Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 29-05-2023 Exécuté par flosal (administrateur) sur GRENOB-004042 (Dell Inc. Latitude 3560) (07-06-2023 22:17:18) Exécuté depuis C:\Users\flosal\Desktop\FRST64.exe Profils chargés: flosal Plate-forme: Microsoft Windows 10 Professionnel Version 21H1 19043.1586 (X64) Langue: Français (France) Navigateur par défaut: Chrome Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Endpoint Security\EPConsole.exe (C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\awic\AWiCMgr.exe ->) (Qualcomm Atheros, Inc.) [Fichier non signé] C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\ihvs\AWiCDiag.exe (C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\Wcct.exe ->) () [Fichier non signé] C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\spectral\SocketServer.exe (C:\Program Files\Bitdefender\Endpoint Security\EPSecurityService.exe ->) (S.C. BITDEFENDER S.R.L. -> Bitdefender) C:\Program Files\Bitdefender\Endpoint Security\EPHost.Integrity.exe (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (C:\Program Files\McAfee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe (C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <4> (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <31> (explorer.exe ->) (Qualcomm Atheros Inc.) [Fichier non signé] C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\awic\AWiCMgr.exe (explorer.exe ->) (Qualcomm Atheros Inc.) [Fichier non signé] C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\Wcct.exe (explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Endpoint Security\bdredline.exe (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Endpoint Security\EPIntegrationService.exe (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Endpoint Security\EPProtectedService.exe (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Endpoint Security\EPSecurityService.exe (services.exe ->) (Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender\Endpoint Security\EPUpdateService.exe (services.exe ->) (Firebird Project) [Fichier non signé] C:\Program Files (x86)\Fisher & Paykel Healthcare\InfoSmart\InfoSmartDB2\bin\fbserver.exe (services.exe ->) (Fisher & Paykel Healthcare) [Fichier non signé] C:\Program Files (x86)\Fisher & Paykel Healthcare\InfoSmart\Server12\InfoSmartServer.exe (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (services.exe ->) (Intel Corporation - Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESSWTS\MSSQL\Binn\sqlservr.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.ENCOREPRO2\MSSQL\Binn\sqlservr.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.SMARTLINKSQL\MSSQL\Binn\sqlservr.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (services.exe ->) (National Instruments Corporation -> National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe (services.exe ->) (National Instruments Corporation -> National Instruments Corporation) C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe (services.exe ->) (National Instruments Corporation -> National Instruments Corporation) C:\Windows\SysWOW64\lkads.exe (services.exe ->) (National Instruments Corporation -> National Instruments Corporation) C:\Windows\SysWOW64\lktsrv.exe (services.exe ->) (National Instruments Corporation -> National Instruments, Inc.) C:\Windows\SysWOW64\lkcitdl.exe (services.exe ->) (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe (services.exe ->) (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe (services.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe\HxAccounts.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe\HxOutlook.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe\HxTsr.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8822008 2017-01-25] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1478144 2017-01-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation - Rapid Storage Technology -> Intel Corporation) HKLM\...\Run: [AWiCMgr] => C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\AWiC\AWiCMgr.exe [185856 2016-04-21] (Qualcomm Atheros Inc.) [Fichier non signé] HKLM\...\Run: [AWiCDiag] => C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\ihvs\AWiCDiag.exe [3067392 2016-04-21] (Qualcomm Atheros, Inc.) [Fichier non signé] HKLM\...