Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 09-02-2023 01 Exécuté par touggourt (administrateur) sur PÉPÉJANOT (Hewlett-Packard HP Pavilion 17 Notebook PC) (15-02-2023 18:18:26) Exécuté depuis C:\Users\touggourt\Desktop Profils chargés: touggourt Plate-forme: Microsoft Windows 10 Famille Version 22H2 19045.2486 (X64) Langue: Français (France) Navigateur par défaut: "C:\CONTENU BUREAU\RACCOURCIS\slimjet\Slimjet\slimjet.exe" -- "%1" Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe (C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\MpCopyAccelerator.exe (C:\Users\touggourt\AppData\Local\Programs\Opera\opera.exe ->) (Opera Norway AS -> Opera Software) C:\Users\touggourt\AppData\Local\Programs\Opera\95.0.4635.37\opera_crashreporter.exe (DriverStore\FileRepository\c0360470.inf_amd64_b06c374aee20d185\B360357\atiesrxx.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0360470.inf_amd64_b06c374aee20d185\B360357\atieclxx.exe (explorer.exe ->) (FlashPeak Inc. -> FlashPeak Inc.) C:\CONTENU BUREAU\RACCOURCIS\slimjet\Slimjet\slimjet.exe <12> (explorer.exe ->) (Krzysztof Kowalczyk) [Fichier non signé] C:\Program Files (x86)\SumatraPDF\SumatraPDF.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\MpSigStub.exe (Opera Norway AS -> Opera Software) C:\Users\touggourt\AppData\Local\Programs\Opera\opera.exe <17> (services.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0360470.inf_amd64_b06c374aee20d185\B360357\atiesrxx.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\NisSrv.exe (svchost.exe ->) (Bitdefender SRL -> ) C:\Program Files\Bitdefender\Tools\AntiCryptoWall\BDAntiCryptoWall.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2300_none_7e14edbc7c88b7d5\TiWorker.exe (WhatsApp LLC -> WhatsApp) C:\Users\touggourt\AppData\Local\WhatsApp\app-2.2305.7\WhatsApp.exe <7> (wuauclt.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\AM_Delta.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8505088 2015-07-03] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-07-03] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\Run: [USB Security] => C:\Program Files (x86)\USB Disk Security\USBGuard.exe [695528 2015-01-31] (Lanzhou Itanium Software Technology Co., Ltd. -> Zbshareware Lab) HKLM-x32\...\Run: [AutoTransfer PC] => C:\Program Files (x86)\USB Disk Security\backupmaster.exe [397200 2018-04-08] (Bo Zheng -> Bo Zheng) HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKU\S-1-5-21-2099052359-4194192794-1698811201-1002\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 6\CyberGhost.exe [1398352 2018-06-11] (CyberGhost SRL -> CyberGhost S.A.) HKU\S-1-5-21-2099052359-4194192794-1698811201-1002\...\Run: [Opera Browser Assistant] => C:\Users\touggourt\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3154456 2020-11-25] (Opera Software AS -> Opera Software) HKU\S-1-5-21-2099052359-4194192794-1698811201-1002\...\Run: [MicrosoftEdgeAutoLaunch_E349E25CDDA37349DEA42844FF639202] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4243408 2023-02-14] (Microsoft Corporation -> Microsoft Corporation) HKLM\...\Windows x64\Print Processors\Canon MG3100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDAR.DLL [30208 2012-03-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Windows x64\Print Processors\Canon MG5100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDAD.DLL [28672 2010-08-25] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Windows x64\Print Processors\Epson Inkjet: C:\Windows\System32\spool\prtprocs\x64\EP0NPP01.DLL [38912 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3100 series: C:\WINDOWS\system32\CNMLMAR.DLL [385024 2012-03-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG5100 series: C:\WINDOWS\system32\CNMLMAD.DLL [361472 2010-08-25] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Epson Inbox Language Monitor01: C:\WINDOWS\system32\EP0SLM01.DLL [77824 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION) HKLM\...\Print\Monitors\HP Universal Port Monitor: C:\WINDOWS\system32\hpbprtmon.dll [365568 2012-12-01] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard) HKLM\...\Print\Monitors\pdfcmon: C:\WINDOWS\system32\pdfcmon.dll [114872 2015-01-05] (pdfforge GmbH -> pdfforge GmbH) HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\99.1.36.122\Installer\chrmstp.exe [2022-03-29] (Brave Software, Inc. -> Brave Software, Inc.) HKLM\Software\...\Authentication\Credential Providers: [{538C240D-3DEE-4032-AB4C-08A3A6EB0861}] -> Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2022-01-26] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> AnyDesk Software GmbH) GroupPolicy: Restriction ? <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION ==================== Tâches planifiées (Avec liste blanche) ============ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {0308F20F-4978-490E-81A5-14DD518E4B85} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1562376 2021-08-16] (Adobe Inc. -> Adobe Inc.) Task: {0591CE36-83D0-4B1D-9503-9D0B5429268C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {094CD275-5C71-4753-B57E-5566CA859498} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316} Task: {0F6DBBD1-1FA5-490B-A482-1F43FCC689E6} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969} Task: {1273E017-2A93-4609-8601-456436E6B15C} - System32\Tasks\BDAntiCryptoWallTask => C:\Program Files\Bitdefender\Tools\AntiCryptoWall\BDAntiCryptoWall.exe [1216264 2015-08-17] (Bitdefender SRL -> ) Task: {1F294BB3-C4D3-41D8-8BF5-32256AD886C8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {3223B411-0241-4ABD-9C14-967505F747B0} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [155848 2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) Task: {3B42A365-8E44-4F06-88F9-37CE2F46DC2A} - System32\Tasks\Opera scheduled assistant Autoupdate 1586679088 => C:\Users\touggourt\AppData\Local\Programs\Opera\launcher.exe [2635208 2023-02-08] (Opera Norway AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\touggourt\AppData\Local\Programs\Opera\assistant" $(Arg0) Task: {449F016C-7DE6-41BF-9291-C96FDF1CE882} - System32\Tasks\NCH Software\WavePadDowngrade => C:\Program Files (x86)\NCH Software\WavePad\wavepad.exe [3506712 2018-11-02] (NCH Software Pty Ltd -> NCH Software) Task: {4C4B99D8-61C8-4D91-92EB-076706D06DA4} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [184096 2017-05-31] (Maxthon (Asia) Limited. -> Maxthon International ltd.) Task: {5423E408-20E0-4AC6-AD51-83B377AA7FD2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /DeviceScanR6 (Pas de fichier) Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Task: {778ED82B-1E1F-457C-9105-4673A965DC90} - System32\Tasks\Maxthon5 Update => C:\Program Files (x86)\Maxthon5\bin\Maxthon.exe [170776 2020-02-21] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) Task: {7C0B8362-1CBE-435D-90D4-6AF575F0F8F3} - System32\Tasks\CCleaner Update => C:\Program Files\Cleaner\CCUpdate.exe [684976 2021-03-05] (Piriform Software Ltd -> Piriform) Task: {82C3068F-F8BC-49C0-BF77-10CE80A3FCC3} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2020-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE} Task: {8B6759EE-1C08-4B8F-955C-774AB5A6544E} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1} Task: {9439A3A7-79CC-47F7-9BFF-9FE5020995CC} - System32\Tasks\Opera scheduled Autoupdate 1586679058 => C:\Users\touggourt\AppData\Local\Programs\Opera\launcher.exe [2635208 2023-02-08] (Opera Norway AS -> Opera Software) Task: {9767E806-4B91-4F7D-9426-681BA903A142} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe /send (Pas de fichier) Task: {9C41A5EC-F56C-455E-905E-295D7F84B133} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA} Task: {9EFF7721-0DD2-4126-A008-C52F68D38C30} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [4397144 ] (Synaptics Incorporated -> Synaptics Incorporated) Task: {AC89AD10-E447-49AD-AA6A-CD61C8D970DB} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [69304 2020-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {B1AC6451-C7C7-4366-94D6-E0FF544D2AAC} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [155848 2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) Task: {C9DCF59E-6B97-4C0C-8641-B8261089C8CA} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E} Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371} Task: {D4648684-6E8B-40A8-86D8-9E472E196B05} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {DB21EF32-6BA9-4118-BBC1-BC4FF48961E5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61} Task: {F412EBE5-6857-4500-8C10-9AB6D7185B6E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MpCmdRun.exe [1592184 2022-12-10] (Microsoft Windows Publisher -> Microsoft Corporation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 109.0.66.20 109.0.66.10 Tcpip\..\Interfaces\{00ff6b89-d220-4306-bd49-f1e8f79d4f1c}: [DhcpNameServer] 109.0.66.20 109.0.66.10 Tcpip\..\Interfaces\{2d86388d-f132-416c-a9fe-1b39133c4907}: [DhcpNameServer] 109.0.66.20 109.0.66.10 Tcpip\..\Interfaces\{532d4ce3-b0a6-4bc7-9caf-e9e017009f95}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{e9bfdbe2-591b-4d99-9769-35591778d733}: [NameServer] 192.168.1.1 Edge: ======= DownloadDir: C:\Users\touggourt\Downloads Edge DefaultProfile: Default Edge Profile: C:\Users\touggourt\AppData\Local\Microsoft\Edge\User Data\Default [2023-02-14] Edge Extension: (Malwarebytes Browser Guard) - C:\Users\touggourt\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-02-14] Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] FireFox: ======== FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] Opera: ======= OPR Profile: C:\Users\touggourt\AppData\Roaming\Opera Software\Opera Stable [2023-02-15] OPR DownloadDir: C:\CONTENU BUREAU\A REMETTRE sur BUREAU pour TRI\DESK\OPERA OPR Notifications: Opera Stable -> hxxps://mail.proton.me OPR DefaultSearchURL: Opera Stable -> hxxps://duckduckgo.com/?q={searchTerms} OPR DefaultSearchKeyword: Opera Stable -> duckduckgo.com OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding} OPR Session Restore: Opera Stable -> est activé. OPR Extension: (DuckDuckGo) - C:\Users\touggourt\AppData\Roaming\Opera Software\Opera Stable\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2023-02-11] OPR Extension: (Rich Hints Agent) - C:\Users\touggourt\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2022-10-28] OPR Extension: (Opera Wallet) - C:\Users\touggourt\AppData\Roaming\Opera Software\Opera Stable\Extensions\gojhcdgcpbpfigcaejpfhfegekdgiblk [2023-02-14] OPR Extension: (Amazon Assistant Promotion) - C:\Users\touggourt\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-08-24] OPR Extension: (Google Traduction) - C:\Users\touggourt\AppData\Roaming\Opera Software\Opera Stable\Extensions\mchdgimobfnilobnllpdnompfjkkfdmi [2022-03-28] Brave: ======= BRA DefaultProfile: Default BRA Profile: C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2023-02-15] BRA Extension: (Google