cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 07-07-2021
Exécuté par maurice (administrateur) sur DESKTOP-VB01NJF (08-07-2021 22:24:30)
Exécuté depuis C:\Users\maurice\Desktop
Profils chargés: maurice
Platform: Windows 10 Pro N Version 2004 19041.1052 (X64) Langue: Français (France)
Navigateur par défaut: Chrome
Mode d'amorçage: Normal

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe <2>
(AOMEI International Network Limited -> AOMEI International Network Limited) C:\Program Files (x86)\AOMEI\AOMEI Backupper 6.0.0\ABService.exe
(Avanquest UK Ltd -> Avanquest Software) C:\Program Files (x86)\eXpert PDF 12 Manager\eXpert PDF 12\eXpert Manager.exe
(Avanquest UK Ltd -> Avanquest Software) C:\Program Files\eXpert PDF 12\creator\common\creator-ws.exe
(Avanquest UK Ltd -> Avanquest Software) C:\Program Files\eXpert PDF 12\expert.exe
(Avanquest UK Ltd -> Avanquest Software) C:\Program Files\eXpert PDF 12\ws.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <20>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Jiangmen Ruili Software Co., Ltd. -> Rene.E Laboratory) C:\Program Files (x86)\Rene.E Laboratory\Becca\x64\bcservice.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\SetPointP\LogiAppBroker.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <8>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\maurice\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxIdentityProvider_12.67.21001.0_x64__8wekyb3d8bbwe\XboxIdp.exe
(Microsoft Studios) C:\Program Files\WindowsApps\Microsoft.MicrosoftSudoku_2.5.6181.0_x64__8wekyb3d8bbwe\Microsoft Sudoku.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\NisSrv.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe <2>
(Nicolas Coolman -> Nicolas Coolman) [Fichier non signé] C:\Users\maurice\Desktop\ZHPCleaner.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VIA Technologies, Inc -> VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe

==================== Registre (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3136136 2019-01-31] (Logitech Inc -> Logitech, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-133066294-687466313-2902525667-1001\...\Run: [TomTom MySports Connect.exe] => C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe [638464 2018-09-03] (TomTom) [Fichier non signé]
HKU\S-1-5-21-133066294-687466313-2902525667-1001\...\Run: [com.deezer.deezer-desktop] => C:\Users\maurice\AppData\Local\Programs\deezer-desktop\Deezer.exe [52759360 2019-03-29] (Deezer -> Deezer)
HKU\S-1-5-21-133066294-687466313-2902525667-1001\...\Run: [RLinkToolbox.exe] => C:\Program Files (x86)\RLinkToolbox 3\RLinkToolbox.exe [1050040 2020-06-08] (TomTom International B.V. -> TomTom)
HKU\S-1-5-21-133066294-687466313-2902525667-1001\...\Run: [LBRY] => C:\Program Files\LBRY\LBRY.exe [94038840 2020-08-31] (LBRY, Inc -> LBRY Inc.)
HKU\S-1-5-21-133066294-687466313-2902525667-1001\...\Run: [Reverso] => "C:\Users\maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Reverso\Reverso.appref-ms" -minimized
HKLM\...\Print\Monitors\HP 5912 Status Monitor: C:\WINDOWS\system32\hpinksts5912LM.dll [331664 2012-06-18] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP Officejet Pro 8600): C:\WINDOWS\system32\HPDiscoPM5912.dll [741480 2012-10-17] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.124\Installer\chrmstp.exe [2021-06-29] (Google LLC -> Google LLC)
Startup: C:\Users\maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Envoyer à OneNote.lnk [2021-06-09]
ShortcutTarget: Envoyer à OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION

