Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 28-06-2023 Exécuté par jmnau (administrateur) sur PC-FIXE-DE-JM (Gigabyte Technology Co., Ltd. H510M H) (30-06-2023 15:48:13) Exécuté depuis D:\OneDrive_D\OneDrive\Documents JMN\Desktop\FRST64.exe Profils chargés: jmnau Plate-forme: Microsoft Windows 11 Professionnel Version 22H2 22621.1848 (X64) Langue: Anglais (Royaume-Uni) -> Français (France) Navigateur par défaut: FF Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Audials AG -> ) C:\Program Files\Audials\Audials 2023\AudialsNotifier.exe (C:\Program Files\WindowsApps\MicrosoftTeams_23119.303.2080.2726_x64__8wekyb3d8bbwe\msteams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\114.0.1823.58\msedgewebview2.exe <13> (DriverStore\FileRepository\cui_dch.inf_amd64_2fd56aca57cf42dd\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_2fd56aca57cf42dd\igfxEM.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5> (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_2fd56aca57cf42dd\igfxCUIService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_9d19662e01abea6b\OneApp.IGCC.WinService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_0797c0ea8580ae89\IntelCpHDCPSvc.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_0797c0ea8580ae89\IntelCpHeciSvc.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\23.122.0611.0001\FileSyncHelper.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\NisSrv.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe <2> (services.exe ->) (SafeNet, Inc. -> SafeNet Inc.) C:\Windows\System32\hasplms.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe (svchost.exe ->) (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> ) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.214.1149.0_x86__zpdnekdrzrea0\XboxGameBarSpotify.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\23.122.0611.0001\FileCoAuth.exe (svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.13900.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_bc81681eb27bc1ae\RtkAudUService64.exe [1231864 2021-02-17] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKU\S-1-5-21-3722162592-3493389248-2344746714-1006\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2606472 2023-06-29] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-3722162592-3493389248-2344746714-1006\...\Run: [AudialsNotifier] => C:\Program Files\Audials\Audials 2023\AudialsNotifier.exe [2203840 2022-10-20] (Audials AG -> ) HKU\S-1-5-21-3722162592-3493389248-2344746714-1006\...\Run: [MicrosoftEdgeAutoLaunch_878A606CA185B854FF5CCF8AFD397E8F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4113856 2023-06-22] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-3722162592-3493389248-2344746714-1006\...\MountPoints2: {667b2d82-a925-11ed-99a7-803f5d020a27} - "H:\Setup.exe" ==================== Tâches planifiées (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {0105D32C-C7C6-4580-801C-EAF9712CCBAD} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26557352 2023-06-25] (Microsoft Corporation -> Microsoft Corporation) Task: {19235784-74D7-4D56-B3AE-5DBC9F0FC9B7} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [170456 2023-06-09] (Microsoft Corporation -> Microsoft Corporation) Task: {1E9A2C26-DE74-4454-BBBE-3EDAAF028E8A} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3722162592-3493389248-2344746714-1006 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4150136 2023-06-29] (Microsoft Corporation -> Microsoft Corporation) Task: {2B8BD174-6686-4C74-B7FD-F4368089DCBD} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4150136 2023-06-29] (Microsoft Corporation -> Microsoft Corporation) Task: {422BE114-5440-4C5D-9B0E-7B358BC6C5BA} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [732064 2023-06-22] (Mozilla Corporation -> Mozilla Foundation) Task: {5486C9D4-877C-4D98-A584-64526D4B9D01} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564152 2023-04-03] (Adobe Inc. -> Adobe Inc.) Task: {7C6740E1-2A02-4750-9455-908070B8D62B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe [1650040 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {91ABE6C0-271D-43EC-9478-B35920CAAB27} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [157632 2023-06-25] (Microsoft Corporation -> Microsoft Corporation) Task: {C61DDD53-EB82-4F0E-92F8-16D8B5C91A63} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe [1650040 