Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 20-10-2021 Exécuté par marite (administrateur) sur DESKTOP-ORFT8T3 (ASUSTeK COMPUTER INC. GL752VW) (21-10-2021 17:51:02) Exécuté depuis G:\ Profils chargés: marite Platform: Microsoft Windows 10 Famille Version 20H2 19042.1288 (X64) Langue: Français (France) Navigateur par défaut: FF Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ROG Gaming Center\ROGGamingKey.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (Conexant Systems LLC -> Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe (Conexant Systems LLC -> Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (Conexant Systems, Inc. -> Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Conexant Systems, Inc. -> Conexant Systems, Inc.) C:\Windows\System32\SASrv.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Flexera Software LLC -> Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe (Flexera Software LLC -> Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe (Hewlett-Packard -> HP Development Company, L.P.) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (ICEpower a/s -> ICEpower) C:\Windows\System32\DriverStore\FileRepository\x40plmwa.inf_amd64_ebba65282f89f8eb\ICEsoundService64.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) [Fichier non signé] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\igfxEM.exe (Intel(R) Software -> Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe (Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe (Intel(R) Software -> Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Users\maite\AppData\Local\Microsoft\OneDrive\21.196.0921.0007\FileCoAuth.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20520.0_x64__8wekyb3d8bbwe\HxOutlook.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20520.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (NortonLifeLock Inc. -> Broadcom) C:\Program Files\Norton Security\Engine\22.21.9.25\NortonSecurity.exe <2> (NortonLifeLock Inc. -> NortonLifeLock Inc.) C:\Program Files\Norton Security\Engine\22.21.9.25\nsWscSvc.exe (NortonLifeLock Inc. -> Symantec Corporation) C:\Program Files\Norton Utilities Premium\x64\LBGovernor.exe (Nuance Communications, Inc. -> Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\Power PDF 21\NPDFLM.exe (NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2> (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Samsung Electronics CO., LTD. -> ) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (TeamViewer -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (WildTangent Inc -> WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [604496 2017-11-24] (Conexant Systems LLC -> Conexant Systems, Inc.) HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] (Samsung Electronics CO., LTD. -> ) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412736 2021-09-07] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM\...\Run: [AdobePSE17AutoAnalyzer] => C:\Program Files\Adobe\Elements 2019 Organizer\Elements Auto Creations 2019.exe [3058696 2018-08-30] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard) HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [331344 2015-07-22] (Hewlett-Packard -> HP Development Company, L.P.) HKLM-x32\...\Run: [PowerPDF Registry Controller] => C:\Program Files (x86)\Nuance\Power PDF 21\RegistryController.exe [274216 2017-05-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [NuanPowerPdf1NPDFLM] => C:\Program Files (x86)\Nuance\Power PDF 21\NPDFLM.exe [3464816 2017-05-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [Nuance Power PDF Standard-reminder] => C:\Program Files (x86)\Nuance\Power PDF 21\Ereg\Ereg.exe [3164280 2016-05-06] (Nuance Communications, Inc. -> Nuance Communications, Inc.) HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [3312208 2019-05-04] (Open Source Developer, Dominik Reichl -> Dominik Reichl) HKLM-x32\...\Run: [WDDiscovery] => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Discovery.exe [81376504 2020-03-25] (Western Digital Technologies, Inc. -> Western Digital Corporation) HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [24720 2019-06-27] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) HKLM-x32\...\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [2311840 2019-06-26] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) HKU\S-1-5-21-2595580047-1136342414-3253307354-1001\...