Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 06-10-2023 Exécuté par battj (administrateur) sur DESKTOP-56Q7FG9 (LENOVO 81Q4) (16-10-2023 00:01:08) Exécuté depuis C:\Users\battj\Downloads\FRST64.exe Profils chargés: battj & SQLTELEMETRY$SQLTOPSOLID Plate-forme: Microsoft Windows 11 Professionnel Version 22H2 22621.2428 (X64) Langue: Français (France) Navigateur par défaut: Chrome Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusService.exe ->) (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusClient.exe (C:\Program Files\Shadow\ShadowUSB-2.1.3\ShadowUSB.exe ->) () [Fichier non signé] C:\Program Files\Shadow\ShadowUSB-2.1.3\crashpad_handler.exe (dolbyaposvc\DAX3API.exe ->) (Dolby Laboratories, Inc. -> ) C:\Program Files\Common Files\Dolby\DAX3\RADARHOST\DSRHost.exe (DriverStore\FileRepository\dptf_cpu.inf_amd64_1da48d5885266bb7\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_1da48d5885266bb7\dptf_helper.exe (explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <48> (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5> (Nvidia Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (services.exe ->) () [Fichier non signé] C:\Program Files (x86)\Wondershare\Wondershare dr.fone (CPC)\Addins\SocialApps\ElevationService.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (services.exe ->) (AVerMedia TECHNOLOGIES, INC. -> AVerMedia TECHNOLOGIES, Inc.) C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe (services.exe ->) (Blade -> Electronic Team) C:\Users\battj\AppData\Local\Programs\shadow\resources\app.asar.unpacked\release\native\eltima10\service\UsbService64.exe (services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe (services.exe ->) (Datronicsoft Inc. -> ) C:\Windows\System32\spacedeskService.exe (services.exe ->) (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusService.exe (services.exe ->) (Dolby Laboratories, Inc. -> ) C:\Windows\System32\dolbyaposvc\DAX3API.exe <2> (services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_1da48d5885266bb7\esif_uf.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe (services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0b214be229a13e84\jhi_service.exe (services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_fc9ac11e55f51133\RstMwService.exe (services.exe ->) (Lenovo -> ) C:\Program Files (x86)\Lenovo\System Update\SUService.exe (services.exe ->) (Logitech Inc -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft GameInput\x64\gameinputsvc.exe <2> (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.SQLTOPSOLID\MSSQL\Binn\sqlceip.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL15.SQLTOPSOLID\MSSQL\Binn\sqlservr.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe (services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2> (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvltsi.inf_amd64_81b761923f254c78\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (O&O Software GmbH) [Fichier non signé] C:\ProgramData\FileOptimizer\FileOptimizer.exe (services.exe ->) (philandro Software GmbH -> AnyDesk Software GmbH) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2> (services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (services.exe ->) (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe (services.exe ->) (Segurazo Security -> DlGlTAL COMMUNICATIONS INC) [Fichier non signé] C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusWD.exe (services.exe ->) (Shadow -> Shadow) C:\Program Files\Shadow\ShadowUSB-2.1.3\ShadowUSB.exe (services.exe ->) (SplitmediaLabs Limited -> SplitmediaLabs Limited) C:\Program Files\XSplit\VCam\service\XSpltVidSvc.exe (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe (services.exe ->) (TGMDev) [Fichier non signé] C:\ProgramData\DiskOptimizer\DiskOptimizer.exe (services.exe ->) (wondershare) [Fichier non signé] C:\Program Files (x86)\Wondershare\Wondershare dr.fone (CPC)\WsidService.exe (services.exe ->) (Wondershare) [Fichier non signé] C:\ProgramData\Wondershare\Service\InstallAssistService.exe (spacedeskService.exe ->) (Datronicsoft Inc. -> datronicsoft) C:\Windows\System32\spacedeskServiceTray.exe (svchost.exe ->) (AutoIt Consulting Ltd -> AutoIt Team) C:\Users\battj\AppData\Roaming\kipeua\corsve.exe (svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CastSrv.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [1076728 2020-03-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [PentabletService] => C:\Program Files\Pentablet\PentabletService.exe [2243736 2021-01-11] (Guangzhou Ugee Computers Technology Co.,Ltd -> Ugee Technology Company Ltd) HKLM\...\Run: [PAC207_Monitor] => C:\WINDOWS\PixArt\PAC207\Monitor.exe [323584 2007-12-10] (Microsoft Windows Hardware Compatibility Publisher -> PixArt Imaging Incorporation) HKLM\...\Run: [Monitor] => C:\WINDOWS\PixArt\PAC207\Monitor.exe [323584 2007-12-10] (Microsoft Windows Hardware Compatibility Publisher -> PixArt Imaging Incorporation) HKLM\...