Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x86) Version: 05-11-2023 02 Exécuté par jp (administrateur) sur JP-PC (LENOVO 7075B5G) (25-11-2023 07:54:25) Exécuté depuis C:\Users\jp\Downloads\FRST.exe Profils chargés: jp Plate-forme: Microsoft Windows 7 Édition Familiale Premium Service Pack 1 (X86) Langue: Français (France) Navigateur par défaut: Chrome Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (AuthenTec, Inc. -> Authentec Inc.) C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe (C:\Program Files\IObit\Smart Defrag\SmartDefrag.exe ->) (IObit CO., LTD -> IObit) C:\Program Files\IObit\Smart Defrag\pub\SDbf2023.exe (cmd.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\sfc.exe (explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe (explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe (Glarysoft LTD -> Glarysoft Ltd) C:\Program Files\Glary Utilities 5\Integrator.exe (Google LLC -> Google LLC) C:\Program Files\Google\Update\1.3.36.332\GoogleCrashHandler.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\osk.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe (services.exe ->) (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files\Wondershare\WAF\2.4.3.242\WsAppService.exe (taskeng.exe ->) (IObit CO., LTD -> IObit) C:\Program Files\IObit\Smart Defrag\SmartDefrag.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\Software\Policies\...\system: [EnableSmartScreen] 0 HKU\S-1-5-21-1027861262-4203368321-1641708045-1000\...\Policies\Explorer: [] HKLM\Software\Microsoft\Active Setup\Installed Components: [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] -> "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\109.0.5414.120\Installer\chrmstp.exe [2023-01-29] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{18CBEEAA-6708-41A1-9379-D08915333CF2}] -> C:\Program Files\ThinkVantage Fingerprint Software\provider.dll [2013-03-05] (AuthenTec, Inc. -> Authentec Inc.) HKLM\Software\...\Authentication\Credential Provider Filters: [{AE583D93-8D1B-424F-9858-5623FB7824EE}] -> C:\Program Files\ThinkVantage Fingerprint Software\provider.dll [2013-03-05] (AuthenTec, Inc. -> Authentec Inc.) Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll BootExecute: autocheck autochk * sdnclean.exe GroupPolicy: Restriction ? <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION ==================== Tâches planifiées (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {B1459641-0E55-4B1A-AD5C-99867E4B8A3A} - \{B3D40C75-B54D-450C-9B31-90AA27FF1AA5} -> Pas de fichier <==== ATTENTION Task: {F7FD10E8-C187-4013-A32C-340B24350DB7} - \Opera scheduled assistant Autoupdate 1618935437 -> Pas de fichier <==== ATTENTION Task: {8E8369C2-5328-4E0E-A844-DF574EE9B8AD} - System32\Tasks\{014363DD-7A6B-40D7-A0EE-016C63394D5F} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "F:\Office 2016\InstallOffice.exe" -d "F:\Office 2016" Task: {C8D2307F-DDC9-4C05-B27A-242A537349B5} - System32\Tasks\{156E6C6F-460F-490D-998E-91EF4398566D} => C:\Users\jp\Desktop\Nouveau dossier (2)\Setups1.exe (Pas de fichier) Task: {5D95FCDF-A5D9-49C3-9A9D-B95CBFF02771} - System32\Tasks\{18B55D4F-7820-4537-B033-EEE346D617C0} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (6)\Setups.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (6)" Task: {D23B162E-A6DA-45CA-A033-F2C4B29CBD01} - System32\Tasks\{28E2F12A-010B-49FA-8664-61E193853103} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (3)\Setups1.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (3)" Task: {1F11F309-C7A3-4FA0-B0DF-CE2290A75248} - System32\Tasks\{2FC5A9F1-91B5-4075-8A0C-018AA9464BD8} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (2)\autocad-keygen-free-_zpJrfC3.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (2)" Task: {E0EEC9FA-6692-477B-ABFD-58C06D771CBA} - System32\Tasks\{31E89068-7B4E-4535-9E2A-BCEB149EC216} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (3)\setup.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (3)" Task: {2F6E2255-CC74-4E2D-A7EC-DFF929884B2A} - System32\Tasks\{48733ECE-3324-4FE7-8429-20F37295FDAB} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (2)\Setups1.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (2)" Task: {4EB51857-3516-47B0-A06B-B72209E282CE} - System32\Tasks\{697226C5-CB9E-4126-B5BF-5A64165A741C} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Program Files\InstallShield Installation Information\{71A51CC2-E7D3-11DB-A386-005056C00008}\setup.exe" -c -runfromtemp -l0x040c -removeonly Task: {0DA24407-021E-4EDC-B27C-719D8B2045EE} - System32\Tasks\{69C30D92-780B-44F7-A999-34A56F18CBD4} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (2)\AUTOCAD 2008 32bit\Setup.