\Run: [wcct] => C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\wcct.exe [1076224 2016-04-21] (Qualcomm Atheros Inc.) [Fichier non signé] HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [724912 2016-09-13] (Waves Inc -> Waves Audio Ltd.) HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG) HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKU\S-1-5-21-2565604041-4069925371-3295733377-1024\...\Run: [com.squirrel.Teams.Teams] => C:\Users\flosal\AppData\Local\Microsoft\Teams\Update.exe [2453728 2021-04-08] (Microsoft 3rd Party Application Component -> Microsoft Corporation) HKU\S-1-5-21-2565604041-4069925371-3295733377-1024\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [40454048 2023-05-12] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) HKLM\...\Print\Monitors\pdfcmon: C:\WINDOWS\system32\pdfcmon.dll [116736 2021-08-11] (pdfforge GmbH) [Fichier non signé] HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\114.0.5735.110\Installer\chrmstp.exe [2023-06-07] (Google LLC -> Google LLC) ==================== Tâches planifiées (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {0B80EB7D-8867-4D60-B80F-B1273A6D6ADB} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-05-12] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "8dacd5ba-ea00-4e16-880f-3aa7414b6460" --version "6.12.10490" --silent Task: {0C9AF20A-9D84-4615-B1FC-2A3E9CE0944C} - System32\Tasks\CCleanerSkipUAC - flosal => C:\Program Files\CCleaner\CCleaner.exe [34264480 2023-05-12] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) Task: {0FDD4F46-375C-4E6C-83E4-483B9A321ACA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2023-06-07] (Google Inc -> Google LLC) Task: {13A2409B-28FC-479D-B5DA-82D978EA3F17} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\flosal\Downloads\esetonlinescanner (1).exe LOGON (Pas de fichier) Task: {14E6AA70-CA1C-4187-B6EC-7E4D173A31F1} - System32\Tasks\Dell\Command Update => C:\Program Files (x86)\Dell\CommandUpdate\DellCommandUpdate.exe [2932664 2017-01-12] (Dell Inc. -> Dell Inc.) Task: {2D7A1B70-69C4-4044-90A8-59774AA25C82} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1478144 2017-01-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor) Task: {304B435E-8E79-40C0-92A7-8115529146D5} - System32\Tasks\Mises à jours de SmartLink Desktop 3 => C:\Windows\Installer\SmartLink Desktop 3 Updates for All Users.lnk [825 2017-04-25] () [Fichier non signé] Task: {71AFD851-59EB-4516-A422-26984FF60C55} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\flosal\Downloads\esetonlinescanner (1).exe SCHED (Pas de fichier) Task: {743B8652-B627-41DB-8818-CF2F11DBAE58} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [732064 2023-06-02] (Mozilla Corporation -> Mozilla Foundation) Task: {8269D1AB-0F3F-4B43-B538-4011083FFE08} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-05-12] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) Task: {842727E9-4BBF-4351-ADDD-5CC59D6708C9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2023-06-07] (Google Inc -> Google LLC) Task: {A019EF2F-CA7F-4DA0-BFB7-10BE6E5DD6AD} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [909112 2016-06-14] (Intel(R) Trusted Connect Service -> Intel(R) Corporation) Task: {B175E1B5-9DF3-4EA1-A0A0-00D21BDEAA22} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [680352 2023-06-02] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe Task: C:\WINDOWS\Tasks\Mises à jours de SmartLink Desktop 3.job => C:\Windows\Installer\SmartLink Desktop 3 Updates for All Users.lnk ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.43.228 Tcpip\..\Interfaces\{7d7b4fd0-d33c-45e2-8130-cf552c5a14ed}: [DhcpNameServer] 192.168.43.228 Tcpip\..