==================== Tâches planifiées (Avec liste blanche) ============

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

Task: {05DD0FC8-804D-40AB-952A-33A506D09388} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0AB5A7CC-DB6C-456E-B6EE-0A168003B2D2} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0DBE8DAD-E1EB-47FD-BB90-49EEF3CD4918} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [3965880 2021-07-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {112CE504-6D69-4F21-9404-A7BAA262A2CE} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [118096 2021-07-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {1C0D384B-8008-4498-8B19-18116B38F584} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-12-09] (Google Inc -> Google Inc.)
Task: {21105D2F-C33E-44FF-B5B6-B0A627358F60} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [3965880 2021-07-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {32318EB4-CE12-445F-9960-D8F8A2719BC7} - \Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Unlock -> Pas de fichier <==== ATTENTION
Task: {345879BA-CCBF-4F71-8977-0AACCA722A4E} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
Task: {34712BF5-FFCC-4DA8-B9F5-78AA5131D8EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3BE6E31A-30AE-421A-A085-C00BB428E9B9} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23180168 2021-06-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {3C414F83-9A81-4BCB-B1A9-CB58D82A0A1D} - \Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\OnIdle -> Pas de fichier <==== ATTENTION
Task: {412DEAC6-7D31-4AC8-83BF-504616DAC9D7} - \Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\RunCampaignManager2 -> Pas de fichier <==== ATTENTION
Task: {5A569601-49C3-4F6E-A221-0B9DE8D715E1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-12-09] (Google Inc -> Google Inc.)
Task: {5DCECBBA-ACBB-4720-8A16-005C522669F0} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5F65CC12-EF55-4BEF-9938-7F7005032A45} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5FEA43FD-63EA-4473-9EBE-4296ABF2E64C} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {6B3292CA-EF84-4124-8EAC-D1C67CCA2F4F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23180168 2021-06-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {732564CB-D0DD-4CC3-AE3C-0E269F3B305C} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8159BF4B-8AD6-494C-99E5-0BA757394E96} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3292984 2020-06-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {82F2F17C-7D34-44EC-A932-535725CCE1F3} - \Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\OutOfIdle -> Pas de fichier <==== ATTENTION
Task: {854E137B-A53C-485D-86D9-DF046AA229BF} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [118096 2021-07-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {89FD9B22-69C9-421F-8EF6-A939F9D53B76} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {8CCDDF11-D094-45F8-B57E-175660708310} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [647656 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {912915AD-F8C4-4CE7-A96D-9EDF160B1E28} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A92BDCAA-7403-4F6F-9D31-5CECCD1013E6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D773D838-A47B-4D2B-AE11-CC7E878E5552} - \Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Time -> Pas de fichier <==== ATTENTION
Task: {DDA8F482-B754-474D-80A5-C24A01203E0B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [664784 2020-09-17] (Mozilla Corporation -> Mozilla Foundation)
Task: {DE1D88FD-A1E2-4DC4-8DDD-8E9EA0B7BDCE} - \Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Logon -> Pas de fichier <==== ATTENTION
Task: {EA9518A9-7220-45E7-B909-23D47CC17603} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MpCmdRun.exe [644888 2021-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F103B565-8937-4789-A39A-7B947FD33D20} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {FB6AA4BA-1899-476F-A2E3-1E67A6E9556D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)

(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)


==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{9c222b75-3782-4b60-9434-01ab5c7f87f6}: [DhcpNameServer] 192.168.1.254
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\maurice\AppData\Local\Microsoft\Edge\User Data\Default [2021-07-08]
Edge HomePage: Default -> hxxp://www.google.fr/ig
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\maurice\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-07-08]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

FireFox:
========
FF DefaultProfile: azn6pcvj.default
FF ProfilePath: C:\Users\maurice\AppData\Roaming\Mozilla\Firefox\Profiles\azn6pcvj.default [2020-09-27]
FF ProfilePath: C:\Users\maurice\AppData\Roaming\Mozilla\Firefox\Profiles\8pffekfy.default-release [2021-06-29]
FF Extension: (Malwarebytes Browser Guard) - C:\Users\maurice\AppData\Roaming\Mozilla\Firefox\Profiles\8pffekfy.default-release\Extensions\{242af0bb-db11-4734-b7a0-61cb8a9b20fb}.xpi [2020-12-23]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2019-09-09] [non signé]
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2021-05-27] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-27] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-03-24] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [Fichier non signé]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-03-24] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [Fichier non signé]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-05-28] (Adobe Inc. -> Adobe Systems Inc.)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default [2021-07-08]
CHR HomePage: Default -> hxxp://www.google.fr/ig
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxps://www.google.fr/"
CHR NewTab: Default -> Active:"chrome-extension://eedlgdlajadkbbjoobobefphmfkcchfk/newtab.html"
CHR Extension: (Slides) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-09]
CHR Extension: (Docs) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-09]
CHR Extension: (Google Drive) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (YouTube) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-09]
CHR Extension: (Logitech Smooth Scrolling) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2017-12-09]
CHR Extension: (Ecosia Search) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\eedlgdlajadkbbjoobobefphmfkcchfk [2021-05-21]
CHR Extension: (Adobe Acrobat) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-06-20]
CHR Extension: (Sheets) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-09]
CHR Extension: (Extension Trusted Shops pour Google Chrome) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcpnemckonbbmnoakbjgjkgokkbaeo [2021-01-28]
CHR Extension: (Google Docs hors connexion) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-06-25]
CHR Extension: (AdBlock — le meilleur bloqueur de pubs) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2021-06-23]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-07-08]
CHR Extension: (Video DownloadHelper) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2021-07-01]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-29]
CHR Extension: (Gmail) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Extension: (Chrome Media Router) - C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-06-04]
CHR Profile: C:\Users\maurice\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-09-18]
CHR Profile: C:\Users\maurice\AppData\Local\Google\Chrome\User Data\System Profile [2020-11-20]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

