2021-02-07 22:26 - 000003338 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-05-10 13:04 - 2021-02-07 22:26 - 000003292 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2021-05-10 13:04 - 2021-02-07 22:26 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-311598115-2797514746-1928613779-1001 2021-05-10 13:04 - 2021-02-07 22:26 - 000002852 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-311598115-2797514746-1928613779-500 2021-05-10 13:04 - 2021-02-07 22:26 - 000002730 _____ C:\WINDOWS\system32\Tasks\ACC 2021-05-10 13:04 - 2021-02-07 22:26 - 000002186 _____ C:\WINDOWS\system32\Tasks\NitroSense 2021-05-10 12:33 - 2021-02-07 22:26 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software 2021-05-10 11:26 - 2021-01-26 21:50 - 000000000 ____D C:\ProgramData\Riot Games 2021-05-10 10:16 - 2019-04-07 17:10 - 000000000 ____D C:\Program Files\Acer 2021-05-10 10:16 - 2019-04-07 17:07 - 000000000 ____D C:\Program Files (x86)\Acer 2021-05-09 20:42 - 2021-03-25 21:17 - 000000000 ____D C:\Riot Games 2021-05-09 19:30 - 2021-03-18 14:32 - 000002037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2021-05-09 19:30 - 2021-03-18 14:32 - 000002025 _____ C:\ProgramData\Bureau\Malwarebytes.lnk 2021-05-09 19:19 - 2019-04-07 17:10 - 000000000 ____D C:\Program Files\Mozilla Firefox 2021-05-09 19:17 - 2020-05-01 13:25 - 000001064 _____ C:\ProgramData\Bureau\WinRAR.lnk 2021-05-09 19:17 - 2020-05-01 13:25 - 000000000 ____D C:\Program Files\WinRAR 2021-05-09 19:17 - 2020-04-12 20:34 - 000000000 ____D C:\Users\Louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2021-05-09 19:17 - 2020-04-12 20:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2021-05-09 19:14 - 2019-07-12 20:04 - 000000000 ____D C:\Program Files (x86)\Glary Utilities 5 2021-05-09 18:50 - 2021-02-07 22:26 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update 2021-05-08 16:09 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-05-08 16:09 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-05-08 08:58 - 2021-02-07 22:20 - 000002405 _____ C:\Users\Louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-05-07 07:58 - 2019-07-12 20:29 - 000002500 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk 2021-05-07 07:58 - 2019-07-12 20:29 - 000002465 _____ C:\ProgramData\Bureau\Avast Secure Browser.lnk 2021-05-04 11:27 - 2020-10-01 14:34 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2021-05-03 22:15 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2021-04-29 12:58 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2021-04-29 12:56 - 2019-04-07 17:10 - 000001009 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2021-04-18 14:28 - 2019-07-13 18:57 - 000000000 ____D C:\Users\Louis\AppData\Local\CrashDumps 2021-04-15 10:46 - 2021-03-18 14:31 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2021-04-15 10:35 - 2019-07-12 19:38 - 000000000 ____D C:\Users\Louis\AppData\Local\Packages 2021-04-14 23:52 - 2021-02-07 22:18 - 000458296 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-04-14 23:52 - 2021-02-07 22:18 - 000008192 ___SH C:\DumpStack.log.tmp 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2021-04-14 23:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-04-14 19:44 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-04-14 19:41 - 2021-02-07 22:18 - 002877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2021-04-14 19:32 - 2019-07-12 22:42 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-04-14 19:30 - 2019-07-12 22:42 - 131963968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-04-10 21:27 - 2019-09-17 03:56 - 000000000 ____D C:\Users\Louis\AppData\Local\Ubisoft Game Launcher ==================== Fichiers à la racine de certains dossiers ======== 2020-05-13 00:31 - 2020-05-13 00:31 - 024166400 _____ () C:\Program Files (x86)\GUT5451.tmp 2020-05-12 14:31 - 2020-05-12 14:31 - 024166400 _____ () C:\Program Files (x86)\GUT59FC.tmp 2020-05-12 19:31 - 2020-05-12 19:31 - 024166400 _____ () C:\Program Files (x86)\GUTDFE1.tmp 2020-05-13 09:03 - 2020-05-13 09:03 - 024166400 _____ () C:\Program Files (x86)\GUTE959.tmp ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================