Traduction) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2022-03-29] BRA Extension: (Malwarebytes Browser Guard) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-02-11] BRA Extension: (Brave Local Data Files Updater) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2023-02-14] BRA Extension: (Brave NTP background images) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2022-08-12] BRA Extension: (Wallet Data Files Updater) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\BraveWallet [2023-02-13] BRA Extension: (Brave Ad Block Updater (Default)) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2023-02-15] BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2021-09-23] BRA Extension: (Brave Ad Block Updater (AdGuard Français)) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\emaecjinaegfkoklcdafkiocjhoeilao [2023-02-15] BRA Extension: (Brave SpeedReader Updater) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2022-03-10] BRA Extension: (Brave NTP sponsored images) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\lcenblphbmngnohghkhpojmpflebkcpd [2023-02-15] BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2023-02-15] StartMenuInternet: Brave - C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [155016 2017-09-22] (Advanced Micro Devices, Inc. -> ) S3 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-08-16] (Adobe Inc. -> Adobe Inc.) S3 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [106952 2015-07-03] (Andrea Electronics -> Andrea Electronics Corporation) S3 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-16] (Advanced Micro Devices, Inc.) [Fichier non signé] S3 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [3853384 2022-08-11] (philandro Software GmbH -> AnyDesk Software GmbH) S3 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [155848 2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [155848 2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) S3 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [204880 2018-06-11] (CyberGhost SRL -> CyberGhost S.A.) S3 MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [178464 2020-02-21] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) S3 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-16] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\NisSrv.exe [3191256 2023-02-15] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\MsMpEng.exe [133576 2023-02-15] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 ampa; C:\WINDOWS\system32\ampa.sys [38320 2017-02-28] (CHENGDU AOMEI Tech Co., Ltd. -> ) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) S3 ddmdrv; C:\WINDOWS\system32\ddmdrv.sys [35760 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> ) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R1 ElRawDisk; C:\WINDOWS\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation -> EldoS Corporation) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-01-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-01-28] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-29] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) R3 RtlWlanu; C:\WINDOWS\System32\drivers\n300ma.sys [1577792 2012-11-20] (On Networks -> Realtek Semiconductor Corporation) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49576 2023-02-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [473336 2023-02-15] (Microsoft Windows -> Microsoft Corporation) S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [159936 2016-08-16] (NGO -> MBB) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99576 2023-02-15] (Microsoft Windows -> Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34944 2018-05-11] (HP Inc. -> HP) S3 MpKsl5dfe0de5; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{50A21D5F-85AC-4600-A150-E83A7E55F0BA}\MpKslDrv.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Trois mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-02-15 18:18 - 2023-02-15 18:28 - 000024119 _____ C:\Users\touggourt\Desktop\FRST.txt 2023-02-15 18:12 - 2023-02-15 18:23 - 000000000 ___DC C:\FRST 2023-02-15 18:12 - 2023-02-15 18:12 - 000000000 __HDC C:\$WinREAgent 2023-02-15 18:11 - 2023-02-15 18:11 - 002378240 _____ (Farbar) C:\Users\touggourt\Desktop\FRST64.exe 2023-02-15 17:20 - 2023-02-15 17:21 - 000000876 _____ C:\Users\touggourt\Desktop\ZHPSuite.lnk 2023-02-15 17:19 - 2023-02-15 17:19 - 003513544 _____ (Nicolas Coolman) C:\Users\touggourt\Desktop\ZHPSuite.exe 2023-02-14 20:41 - 2023-02-14 20:41 - 000002892 _____ C:\Users\touggourt\Desktop\125.txt 2023-02-14 20:40 - 2023-02-14 20:40 - 000017438 _____ C:\Users\touggourt\Desktop\zhp.txt 2023-02-14 11:23 - 2023-02-14 11:23 - 000002606 _____ C:\Users\touggourt\Desktop\ZHPCleaner (R).txt 2023-02-14 11:19 - 2023-02-14 11:19 - 000002475 _____ C:\Users\touggourt\Desktop\ZHPCleaner (S).txt 2023-02-14 09:52 - 2023-02-14 09:52 - 000000886 _____ C:\Users\touggourt\Desktop\ZHPCleaner.lnk 2023-02-14 09:42 - 2023-02-14 09:44 - 000000000 ___DC C:\AdwCleaner 2023-02-14 09:41 - 2023-02-14 09:41 - 008791352 _____ (Malwarebytes) C:\Users\touggourt\Desktop\adwcleaner.exe 2023-02-14 07:25 - 2023-02-14 11:49 - 000000000 ____D C:\Program Files (x86)\AppCleaner 2023-02-13 21:31 - 2023-02-15 18:08 - 000476909 _____ C:\Users\touggourt\Desktop\ZHPDiag.txt 2023-02-13 19:49 - 2023-02-13 19:49 - 005735936 _____ C:\Users\touggourt\Desktop\Vieilles cartes postales Marseille 129.pps 2023-02-13 17:41 - 2023-02-13 17:41 - 003314888 _____ (Nicolas