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (2)\AUTOCAD 2008 32bit" Task: {E5B1BFF7-5E6A-461B-B8F1-227FE22528D0} - System32\Tasks\{97F12B32-7BC3-4903-96CC-A4C2BCCF2189} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (4)\Setup.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (4)" Task: {64B373A3-543F-47F3-9948-952F24546165} - System32\Tasks\{990600A3-10F7-4DF8-8285-29FAA5561232} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a C:\Users\jp\Downloads\Smart.Switch.PC_setup.exe -d C:\Users\jp\Downloads Task: {2E62E12F-CF2B-4281-B690-1152CB41BDDE} - System32\Tasks\{B511DE38-14BA-48C0-982B-8EA6A562F77C} => C:\Users\jp\Desktop\Nouveau dossier (2)\Setups1.exe (Pas de fichier) Task: {4A3A4D81-C745-4649-99A9-CCFF39897913} - System32\Tasks\{D4DCDA4A-B579-47A6-BE57-C82155020CB2} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (6)\Setups.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (6)" Task: {E3DD0DAB-B56C-46B0-A21E-5F0CF6691639} - System32\Tasks\{DBBB903A-BD76-4BC3-B293-F78D0C903C9A} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (4)\autorun.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (4)" Task: {8AF2069A-53AF-47C2-9672-32B9AB773399} - System32\Tasks\{F3FA8D12-1335-449E-9DA9-F5B4B6C5214B} => C:\Windows\system32\pcalua.exe [8192 2019-06-12] (Microsoft Windows -> Microsoft Corporation) -> -a "C:\Users\jp\Desktop\Nouveau dossier (2)\Setups1.exe" -d "C:\Users\jp\Desktop\Nouveau dossier (2)" Task: {1D378A08-7562-4249-8E3A-B38463D56FA7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1566200 2023-09-20] (Adobe Inc. -> Adobe Inc.) Task: {8A0FAF72-5135-422E-A65D-0579C44ED6F7} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_371_Plugin.exe [1458232 2022-04-14] (Adobe Inc. -> Adobe) Task: {CB24F737-920E-48A5-8B0A-7A1F63829A52} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_465_pepper.exe [1499704 2021-09-05] (Adobe Inc. -> Adobe) Task: {F7076BD0-33DB-41E8-9CE1-3FB9DC9F7C79} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2022-04-14] (Adobe Inc. -> Adobe) Task: {F846977B-4500-40E4-8A90-33D2B90570A7} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe (Pas de fichier) Task: {CD584AD6-163E-40FA-AE2B-5A1683893B83} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1830296 2023-08-02] (Avast Software s.r.o. -> Avast Software) Task: {48A1A20D-9D38-486D-BCFF-370A75E56184} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files\Avira\Antivirus\avgnt.exe [2648424 2022-02-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) Task: {B98BF294-5CAC-449F-97F6-09290A434EEA} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2023-11-08] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) Task: {636AD2C8-728C-48DD-958B-360A16E39D4D} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4252576 2023-11-08] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "436548e4-e5b5-43d7-805a-40216d490437" --version "6.18.10824" --silent Task: {9EB0AD07-8EE6-4AA8-827F-2683EE95FE13} - System32\Tasks\CCleanerSkipUAC - jp => C:\Program Files\CCleaner\CCleaner.exe [37544352 2023-11-08] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) Task: {FCF28BB0-F712-4DF6-8C37-77661E1E4B1B} - System32\Tasks\GlaryInitialize 5 => C:\Program Files\Glary Utilities 5\Initialize.exe [134640 2017-09-28] (Glarysoft LTD -> Glarysoft Ltd) Task: {58FC0494-AA79-418D-BC73-3EF1EB5DDB03} - System32\Tasks\GoogleUpdateTaskMachineCore{CF0CD731-8EE2-4280-86E8-A527CDB29F7E} => C:\Program Files\Google\Update\GoogleUpdate.exe [156232 2022-04-16] (Google LLC -> Google LLC) Task: {0B74D14C-369F-444B-811E-B1592A959560} - System32\Tasks\GoogleUpdateTaskMachineUA{9D18B874-2F68-4D12-87A0-2238DCFBCCC3} => C:\Program Files\Google\Update\GoogleUpdate.exe [156232 2022-04-16] (Google LLC -> Google LLC) Task: {579DA81B-3C12-4D3C-9800-C70D3E1EB9F4} - System32\Tasks\GU5SkipUAC => C:\Program Files\Glary Utilities 5\Integrator.exe [897520 2017-09-28] (Glarysoft LTD -> Glarysoft Ltd) Task: {FF861EF0-BABA-4329-A2E3-EA524713AF9E} - System32\Tasks\iTop BF Task (One-Time) => "C:\Program Files\iTop VPN\Pub\itopbfp23.exe" /bf (Pas de fichier) Task: {83CD0837-3CFE-4D24-8CF4-B1124FB0BA9D} - System32\Tasks\iTopVPN_Scheduler_jp => "C:\Program Files\iTop VPN\iTopVPN.exe" /autostart (Pas de fichier) Task: {94B03FEC-1DD6-4718-89A9-65AA0CCD0F7C} - System32\Tasks\iTopVPN_SkipUAC_jp => "C:\Program Files\iTop VPN\iTopVPN.exe" /SkipUac (Pas de fichier) Task: {7CD0DCAA-ACE3-4C1B-B73F-584E06CD8867} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-1027861262-4203368321-1641708045-1000 => "C:\Users\jp\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe" (Pas de fichier) Task: {02925318-FFD7-4B19-8E24-949EBD70914F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [18881528 2023-01-02] (Microsoft Corporation -> Microsoft Corporation) Task: {85851945-2142-4E56-A70B-28EAB52FEFDB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [18881528 2023-01-02] (Microsoft Corporation -> Microsoft Corporation) Task: {935A291A-4440-4F7A-B8D6-60ECA2536D11} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [117144 2023-01-19] (Microsoft Corporation -> Microsoft Corporation) Task: {B9FF159A-00C9-4CA4-9E7D-A1FF92511727} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [117144 2023-01-19] (Microsoft Corporation -> Microsoft Corporation) Task: {4AAE9E89-6BE7-4890-A5B9-2F60A4A66DDE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [4373984 2023-01-19] (Microsoft Corporation -> Microsoft Corporation) Task: {A6BAC4EF-8F5A-47C3-8EE5-0FC49621B57C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [4373984 2023-01-19] (Microsoft Corporation -> Microsoft Corporation) Task: {41DF97DF-B70A-4BC5-BF55-B8D14A1DD729} - System32\Tasks\Microsoft\Windows\Wininet\CacheTask => {0358b920-0ac7-461f-98f4-58e32cd89148} Task: {BC5B117B-9E87-4B37-BA73-764AF2E8CF70} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [609696 2023-11-24] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {A480106D-A644-43E2-9F7E-8C0404B31839} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [675232 2023-11-24] (Mozilla Corporation -> Mozilla Foundation) Task: {5CCAAEC9-F040-475B-82A9-B80E779D4F3F} - System32\Tasks\Opera scheduled Autoupdate 1618935428 => C:\Users\jp\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Pas de fichier) Task: {AC15F1F0-8D40-4D7F-8D0C-C3608D4A822C} - System32\Tasks\SmartDefrag_AutoAnalyze => C:\Program Files\IObit\Smart Defrag\AutoDefrag.exe [314128 2018-05-02] (IObit Information Technology -> IObit) Task: {559AD612-8A9D-490F-8694-29EC13D8F4B3} - System32\Tasks\SmartDefrag_Startup => C:\Program Files\IObit\Smart Defrag\SmartDefrag.exe [5983464 2022-06-28] (IObit CO., LTD -> IObit) Task: {AD489B03-A945-487B-9B12-4CD2E494D086} - System32\Tasks\SmartDefrag_Update => C:\Program Files\IObit\Smart Defrag\AutoUpdate.exe [3600616 2022-06-28] (IObit CO., LTD -> IObit) Task: {B82F2400-2E97-4A7E-A251-E282A6B06426} - System32\Tasks\TVT\TVSUUpdateTask => "C:\Program Files\Lenovo\System Update\tvsuShim.exe" /CM -search R -action INSTALL -includerebootpackages 1,3,4,5 -noicon -noreboot -nolicense -defaultupdate -schtask (Pas de fichier) Task: {BE3056CC-141E-46DB-B35A-5345A550704A} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => "C:\Program Files\Lenovo\System Update\tvsuShim.exe" PendingTask (Pas de fichier) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\Windows\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3: <==== ATTENTION (Restriction - Zones) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 Tcpip\..\Interfaces\{6FE0F833-FF97-41A7-8330-8AD223162DD5}: [DhcpNameServer] 192.168.0.254 HKLM\System\...\Parameters\PersistentRoutes: [104.87.88.177,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [104.89.242.39,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [104.96.147.3,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.177,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [111.221.29.253,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.34.230,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.40.37,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.61.100,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.61.64,255.255.255.255,0.0.0.0,1] HKLM\System\...