\Run: [STUISpeedLauncher] => C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe [411136 2015-02-09] () [Fichier non signé] HKU\S-1-5-21-2595580047-1136342414-3253307354-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\maite\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" HKU\S-1-5-21-2595580047-1136342414-3253307354-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\maite\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" HKU\S-1-5-21-2595580047-1136342414-3253307354-1001\...\RunOnce: [Uninstall 21.180.0905.0007] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\maite\AppData\Local\Microsoft\OneDrive\21.180.0905.0007" HKLM\...\Windows x64\Print Processors\BJ Print Processor3: C:\Windows\System32\spool\prtprocs\x64\CNBPP3.DLL [83968 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Windows x64\Print Processors\hpcpp155: C:\Windows\System32\spool\prtprocs\x64\hpcpp155.DLL [597792 2013-09-04] (Hewlett-Packard Company -> Hewlett-Packard Corporation) HKLM\...\Windows x64\Print Processors\us005PC: C:\Windows\System32\spool\prtprocs\x64\us005pc.dll [43520 2015-01-29] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider) HKLM\...\Print\Monitors\BJ Language Monitor3_2: C:\Windows\system32\CNBLM3_2.DLL [211456 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\Windows\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [Fichier non signé] HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\94.0.4606.81\Installer\chrmstp.exe [2021-10-08] (Google LLC -> Google LLC) Startup: C:\Users\maite\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Envoyer à OneNote.lnk [2019-08-10] ShortcutTarget: Envoyer à OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation) ==================== Tâches planifiées (Avec liste blanche) ============ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {00D97387-E7A2-41E3-8CB1-186B4815A2FD} - System32\Tasks\TUDsDownloader => C:\Program Files\Norton Utilities Premium\activesync.exe Task: {038005E8-CF40-469D-8518-94277E9F163F} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [54784 2015-12-02] (ASUS) [Fichier non signé] Task: {0702B28F-ED31-4C1B-8357-2A100533CE14} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [746104 2017-11-16] (NVIDIA Corporation -> NVIDIA Corporation) Task: {0D3D83E7-39B2-4E0F-82F6-08233D7C6107} - System32\Tasks\Norton 360\Norton 360 Error Analyzer => C:\Program Files\Norton Security\Engine\22.21.9.25\SymErr.exe [108752 2021-09-29] (NortonLifeLock Inc. -> NortonLifeLock Inc) Task: {1A344A55-061E-4483-B4AC-42F082D5CC8B} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [746104 2017-11-16] (NVIDIA Corporation -> NVIDIA Corporation) Task: {1AC84C02-4ECF-4910-866A-1166406E7CB0} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [1864824 2017-11-16] (NVIDIA Corporation -> NVIDIA Corporation) Task: {2C5DF4BB-465F-4BC3-87E9-51926877B2E2} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [964728 2017-11-16] (NVIDIA Corporation -> NVIDIA Corporation) Task: {2F42A017-3BA0-4E0C-9E5D-EF5C4AFA9F62} - System32\Tasks\Norton 360\Norton 360 Autofix => C:\Program Files\Norton Security\Engine\22.21.9.25\SymErr.exe [108752 2021-09-29] (NortonLifeLock Inc. -> NortonLifeLock Inc) Task: {329705BF-646E-4784-91F8-E062DA50BA37} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19782224 2015-05-25] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {39CD21EB-35CB-4512-AA79-269F27FC6E2F} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [129808 2021-08-13] (Dropbox, Inc -> Dropbox, Inc.) Task: {40C16C89-5B22-4B8C-9C81-473B802B8152} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [129808 2021-08-13] (Dropbox, Inc -> Dropbox, Inc.) Task: {4C498D5E-FF55-4ED5-B04F-CED07AFCEF99} - System32\Tasks\Norton Security with Backup\Norton Security Error Analyzer => C:\Program Files\Norton Security with Backup\Engine\22.20.2.57\SymErr.exe Task: {51490AFD-08C4-46C1-A2EF-5325F6E62DD3} - System32\Tasks\Norton Utility\ActiveSync-NortonUtility => C:\Program Files\Norton Utilities Premium\ActiveBridge.exe Task: {57B689D7-8F8C-4A0E-992F-B9A126FBE9C8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-04] (Google LLC -> Google LLC) Task: {5887560B-FCF8-4338-B0D5-AE107A62F34F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-03-04] (Google LLC -> Google LLC) Task: {5FF22086-EAFB-4F5A-A767-F5ED58362318} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-ORFT8T3-marite => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) Task: {6430CC72-EBF8-4F8C-AF87-2CCE1878ED23} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [1616160 