Coolman) C:\Users\touggourt\Desktop\ZHPDiag3.exe 2023-02-12 18:39 - 2023-02-12 18:39 - 000002228 _____ C:\Users\touggourt\Desktop\WhatsApp.lnk 2023-02-12 18:38 - 2023-02-12 18:39 - 000000000 ____D C:\Users\touggourt\AppData\Local\WhatsApp 2023-02-12 09:33 - 2023-02-12 09:33 - 000000085 _____ C:\Users\touggourt\Desktop\vifi.txt 2023-02-12 08:21 - 2023-02-12 08:21 - 000326640 _____ C:\Users\touggourt\Desktop\WiFi connecté mais pas d'accès internet sous Windows 10.pdf 2023-02-11 19:04 - 2023-02-11 19:05 - 005858839 _____ C:\Users\touggourt\Desktop\Corriger le problème «Wifi limité» (pas d'accès internet).mp4 2023-02-11 17:18 - 2023-02-11 17:19 - 000000000 ____D C:\Users\touggourt\Desktop\LU CI 2023-02-11 16:28 - 2023-02-11 16:28 - 000001537 _____ C:\Users\touggourt\Desktop\wifi fon.txt 2023-02-10 11:26 - 2023-02-10 11:58 - 000000000 ____D C:\Users\touggourt\Desktop\LEA 2023-02-05 20:29 - 2023-02-05 20:29 - 000097520 _____ C:\Users\touggourt\Desktop\WhatsApp Image 2023-02-05 at 19.07.14.jpeg 2023-02-05 20:07 - 2023-02-05 20:08 - 000347868 _____ C:\Users\touggourt\Desktop\LUCIE Bulletin Scolaire.jpeg 2023-02-05 17:13 - 2023-02-13 09:45 - 000000000 ____D C:\Users\touggourt\Desktop\VIDEOS Famille à Trier 2023-02-04 20:38 - 2023-02-05 08:30 - 000000000 ____D C:\Users\touggourt\Desktop\PHOTOS CAMBOIS Meubles à vendre 2023-02-04 11:28 - 2023-02-13 16:49 - 000000000 ____D C:\Users\touggourt\Desktop\Nouveau dossier (2) 2023-02-04 11:05 - 2023-02-10 21:57 - 000000000 ____D C:\Users\touggourt\Desktop\ZIP Famille 2023-02-03 11:51 - 2023-02-14 18:50 - 000000000 ____D C:\Users\touggourt\Desktop\SOPHIE Save 2023-02-03 11:51 - 2023-02-14 15:48 - 000000000 ____D C:\Users\touggourt\Desktop\REM Save 2023-02-03 11:21 - 2023-02-14 19:51 - 000000000 ____D C:\Users\touggourt\Desktop\CHON Save 2023-02-03 11:16 - 2023-02-13 12:10 - 000000000 ____D C:\Users\touggourt\Desktop\JOSEPHINE Save 2023-02-03 11:14 - 2023-02-15 17:06 - 000000000 ____D C:\Users\touggourt\Desktop\CHLOE Save 2023-02-03 11:14 - 2023-02-14 19:46 - 000000000 ____D C:\Users\touggourt\Desktop\HUGO Save 2023-02-03 11:13 - 2023-02-14 19:59 - 000000000 ____D C:\Users\touggourt\Desktop\LUCIE Save 2023-01-30 17:08 - 2023-01-30 17:09 - 000002184 _____ C:\Users\touggourt\Desktop\rundll32.exe.lnk 2023-01-29 19:10 - 2023-01-29 19:10 - 000580451 _____ C:\Users\touggourt\Desktop\URINE boire son __ BIENFAITS.pdf 2023-01-29 18:36 - 2023-01-29 18:37 - 000416633 _____ C:\Users\touggourt\Desktop\HONGROIS Mails.pdf 2023-01-24 21:13 - 2023-01-24 21:13 - 000000599 _____ C:\Users\touggourt\Desktop\SAGESSE AUTOCHTONE.txt 2023-01-24 19:41 - 2023-01-24 19:41 - 000072045 _____ C:\Users\touggourt\Desktop\WhatsApp Image 2023-01-23 at 21.20.08.jpeg 2023-01-23 11:17 - 2023-02-06 20:09 - 000000000 ____D C:\WINDOWS\Minidump 2023-01-23 11:04 - 2023-01-23 11:04 - 000008905 _____ C:\Users\touggourt\Desktop\MESSAGE..... aux......txt 2023-01-20 11:08 - 2023-01-22 20:05 - 000000000 ____D C:\Users\touggourt\Desktop\LUCIE 2023-01-17 15:59 - 2023-01-17 16:02 - 000000000 ____D C:\Users\touggourt\Desktop\IQ Test – WW IQ TEST 2023-01-15 19:36 - 2010-11-03 14:59 - 000004703 _____ C:\Users\touggourt\Desktop\proverbe.txt 2023-01-12 23:32 - 2023-01-12 23:32 - 000002212 _____ C:\Users\touggourt\Desktop\12 01 23 fgfgfggff.txt 2023-01-04 15:05 - 2023-01-16 18:51 - 000000000 ____D C:\Users\touggourt\Desktop\Nouveau dossier 2023-01-02 20:13 - 2023-01-02 20:13 - 000276345 _____ C:\Users\touggourt\Desktop\XVII.Farsang Kupa vkiírás 2023.01.21..pdf 2023-01-01 19:59 - 2023-01-01 19:59 - 000100379 _____ C:\Users\touggourt\Desktop\voeux-licciardi-formation-2023.pdf 2022-12-31 19:46 - 2022-12-31 19:47 - 010516480 _____ C:\Users\touggourt\Desktop\Coucou les Anciens Re.pps 2022-12-31 19:36 - 2023-02-14 20:39 - 000000293 _____ C:\Users\touggourt\Desktop\2023.txt 2022-12-31 19:03 - 2023-01-22 08:13 - 000000000 ____D C:\Users\touggourt\Desktop\rozalia 2022-12-29 15:20 - 2022-12-29 15:20 - 000082890 _____ C:\Users\touggourt\Desktop\2 bras.jpeg 2022-12-29 15:18 - 2022-12-29 15:18 - 000060276 _____ C:\Users\touggourt\Desktop\1 bras.jpeg 2022-12-22 15:19 - 2022-12-22 15:19 - 000056532 _____ C:\Users\touggourt\Desktop\5-768x512-1.jpeg 2022-12-21 15:37 - 2022-12-26 19:50 - 000000453 _____ C:\Users\touggourt\Desktop\Maurice Herboriste.txt 2022-12-11 11:14 - 2023-01-28 18:46 - 000000000 ____D C:\ProgramData\Malwarebytes 2022-11-27 15:59 - 2022-11-27 15:59 - 000000000 ____D C:\Users\touggourt\AppData\Local\cache 2022-11-25 20:17 - 2022-12-27 18:51 - 000011852 _____ C:\Users\touggourt\Desktop\CR GC.txt ==================== Trois mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-02-15 18:12 - 2018-03-03 14:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2023-02-15 18:08 - 2017-06-25 11:32 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\ZHP 2023-02-15 18:00 - 2022-10-28 01:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-02-15 17:44 - 2018-12-06 20:04 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\WhatsApp 2023-02-15 17:20 - 2022-10-31 11:40 - 000000000 ____D C:\Users\touggourt\AppData\Local\ZHP 2023-02-15 17:16 - 2020-04-20 08:27 - 000000000 ____D C:\Program Files\Cleaner 2023-02-15 17:15 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-02-15 16:35 - 2021-11-15 17:39 - 000000000 ____D C:\Users\touggourt\Desktop\PdF à remplir 2023-02-15 09:30 - 2022-10-28 02:10 - 000004208 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2023-02-15 07:19 - 2020-07-15 06:28 