Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 18-04-2022 01 Exécuté par jpt (administrateur) sur TREMBLAY-NANTES (ASUSTeK COMPUTER INC. X751LD) (20-04-2022 17:16:59) Exécuté depuis C:\Users\jpt\Downloads Profils chargés: jpt Plate-forme: Microsoft Windows 10 Famille (X64) Langue: Français (France) Navigateur par défaut: FF Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe ->) (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe ->) (ASUSTeK Computer Inc. -> AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe ->) (Qualcomm Atheros -> ) [Fichier non signé] C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe ->) (Logitech -> Logitech, Inc.) C:\Users\jpt\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe (C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe ->) (Logitech, Inc. -> ) C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (C:\Program Files\Mozilla Firefox\firefox.exe ->) (Farbar) [Fichier non signé] C:\Users\jpt\Downloads\FRST64(2).exe (C:\Users\jpt\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LULnchr.exe ->) (Logitech -> Logitech, Inc.) C:\Users\jpt\AppData\Local\Logitech® Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe (C:\Windows\SysWOW64\esif_uf.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe (explorer.exe ->) (F.lux Software LLC -> f.lux Software LLC) C:\Users\jpt\AppData\Local\FluxSoftware\Flux\flux.exe (explorer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (explorer.exe ->) (Qualcomm Atheros -> Qualcomm®Atheros®) [Fichier non signé] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe (Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Logitech, Inc. -> Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <10> (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (services.exe ->) (Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (services.exe ->) (ASUS Cloud Corporation) [Fichier non signé] C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\AsusWSWinService.exe (services.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (services.exe ->) (Atheros) [Fichier non signé] C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (services.exe ->) (Geek Software GmbH -> Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe <2> (services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (services.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe (services.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [Fichier non signé] C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (services.exe ->) (TeamViewer -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (svchost.exe ->) (Advanced System Repair Inc -> Advanced System Repair Inc.) C:\Program Files (x86)\Advanced System Repair Pro 1.9.3.8.0\AdvancedSystemRepairPro.exe (svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (svchost.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (svchost.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2> (svchost.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-20] (NVIDIA Corporation -> NVIDIA Corporation) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3426560 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-09-11] (Intel(R) Software -> Intel Corporation) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [1080992 2014-05-15] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) [Fichier non signé] HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\ASUSWSLoader.exe [63296 2014-02-25] (ASUS Cloud Corporation -> ) HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft) [Fichier non signé] HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [1057240 2017-11-18] (DivX, LLC -> DivX, LLC) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [483976 2020-08-13] (Geek Software GmbH -> Geek Software GmbH) HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech, Inc. -> Logitech Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [706680 2020-12-09] (Oracle America, Inc. -> Oracle Corporation) HKLM-x32\...\Winlogon: [Userinit] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [134784 2014-02-26] (Qualcomm Atheros -> Qualcomm®Atheros®) [Fichier non signé] HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-1621322746-441669930-4159517136-1001\...