==================== Services (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 Backupper Service; C:\Program Files (x86)\AOMEI\AOMEI Backupper 6.0.0\ABService.exe [898216 2020-09-07] (AOMEI International Network Limited -> AOMEI International Network Limited)
R2 Becca Service; C:\Program Files (x86)\Rene.E Laboratory\Becca\x64\bcservice.exe [86448 2020-09-22] (Jiangmen Ruili Software Co., Ltd. -> Rene.E Laboratory)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9056656 2021-06-28] (Microsoft Corporation -> Microsoft Corporation)
R3 eXpert PDF 12; C:\Program Files\eXpert PDF 12\ws.exe [2006248 2018-12-12] (Avanquest UK Ltd -> Avanquest Software)
R2 eXpert PDF 12 Creator; C:\Program Files\eXpert PDF 12\creator\common\creator-ws.exe [756968 2018-12-12] (Avanquest UK Ltd -> Avanquest Software)
R2 eXpert PDF 12 Manager; C:\Program Files (x86)\eXpert PDF 12 Manager\eXpert PDF 12\eXpert Manager.exe [1253736 2018-06-27] (Avanquest UK Ltd -> Avanquest Software)
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [Fichier non signé]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7462200 2021-07-05] (Malwarebytes Inc -> Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Fichier non signé]
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Fichier non signé]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5393304 2021-06-16] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ss_conn_launcher_service; C:\WINDOWS\System32\Samsung\EasySetup\ss_conn_launcher.exe [182128 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13172752 2020-01-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 VIAKaraokeService; C:\WINDOWS\system32\viakaraokesrv.exe [41952 2016-10-27] (VIA Technologies, Inc -> VIA Technologies, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\NisSrv.exe [2644776 2021-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2105.5-0\MsMpEng.exe [136656 2021-06-13] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Pilotes (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R0 ambakdrv; C:\WINDOWS\System32\ambakdrv.sys [51120 2016-12-21] (CHENGDU AOMEI Tech Co., Ltd. -> )
R2 ammntdrv; C:\WINDOWS\system32\ammntdrv.sys [171952 2016-12-21] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 ampa; C:\WINDOWS\system32\ampa.sys [38320 2017-02-28] (CHENGDU AOMEI Tech Co., Ltd. -> )
R2 amwrtdrv; C:\WINDOWS\system32\amwrtdrv.sys [38320 2017-09-01] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Fichier non signé]
S3 ddmdrv; C:\WINDOWS\system32\ddmdrv.sys [35760 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [199128 2021-04-07] (Malwarebytes Inc -> Malwarebytes)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220752 2021-07-05] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-12-23] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [198888 2021-07-08] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [69016 2021-07-08] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-06-22] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [156880 2021-07-08] (Malwarebytes Inc -> Malwarebytes)
R0 mvs91xx; C:\WINDOWS\System32\drivers\mvs91xx.sys [342760 2016-04-11] (Marvell Semiconductor, Inc. -> Marvell Semiconductor, Inc.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [43376 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49568 2021-06-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [425184 2021-06-13] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [76000 2021-06-13] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois (créés) (Avec liste blanche) =========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2021-07-08 21:00 - 2021-07-08 21:37 - 000000000 ____D C:\Users\maurice\Downloads\ilovepdf_extracted-pages
2021-07-08 20:57 - 2021-07-08 20:57 - 000428084 _____ C:\Users\maurice\Downloads\ilovepdf_merged (7).pdf
2021-07-08 20:55 - 2021-07-08 20:55 - 000142807 _____ C:\Users\maurice\Downloads\001_CT la réserve.pdf
2021-07-08 20:53 - 2021-07-08 20:53 - 002034758 _____ C:\Users\maurice\Downloads\CT la réserve.pdf
2021-07-08 20:51 - 2021-07-08 20:51 - 000275673 _____ C:\Users\maurice\Downloads\CT la réserve-7.pdf
2021-07-08 20:51 - 2021-07-08 20:51 - 000275673 _____ C:\Users\maurice\Downloads\CT la réserve-7 (1).pdf
2021-07-08 18:58 - 2021-07-08 18:58 - 000001538 ____C C:\Users\maurice\Desktop\MBAM.txt
2021-07-08 18:48 - 2021-07-08 18:48 - 000013890 ____C C:\Users\maurice\Desktop\ZHPCleaner (R).txt
2021-07-08 18:42 - 2021-07-08 19:23 - 000002355 ____C C:\Users\maurice\Desktop\ZHPCleaner (S).txt
2021-07-08 18:15 - 2021-07-08 18:15 - 003258008 _____ (Nicolas Coolman) C:\Users\maurice\Downloads\ZHPCleaner (1).exe