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-02-15 07:19 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 2023-02-15 07:19 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-02-14 21:20 - 2022-10-28 02:10 - 000003190 _____ C:\WINDOWS\system32\Tasks\BDAntiCryptoWallTask 2023-02-14 21:03 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\NDF 2023-02-14 20:48 - 2022-10-25 15:35 - 000000290 __RSH C:\ProgramData\ntuser.pol 2023-02-14 20:44 - 2022-10-28 02:10 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-02-14 20:44 - 2021-03-07 00:24 - 000008192 ___SH C:\DumpStack.log.tmp 2023-02-14 20:44 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState 2023-02-14 20:43 - 2019-12-07 10:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI 2023-02-14 20:43 - 2017-09-15 21:51 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin 2023-02-14 20:42 - 2019-05-17 09:11 - 000000000 ____D C:\Program Files (x86)\AnyDesk 2023-02-14 20:29 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF 2023-02-14 20:14 - 2015-01-05 15:50 - 000000000 ____D C:\Users\touggourt\AppData\Local\PDFCreator 2023-02-14 07:28 - 2022-10-27 18:18 - 000000000 ___DC C:\WINDOWS\Panther 2023-02-13 12:10 - 2020-04-13 13:47 - 000000000 ____D C:\Users\touggourt\Downloads\Whats JOSEPHINE avril 2020 2023-02-13 11:14 - 2014-11-20 19:48 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\vlc 2023-02-13 09:25 - 2021-05-20 18:22 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\dvdcss 2023-02-12 18:39 - 2018-12-06 20:05 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp 2023-02-12 18:39 - 2018-12-06 20:03 - 000000000 ____D C:\Users\touggourt\AppData\Local\SquirrelTemp 2023-02-12 11:51 - 2018-06-13 14:24 - 000000000 ____D C:\Users\touggourt\AppData\Local\D3DSCache 2023-02-11 20:12 - 2020-04-12 09:11 - 000001488 _____ C:\Users\touggourt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navigateur Opera.lnk 2023-02-11 20:09 - 2022-10-28 02:10 - 000003690 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2023-02-11 20:09 - 2022-10-28 02:10 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2023-02-11 18:51 - 2022-10-27 22:50 - 000000000 ____D C:\Users\touggourt 2023-02-11 18:43 - 2022-10-28 02:10 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software 2023-02-11 18:43 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2023-02-11 18:43 - 2018-03-15 19:25 - 000000000 ____D C:\bureau 2023-02-11 18:43 - 2015-01-07 21:15 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\XnView 2023-02-11 18:43 - 2013-08-22 16:36 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2023-02-11 18:03 - 2021-03-04 11:53 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\Signal 2023-02-11 18:03 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\registration 2023-02-08 10:12 - 2016-01-17 11:46 - 000000000 ____D C:\temp 2023-02-05 17:07 - 2022-05-20 10:00 - 000000000 ____D C:\Users\touggourt\Desktop\Pál 2023-01-30 18:46 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2023-01-30 18:46 - 2018-12-16 08:52 - 000000000 ____D C:\Users\touggourt\AppData\Local\CrashDumps 2023-01-30 13:20 - 2022-10-28 01:35 - 001924350 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2023-01-30 13:20 - 2019-12-07 15:49 - 000833158 _____ C:\WINDOWS\system32\perfh00C.dat 2023-01-30 13:20 - 2019-12-07 15:49 - 000167888 _____ C:\WINDOWS\system32\perfc00C.dat 2023-01-28 18:55 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2023-01-21 19:45 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-01-21 07:42 - 2020-10-07 10:53 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools ==================== Fichiers à la racine de certains dossiers ======== 2020-02-05 17:38 - 2016-11-26 21:09 - 003299391 _____ (Artec) C:\Users\touggourt\ArtecUSBScannerE+48U(Update)V.1.42.exe 2016-06-13 08:15 - 2016-06-13 08:15 - 000000096 _____ () C:\Users\touggourt\AppData\Roaming\version2.xml 2017-02-15 18:41 - 2017-02-15 18:41 - 000132803 _____ () C:\Users\touggourt\AppData\Local\ars.cache 2017-02-15 18:43 - 2017-02-15 18:43 - 000389166 _____ () C:\Users\touggourt\AppData\Local\census.cache 2020-04-13 14:53 - 2023-01-06 17:45 - 000016896 _____ () C:\Users\touggourt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-02-15 17:13 - 2017-02-15 17:13 - 000000036 _____ () C:\Users\touggourt\AppData\Local\housecall.guid.cache 2015-10-11 10:16 - 2015-10-11 10:16 - 000000888 _____ () C:\Users\touggourt\AppData\Local\recently-used.xbel 2018-02-24 16:42 - 2022-02-03 08:54 - 000007597 _____ () C:\Users\touggourt\AppData\Local\Resmon.ResmonCfg ==================== SigCheckExt ========================= 2015-10-18 13:55 - 2009-02-06 01:09 - 000685568 ____C C:\MiNi-Image.dll 2015-10-18 13:55 - 2010-10-07 23:15 - 001622016 ____C C:\minidir.exe 2015-10-18 13:55 - 2010-10-07 23:14 - 001622016 ____C C:\miniima.exe 2016-07-16 12:42 - 2016-07-16 12:42 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AllJoynDiscoveryPlugin.dll 2013-08-22 12:45 - 2013-08-22 12:45 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-core-fibers-l2-1-1.dll 2013-08-22 12:42 - 2013-08-22 12:42 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-core-psm-appnotify-l1-1-0.dll 2013-08-22 12:43 - 2013-08-22 12:43 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-devices-config-l1-1-1.dll 2013-08-22 12:42 - 2013-08-22 12:42 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-mm-misc-l1-1-1.dll 2013-08-22 12:42 - 2013-08-22 12:42 