Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 29-06-2021 Exécuté par Administrateur (administrateur) sur DESKTOP-09JMCHM (30-06-2021 19:07:58) Exécuté depuis C:\Users\JeanClaude\Desktop 2 Profils chargés: JeanClaude & Administrateur Platform: Windows 10 Home Version 20H2 19042.1052 (X64) Langue: Français (France) Navigateur par défaut: Edge Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) () [Fichier non signé] C:\Program Files (x86)\Orange\wifi d'Orange\{9d78a505-6248-4d1b-81b6-df69655beccf}\OrangeWifi.exe () [Fichier non signé] C:\Program Files (x86)\Orange\wifi d'Orange\{9d78a505-6248-4d1b-81b6-df69655beccf}\UpdteApp.exe (0) C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_4.1.6.0_x64__8wekyb3d8bbwe\Microsoft.Notes.exe (0) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21042.143.0_x64__8wekyb3d8bbwe\YourPhone.exe (0) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.21061.10121.0_x64__8wekyb3d8bbwe\Video.UI.exe (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avanquest UK Ltd -> Avanquest Software) C:\Program Files\Expert PDF 14\creator\common\creator-ws.exe (Avanquest UK Ltd -> Avanquest Software) C:\Program Files\Expert PDF 14\updater-ws.exe (Avanquest UK Ltd -> Avanquest Software) C:\Program Files\Expert PDF 14\ws.exe (Canon Inc. -> Canon INC.) C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.5-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.5-0\NisSrv.exe (Orange -> Orange) [Fichier non signé] C:\Users\JeanClaude\AppData\Roaming\Orange\OrangeInside\OrangeInside.exe (philandro Software GmbH -> philandro Software GmbH) C:\Program Files (x86)\AnyDesk\AnyDesk.exe <3> (PhotoFiltre) [Fichier non signé] C:\Program Files (x86)\PhotoFiltre Studio X\pfstudiox.exe (SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIPKE.EXE <2> (Sony Nordic (Sweden), Filial till Sony Europe B.V.(NL) -> Sony) C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe (Sony) [Fichier non signé] C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe 0 C:\Program Files\WindowsApps\22450.ImageResizerforWindows10_2.0.0.0_x64__0aqw1zw0x2snt\huaImageResizer.exe 0 C:\Program Files\WindowsApps\AppleInc.iCloud_12.4.103.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe 0 C:\Program Files\WindowsApps\AppleInc.iTunes_12113.17.53090.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe 0 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxOutlook.exe 0 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe\HxTsr.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9235936 2017-08-10] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [Start_OrangeWifi_{9d78a505-6248-4d1b-81b6-df69655beccf}] => C:\Program Files (x86)\Orange\wifi d'Orange\{9d78a505-6248-4d1b-81b6-df69655beccf}\OrangeWifi.exe [1944064 2014-03-26] () [Fichier non signé] HKLM-x32\...\Run: [Start_Update_{9d78a505-6248-4d1b-81b6-df69655beccf}] => C:\Program Files (x86)\Orange\wifi d'Orange\{9d78a505-6248-4d1b-81b6-df69655beccf}\UpdteApp.exe [1013760 2014-03-26] () [Fichier non signé] HKLM-x32\...\Run: [CheckUpdate] => C:\ProgramData\Update\fmaj5.exe [613888 2014-05-02] () [Fichier non signé] HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files (x86)\Microsoft OneDrive\Update\OneDriveSetup.exe" HKLM-x32\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files (x86)\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" HKU\S-1-5-21-2179091637-2390061930-682908365-1001\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Audials\Audials 2021\AudialsNotifier.exe [2201296 2021-05-14] (Audials AG -> ) HKU\S-1-5-21-2179091637-2390061930-682908365-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIPKE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) HKU\S-1-5-21-2179091637-2390061930-682908365-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [50041472 2021-03-12] (Google LLC -> ) HKU\S-1-5-21-2179091637-2390061930-682908365-1001\...\Run: [EPLTarget\P0000000000000001] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIPKE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) HKU\S-1-5-21-2179091637-2390061930-682908365-1001\...