Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-08-2022 ([color=red]ATTENTION: ====> FRST version is 35 days old and could be outdated[/color]) Ran by User (administrator) on ADRIEN (MSI MS-7693) (04-10-2022 18:14:51) Running from C:\Users\User\Desktop\englishFRST64 Loaded Profiles: User Platform: Microsoft Windows 10 Famille Version 21H1 19043.2006 (X64) Language: Français (France) Default browser: FF Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <4> (C:\Program Files (x86)\Cle USB Wi-Fi Essentiel B\USB Wireless LAN Utility\RtlService.exe ->) (Realtek Semiconductor Corp.) [File not signed] C:\Program Files (x86)\Cle USB Wi-Fi Essentiel B\USB Wireless LAN Utility\RtWLan.exe (C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\BridgeCommunication.exe (explorer.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <9> (explorer.exe ->) (HP Inc -> HP Inc.) C:\Program Files\HP\HP OfficeJet Pro 9010 series\Bin\ScanToPCActivationApp.exe (explorer.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP ENVY 5640 series\Bin\ScanToPCActivationApp.exe (explorer.exe ->) (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe (services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\DiagsCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\NetworkCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_df0bee9f4cb9436e\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (pdfforge GmbH -> pdfforge GmbH) C:\Program Files\PDF Architect 7\updater-ws.exe (services.exe ->) (pdfforge GmbH -> pdfforge GmbH) C:\Program Files\PDF Architect 7\ws.exe (services.exe ->) (Realtek) [File not signed] C:\Program Files (x86)\Cle USB Wi-Fi Essentiel B\USB Wireless LAN Utility\RtlService.exe (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP ENVY 5640 series\Bin\HPNetworkCommunicatorCom.exe (svchost.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP OfficeJet Pro 9010 series\Bin\HPNetworkCommunicatorCom.exe (svchost.exe ->) (IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22072.207.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213760 2022-06-28] (Avast Software s.r.o. -> AVAST Software) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-09-18] (Apple Inc. -> Apple Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard Company -> Hewlett-Packard) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKU\S-1-5-21-4012182184-2294530567-3611176650-1001\...\Run: [Advanced SystemCare] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [3634960 2019-12-13] (IObit Information Technology -> IObit) HKU\S-1-5-21-4012182184-2294530567-3611176650-1001\...\Run: [HP OfficeJet Pro 9010 series (NET)] => C:\Program Files\HP\HP OfficeJet Pro 9010 series\Bin\ScanToPCActivationApp.exe [4075072 2021-03-30] (HP Inc -> HP Inc.) HKU\S-1-5-21-4012182184-2294530567-3611176650-1001\...\Run: [HP ENVY 5640 series (NET)] => C:\Program Files\HP\HP ENVY 5640 series\Bin\ScanToPCActivationApp.exe [3770528 2021-11-15] (HP Inc. -> HP Inc.) HKU\S-1-5-21-4012182184-2294530567-3611176650-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKLM\...\Windows x64\Print Processors\hpcpp210: C:\Windows\System32\spool\prtprocs\x64\hpcpp210.dll [769776 2017-08-23] (HP Inc. -> HP Inc.) HKLM\...\Print\Monitors\HP CC11 Status Monitor: C:\WINDOWS\system32\hpinkstsCC11LM.dll [391992 2019-03-15] (HP Inc -> HP Inc.) HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\WINDOWS\system32\HPMPW081.DLL [127728 2017-08-23] (HP Inc. -> HP Inc.) HKLM\...\Print\Monitors\HPMLM190: C:\WINDOWS\system32\hpmlm190.dll [310696 2017-08-23] (HP Inc. -> HP Inc.) HKLM\...