Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 19-07-2021 01 Exécuté par Fred (administrateur) sur LAPTOP-2LCM46LC (LENOVO 81DM) (22-07-2021 09:01:08) Exécuté depuis C:\Users\Fred\Desktop Profils chargés: Fred Platform: Windows 10 Home Version 21H1 19043.1110 (X64) Langue: Français (France) Navigateur par défaut: FF Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Brother Industries, Ltd.) [Fichier non signé] C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe (Brother Industries, Ltd.) [Fichier non signé] C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <9> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.92\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.92\GoogleCrashHandler64.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_7c484f80872e1cd8\jhi_service.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_120314e52c04567c\RstMwService.exe (LAVASOFT SOFTWARE CANADA INC -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe (Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\VantageService\LenovoVantageService.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe <2> (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe <2> (LENOVO INC) C:\Program Files\WindowsApps\E0469640.LenovoUtility_4.0.44.0_x64__5grkq8ppsgwt4\LaunchUtility\utility.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\CUAssistant\culauncher.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MsMpEng.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\NisSrv.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <7> (Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3> (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (SweetLabs Inc. -> SweetLabs, Inc) C:\Users\Fred\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Windows\System32\SynTPEnhService.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18390912 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-06-16] (Brother Industries, Ltd.) [Fichier non signé] HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.) [Fichier non signé] HKU\S-1-5-21-3222674123-2028769319-233793147-1002\...\Run: [utweb] => C:\Users\Fred\AppData\Roaming\uTorrent Web\utweb.exe [5649952 2021-02-04] (BitTorrent Inc -> BitTorrent Inc.) HKU\S-1-5-21-3222674123-2028769319-233793147-1002\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [7514200 2019-07-22] (LAVASOFT SOFTWARE CANADA INC -> Lavasoft) HKU\S-1-5-21-3222674123-2028769319-233793147-1002\...\MountPoints2: {2ea53de5-a35a-11e9-adef-00f48de300c6} - "H:\HiSuiteDownLoader.exe" HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.164\Installer\chrmstp.exe [2021-07-21] (Google LLC -> Google LLC) ==================== Tâches planifiées (Avec liste blanche) ============ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {01CF07E6-750D-430B-8109-F052FC478E31} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\0b5256f4-9013-4008-acdd-f678b5be41c7 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81912 2021-06-17] (Lenovo -> Lenovo Group Ltd.) Task: {03946BB5-2730-4977-A554-06AC30B17B24} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor) Task: {26ACEAB3-3E7C-4AD3-BF95-6A06945DEBB0} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\344dc4c1-1125-47b3-bc78-b32bf8bc2e59 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81912 2021-06-17] (Lenovo -> Lenovo Group Ltd.) Task: {2D1CB9ED-698B-41B0-A840-397A28A7A4DC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23182224 2021-07-09] (Microsoft Corporation -> Microsoft Corporation) Task: {2F6EFA34-D8F9-4B2A-9C14-6F880F3F371B} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} Task: {316C380F-9360-44BF-B950-457448750A99} - System32\Tasks\App Explorer => C:\Users\Fred\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7744560 2021-01-20] (SweetLabs Inc. -> SweetLabs, Inc) <==== ATTENTION Task: {37DF73CB-FA58-4E7F-903B-244023CB9530} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32 Task: {3D9FA6DE-384A-44B6-890A-FC1E936E3148} - System32\Tasks\RtHDVBg_LENOVO_DOLBYDRAGON => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor) Task: {3E079E65-041C-4C01-AD10-3F9029410F6C} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412680 