2016-01-19] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) [Fichier non signé] Task: {66BA4689-2D86-4061-B839-0A9D4F527A72} - System32\Tasks\Microsoft\Windows\Conexant\AFA => C:\Program Files\CONEXANT\cAudioFilterAgent\SACpl.exe [1823232 2016-07-05] (Conexant Systems, Inc.) [Fichier non signé] Task: {6FA29E6E-A3F4-4EC8-82BD-7FDC476DBDB6} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {71FB28DC-438B-4B27-BD72-6371F8A1C875} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [680888 2021-10-09] (Mozilla Corporation -> Mozilla Foundation) Task: {74A32973-95C3-46C5-B51D-CC2964F5C33C} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [521336 2017-11-16] (NVIDIA Corporation -> NVIDIA Corporation) Task: {77996AB1-ACC4-4C62-9575-A82787072C68} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [134504 2021-10-19] (Microsoft Corporation -> Microsoft Corporation) Task: {787D3348-1569-43EB-B79A-CBD3900432BE} - System32\Tasks\WD Discovery Service Task marite => C:\Program Files (x86)\Western Digital\Discovery\Current\Service\WDDiscoveryService.exe [75512 2020-03-25] (Western Digital Technologies, Inc. -> ) Task: {852934A2-A44C-40EA-B6EF-6AE70FF4644C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21978504 2021-10-11] (Microsoft Corporation -> Microsoft Corporation) Task: {8877CE76-5E43-4E69-94E0-2EA1CD3536B3} - System32\Tasks\Norton Security with Backup\Norton Security Autofix => C:\Program Files\Norton Security with Backup\Engine\22.20.2.57\SymErr.exe Task: {8890AA39-EA3B-4027-B29D-9225553E3E16} - System32\Tasks\WD Device Agent Task marite => C:\Program Files (x86)\Western Digital\Discovery\Current\WD Device Agent.exe [720632 2020-03-25] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) Task: {89DD2D60-91C9-4872-878A-C569C682F607} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton 360\Upgrade.exe [2353000 2021-09-29] (NortonLifeLock Inc. -> NortonLifeLock Inc.) Task: {8A4CE4B5-F084-4A73-BDFD-E70E8EBD6AE5} - System32\Tasks\Norton 360\Norton 360 Error Processor => C:\Program Files\Norton Security\Engine\22.21.9.25\SymErr.exe [108752 2021-09-29] (NortonLifeLock Inc. -> NortonLifeLock Inc) Task: {8A89E39B-A29F-45BA-BB9C-D0F39A38BDED} - System32\Tasks\Microsoft\Windows\Conexant\SA2 => C:\Program Files\CONEXANT\SAII\SACpl.exe [1832280 2017-06-07] (Conexant Systems, Inc. -> Conexant Systems, Inc.) Task: {8B5F7B8F-CF71-453B-AD43-B1120570D832} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [658040 2017-11-16] (NVIDIA Corporation -> NVIDIA Corporation) Task: {96C03B8A-D2D1-438B-8EA6-B11D48193DDA} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21978504 2021-10-11] (Microsoft Corporation -> Microsoft Corporation) Task: {97F89AAA-5562-432B-9F44-AF5F94018CF2} - System32\Tasks\EPM Preload => C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2DotNetHandler.exe [1335928 2016-08-22] (Samsung Electronics CO., LTD. -> ) Task: {99339CB7-212A-42EA-A240-9075C6738606} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [658040 2017-11-16] (NVIDIA Corporation -> NVIDIA Corporation) Task: {A409C081-0F2D-4FCB-AB27-D534555AFACE} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [585000 2016-09-21] (Dropbox, Inc -> ) Task: {AEF995BE-A2B5-406E-A395-A0ADBEB82913} - System32\Tasks\Live Boost Process Governor => C:\Program Files\Norton Utilities Premium\x64\LBgovernor.exe [1050096 2021-09-16] (NortonLifeLock Inc. -> Symantec Corporation) Task: {B1CF5B33-B9C8-46F4-82AA-7B890183AA40} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {C5889018-2C04-4950-9679-D41D55F459A2} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18416 2015-12-18] (ASUSTeK Computer Inc. -> AsusTek) Task: {CF1917BC-4782-46D9-9F3F-0637815B5BB1} - System32\Tasks\HPLJCustParticipation => C:\Program Files (x86)\HP\HPLJUT\HPLJUTSCH.exe [91728 2015-08-20] (Hewlett-Packard -> HP Development Company, L.P.) Task: {D36893FA-860B-49F2-9415-44E5EE7C4330} - System32\Tasks\Norton Security with Backup\Norton Security Error Processor => C:\Program Files\Norton Security with Backup\Engine\22.20.2.57\SymErr.exe Task: {D3DC3359-CCF2-40AC-B47E-5D35345F2F44} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Security\Engine\22.21.9.25\WSCStub.exe [646520 2021-09-29] (NortonLifeLock Inc. -> NortonLifeLock Inc.) Task: {D99219A1-95A8-42C8-A1D3-0C68D4FC9B16} - System32\Tasks\ROG Gaming Center => C:\Program Files (x86)\ASUS\ROG Gaming Center\ROGGamingKey.exe [3604792 2016-01-08] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {E10CA438-2C65-4D46-9AC1-006D772F34C0} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3412736 