Résultats de correction de Farbar Recovery Scan Tool (x64) Version: 28.03.2024 Exécuté par PC (29-03-2024 13:19:03) Run:1 Exécuté depuis C:\Users\PC\Desktop Profils chargés: PC Mode d'amorçage: Normal ============================================== fixlist contenu: ***************** start:: CreateRestorePoint: CloseProcesses: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45285792 2024-03-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) HKU\S-1-5-21-3815695886-347864032-1501953893-1001\...\Run: [] => [X] HKU\S-1-5-21-3815695886-347864032-1501953893-1001\...\Run: [MicrosoftEdgeAutoLaunch_B47356396DDD0FAAE76D0ED141F5CEA2] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060712 2024-03-14] (Microsoft Corporation -> Microsoft Corporation) GroupPolicy-Firefox: Restriction HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction DeleteValue: HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\StartupApproved\Run|OneDriveSetup DeleteValue: HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\StartupApproved\Run|OneDriveSetup DeleteValue: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{1DAC0C53-7D23-4AB3-856A-B04D98CD982A} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{044F89F5-0FD0-4666-B0DE-851B2855490F}C:\program files (x86)\gigatribe\gigatribe.exe" DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{E8FABCFD-EFF3-4950-9F9E-C86619C3E197}C:\program files (x86)\gigatribe\gigatribe.exe" DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{F148C969-EC89-470C-A771-453E0D603003}C:\program files (x86)\gigatribe\gigatribe.exe" DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{FCB18FE1-BBF3-49A6-B3F1-B5B308BBC70B}C:\program files (x86)\gigatribe\gigatribe.exe" DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\AppData\Local\Programs\nordpass\NordPass.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\AppData\Local\Programs\nordpass\NordPass.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\Pictures\assoconnect\iPrintScan-Setup-6_1_3_4.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\Pictures\assoconnect\iPrintScan-Setup-6_1_3_4.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\Pictures\assoconnect\LogiCameraSettings_2.12.8.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\Pictures\assoconnect\LogiCameraSettings_2.12.8.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\gigatribe\gigatribe.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\gigatribe\gigatribe.exe.ApplicationCompany DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\NordVPN\NordVPN.exe.FriendlyAppName DeleteValue: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\NordVPN\NordVPN.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\AppData\Local\Programs\nordpass\NordPass.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\AppData\Local\Programs\nordpass\NordPass.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\Pictures\assoconnect\iPrintScan-Setup-6_1_3_4.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\Pictures\assoconnect\iPrintScan-Setup-6_1_3_4.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\Pictures\assoconnect\LogiCameraSettings_2.12.8.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\PC\Pictures\assoconnect\LogiCameraSettings_2.12.8.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\gigatribe\gigatribe.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\program files (x86)\gigatribe\gigatribe.exe.ApplicationCompany DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\NordVPN\NordVPN.exe.FriendlyAppName DeleteValue: HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files\NordVPN\NordVPN.exe.ApplicationCompany DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Edge Profile: C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\cId=128000000001363769&path= [2024-03-14] CustomCLSID: HKU\S-1-5-21-3815695886-347864032-1501953893-1001_Classes\CLSID\{4e6f7264-5650-4e00-0000-000000000000}\localserver32 -> "C:\Program Files\NordVPN\NordVPN.exe" -ToastActivated => Pas de fichier StartBatch: For /D %%d In ("%userprofile%\AppData\Local\Mozilla\Firefox\Profiles\*") Do (If Exist "%%d\Cache2" Del /s /q "%%d\Cache2\*.*") del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*" del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*" del /s /q "%userprofile%\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\*.*" For /D %%d In ("%userprofile%\AppData\Roaming\Mozilla\Firefox\Profiles\*") Do (If Exist "%%d\cookies.sqlite" Del /s /q "%%d\cookies.sqlite") del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\History" del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\History" del /s /q "%userprofile%\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\History" EndBatch: EmptyTemp: end:: ***************** Le Point de restauration a été créé avec succès. Processus fermé avec succès. "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Smart Cleaning" => supprimé(es) avec succès "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Microsoft\Windows\CurrentVersion\Run\\" => supprimé(es) avec succès "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Microsoft\Windows\CurrentVersion\Run\\MicrosoftEdgeAutoLaunch_B47356396DDD0FAAE76D0ED141F5CEA2" => supprimé(es) avec succès C:\Program Files\Mozilla Firefox\distribution\policies.json => déplacé(es) avec succès HKLM\SOFTWARE\Policies\Microsoft\Edge => supprimé(es) avec succès "HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\StartupApproved\Run\\OneDriveSetup" => supprimé(es) avec succès "HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\StartupApproved\Run\\OneDriveSetup" => supprimé(es) avec succès "HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{1DAC0C53-7D23-4AB3-856A-B04D98CD982A}" => supprimé(es) avec succès "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{044F89F5-0FD0-4666-B0DE-851B2855490F}C:\program files (x86)\gigatribe\gigatribe.exe"" => non