\Parameters\PersistentRoutes: [131.253.61.68,255.255.255.255,0.0.0.0,1] PersistentRoutes: Il y a 82 PersistentRoutes. Edge: ======= Edge Profile: C:\Users\jp\AppData\Local\Microsoft\Edge\User Data\Default [2023-11-25] Edge Extension: (Malwarebytes Browser Guard) - C:\Users\jp\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2022-05-25] Edge HKLM\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] FireFox: ======== FF DefaultProfile: pnwtm3k3.default FF DefaultProfile: 3lq0rz63.default FF ProfilePath: C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1 [2023-11-25] FF Homepage: Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1 -> hxxps://www.apple.com/fr/?afid=p238%7Cs05EVyND6-dc_mtid_187079nc38483_pcrid_674107563808_pgrid_16898309484_pntwk_g_pchan__pexid__&cid=aos-fr-kwgo-brand--slid--bran-product- FF Notifications: Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1 -> hxxps://www.castorama.fr; hxxps://ww3.filmstoon.ink; hxxps://fr.aliexpress.com FF Extension: (Protection Web Avira) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\abs@avira.com.xpi [2022-10-10] FF Extension: (anonymoX) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\client@anonymox.net.xpi [2021-04-22] FF Extension: (Ghostery – Bloqueur de publicité protégeant la vie privée) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\firefox@ghostery.com.xpi [2023-08-01] FF Extension: (To Google Translate) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2021-06-23] FF Extension: (Privacy Badger) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2023-11-03] FF Extension: (Google Translator for Firefox) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\translator@zoli.bod.xpi [2020-11-12] FF Extension: (uBlock Origin) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\uBlock0@raymondhill.net.xpi [2023-11-04] FF Extension: (TWP - Translate Web Pages) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\{036a55b4-5e72-4d05-a06c-cba2dfcc134a}.xpi [2023-09-20] FF Extension: (Malwarebytes Browser Guard) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2022-10-13] FF Extension: (YouTube Downloader) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\{307f416a-39c0-49e0-8e96-cf802290e33c}.xpi [2022-10-20] FF Extension: (ImTranslator: Traducteur, Dictionnaire, Voix) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2023-10-25] FF Extension: (Video DownloadHelper) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2023-08-26] FF Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\7c7kdjmw.default-release-1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2023-06-21] FF ProfilePath: C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\pnwtm3k3.default [2023-11-25] FF Homepage: Mozilla\Firefox\Profiles\pnwtm3k3.default -> hxxps://www.google.com/ FF ProfilePath: C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release [2023-11-25] FF Homepage: Mozilla\Firefox\Profiles\0akbrud2.default-release -> hxxps://www.google.com/ FF Extension: (Protection Web Avira) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\abs@avira.com.xpi [2022-06-04] FF Extension: (anonymoX) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\client@anonymox.net.xpi [2021-04-22] FF Extension: (Ghostery – Bloqueur de publicité protégeant la vie privée) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\firefox@ghostery.com.xpi [2022-08-21] FF Extension: (To Google Translate) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\jid1-93WyvpgvxzGATw@jetpack.xpi [2021-06-23] FF Extension: (Privacy Badger) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2022-09-29] FF Extension: (Google Translator for Firefox) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\translator@zoli.bod.xpi [2020-11-12] FF Extension: (TWP - Translate Web Pages) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\{036a55b4-5e72-4d05-a06c-cba2dfcc134a}.xpi [2022-10-05] FF Extension: (Malwarebytes Browser Guard) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2022-08-30] FF Extension: (ImTranslator: Traducteur, Dictionnaire, Voix) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2022-08-21] FF Extension: (Video DownloadHelper) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2021-12-05] FF Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\jp\AppData\Roaming\Mozilla\Firefox\Profiles\0akbrud2.