Résultats de correction de Farbar Recovery Scan Tool (x64) Version: 06-12-2020 Exécuté par harry (09-12-2020 10:37:29) Run:3 Exécuté depuis C:\Users\harry\Desktop Profils chargés: harry Mode d'amorçage: Normal ============================================== fixlist contenu: ***************** CloseProcesses: DeleteValue: HKU\S-1-5-21-1417548909-3079596742-2592710102-1001\\Software\Microsoft\Windows\CurrentVersion\Run|E341CF1DBA1CD7DA51BD48992DE9557A1C566426._service_run] DeleteKey: HKLM\SOFTWARE\WOW6432Node\McAfee DeleteKey: HKLM\SOFTWARE\WOW6432Node\McAfee NGI DeleteKey: HKLM\SOFTWARE\WOW6432Node\TeamViewer DeleteKey: HKLM\SOFTWARE\WOW6432Node\webroot DeleteKey: HKU\.DEFAULT\SOFTWARE\McAfee DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|E341CF1DBA1CD7DA51BD48992DE9557A1C566426._service_run DeleteValue: HKEY_USERS\S-1-5-21-1417548909-3079596742-2592710102-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|E341CF1DBA1CD7DA51BD48992DE9557A1C566426._service_run C:\Program Files\mcafee C:\Program Files (x86)\McAfee Task: {309E3EF8-8C76-4B15-8BA2-267A6707F7A7} - System32\Tasks\WpsKtpcntrQingTask_Administrator => C:\Program Files (x86)\Kingsoft\WPS Office\10.1.0.5644\office6\ktpcntr.exe [1531136 2016-11-11] (Zhuhai Kingsoft Office Software Co.,Ltd -> Zhuhai Kingsoft Office Software Co.,Ltd) Task: {E39B04FB-3166-494E-B519-06F60D7B1BBC} - System32\Tasks\WpsExternal_20161111081738 => C:\Program Files (x86)\Kingsoft\WPS Office\ksolaunch.exe [516352 2016-11-11] (Zhuhai Kingsoft Office Software Co.,Ltd -> Zhuhai Kingsoft Office Software Co.,Ltd) Task: {F1A3EF0A-DBE2-41D9-8539-FBD3CDF7407E} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144736 2020-11-21] (Microsoft Corporation -> Microsoft Corporation) Task: C:\WINDOWS\Tasks\WpsExternal_20161111081738.job => C:\Program Files (x86)\Kingsoft\WPS Office\ksolaunch.exe Task: C:\WINDOWS\Tasks\WpsKtpcntrQingTask_Administrator.job => C:\Program Files (x86)\Kingsoft\WPS Office\10.1.0.5644\office6\ktpcntr.exeÃqing 10.1.0.5644 xxx server_url=hxxp:/kdl1.cache.wps.com/ksodl/wpscfg/client/____client____html____service____bubble.html ic_server_url=hxxp:/info.kingsoftstore.com/wpsv6internet/infos.ads 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin 2020-11-15 18:40 - 2020-11-15 18:40 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2018-11-12 19:52 - 2020-12-09 05:36 - 000000182 _____ () C:\Users\harry\AppData\Roaming\sp_data.sys EmptyTemp: ***************** Processus fermé avec succès. "HKU\S-1-5-21-1417548909-3079596742-2592710102-1001\\Software\Microsoft\Windows\CurrentVersion\Run\\E341CF1DBA1CD7DA51BD48992DE9557A1C566426._service_run]" => non trouvé(e) HKLM\SOFTWARE\WOW6432Node\McAfee => non trouvé(e) HKLM\SOFTWARE\WOW6432Node\McAfee NGI => non trouvé(e) HKLM\SOFTWARE\WOW6432Node\TeamViewer => non trouvé(e) HKLM\SOFTWARE\WOW6432Node\webroot => non trouvé(e) HKU\.DEFAULT\SOFTWARE\McAfee => non trouvé(e) "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\E341CF1DBA1CD7DA51BD48992DE9557A1C566426._service_run" => non trouvé(e) "HKEY_USERS\S-1-5-21-1417548909-3079596742-2592710102-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\E341CF1DBA1CD7DA51BD48992DE9557A1C566426._service_run" => non trouvé(e) "C:\Program Files\mcafee" => non trouvé(e) "C:\Program Files (x86)\McAfee" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{309E3EF8-8C76-4B15-8BA2-267A6707F7A7}" => non trouvé(e) "C:\WINDOWS\System32\Tasks\WpsKtpcntrQingTask_Administrator" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WpsKtpcntrQingTask_Administrator" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E39B04FB-3166-494E-B519-06F60D7B1BBC}" => non trouvé(e) "C:\WINDOWS\System32\Tasks\WpsExternal_20161111081738" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WpsExternal_20161111081738" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F1A3EF0A-DBE2-41D9-8539-FBD3CDF7407E}" => non trouvé(e) "C:\WINDOWS\System32\Tasks\Microsoft\Office\Office Feature Updates Logon" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Office\Office Feature Updates Logon" => non trouvé(e) "C:\WINDOWS\Tasks\WpsExternal_20161111081738.job" => non trouvé(e) "C:\WINDOWS\Tasks\WpsKtpcntrQingTask_Administrator.job" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth9.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth8.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth7.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth6.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth5.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth4.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth3.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth2.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth12.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth11.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth10.bin" => non trouvé(e) "C:\WINDOWS\system32\DrtmAuth1.bin" => non trouvé(e) C:\Users\harry\AppData\Roaming\sp_data.sys => déplacé(es) avec succès =========== EmptyTemp: ========== BITS transfer queue => 7888896 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8500622 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 276262 B Edge => 0 B Chrome => 0 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 0 B NetworkService => 5652 B harry => 29431 B RecycleBin => 0 B EmptyTemp: => 15.9 MB données temporaires supprimées. ================================ Le système a dû redémarrer. ==== Fin de Fixlog 10:37:46 ====