\Run: [f.lux] => C:\Users\jpt\AppData\Local\FluxSoftware\Flux\flux.exe [1515848 2021-06-18] (F.lux Software LLC -> f.lux Software LLC) HKU\S-1-5-21-1621322746-441669930-4159517136-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [112191904 2021-12-06] (Skype Software Sarl -> Skype Technologies S.A.) HKU\S-1-5-21-1621322746-441669930-4159517136-1001\...\Run: [pCloud] => C:\Program Files\pCloud Drive\pCloud.exe [3864576 2021-03-11] (pCloud AG -> pCloud AG) HKU\S-1-5-21-1621322746-441669930-4159517136-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1621322746-441669930-4159517136-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Bubbles.scr [809472 2019-12-07] (Microsoft Windows -> Microsoft Corporation) HKU\S-1-5-21-1621322746-441669930-4159517136-1004\...\Run: [MicrosoftEdgeAutoLaunch_CCBA45E8BBBE670A079BA606224E422D] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3540408 2022-04-15] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1621322746-441669930-4159517136-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [581120 2021-01-16] (Microsoft Windows -> Microsoft Corporation) HKLM\...\Windows x64\Print Processors\hpzppw71: C:\Windows\System32\spool\prtprocs\x64\hpzppw71.dll [230400 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation) HKLM\...\Print\Monitors\PCL hpz3lw71: C:\WINDOWS\system32\hpz3lw71.dll [46080 2009-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\100.0.4896.127\Installer\chrmstp.exe [2022-04-20] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\WINDOWS\system32\AthCredentialProvider.dll [2014-02-26] (Qualcomm Atheros -> Qualcomm®Atheros®) [Fichier non signé] HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\WINDOWS\system32\AthCredentialProvider.dll [2014-02-26] (Qualcomm Atheros -> Qualcomm®Atheros®) [Fichier non signé] GroupPolicy: Restriction ? <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Tâches planifiées (Avec liste blanche) ============ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {023E19D2-7DFE-4F58-80D3-1122A7DEA92F} - System32\Tasks\{9DD623DE-6537-4ED1-8EB4-6E2C3F3542F2} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxps://ui.skype.com/ui/0/7.32.0.104/fr/abandoninstall?page=tsProgressBar Task: {07CEF87B-41DF-4B1A-A95C-5F455E03DF75} - System32\Tasks\Windows Care Genius.job => C:\Program Files (x86)\Windows Care Genius\WCGTray.exe -StartTray (Pas de fichier) Task: {08889E22-E993-4ED8-8585-18EDF18C0247} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Pas de fichier <==== ATTENTION Task: {0C0DA72C-110E-4C0A-90F2-6D86CA869ED0} - System32\Tasks\ASR-Startup => C:\Program Files (x86)\Advanced System Repair Pro 1.9.3.8.0\AdvancedSystemRepairPro.exe [22839672 2022-04-19] (Advanced System Repair Inc -> Advanced System Repair Inc.) Task: {0CEB0D7F-37C6-46DC-A4DD-543F453D58A9} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [181360 2013-10-07] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) Task: {0F53EEF8-02F8-432F-8345-7A05CB8327EE} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [55880 2013-10-07] (ASUSTeK Computer Inc. -> ASUS) Task: {19C13625-13EB-4B49-BC47-47B885D17BC6} - System32\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Windows Care Genius\WCGTurbo.exe (Pas de fichier) Task: {1BE8D386-4D3C-4FED-B1F1-A878F6C6C5C0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.) Task: {2531C52D-D966-4784-BFC7-0E68FA646228} - \WPD\SqmUpload_S-1-5-21-1621322746-441669930-4159517136-1004 -> Pas de fichier <==== ATTENTION Task: {29692341-05B6-46EA-89B3-CAC15FC4C211} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {2FF21273-7AB3-4EC1-9689-A36B495DF439} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19723888 2014-03-27] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {30A90473-89BC-49CF-97D6-99BC100DB852} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe join (Pas de fichier) Task: {3AD2944D-1801-419F-9C0D-61590A1C12A9} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16174352 2015-11-10] (Realtek