\Run: [XperiaCompanionAgent] => C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe [1700928 2021-01-21] (Sony Nordic (Sweden), Filial till Sony Europe B.V.(NL) -> Sony) HKU\S-1-5-21-2179091637-2390061930-682908365-1001\...\MountPoints2: {fc243a54-ceae-11e9-b97f-1c1b0da9c79f} - "H:\startme.exe" HKU\S-1-5-21-2179091637-2390061930-682908365-500\...\Run: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe [1976184 2021-06-28] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-2179091637-2390061930-682908365-500\...\Run: [Avanquest Message] => C:\Users\Administrateur\AppData\Local\Avanquest\Avanquest Message\AQNotif.exe [594800 2021-03-18] (Avanquest Software SAS -> Avanquest Software) HKU\S-1-5-21-2179091637-2390061930-682908365-500\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [50041472 2021-03-12] (Google LLC -> ) HKU\S-1-5-21-2179091637-2390061930-682908365-500\...\Run: [XperiaCompanionAgent] => C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe [1700928 2021-01-21] (Sony Nordic (Sweden), Filial till Sony Europe B.V.(NL) -> Sony) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG4200 series: C:\WINDOWS\system32\CNMLMB9.DLL [389120 2012-03-26] (CANON INC.) [Fichier non signé] HKLM\...\Print\Monitors\Canon BJ Language Monitor MG4200 series XPS: C:\WINDOWS\system32\CNMXLMB9.DLL [392192 2012-03-26] (CANON INC.) [Fichier non signé] HKLM\...\Print\Monitors\EPSON XP-830 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMBPKE.DLL [180224 2014-03-05] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.124\Installer\chrmstp.exe [2021-06-25] (Google LLC -> Google LLC) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2021-03-29] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> philandro Software GmbH) Startup: C:\Users\JeanClaude\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\EOS Utility.lnk [2020-04-14] ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Canon Inc. -> Canon INC.) Startup: C:\Users\JeanClaude\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\Lanceur.lnk [2019-10-21] ShortcutTarget: Lanceur.lnk -> C:\Program Files (x86)\Micro Application\LauncherMA.exe (Micro Application) [Fichier non signé] HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Tâches planifiées (Avec liste blanche) ============ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {1CDE1FD9-8797-4A2D-AE74-93F962A1C7D5} - System32\Tasks\{6DD5EC17-2753-6087-C935-2D1F12E55D13} => C:\Users\JEANCL~1\AppData\Local\NIDOKU~1\PAGUKO~1.EXE <==== ATTENTION Task: {3BE6E4F4-88A9-498A-9AEF-F7D45DD44D28} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.) Task: {3D99EA80-7B47-4330-A89C-62636F4EA62C} - System32\Tasks\Microsoft\Windows\OrangeUpdate_Install => C:\Program Files (x86)\Orange Update\install.bat [0 2019-03-06] () <==== ATTENTION Task: {4165FD58-FD67-4EAA-A6C7-FD231DBBB8A9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-22] (Google Inc -> Google LLC) Task: {47DBF632-A63B-4A00-8A26-9F339C9EF121} - System32\Tasks\DriverHubUACDisablingTask => C:\Program Files (x86)\DriverHub\DriverHub.exe Task: {5A2EC46E-1BD2-462B-ADCE-72124246B830} - System32\Tasks\EPSON XP-830 Series Update {FAB4E806-93B4-47AC-9C6A-BB0392AE9C85} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPKE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) Task: {63016A73-05BC-4EFD-B50C-F80BE28B9F4B} - System32\Tasks\Microsoft\Windows\orangeinside => C:\Users\JeanClaude\AppData\Roaming\Orange\OrangeInside\OrangeInside.exe [1913072 2019-09-24] (Orange -> Orange) [Fichier non signé] Task: {6C290EED-898F-406F-BADA-41F3E7EE8CDC} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [754472 2021-04-05] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.) Task: {716A88D5-BE0A-4136-A2A1-6F4F16843A2E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.5-0\MpCmdRun.exe [644880 2021-06-26] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {81484DDC-F843-4D60-BE42-D3517521C94E} - System32\Tasks\Microsoft\Windows\OrangeUpdate_Launch => Command(1): Net -> stop "Orange Update Core Service" Task: {81484DDC-F843-4D60-BE42-D3517521C94E} - System32\Tasks\Microsoft\Windows\OrangeUpdate_Launch => Command(2): Net -> start "Orange Update Core Service" Task: {88B73CC8-CEE9-4789-BD16-97732D8FB7F1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.5-0\MpCmdRun.exe [644880 2021-06-26] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {8A83B288-41E9-4D00-A60B-8AF91BA91EFB} - System32\Tasks\Opera scheduled Autoupdate 1541478382 => C:\Users\JeanClaude\AppData\Local\Programs\Opera\launcher.exe Task: {A1F2DC5A-368D-4DA6-8BA8-9DA9B580AEF1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.5-0\MpCmdRun.exe [644880 2021-06-26] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {AEAFF5AC-F948-4C94-A020-8F31528B53B6} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [2822520 2021-06-28] (Microsoft Corporation -> Microsoft Corporation) Task: {DC228122-BCFE-42B0-881D-3E05CD0AE0BB} - System32\Tasks\EPSON XP-830 Series Update {A92673C1-1D50-4F63-A101-A50C48A0D0E4} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPKE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) Task: {EC26CD90-E6E5-4D64-9299-69DFD3262E8A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-22] (Google Inc -> Google LLC) Task: {F6FBA2C2-69E1-48B8-889C-10B86E7FE3F1} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {F8F4F5AA-4DA7-49E1-9EFE-F91A7E71BC2D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.5-0\MpCmdRun.exe [644880 2021-06-26] (Microsoft Windows Publisher -> Microsoft Corporation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\EPSON XP-830 Series Update {A92673C1-1D50-4F63-A101-A50C48A0D0E4}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPKE.EXE:/EXE:{A92673C1-1D50-4F63-A101-A50C48A0D0E4} /F:UpdateWORKGROUP\DESKTOP-09JMCHM$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\EPSON XP-830 Series Update {FAB4E806-93B4-47AC-9C6A-BB0392AE9C85}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPKE.EXE:/EXE:{FAB4E806-93B4-47AC-9C6A-BB0392AE9C85} /F:UpdateWORKGROUP\DESKTOP-09JMCHM$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\{6DD5EC17-2753-6087-C935-2D1F12E55D13}.job => C:\Users\JEANCL~1\AppData\Local\NIDOKU~1\PAGUKO~1.EXE <==== ATTENTION ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{3d0def18-e90b-4c9e-b507-e568fbf72598}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{5fb09def-6614-49e7-81d3-df3c6007f3bf}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{f3bb9d51-23a6-4ac3-8d0d-333935baa7bb}: [DhcpNameServer] 192.168.137.129 Tcpip\..\Interfaces\{fa565868-4a66-4d27-82aa-ad4a53727919}: [DhcpNameServer] 192.168.1.1 Edge: ======= Edge Notifications: HKU\S-1-5-21-2179091637-2390061930-682908365-1001 -> hxxps://www.facebook.com; hxxps://mail.google.com; hxxps://wikiclic.com Edge DefaultProfile: Default Edge Profile: C:\Users\Administrateur\AppData\Local\Microsoft\Edge\User Data\Default [2021-02-07] Edge Notifications: Default -> hxxps://filmora.wondershare.com; hxxps://videoconverter.wondershare.com FireFox: ======== FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2019-09-13] [] [non signé] FF Plugin: @java.com/DTPlugin,version=11.281.2 -> C:\Program Files\Java\jre1.8.0_281\bin\dtplugin\npDeployJava1.dll [2021-03-26] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.281.2 -> C:\Program Files\Java\jre1.8.0_281\bin\plugin2\npjp2.dll [2021-03-26] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-05-28] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2179091637-2390061930-682908365-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\JeanClaude\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2019-10-22] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) Chrome: ======= CHR Profile: C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default [2020-04-14] CHR HomePage: Default -> qwant.com CHR StartupUrls: Default -> "hxxps://docs.microsoft.com/fr-fr/windows-server/storage/disk-management/overview-of-disk-management","hxxps://www.google.com/","hxxps://www.google.com/","hxxps://www.google.com/","hxxps://fr.