\Print\Monitors\PDF Architect 7 Monitor: C:\WINDOWS\system32\spool\DRIVERS\x64\pdf architect_pdfpmon_v.4.12.26.3.dll [932984 2020-04-16] (PDF Tools AG -> PDF Tools AG (hxxp://www.pdf-tools.com)) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\105.0.5195.127\Installer\chrmstp.exe [2022-09-16] (Google LLC -> Google LLC) HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {08EF4C0C-5E62-4419-A96E-4FE0FDBA4C7A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [221328 2022-08-17] (HP Inc. -> ) Task: {13881A38-F5E8-4A31-A848-0B57518E4AAE} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [4938496 2022-06-28] (Avast Software s.r.o. -> AVAST Software) Task: {16EE94F8-EBEB-4573-9662-41DB2F6D0DB1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2022-08-17] (HP Inc. -> HP Inc.) Task: {29CC22E2-6F9C-4CA1-81F2-CCD4CBAC8562} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1149512 2022-08-17] (HP Inc. -> HP Inc.) Task: {3DFFE817-49B4-4EF0-BACC-DDEB2D415329} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.) Task: {5CAE9AFB-BA6C-4447-A5ED-9964D1938B9C} - System32\Tasks\ASC_SkipUac_User => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [8797456 2019-12-18] (IObit Information Technology -> IObit) Task: {6A7D9FDA-218A-4C11-A2FB-74B050D9BC32} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116096 2022-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {6BA4BE8C-1A47-467C-87CA-5024F9A4E099} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {7A2D3BC8-8D70-4C55-A982-72E438430367} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {800DBDC8-FB7D-4EEE-8383-5657081E641C} - System32\Tasks\HPCustParticipation HP OfficeJet Pro 9010 series => C:\Program Files\HP\HP OfficeJet Pro 9010 series\Bin\HPCustPartic.exe [6721184 2021-10-30] (HP Inc. -> HP Inc.) Task: {A81D441B-AAE7-4063-8B95-1F9A3C18FEC7} - System32\Tasks\Driver Booster SkipUAC (User) => C:\Program Files (x86)\IObit\Driver Booster\4.4.0\DriverBooster.exe /skipuac (No File) Task: {AB746DEF-DC21-413C-97B2-5D2D4B4D4699} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116096 2022-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {ADA47548-1C5B-4473-B1B2-8478D5E94D5C} - System32\Tasks\ASC_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [3169552 2019-12-13] (IObit Information Technology -> IObit) Task: {AFC5D60C-35C3-403D-B1D3-C9D3BB18EBF7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {BB211B1B-DAAC-4A8A-99F4-401532E97336} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6624232 2022-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {BC266D69-58D1-4888-9F71-9632A41A2329} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_TH0B3771XK => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1149512 2022-08-17] (HP Inc. -> HP Inc.) Task: {C195D877-B9ED-4EBE-9144-4BFADE28F23E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_TH5BG8W0FT => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1149512 2022-08-17] (HP Inc. -> HP Inc.) Task: {C5DEF25B-EB65-4253-9980-707230351F1B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6624232 2022-10-01] (Microsoft Corporation -> Microsoft Corporation) Task: {C6C7BC8B-7B3A-4ACD-B501-E10092AC3B7E} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\avast software\overseer\overseer.exe [2250576 2022-05-24] (Avast Software s.r.o. -> Avast Software) Task: {D234E760-40CC-4333-8905-C1FF33C34C7B} - System32\Tasks\HPCustParticipation HP ENVY 5640 series => C:\Program Files\HP\HP ENVY 5640 series\Bin\HPCustPartic.exe [6439584 2021-11-15] (HP Inc. -> HP Inc.) Task: {D2448E34-E8B9-4526-9872-810640ADFEF7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-07-05] (Google Inc -> Google Inc.) Task: {DC033F4A-1D64-4DAD-BE2D-E8B0AF8B7695} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" Task: {E3DC2C15-A119-4522-B07A-94D1F9BF0BEE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-07-05] (Google Inc -> Google Inc.) Task: {E792E649-98BD-43E4-ABE2-A2D51ECB54D1} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-10-01] (Microsoft Corporation -> Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.) Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{09fb0022-b73b-4c62-b4af-018a36bdd2ed}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{0d253741-0e42-4617-ada6-ca44b723dae4}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{4dac3b68-3743-4011-9fa6-f0c8013fec4d}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{913e95c5-2758-4524-b59a-a0ef3d24b4ce}: [DhcpNameServer] 192.168.1.1 Edge: ======= DownloadDir: C:\Users\User\Downloads Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] Edge DefaultProfile: Default Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2022-09-15] Edge HomePage: Default -> hxxp://www.google.fr/ FireFox: ======== FF DefaultProfile: 3bfl9puu.default FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3bfl9puu.default [2022-10-04] FF NewTab: Mozilla\Firefox\Profiles\3bfl9puu.default -> hxxps://defaultsearch.co/homepage?hp=1&pId=PF170501&iDate=2020-04-16 07:30:02&bName=&bitmask=0600 FF Extension: (Avast SafePrice | Comparateur de prix, offres, coupons) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3bfl9puu.default\Extensions\sp@avast.com.xpi [2022-09-01] FF Extension: (Avast Online Security & Privacy) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3bfl9puu.default\Extensions\wrc@avast.com.xpi [2022-09-01] FF Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3bfl9puu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-09-01] FF HKLM\...\Firefox\Extensions: [pdf_architect_7_conv_v.2@pdfforge.org] - C:\Program Files\PDF Architect 7\creator\plugins\FirefoxAddin\pdf_architect_7_conv_v.2@pdfforge.org.xpi FF Extension: (PDF Architect 7 Creator) - C:\Program Files\PDF Architect 7\creator\plugins\FirefoxAddin\pdf_architect_7_conv_v.2@pdfforge.org.xpi [2019-10-02] FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_7_conv_v.2@pdfforge.org] - C:\Program Files\PDF Architect 7\creator\plugins\FirefoxAddin\pdf_architect_7_conv_v.2@pdfforge.org.xpi FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-04] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-07-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.) FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2017-09-13] Chrome: ======= CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2022-10-04] CHR Notifications: Default -> hxxps://www.facebook.com CHR HomePage: Default -> hxxp://www.google.com CHR Extension: (Google Docs hors connexion) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-14] CHR Extension: (Avast Online Security & Privacy) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2022-10-04] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-10] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2022-09-26] (Adobe Inc. -> Adobe Inc.) R2 AdvancedSystemCareService13; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [1290000 2019-12-17] (IObit Information Technology -> IObit) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-09-07] (Apple Inc. -> Apple Inc.) S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [8486968 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [590080 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R2 avast! Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [589056 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [56912 2021-09-16] (Avast Software s.r.o. -> AVAST Software) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12477392 2022-10-01] (Microsoft Corporation -> Microsoft Corporation) R2 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [771088 2022-08-17] (HP Inc. -> HP Inc.) R2 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [769568 2022-08-17] (HP Inc. -> HP Inc.) R2 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [766504 2022-08-17] (HP Inc. -> HP Inc.) R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [224320 2022-08-25] (HP Inc. -> HP Inc.) R2 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [770088 2022-08-17] (HP Inc. -> HP Inc.) R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2016-06-15] (HP Inc.) [File not signed] R3 PDF Architect 7; C:\Program Files\PDF Architect 7\ws.exe [2579752 2019-10-07] (pdfforge GmbH -> pdfforge GmbH) S3 PDF Architect 7 Creator; C:\Program Files\PDF Architect 7\creator\common\creator-ws.exe [692008 2019-10-07] (pdfforge GmbH -> pdfforge GmbH) R2 PDF Architect 7 Update Service; C:\Program