Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 23-08-2023 Exécuté par DRJMLAPS (administrateur) sur DRJMLAPS (Hewlett-Packard HP Pro3500 Series) (23-08-2023 18:34:20) Exécuté depuis C:\Users\DRJMLAPS\Desktop\FRST64.exe Profils chargés: DRJMLAPS Plate-forme: Microsoft Windows 10 Professionnel Version 22H2 19045.3393 (X64) Langue: Français (France) Navigateur par défaut: FF Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe (services.exe ->) (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte Ltd) C:\Program Files (x86)\2BrightSparks\SyncBackFree\SchedulesMonitor.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\NisSrv.exe (services.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [366944 2023-05-12] (Apple Inc. -> Apple Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard) HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKLM\Software\Policies\...\system: [EnableActivityFeed] 0 HKLM\Software\Policies\...\system: [PublishUserActivities] 0 HKU\S-1-5-21-2698232632-3730632774-2639926750-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [41584544 2023-08-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) HKU\S-1-5-21-2698232632-3730632774-2639926750-1001\...\Run: [MicrosoftEdgeAutoLaunch_6A0809A2ED206FD0BB7CA1AC3860E8F4] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4116520 2023-08-18] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-2698232632-3730632774-2639926750-1001\...\MountPoints2: {bab66334-0974-11ec-b0e6-2c44fd1714ec} - "F:\HiSuiteDownLoader.exe" HKLM\...\Print\Monitors\HP C311 Status Monitor: C:\WINDOWS\system32\hpinkstsC311LM.dll [333496 2012-12-16] (Hewlett Packard -> Hewlett-Packard Co.) HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP ENVY 5530 series): C:\WINDOWS\system32\HPDiscoPMC311.dll [763040 2021-11-30] (HP Inc. -> Hewlett-Packard Development Company, LP) HKLM\...\Print\Monitors\Wondershare PDFelement Monitor: C:\WINDOWS\system32\PEPrinterMonitor.dll [291568 2023-05-04] (Wondershare Technology Group Co.,Ltd -> Wondershare Software) HKLM\Software\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] -> HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] -> C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install IFEO\CompatTelRunner.exe: [Debugger] %windir%\System32\taskkill.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Taskmgr.bat [2022-03-28] () [Fichier non signé] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wondershare PEScreenshot.lnk [2023-05-12] ShortcutTarget: Wondershare PEScreenshot.lnk -> C:\Program Files\PDFelement\Wondershare\Wondershare PDFelement pour Windows (FR)\PENotify.exe (Pas de fichier) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wondershare PEToolbox.lnk [2023-05-12] ShortcutTarget: Wondershare PEToolbox.lnk -> C:\Program Files\PDFelement\Wondershare\Wondershare PDFelement pour Windows (FR)\PENotify.exe (Pas de fichier) Startup: C:\Users\DRJMLAPS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Alertes de surveillance de l'encre - HP ENVY 5530 series.lnk [2022-08-16] ShortcutAndArgument: Alertes de surveillance de l'encre - HP ENVY 5530 series.lnk -> C:\WINDOWS\system32\RunDll32.exe => "C:\Program Files\HP\HP ENVY 5530 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN4BB4632G067B;CONNECTION=USB;MONITOR=1; Startup: C:\Users\DRJMLAPS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Taskmgr.exe - Raccourci.lnk [2022-03-22] ShortcutTarget: Taskmgr.exe - Raccourci.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Windows -> Microsoft Corporation) HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION ==================== Tâches planifiées (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {B8843F88-A1B2-4967-BC9F-598721C662BA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564152 2023-04-03] (Adobe Inc. -> Adobe Inc.) Task: {ED5687D6-80A1-4B9B-92A5-082A27887099} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [617096 2022-02-25] (Apple Inc. -> Apple Inc.) Task: {4A647F97-C15C-483F-A6F2-E7077253815D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-08-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) Task: {A26140A3-6F35-4BCF-891B-DF5DDC41C8F9} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2023-08-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "2bf97693-9da3-49d5-87bb-31d0fd64970e" --version "6.15.10623" --silent Task: {4943E065-8378-4D7F-8619-22B42E84D3B8} - System32\Tasks\CCleanerSkipUAC - DRJMLAPS => C:\Program Files\CCleaner\CCleaner.exe [34687904 2023-08-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) Task: {BF57C6B5-39C4-45CA-B66F-5D63F84D7454} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe [5311288 2023-08-23] (Microsoft Windows -> Microsoft Corporation) Task: {A52E62C7-22E8-4F45-80D7-4E6AF68034B9} - System32\Tasks\HPCustParticipation HP ENVY 5530 series => C:\Program Files\HP\HP ENVY 5530 series\Bin\HPCustPartic.exe [5744800 2021-11-30] (HP Inc. -> Hewlett-Packard Development Company, LP) Task: {045A1204-628A-4851-916C-29E5C453B946} - System32\Tasks\HPEA3JOBS => C:\Program -> Files\HP\HP ePrint\hpeprint.exe /CheckJobs Task: {53056BAB-0FB5-41E9-855A-85DA09171899} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(1): %windir%\system32\compattelrunner.exe -> -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc Task: {53056BAB-0FB5-41E9-855A-85DA09171899} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(2): %windir%\system32\compattelrunner.exe -> -m:appraiser.dll -f:DoScheduledTelemetryRun Task: {53056BAB-0FB5-41E9-855A-85DA09171899} - System32\Tasks\Microsoft\Windows\Application Experience\MareBackup => Command(3): %windir%\system32\compattelrunner.exe -> -m:aemarebackup.dll -f:BackupMareData Task: {F9975DFB-57C5-475F-BAB5-726C81F3F414} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F67606D2-16EF-47B7-931E-A03E1AA11081} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F1ADB657-8EC4-45B7-95F1-06DB0AAB2EB0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {33BE3EF1-4CAB-4668-9F20-BC1D259D5650} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MpCmdRun.exe [1596320 2023-08-10] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {46AE28D6-E91C-4D32-9BCD-2902599A6759} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [733088 2023-08-17] (Mozilla Corporation -> Mozilla Foundation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 89.2.0.1 89.2.0.2 192.168.1.1 Tcpip\..\Interfaces\{68a0ec23-34d7-46b9-bf9e-f6a44c56fff3}: [DhcpNameServer] 89.2.0.1 89.2.0.2 192.168.1.1 Edge: ======= Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)] Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)] Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)] Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)] Edge Profile: C:\Users\DRJMLAPS\AppData\Local\Microsoft\Edge\User Data\Default [2023-08-23] Edge Extension: (Edge relevant text changes) - C:\Users\DRJMLAPS\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-08-17] FireFox: ======== FF DefaultProfile: xzmu3ifo.default-1635004899114 FF ProfilePath: C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\i7fodjgd.Dylav [2023-08-23] FF Homepage: Mozilla\Firefox\Profiles\i7fodjgd.Dylav -> hxxps://www.google.com FF Notifications: Mozilla\Firefox\Profiles\i7fodjgd.Dylav -> hxxps://www.zebulon.fr FF Extension: (AdGuard AdBlocker) - C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\i7fodjgd.Dylav\Extensions\adguardadblocker@adguard.com.xpi [2023-07-22] FF Extension: (ImTranslator: Traducteur, Dictionnaire, Voix) - C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\i7fodjgd.Dylav\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2023-08-10] FF Extension: (Video DownloadHelper) - C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\i7fodjgd.Dylav\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2023-07-22] FF ProfilePath: C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\xzmu3ifo.default-1635004899114 [2023-03-26] FF ProfilePath: C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\09ffkhh0.Dylav [2023-03-26] FF Homepage: Mozilla\Firefox\Profiles\09ffkhh0.Dylav -> hxxps://www.google.com FF Session Restore: Mozilla\Firefox\Profiles\09ffkhh0.Dylav -> est activé. FF Extension: (Google™ Translator) - C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\09ffkhh0.Dylav\Extensions\{059cddf1-f66c-4b63-a79a-c35ac7e6ac65}.xpi [2021-01-12] FF Extension: (Malwarebytes Browser Guard) - C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\09ffkhh0.Dylav\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2021-10-21] FF Extension: (Video DownloadHelper) - C:\Users\DRJMLAPS\AppData\Roaming\Mozilla\Firefox\Profiles\09ffkhh0.Dylav\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-07-01] FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.13 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.15 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.17.