\Interfaces\{f8f0e892-cee2-4aa8-b845-ac69f553a06c}: [DhcpNameServer] 172.16.128.41 8.8.8.8 Edge: ======= Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)] Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)] Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)] Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)] Edge DefaultProfile: Default Edge Profile: C:\Users\flosal\AppData\Local\Microsoft\Edge\User Data\Default [2023-06-07] Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] FireFox: ======== FF DefaultProfile: qy69g3fn.default FF ProfilePath: C:\Users\flosal\AppData\Roaming\Mozilla\Firefox\Profiles\qy69g3fn.default [2023-06-07] FF ProfilePath: C:\Users\flosal\AppData\Roaming\Mozilla\Firefox\Profiles\1yoragpp.default-release [2023-06-07] FF Plugin: @java.com/DTPlugin,version=1.6.0_32 -> C:\Windows\system32\npdeployJava1.dll [2017-04-24] (Sun Microsystems, Inc. -> Sun Microsystems, Inc.) FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll [2017-04-24] (Sun Microsystems, Inc. -> Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR Profile: C:\Users\flosal\AppData\Local\Google\Chrome\User Data\Default [2023-06-07] CHR StartupUrls: Default -> "hxxps://www.google.com/" CHR Extension: (McAfee® WebAdvisor) - C:\Users\flosal\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2023-06-07] CHR Extension: (Malwarebytes Browser Guard) - C:\Users\flosal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-06-07] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\flosal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-06-07] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] CHR HKU\S-1-5-21-2565604041-4069925371-3295733377-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S2 acrwatchsrv; C:\WINDOWS\system32\acrwatchsrv.exe [103728 2019-03-11] (Activecrypt Software Ltd. -> Activecrypt Software Co., Ltd.) R3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1063840 2023-05-12] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) R2 EPIntegrationService; C:\Program Files\Bitdefender\Endpoint Security\EPIntegrationService.exe [158048 2023-06-07] (Bitdefender SRL -> Bitdefender) R2 EPProtectedService; C:\Program Files\Bitdefender\Endpoint Security\EPProtectedService.exe [158048 2023-06-07] (Bitdefender SRL -> Bitdefender) R2 EPRedline; C:\Program Files\Bitdefender\Endpoint Security\bdredline.exe [2707296 2023-06-07] (Bitdefender SRL -> Bitdefender) R2 EPSecurityService; C:\Program Files\Bitdefender\Endpoint Security\EPSecurityService.exe [158048 2023-06-07] (Bitdefender SRL -> Bitdefender) R2 EPUpdateService; C:\Program Files\Bitdefender\Endpoint Security\EPUpdateService.exe [158048 2023-06-07] (Bitdefender SRL -> Bitdefender) R2 FirebirdServerInfoSmartDB2; C:\Program Files (x86)\Fisher & Paykel Healthcare\InfoSmart\InfoSmartDB2\bin\fbserver.exe [3735552 2011-08-30] (Firebird Project) [Fichier non signé] R2 InfoSmartServer12; C:\Program Files (x86)\Fisher & Paykel Healthcare\InfoSmart\Server12\InfoSmartServer.exe [32768 2015-04-28] (Fisher & Paykel Healthcare) [Fichier non signé] R2 LkCitadelServer; C:\Windows\SysWOW64\lkcitdl.exe [695136 2010-10-27] (National Instruments Corporation -> National Instruments, Inc.) R2 lkClassAds; C:\Windows\SysWOW64\lkads.exe [46192 2011-06-14] (National Instruments Corporation -> National Instruments Corporation) R2 lkTimeSync; C:\Windows\SysWOW64\lktsrv.exe [56952 2011-06-14] (National Instruments Corporation -> National Instruments Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9258016 2023-06-07] (Malwarebytes Inc. -> Malwarebytes) R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [856472 2023-06-07] (McAfee, LLC -> McAfee, LLC) R2 MSSQL$ENCOREPRO2; c:\Program Files\Microsoft SQL Server\MSSQL10.ENCOREPRO2\MSSQL\Binn\sqlservr.exe [69964448 2015-04-03] (Microsoft Corporation -> Microsoft Corporation) R2 MSSQL$SMARTLINKSQL; C:\Program Files\Microsoft SQL Server\MSSQL11.SMARTLINKSQL\MSSQL\Binn\sqlservr.exe [194240 2017-07-07] (Microsoft Corporation -> Microsoft Corporation) R2 MSSQL$SQLEXPRESSWTS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESSWTS\MSSQL\Binn\sqlservr.exe [43040096 2011-06-17] (Microsoft Corporation -> Microsoft Corporation) R2 NIDomainService; C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe [362104 2011-06-14] (National Instruments Corporation -> National Instruments Corporation) R2 niSvcLoc; C:\Program Files (x86)\National Instruments\Shared\NI WebServer\SystemWebServer.exe [50328 2011-05-27] (National Instruments Corporation -> National Instruments Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6228008 2022-04-18] (Microsoft Windows Publisher -> Microsoft Corporation) S4 SQLAgent$ENCOREPRO2; c:\Program Files\Microsoft SQL Server\MSSQL10.ENCOREPRO2\MSSQL\Binn\SQLAGENT.EXE [441512 2015-04-03] (Microsoft Corporation -> Microsoft Corporation) S4 SQLAgent$SMARTLINKSQL; C:\Program Files\Microsoft SQL