Semiconductor Corp -> Realtek Semiconductor) Task: {3CB3F6F2-58AB-4DB4-9DB5-691CEC8DA462} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3426560 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {43D34575-C62D-4AC1-BC09-3E5F3986E20E} - System32\Tasks\Opera scheduled Autoupdate 1586203526 => C:\Users\jpt\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Pas de fichier) Task: {49FBF7CE-9265-4166-A812-C1891CCCCFC2} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86) [Argument = -critical] Task: {4A9E2DEE-899F-4600-9188-A4099D95FAD3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Pas de fichier <==== ATTENTION Task: {58603528-C16E-4B65-8D98-F16187D91118} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Pas de fichier <==== ATTENTION Task: {5AB2EE13-FC54-4CBE-A1B6-EC4105E13B3B} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe (Pas de fichier) Task: {6A3FA468-EB27-46F4-9B3D-B07A2819D6EC} - \WPD\SqmUpload_S-1-5-21-1621322746-441669930-4159517136-1001 -> Pas de fichier <==== ATTENTION Task: {6AE86AC2-480E-4F48-80F2-042B7264D373} - System32\Tasks\BraveSoftwareUpdateTaskUserS-1-5-21-1621322746-441669930-4159517136-1001Core => C:\Users\jpt\AppData\Local\BraveSoftware\Update\BraveUpdate.exe /c (Pas de fichier) Task: {6DD162E6-49C0-4C00-A5B4-DC65070F3FB4} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Pas de fichier <==== ATTENTION Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Task: {6F914E5D-121A-4E94-A593-AC8A9F406A7E} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe -sr (Accès refusé) <==== ATTENTION Task: {7CD988F4-8CDC-4E86-919C-E9A62C194B7D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Pas de fichier <==== ATTENTION Task: {83567CBE-09AF-416C-B2FF-A168BD495123} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Pas de fichier <==== ATTENTION Task: {8510A9B1-B419-4E37-B2A6-C9616C09D32C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE} Task: {89FA0D4F-876C-43BD-B68B-67C111E42D1D} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411856 2015-11-10] (Realtek Semiconductor Corp -> Realtek Semiconductor) Task: {90A7EFC1-3C83-4252-B647-2E73ABA313DF} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [11776 2014-03-11] () [Fichier non signé] Task: {926BCD55-93D6-4E09-B6D9-68FD99462B3D} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [1038648 2014-02-11] (ASUSTeK Computer Inc. -> ASUS) Task: {928221E2-D858-423B-AE11-BE271D3F7465} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.) Task: {94D50A12-1EE1-4871-B511-8A44B7E860B4} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Pas de fichier <==== ATTENTION Task: {9E5199F8-12B9-45E9-A2C9-39FBE3AFDDE8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {AE656976-9D08-4AA5-88DA-BED7FA960C8F} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [120632 2014-06-11] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) Task: {B6142303-4FA9-4B87-9F9B-6B0BDF0D0EFD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Pas de fichier <==== ATTENTION Task: {BE24CDA1-45B3-459A-BC62-BA955F28DCC3} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86) [Argument = -check] Task: {BFB68486-199E-4FF8-8162-974E1B480947} - System32\Tasks\BraveSoftwareUpdateTaskUserS-1-5-21-1621322746-441669930-4159517136-1001UA => C:\Users\jpt\AppData\Local\BraveSoftware\Update\BraveUpdate.exe /ua /installsource scheduler (Pas de fichier) Task: {C0F4365B-38D7-4F1D-A9BE-53BB800093A1} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Pas de fichier <==== ATTENTION Task: {C2702470-107D-49EB-A09D-903EB3731ACE} - System32\Tasks\Opera scheduled Autoupdate 1525338061 => C:\Users\jpt\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Pas de fichier) Task: {C8E7DDFF-445F-481B-805E-F765E2ECBB49} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371} Task: {D03F15D9-3C70-41D9-ACE9-C366E64E0B77} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA} Task: {D20EFF40-3C5C-407D-B7B5-5004C9D9E098} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18400 2017-03-09] (ASUSTeK Computer Inc. -> AsusTek) Task: {D369DB48-6B67-432D-9C6C-AF9FE40653D4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {D75DCA72-453B-4FBF-8587-23E9C2D0AC86} - System32\Tasks\P4GIntlCtrl => C:\Program Files\ASUS\P4G\IntlDPST.exe [74112 2014-02-11] (ASUSTeK Computer Inc. -> ) Task: {E60ABC71-DA57-424D-AE50-2426E5988C29} - System32\Tasks\DivXUpdate => C:\Program Files (x86)\Common Files\DivX Shared\DivX Update\DivXUpdate.exe [68568 2017-08-02] (DivX, LLC -> DivX, LLC) Task: {EA4B4373-6B98-42FC-887D-EA413F28AEE7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Pas de fichier <==== ATTENTION Task: {F2214E5E-7C1D-423A-998C-FF1B4411B8EC} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Pas de fichier <==== ATTENTION Task: {F42CFBE8-48C9-455A-9E0D-6874646138C9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-18] (Adobe Inc. -> Adobe Inc.) Task: {F8023D4C-D7A2-47B7-9857-E3EA55CA576B} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs (Pas de fichier) Task: {FC7E1E85-8ACE-4CB4-9315-D63A2BF9D5C1} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411856 2015-11-10] (Realtek Semiconductor Corp -> Realtek Semiconductor) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 212.27.40.241 212.27.40.240 Tcpip\..\Interfaces\{ee955b60-56ae-4520-8606-208389ae529a}: [DhcpNameServer] 212.27.40.241 212.27.40.240 Tcpip\..\Interfaces\{fed7d158-c0f5-4e24-81fe-bfa048a33e71}: [DhcpNameServer] 212.27.40.241 212.27.40.240 ManualProxies: Edge: ======= Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)] Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)] Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)] Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)] Edge Profile: C:\Users\jpt\AppData\Local\Microsoft\Edge\User Data\Default [2022-04-19] FireFox: ======== FF DefaultProfile: v1lqrtzu.default-1650464442296 FF ProfilePath: C:\Users\jpt\AppData\Roaming\Mozilla\Firefox\Profiles\v1lqrtzu.default-1650464442296 [2022-04-20] FF Extension: (AdBlocker Ultimate) - C:\Users\jpt\AppData\Roaming\Mozilla\Firefox\Profiles\v1lqrtzu.default-1650464442296\Extensions\adblockultimate@adblockultimate.net.xpi [2022-04-20] FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-04-07] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [Pas de fichier] FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2017-11-21] (DivX, LLC -> DivX, LLC) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [Pas de fichier] FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [Pas de fichier] FF Plugin-x32: @java.com/DTPlugin,version=11.281.2 -> C:\Program Files (x86)\Java\jre1.8.0_281\bin\dtplugin\npDeployJava1.dll [2021-01-26] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.281.2 -> C:\Program Files (x86)\Java\jre1.8.0_281\bin\plugin2\npjp2.dll [2021-01-26] (Oracle America, Inc. -> Oracle Corporation) Chrome: ======= CHR Profile: C:\Users\jpt\AppData\Local\Google\Chrome\User Data\Default [2022-04-19] CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default CHR DefaultSearchKeyword: Default -> Yahoo CHR DefaultSuggestURL: Default -> hxxps://fr.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10 CHR Extension: (Yahoo Partner) - C:\Users\jpt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibbfklbaljofpaanmpaeadejijfdddco [2018-05-09] CHR Extension: (Yahoo Partner) - C:\Users\jpt\AppData\Local\Google\Chrome\User Data\Default\Extensions\njpedbdniajflhgfoipnjkednnlkngbj [2018-05-09] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\jpt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-12-26] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] CHR HKLM-x32\...\Chrome\Extension: [ibbfklbaljofpaanmpaeadejijfdddco] CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] CHR HKLM-x32\...