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {CE27854C-F6C5-48FB-8251-0871C46F6D5D} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [680352 2023-06-22] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {D0AABAB0-FF53-4185-940A-436EF68ABCD9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe [1650040 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {E31E5716-BB82-4889-A9EE-B1B58F260F90} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [157632 2023-06-25] (Microsoft Corporation -> Microsoft Corporation) Task: {EE133856-3568-4ACC-BB39-99C2F3633A6F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MpCmdRun.exe [1650040 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {FA7CE884-D5D8-4578-81D3-8FD902AFEBC0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26557352 2023-06-25] (Microsoft Corporation -> Microsoft Corporation) Task: {FCAE8FE7-5803-445F-80C2-A0134AC5628A} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\Explorer.exe [5071384 2023-06-14] (Microsoft Windows -> Microsoft Corporation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{33ae9cfe-8a54-4783-949f-ba0af2507e3e}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{722d3bfa-fbae-4c09-bba3-64886b1c7be7}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{f4f656de-3030-4128-b3eb-173cf0e5af72}: [DhcpNameServer] 192.168.1.254 Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\jmnau\AppData\Local\Microsoft\Edge\User Data\Default [2023-06-30] Edge Extension: (Edge relevant text changes) - C:\Users\jmnau\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-04-25] FireFox: ======== FF DefaultProfile: lp77kve2.default-1478419688235 FF ProfilePath: C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\ajiqg1f2.default-release [2022-10-15] FF Session Restore: Mozilla\Firefox\Profiles\ajiqg1f2.default-release -> est activé. FF ProfilePath: C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235 [2023-06-30] FF DownloadDir: D:\OneDrive_D\OneDrive\Documents JMN\Desktop FF Homepage: Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235 -> hxxps://duckduckgo.com/ FF Session Restore: Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235 -> est activé. FF Extension: (Disconnect) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235\Extensions\2.0@disconnect.me.xpi [2021-06-02] FF Extension: (Disable HTML5 Autoplay) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235\Extensions\disable-html5-autoplay@afnankhan.xpi [2020-04-15] FF Extension: (Dictionnaire français) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235\Extensions\fr-dicollecte@dictionaries.addons.mozilla.org.xpi [2020-05-30] FF Extension: (DuckDuckGo Privacy Essentials) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235\Extensions\jid1-ZAdIEUB7XOzOJw@jetpack.xpi [2023-06-29] FF Extension: (Decodex) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235\Extensions\lemonde-decodex@lemonde.fr.xpi [2020-01-18] FF Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-06-21] FF Extension: (Add-ons Restricted Domains) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\lp77kve2.default-1478419688235\features\{920a5b06-816f-4068-a3f7-d8c58ce9a812}\addons-restricted-domains@mozilla.com.xpi [2023-06-24] FF ProfilePath: C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\ei5oj8t2.default-1401315239375 [2022-10-15] FF Homepage: Mozilla\Firefox\Profiles\ei5oj8t2.default-1401315239375 -> hxxp://duckduckgo.com/ FF Extension: (Ghostery) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\ei5oj8t2.default-1401315239375\Extensions\firefox@ghostery.com.xpi [2016-05-04] [] FF Extension: (YouTube mp3) - C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\ei5oj8t2.default-1401315239375\Extensions\info@youtube-mp3.org.xpi [2016-06-11] [] FF SearchPlugin: C:\Users\jmnau\AppData\Roaming\Mozilla\Firefox\Profiles\ei5oj8t2.default-1401315239375\searchplugins\McSiteAdvisor.xml [2016-03-09] FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-01] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-06-14] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-01] (Microsoft Corporation -> Microsoft Corporation) ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11774352 2023-06-25] (Microsoft Corporation -> Microsoft Corporation) R3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\23.122.0611.0001\FileSyncHelper.exe [3446648 2023-06-29] (Microsoft Corporation -> Microsoft Corporation) R2 hasplms; C:\WINDOWS\system32\hasplms.exe [4683144 2014-07-17] (SafeNet, Inc. -> SafeNet Inc.) R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [230352 2023-06-14] (HP Inc. -> HP Inc.) S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\23.122.0611.0001\OneDriveUpdaterService.exe [3782520 2023-06-29] (Microsoft Corporation -> Microsoft Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [336144 2023-06-14] (Microsoft Windows Publisher -> Microsoft Corporation) R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [20667704 2023-06-19] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\NisSrv.exe [3232576 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23050.5-0\MsMpEng.exe [133592 2023-06-13] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R3 akshasp; C:\WINDOWS\system32\DRIVERS\akshasp.sys [60488 2014-07-17] (SafeNet, Inc. -> SafeNet Inc.) R3 akshhl; C:\WINDOWS\system32\DRIVERS\akshhl.sys [63944 2014-07-17] (SafeNet, Inc. -> SafeNet Inc.) R3 aksusb; C:\WINDOWS\system32\DRIVERS\aksusb.sys [303624 2014-07-17] (SafeNet, Inc. -> SafeNet Inc.) R3 amdfendrmgr; C:\WINDOWS\System32\drivers\amdfendrmgr.sys [41376 2021-07-30] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [65168 2021-08-17] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [532480 2022-10-09] (Microsoft Corporation) [Fichier non signé] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [184320 2022-10-09] (Microsoft Corporation) [Fichier non signé] S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [106496 2022-05-07] (Microsoft Corporation) [Fichier non signé] R3 dlcdcncm; C:\WINDOWS\System32\drivers\dlcdcncm62_x64.sys [90344 2020-04-28] (DISPLAYLINK (UK) LIMITED -> DisplayLink Corp.) R2 hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [331608 2014-07-17] (SafeNet, Inc. -> SafeNet Inc.) R3 iaLPSS2_GPIO2_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_cb8dd04b85ac9a58\iaLPSS2_GPIO2_TGL.sys [128680 2020-12-23] (Intel Corporation -> Intel Corporation) R3 MpKslf557e434; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E409DE6D-4F77-49A1-9CC7-97FBD0130FB2}\MpKslDrv.sys [213288 2023-06-30] (Microsoft Windows -> Microsoft Corporation) R3 rtcx21; C:\WINDOWS\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek) S3 UsbNcm; C:\WINDOWS\System32\drivers\UsbNcm.sys [167936 2022-05-07] (Microsoft Windows -> ) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2023-06-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [169232 2022-05-07] (Microsoft Windows -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [498944 2023-06-13] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99568 2023-06-13] (Microsoft Windows -> Microsoft Corporation) S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-06-28 14:36 - 2023-06-28 14:36 - 000023387 _____ C:\Users\jmnau\Downloads\FA2023-142952.pdf 2023-06-27 17:38 - 2023-06-27 17:38 - 000126276 _____ C:\Users\jmnau\Downloads\CANAL+ formulaire de résiliation.pdf 2023-06-27 17:37 - 2023-06-27 17:37 - 000049383 _____ C:\Users\jmnau\Downloads\formulaire-donnees-personnelles.pdf 2023-06-24 12:51 - 2023-06-24 12:51 - 000097024 _____ C:\Users\jmnau\Downloads\FORM-RETRACTATION.pdf 2023-06-24 12:00 - 2023-06-24 12:00 - 000036223 _____ C:\Users\jmnau\Downloads\Facture_Free_202306_27524429_1206609364.pdf 2023-06-22 19:26 - 2023-06-22 23:53 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-06-20 18:43 - 2023-06-20 18:43 - 000771570 _____ C:\WINDOWS\system32\perfh00C.dat 2023-06-20 18:43 - 2023-06-20 18:43 - 000148698 _____ C:\WINDOWS\system32\perfc00C.dat 2023-06-14 18:12 - 2023-06-14 18:12 - 000000000 ___HD C:\$WinREAgent 2023-06-13 23:42 - 2023-06-13 23:42 - 000000000 ____D C:\Users\jmnau\AppData\Roaming\Microsoft\Document Building Blocks 2023-06-12 23:46 - 2023-06-12 23:46 - 000020317 _____ C:\Users\jmnau\Downloads\affiche chorale.odt 2023-06-12 17:53 - 2023-06-14 12:40 - 000000000 ____D C:\Program Files\Mozilla Thunderbird 2023-06-09 11:44 - 2023-06-09 11:44 - 000158520 _____ C:\Users\jmnau\Downloads\Avis_de_taxes_foncieres_2022 2.pdf 2023-06-09 11:43 - 2023-06-09 11:43 - 000157993 _____ C:\Users\jmnau\Downloads\Avis_de_taxes_foncieres_2022.pdf 2023-06-07 11:47 - 2023-06-07 11:47 - 000121564 _____ C:\Users\jmnau\Downloads\OSCAISS_DPP_editionRibV2.pdf 2023-06-06 12:14 - 2023-06-06 12:14 - 000118847 _____ C:\Users\jmnau\Downloads\facture_freemobile_20230426.pdf 2023-06-06 12:12 - 2023-06-06 12:12 - 000090214 _____ C:\Users\jmnau\Downloads\recapitulatif_multilignes_freemobile_20230606.pdf 2023-06-01 11:47 - 2023-06-01 11:47 - 000164884 _____ C:\Users\jmnau\Downloads\AttestationDroits.pdf 2023-05-31 16:52 - 2023-05-31 16:52 - 000235765 _____ C:\Users\jmnau\Downloads\Facture 0423.pdf 2023-05-31 16:50 - 2023-05-31 16:50 - 000236885 _____ C:\Users\jmnau\Downloads\Facture.pdf ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-06-30 15:48 - 2023-03-01 18:41 - 000000000 ____D C:\FRST 2023-06-30 15:47 - 2022-10-22 23:56 - 000000000 ____D C:\Users\jmnau\AppData\Local\CrashDumps 2023-06-30 15:47 - 2022-10-09 00:56 - 000000000 ____D C:\Users\jmnau\AppData\LocalLow\Mozilla 2023-06-30 15:47 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-06-30 15:28 - 2022-10-09 00:28 - 000000000 ____D C:\Users\jmnau\AppData\Local\D3DSCache 2023-06-30 15:28 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemTemp 2023-06-30 14:34 - 2022-10-09 13:13 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-06-30 12:13 - 2022-10-09 00:56 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2023-06-30 11:27 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps 2023-06-30 11:27 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-06-30 09:51 - 2022-10-09 17:37 - 000000000 ____D C:\Users\jmnau\AppData\Roaming\Microsoft\Excel 2023-06-30 09:44 - 2022-10-09 00:19 - 000000000 __SHD C:\Users\jmnau\IntelGraphicsProfiles 2023-06-29 11:38 - 2022-10-10 23:27 - 000000000 ____D C:\Program Files\TeamViewer 2023-06-29 09:44 - 2022-10-09 20:14 - 000000000 ____D C:\Users\jmnau\AppData\Roaming\Microsoft\Word 2023-06-29 08:37 - 2022-10-09 13:18 - 000003596 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3722162592-3493389248-2344746714-1006 2023-06-29 08:37 - 2022-10-09 13:18 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task 2023-06-29 08:37 - 2022-10-09 09:56 - 000000000 ____D C:\Program Files\Microsoft OneDrive 2023-06-29 08:37 - 2022-10-09 08:56 - 000002170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2023-06-25 17:01 - 2022-10-09 01:12 - 000000000 ____D C:\Program Files\Microsoft Office 2023-06-24 11:56 - 2023-01-17 22:52 - 000002282 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2023-06-24 11:56 - 2021-10-24 20:24 - 000002444 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-06-22 23:53 - 2022-10-09 00:56 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2023-06-22 23:53 - 2022-10-09 00:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2023-06-22 15:00 - 2022-10-11 21:37 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2023-06-22 15:00 - 2022-10-11 21:37 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk 2023-06-22 15:00 - 2022-10-11 21:37 - 000002061 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk 2023-06-20 23:43 - 2022-10-09 13:15 - 000000000 ____D C:\Users\jmnau 2023-06-20 18:43 - 2022-10-09 13:22 - 001713450 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2023-06-20 18:43 - 2022-05-07 07:22 - 000000000 ____D C:\WINDOWS\INF 2023-06-20 18:36 - 2022-10-09 13:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-06-20 18:36 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ServiceState 2023-06-20 18:36 - 2022-04-25 23:50 - 000000000 ____D C:\Intel 2023-06-20 18:36 - 2021-10-24 20:23 - 000012288 ___SH C:\DumpStack.log.tmp 2023-06-17 19:11 - 2022-10-09 11:19 - 000000000 ____D C:\ProgramData\PC SOFT 2023-06-14 23:08 - 2022-10-09 13:18 - 000003690 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2023-06-14 23:08 - 2022-10-09 13:18 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2023-06-14 18:43 - 2022-10-09 09:01 - 000000000 ____D C:\WINDOWS\system32\MRT 2023-06-14 18:42 - 2022-10-09 09:01 - 170078616 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2023-06-14 18:24 - 2022-10-09 18:55 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP 2023-06-14 18:24 - 2022-10-09 18:55 - 000000000 ____D C:\Program Files\HPPrintScanDoctor 2023-06-14 18:22 - 2022-10-09 13:13 - 000474144 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-06-14 18:22 - 2022-05-07 07:17 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2023-06-14 18:21 - 2022-05-07 12:16 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\WUModels 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\UUS 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemResources 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Dism 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellExperiences 2023-06-14 18:21 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\bcastdvr 2023-06-14 18:21 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\servicing 2023-06-14 18:17 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-06-14 18:15 - 2022-10-09 13:18 - 003211776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2023-06-13 23:36 - 2021-10-24 20:23 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2023-06-13 09:00 - 2022-10-09 12:42 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk 2023-06-13 00:12 - 2022-10-09 00:20 - 000000000 ____D C:\Users\jmnau\AppData\Local\Packages ==================== Fichiers à la racine de certains dossiers ======== 2022-10-16 10:04 - 2022-10-16 10:04 - 000007605 _____ () C:\Users\jmnau\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== BCD ================================ Gestionnaire de démarrage du microprogramme ------------------------------------------- identificateur {fwbootmgr} displayorder {de6d2b44-0c22-11ee-99fe-806e6f6e6963} {bootmgr} timeout 2 Gestionnaire de démarrage Windows --------------------------------- identificateur {bootmgr} device partition=\Device\HarddiskVolume1 path \EFI\MICROSOFT\BOOT\BOOTMGFW.EFI description Windows Boot Manager locale fr-FR inherit {globalsettings} default {current} resumeobject {2a4c5149-47d4-11ed-9625-ef2a260243d0} displayorder {current} toolsdisplayorder {memdiag} timeout 30 Application logicielle (101fffff) -------------------------------- identificateur {de6d2b44-0c22-11ee-99fe-806e6f6e6963} device partition=I: description UEFI: USB, Partition 1 Chargeur de démarrage Windows ----------------------------- identificateur {current} device partition=C: path \WINDOWS\system32\winload.efi description Windows 11 locale fr-FR inherit {bootloadersettings} recoverysequence {2a4c514b-47d4-11ed-9625-ef2a260243d0} displaymessageoverride Recovery recoveryenabled Yes isolatedcontext Yes allowedinmemorysettings 0x15000075 osdevice partition=C: systemroot \WINDOWS resumeobject {2a4c5149-47d4-11ed-9625-ef2a260243d0} nx OptIn bootmenupolicy Standard Chargeur de démarrage Windows ----------------------------- identificateur {2a4c514b-47d4-11ed-9625-ef2a260243d0} device ramdisk=[\Device\HarddiskVolume4]\Recovery\WindowsRE\Winre.wim,{2a4c514c-47d4-11ed-9625-ef2a260243d0} path \windows\system32\winload.efi description Windows Recovery Environment locale en-GB inherit {bootloadersettings} displaymessage Recovery osdevice ramdisk=[\Device\HarddiskVolume4]\Recovery\WindowsRE\Winre.wim,{2a4c514c-47d4-11ed-9625-ef2a260243d0} systemroot \windows nx OptIn bootmenupolicy Standard winpe Yes Reprendre à partir de la mise en veille prolongée ------------------------------------------------- identificateur {2a4c5149-47d4-11ed-9625-ef2a260243d0} device partition=C: path \WINDOWS\system32\winresume.efi description Windows Resume Application locale fr-FR inherit {resumeloadersettings} recoverysequence {2a4c514b-47d4-11ed-9625-ef2a260243d0} recoveryenabled Yes isolatedcontext Yes allowedinmemorysettings 0x15000075 filedevice partition=C: custom:21000026 partition=C: filepath \hiberfil.sys bootmenupolicy Standard debugoptionenabled No Testeur de mémoire Windows -------------------------- identificateur {memdiag} device partition=\Device\HarddiskVolume1 path \EFI\Microsoft\Boot\memtest.efi description Windows Memory Diagnostic locale fr-FR inherit {globalsettings} badmemoryaccess Yes Paramètres EMS -------------- identificateur {emssettings} bootems No Paramètres du débogueur ----------------------- identificateur {dbgsettings} debugtype Local Erreurs de mémoire RAM ---------------------- identificateur {badmemory} Paramètres globaux ------------------ identificateur {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Paramètres du chargeur de démarrage ----------------------------------- identificateur {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Paramètres de l'hyperviseur ------------------- identificateur {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Paramètres du chargeur de reprise --------------------------------- identificateur {resumeloadersettings} inherit {globalsettings} Options de périphérique ----------------------- identificateur {2a4c514c-47d4-11ed-9625-ef2a260243d0} description Windows Recovery ramdisksdidevice partition=\Device\HarddiskVolume4 ramdisksdipath \Recovery\WindowsRE\boot.sdi ==================== Fin de FRST.txt ========================