2021-09-07] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {EC7BC5D3-C1FD-4D02-9850-61CFABD5C8D0} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1551280 2021-10-19] (Microsoft Corporation -> Microsoft Corporation) Task: {FB60F851-0EA5-443F-895F-52CE91553440} - System32\Tasks\AutomaticCare => C:\Program Files\Norton Utilities Premium\nup.exe [3629552 2021-09-16] (NortonLifeLock Inc. -> NortonLifeLock Inc) Task: {FCFD4684-2F0D-4684-89CE-AC571EEC197C} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519288 2017-11-16] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {FF97A72C-6AE6-4D9C-BE44-068255AEEC27} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [134504 2021-10-19] (Microsoft Corporation -> Microsoft Corporation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{be6ae88a-46f5-4021-9b80-9f72689c4368}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{cbe39d70-6a23-4981-9760-adc1ef3daea3}: [DhcpNameServer] 192.168.1.1 Edge: ======= DownloadDir: C:\Users\maite\Downloads Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)] Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)] Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)] Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)] Edge DefaultProfile: Default Edge Profile: C:\Users\maite\AppData\Local\Microsoft\Edge\User Data\Default [2021-10-20] Edge DownloadDir: Default -> C:\Users\maite\Downloads Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] FireFox: ======== FF DefaultProfile: 8vobi0mj.default FF ProfilePath: C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\hezt4212.default-release-1631601493388 [2021-10-21] FF Notifications: Mozilla\Firefox\Profiles\hezt4212.default-release-1631601493388 -> hxxps//mail.google.com FF Extension: (Norton Safe Search) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\hezt4212.default-release-1631601493388\Extensions\nortonsafesearch_ul_2@symantec.com.xpi [2021-10-13] [UpdateUrl:hxxps//static.nortoncdn.com/idscp/firefox/nsss/ds_modified/updates.json] FF Extension: (Norton Safe Web) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\hezt4212.default-release-1631601493388\Extensions\nortonsafeweb@symantec.com.xpi [2021-09-14] FF Extension: (NoScript) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\hezt4212.default-release-1631601493388\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2021-09-14] FF ProfilePath: C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default [2019-09-26] FF Homepage: Mozilla\Firefox\Profiles\8vobi0mj.default -> hxxps//www.qwant.com/?client=ext-firefox-hp FF HomepageOverride: Mozilla\Firefox\Profiles\8vobi0mj.default -> Enabled: qwantcomforfirefox@jetpack FF Extension: (Norton Password Manager) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default\Extensions\idsafe@norton.com.xpi [2019-09-05] FF Extension: (Norton Safe Search) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default\Extensions\nortonsafesearch_ul_2@symantec.com.xpi [2019-08-05] [UpdateUrl:hxxps//static.nortoncdn.com/idscp/firefox/nsss/ds_modified/updates.json] FF Extension: (Norton Safe Web) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default\Extensions\nortonsafeweb@symantec.com.xpi [2019-08-31] FF Extension: (Oui) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default\Extensions\qwantcomforfirefox@jetpack.xpi [2018-12-18] FF Extension: (Désactivation de Google Analytics) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default\Extensions\{6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}.xpi [2017-11-11] [UpdateUrl:hxxps//tools.google.com/service/update2/ff?guid=%ITEM_ID%&version=%ITEM_VERSION%&application=%APP_ID%&appversion=%APP_VERSION%] FF Extension: (NoScript) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2019-08-20] FF Extension: (Video DownloadHelper) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2019-07-08] FF Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\maite\AppData\Roaming\Mozilla\Firefox\Profiles\8vobi0mj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-08-22] FF Extension: (Nuance PDF Create) - C:\Program Files (x86)\Nuance\Power PDF 21\bin\SFirefoxExtn [2017-07-30] [] FF HKLM\...\Firefox\Extensions: [sweb2pdfextension.3@nuance.com] - C:\Program Files (x86)\Nuance\Power PDF 21\bin\SFirefoxExtn FF HKLM-x32\...