\Chrome\Extension: [njpedbdniajflhgfoipnjkednnlkngbj] Opera: ======= OPR Profile: C:\Users\jpt\AppData\Roaming\Opera Software\Opera Stable [2021-10-15] OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.fr/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding} Brave: ======= BRA Profile: C:\Users\jpt\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2022-04-19] BRA Extension: (Brave Tracking Protection Updater) - C:\Users\jpt\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2019-01-06] BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\jpt\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2019-01-07] BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\jpt\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2019-01-06] BRA Extension: (Brave Ad Block Updater (FRA: EasyList Liste FR)) - C:\Users\jpt\AppData\Local\BraveSoftware\Brave-Browser\User Data\emaecjinaegfkoklcdafkiocjhoeilao [2019-01-07] BRA Extension: (PDF Viewer) - C:\Users\jpt\AppData\Local\BraveSoftware\Brave-Browser\User Data\oemmndcbldboiebfnladdacbdfmadadm [2019-01-06] BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\jpt\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2019-01-06] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-18] (Adobe Inc. -> Adobe Inc.) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3849472 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3617024 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated) R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\AsusWSWinService.exe [71680 2014-02-25] (ASUS Cloud Corporation) [Fichier non signé] R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [319104 2014-02-26] (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [Fichier non signé] R2 DptfParticipantProcessorService; C:\WINDOWS\system32\DptfParticipantProcessorService.exe [115632 2013-09-11] (Intel(R) Software -> Intel Corporation) S2 DptfPolicyConfigTDPService; C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe [116656 2013-09-11] (Intel(R) Software -> Intel Corporation) S2 DptfPolicyCriticalService; C:\WINDOWS\system32\DptfPolicyCriticalService.exe [148688 2013-09-11] (Intel(R) Software -> Intel Corporation) S2 DptfPolicyLpmService; C:\WINDOWS\system32\DptfPolicyLpmService.exe [124880 2013-09-11] (Intel(R) Software -> Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [827392 2013-09-02] (Intel(R) Corporation) [Fichier non signé] R2 PDF24; C:\Program Files (x86)\PDF24\pdf24.exe [483976 2020-08-13] (Geek Software GmbH -> Geek Software GmbH) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer -> TeamViewer GmbH) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-02-25] (Atheros) [Fichier non signé] ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2018-03-06] (AnchorFree Inc -> The OpenVPN Project) R3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [128024 2017-03-09] (ASUSTeK Computer Inc. -> ASUS Corporation) R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [19768 2013-07-02] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [269408 2018-06-21] (Bluestack Systems, Inc. -> Bluestack System Inc.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Fichier non signé] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Fichier non signé] R1 cbfsconnect2017; C:\WINDOWS\system32\drivers\cbfsconnect2017.sys [481296 2020-06-25] (Microsoft Windows Hardware Compatibility Publisher -> Callback Technologies, Inc.) R3 DptfDevDram; C:\WINDOWS\system32\DRIVERS\DptfDevDram.sys [143568 2013-09-11] (Intel(R) Software -> Intel Corporation) R3 DptfDevPch; C:\WINDOWS\system32\DRIVERS\DptfDevPch.sys [114680 2013-09-11] (Intel(R) Software -> Intel Corporation) R3 DptfDevProc; C:\WINDOWS\system32\DRIVERS\DptfDevProc.sys [287160 2013-09-11] (Intel(R) Software -> Intel Corporation) S3 DptfManager; C:\WINDOWS\system32\DRIVERS\DptfManager.sys [494272 2013-09-11] (Intel(R) Software -> Intel Corporation) S3 DrvAgent64; C:\WINDOWS\SysWOW64\Drivers\DrvAgent64.SYS [20872 2017-01-13] (eSupport.com, Inc -> Phoenix Technologies) S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [22704 2015-12-22] (Enigma Software Group USA, LLC -> ) R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32696 2020-11-19] (ASUSTek Computer Inc. -> ASUS) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2021-01-26] (Martin Malik - REALiX -> REALiX(tm)) R3 int0800; C:\WINDOWS\System32\drivers\flashud.sys [51712 2015-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [17280 2012-08-06] (ASUSTeK Computer Inc. -> ) R2 plctrl; C:\Program Files\ASUS\P4G\plctrl.sys [14136 