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {45F3F2DB-1E0D-4435-8A75-86CDFF215EBA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {5A50EC8A-C404-4879-BAD6-760943B9023A} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-05-02] (Realtek Semiconductor Corp. -> Realtek Semiconductor) Task: {66A89BD6-9BB0-4CAF-BCF5-0CCD4571ED29} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [147304 2021-07-19] (Microsoft Corporation -> Microsoft Corporation) Task: {690A3B07-384B-4F4F-9D66-8BCB5AF51554} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-07] (Google Inc -> Google LLC) Task: {6A7C1034-C38F-49B4-8F2E-C48F72E19972} - System32\Tasks\LenovoUtility Task => C:\Windows\explorer.exe lenovo-utility:// Task: {6CD22F24-225E-4D57-AF90-A721EB87846B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {84245F09-5C34-4A3A-AAB8-D90B7A337AEB} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [682424 2021-07-21] (Mozilla Corporation -> Mozilla Foundation) Task: {8614FB80-66E9-4B6B-9BE7-8F8FF7138726} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.) Task: {90A363C2-234A-4408-81EE-C053C35A9360} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe [144456 2021-05-19] (Lenovo -> Lenovo Group Ltd.) Task: {A46A9698-060C-4406-A8B5-A2394EF664B8} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\60f671c8-f03f-456d-9e4f-b3e74e8e135e => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81912 2021-06-17] (Lenovo -> Lenovo Group Ltd.) Task: {ADE74865-D2CA-4BF6-82D9-83AF85403490} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [62448 2021-06-17] (Lenovo -> Lenovo Group Ltd.) Task: {BD36F6EB-F70F-498A-851D-F531134A6AC9} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23182224 2021-07-09] (Microsoft Corporation -> Microsoft Corporation) Task: {BFB30DC3-0D2A-456B-934B-BFC20426FD02} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\75f9d3d1-3c05-4e9d-9c94-5cb8ce3d1d04 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81912 2021-06-17] (Lenovo -> Lenovo Group Ltd.) Task: {CB6EF0D6-55C5-43BD-92B6-53C8106485D1} - System32\Tasks\AdobeAAMUpdater-1.0-LAPTOP-2LCM46LC-Fred => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated -> Adobe Systems Incorporated) Task: {DE341B2F-EB86-4BA5-B536-FCD616B9A5C1} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1537408 2021-07-19] (Microsoft Corporation -> Microsoft Corporation) Task: {E9A72C81-8E42-4FB7-9C6D-D32BAFF4877D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {EC86D10C-6F5D-4F63-90B3-61E0E999F81C} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [147304 2021-07-19] (Microsoft Corporation -> Microsoft Corporation) Task: {EDF3EBBD-0A49-4774-B799-6694658F02DB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MpCmdRun.exe [644888 2021-07-14] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F002030B-CAF3-4205-B2B5-85965B009BC4} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService Task: {F24F5701-802A-452C-9637-16A4A76D25F9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-07] (Google Inc -> Google LLC) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 Tcpip\..\Interfaces\{304d791f-01f2-44dc-8f7f-5dafc0631871}: [DhcpNameServer] 192.168.0.254 Tcpip\..\Interfaces\{34425971-6ae4-47f9-b6c8-b31c19cb2d4d}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{d2e03ed1-32e2-4ab1-901a-74bd0cb05dfb}: [DhcpNameServer] 150.209.1.2 Edge: ======= Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)] Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)] Edge DefaultProfile: Default Edge Profile: C:\Users\Fred\AppData\Local\Microsoft\Edge\User Data\Default [2021-07-22] FireFox: ======== FF DefaultProfile: pbugtaw0.default-1582667479061 FF ProfilePath: C:\Users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\pbugtaw0.default-1582667479061 [2021-07-22] FF Notifications: Mozilla\Firefox\Profiles\pbugtaw0.default-1582667479061 -> hxxps://teams.microsoft.com FF Extension: (EPUBReader) - C:\Users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\pbugtaw0.default-1582667479061\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}.xpi [2021-01-31] FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.12 -> D:\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> D:\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-05-28] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-06-27] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3222674123-2028769319-233793147-1002: SkypeForBusinessPlugin-15.8 -> C:\Users\Fred\AppData\Local\Microsoft\SkypeForBusinessPlugin\15.8.20020.400\npGatewayNpapi.dll [2015-06-15] (Microsoft Corporation -> Microsoft Corporation) FF Plugin HKU\S-1-5-21-3222674123-2028769319-233793147-1002: SkypeForBusinessPlugin64-15.8 -> C:\Users\Fred\AppData\Local\Microsoft\SkypeForBusinessPlugin\15.8.20020.400\npGatewayNpapi-x64.dll [2015-06-15] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR DefaultProfile: Profile 1 CHR Profile: C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default [2021-07-21] CHR Notifications: Default -> hxxps://join.meetme.bnpparibas; hxxps://meet.google.com; hxxps://www.facebook.com CHR StartupUrls: Default -> "hxxps://mail.google.com/mail/u/0/#inbox" CHR Extension: (Slides) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-07] CHR Extension: (Docs) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-07] CHR Extension: (Google Drive) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-26] CHR Extension: (YouTube) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-07] CHR Extension: (Sheets) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-07] CHR Extension: (Google Docs hors connexion) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-26] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-31] CHR Extension: (Gmail) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-23] CHR Extension: (Chrome Media Router) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-05-27] CHR Profile: C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-07-22] CHR Profile: C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-07-22] CHR Notifications: Profile 1 -> hxxps://meet.google.com CHR Extension: (Slides) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-06-29] CHR Extension: (Docs) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2021-06-29] CHR Extension: (Google Drive) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-06-29] CHR Extension: (YouTube) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-06-29] CHR Extension: (Sheets) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-06-29] CHR Extension: (Google Docs hors connexion) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-29] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-06-29] CHR Extension: (Gmail) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-06-29] CHR Extension: (Chrome Media Router) - C:\Users\Fred\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-29] CHR Profile: C:\Users\Fred\AppData\Local\Google\Chrome\User Data\System Profile [2021-07-22] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3780296 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3548360 2021-02-17] (Adobe Inc. -> Adobe Systems, Incorporated) S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [Fichier non signé] R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9056672 2021-07-08] (Microsoft Corporation -> Microsoft Corporation) R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [189464 2019-01-21] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81912 2021-06-17] (Lenovo -> Lenovo Group Ltd.) R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\LenovoVantageService.exe [18200 2019-07-25] (Lenovo -> Lenovo Group Ltd.) R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [28760 2019-07-22] (LAVASOFT SOFTWARE CANADA INC -> ) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\NisSrv.exe [2665432 2021-07-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2106.6-0\MsMpEng.exe [136640 2021-07-14] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R2 npf; C:\WINDOWS\system32\drivers\npf.sys [36600 2018-12-07] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) R0 PxHlpa64; C:\WINDOWS\System32\drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation -> Corel