\Firefox\Extensions: [sweb2pdfextension.3@nuance.com] - C:\Program Files (x86)\Nuance\Power PDF 21\bin\SFirefoxExtn FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-29] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [Pas de fichier] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [Pas de fichier] FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-08-24] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-08-24] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-05-29] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2015-12-22] (WildTangent Inc -> ) FF Plugin HKU\S-1-5-21-2595580047-1136342414-3253307354-1001: www.mydlink.com/Uplayer -> C:\Users\maite\AppData\Roaming\D-Link\mydlink services plugin\1.0.2.7\npUplayer.dll [2015-12-11] (D-LINK CORPORATION -> D-Link Corporation) Chrome: ======= CHR Profile: C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default [2021-09-12] CHR Notifications: Default -> hxxps//www.facebook.com CHR Extension: (Slides) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-11-14] CHR Extension: (Docs) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-11-14] CHR Extension: (Google Drive) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-11-14] CHR Extension: (YouTube) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-11-14] CHR Extension: (Sheets) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-11-14] CHR Extension: (Google Docs hors connexion) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-08-27] CHR Extension: (Malwarebytes Browser Guard) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-08-27] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-22] CHR Extension: (Gmail) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-11-14] CHR Extension: (Chrome Media Router) - C:\Users\maite\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-08-27] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3833088 2021-09-07] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3603200 2021-09-07] (Adobe Inc. -> Adobe Systems, Incorporated) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9251696 2021-10-11] (Microsoft Corporation -> Microsoft Corporation) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [129808 2021-08-13] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [129808 2021-08-13] (Dropbox, Inc -> Dropbox, Inc.) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [349728 2015-12-22] (WildTangent Inc -> WildTangent) S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [176128 2014-06-24] (HP) [Fichier non signé] R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [288360 2021-05-11] (HP Inc. -> HP Inc.) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Fichier non signé] S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Fichier non signé] S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7785656 2021-09-18] (Malwarebytes Inc -> Malwarebytes) S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2013-05-16] (Hewlett-Packard) [Fichier non signé] R2 NortonSecurity; C:\Program Files\Norton Security\Engine\22.21.9.25\NortonSecurity.exe [343336 2021-09-29] (NortonLifeLock Inc. -> Broadcom) R2 nsWscSvc; C:\Program Files\Norton Security\Engine\22.21.9.25\nsWscSvc.exe [1058664 2021-09-29] (NortonLifeLock Inc. -> NortonLifeLock Inc.) S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2013-05-16] (Hewlett-Packard) [Fichier non signé] S3 ROGGamingCenterService; C:\Program Files (x86)\ASUS\ROG Gaming Center\ROGGamingCenterService.exe [48128 2016-01-08] (ASUSTeK Computer Inc. -> ASUSTeK COMPUTER INC.) S3 SamsungUPDUtilSvc; C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe [143664 2017-07-12] (Samsung Electronics CO., LTD. -> ) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1570520 2016-02-02] (Flexera Software LLC -> Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [837848 2016-02-02] (Flexera Software LLC -> Secunia) S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182128 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5495056 2015-06-17] (TeamViewer -> TeamViewer GmbH) S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19256 2021-04-18] (Microsoft Windows -> Microsoft Corporation) S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19256 2021-04-18] (Microsoft Windows -> Microsoft Corporation) S2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [367232 2019-06-26] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 ASMMAP64; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [18048 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUS) R3 AsusSGDrv; C:\WINDOWS\system32\DRIVERS\AsusSGDrv.sys [138744 2015-12-18] (ASUSTeK Computer