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-08-30] FF ProfilePath: C:\Users\jp\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\3lq0rz63.default [2023-11-25] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_32_0_0_371.dll [2022-04-14] (Adobe Inc. -> ) FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-04-21] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-04-21] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.14 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.15 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2023-02-14] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1027861262-4203368321-1641708045-1000: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files\Lightspark\nplightsparkplugin.dll [Pas de fichier] Chrome: ======= CHR Profile: C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default [2023-11-25] CHR Notifications: Default -> hxxps://www.apple.com,*"; hxxps://www.facebook.com; hxxps://www.youtube.com CHR HomePage: Default -> hxxp://www.google.com CHR StartupUrls: Default -> "hxxps://www.apple.com/fr/","hxxps://www.apple.com/fr/" CHR Extension: (Google Traduction) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-03-24] CHR Extension: (Avira Password Manager) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\caljgklbbfbcjjanaijlacgncafpegll [2023-11-10] CHR Extension: (uBlock Origin) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2023-11-10] CHR Extension: (Do Not Track) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckdcpbflcbeillmamogkpmdhnbeggfja [2022-11-06] CHR Extension: (Protection Web Avira) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2022-11-03] CHR Extension: (Quick Javascript Switcher) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\geddoclleiomckbhadiaipdggiiccfje [2022-11-06] CHR Extension: (Google Docs hors connexion) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-26] CHR Extension: (Malwarebytes Browser Guard) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-11-24] CHR Extension: (Mate Translate - traducteur, dictionnaire) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihmgiclibbndffejedjimfjmfoabpcke [2022-11-18] CHR Extension: (Temp Mail - E-mail temporaire disponible) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\inojafojbhdpnehkhhfjalgjjobnhomj [2023-02-11] CHR Extension: (Video DownloadHelper) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2023-08-25] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-04-14] CHR Extension: (ImTranslator: Traducteur, Dictionnaire, Voix) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\noaijdpnepcgjemiklgfkcfbkokogabh [2023-11-13] CHR Extension: (Reverso - Traduction, dictionnaire) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\onhiacboedfinnofagfgoaanfedhmfab [2023-10-02] CHR Extension: (Privacy Badger) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkehgijcmpdhfbdbbnkijodmdjhbjlgp [2023-11-10] CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] CHR HKLM\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] Opera: ======= OPR Profile: C:\Users\jp\AppData\Roaming\Opera Software\Opera Stable [2023-11-25] OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding} OPR Extension: (Rich Hints Agent) - C:\Users\jp\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2022-04-14] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 AdobeARMservice; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [173040 2023-09-20] (Adobe Inc. -> Adobe Inc.) S3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2022-04-14] (Adobe Inc. -> Adobe) S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [911264 2023-11-08] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7247352 2023-01-02] (Microsoft Corporation -> Microsoft Corporation) S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [280680 2015-06-04] (Intel Corporation - pGFX -> Intel Corporation) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3928768 2022-04-06] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2022-04-01] (Flexera Software, Inc. -> Flexera Software, Inc.) S3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [169752 2012-04-24] (Intel Corporation -> Intel Corporation) S3 IEEtwCollectorService; C:\Windows\system32\IEEtwCollector.exe [102912 2022-04-13] (Microsoft Corporation) [Fichier non signé] R2 Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [109728 2011-01-17] (Intel Corporation -> Intel Corporation) R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2022-10-04] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [920768 2022-10-04] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Windows -> Microsoft Corporation) R2 WsAppService; C:\Program Files\Wondershare\WAF\2.4.3.242\WsAppService.exe [495720 2018-08-29] (Wondershare Technology Co.,Ltd -> Wondershare) S2 DCIService; C:\Program Files\Lavasoft\Web Companion\Service\Win32\DCIService.exe [X] <==== ATTENTION S2 MaskVPNService; "C:\Program Files\MaskVPN\mask_svc.exe" [X] <==== ATTENTION S3 Power Manager DBC Service; "C:\Program