Corporation) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-07-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [425192 2021-07-14] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76008 2021-07-14] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2021-07-22 09:01 - 2021-07-22 09:04 - 000024945 _____ C:\Users\Fred\Desktop\FRST.txt 2021-07-22 08:59 - 2021-07-22 09:03 - 000000000 ____D C:\FRST 2021-07-22 08:56 - 2021-07-22 08:56 - 000309522 _____ C:\Users\Fred\Desktop\ZHPDiag.txt 2021-07-22 08:49 - 2021-07-22 08:49 - 002300416 _____ (Farbar) C:\Users\Fred\Desktop\FRST64.exe 2021-07-22 08:38 - 2021-07-22 08:56 - 000000000 ____D C:\Users\Fred\AppData\Roaming\ZHP 2021-07-22 08:38 - 2021-07-22 08:38 - 000000871 _____ C:\Users\Fred\Desktop\ZHPSuite.lnk 2021-07-22 08:38 - 2021-07-22 08:38 - 000000000 ____D C:\Users\Fred\AppData\Local\ZHP 2021-07-22 08:37 - 2021-07-22 08:37 - 003473048 _____ (Nicolas Coolman) C:\Users\Fred\Desktop\ZHPSuite.exe 2021-07-21 16:36 - 2021-07-21 16:36 - 001617342 _____ C:\Users\Fred\Downloads\Trame de reporting du contrôle permanent aux instances.pdf 2021-07-21 16:33 - 2021-07-21 16:33 - 000497644 _____ C:\Users\Fred\Desktop\REGENERATION_-_Votre_nouvel_avenant_de_télétr.pdf 2021-07-21 16:32 - 2021-07-21 16:32 - 000497644 _____ C:\Users\Fred\Downloads\REGENERATION_-_Votre_nouvel_avenant_de_télétr.pdf 2021-07-21 16:00 - 2021-07-21 16:01 - 021230458 _____ C:\Users\Fred\Downloads\P7121351.zip 2021-07-21 15:54 - 2021-07-21 15:54 - 021230458 _____ C:\Users\Fred\Desktop\P7121351.zip 2021-07-21 10:57 - 2021-07-21 10:57 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2021-07-21 10:03 - 2021-07-21 10:57 - 000000000 ____D C:\Program Files\Mozilla Firefox 2021-07-21 09:40 - 2021-07-21 09:40 - 000061924 _____ C:\Users\Fred\Desktop\Attestation assurance.pdf 2021-07-20 22:21 - 2021-07-20 22:21 - 011390248 _____ (Tim Kosse) C:\Users\Fred\Downloads\FileZilla_3.54.1_win64-setup.exe 2021-07-20 15:12 - 2021-07-20 15:12 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsraLegacy.tlb 2021-07-20 15:12 - 2021-07-20 15:12 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsraLegacy.tlb 2021-07-20 15:12 - 2021-07-20 15:12 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rendezvousSession.tlb 2021-07-20 15:12 - 2021-07-20 15:12 - 000006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\rendezvousSession.tlb 2021-07-20 15:09 - 2021-07-20 15:09 - 000452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2021-07-20 15:09 - 2021-07-20 15:09 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2021-07-20 15:09 - 2021-07-20 15:09 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2021-07-20 15:08 - 2021-07-20 15:08 - 002371072 _____ C:\WINDOWS\system32\rdpnano.dll 2021-07-20 15:08 - 2021-07-20 15:08 - 001314128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2021-07-20 15:08 - 2021-07-20 15:08 - 000570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2021-07-20 15:08 - 2021-07-20 15:08 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-07-20 15:06 - 2021-07-20 15:06 - 001823280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2021-07-20 15:06 - 2021-07-20 15:06 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2021-07-20 15:06 - 2021-07-20 15:06 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe 2021-07-20 15:05 - 2021-07-20 15:05 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll 2021-07-20 15:05 - 2021-07-20 15:05 - 000097792 _____ C:\WINDOWS\system32\Drivers\cimfs.sys 2021-06-29 15:02 - 2021-06-29 15:02 - 000096043 _____ C:\Users\Fred\Downloads\Scanned from a Xerox Multifunction Device.pdf 2021-06-28 14:19 - 2021-06-28 14:19 - 004934554 _____ C:\Users\Fred\Downloads\Conseil de surveillance FFG 2020 06 19.zip 2021-06-28 10:00 - 2021-06-28 10:00 - 000150295 _____ C:\Users\Fred\Downloads\1964_21306_questionnaire_PATTYN_Maxence_2021-06-28_09-59-16.pdf 2021-06-23 15:15 - 2021-06-23 15:15 - 000047616 _____ C:\Users\Fred\Downloads\itg.xls ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2021-07-22 08:48 - 2019-04-07 21:58 - 000000000 ____D C:\Program Files (x86)\Google 2021-07-22 08:40 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-07-22 08:27 - 2019-10-03 11:48 