2021-07-08 18:06 - 2021-07-08 18:06 - 000198888 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2021-07-08 18:06 - 2021-07-08 18:06 - 000156880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2021-07-08 18:06 - 2021-07-08 18:06 - 000069016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2021-07-07 22:49 - 2021-07-07 22:49 - 000081805 ____C C:\Users\maurice\Desktop\Shortcut.txt
2021-07-07 22:48 - 2021-07-07 22:49 - 000051590 ____C C:\Users\maurice\Desktop\Addition.txt
2021-07-07 22:42 - 2021-07-08 22:25 - 000027608 ____C C:\Users\maurice\Desktop\FRST.txt
2021-07-07 22:42 - 2021-07-08 22:25 - 000000000 ____D C:\FRST
2021-07-07 22:40 - 2021-07-07 22:40 - 002301440 _____ (Farbar) C:\Users\maurice\Desktop\FRST64.exe
2021-07-07 22:31 - 2021-07-07 22:31 - 000380737 ____C C:\Users\maurice\Desktop\ZHPDiag.txt
2021-07-07 22:23 - 2021-07-07 22:23 - 003277976 _____ (Nicolas Coolman) C:\Users\maurice\ZHPDiag3.exe
2021-07-07 22:16 - 2021-07-07 22:17 - 019802736 _____ (Glarysoft Ltd) C:\Users\maurice\Downloads\gup5setup (4).exe
2021-07-05 23:53 - 2021-07-05 23:53 - 000220752 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2021-07-05 07:04 - 2021-07-05 07:04 - 000035473 _____ C:\Users\maurice\Downloads\comptes (16).xlsm
2021-07-04 09:07 - 2021-07-08 19:23 - 000008938 ____C C:\Users\maurice\Desktop\ZHPCleaner (S).html
2021-07-03 14:57 - 2021-07-03 14:57 - 000012887 _____ C:\Users\maurice\Downloads\export-1-01_05_2021-03_07_2021.xlsx
2021-07-03 14:31 - 2021-07-03 14:31 - 000014077 _____ C:\Users\maurice\Downloads\export-2-01_05_2021-03_07_2021.xlsx
2021-07-03 13:24 - 2021-07-07 22:23 - 000000726 ____C C:\Users\maurice\Desktop\ZHPDiag.lnk
2021-07-03 13:24 - 2021-07-03 13:24 - 003277976 _____ (Nicolas Coolman) C:\Users\maurice\Downloads\ZHPDiag3.exe
2021-07-03 13:05 - 2021-07-03 13:05 - 003258008 _____ (Nicolas Coolman) C:\Users\maurice\ZHPCleaner.exe
2021-07-02 19:42 - 2021-07-02 19:42 - 008553680 _____ (Malwarebytes) C:\Users\maurice\Downloads\adwcleaner_8.3.0.exe
2021-06-24 20:59 - 2021-06-24 21:06 - 180361280 _____ (SUPERAntiSpyware) C:\Users\maurice\Downloads\SUPERAntiSpyware.exe
2021-06-22 21:12 - 2021-06-22 21:12 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-06-20 10:46 - 2021-07-08 19:23 - 000000000 ____D C:\Users\maurice\AppData\Roaming\ZHP
2021-06-20 10:46 - 2021-07-08 18:18 - 000000877 ____C C:\Users\maurice\Desktop\ZHPCleaner.lnk
2021-06-20 10:46 - 2021-07-03 13:24 - 000000000 ____D C:\Users\maurice\AppData\Local\ZHP
2021-06-20 10:46 - 2021-06-20 10:44 - 003257496 ____C (Nicolas Coolman) C:\Users\maurice\Desktop\ZHPCleaner.exe
2021-06-20 10:43 - 2021-06-20 10:44 - 003257496 _____ (Nicolas Coolman) C:\Users\maurice\Downloads\ZHPCleaner.exe
2021-06-19 21:35 - 2021-06-19 21:35 - 000050829 _____ C:\Users\maurice\Downloads\cut-organism-155337-479580 (1).pdf
2021-06-18 07:20 - 2021-06-18 07:20 - 000114419 _____ C:\Users\maurice\Downloads\INV87300600.pdf
2021-06-16 12:48 - 2021-06-16 12:48 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-06-16 12:48 - 2021-06-16 12:48 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-06-16 12:48 - 2021-06-16 12:48 - 001864192 _____ (The ICU Project) C:\WINDOWS\SysWOW64\icu.dll
2021-06-16 12:48 - 2021-06-16 12:48 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-06-16 12:48 - 2021-06-16 12:48 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2021-06-16 12:48 - 2021-06-16 12:48 - 000468440 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2021-06-16 12:48 - 2021-06-16 12:48 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2021-06-16 12:48 - 2021-06-16 12:48 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-06-16 12:48 - 2021-06-16 12:48 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-06-16 12:48 - 2021-06-16 12:48 - 000011353 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-06-16 12:47 - 2021-06-16 12:47 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2021-06-16 12:47 - 2021-06-16 12:47 - 001823792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-06-16 12:47 - 2021-06-16 12:47 - 001393496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-06-16 12:47 - 2021-06-16 12:47 - 000657464 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2021-06-16 12:47 - 2021-06-16 12:47 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-06-16 12:47 - 2021-06-16 12:47 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2021-06-16 12:47 - 2021-06-16 12:47 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-06-16 12:47 - 2021-06-16 12:47 - 000097280 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-06-14 22:22 - 2021-06-14 22:22 - 000050829 _____ C:\Users\maurice\Downloads\cut-organism-155337-479580.pdf
2021-06-09 23:17 - 2021-06-09 23:18 - 002463134 _____ C:\Users\maurice\Downloads\2021-06-ACP-TCS-39.zip
2021-06-08 22:35 - 2021-06-08 22:35 - 000257199 _____ C:\Users\maurice\Downloads\020621-Bulletin-Epidemiologique-_draft-flyer-publication.pdf