Files\Lenovo\PowerMgr\PWMDBSVC.EXE" [X] S3 SUService; "C:\Program Files\Lenovo\System Update\SUService.exe" [X] ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [33552 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [179032 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [292336 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [206320 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [91616 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [39248 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [151912 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [378384 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [36104 2021-04-20] (AVAST Software s.r.o. -> AVAST Software) R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [92704 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [71352 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [690144 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [386248 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [161824 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [276984 2021-04-20] (Avast Software s.r.o. -> AVAST Software) R0 avdevprot; C:\Windows\System32\DRIVERS\avdevprot.sys [50728 2019-06-07] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R0 avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [33280 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) R2 BdDci; C:\Windows\System32\DRIVERS\bddci.sys [255400 2022-04-14] (Bitdefender SRL -> Bitdefender) S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [123920 2022-10-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 e1cexpress; C:\Windows\System32\DRIVERS\e1c6232.sys [368392 2014-05-02] (Intel Corporation -> Intel Corporation) R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [17472 2021-04-21] (Glarysoft Ltd -> Glarysoft Ltd) R3 MEI; C:\Windows\System32\DRIVERS\TeeDriver.sys [109568 2014-08-13] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) R3 NETwNs32; C:\Windows\System32\DRIVERS\NETwsn00.sys [10384656 2015-05-04] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [23552 2014-08-08] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S3 RSUSBVSTOR; C:\Windows\System32\Drivers\RTSUVSTOR.sys [226408 2011-02-09] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) R3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [293080 2015-05-27] (Realtek Semiconductor Corp -> Realsil Semiconductor Corporation) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [18800 2016-03-22] (IObit Information Technology -> IObit) R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [25840 2014-12-04] (Synaptics Incorporated -> Synaptics Incorporated) R2 smihlp; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [11976 2011-05-30] (AuthenTec, Inc. -> Authentec Inc.) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [155664 2022-10-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 VMC444; C:\Windows\System32\Drivers\VMC444.sys [250112 2011-07-26] (Microsoft Windows Hardware Compatibility Publisher -> Vimicro Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-11-25 07:54 - 2023-11-25 07:56 - 000035935 _____ C:\Users\jp\Downloads\FRST.txt 2023-11-25 07:47 - 2023-11-25 07:47 - 000001258 _____ C:\Users\jp\Desktop\Magnify (2).lnk 2023-11-25 07:46 - 2023-11-25 07:46 - 000001258 _____ C:\Users\jp\Desktop\Magnify.lnk 2023-11-25 06:56 - 2023-11-25 06:56 - 002084864 _____ (Farbar) C:\Users\jp\Downloads\FRST.exe 2023-11-25 06:30 - 2023-11-25 06:30 - 001464712 _____ (PortableApps.com) C:\Users\jp\Downloads\GoogleChromePortable_109.0.5414.120_online.paf.exe 2023-11-25 06:15 - 2023-11-25 06:15 - 000000000 __SHD C:\Windows\system32\%APPDATA% 2023-11-25 05:37 - 2023-11-25 05:36 - 000470803 ____R C:\Windows\system32\Drivers\etc\hosts.20231125-053716.backup 2023-11-25 05:36 - 2023-11-25 05:35 - 000470803 ____R C:\Windows\system32\Drivers\etc\hosts.20231125-053621.backup 2023-11-25 05:35 - 2023-11-25 05:25 - 000017091 _____ C:\Windows\system32\Drivers\etc\hosts.20231125-053528.backup 2023-11-25 05:25 - 2023-11-25 05:25 - 000000000 ____D C:\Windows\system32\Tasks\COMODO 2023-11-25 05:11 - 2023-11-25 05:11 - 000000000 ____D C:\Users\jp\AppData\Local\Safer-Networking Ltd 2023-11-25 05:11 - 2023-11-25 05:11 - 000000000 ____D C:\Program Files\Safer-Networking Ltd 2023-11-25 05:09 - 2023-11-25 05:09 - 000000000 ____D C:\Users\jp\AppData\Local\unali-2480447 2023-11-25 05:09 - 2023-11-25 05:09 - 000000000 ____D