Server\MSSQL11.SMARTLINKSQL\MSSQL\Binn\SQLAGENT.EXE [613056 2017-07-07] (Microsoft Corporation -> Microsoft Corporation) S4 SQLAgent$SQLEXPRESSWTS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.SQLEXPRESSWTS\MSSQL\Binn\SQLAGENT.EXE [370016 2011-06-17] (Microsoft Corporation -> Microsoft Corporation) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe [2909208 2022-02-14] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe [128376 2022-02-14] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R1 acrwatchdrv; C:\WINDOWS\system32\drivers\acrwatchdrv.sys [33336 2017-07-06] (Activecrypt Software Ltd. -> ) S3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2017-11-16] (AnchorFree Inc -> The OpenVPN Project) R1 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [5579176 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender S.R.L. Bucharest, ROMANIA) R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [798160 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender) S0 BDElam; C:\WINDOWS\System32\drivers\bdelam.sys [22976 2021-04-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [284672 2021-04-04] (Microsoft Corporation) [Fichier non signé] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Fichier non signé] R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [22864 2016-10-27] (WDKTestCert Andy_Chen6,131219483243550933 -> OSR Open Systems Resources, Inc.) S3 fenrir; C:\WINDOWS\System32\drivers\fenrir.sys [38816 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> ) S3 FTSER2K; C:\WINDOWS\system32\drivers\ftser2k.sys [79872 2014-10-21] (Microsoft Windows Hardware Compatibility Publisher -> FTDI Ltd.) R3 gemma; C:\WINDOWS\System32\DRIVERS\gemma.sys [1322912 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> BitDefender S.R.L. Bucharest, ROMANIA) R0 Ignisv2; C:\WINDOWS\System32\DRIVERS\ignisv2.sys [160704 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223176 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-06-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S4 RsFx0202; C:\WINDOWS\System32\DRIVERS\RsFx0202.sys [339648 2015-10-20] (Microsoft Corporation -> Microsoft Corporation) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R0 stdcfltn; C:\WINDOWS\System32\DRIVERS\stdcfltn.sys [30352 2016-10-07] (STMICROELECTRONICS S.R.L. -> ST Microelectronics) R2 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [633264 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender) R0 vlflt; C:\WINDOWS\System32\DRIVERS\vlflt.sys [522136 2023-06-07] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2022-02-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [438520 2022-02-14] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90360 2022-02-14] (Microsoft Windows -> Microsoft Corporation) U3 aswbdisk; pas de ImagePath ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-06-07 22:17 - 2023-06-07 22:20 - 000025181 _____ C:\Users\flosal\Desktop\FRST.txt 2023-06-07 22:15 - 2023-06-07 22:19 - 000000000 ____D C:\FRST 2023-06-07 22:14 - 2023-06-07 22:14 - 002383360 _____ (Farbar) C:\Users\flosal\Downloads\FRST64.exe 2023-06-07 22:14 - 2023-06-07 22:14 - 002383360 _____ (Farbar) C:\Users\flosal\Desktop\FRST64.exe 2023-06-07 21:16 - 2023-06-07 21:16 - 000347058 _____ C:\Users\flosal\Desktop\ZHPDiag.txt 2023-06-07 20:47 - 2023-06-07 20:47 - 000000866 _____ C:\Users\flosal\Desktop\ZHPDiag.lnk 2023-06-07 20:46 - 2023-06-07 20:46 - 000000000 ____D C:\Users\flosal\AppData\Local\ZHP 2023-06-07 20:45 - 2023-06-07 20:45 - 003318472 _____ (Nicolas Coolman) C:\Users\flosal\Downloads\ZHPDiag3.exe 2023-06-07 20:00 - 2023-06-07 20:00 - 000002281 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2023-06-07 20:00 - 2023-06-07 20:00 - 000002240 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2023-06-07 19:59 - 2023-06-07 20:07 - 000003884 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2023-06-07 19:59 - 2023-06-07 20:07 - 000003760 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2023-06-07 19:59 - 2023-06-07 19:59 - 000000000 ____D C:\ProgramData\Piriform 2023-06-07 19:59 - 2023-06-07 19:59 - 000000000 ____D C:\Program Files\Google 2023-06-07 19:58 - 2023-06-07 19:58 - 000000000 ____D C:\Users\flosal\AppData\Local\Malwarebytes 2023-06-07 19:57 - 2023-06-07 19:57 