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-rtcore-ntuser-winevent-l1-1-0.dll 2013-08-22 12:42 - 2013-08-22 12:42 - 000004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-security-cryptoapi-l1-1-0.dll 2016-07-14 13:13 - 2016-07-01 04:57 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpreference.exe 2013-08-22 13:37 - 2013-06-18 16:03 - 000032256 _____ (CANON INC.) C:\WINDOWS\system32\CNHI10A.DLL 2013-08-22 13:37 - 2013-06-18 16:03 - 000180224 _____ (CANON INC.) C:\WINDOWS\system32\CNHL5100.DLL 2013-08-22 13:37 - 2013-06-18 16:03 - 000019968 _____ (CANON INC.) C:\WINDOWS\system32\CNHMCAN.DLL 2015-10-30 08:19 - 2015-10-30 08:19 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafCdp.dll 2017-04-18 08:46 - 2017-03-28 06:37 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DdcWnsListener.dll 2014-12-17 20:02 - 2014-10-29 02:59 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dfp.exe 2014-12-17 20:07 - 2014-10-29 02:54 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DfpCommon.dll 2013-08-22 12:42 - 2013-08-22 12:42 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ext-ms-win-msa-ui-l1-1-0.dll 2013-08-22 12:42 - 2013-08-22 12:42 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ext-ms-win-ntuser-misc-l1-2-0.dll 2013-08-22 12:42 - 2013-08-22 12:42 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ext-ms-win-rtcore-ntuser-dpi-l1-1-0.dll 2016-07-16 12:41 - 2016-07-16 12:41 - 003447296 _____ (Hewlett-Packard Co.) C:\WINDOWS\system32\HPScanTRDrvWn8.dll 2016-07-16 12:41 - 2016-07-16 12:41 - 000303616 _____ (Hewlett-Packard) C:\WINDOWS\system32\HPWia2DrvRootWn8.dll 2012-07-25 21:22 - 2012-07-26 04:07 - 004722176 _____ (Intel Corporation) C:\WINDOWS\system32\igd10umd64.dll 2012-07-25 21:22 - 2012-07-26 04:07 - 006549504 _____ (Intel Corporation) C:\WINDOWS\system32\igdumd64.dll 2017-05-11 19:58 - 2017-03-04 07:26 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-07-16 12:43 - 2016-07-16 23:45 - 003584000 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkAnalysisLegacyCom.dll 2012-11-27 00:18 - 2012-11-27 00:18 - 000050688 _____ C:\WINDOWS\system32\kdbsdk64.dll 2015-08-20 21:55 - 2014-11-19 10:20 - 001207670 _____ (The GLib developer community) C:\WINDOWS\system32\libglib-2.0-0.dll 2014-10-20 12:16 - 2014-07-10 05:08 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\lockscreencn.dll 2005-09-13 16:27 - 2005-09-13 16:27 - 000054784 _____ C:\WINDOWS\system32\lxbkcnv5.dll 2006-10-14 09:59 - 2006-10-14 09:59 - 001462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\lxbkg.dll 2007-02-28 14:00 - 2007-02-28 14:00 - 000138240 _____ (Funai) C:\WINDOWS\system32\rtscan.dll 2015-10-30 08:18 - 2015-10-30 08:18 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flashlight.dll 2012-07-18 19:30 - 2012-07-18 19:30 - 000007680 _____ (Voyage au bout de la langue) C:\WINDOWS\system32\voyaFRHU.dll 2014-12-17 20:03 - 2014-10-29 03:09 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiafbdrv.dll 2016-07-16 12:42 - 2016-07-16 12:42 - 000076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDiscoveryPlugin.dll 2016-07-16 12:42 - 2016-07-16 12:42 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiOnboardingPlugin.dll 2015-04-11 20:09 - 2015-03-14 02:51 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll 2019-04-17 17:20 - 2016-09-29 08:44 - 001298584 _____ C:\WINDOWS\ddmmain.exe 2018-12-16 11:29 - 2018-12-16 11:29 - 000253952 _____ (Microsoft Corporation) C:\WINDOWS\Setup1.exe 2018-12-16 11:29 - 2018-12-16 11:29 - 000074752 _____ (Microsoft Corporation) C:\WINDOWS\ST6UNST.EXE 2013-08-22 05:17 - 2013-08-22 05:17 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-core-fibers-l2-1-1.dll 2013-08-22 05:14 - 2013-08-22 05:14 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-core-psm-appnotify-l1-1-0.dll 2013-08-22 05:14 - 2013-08-22 05:14 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-devices-config-l1-1-1.dll 2013-08-22 05:14 - 2013-08-22 05:14 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-mm-misc-l1-1-1.dll 2013-08-22 05:14 - 2013-08-22 05:14 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-rtcore-ntuser-winevent-l1-1-0.dll 2013-08-22 05:14 - 2013-08-22 05:14 - 000004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-security-cryptoapi-l1-1-0.dll 2015-10-21 08:22 - 2005-02-24 13:10 - 002084864 _____ (NCT Company Ltd.) C:\WINDOWS\SysWOW64\AudDesign.dll 2015-10-21 08:22 - 2005-02-24 13:10 - 000417792 _____ (NCT Company Ltd.) C:\WINDOWS\SysWOW64\AudDisplay.dll 2015-10-21 08:11 - 2011-09-29 13:20 - 001986560 _____ (NCT Company Ltd.) C:\WINDOWS\SysWOW64\AudFile.dll 2015-10-21 08:11 - 2011-09-29 13:20 - 001212416 _____ (NCT Company Ltd.) C:\WINDOWS\SysWOW64\AudioInfos.dll 2015-10-21 08:22 - 2005-03-10 17:00 - 000454656 _____ (NCT Company Ltd.) C:\WINDOWS\SysWOW64\AudioRecord.dll 2015-10-21 08:22 - 2005-02-24 13:11 - 000479232 _____ (NCT Company Ltd.) C:\WINDOWS\SysWOW64\AudioVisu.dll 2015-10-21 08:11 - 2011-09-29 13:20 - 000458752 _____ (NCT Company Ltd.) C:\WINDOWS\SysWOW64\AudPlayer.