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2022-11-08] (VideoLAN -> VideoLAN) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2023-08-19] (Adobe Inc. -> Adobe Systems Inc.) ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-04-03] (Adobe Inc. -> Adobe Inc.) S3 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [103264 2023-03-01] (Apple Inc. -> Apple Inc.) S3 Everything; C:\Program Files (x86)\Everything\Everything.exe [1774696 2021-05-12] (voidtools -> voidtools) R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [230352 2023-08-09] (HP Inc. -> HP Inc.) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9283096 2023-08-18] (Malwarebytes Inc. -> Malwarebytes) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402264 2023-08-23] (Microsoft Windows Publisher -> Microsoft Corporation) R2 SyncBackFreeSchedulesMonitor; C:\Program Files (x86)\2BrightSparks\SyncBackFree\SchedulesMonitor.exe [3389168 2023-07-21] (2BrightSparks Pte. Ltd. -> 2BrightSparks Pte Ltd) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\NisSrv.exe [3104488 2023-08-10] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe [133576 2023-08-10] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Fichier non signé] S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Fichier non signé] S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2021-06-03] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2022-04-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-08-09] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55704 2023-08-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572656 2023-08-10] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [104688 2023-08-10] (Microsoft Windows -> Microsoft Corporation) S3 dg_ssudbus; \SystemRoot\system32\DRIVERS\ssudbus.sys [X] S3 ssudmdm; \SystemRoot\system32\DRIVERS\ssudmdm.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-08-23 18:32 - 2023-08-23 18:35 - 000019112 _____ C:\Users\DRJMLAPS\Desktop\FRST.txt 2023-08-23 18:31 - 2023-08-23 18:34 - 000000000 ____D C:\FRST 2023-08-23 18:27 - 2023-08-23 18:27 - 002381824 _____ (Farbar) C:\Users\DRJMLAPS\Desktop\FRST64.exe 2023-08-23 14:29 - 2023-08-23 14:29 - 000000000 ___HD C:\$WinREAgent 2023-08-23 11:10 - 2023-08-23 11:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 7.6 2023-08-23 11:10 - 2023-08-23 11:10 - 000000000 ____D C:\Program Files\LibreOffice 2023-08-09 23:15 - 2023-08-09 23:15 - 000000000 ____D C:\Users\DRJMLAPS\Documents\FormatFactory 2023-08-09 23:14 - 2023-08-09 23:14 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory 2023-08-09 14:16 - 2023-08-09 14:16 - 000000000 ____D C:\Program Files\HPPrintScanDoctor 2023-07-24 17:27 - 2023-07-24 17:27 - 000001080 _____ C:\Users\DRJMLAPS\Desktop\KMPlayer 4.2.2.79.lnk ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-08-23 18:38 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-08-23 18:34 - 2022-02-08 18:44 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2023-08-23 18:22 - 2022-11-09 14:53 - 000003476 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting 2023-08-23 18:22 - 2022-09-20 19:21 - 000000760 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job 2023-08-23 18:22 - 2022-01-25 18:04 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2023-08-23 18:22 - 2020-03-19 19:59 - 000000000 ____D C:\Program Files\CCleaner 2023-08-23 18:15 - 2022-01-25 17:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-08-23 15:20 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2023-08-23 15:14 - 2022-01-25 18:02 - 001681370 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2023-08-23 15:14 - 2019-12-07 16:50 - 000755174 _____ C:\WINDOWS\system32\perfh00C.dat 2023-08-23 15:14 - 2019-12-07 16:50 - 000141980 _____ C:\WINDOWS\system32\perfc00C.dat 2023-08-23 15:11 - 2020-03-18 19:00 - 000000000 __SHD C:\Users\DRJMLAPS\IntelGraphicsProfiles 2023-08-23 15:11 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-08-23 15:09 - 2022-01-25 17:51 - 000493448 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-08-23 15:08 - 2022-01-25 18:04 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-08-23 15:08 - 2020-12-05 18:44 - 000008192 ___SH C:\DumpStack.log.tmp 2023-08-23 15:08 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2023-08-23 