==================== Un mois (modifiés) ==================

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2021-07-08 22:08 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-07-08 21:24 - 2020-09-29 15:14 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-07-08 19:52 - 2017-12-10 10:46 - 000000000 ___DC C:\Users\maurice\AppData\Local\Packages
2021-07-08 19:13 - 2019-12-07 11:12 - 000000000 ____D C:\WINDOWS\INF
2021-07-08 18:39 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-07-08 18:39 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-07-08 18:12 - 2020-09-29 15:27 - 001681374 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-07-08 18:12 - 2019-12-07 16:50 - 000755342 _____ C:\WINDOWS\system32\perfh00C.dat
2021-07-08 18:12 - 2019-12-07 16:50 - 000142148 _____ C:\WINDOWS\system32\perfc00C.dat
2021-07-08 18:08 - 2017-12-09 14:36 - 000000000 ____D C:\ProgramData\NVIDIA
2021-07-08 18:06 - 2020-09-23 00:18 - 000000208 _____ C:\WINDOWS\SysWOW64\AbBakConfig.dat
2021-07-08 18:06 - 2020-09-22 23:51 - 000000150 _____ C:\WINDOWS\SysWOW64\winsevr.dat
2021-07-08 18:06 - 2019-01-23 14:58 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-07-08 18:06 - 2017-12-09 11:59 - 000000000 ___RD C:\Users\maurice\OneDrive
2021-07-08 18:05 - 2020-09-29 15:25 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-07-08 18:05 - 2020-09-29 15:14 - 000008192 ___SH C:\DumpStack.log.tmp
2021-07-08 13:00 - 2019-12-07 11:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-07-08 13:00 - 2018-06-07 07:53 - 000000000 ____D C:\ProgramData\GlarySoft
2021-07-08 13:00 - 2018-03-07 23:53 - 000000000 ___DC C:\Users\maurice\AppData\Roaming\GlarySoft
2021-07-08 12:54 - 2020-09-18 18:11 - 000000000 ___DC C:\Users\maurice\AppData\LocalLow\Mozilla
2021-07-07 22:23 - 2020-09-29 15:18 - 000000000 ____D C:\Users\maurice
2021-07-07 22:20 - 2021-05-26 20:34 - 000000000 ____D C:\WINDOWS\Minidump
2021-07-05 23:53 - 2020-07-31 13:24 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-07-05 23:53 - 2019-07-05 15:30 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2021-07-03 09:20 - 2017-12-11 17:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2021-07-03 09:07 - 2020-08-21 17:50 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-07-02 19:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-07-02 07:28 - 2019-11-27 10:25 - 000000000 ____D C:\Users\maurice\AppData\Local\CrashDumps
2021-07-01 19:25 - 2021-03-11 23:56 - 000002073 _____ C:\Users\Public\Desktop\Google Slides.lnk
2021-07-01 19:25 - 2021-03-11 23:56 - 000002071 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2021-07-01 19:25 - 2021-03-11 23:56 - 000002061 _____ C:\Users\Public\Desktop\Google Docs.lnk
2021-07-01 19:25 - 2021-03-11 23:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2021-07-01 19:16 - 2020-09-29 15:25 - 000003380 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-133066294-687466313-2902525667-1001
2021-07-01 19:16 - 2020-09-29 15:18 - 000002423 ____C C:\Users\maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-06-29 22:38 - 2020-09-29 15:25 - 000003634 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-06-29 22:38 - 2020-09-29 15:25 - 000003510 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-06-28 21:46 - 2019-10-11 18:24 - 000000000 ___DC C:\Users\maurice\Desktop\Captvty
2021-06-28 18:10 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-06-27 09:18 - 2019-05-15 13:10 - 000000000 ___DC C:\Users\maurice\Documents\Modèles Office personnalisés
2021-06-24 12:41 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-06-23 20:18 - 2020-05-20 23:12 - 000000000 ____D C:\Users\maurice\AppData\Roaming\Telegram Desktop
2021-06-21 22:27 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-06-21 22:25 - 2020-09-29 15:14 - 000442032 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-06-21 22:02 - 2019-12-07 16:53 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-06-21 22:02 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-06-20 23:46 - 2020-11-03 15:06 - 000000000 ____D C:\Users\maurice\AppData\Roaming\TeamViewer
2021-06-20 23:45 - 2019-04-03 13:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2021-06-19 22:32 - 2021-02-25 20:40 - 000000000 ____D C:\Users\maurice\AppData\Local\ElevatedDiagnostics
2021-06-19 08:48 - 2020-08-17 19:05 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-06-13 23:25 - 2018-02-13 23:06 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-06-10 23:32 - 2017-12-10 15:06 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-06-10 19:57 - 2017-12-09 20:31 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-06-10 19:54 - 2017-12-09 20:31 - 132447432 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