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000974848 _____ C:\WINDOWS\SysWOW64\cis-2.4.dll 2015-10-21 08:11 - 2011-09-29 13:19 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CMDLGFR.DLL 2016-07-16 12:43 - 2016-07-16 12:43 - 000300032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\configmanager2.dll 2016-07-16 12:43 - 2016-07-16 12:43 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coredpus.dll 2015-10-30 08:19 - 2015-10-30 08:19 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafCdp.dll 2014-09-26 16:29 - 1999-01-20 05:01 - 000210032 _____ C:\WINDOWS\SysWOW64\DBCLIENT.DLL 2007-04-27 09:43 - 2007-04-27 09:43 - 000120200 _____ () C:\WINDOWS\SysWOW64\DLLDEV32i.dll 1997-09-12 00:00 - 1997-09-12 00:00 - 000022016 _____ C:\WINDOWS\SysWOW64\DOCOBJ.DLL 2013-08-22 05:14 - 2013-08-22 05:14 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ext-ms-win-msa-ui-l1-1-0.dll 2013-08-22 05:14 - 2013-08-22 05:13 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ext-ms-win-ntuser-misc-l1-2-0.dll 2013-08-22 05:14 - 2013-08-22 05:13 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ext-ms-win-rtcore-ntuser-dpi-l1-1-0.dll 1997-09-12 00:00 - 1997-09-12 00:00 - 000012288 _____ C:\WINDOWS\SysWOW64\HLINKPRX.DLL 2012-07-25 21:22 - 2012-06-02 15:32 - 004338688 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10umd32.dll 2012-07-25 21:22 - 2012-06-02 15:32 - 004896768 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumd32.dll 2017-03-20 12:37 - 2017-03-04 07:18 - 000198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2015-10-21 08:11 - 2011-09-29 13:19 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetfr.DLL 2016-07-16 12:44 - 2016-07-16 23:45 - 002549760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkAnalysisLegacyCom.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000081920 _____ C:\WINDOWS\SysWOW64\issacapi_bs-2.3.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000065536 _____ C:\WINDOWS\SysWOW64\issacapi_pe-2.3.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000057344 _____ C:\WINDOWS\SysWOW64\issacapi_se-2.3.dll 2014-09-12 09:03 - 2010-12-01 08:31 - 000451072 _____ C:\WINDOWS\SysWOW64\ISSRemoveSP.exe 2012-11-27 00:18 - 2012-11-27 00:18 - 000038912 _____ C:\WINDOWS\SysWOW64\kdbsdk32.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000045056 _____ ((주) 마크애니) C:\WINDOWS\SysWOW64\MACXMLProto.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000118784 _____ ((주)마크애니) C:\WINDOWS\SysWOW64\MaDRM.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000049152 _____ ((주) 마크애니) C:\WINDOWS\SysWOW64\MaJGUILib.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000045320 _____ (MARKANY) C:\WINDOWS\SysWOW64\MAMACExtract.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000024576 _____ ((주)마크애니) C:\WINDOWS\SysWOW64\MASetupCleaner.exe 2016-05-17 22:49 - 2016-05-17 22:49 - 000045056 _____ ((주) 마크애니) C:\WINDOWS\SysWOW64\MaXMLProto.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000057344 _____ (Marktek) C:\WINDOWS\SysWOW64\MK_Lyric.dll 2015-10-30 08:19 - 2016-09-14 11:26 - 000014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll 2015-10-30 08:19 - 2016-09-14 11:26 - 000635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll 2015-10-21 08:11 - 2011-09-29 13:19 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Mscc2fr.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000245760 _____ (Teruten Inc.) C:\WINDOWS\SysWOW64\MSCLib.dll 2015-10-21 08:11 - 2011-09-29 13:19 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCMCFR.DLL 2016-05-17 22:49 - 2016-05-17 22:49 - 000155648 _____ (Teruten Inc.) C:\WINDOWS\SysWOW64\MSFLib.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000352256 _____ (Sample Corporation) C:\WINDOWS\SysWOW64\MSLUR71.dll 2014-09-12 09:23 - 2014-09-12 09:23 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp71.dll 2014-09-12 09:23 - 2014-09-12 09:23 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr71.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000040960 _____ (Telechips Inc.,) C:\WINDOWS\SysWOW64\MTTELECHIP.dll 2016-05-17 22:49 - 2016-05-17 22:49 - 000057344 _____ (Marktek Inc.) C:\WINDOWS\SysWOW64\MTXSYNCICON.dll 2018-07-09 07:46 - 2016-05-17 22:49 - 004659712 _____ (Dmitry Streblechenko) C:\WINDOWS\SysWOW64\Redemption.dll 2017-01-11 15:47 - 2001-07-10 18:01 - 000045056 _____ (ULTIMA ELECTRONICS CORP.) C:\WINDOWS\SysWOW64\Remove48U.exe 2014-10-23 18:40 - 2012-02-14 18:37 - 000594432 _____ (Realtek Semiconductor Corp. ) C:\WINDOWS\SysWOW64\Rtlihvs.dll 2015-10-21 08:11 - 2011-09-29 13:19 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TABCTFR.DLL 2015-10-21 08:11 - 2011-09-29 13:19 - 000119568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VB6FR.DLL 2015-10-21 08:11 - 2011-09-29 13:19 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VB6STKIT.DLL 2012-07-18 19:30 - 2012-07-18 19:30 - 000007680 _____ (Voyage au bout de la langue) C:\WINDOWS\SysWOW64\voyaFRHU.dll 2006-10-26 12:45 - 2006-10-26 12:45 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WISPTIS.EXE 2015-10-21 08:11 - 2011-09-29 13:20 - 000348160 _____ (NCT Company Ltd.) C:\WINDOWS\SysWOW64\WMAFile.dll 2020-02-05 17:38 - 2016-11-26 21:09 - 003299391 _____ (Artec) C:\Users\touggourt\ArtecUSBScannerE+48U(Update)V.1.42.exe 2023-02-15 18:11 - 2023-02-15 18:11 - 002378240 _____ (Farbar) C:\Users\touggourt\Desktop\FRST64.exe 2023-02-13 17:41 - 2023-02-13 17:41 - 003314888 _____ (Nicolas Coolman) C:\Users\touggourt\Desktop\ZHPDiag3.exe 2023-02-15 17:19 - 2023-02-15 17:19 - 003513544 _____ (Nicolas Coolman) C:\Users\touggourt\Desktop\ZHPSuite.exe ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== BCD ================================ Gestionnaire de d‚marrage du microprogramme ------------------------------------------- identificateur {fwbootmgr} displayorder {bootmgr} {25c4cfe3-5472-11ed-824c-806e6f6e6963} {4d8bebb6-3aa3-11e4-8ad4-947cdaeb8744} {4d8bebb7-3aa3-11e4-8ad4-947cdaeb8744} timeout 