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=87dpyqptgki1320egikmoq9ay004219¶m1=y6bdVFVIsvuYsgEClQfz8GNAvS%2FuW585f43SFov1egEnLPxpPTiE%2FbXt5%2BAHq6dYwQRzovpyPEybg%2BQYKUHQ6FTbGp%2FBP4ZLziywg9ZJpZXWinx%2F2xzfG%2BWnupCT%2FCeK0eNEGH%2FCr%2B8Yfvt9yS7zW5aIXTpYnihqG%2F%2Bc25VVbMNx8uUodk6pRyoF0uP15DQct4%2FgFdfIc%2BCVqz6X493BoVx%2B2%2FjjG7oJtmT%2BGmhOgdMKAgD6RhWRPf6dUt8n9STEJWeSWKcujS1QDZrkpRSA%2B2r9F79NrvjUhlTTlXAawFLH1aNJ1IzBvXNr7cqRJvok5Tr44DNCNSsnjxv%2FDzXxFr3%2Bidlv%2FEz9YDkA6OkLERvMxX%2B3jeDwnMouBuSuNkqFfUZomjJHGrHcY%2F5avmIh%2BoWhnlZyJ46N53wyrF4HqcE%3D" CHR NewTab: Default -> Active:"chrome-extension://jdlnhgjcehghpjmemkjbkhgpeblojiaj/ntp1.html", Active:"chrome-extension://ibpijdjmndlnijflckapeengbnkfnacj/ntp1.html" CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/yhs/search?hspart=omr&hsimp=yhs-001&type=87dpyqptgki1320egikmoq9ay004219¶m1=y6bdVFVIsvuYsgEClQfz8GNAvS%2FuW585f43SFov1egEnLPxpPTiE%2FbXt5%2BAHq6dYwQRzovpyPEybg%2BQYKUHQ6FTbGp%2FBP4ZLziywg9ZJpZUTofqCHIp%2FkeSVjIISuUe00Sndl%2BeGU6bIsjZmN6N9G70yxmnkPsKUGPd7c1wij2QXeeCWe2awYgCcy%2Bj8ojRyA%2BK0Dly8CE5uIm0D%2BljGJcujuh4SVVsrqE%2F3f%2BDcIwDROI8Oim0KxA3wuCgtXye7QXqWuz8QPGficfCZgdcMpUzcA220HClBBcPeuIkpBv%2FYMHR3DXnekEWI%2Fehiqnn9OzkRS7fTM2LWd2qLYc9H%2FiESjs5f07gsms3Qzbb3kkgHe983yLoEJ6xaeW9c77Lndo1L%2F38uS0ecQXe123bmGQ%3D%3D&p={searchTerms} CHR DefaultSearchKeyword: Default -> search.yahoo.com CHR DefaultNewTabURL: Default -> hxxps://fr.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=87dpyqptgki1320egikmoq9ay004219¶m1=y6bdVFVIsvuYsgEClQfz8GNAvS%2FuW585f43SFov1egEnLPxpPTiE%2FbXt5%2BAHq6dYwQRzovpyPEybg%2BQYKUHQ6FTbGp%2FBP4ZLziywg9ZJpZU%2BWjL3a5F%2B6LaLZiFuAjNFbB%2FZmU4TyqJwjlrJOsfRN20bd%2FLAS4%2FE2WE4THmSrqWvvDxaFXUOHBpyLdChC2dGAu%2BitZVXp%2Fs%2BoqJmTULtlP8vU3Lb8JX5o3ySxMIR49CTUADp25YkJrcmSIJP5VUpicmgA3jIyzzT205SQiPlW2AOmDWvPTk5qhHTeLFbSnCNQt5WSV4MduXWzcMXge7b0%2FePNTCgGPpPMnA9a6b%2BpGoHX0sD5FtuG4x2z4nAwtHYP%2FmTuhZv2NmDnzWmZwjouIie%2BsqRRofz3IPk%2Ftws5A%3D%3D CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms} CHR Extension: (Slides) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-14] CHR Extension: (Docs) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-14] CHR Extension: (Google Drive) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-04-14] CHR Extension: (Beauty) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbbelgoeoihcmnkgkeanmogncgkfichm [2020-04-14] CHR Extension: (OnlineWorkSuite) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcdhacjdengeibbbhmdjodiecaiciehc [2020-04-14] CHR Extension: (Safe Site de Total AV) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdbgahnlbdodjkejgilbpflbhgchdfni [2020-04-14] CHR Extension: (FromDocToPDF) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bidmloagildlhkkiabgfdhpgkmhmgjho [2020-04-14] CHR Extension: (YouTube) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-14] CHR Extension: (MapMyWayFree) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bonnlkdeoibjfmdjkkboihalnacmfhoj [2020-04-14] CHR Extension: (DownSpeedTest) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\cepfmncolcdiadbbbphfjhjgojoiekhd [2020-04-14] CHR Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-04-14] CHR Extension: (Adobe Acrobat) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-04-14] CHR Extension: (Outlook) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\eigpmdhekjlgjgcppnanaanbdmnlnagl [2020-04-14] CHR Extension: (EasyPDFCombine for Chrome) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekamneaohnpkfjaffmimdhgbpdablhbn [2020-04-14] CHR Extension: (Avast Passwords) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2020-04-14] CHR Extension: (Search Extension by Ask) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\eocnnoackodjagdbaoddhjbkpjabimed [2020-04-14] CHR Extension: (Avast SafePrice | Comparaison, offres, coupons) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2020-04-14] CHR Extension: (Sheets) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-14] CHR Extension: (Barre de Confiance CM-CIC) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffjkhaeogkeelkioellpgcebmekedpag [2020-04-14] CHR Extension: (FileSendSuite) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffkkhnmhakkikpkabfmoejhlohnceknd [2020-04-14] CHR Extension: (McAfee® WebAdvisor) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-04-14] CHR Extension: (Désactivation de Google Analytics) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2020-04-14] CHR Extension: (ProductivityBoss) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmgfhejnhlniacgkjnmakangponnkggd [2020-04-14] CHR Extension: (Google Docs hors connexion) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-14] CHR Extension: (Obtenez Email Facile) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\glllkgblkjnleeedipgdeljcpienpaal [2020-04-14] CHR Extension: (PDF Viewer & Converter by ProPDFConverter) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\glmfdkfmoamfkgkncklicdngnfabhaim [2020-04-14] CHR Extension: (OneNote Web Clipper) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\gojbdfnpnhogfdgjbigejoaolejmgdhk [2020-04-14] CHR Extension: (Avast Online Security) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2020-04-14] CHR Extension: (Qwant) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnlkiofnhhoahaiimdicppgemmmomijo [2020-04-14] CHR Extension: (Search Manager) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\hppemobdikemkbmccnjbilolonmpaljl [2020-04-14] CHR Extension: (Marine Aquarium Lite) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibpijdjmndlnijflckapeengbnkfnacj [2020-04-14] CHR Extension: (Chrome Remote Desktop) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2020-04-14] CHR Extension: (Search Extension by Ask) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbldcomffojmkkjbblhcebeicbncmjpf [2020-04-14] CHR Extension: (FileSendSuite) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdlnhgjcehghpjmemkjbkhgpeblojiaj [2020-04-14] CHR Extension: (Itineraire - Offres shopping) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlincbpgbkpbjepghokdnhnnpphmegig [2020-04-14] CHR Extension: (Page Captures d'écran Web - Fireshot) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbpblocgmgfnpjjppndjkmgjaogfceg [2020-04-14] CHR Extension: (Search Manager) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [2020-04-14] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-14] CHR Extension: (Search Manager) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\olojcnagmcbplpdddabmpfehhlleobpb [2020-04-14] CHR Extension: (Orange page d'accueil) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\onghofjobpgcdeeifjfbcfepkchnenoh [2020-04-14] CHR Extension: (EasyFileConvert) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\pahplobpnpkkginldibgnocfdnebjhcj [2020-04-14] CHR Extension: (Secured Search Extension) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdpcpceofkopegffcdnffeenbfdldock [2020-04-14] CHR Extension: (Ask Web Search) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\phflngbadmllcaelcfihcadcpjalhdmp [2020-04-14] CHR Extension: (Search Manager) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej [2020-04-14] CHR Extension: (Gmail) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-04-14] CHR Extension: (Chrome Media Router) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-14] CHR Extension: (Download une image) - C:\Users\Administrateur\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkkboomagahhdmhndlkfeeplhpdaidgl [2020-04-14] CHR HKLM\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] CHR HKLM\...\Chrome\Extension: [jdanfkhnfpagoijgfmklhgakdicpnfil] CHR HKLM\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] CHR HKLM\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] CHR HKLM\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\JeanClaude\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2020-03-20] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [jdanfkhnfpagoijgfmklhgakdicpnfil] CHR HKU\S-1-5-21-2179091637-2390061930-682908365-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] CHR HKLM-x32\...\Chrome\Extension: [hppemobdikemkbmccnjbilolonmpaljl] CHR HKLM-x32\...\Chrome\Extension: [jdanfkhnfpagoijgfmklhgakdicpnfil] CHR HKLM-x32\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] CHR HKLM-x32\...\Chrome\Extension: [olojcnagmcbplpdddabmpfehhlleobpb] CHR HKLM-x32\...