Files\PDF Architect 7\updater-ws.exe [1832232 2019-10-07] (pdfforge GmbH -> pdfforge GmbH) R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2016-06-15] (HP Inc.) [File not signed] R2 RealtekWlanU; C:\Program Files (x86)\Cle USB Wi-Fi Essentiel B\USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed] S2 RTLDHCPService; C:\Program Files (x86)\Cle USB Wi-Fi Essentiel B\USB Wireless LAN Utility\RTLDHCP.exe [261848 2013-11-12] (Realtek Semiconductor Corp -> Realtek) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\NisSrv.exe [3004048 2019-10-12] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MsMpEng.exe [103384 2019-10-12] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_df0bee9f4cb9436e\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_df0bee9f4cb9436e\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) R3 AscFileFilter; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys [45432 2019-07-15] (IObit Information Technology -> IObit) R3 AscRegistryFilter; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys [46008 2019-07-15] (IObit Information Technology -> IObit) R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [41832 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [235584 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [385560 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [258072 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [104976 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [25048 2022-06-27] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [47976 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R1 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [274536 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R1 aswNetHub; C:\WINDOWS\System32\drivers\aswNetHub.sys [553928 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [113984 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [89056 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [860416 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [668208 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [221528 2022-06-28] (Avast Software s.r.o. -> AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [324864 2022-06-28] (Avast Software s.r.o. -> AVAST Software) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed] R3 cpuz145; C:\WINDOWS\temp\cpuz145\cpuz145_x64.sys [49968 2022-10-04] (CPUID -> CPUID) R1 HWiNFO32; C:\Windows\SysWoW64\drivers\HWiNFO64A.SYS [27552 2017-07-03] (Martin Malik - REALiX -> REALiX(tm)) R3 iobit_monitor_server; C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win10_x64.sys [32520 2018-07-05] (IObit Information Technology -> IObit) S3 pelmouse; C:\WINDOWS\system32\DRIVERS\pelmouse.sys [23040 2012-11-28] (TPMX Electronics Ltd.) [File not signed] S3 pelusblf; C:\WINDOWS\system32\DRIVERS\pelusblf.sys [34816 2013-03-19] (TPMX Electronics Ltd.) [File not signed] S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46688 2019-10-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [350136 2019-10-12] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54200 2019-10-12] (Microsoft Windows -> Microsoft Corporation) S3 RtlWlanu; \SystemRoot\System32\drivers\rtwlanu.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2022-10-04 18:14 - 2022-10-04 18:14 - 000000000 ____D C:\Users\User\Desktop\englishFRST64 2022-10-04 18:04 - 2022-10-04 18:04 - 001827015 _____ C:\Users\User\Desktop\englishFRST64.zip 2022-10-04 17:26 - 2022-10-04 18:15 - 000000000 ____D C:\FRST 2022-10-03 01:00 - 2022-10-03 01:00 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2022-10-01 11:51 - 2022-10-01 11:51 - 000000000 ___SD C:\Users\User\Documents\Mes sources de données 2022-09-30 13:11 - 2022-09-30 13:11 - 000988104 _____ C:\Users\User\Downloads\PV AGO US 2021.pdf 2022-09-30 13:07 - 2022-09-30 13:07 - 003013240 _____ C:\Users\User\Downloads\FUTURA 3000.pdf 2022-09-29 22:03 - 2022-09-29 22:03 - 001308520 _____ C:\Users\User\Downloads\471_xl3400 (1).pdf 2022-09-29 21:53 - 2022-09-29 