15:07 - 2019-12-07 16:53 - 000000000 ___SD C:\WINDOWS\system32\AppV 2023-08-23 15:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2023-08-23 15:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources 2023-08-23 15:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2023-08-23 15:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2023-08-23 15:07 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser 2023-08-23 15:06 - 2019-12-07 16:53 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2023-08-23 15:06 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog 2023-08-23 15:06 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2023-08-23 15:06 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2023-08-23 15:06 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2023-08-23 15:06 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2023-08-23 15:06 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-08-23 15:04 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2023-08-23 14:56 - 2022-01-25 17:54 - 003014144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2023-08-23 14:52 - 2020-03-19 18:41 - 000000000 ___RD C:\Users\DRJMLAPS\Documents\Dominique 2023-08-23 14:42 - 2022-01-25 18:04 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task 2023-08-23 14:41 - 2023-01-30 11:49 - 000002073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk 2023-08-23 12:08 - 2020-03-21 02:59 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Roaming\Microsoft\Excel 2023-08-23 10:56 - 2020-03-22 14:45 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-08-19 11:57 - 2023-04-21 14:14 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Local\Malwarebytes 2023-08-18 10:53 - 2023-05-23 17:51 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-08-18 10:53 - 2020-03-19 12:45 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2023-08-17 11:44 - 2020-03-19 12:45 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2023-08-16 17:28 - 2020-05-17 23:35 - 000001522 _____ C:\Users\DRJMLAPS\Desktop\Creation Point Restauration.lnk 2023-08-16 17:28 - 2020-04-26 20:43 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Roaming\vlc 2023-08-16 17:27 - 2021-08-26 12:03 - 000000000 ____D C:\Program Files\Audacity 2023-08-16 17:27 - 2020-12-31 17:03 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Roaming\audacity 2023-08-15 23:20 - 2020-03-19 23:32 - 000001104 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk 2023-08-15 23:20 - 2020-03-19 23:32 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Roaming\Notepad++ 2023-08-13 01:19 - 2020-03-21 03:05 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Local\Everything 2023-08-13 01:19 - 2020-03-21 02:42 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Roaming\Everything 2023-08-10 17:29 - 2020-03-22 21:38 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Roaming\Microsoft\Word 2023-08-10 17:29 - 2020-03-21 01:18 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Roaming\Microsoft\Office 2023-08-10 16:59 - 2020-04-04 23:45 - 000085832 _____ C:\Users\DRJMLAPS\AppData\Local\GDIPFONTCACHEV1.DAT 2023-08-10 12:41 - 2020-03-18 16:51 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2023-08-09 23:13 - 2022-07-24 19:39 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Local\Free_Time_Co.,_Ltd 2023-08-09 14:52 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\setup 2023-08-09 14:16 - 2020-03-19 12:35 - 000000000 ____D C:\WINDOWS\system32\MRT 2023-08-09 14:11 - 2020-03-19 12:35 - 175983240 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2023-08-04 22:56 - 2020-09-06 13:35 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Local\CrashDumps 2023-08-03 14:52 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF 2023-07-27 16:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2023-07-27 16:18 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\appcompat 2023-07-27 13:45 - 2020-03-19 12:11 - 000918960 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2023-07-24 17:27 - 2022-02-20 17:56 - 000000000 ____D C:\Program Files (x86)\KMPlayer 2023-07-24 10:42 - 2020-03-19 20:29 - 000000000 ____D C:\Users\DRJMLAPS\AppData\Local\2BrightSparks 2023-07-24 10:41 - 2022-06-29 17:25 - 000001411 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SyncBackFree.lnk ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================