\Chrome\Extension: [onghofjobpgcdeeifjfbcfepkchnenoh] CHR HKLM-x32\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3780296 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3548360 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [351944 2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [3743464 2021-03-29] (philandro Software GmbH -> philandro Software GmbH) S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\92.0.4515.41\remoting_host.exe [71336 2021-06-01] (Google LLC -> Google LLC) R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation) R3 Expert PDF 14; C:\Program Files\Expert PDF 14\ws.exe [1984584 2021-03-19] (Avanquest UK Ltd -> Avanquest Software) R2 Expert PDF 14 Creator; C:\Program Files\Expert PDF 14\creator\common\creator-ws.exe [711760 2021-03-19] (Avanquest UK Ltd -> Avanquest Software) R2 Expert PDF 14 Update Service; C:\Program Files\Expert PDF 14\updater-ws.exe [1646664 2021-03-19] (Avanquest UK Ltd -> Avanquest Software) S3 FileSyncHelper; C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\FileSyncHelper.exe [2262904 2021-06-28] (Microsoft Corporation -> Microsoft Corporation) S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [82216 2020-06-24] (Mixbyte Inc -> Freemake) S4 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [714712 2017-06-28] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) S3 OneDrive Updater Service; C:\Program Files (x86)\Microsoft OneDrive\21.109.0530.0001\OneDriveUpdaterService.exe [2728312 2021-06-28] (Microsoft Corporation -> Microsoft Corporation) S4 Orange Update Core Service; C:\Program Files (x86)\Orange Update\OUService.exe [166144 2019-03-11] (Orange -> Orange) [Fichier non signé] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12849960 2021-03-15] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.5-0\NisSrv.exe [2665440 2021-06-26] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.5-0\MsMpEng.exe [136640 2021-06-26] (Microsoft Windows Publisher -> Microsoft Corporation) R2 XperiaCompanionService; C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe [2575360 2021-01-21] (Sony) [Fichier non signé] ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices) R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-09-10] (Bluestack Systems, Inc -> Bluestack System Inc.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Fichier non signé] S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [32384 2018-03-14] (Sony Mobile Communications AB -> Sony Mobile Communications) R1 RrNetCapFilterDriver; C:\WINDOWS\system32\DRIVERS\RrNetCapFilterDriver.sys [34608 2019-09-16] (Audials AG -> Audials AG) R3 tbhsd; C:\WINDOWS\system32\drivers\tbhsd.sys [57648 2019-09-16] (Audials AG -> RapidSolution Software AG) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49576 2021-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [425216 2021-06-26] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76000 2021-06-26] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2021-06-30 18:55 - 2021-06-30 19:09 - 000000000 ____D C:\FRST 2021-06-30 18:02 - 2021-06-30 18:02 - 000000000 ____D C:\Users\JeanClaude\AppData\LocalLow\Google 2021-06-30 18:01 - 2021-06-30 18:01 - 000002253 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk 2021-06-30 18:01 - 2021-06-30 18:01 - 000002241 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk 2021-06-29 10:18 - 2021-06-29 10:18 - 000000817 _____ C:\Users\JeanClaude\Documents\Images - Raccourci.lnk 2021-06-28 15:22 - 2021-06-28 15:22 - 000005252 _____ C:\Users\JeanClaude\Documents\Courses à faire.odt 2021-06-26 16:47 - 2021-06-26 16:47 - 011390248 _____ (Tim Kosse) C:\Users\JeanClaude\Downloads\FileZilla_3.54.1_win64-setup.exe 2021-06-14 19:26 - 2021-06-14 19:26 - 000000000 ____D C:\Users\JeanClaude\AppData\Local\PicturesToExe 2021-06-14 19:26 - 2021-06-14 19:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PicturesToExe 7.0 2021-06-14 19:26 - 2021-06-14 19:26 - 000000000 ____D C:\Program Files (x86)\WnSoft PicturesToExe 2021-06-14 19:26 - 2011-09-14 18:01 - 000024832 _____ C:\WINDOWS\SysWOW64\PteVideo.dll 2021-06-12 10:11 - 2021-06-12 10:11 - 000000000 ____D C:\Users\JeanClaude\AppData\Local\LiveCraft 2021-06-11 17:09 - 2021-06-11 17:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint 2021-06-11 17:08 - 2021-06-11 17:08 - 000000000 ____D C:\WINDOWS\PCHEALTH 2021-06-11 17:08 - 2021-06-11 17:08 - 