Inc. -> ASUS Corporation) R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.) R1 BHDrvx64; C:\Program Files\Norton Security\NortonData\22.20.5.39\Definitions\BASHDefs\20211019.011\BHDrvx64.sys [2018784 2021-09-15] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Fichier non signé] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Fichier non signé] R1 ccSet_NGC; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\ccSetx64.sys [192256 2021-09-29] (Symantec Corporation -> Symantec Corporation) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159864 2021-06-29] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [516168 2021-10-14] (Symantec Corporation -> Broadcom) U3 EraserUtilDrv11912; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11912.sys [153672 2021-10-14] (Symantec Corporation -> Broadcom) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [145352 2021-10-13] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) R1 gfdriver; C:\WINDOWS\System32\drivers\gfdriver.sys [51904 2015-01-14] (TITAN ARC CORP. TAIWAN BRANCH (SAMOA) -> Titan ARC Corp.) R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. -> ASUS) R1 IDSVia64; C:\Program Files\Norton Security\NortonData\22.20.5.39\Definitions\IPSDefs\20211020.061\IDSvia64.sys [1480144 2021-09-28] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [210344 2021-09-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-12-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-09-17] (Malwarebytes Inc -> Malwarebytes) S3 nsvst_NGC; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\nsvst.sys [56080 2021-09-29] (NortonLifeLock Inc. -> NortonLifeLock Inc.) S3 PSI; C:\WINDOWS\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia -> Secunia) R0 PxHlpa64; C:\WINDOWS\System32\drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation -> Corel Corporation) R3 SRTSP; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\SRTSP64.SYS [892600 2021-09-29] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) R1 SRTSPX; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\SRTSPX64.SYS [48832 2021-09-29] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43376 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R0 SymEFASI; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\SYMEFASI64.SYS [2059952 2021-09-29] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) S0 SymELAM; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\SymELAM.sys [31976 2021-09-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Broadcom Corporation) R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [93152 2021-07-25] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) R3 SymEvnt; C:\Program Files\Norton Security\NortonData\22.20.5.39\SymPlatform\SymEvnt.sys [712432 2021-07-13] (Symantec Corporation -> Symantec Corporation) R1 SymIRON; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\Ironx64.SYS [319176 2021-09-29] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom) R1 SymNetS; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\symnets.sys [575344 2021-09-29] (Symantec Corporation -> Symantec Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation) R1 wdfsconnect2017; C:\WINDOWS\system32\drivers\wdfsconnect2017.sys [468112 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation) R3 wdvpnpbus; C:\WINDOWS\System32\drivers\wdvpnpbus.sys [20624 2017-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies, Inc.) R1 wpCtrlDrv_NGC; C:\WINDOWS\System32\drivers\NGCx64\1615090.019\wpCtrlDrv.sys [1015760 2021-09-29] (NortonLifeLock Inc. -> NortonLifeLock Inc.) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2021-10-21 10:49 - 2021-10-21 10:49 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation 2021-10-17 20:06 - 2021-10-17 20:06 - 000099624 _____ C:\Users\maite\Desktop\guinvarch-marie-therese-dav-co-1.pdf 2021-10-17 20:05 - 2021-10-17 20:05 - 000469266 _____ C:\Users\maite\Desktop\GUINVARCH MARIE THERESE-I001Pr-2021.10.14-16.52.14.tif 2021-10-13 10:19 - 2021-10-21 11:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\Norton 360 2021-10-13 10:13 - 2021-10-13 10:13 - 000003376 _____ C:\WINDOWS\system32\Tasks\Norton WSC Integration 2021-10-13 10:13 - 2021-10-13 10:13 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security 2021-10-13 09:11 - 2021-10-13 09:11 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx 2021-10-13 09:11 - 2021-10-13 09:11 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx 2021-10-13 09:10 - 2021-10-13 09:10 - 