21:53 - 001308520 _____ C:\Users\User\Downloads\471_xl3400.pdf 2022-09-29 20:40 - 2022-09-29 20:41 - 000202102 _____ C:\Users\User\Downloads\Mode d'emploi Singer 3400 XL (Français - 76 des page s).pdf 2022-09-28 22:17 - 2022-09-28 22:17 - 000003360 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4012182184-2294530567-3611176650-1001 2022-09-28 22:17 - 2022-09-28 22:17 - 000002454 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2022-09-28 14:23 - 2022-09-28 14:23 - 002515961 _____ C:\Users\User\Desktop\PV AGO US SAMOENS 08 2022.pdf 2022-09-28 14:18 - 2022-09-28 14:18 - 000224437 _____ C:\Users\User\Downloads\PV AGO UNION SYNDICALE LES ESPAC_ES vendredi 12 août 2022 (1).pdf 2022-09-28 14:16 - 2022-09-28 14:16 - 000224197 _____ C:\Users\User\Downloads\PV AGO UNION SYNDICALE LES ESPACES vendredi 12 août 2022_ (1).pdf 2022-09-28 14:15 - 2022-09-28 14:15 - 000224437 _____ C:\Users\User\Downloads\PV AGO UNION SYNDICALE LES ESPAC_ES vendredi 12 août 2022.pdf 2022-09-28 14:13 - 2022-09-28 14:13 - 000224197 _____ C:\Users\User\Downloads\PV AGO UNION SYNDICALE LES ESPACES vendredi 12 août 2022_.pdf 2022-09-27 13:03 - 2022-09-27 13:03 - 000000000 ____D C:\Program Files\Common Files\Hewlett-Packard 2022-09-17 17:30 - 2022-09-17 17:30 - 000001822 _____ C:\Users\Public\Desktop\iTunes.lnk 2022-09-17 17:30 - 2022-09-17 17:30 - 000000000 ____D C:\Users\User\AppData\Local\Apple Computer 2022-09-17 17:30 - 2022-09-17 17:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2022-09-17 17:30 - 2022-09-17 17:30 - 000000000 ____D C:\ProgramData\Apple Computer 2022-09-17 17:30 - 2022-09-17 17:30 - 000000000 ____D C:\Program Files\iTunes 2022-09-17 17:30 - 2022-09-17 17:30 - 000000000 ____D C:\Program Files\iPod 2022-09-17 17:29 - 2022-09-17 17:29 - 000002579 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2022-09-17 17:29 - 2022-09-17 17:29 - 000000000 ____D C:\Users\User\AppData\Local\Apple 2022-09-17 17:29 - 2022-09-17 17:29 - 000000000 ____D C:\Program Files\Common Files\Apple 2022-09-17 17:29 - 2022-09-17 17:29 - 000000000 ____D C:\Program Files\Bonjour 2022-09-17 17:29 - 2022-09-17 17:29 - 000000000 ____D C:\Program Files (x86)\Bonjour 2022-09-17 17:29 - 2022-09-17 17:29 - 000000000 ____D C:\Program Files (x86)\Apple Software Update 2022-09-17 17:28 - 2022-09-17 17:29 - 000000000 ____D C:\ProgramData\Apple 2022-09-17 17:26 - 2022-09-17 17:28 - 270075208 _____ (Apple Inc.) C:\Users\User\Downloads\iTunes64Setup.exe 2022-09-14 14:46 - 2022-09-14 14:46 - 000413696 _____ C:\WINDOWS\system32\AzureCheck.dll 2022-09-14 14:46 - 2022-09-14 14:46 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll 2022-09-14 14:46 - 2022-09-14 14:46 - 000098816 _____ C:\WINDOWS\system32\Drivers\cimfs.sys 2022-09-14 14:46 - 2022-09-14 14:46 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe 2022-09-14 14:46 - 2022-09-14 14:46 - 000011813 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim 2022-09-14 14:32 - 2022-09-14 14:32 - 000000000 ___HD C:\$WinREAgent 2022-09-05 15:41 - 2022-09-05 15:41 - 001534312 _____ C:\Users\User\Downloads\ARRET TRAVAIL BOROT ADRIEN.pdf ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2022-10-04 18:14 - 2018-10-10 19:12 - 000000000 ____D C:\Users\User\AppData\Local\AVAST Software 2022-10-04 18:13 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2022-10-04 17:55 - 2017-07-03 14:50 - 000000000 ____D C:\Program Files (x86)\Google 2022-10-04 17:48 - 2020-09-04 19:54 - 001771594 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2022-10-04 17:48 - 2019-12-07 16:49 - 000791924 _____ C:\WINDOWS\system32\perfh00C.dat 2022-10-04 17:48 - 2019-12-07 16:49 - 000150090 _____ C:\WINDOWS\system32\perfc00C.dat 2022-10-04 17:48 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2022-10-04 17:43 - 2020-09-04 19:56 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2022-10-04 17:43 - 2020-09-04 19:45 - 000008192 ___SH C:\DumpStack.log.tmp 2022-10-04 17:43 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2022-10-04 