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2021-07-22 08:18 - 2019-04-07 21:35 - 000000000 ____D C:\Users\Fred\AppData\Local\Host App Service 2021-07-22 08:17 - 2019-04-12 11:22 - 000000000 ____D C:\Users\Fred\AppData\Local\Adobe 2021-07-22 08:17 - 2019-04-07 21:55 - 000000000 ____D C:\ProgramData\Mozilla 2021-07-22 08:16 - 2019-04-07 21:55 - 000000000 ____D C:\Users\Fred\AppData\LocalLow\Mozilla 2021-07-22 08:15 - 2019-04-07 21:37 - 000000000 __SHD C:\Users\Fred\IntelGraphicsProfiles 2021-07-21 23:39 - 2020-09-29 01:47 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-07-21 22:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-07-21 22:03 - 2020-06-17 16:06 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-07-21 22:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-07-21 15:36 - 2019-07-03 19:36 - 000000000 ____D C:\Users\Fred\AppData\Roaming\vlc 2021-07-21 15:08 - 2021-03-18 11:09 - 000000000 ____D C:\Users\Fred\Desktop\RACI 2021 Exercice 2020 2021-07-21 13:28 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2021-07-21 10:57 - 2019-04-07 21:55 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2021-07-21 10:57 - 2019-04-07 21:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2021-07-21 10:53 - 2020-09-29 02:10 - 001770910 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-07-21 10:53 - 2019-12-07 16:49 - 000793016 _____ C:\WINDOWS\system32\perfh00C.dat 2021-07-21 10:53 - 2019-12-07 16:49 - 000150146 _____ C:\WINDOWS\system32\perfc00C.dat 2021-07-21 10:49 - 2020-09-29 01:47 - 000438080 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-07-21 10:48 - 2020-09-29 02:30 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-07-21 10:48 - 2020-09-29 01:46 - 000008192 ___SH C:\DumpStack.log.tmp 2021-07-21 10:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState 2021-07-21 10:47 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-07-21 10:44 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System 2021-07-21 08:46 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-07-20 22:22 - 2019-04-15 21:40 - 000000600 _____ C:\Users\Fred\AppData\Local\PUTTY.RND 2021-07-20 22:22 - 2019-04-11 22:33 - 000000000 ____D C:\Users\Fred\AppData\Roaming\FileZilla 2021-07-20 22:09 - 2020-09-26 23:08 - 000000000 ___HD C:\$WinREAgent 2021-07-19 22:58 - 2019-04-07 21:41 - 000000000 ___RD C:\Users\Fred\OneDrive 2021-07-19 22:57 - 2020-09-29 02:30 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3222674123-2028769319-233793147-1002 2021-07-19 22:57 - 2020-09-29 01:58 - 000002421 _____ C:\Users\Fred\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-07-19 00:05 - 2019-04-10 21:06 - 000000000 ____D C:\Program Files\Microsoft Office 2021-07-19 00:02 - 2020-09-29 01:58 - 000000000 ____D C:\Users\Fred 2021-07-18 23:57 - 2019-04-10 21:39 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-07-18 23:47 - 2019-04-10 21:39 - 133422552 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-07-18 23:43 - 2020-09-29 02:30 - 000003588 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2021-07-18 23:43 - 2020-09-29 02:30 - 000003464 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2021-07-18 23:23 - 2018-04-17 21:02 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2021-07-14 16:42 - 2019-04-12 11:25 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2021-07-12 22:06 - 2019-05-30 17:41 - 000000000 ____D C:\Users\Fred\AppData\Local\ElevatedDiagnostics 2021-06-30 17:14 - 2019-04-07 21:37 - 000000000 ____D C:\Users\Fred\AppData\Local\Packages 2021-06-30 14:16 - 2021-03-04 09:53 - 000003540 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d7018956b8da76 2021-06-30 14:16 - 2020-09-29 02:30 - 000003634 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA ==================== Fichiers à la racine de certains dossiers ======== 2020-01-02 18:49 - 2020-12-17 11:04 - 000000600 _____ () C:\Users\Fred\AppData\Roaming\PUTTY.RND 2019-04-18 21:09 - 2019-04-18 21:09 - 000000000 _____ () C:\Users\Fred\AppData\Local\oobelibMkey.log 2019-04-15 21:40 - 2021-07-20 22:22 - 000000600 _____ () C:\Users\Fred\AppData\Local\PUTTY.RND ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================