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2023-06-07 19:57 - 2023-06-07 19:57 - 000003476 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting 2023-06-07 19:57 - 2023-06-07 19:57 - 000002904 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - flosal 2023-06-07 19:57 - 2023-06-07 19:57 - 000001993 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2023-06-07 19:57 - 2023-06-07 19:57 - 000001981 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2023-06-07 19:57 - 2023-06-07 19:57 - 000000823 _____ C:\Users\Public\Desktop\CCleaner.lnk 2023-06-07 19:57 - 2023-06-07 19:57 - 000000760 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job 2023-06-07 19:57 - 2023-06-07 19:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2023-06-07 19:54 - 2023-06-07 20:59 - 000000000 ____D C:\Program Files\CCleaner 2023-06-07 19:54 - 2023-06-07 19:54 - 002645944 _____ (Malwarebytes) C:\Users\flosal\Downloads\MBSetup(1).exe 2023-06-07 19:52 - 2023-06-07 19:52 - 000000000 ____D C:\ProgramData\Malwarebytes 2023-06-07 19:51 - 2023-06-07 19:52 - 056205720 _____ (Piriform Software Ltd) C:\Users\flosal\Downloads\ccsetup612.exe 2023-06-07 19:51 - 2023-06-07 19:51 - 002645944 _____ (Malwarebytes) C:\Users\flosal\Downloads\MBSetup.exe 2023-06-07 19:44 - 2023-06-07 21:18 - 000000020 _____ C:\WINDOWS\system32\Caad.db 2023-06-07 19:20 - 2023-06-07 20:48 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2023-06-07 19:20 - 2023-06-07 19:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2023-06-07 19:20 - 2023-06-07 19:20 - 000002218 _____ C:\Users\flosal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navigation privée de Firefox.lnk 2023-06-07 19:20 - 2023-06-07 19:20 - 000002006 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigation privée de Firefox.lnk 2023-06-07 19:20 - 2023-06-07 19:20 - 000001152 _____ C:\Users\flosal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2023-06-07 19:20 - 2023-06-07 19:20 - 000000965 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2023-06-07 19:20 - 2023-06-07 19:20 - 000000953 _____ C:\Users\Public\Desktop\Firefox.lnk 2023-06-07 19:20 - 2023-06-07 19:20 - 000000000 ____D C:\Users\flosal\AppData\Local\Mozilla Firefox 2023-06-07 19:20 - 2023-06-07 19:20 - 000000000 ____D C:\Users\flosal\AppData\Local\Mozilla 2023-06-07 19:20 - 2023-06-07 19:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2023-06-07 19:19 - 2023-06-07 21:05 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-06-07 19:07 - 2023-06-07 19:07 - 000398936 _____ (Mozilla) C:\Users\flosal\Downloads\Firefox Installer (1).exe 2023-06-07 18:59 - 2023-06-07 18:59 - 000398936 _____ (Mozilla) C:\Users\flosal\Downloads\Firefox Installer.exe 2023-06-07 18:29 - 2023-06-07 18:29 - 000000000 __HDC C:\ProgramData\{CEC9C77E-6F81-40D4-9C48-45189C4B9438} ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-06-07 22:12 - 2017-04-10 12:58 - 000000000 ____D C:\Program Files (x86)\Google 2023-06-07 21:34 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-06-07 21:20 - 2020-10-29 22:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender Endpoint Security Tools 2023-06-07 21:18 - 2020-11-19 00:44 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-06-07 21:18 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2023-06-07 21:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-06-07 21:16 - 2021-01-21 09:12 - 000000000 ____D C:\Users\flosal\AppData\Roaming\ZHP 2023-06-07 21:16 - 2017-10-06 04:01 - 000000000 ____D C:\Users\flosal\AppData\Local\Packages 2023-06-07 21:07 - 2020-10-30 08:24 - 000000000 ____D C:\ProgramData\GenPatch 2023-06-07 21:00 - 2022-04-18 08:04 - 000160704 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\ignisv2.sys 2023-06-07 21:00 - 2022-04-18 08:04 - 000010985 _____ C:\WINDOWS\system32\Drivers\ignisv2.cat 2023-06-07 21:00 - 2020-10-29 22:11 - 000633264 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\trufos.sys 2023-06-07 20:59 - 2021-11-15 15:31 - 000522136 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\vlflt.sys 2023-06-07 20:57 - 2020-10-29 22:50 - 000038816 _____ C:\WINDOWS\system32\Drivers\fenrir.sys 2023-06-07 20:57 - 2020-10-29 22:50 - 000011127 _____ C:\WINDOWS\system32\Drivers\fenrir.cat 2023-06-07 20:57 - 2020-10-29 22:49 - 001322912 