17:43 - 2017-10-18 07:44 - 000000000 ____D C:\ProgramData\NVIDIA 2022-10-04 17:43 - 2017-07-05 20:32 - 000000000 ____D C:\ProgramData\AVAST Software 2022-10-04 17:40 - 2017-07-03 14:56 - 000000000 ____D C:\ProgramData\ProductData 2022-10-04 17:06 - 2020-09-04 19:45 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2022-10-04 11:22 - 2017-07-07 23:05 - 000000000 ____D C:\Users\User\AppData\LocalLow\Mozilla 2022-10-01 10:22 - 2017-07-03 14:51 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2022-09-30 23:18 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2022-09-30 23:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2022-09-29 22:02 - 2017-07-04 19:52 - 000000000 ____D C:\Users\User\AppData\Local\ElevatedDiagnostics 2022-09-28 22:17 - 2021-12-11 18:51 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4012182184-2294530567-3611176650-1001 2022-09-28 08:26 - 2020-06-23 01:04 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2022-09-28 08:26 - 2020-06-23 01:04 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2022-09-27 13:04 - 2020-09-09 16:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2022-09-27 13:04 - 2020-09-09 16:19 - 000000000 ____D C:\Program Files (x86)\HP 2022-09-27 13:03 - 2021-09-22 14:22 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard 2022-09-27 13:02 - 2020-09-09 16:19 - 000000000 ____D C:\ProgramData\HP 2022-09-17 17:33 - 2017-07-03 15:01 - 000000000 ____D C:\Users\User\AppData\Roaming\Apple Computer 2022-09-17 15:14 - 2018-03-03 04:38 - 000000000 ____D C:\Users\User\AppData\Local\Packages 2022-09-17 15:13 - 2021-12-15 16:28 - 000002626 _____ C:\WINDOWS\system32\Tasks\HPCustParticipation HP ENVY 5640 series 2022-09-17 15:13 - 2021-11-22 15:32 - 000002662 _____ C:\WINDOWS\system32\Tasks\HPCustParticipation HP OfficeJet Pro 9010 series 2022-09-17 15:13 - 2021-03-12 23:48 - 000002458 _____ C:\WINDOWS\system32\Tasks\ASC_PerformanceMonitor 2022-09-17 15:13 - 2021-03-12 23:48 - 000002346 _____ C:\WINDOWS\system32\Tasks\ASC_SkipUac_User 2022-09-17 15:13 - 2020-09-04 19:56 - 000003618 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2022-09-17 15:13 - 2020-09-04 19:56 - 000003518 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2022-09-17 15:13 - 2020-09-04 19:56 - 000003394 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2022-09-17 15:13 - 2020-09-04 19:56 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2022-09-17 15:13 - 2020-09-04 19:56 - 000002276 _____ C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (User) 2022-09-17 15:13 - 2020-09-04 19:56 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software 2022-09-14 17:40 - 2021-09-22 14:23 - 000000000 ____D C:\WINDOWS\system32\Tasks\Hewlett-Packard 2022-09-14 17:38 - 2020-09-04 19:45 - 000569304 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2022-09-14 17:38 - 2017-07-07 23:04 - 000000000 ____D C:\Program Files\Mozilla Firefox 2022-09-14 17:38 - 2017-07-07 23:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\DDFs 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\Provisioning 2022-09-14 17:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2022-09-14 14:50 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2022-09-14 14:46 - 2020-09-04 19:47 - 003011072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2022-09-14 14:26 - 2017-07-03 15:51 - 000000000 ____D C:\WINDOWS\system32\MRT 2022-09-14 14:23 - 2017-07-03 15:51 - 141646296 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2022-09-08 11:06 - 2021-11-15 21:42 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2022-09-08 11:06 - 2017-07-07 23:04 - 000001011 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk ==================== Files in the root of some directories ======== 2020-01-02 20:39 - 2020-01-02 20:39 - 000001047 _____ () C:\Users\User\AppData\Local\recently-used.xbel 2017-07-04 19:59 - 2017-07-04 19:59 - 000000017 _____ () C:\Users\User\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================