2014-02-11] (ASUSTeK Computer Inc. -> Windows (R) Win 7 DDK provider) S3 RTL8192cu; C:\WINDOWS\System32\drivers\RTL8192cu.sys [806400 2011-06-01] (Realtek Semiconductor Corporation) [Fichier non signé] S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 vpnpbus; C:\WINDOWS\System32\drivers\vpnpbus.sys [20496 2020-06-25] (Microsoft Windows Hardware Compatibility Publisher -> Callback Technologies, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49600 2022-04-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [443664 2022-04-08] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90384 2022-04-08] (Microsoft Windows -> Microsoft Corporation) S3 WiseHDInfo; C:\WINDOWS\WiseHDInfo64.dll [14800 2017-02-18] (Lespeed Technology Ltd. -> wisecleaner.com) [Fichier non signé] S3 MpKslb3bd92c2; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{18199E3E-CFF0-476E-97F2-0D963D6A24C8}\MpKslDrv.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2022-04-20 17:16 - 2022-04-20 17:21 - 000034439 _____ C:\Users\jpt\Downloads\FRST.txt 2022-04-20 17:15 - 2022-04-20 17:20 - 000000000 ____D C:\FRST 2022-04-20 17:15 - 2022-04-20 17:15 - 002366464 _____ (Farbar) C:\Users\jpt\Downloads\FRST64(2).exe 2022-04-20 16:54 - 2022-04-20 16:54 - 002366464 _____ (Farbar) C:\Users\jpt\Downloads\FRST64(1).exe 2022-04-20 16:15 - 2022-04-20 16:15 - 002366464 _____ (Farbar) C:\Users\jpt\Downloads\FRST64.exe 2022-04-19 17:18 - 2022-04-19 17:18 - 008551608 _____ (Malwarebytes) C:\Users\jpt\Downloads\adwcleaner.exe 2022-04-19 17:17 - 2022-04-19 17:17 - 008540344 _____ (Malwarebytes) C:\Users\jpt\Downloads\adwcleaner_8.3.1.exe 2022-04-19 17:13 - 2022-04-19 17:13 - 000239165 _____ C:\Users\jpt\Downloads\cleanmgr_1-50-1300_en_436394.zip 2022-04-19 15:17 - 2022-04-19 15:17 - 003295944 _____ (Nicolas Coolman) C:\Users\jpt\Downloads\ZHPCleaner(10).exe 2022-04-19 14:31 - 2022-04-19 14:31 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2022-04-19 14:31 - 2022-04-19 14:31 - 000011803 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2022-04-19 14:30 - 2022-04-19 14:30 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2022-04-19 14:28 - 2022-04-19 14:28 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe 2022-04-19 14:21 - 2022-04-19 14:21 - 000003240 _____ C:\WINDOWS\system32\Tasks\ASR-Startup 2022-04-19 14:17 - 2022-04-20 16:42 - 000000000 ____D C:\ProgramData\ASR8Settings 2022-04-19 14:17 - 2022-04-19 16:50 - 000000000 ____D C:\Program Files (x86)\Advanced System Repair Pro 1.9.3.8.0 2022-04-19 12:17 - 2022-04-19 12:17 - 000002255 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk 2022-04-19 12:17 - 2022-04-19 12:17 - 000002243 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk 2022-04-18 18:55 - 2022-04-18 18:55 - 000000000 ___HD C:\$WinREAgent 2022-04-14 21:27 - 2022-04-20 16:32 - 000000000 ____D C:\Program Files\Mozilla Firefox 2022-04-14 18:16 - 2022-04-14 18:28 - 000000000 ____D C:\Users\TEMP.TREMBLAY-NANTES.007 2022-04-09 21:15 - 2022-04-09 21:15 - 000262209 _____ C:\Users\Edith\Downloads\INFORMATION-COPROPRIETAIRES.pdf 2022-04-08 16:28 - 2022-04-08 16:28 - 001412983 _____ C:\Users\jpt\Desktop\Guide_Technique_LMS_2019.pdf 2022-03-31 18:14 - 2022-03-31 18:14 - 000152920 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210308 (7).pdf 2022-03-31 18:13 - 2022-03-31 18:13 - 000152467 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210208 (5).pdf 2022-03-31 18:13 - 2022-03-31 18:13 - 000086054 _____ C:\Users\Edith\Downloads\_048543431_ (3).pdf 2022-03-31 17:59 - 2022-03-31 17:59 - 000149597 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210707 (1).pdf 2022-03-31 17:58 - 2022-03-31 17:58 - 000140665 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210608 (1).pdf 2022-03-31 17:58 - 2022-03-31 17:58 - 000133592 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210507 (2).pdf 2022-03-31 17:57 - 2022-03-31 17:57 - 000152920 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210308 (6).pdf 2022-03-31 17:57 - 2022-03-31 17:57 - 000147547 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210407 (1).pdf 2022-03-31 17:52 - 2022-03-31 