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\gemma.sys 2023-06-07 20:57 - 2020-10-29 22:49 - 000011044 _____ C:\WINDOWS\system32\Drivers\gemma.cat 2023-06-07 20:56 - 2020-10-29 22:49 - 005579176 _____ (Bitdefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys 2023-06-07 20:56 - 2020-10-29 22:49 - 000798160 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys 2023-06-07 20:56 - 2020-10-29 22:49 - 000011085 _____ C:\WINDOWS\system32\Drivers\atc.cat 2023-06-07 20:56 - 2020-10-29 22:49 - 000011031 _____ C:\WINDOWS\system32\Drivers\bddci.cat 2023-06-07 20:39 - 2021-05-12 07:39 - 000000000 ____D C:\Users\flosal\AppData\LocalLow\IGDump 2023-06-07 20:13 - 2021-06-07 22:35 - 000000000 ____D C:\Users\flosal\AppData\Roaming\TeamViewer 2023-06-07 20:13 - 2021-04-12 07:41 - 000000000 ____D C:\WINDOWS\Minidump 2023-06-07 20:13 - 2019-11-27 18:55 - 000000000 ____D C:\Users\flosal\AppData\Local\CrashDumps 2023-06-07 20:13 - 2017-04-10 13:50 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2023-06-07 20:02 - 2022-01-14 20:11 - 000000000 ____D C:\WINDOWS\SystemTemp 2023-06-07 20:01 - 2021-04-04 14:37 - 002006982 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2023-06-07 20:01 - 2019-12-07 16:50 - 000866684 _____ C:\WINDOWS\system32\perfh00C.dat 2023-06-07 20:01 - 2019-12-07 16:50 - 000177998 _____ C:\WINDOWS\system32\perfc00C.dat 2023-06-07 20:01 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2023-06-07 20:00 - 2017-10-06 04:01 - 000000000 ____D C:\Users\flosal\AppData\Local\Google 2023-06-07 19:55 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2023-06-07 19:52 - 2021-04-20 21:14 - 000000000 ____D C:\Program Files\Malwarebytes 2023-06-07 19:26 - 2017-10-06 04:01 - 000000000 __SHD C:\Users\flosal\IntelGraphicsProfiles 2023-06-07 19:26 - 2017-04-10 16:20 - 000000000 ____D C:\ProgramData\firebird 2023-06-07 19:26 - 2017-04-07 14:36 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2023-06-07 19:25 - 2020-11-19 00:44 - 000350400 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-06-07 19:24 - 2021-04-04 14:13 - 000008192 ___SH C:\DumpStack.log.tmp 2023-06-07 19:24 - 2020-11-19 01:44 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-06-07 19:23 - 2019-12-07 11:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2023-06-07 19:22 - 2021-04-04 14:20 - 000000000 ____D C:\Users\flosal 2023-06-07 19:20 - 2017-10-11 05:39 - 000000000 ____D C:\Users\flosal\AppData\Roaming\Mozilla 2023-06-07 19:13 - 2017-04-11 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BreasMedical 2023-06-07 19:13 - 2017-04-11 14:32 - 000000000 ____D C:\BreasMedical 2023-06-07 19:03 - 2021-08-11 09:26 - 000000000 ____D C:\ProgramData\McAfee 2023-06-07 18:53 - 2020-10-29 21:18 - 000000000 ____D C:\ProgramData\bdkitinstaller 2023-06-07 18:42 - 2017-04-24 16:04 - 000000000 ____D C:\prisma_Backup 2023-06-07 18:39 - 2017-04-11 14:40 - 000000000 ____D C:\ProgramData\nVision 2023-06-07 18:38 - 2017-04-07 15:52 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2023-06-07 18:31 - 2017-04-11 10:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Respironics 2023-06-07 18:19 - 2017-04-11 12:27 - 000000000 ____D C:\Program Files (x86)\ResMed 2023-06-07 18:08 - 2017-04-07 15:52 - 000000000 ____D C:\ProgramData\Package Cache 2023-06-07 18:03 - 2017-04-11 09:56 - 000000000 ____D C:\Program Files\Microsoft SQL Server 2023-06-07 18:03 - 2017-04-11 09:56 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2023-06-07 17:59 - 2017-04-11 12:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Weinmann ==================== Fichiers à la racine de certains dossiers ======== 2021-04-04 20:46 - 2021-04-04 20:46 - 003273368 _____ (Nicolas Coolman) C:\Users\flosal\ZHPDiag3.exe 2021-06-18 00:22 - 2021-06-18 00:22 - 010055680 _____ () C:\Program Files (x86)\GUT7978.tmp 2020-11-01 17:34 - 2021-06-17 23:01 - 000146756 _____ () C:\Users\flosal\AppData\Local\ars.cache 2020-11-01 17:34 - 2021-06-17 23:05 - 001641060 _____ () C:\Users\flosal\AppData\Local\census.cache 2020-04-30 17:30 - 2020-04-30 17:30 - 000000036 _____ () C:\Users\flosal\AppData\Local\housecall.guid.cache 2021-06-17 22:08 - 2021-06-17 22:08 - 000000010 _____ () C:\Users\flosal\AppData\Local\sponge.last.runtime.cache ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================