000000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2021-06-11 17:08 - 2021-06-11 17:08 - 000000000 ____D C:\Program Files (x86)\Microsoft Sync Framework 2021-06-11 17:06 - 2021-06-11 17:06 - 000000000 ____D C:\WINDOWS\system32\Tasks\OfficeSoftwareProtectionPlatform 2021-06-11 17:05 - 2021-06-11 17:05 - 000000000 ____D C:\Program Files\Microsoft Office 2021-06-11 17:05 - 2021-06-11 17:05 - 000000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2021-06-11 17:04 - 2021-06-11 17:09 - 000000000 ____D C:\WINDOWS\SHELLNEW 2021-06-11 17:04 - 2021-06-11 17:08 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2021-06-11 17:04 - 2021-06-11 17:04 - 000000000 ____D C:\Users\Administrateur\AppData\Local\Microsoft Help 2021-06-11 17:04 - 2021-06-11 17:04 - 000000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2021-06-11 06:41 - 2021-06-11 06:41 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2021-06-11 06:40 - 2021-06-11 06:40 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2021-06-11 06:40 - 2021-06-11 06:40 - 000011353 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-06-03 08:41 - 2021-06-03 08:41 - 000000000 ____D C:\Users\JeanClaude\Documents\Expert PDF 2021-06-02 20:04 - 2021-06-02 20:04 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2021-06-02 20:04 - 2021-06-02 20:04 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2021-06-02 20:03 - 2021-06-02 20:03 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll 2021-06-02 20:03 - 2021-06-02 20:03 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2021-06-02 20:03 - 2021-06-02 20:03 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll 2021-06-02 20:03 - 2021-06-02 20:03 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2021-06-02 20:03 - 2021-06-02 20:03 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe 2021-06-02 20:02 - 2021-06-02 20:02 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll 2021-06-02 20:02 - 2021-06-02 20:02 - 001823792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2021-06-02 20:02 - 2021-06-02 20:02 - 001393496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2021-06-02 20:02 - 2021-06-02 20:02 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll 2021-06-02 20:02 - 2021-06-02 20:02 - 000097280 _____ C:\WINDOWS\system32\Drivers\cimfs.sys 2021-06-02 20:01 - 2021-06-02 20:01 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2021-06-02 20:01 - 2021-06-02 20:01 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll 2021-06-02 20:01 - 2021-06-02 20:01 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2021-06-30 19:03 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-06-30 19:03 - 2019-10-12 13:45 - 000000000 ___RD C:\Users\JeanClaude\Desktop 2 2021-06-30 18:42 - 2020-09-10 02:47 - 000004186 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{7490B30F-B400-4139-BA50-C8C2139D8CC7} 2021-06-30 18:01 - 2020-03-20 15:53 - 000000000 ____D C:\Program Files\Google 2021-06-30 17:03 - 2020-09-10 02:16 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-06-30 16:57 - 2019-10-04 15:54 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2021-06-30 16:57 - 2019-10-04 15:54 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData 2021-06-30 09:41 - 2020-09-10 02:35 - 001770906 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-06-30 09:41 - 2019-12-07 16:49 - 000791756 _____ C:\WINDOWS\system32\perfh00C.dat 2021-06-30 09:41 - 2019-12-07 16:49 - 000149922 _____ C:\WINDOWS\system32\perfc00C.dat 2021-06-30 09:41 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2021-06-30 09:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2021-06-30 02:16 - 2018-07-20 04:45 - 000000000 ____D C:\ProgramData\Update 2021-06-29 19:18 - 2018-07-19 12:49 - 000000000 ____D C:\Users\JeanClaude\AppData\Roaming\Molotov 2021-06-29 17:43 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-06-29 17:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-06-29 01:29 - 2018-07-20 04:32 - 000000000 ____D C:\Users\JeanClaude\AppData\Local\D3DSCache 2021-06-28 18:36 - 2021-03-31 14:24 - 000003206 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task 2021-06-28 18:36 - 2021-03-31 14:24 - 000002212 