C:\Users\jp\AppData\Local\unali-2479682 2023-11-25 03:35 - 2023-11-25 06:06 - 000000079 _____ C:\Windows\wininit.ini 2023-11-25 01:35 - 2023-11-25 07:55 - 000000000 ____D C:\FRST 2023-11-24 23:47 - 2023-11-25 02:34 - 000000000 ____D C:\Program Files\Mozilla Firefox 2023-11-20 16:45 - 2023-11-20 16:45 - 000003174 _____ C:\Windows\system32\Tasks\iTop BF Task (One-Time) 2023-11-19 12:27 - 2023-11-25 01:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTop VPN 2023-11-19 12:27 - 2023-11-24 23:23 - 000000000 ____D C:\Users\jp\AppData\Roaming\iTop VPN 2023-11-19 12:27 - 2023-11-19 12:27 - 000003288 _____ C:\Windows\system32\Tasks\iTopVPN_Scheduler_jp 2023-11-19 12:27 - 2023-11-19 12:27 - 000003266 _____ C:\Windows\system32\Tasks\iTopVPN_SkipUAC_jp 2023-11-19 12:26 - 2023-11-24 23:41 - 000000000 ____D C:\Program Files\iTop VPN 2023-11-16 08:37 - 2023-11-16 08:37 - 000051742 _____ C:\Users\jp\Desktop\facture A 23 5g.pdf 2023-11-15 01:10 - 2023-11-15 01:10 - 000000000 ____D C:\Users\Public\Documents\NativeFus_Log 2023-11-15 01:10 - 2022-10-04 07:16 - 000155664 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudmdm.sys 2023-11-15 01:10 - 2022-10-04 07:16 - 000123920 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\ssudbus.sys 2023-11-14 23:32 - 2023-11-24 23:17 - 000000000 ____D C:\ProgramData\iTop 2023-11-14 10:46 - 2023-11-14 10:49 - 000000000 ____D C:\Users\jp\Desktop\Nouveau dossier (5) 2023-11-14 09:49 - 2023-11-14 09:50 - 000000000 ____D C:\Users\jp\AppData\Local\AdvertisingPopup 2023-11-14 09:43 - 2023-11-14 09:43 - 000003126 _____ C:\Windows\system32\Tasks\{990600A3-10F7-4DF8-8285-29FAA5561232} 2023-11-14 09:39 - 2023-11-14 09:39 - 043097408 _____ (Samsung Electronics) C:\Users\jp\Downloads\Smart.Switch.PC_setup.exe 2023-11-14 07:16 - 2023-11-14 07:16 - 036869556 _____ C:\Users\jp\Downloads\Samsung-USB-Driver-v1_7_50_0.zip 2023-11-12 18:49 - 2023-11-25 04:30 - 000000048 _____ C:\Windows\system32\EUTB.TODF 2023-11-12 18:49 - 2023-11-12 18:49 - 000000000 ____D C:\ProgramData\SystemAcCrux 2023-11-12 18:48 - 2023-09-22 01:45 - 000474616 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\EuFdDisk.sys 2023-11-12 18:48 - 2023-09-22 01:45 - 000071672 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\eubakup.sys 2023-11-12 18:48 - 2023-09-22 01:45 - 000053752 _____ C:\Windows\system32\Drivers\EUBKMON.sys 2023-11-12 18:48 - 2023-09-22 01:45 - 000026616 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\Windows\system32\Drivers\eudskacs.sys 2023-11-12 18:46 - 2023-11-25 05:10 - 000000000 ____D C:\Program Files\EaseUS 2023-11-12 18:46 - 2023-11-24 23:17 - 000000000 ____D C:\ProgramData\EaseUS 2023-11-12 18:46 - 2023-09-22 01:45 - 000027640 _____ C:\Windows\system32\Drivers\euimgprt.sys 2023-11-12 18:45 - 2023-11-12 18:45 - 145676248 _____ (EaseUS ) C:\Users\jp\Downloads\TB_free_easeus.exe 2023-10-26 08:11 - 2023-10-26 08:11 - 000003584 _____ C:\Users\jp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-11-25 07:55 - 2021-04-20 20:51 - 000000000 ____D C:\Users\jp\AppData\Local\CrashDumps 2023-11-25 07:50 - 2009-07-14 05:34 - 000031648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2023-11-25 07:50 - 2009-07-14 05:34 - 000031648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2023-11-25 07:44 - 2021-04-18 20:10 - 000000000 ____D C:\Program Files\Google 2023-11-25 07:43 - 2021-04-21 14:49 - 000000000 ____D C:\Program Files\Glary Utilities 5 2023-11-25 07:42 - 2009-07-14 05:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2023-11-25 06:17 - 2022-04-14 12:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2023-11-25 06:17 - 2022-04-14 12:39 - 000000000 ____D C:\Users\jp\AppData\Roaming\Lavasoft 2023-11-25 06:17 - 2022-04-14 12:39 - 000000000 ____D C:\Users\jp\AppData\Local\Lavasoft 2023-11-25 06:17 - 2022-04-14 12:38 - 000000000 ____D C:\ProgramData\Lavasoft 2023-11-25 06:17 - 2022-04-14 12:38 - 000000000 ____D C:\Program Files\Lavasoft 2023-11-25 06:17 - 2022-04-14 12:37 - 000000000 ____D C:\Users\jp\AppData\Roaming\IObit 2023-11-25 06:17 - 2022-04-14 12:37 - 000000000 ____D C:\Users\jp\AppData\LocalLow\IObit 2023-11-25 06:17 - 2022-04-14 12:37 - 000000000 ____D C:\ProgramData\IObit 2023-11-25 06:17 - 2022-04-14 12:37 - 000000000 ____D C:\Program Files\Common Files\IObit 2023-11-25 06:17 - 2021-05-07 06:14 - 000000000 ____D C:\Users\jp\AppData\Roaming\Samsung 2023-11-25 06:17 - 2021-05-07 06:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2023-11-25 