trouvé(e) "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E8FABCFD-EFF3-4950-9F9E-C86619C3E197}C:\program files (x86)\gigatribe\gigatribe.exe"" => non trouvé(e) "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{F148C969-EC89-470C-A771-453E0D603003}C:\program files (x86)\gigatribe\gigatribe.exe"" => non trouvé(e) "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{FCB18FE1-BBF3-49A6-B3F1-B5B308BBC70B}C:\program files (x86)\gigatribe\gigatribe.exe"" => non trouvé(e) "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\AppData\Local\Programs\nordpass\NordPass.exe.FriendlyAppName" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\AppData\Local\Programs\nordpass\NordPass.exe.ApplicationCompany" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\Pictures\assoconnect\iPrintScan-Setup-6_1_3_4.exe.FriendlyAppName" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\Pictures\assoconnect\iPrintScan-Setup-6_1_3_4.exe.ApplicationCompany" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\Pictures\assoconnect\LogiCameraSettings_2.12.8.exe.FriendlyAppName" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\Pictures\assoconnect\LogiCameraSettings_2.12.8.exe.ApplicationCompany" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\program files (x86)\gigatribe\gigatribe.exe.FriendlyAppName" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\program files (x86)\gigatribe\gigatribe.exe.ApplicationCompany" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Program Files\NordVPN\NordVPN.exe.FriendlyAppName" => supprimé(es) avec succès "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Program Files\NordVPN\NordVPN.exe.ApplicationCompany" => supprimé(es) avec succès "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\AppData\Local\Programs\nordpass\NordPass.exe.FriendlyAppName" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\AppData\Local\Programs\nordpass\NordPass.exe.ApplicationCompany" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\Pictures\assoconnect\iPrintScan-Setup-6_1_3_4.exe.FriendlyAppName" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\Pictures\assoconnect\iPrintScan-Setup-6_1_3_4.exe.ApplicationCompany" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\Pictures\assoconnect\LogiCameraSettings_2.12.8.exe.FriendlyAppName" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Users\PC\Pictures\assoconnect\LogiCameraSettings_2.12.8.exe.ApplicationCompany" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\program files (x86)\gigatribe\gigatribe.exe.FriendlyAppName" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\program files (x86)\gigatribe\gigatribe.exe.ApplicationCompany" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Program Files\NordVPN\NordVPN.exe.FriendlyAppName" => non trouvé(e) "HKU\S-1-5-21-3815695886-347864032-1501953893-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Program Files\NordVPN\NordVPN.exe.ApplicationCompany" => non trouvé(e) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} => non trouvé(e) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} => non trouvé(e) HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} => supprimé(es) avec succès "C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\cId=128000000001363769&path=" Dossier déplacer: C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\cId=128000000001363769&path= => déplacé(es) avec succès HKU\S-1-5-21-3815695886-347864032-1501953893-1001_Classes\CLSID\{4e6f7264-5650-4e00-0000-000000000000} => supprimé(es) avec succès ========= Batch: ========= C:\Users\PC\Desktop>(If Exist "C:\Users\PC\AppData\Local\Mozilla\Firefox\Profiles\atl2wel3.default\Cache2" Del /s /q "C:\Users\PC\AppData\Local\Mozilla\Firefox\Profiles\atl2wel3.default\Cache2\*.*" ) C:\Users\PC\Desktop>(If Exist "C:\Users\PC\AppData\Local\Mozilla\Firefox\Profiles\e0y4zjlv.default-release-1579164755688\Cache2" Del /s /q "C:\Users\PC\AppData\Local\Mozilla\Firefox\Profiles\e0y4zjlv.default-release-1579164755688\Cache2\*.*" ) 䰀攀 挀栀攀洀椀渀 搀ᤠ愀挀挀쎨s spÃ꤀挀椀昀椀쎩 est introuvable. Fichier supprimé - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\data_0 Fichier supprimé - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\data_1 Fichier supprimé - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\data_2 Fichier supprimé - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\data_3 Fichier supprimé - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\Cache\Cache_Data\index 0 C:\Users\PC\Desktop>(If Exist "C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\atl2wel3.default\cookies.sqlite" Del /s /q "C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\atl2wel3.default\cookies.sqlite" ) C:\Users\PC\Desktop>(If Exist "C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\e0y4zjlv.default-release-1579164755688\cookies.sqlite" Del /s /q "C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\e0y4zjlv.default-release-1579164755688\cookies.sqlite" ) Fichier supprimé - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\e0y4zjlv.default-release-1579164755688\cookies.sqlite 䰀攀 挀栀攀洀椀渀 搀ᤠ愀挀挀쎨s spÃ꤀挀椀昀椀쎩 est introuvable. Fichier supprimé - C:\Users\PC\AppData\Local\Microsoft\Edge\User Data\Default\History Fichier supprimé - C:\Users\PC\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\History ========= Fin de Batch: ========= =========== EmptyTemp: ========== FlushDNS => terminé(e) BITS transfer queue => 1310720 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18046152 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B Windows/system/drivers => 116333614 B Edge => 0 B Brave => 20480 B Firefox => 16896840 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 147222 B systemprofile32 => 147222 B LocalService => 152511 B NetworkService => 8893635 B PC => 21395615 B RecycleBin => 0 B EmptyTemp: => 174.9 MB données temporaires supprimées. ================================ Le système a dû redémarrer. ==== Fin de Fixlog 13:19:51 ====