17:52 - 000152920 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210308 (5).pdf 2022-03-31 17:51 - 2022-03-31 17:51 - 000133930 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210907.pdf 2022-03-31 17:50 - 2022-03-31 17:50 - 000139040 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210807.pdf 2022-03-31 17:49 - 2022-03-31 17:49 - 000149597 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210707.pdf 2022-03-31 17:49 - 2022-03-31 17:49 - 000140665 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210608.pdf 2022-03-31 17:48 - 2022-03-31 17:48 - 000133592 _____ C:\Users\Edith\Downloads\RELEVES_0052550621_20210507 (1).pdf 2022-03-31 17:46 - 2022-03-31 17:47 - 000085781 _____ C:\Users\Edith\Downloads\FGDR_0052550621_20220122.pdf 2022-03-29 11:06 - 2022-03-29 11:06 - 000078716 _____ C:\Users\Edith\Downloads\F021442.synX.pdf_aprogi08.18.pdf ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2022-04-20 17:20 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-04-20 17:13 - 2019-10-03 12:54 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2022-04-20 17:09 - 2015-10-20 17:18 - 000000000 ____D C:\Program Files (x86)\Google 2022-04-20 16:24 - 2022-02-15 11:54 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2022-04-20 16:23 - 2021-10-15 19:20 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2022-04-20 16:20 - 2020-03-14 16:44 - 000000000 ____D C:\Users\jpt\Desktop\Anciennes données de Firefox 2022-04-20 16:04 - 2020-10-22 12:32 - 000003590 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2022-04-20 16:04 - 2020-10-22 12:32 - 000003466 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2022-04-20 14:30 - 2015-10-20 16:40 - 000000062 _____ C:\Users\jpt\AppData\Roaming\sp_data.sys 2022-04-20 14:29 - 2017-04-13 18:53 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture 2022-04-20 14:26 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2022-04-20 14:26 - 2017-07-25 19:42 - 000000000 ____D C:\ProgramData\NVIDIA 2022-04-20 14:26 - 2017-07-25 19:41 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2022-04-20 14:26 - 2015-05-21 22:32 - 000000000 __SHD C:\Users\jpt\IntelGraphicsProfiles 2022-04-20 14:25 - 2015-05-23 15:45 - 000000000 __SHD C:\Users\Edith\IntelGraphicsProfiles 2022-04-20 10:36 - 2020-10-22 09:48 - 000000000 ____D C:\Users\jpt 2022-04-20 10:36 - 2020-10-22 09:47 - 000000000 ____D C:\Users\Edith 2022-04-20 10:30 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2022-04-20 10:25 - 2015-10-20 17:08 - 000000062 _____ C:\Users\Edith\AppData\Roaming\sp_data.sys 2022-04-19 21:04 - 2016-07-28 18:34 - 000000000 ____D C:\Users\jpt\Documents\photos papiers perso 2022-04-19 17:18 - 2015-12-23 13:21 - 000000000 ____D C:\AdwCleaner 2022-04-19 17:07 - 2016-11-19 14:28 - 000000000 ____D C:\Users\jpt\AppData\LocalLow\Mozilla 2022-04-19 17:03 - 2020-10-22 11:55 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2022-04-19 17:00 - 2020-10-22 12:32 - 000004220 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1586203526 2022-04-19 16:58 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-04-19 16:55 - 2020-10-22 12:14 - 001770910 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-04-19 16:55 - 2019-12-07 16:49 - 000802106 _____ C:\WINDOWS\system32\perfh00C.dat 2022-04-19 16:55 - 2019-12-07 16:49 - 000153738 _____ C:\WINDOWS\system32\perfc00C.dat 2022-04-19 16:46 - 2020-10-22 12:32 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2022-04-19 16:46 - 2020-10-22 11:55 - 000466424 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2022-04-19 16:46 - 2020-10-22 11:55 - 000008192 ___SH C:\DumpStack.log.tmp 2022-04-19 16:46 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState 2022-04-19 16:45 - 2019-12-07 11:03 - 001310720 _____ C:\WINDOWS\system32\config\BBI 2022-04-19 16:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2022-04-19 16:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2022-04-19 16:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2022-04-19 16:43 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2022-04-19 16:42 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2022-04-19 