06:17 - 2021-05-07 06:14 - 000000000 ____D C:\Program Files\Samsung 2023-11-25 06:17 - 2021-04-18 21:44 - 000000000 ____D C:\Program Files\Lenovo 2023-11-25 06:16 - 2023-09-17 02:18 - 000000000 ____D C:\AdwCleaner 2023-11-25 06:08 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\PolicyDefinitions 2023-11-25 06:06 - 2022-04-12 13:11 - 000000000 ____D C:\Program Files\Spybot - Search & Destroy 2 2023-11-25 06:06 - 2022-04-12 12:54 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy 2023-11-25 05:25 - 2021-04-18 21:30 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo 2023-11-25 05:11 - 2022-04-12 14:38 - 000000000 ____D C:\Windows\system32\Tasks\Safer-Networking 2023-11-25 05:11 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\registration 2023-11-25 05:07 - 2022-04-05 10:46 - 000000000 ____D C:\ProgramData\Autodesk 2023-11-25 05:07 - 2022-02-18 20:07 - 000000000 ____D C:\Program Files\Common Files\Autodesk Shared 2023-11-25 05:07 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\Help 2023-11-25 05:05 - 2021-09-05 07:02 - 000000000 ____D C:\Windows\system32\Macromed 2023-11-25 04:30 - 2023-03-29 07:35 - 000000000 ____D C:\Program Files\CCleaner 2023-11-25 02:45 - 2023-01-29 13:37 - 000000000 ____D C:\Users\jp\Desktop\firefox save 2023 2023-11-25 02:34 - 2021-04-18 20:11 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service 2023-11-25 01:13 - 2021-04-18 21:19 - 000000000 ____D C:\Users\jp\AppData\LocalLow\Mozilla 2023-11-25 01:12 - 2022-02-08 23:34 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2023-11-25 00:05 - 2021-10-11 05:21 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla 2023-11-24 23:23 - 2022-04-14 07:29 - 000000000 ____D C:\Users\jp 2023-11-24 23:17 - 2022-04-14 07:27 - 000000000 ____D C:\Windows\VMC444 2023-11-24 23:17 - 2021-04-21 06:11 - 000000000 ____D C:\Windows\system32\Tasks\OfficeSoftwareProtectionPlatform 2023-11-24 23:17 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\inf 2023-11-21 09:13 - 2023-02-14 11:06 - 000000000 ____D C:\Users\jp\Desktop\Nouveau dossier (3) 2023-11-20 08:07 - 2023-03-29 07:35 - 000000666 _____ C:\Windows\Tasks\CCleanerCrashReporting.job 2023-11-16 10:29 - 2023-03-29 07:35 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update 2023-11-16 10:29 - 2023-03-29 07:35 - 000003246 _____ C:\Windows\system32\Tasks\CCleanerCrashReporting 2023-11-16 03:13 - 2023-09-18 02:01 - 000000000 ____D C:\Windows\system32\MRT 2023-11-16 03:02 - 2023-09-18 02:01 - 178067448 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2023-11-15 01:09 - 2021-04-18 21:50 - 000000000 ___HD C:\Program Files\InstallShield Installation Information 2023-11-15 00:47 - 2022-04-07 14:58 - 000000000 ____D C:\Users\jp\AppData\Local\ElevatedDiagnostics 2023-11-14 23:38 - 2022-04-14 12:39 - 000000000 ____D C:\ProgramData\iTop VPN 2023-11-14 09:56 - 2011-04-12 02:35 - 000746916 _____ C:\Windows\system32\perfh00C.dat 2023-11-14 09:56 - 2011-04-12 02:35 - 000149440 _____ C:\Windows\system32\perfc00C.dat 2023-11-14 09:56 - 2010-11-20 22:01 - 001667292 _____ C:\Windows\system32\PerfStringBackup.INI 2023-11-14 09:34 - 2021-04-18 21:44 - 000000000 ____D C:\ProgramData\Lenovo 2023-11-14 03:09 - 2022-04-16 08:21 - 000003818 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA{9D18B874-2F68-4D12-87A0-2238DCFBCCC3} 2023-11-14 03:09 - 2022-04-16 08:21 - 000003690 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore{CF0CD731-8EE2-4280-86E8-A527CDB29F7E} 2023-11-13 10:49 - 2021-04-18 21:44 - 000000000 ____D C:\Windows\system32\Tasks\TVT 2023-11-13 10:49 - 2021-04-18 21:38 - 000000000 ____D C:\Windows\TempInst 2023-11-13 10:48 - 2021-06-07 09:48 - 000002873 _____ C:\Windows\system32\InstallUtil.InstallLog 2023-11-13 10:48 - 2021-04-18 21:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\lenovo 2023-11-12 11:06 - 2021-04-18 23:01 - 000000000 ___HD C:\Users\jp\Documents\Bandicam 2023-11-10 09:48 - 2022-04-14 12:37 - 000000000 ____D C:\ProgramData\ProductData ==================== Fichiers à la racine de certains dossiers ======== 2021-11-24 13:48 - 2021-11-24 13:50 - 010229760 _____ () C:\Program Files\GUT7347.tmp 2023-10-26 08:11 - 2023-10-26 08:11 - 000003584 _____ () C:\Users\jp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) testsigning: ==> 'testsigning' est activé. Rechercher un éventuel pilote non signé <==== ATTENTION LastRegBack: 2023-11-14 11:38 ==================== Fin de FRST.txt ========================