==================== Fichiers à la racine de certains dossiers ========

2021-07-03 13:05 - 2021-07-03 13:05 - 003258008 _____ (Nicolas Coolman) C:\Users\maurice\ZHPCleaner.exe
2021-07-07 22:23 - 2021-07-07 22:23 - 003277976 _____ (Nicolas Coolman) C:\Users\maurice\ZHPDiag3.exe
2019-01-23 12:12 - 2019-01-24 17:07 - 000022970 ____C () C:\Users\maurice\AppData\Roaming\Valeurs séparées par une virgule (DOS).ADR
2019-01-23 12:16 - 2019-01-23 13:57 - 000021911 ____C () C:\Users\maurice\AppData\Roaming\Valeurs séparées par une virgule (Windows).ADR
2020-01-29 23:07 - 2021-01-23 15:39 - 000031729 _____ () C:\Users\maurice\AppData\Roaming\Valeurs séparées par une virgule.ADR
2019-05-04 18:57 - 2019-05-04 18:57 - 000000017 ____C () C:\Users\maurice\AppData\Local\resmon.resmoncfg
2019-04-03 13:05 - 2019-04-03 13:05 - 000000003 ____C () C:\Users\maurice\AppData\Local\updater.log
2019-04-03 13:05 - 2019-04-03 13:05 - 000000425 ____C () C:\Users\maurice\AppData\Local\UserProducts.xml
2018-01-14 16:58 - 2018-01-14 16:59 - 000000000 ____C () C:\Users\maurice\AppData\Local\{47D0B457-3E85-48C2-B115-A0CEC786ECCB}