16:42 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2022-04-19 16:42 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning 2022-04-19 16:42 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2022-04-19 16:42 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2022-04-19 16:14 - 2017-02-19 23:39 - 000000000 ____D C:\Users\jpt\AppData\Roaming\ZHP 2022-04-19 16:13 - 2021-01-26 12:00 - 000000000 ____D C:\Users\jpt\AppData\Roaming\IObit 2022-04-19 15:20 - 2018-08-12 14:04 - 000000875 _____ C:\Users\jpt\Desktop\ZHPCleaner.lnk 2022-04-19 15:00 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2022-04-19 14:14 - 2022-01-17 14:56 - 000000000 ____D C:\WINDOWS\Minidump 2022-04-19 14:14 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2022-04-19 12:17 - 2015-10-20 17:20 - 000000000 ____D C:\Program Files\Google 2022-04-19 11:57 - 2020-04-08 22:44 - 000000967 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2022-04-18 18:45 - 2020-06-29 14:58 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2022-04-18 18:33 - 2015-10-21 11:24 - 000000000 ____D C:\WINDOWS\system32\MRT 2022-04-18 18:31 - 2021-12-12 11:43 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1621322746-441669930-4159517136-1004 2022-04-18 18:31 - 2020-10-22 12:32 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1621322746-441669930-4159517136-1004 2022-04-18 18:31 - 2020-10-22 09:47 - 000002419 _____ C:\Users\Edith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2022-04-18 18:22 - 2015-10-21 11:24 - 143823848 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2022-04-14 21:30 - 2021-11-28 19:42 - 000002075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk 2022-04-14 21:30 - 2021-11-28 19:42 - 000002063 _____ C:\Users\Public\Desktop\Adobe Acrobat DC.lnk 2022-04-14 21:30 - 2020-10-22 12:32 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2022-04-14 18:18 - 2015-09-10 07:54 - 000000000 __RHD C:\Users\Public\AccountPictures 2022-04-09 09:57 - 2021-12-21 23:20 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1621322746-441669930-4159517136-1001 2022-04-09 09:57 - 2021-11-22 18:38 - 000002413 _____ C:\Users\jpt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2022-04-09 09:57 - 2020-10-22 12:32 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1621322746-441669930-4159517136-1001 2022-04-08 09:51 - 2018-02-28 12:39 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2022-04-06 14:43 - 2020-10-22 16:21 - 000003540 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6a85bc77eb00a 2022-04-06 14:43 - 2020-10-22 12:32 - 000003634 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2022-04-06 14:38 - 2020-09-30 17:14 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2022-04-05 12:52 - 2015-12-22 17:29 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2022-03-23 21:13 - 2020-09-30 17:14 - 000601432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll 2022-03-23 21:12 - 2020-09-30 17:14 - 000483664 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll ==================== Fichiers à la racine de certains dossiers ======== 2017-02-20 22:51 - 2018-08-23 21:51 - 003270016 _____ () C:\Users\jpt\ZHPCleaner.exe 2016-04-27 14:25 - 2016-04-27 14:45 - 000000115 _____ () C:\Users\jpt\AppData\Roaming\LogFile.txt 2015-10-20 16:40 - 2022-04-20 14:30 - 000000062 _____ () C:\Users\jpt\AppData\Roaming\sp_data.sys 2016-09-28 11:05 - 2016-09-28 11:05 - 000004096 ____H () C:\Users\jpt\AppData\Local\keyfile3.drm 2018-10-01 09:17 - 2018-10-01 09:17 - 000000000 _____ () C:\Users\jpt\AppData\Local\oobelibMkey.log 2018-01-17 16:21 - 2018-01-17 16:21 - 000000218 _____ () C:\Users\jpt\AppData\Local\recently-used.xbel 2018-10-25 23:06 - 2018-10-25 23:06 - 000000017 _____ () C:\Users\jpt\AppData\Local\resmon.resmoncfg 2018-09-17 20:52 - 2018-09-17 20:52 - 000000000 _____ () C:\Users\jpt\AppData\Local\{3155E385-4758-43D6-A79D-33CB55C79044} 2018-09-10 15:03 - 2018-09-10 15:03 - 000000000 _____ () C:\Users\jpt\AppData\Local\{52786BB3-32AC-4E71-B58C-9F811888F454} ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================