001823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2021-10-13 09:10 - 2021-10-13 09:10 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2021-10-13 09:10 - 2021-10-13 09:10 - 000706536 _____ C:\WINDOWS\system32\TextShaping.dll 2021-10-13 09:10 - 2021-10-13 09:10 - 000611960 _____ C:\WINDOWS\SysWOW64\TextShaping.dll 2021-10-13 09:10 - 2021-10-13 09:10 - 000593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2021-10-13 09:10 - 2021-10-13 09:10 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2021-10-13 09:10 - 2021-10-13 09:10 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2021-10-13 09:10 - 2021-10-13 09:10 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2021-10-13 09:10 - 2021-10-13 09:10 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll 2021-10-13 09:10 - 2021-10-13 09:10 - 000098304 _____ C:\WINDOWS\system32\Drivers\cimfs.sys 2021-10-13 09:10 - 2021-10-13 09:10 - 000011495 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2021-10-13 09:03 - 2021-10-13 09:03 - 000000000 ___HD C:\$WinREAgent 2021-10-11 16:55 - 2021-10-11 16:55 - 000000000 ____D C:\Users\maite\AppData\Roaming\RadiantViewer 2021-10-11 16:55 - 2021-10-11 16:55 - 000000000 ____D C:\Users\maite\AppData\Local\RadiantViewer 2021-10-11 16:55 - 2021-10-11 16:55 - 000000000 ____D C:\ProgramData\RadiantViewer 2021-10-09 16:11 - 2021-10-09 16:11 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2021-10-09 15:52 - 2021-10-10 09:30 - 000000000 ____D C:\Program Files\Mozilla Firefox 2021-10-06 09:45 - 2021-10-19 08:30 - 000013395 _____ C:\Users\maite\Desktop\CABOURG PREV.xlsx 2021-09-28 16:01 - 2021-09-28 16:01 - 000179567 _____ C:\Users\maite\Desktop\Bilan SCM2016.pdf 2021-09-28 15:59 - 2021-09-28 15:59 - 000175149 _____ C:\Users\maite\Desktop\Bilan SCM2020.pdf 2021-09-28 15:58 - 2021-09-28 15:58 - 000204750 _____ C:\Users\maite\Desktop\Bilan SCM2019.pdf 2021-09-28 15:57 - 2021-09-28 15:57 - 000178585 _____ C:\Users\maite\Desktop\Bilan SCM2018.pdf 2021-09-28 15:57 - 2021-09-28 15:57 - 000177698 _____ C:\Users\maite\Desktop\Bilan SCM2017.pdf ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2021-10-21 17:52 - 2017-05-07 15:55 - 000000000 ____D C:\ProgramData\TEMP 2021-10-21 17:51 - 2020-03-24 12:28 - 000000000 ____D C:\FRST 2021-10-21 17:49 - 2017-04-27 11:30 - 000000000 ____D C:\Users\maite\AppData\LocalLow\Mozilla 2021-10-21 17:48 - 2017-04-27 19:38 - 000000000 ____D C:\Users\maite\Documents\Fichiers Outlook 2021-10-21 17:47 - 2020-03-04 14:08 - 000000000 ____D C:\Program Files (x86)\Google 2021-10-21 17:40 - 2021-04-18 10:38 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-10-21 17:40 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-10-21 14:36 - 2019-02-06 10:08 - 000000000 ____D C:\ProgramData\Mozilla 2021-10-21 14:10 - 2021-04-18 10:50 - 000003382 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2595580047-1136342414-3253307354-1001 2021-10-21 14:10 - 2021-04-18 10:42 - 000002470 _____ C:\Users\maite\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-10-21 12:25 - 2017-07-18 21:01 - 000000000 ____D C:\ProgramData\NVIDIA 2021-10-21 10:04 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2021-10-21 10:04 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-10-21 09:47 - 2017-05-08 18:23 - 000000000 ____D C:\Users\maite\AppData\Local\Adobe 2021-10-20 19:30 - 2018-05-24 18:09 - 000000000 ____D C:\Users\maite\AppData\Local\D3DSCache 2021-10-20 18:09 - 2019-10-03 21:04 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2021-10-20 12:38 - 2021-04-18 10:52 - 001930464 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-10-20 12:38 - 2019-12-07 16:49 - 000841850 _____ C:\WINDOWS\system32\perfh00C.dat 2021-10-20 12:38 - 2019-12-07 16:49 - 000167942 _____ C:\WINDOWS\system32\perfc00C.dat 2021-10-20 10:29 - 2016-11-04 15:44 - 000000000 ____D C:\Program Files\Microsoft Office 2021-10-18 19:01 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2021-10-18 12:05 - 2021-09-16 10:07 - 000001983 _____ C:\Users\maite\Desktop\Norton Utilities.lnk 2021-10-18 12:05 - 2021-06-30 10:14 - 000001442 _____ C:\Users\maite\Desktop\Norton Installation Files.lnk 2021-10-16 14:50 - 2020-06-26 21:06 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-10-13 19:19 - 2018-10-13 09:02 - 000000000 ____D C:\Users\maite\Documents\Enregistrements audio 2021-10-13 18:46 - 2017-11-20 01:08 - 000000000 ____D C:\Users\maite\AppData\Local\Packages 2021-10-13 10:39 - 2017-05-03 17:51 - 000000000 ____D C:\Program Files\Common Files\AV 