==================== SigCheckExt =========================

2010-07-23 10:55 - 2010-07-23 10:55 - 000032768 _____ (Hewlett-Packard Company) C:\WINDOWS\system32\hpbmiapi.dll
2010-07-23 10:55 - 2010-07-23 10:55 - 000033280 _____ (Hewlett-Packard Company) C:\WINDOWS\system32\hpboid.dll
2010-07-23 10:55 - 2010-07-23 10:55 - 000009216 _____ (Hewlett-Packard Company) C:\WINDOWS\system32\hpboidps.dll
2010-07-23 10:55 - 2010-07-23 10:55 - 000057344 _____ (Hewlett-Packard Company) C:\WINDOWS\system32\hpbpro.dll
2010-07-23 10:55 - 2010-07-23 10:55 - 000009728 _____ (Hewlett-Packard Company) C:\WINDOWS\system32\hpbprops.dll
2010-01-19 16:12 - 2010-01-19 16:12 - 000070144 _____ (Hewlett-Packard) C:\WINDOWS\system32\HPBWSDR.DLL
2009-11-27 13:15 - 2009-11-27 13:15 - 000228864 _____ (hp) C:\WINDOWS\system32\hplbddrv.dll
2010-08-06 12:15 - 2010-08-06 12:15 - 000079872 _____ (Hewlett-Packard) C:\WINDOWS\system32\HPZidr12.dll
2010-08-06 12:15 - 2010-08-06 12:15 - 000071680 _____ (Hewlett-Packard) C:\WINDOWS\system32\HPZinw12.dll
2010-08-06 12:15 - 2010-08-06 12:15 - 000089600 _____ (Hewlett-Packard) C:\WINDOWS\system32\HPZipm12.dll
2010-08-06 12:15 - 2010-08-06 12:15 - 000054784 _____ (Hewlett-Packard) C:\WINDOWS\system32\HPZipr12.dll
2010-08-06 12:15 - 2010-08-06 12:15 - 000045056 _____ (Hewlett-Packard) C:\WINDOWS\system32\hpzipt12.dll
2010-08-06 12:15 - 2010-08-06 12:15 - 000030208 _____ (Hewlett-Packard) C:\WINDOWS\system32\hpzisn12.dll
2018-07-31 16:45 - 2010-12-06 04:16 - 000090112 _____ (Vestris Inc.) C:\WINDOWS\system32\Vestris.ResourceLib.dll
2020-09-23 09:00 - 2016-09-29 09:44 - 001298584 _____ C:\WINDOWS\ddmmain.exe
2010-08-06 12:13 - 2010-08-06 12:13 - 000050688 _____ (Hewlett-Packard) C:\WINDOWS\SysWOW64\HPZidr12.dll
2010-08-06 12:13 - 2010-08-06 12:13 - 000034816 _____ (Hewlett-Packard) C:\WINDOWS\SysWOW64\HPZipr12.dll
2020-04-18 11:03 - 2004-12-10 09:47 - 000184320 _____ (MAGIX AG) C:\WINDOWS\SysWOW64\mgxoschk.dll
2011-04-29 13:27 - 2011-04-29 13:27 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp71.dll
2011-04-29 18:01 - 2011-04-29 18:01 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr71.dll
2011-04-29 10:04 - 2011-04-29 10:04 - 001230336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4.dll
2011-04-29 10:04 - 2011-04-29 10:04 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4r.dll
2021-07-03 13:05 - 2021-07-03 13:05 - 003258008 _____ (Nicolas Coolman) C:\Users\maurice\ZHPCleaner.exe
2021-07-07 22:23 - 2021-07-07 22:23 - 003277976 _____ (Nicolas Coolman) C:\Users\maurice\ZHPDiag3.exe
2021-07-07 22:40 - 2021-07-07 22:40 - 002301440 _____ (Farbar) C:\Users\maurice\Desktop\FRST64.exe
2021-06-20 10:46 - 2021-06-20 10:44 - 003257496 ____C (Nicolas Coolman) C:\Users\maurice\Desktop\ZHPCleaner.exe
2020-11-16 18:14 - 2020-11-16 18:15 - 011032672 _____ (Oleg N. Scherbakov) C:\Users\maurice\Downloads\captvty-2.8.10.1-autoextract.exe
2019-11-25 17:30 - 2019-11-25 17:31 - 011023338 _____ (Oleg N. Scherbakov) C:\Users\maurice\Downloads\captvty-2.8.5.1-autoextract.exe
2019-12-25 12:41 - 2019-12-25 12:41 - 011021789 _____ (Oleg N. Scherbakov) C:\Users\maurice\Downloads\captvty-2.8.6.2-autoextract.exe
2020-04-30 14:48 - 2020-04-30 14:48 - 011032667 _____ (Oleg N. Scherbakov) C:\Users\maurice\Downloads\captvty-2.8.8.1-autoextract.exe
2020-09-17 17:07 - 2020-09-17 17:08 - 011036161 _____ (Oleg N. Scherbakov) C:\Users\maurice\Downloads\captvty-2.8.9.1-autoextract.exe
2021-02-27 00:03 - 2021-02-27 00:05 - 047599634 _____ (Oleg N. Scherbakov) C:\Users\maurice\Downloads\captvty-2.9.2.1-autoextract.exe
2020-12-20 11:08 - 2020-12-20 11:08 - 002286592 _____ (Farbar) C:\Users\maurice\Downloads\FRSTEnglish.exe
2021-07-08 18:15 - 2021-07-08 18:15 - 003258008 _____ (Nicolas Coolman) C:\Users\maurice\Downloads\ZHPCleaner (1).exe
2021-06-20 10:43 - 2021-06-20 10:44 - 003257496 _____ (Nicolas Coolman) C:\Users\maurice\Downloads\ZHPCleaner.exe
2021-07-03 13:24 - 2021-07-03 13:24 - 003277976 _____ (Nicolas Coolman) C:\Users\maurice\Downloads\ZHPDiag3.exe