5 Gestionnaire de d‚marrage Windows --------------------------------- identificateur {bootmgr} device partition=\Device\HarddiskVolume2 path \EFI\Microsoft\Boot\bootmgfw.efi description Windows Boot Manager locale fr-FR inherit {globalsettings} default {current} resumeobject {566c5309-7ed3-11eb-81f4-c49c7e26f49b} displayorder {current} toolsdisplayorder {memdiag} timeout 30 Application logicielle (101fffff) -------------------------------- identificateur {25c4cfe3-5472-11ed-824c-806e6f6e6963} description Internal Hard Disk or Solid State Disk Application logicielle (101fffff) -------------------------------- identificateur {4d8bebb6-3aa3-11e4-8ad4-947cdaeb8744} description USB Drive (UEFI) Application logicielle (101fffff) -------------------------------- identificateur {4d8bebb7-3aa3-11e4-8ad4-947cdaeb8744} description Internal CD/DVD ROM Drive (UEFI) Application logicielle (101fffff) -------------------------------- identificateur {4d8bebb8-3aa3-11e4-8ad4-947cdaeb8744} description Internal Hard Disk or Solid State Disk Application logicielle (101fffff) -------------------------------- identificateur {4d8bebb9-3aa3-11e4-8ad4-947cdaeb8744} description Internal Hard Disk or Solid State Disk Application logicielle (101fffff) -------------------------------- identificateur {4d8bebba-3aa3-11e4-8ad4-947cdaeb8744} description Internal Hard Disk or Solid State Disk Application logicielle (101fffff) -------------------------------- identificateur {4d8bebbb-3aa3-11e4-8ad4-947cdaeb8744} description Notebook Hard Drive Application logicielle (101fffff) -------------------------------- identificateur {4d8bebbc-3aa3-11e4-8ad4-947cdaeb8744} description Network Adapter (IPv4 Legacy) Application logicielle (101fffff) -------------------------------- identificateur {863468e2-3a4f-11e4-be69-806e6f6e6963} description Internal Hard Disk or Solid State Disk Application logicielle (101fffff) -------------------------------- identificateur {edfb49db-9b06-11ed-825f-806e6f6e6963} description USB Hard Drive - Samsung M3 Portable Chargeur de d‚marrage Windows ----------------------------- identificateur {4d8bebc7-3aa3-11e4-8ad4-947cdaeb8744} device ramdisk=[unknown]\Recovery\WindowsRE\Winre.wim,{4d8bebc8-3aa3-11e4-8ad4-947cdaeb8744} path \windows\system32\winload.efi description Windows Recovery Environment locale fr-FR inherit {bootloadersettings} displaymessage Recovery displaymessageoverride Recovery osdevice ramdisk=[unknown]\Recovery\WindowsRE\Winre.wim,{4d8bebc8-3aa3-11e4-8ad4-947cdaeb8744} systemroot \windows nx OptIn bootmenupolicy Standard winpe Yes Chargeur de d‚marrage Windows ----------------------------- identificateur {current} device partition=C: path \WINDOWS\system32\winload.efi description Windows 10 locale fr-FR inherit {bootloadersettings} recoverysequence {d01a3762-5653-11ed-824e-d3505b6e4513} displaymessageoverride Recovery recoveryenabled Yes isolatedcontext Yes allowedinmemorysettings 0x15000075 osdevice partition=C: systemroot \WINDOWS resumeobject {566c5309-7ed3-11eb-81f4-c49c7e26f49b} nx OptIn bootmenupolicy Standard Chargeur de d‚marrage Windows ----------------------------- identificateur {d01a3762-5653-11ed-824e-d3505b6e4513} device ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{d01a3763-5653-11ed-824e-d3505b6e4513} path \windows\system32\winload.efi description Windows Recovery Environment locale fr-FR inherit {bootloadersettings} displaymessage Recovery osdevice ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{d01a3763-5653-11ed-824e-d3505b6e4513} systemroot \windows nx OptIn bootmenupolicy Standard winpe Yes Reprendre … partir de la mise en veille prolong‚e ------------------------------------------------- identificateur {566c5309-7ed3-11eb-81f4-c49c7e26f49b} device partition=C: path \WINDOWS\system32\winresume.efi description Windows Resume Application locale fr-FR inherit {resumeloadersettings} recoverysequence {d01a3762-5653-11ed-824e-d3505b6e4513} recoveryenabled Yes isolatedcontext Yes allowedinmemorysettings 0x15000075 filedevice partition=C: filepath \hiberfil.sys bootmenupolicy Standard debugoptionenabled No Testeur de m‚moire Windows -------------------------- identificateur {memdiag} device partition=\Device\HarddiskVolume2 path \EFI\Microsoft\Boot\memtest.efi description Diagnostics m‚moire Windows locale fr-FR inherit {globalsettings} badmemoryaccess Yes ParamŠtres EMS -------------- identificateur {emssettings} bootems No ParamŠtres du d‚bogueur ----------------------- identificateur {dbgsettings} debugtype Serial debugport 1 baudrate 115200 Erreurs de m‚moire RAM ---------------------- identificateur {badmemory} ParamŠtres globaux ------------------ identificateur {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} ParamŠtres du chargeur de d‚marrage ----------------------------------- identificateur {bootloadersettings} inherit {globalsettings} {hypervisorsettings} ParamŠtres de l'hyperviseur ------------------- identificateur {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 ParamŠtres du chargeur de reprise --------------------------------- identificateur {resumeloadersettings} inherit {globalsettings} Options de p‚riph‚rique ----------------------- identificateur {d01a3763-5653-11ed-824e-d3505b6e4513} description Windows Recovery ramdisksdidevice partition=\Device\HarddiskVolume5 ramdisksdipath \Recovery\WindowsRE\boot.sdi ==================== Fin de FRST.txt ========================