2021-10-13 10:13 - 2021-06-28 15:16 - 000002422 _____ C:\Users\Public\Desktop\Norton Security.lnk 2021-10-13 10:13 - 2021-04-18 10:50 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-10-13 10:13 - 2021-04-18 10:38 - 000439480 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2021-10-13 10:13 - 2021-04-18 10:38 - 000008192 ___SH C:\DumpStack.log.tmp 2021-10-13 10:13 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState 2021-10-13 10:13 - 2019-12-07 11:03 - 001310720 _____ C:\WINDOWS\system32\config\BBI 2021-10-13 10:13 - 2018-02-20 09:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\NGCx64 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\UNP 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\DiagTrack 2021-10-13 10:12 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2021-10-13 09:13 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-10-13 07:41 - 2017-04-27 16:56 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-10-13 07:36 - 2017-04-27 16:56 - 139806512 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-10-12 18:59 - 2021-04-18 10:50 - 000003522 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0 2021-10-10 09:30 - 2019-12-07 11:03 - 000016384 _____ C:\WINDOWS\system32\config\ELAM 2021-10-10 09:30 - 2019-09-25 18:10 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2021-10-10 09:21 - 2021-04-26 07:33 - 000003540 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d7342f10c57170 2021-10-10 09:21 - 2021-04-18 10:50 - 000003634 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-10-09 16:11 - 2019-09-25 18:10 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2021-10-08 13:40 - 2020-09-30 06:28 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2021-10-08 12:05 - 2020-11-14 19:03 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2021-10-01 19:21 - 2017-06-27 14:14 - 000000000 ____D C:\Users\maite\AppData\Local\ElevatedDiagnostics 2021-10-01 01:19 - 2021-04-18 10:50 - 000003590 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2021-10-01 01:19 - 2021-04-18 10:50 - 000003466 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2021-09-27 10:58 - 2021-03-19 08:49 - 000000000 ____D C:\Users\maite\AppData\LocalLow\Norton ==================== Fichiers à la racine de certains dossiers ======== 2016-06-15 23:06 - 2016-06-15 23:06 - 000065352 _____ (Nuance Communications, Inc.) C:\Users\maite\Runner.exe 2016-06-15 23:06 - 2016-06-15 23:06 - 002241648 _____ (Nuance Communications, Inc.) C:\Users\maite\Setup.exe 2017-07-30 19:54 - 2017-07-30 19:54 - 000003050 _____ () C:\Users\maite\AppData\Roaming\.DEFAULT 2017-07-30 19:54 - 2017-07-30 19:54 - 000000170 _____ () C:\Users\maite\AppData\Roaming\.DEFAULT-dm2 2017-07-30 19:54 - 2017-07-30 19:54 - 000000180 _____ () C:\Users\maite\AppData\Roaming\.DEFAULT-dmpu 2017-07-30 19:54 - 2017-07-30 19:54 - 000046732 _____ () C:\Users\maite\AppData\Roaming\nuanreg 2017-07-30 19:54 - 2017-07-30 19:54 - 000065780 _____ () C:\Users\maite\AppData\Roaming\nuanreg-dm2 2017-07-30 19:54 - 2017-07-30 19:54 - 000000176 _____ () C:\Users\maite\AppData\Roaming\nuanreg-dmpu 2017-07-30 19:54 - 2017-07-30 19:54 - 000003050 _____ () C:\Users\maite\AppData\Roaming\S-1-5-18 2017-07-30 19:54 - 2017-07-30 19:54 - 000000170 _____ () C:\Users\maite\AppData\Roaming\S-1-5-18-dm2 2017-07-30 19:54 - 2017-07-30 19:54 - 000000180 _____ () C:\Users\maite\AppData\Roaming\S-1-5-18-dmpu 2017-07-30 19:54 - 2017-07-30 19:54 - 000000180 _____ () C:\Users\maite\AppData\Roaming\S-1-5-19-dmpu 2017-07-30 19:54 - 2017-07-30 19:54 - 000000180 _____ () C:\Users\maite\AppData\Roaming\S-1-5-20-dmpu 2017-07-30 19:54 - 2017-07-30 19:54 - 000051612 _____ () C:\Users\maite\AppData\Roaming\S-1-5-21-2595580047-1136342414-3253307354-1001 2017-07-30 19:54 - 2017-07-30 19:54 - 000065860 _____ () C:\Users\maite\AppData\Roaming\S-1-5-21-2595580047-1136342414-3253307354-1001-dm2 2017-07-30 19:54 - 2017-07-30 19:54 - 000000256 _____ () C:\Users\maite\AppData\Roaming\S-1-5-21-2595580047-1136342414-3253307354-1001-dmpu 2017-03-05 15:37 - 2021-02-04 20:00 - 000000184 _____ () C:\Users\maite\AppData\Roaming\sp_data.sys 2017-05-28 16:52 - 2018-04-10 10:09 - 000021957 _____ () C:\Users\maite\AppData\Roaming\Valeurs séparées par une virgule.ADR 2018-12-16 17:48 - 2018-12-16 17:48 - 000000410 _____ () C:\Users\maite\AppData\Local\oobelibMkey.log 2019-08-30 22:49 - 2019-09-16 19:12 - 000007622 _____ () C:\Users\maite\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================