==================== SigCheck ============================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)


==================== BCD ================================

Gestionnaire de d‚marrage Windows
---------------------------------
identificateur {bootmgr}
device partition=\Device\HarddiskVolume5
description Windows Boot Manager
locale fr-FR
inherit {globalsettings}
default {current}
resumeobject {fbf41af1-025d-11eb-83f9-875e204ebfb6}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30

Chargeur de d‚marrage Windows
-----------------------------
identificateur {a8e733c8-b36e-11e9-b706-d96b6ed92c3a}
device ramdisk=[unknown]\Recovery\WindowsRE\Winre.wim,{a8e733c9-b36e-11e9-b706-d96b6ed92c3a}
path \windows\system32\winload.exe
description Windows Recovery Environment
locale fr-FR
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[unknown]\Recovery\WindowsRE\Winre.wim,{a8e733c9-b36e-11e9-b706-d96b6ed92c3a}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes

Chargeur de d‚marrage Windows
-----------------------------
identificateur {ca8ce529-0255-11eb-9dc8-d5534eebab56}
device ramdisk=[\Device\HarddiskVolume7]\Recovery\WindowsRE\Winre.wim,{ca8ce52a-0255-11eb-9dc8-d5534eebab56}
path \windows\system32\winload.exe
description Windows Recovery Environment
locale fr-FR
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[\Device\HarddiskVolume7]\Recovery\WindowsRE\Winre.wim,{ca8ce52a-0255-11eb-9dc8-d5534eebab56}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes

Chargeur de d‚marrage Windows
-----------------------------
identificateur {current}
device partition=C:
path \WINDOWS\system32\winload.exe
description Windows 10
locale fr-FR
inherit {bootloadersettings}
recoverysequence {ca8ce529-0255-11eb-9dc8-d5534eebab56}
displaymessageoverride Recovery
recoveryenabled Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \WINDOWS
resumeobject {fbf41af1-025d-11eb-83f9-875e204ebfb6}
nx OptIn
bootmenupolicy Standard

Reprendre … partir de la mise en veille prolong‚e
-------------------------------------------------
identificateur {fbf41af1-025d-11eb-83f9-875e204ebfb6}
device partition=C:
path \WINDOWS\system32\winresume.exe
description Windows Resume Application
locale fr-FR
inherit {resumeloadersettings}
recoverysequence {ca8ce529-0255-11eb-9dc8-d5534eebab56}
recoveryenabled Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No

Testeur de m‚moire Windows
--------------------------
identificateur {memdiag}
device partition=\Device\HarddiskVolume5
path \boot\memtest.exe
description Diagnostics m‚moire Windows
locale fr-FR
inherit {globalsettings}
badmemoryaccess Yes

ParamŠtres EMS
--------------
identificateur {emssettings}
bootems No

ParamŠtres du d‚bogueur
-----------------------
identificateur {dbgsettings}
debugtype Local

Erreurs de m‚moire RAM
----------------------
identificateur {badmemory}

ParamŠtres globaux
------------------
identificateur {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}

ParamŠtres du chargeur de d‚marrage
-----------------------------------
identificateur {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}

ParamŠtres de l'hyperviseur
-------------------
identificateur {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200

ParamŠtres du chargeur de reprise
---------------------------------
identificateur {resumeloadersettings}
inherit {globalsettings}

Options de p‚riph‚rique
-----------------------
identificateur {a8e733c9-b36e-11e9-b706-d96b6ed92c3a}
description Windows Recovery
ramdisksdidevice unknown
ramdisksdipath \Recovery\WindowsRE\boot.sdi

Options de p‚riph‚rique
-----------------------
identificateur {ca8ce52a-0255-11eb-9dc8-d5534eebab56}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume7
ramdisksdipath \Recovery\WindowsRE\boot.sdi

==================== Fin de FRST.txt ========================

Publicité


Signaler le contenu de ce document

Publicité