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-06-28 18:36 - 2021-03-31 14:24 - 000000000 ___RD C:\Users\Administrateur\OneDrive 2021-06-28 18:36 - 2021-03-31 14:24 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive 2021-06-28 18:36 - 2018-03-15 19:48 - 000000000 ___RD C:\Users\JeanClaude\OneDrive 2021-06-28 15:14 - 2018-03-27 03:02 - 000000000 ___RD C:\Users\JeanClaude\Documents\Chiens garde & réservations 2021-06-28 11:02 - 2018-03-25 09:58 - 000000000 ___RD C:\Users\JeanClaude\Desktop\Divers 2021-06-27 15:16 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-06-27 15:16 - 2019-11-08 12:10 - 000000000 ____D C:\Users\Administrateur\AppData\Local\Packages 2021-06-26 16:48 - 2019-03-14 03:37 - 000000000 ____D C:\Users\JeanClaude\AppData\Roaming\FileZilla 2021-06-26 14:56 - 2020-01-17 04:54 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-06-26 14:55 - 2020-03-17 10:44 - 000002280 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2021-06-26 14:52 - 2018-07-19 10:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2021-06-26 04:48 - 2020-09-10 02:47 - 000003634 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-06-26 04:48 - 2020-09-10 02:47 - 000003510 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-06-24 16:51 - 2020-09-10 02:18 - 000000000 ____D C:\Users\JeanClaude 2021-06-24 16:33 - 2020-09-10 02:47 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-06-24 16:33 - 2020-09-10 02:16 - 000008192 ___SH C:\DumpStack.log.tmp 2021-06-24 16:33 - 2019-03-15 08:57 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2021-06-24 10:32 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-06-19 12:00 - 2019-11-12 23:35 - 000000000 ____D C:\Users\JeanClaude\Documents\ShareX 2021-06-18 10:38 - 2020-09-19 07:57 - 000000000 ____D C:\Users\JeanClaude\Documents\Sony 2021-06-18 10:38 - 2019-09-03 19:00 - 000000000 ___RD C:\Users\JeanClaude\Documents\Notice tel portable 2021-06-16 09:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF 2021-06-13 06:33 - 2021-02-27 01:33 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2021-06-11 17:17 - 2020-04-15 06:05 - 000000000 ____D C:\Program Files (x86)\AnyDesk 2021-06-11 17:15 - 2020-09-10 02:16 - 000774504 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-06-11 17:14 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2021-06-11 17:14 - 2018-07-19 10:56 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin 2021-06-11 17:09 - 2020-09-10 02:34 - 000000000 ____D C:\Program Files (x86)\MSBuild 2021-06-11 17:09 - 2018-03-16 18:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2021-06-11 17:08 - 2018-10-13 09:40 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2021-06-11 17:06 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2021-06-11 17:05 - 2018-07-19 11:33 - 000000167 _____ C:\WINDOWS\win.ini 2021-06-11 07:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-06-11 07:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2021-06-11 07:51 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-06-10 12:05 - 2021-04-24 16:21 - 000001817 _____ C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xenofex 2 Manual.lnk 2021-06-09 21:28 - 2018-07-19 12:29 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-06-09 21:22 - 2018-07-19 12:29 - 132447432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-06-09 18:50 - 2020-04-15 06:04 - 000000000 ____D C:\Users\JeanClaude\AppData\Roaming\AnyDesk 2021-06-09 09:18 - 2018-03-15 22:33 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2021-06-07 17:42 - 2018-07-24 18:53 - 000000000 ___RD C:\Users\JeanClaude\Documents\Papiers maison 2021-06-03 02:18 - 2020-03-21 19:49 - 000009479 _____ C:\Users\JeanClaude\Documents\Course a faire.odt 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX 2021-06-02 20:22 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism ==================== Fichiers à la racine de certains dossiers ======== 2021-03-29 04:48 - 2021-03-29 04:48 - 009080787 _____ () C:\Users\JeanClaude\PPP_III-fr.exe 2020-04-27 11:41 - 2021-04-01 09:59 - 082428480 _____ (Sony) C:\Users\Administrateur\AppData\Local\pcc.exe ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================