\Run: [Stream Deck] => C:\Program Files\Elgato\StreamDeck\StreamDeck.exe [11144232 2022-09-29] (Corsair Memory, Inc. -> Corsair Memory, Inc) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [18725336 2022-05-12] (Logitech Inc -> Logitech Inc.) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech -> Logitech Inc.) HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [129288 2021-01-25] (Adobe Inc. -> ) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [711288 2023-01-09] (Oracle America, Inc. -> Oracle Corporation) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restriction <==== ATTENTION HKU\S-1-5-21-36739671-87360890-1428175875-1001\...\Run: [SIMDashboardServer] => C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe [7606248 2023-06-12] (Christian Hausmann -> stryder-it) HKU\S-1-5-21-36739671-87360890-1428175875-1001\...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe [70913464 2023-10-09] (Riot Games, Inc. -> Riot Games, Inc.) HKU\S-1-5-21-36739671-87360890-1428175875-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [2655848 2023-10-11] (Electronic Arts, Inc. -> Electronic Arts) HKU\S-1-5-21-36739671-87360890-1428175875-1001\...\Run: [MicrosoftEdgeAutoLaunch_E419D7F4FFC5054F9E30C18AD0D4D57E] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4131264 2023-10-13] (Microsoft Corporation -> Microsoft Corporation) HKLM\...\Windows x64\Print Processors\Canon MG3500 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBV.DLL [30208 2013-04-04] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3500 series: C:\WINDOWS\system32\CNMLMBV.DLL [391168 2013-04-04] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3500 series XPS: C:\WINDOWS\system32\CNMXLMBV.DLL [394240 2013-04-04] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\EPSON XP-212 213 Series 64MonitorBE: C:\WINDOWS\system32\E_ILMBLHE.DLL [179712 2013-10-22] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION) HKLM\...\Print\Monitors\HP D711 Status Monitor: C:\WINDOWS\system32\hpinkstsD711LM.dll [393352 2017-03-27] (Hewlett Packard -> HP Inc.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\107.0.5304.123\Installer\chrmstp.exe [2022-11-30] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2021-12-01] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> AnyDesk Software GmbH) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAndroidAppHelper.lnk [2022-08-28] ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\Wondershare dr.fone (CPC)\Addins\SocialApps\WSAndroidAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAppHelper.lnk [2022-08-28] ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\Wondershare dr.fone (CPC)\Addins\SocialApps\WSAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft) Startup: C:\Users\battj\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Updater.exe [2023-02-11] (Node.js) [Fichier non signé] GroupPolicy: Restriction - Chrome <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION ==================== Tâches planifiées (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {B0974F9D-77A9-45AF-9FAA-ED6B06CE30AA} - System32\Tasks\AdvancedWindowsManager #1 => C:\Program Files (x86)\AW Manager\Windows Manager\AdvancedWindowsManager.exe -v 110 -t 8080 (Pas de fichier) <==== ATTENTION Task: {5187CF85-D885-417A-92C8-AE9E26BC3CFD} - System32\Tasks\AdvancedWindowsManager #2 => C:\Program Files (x86)\AW Manager\Windows Manager\AdvancedWindowsManager.exe -v 111 -t 8080 (Pas de fichier) <==== ATTENTION Task: {0759A854-58B1-4F28-8681-5D75B98DBA34} - System32\Tasks\AdvancedWindowsManager #3 => C:\Program Files (x86)\AW Manager\Windows Manager\AdvancedWindowsManager.exe -v 112 -t 8080 (Pas de fichier) <==== ATTENTION Task: {8651B2D8-C1CA-43E0-A9B3-8904CACEF1A5} - System32\Tasks\AdvancedWindowsManager #4 => C:\Program Files (x86)\AW Manager\Windows Manager\AdvancedWindowsManager.exe -v 113 -t 8080 (Pas de fichier) <==== ATTENTION Task: {8EA3A0E8-6C95-48D1-8CD2-C01600F0454D} - System32\Tasks\AdvancedWindowsManager #5 => C:\Program Files (x86)\AW Manager\Windows Manager\AdvancedWindowsManager.exe -v 114 -t 8080 (Pas de fichier) <==== ATTENTION Task: {9FB96970-C4AE-4231-9501-5117680868FE} - System32\Tasks\AdvancedWindowsManager #6 => C:\Program Files (x86)\AW Manager\Windows Manager\AdvancedWindowsManager.exe -v 115 -t 8080 (Pas de fichier) <==== ATTENTION Task: {8F13B4D3-7F2B-4430-9AD1-ACD086BE9D2E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [617096 2022-02-25] (Apple Inc. -> Apple Inc.) Task: {F4DC77CE-93E8-4D61-A3DE-8BDD74FA9C33} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe (Pas de fichier) Task: {23FE8650-0010-406B-BE20-9F9ED1409C18} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe --type=heartbeat --hourly (Pas de fichier) Task: {54D292BA-1A96-4B3D-8A51-2E940C9DCEFD} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe --type=heartbeat --logon (Pas de fichier) Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\AdvancedWindowsManager #1" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(10): schtasks.exe -> /Change /TN "\EPSON XP-212 213 Series Update {A1F63CE1-BDE5-4B45-8D6B-F5424337543D}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(11): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineCore" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(12): schtasks.exe -> /Change /TN "\GoogleUpdateTaskMachineUA" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(13): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(14): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineCore1d7bbcbb8dd095f" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(15): schtasks.exe -> /Change /TN "\MicrosoftEdgeUpdateTaskMachineUA" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(16): schtasks.exe -> /Change /TN "\Norton WSC Integration" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(17): schtasks.exe -> /Change /TN "\NortonCleanupTask" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(18): schtasks.exe -> /Change /TN "\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(19): schtasks.exe -> /Change /TN "\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\AdvancedWindowsManager #2" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(20): schtasks.exe -> /Change /TN "\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(21): schtasks.exe -> /Change /TN "\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(22): schtasks.exe -> /Change /TN "\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(23): schtasks.exe -> /Change /TN "\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(24): schtasks.exe -> /Change /TN "\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(25): schtasks.exe -> /Change /TN "\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(26): schtasks.exe -> /Change /TN "\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(27): schtasks.exe -> /Change /TN "\OneDrive Reporting Task-S-1-5-21-36739671-87360890-1428175875-1001" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(28): schtasks.exe -> /Change /TN "\OneDrive Standalone Update Task-S-1-5-21-36739671-87360890-1428175875-1001" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(29): schtasks.exe -> /Change /TN "\Opera scheduled assistant Autoupdate 1620851538" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\AdvancedWindowsManager #3" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(30): schtasks.exe -> /Change /TN "\Opera scheduled Autoupdate 1620851536" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(31): schtasks.exe -> /Change /TN "\Overwolf Updater Task" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(32): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\AdvancedWindowsManager #4" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(5): schtasks.exe -> /Change /TN "\AdvancedWindowsManager #5" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(6): schtasks.exe -> /Change /TN "\AdvancedWindowsManager #6" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(7): schtasks.exe -> /Change /TN "\CCleaner Update" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(8): schtasks.exe -> /Change /TN "\CCleanerSkipUAC - battj" /ENABLE Task: {434DAD92-3B20-4E58-B302-6DB55E595C9A} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(9): schtasks.exe -> /Change /TN "\EPSON XP-212 213 Series Invitation {A1F63CE1-BDE5-4B45-8D6B-F5424337543D}" /ENABLE Task: {320ADA7B-9EBB-45AE-BC92-4ECD99E6705D} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe /from_scheduler:1 (Pas de fichier) Task: {A915EF41-A855-4E9B-9C78-93DC1D6B67F0} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe /c (Pas de fichier) Task: {5DE2B94C-1A45-4F4A-B8E1-A4028D76169F} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe /ua /installsource scheduler (Pas de fichier) Task: {3AE78434-8192-4FB5-B849-D3D0552BCFB9} - System32\Tasks\Diagnostic\Service => C:\Users\battj\AppData\Roaming\kipeua\corsve.exe [893608 2022-10-11] (AutoIt Consulting Ltd -> AutoIt Team) -> "C:\Users\battj\AppData\Roaming\kipeua\corsve.dat" Task: {479EF234-E574-448C-8AE7-DA091603D634} - System32\Tasks\eLrbrmhzYfSdNwVFx2 => C:\WINDOWS\system32\rundll32.exe [73728 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> "C:\Program Files (x86)\jykPaGRYedLqSIhqEsR\mUDiqVc.dll",#1 <==== ATTENTION Task: {2F5FE707-422A-43B3-A1A6-D4912C4F2C9D} - System32\Tasks\eteindre => C:\WINDOWS\system32\shutdown.exe [53248 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> /s Task: {381DFAE9-583A-4B50-9CA6-C8FA46FA24B5} - System32\Tasks\eteindre0 => C:\WINDOWS\system32\shutdown.exe [53248 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> /s Task: {AE7482C8-C581-4B0A-AB9F-F0961DDA911A} - System32\Tasks\Eteindre2 => C:\WINDOWS\system32\shutdown.exe [53248 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> /s Task: {D44746D8-49DF-4DB8-BB3E-4A3A79A49D8A} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-36739671-87360890-1428175875-1001 => C:\Users\battj\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [89096 2023-04-10] (Lenovo (Beijing) Limited -> Lenovo Group Limited) Task: {DD7D6570-088F-447B-91F4-5D53D8C0B0D9} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26977976 2023-10-07] (Microsoft Corporation -> Microsoft Corporation) Task: {F54FE2B8-D403-4DB6-853D-0747EA4488F6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26977976 2023-10-07] (Microsoft Corporation -> Microsoft Corporation) Task: {37C0D332-DF2D-44C2-9BFE-5082B00E0162} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [160736 2023-10-13] (Microsoft Corporation -> Microsoft Corporation) Task: {4AE0D8F0-DB20-491A-8E59-DE3E680A6322} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [160736 2023-10-13] (Microsoft Corporation -> Microsoft Corporation) Task: {7FAB9A99-5327-4765-A950-4433415DAD06} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [169136 2023-10-03] (Microsoft Corporation -> Microsoft Corporation) Task: {E57AE3C1-22BB-426E-90EE-AB5C6E23B4CE} - System32\Tasks\Microsoft\VisualStudio\Updates\BackgroundDownload => C:\Program Files (x86)\Microsoft Visual Studio\Installer\resources\app\ServiceHub\Services\Microsoft.VisualStudio.Setup.Service\BackgroundDownload.exe [66480 2021-12-17] (Microsoft Corporation -> Microsoft) Task: {D4DD9708-80C0-4AB2-AC23-A590014FFCDC} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\UCPD velocity => C:\WINDOWS\system32\UCPDMgr.exe [58880 2023-09-13] (Microsoft Windows -> Microsoft Corporation) Task: {05A447AF-727C-4D71-AC2A-CB100CBEA312} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\Ogwbt => C:\WINDOWS\system32\rundll32.exe [73728 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> C:\Users\battj\AppData\Local\PresentFeatures\LaceSiee\CHBF2dohs_Sm200s.dll kbdijkft_ApqXSUJ Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (Pas de fichier) Task: {007E4BB3-4430-49D8-A59F-F0B5E1751A01} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => %systemroot%\system32\MusNotification.exe LogonUpdateResults (Pas de fichier) Task: {E050AEFA-565E-4456-B777-4B1B86D9F781} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (Pas de fichier) Task: {F4B1F36B-6F50-4237-A659-354D7C0677D1} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC Reboot (Pas de fichier) Task: {C2311749-2D78-42A0-B4F7-2DC11025E451} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery Reboot (Pas de fichier) Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Pas de fichier) Task: {5456DA87-50F9-4C0A-9180-4F209F30E0CF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-06] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {1444CBFD-44D1-48A0-9126-1DD03AFE5A18} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-06] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F2A6261B-812B-402A-80B3-BFC3B80E0647} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe [1596304 2023-10-06] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {E90E9A98-A449-4C97-A6AA-9B7B8C5DC771} - System32\Tasks\MpekihZbrkVPEIu2 => C:\WINDOWS\system32\rundll32.exe [73728 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> "C:\Program Files (x86)\WNQerUHUU\reKFgz.dll",#1 <==== ATTENTION Task: {D7C96A3F-AB52-4C01-8740-04B948C6BE81} - System32\Tasks\NDI Autorun => C:\Program Files\NDI\NDI 5 Tools\NDI Launcher.exe [617864 2023-04-10] (Newtek, Inc. -> NDI) Task: {C382EEA8-9C70-4FF2-840C-F6EAEA59D2E8} - System32\Tasks\NortonCleanupTask => "C:\Users\battj\Desktop\LoginImporter\utils\NortonCleanup.bat" (Pas de fichier) Task: {844807E3-2EAF-488D-825B-3B92A071F31D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [1003128 2022-03-15] (Nvidia Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log Task: {8BE29036-2F77-42AE-BB73-BC99574E9D5C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3342376 2023-01-27] (Nvidia Corporation -> NVIDIA Corporation) Task: {CF9AACC8-284B-4917-B2D5-507CDE8203DF} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [649784 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {D381D8C1-751A-4531-B6B5-5C868B2C695C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {CD7AAF20-854E-42B8-8611-9EAD56B42C02} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [910888 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {075EB88F-FEF3-4B76-89C7-514C42A4A46D} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {DC74E7F3-F35A-436E-B1D1-B3F859599794} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {81B80A0C-E877-4C17-ABE1-DE29C43B7968} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {FD978C61-8B28-4B05-9B2F-CA00CEA2D017} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1665064 2023-01-20] (NVIDIA Corporation -> NVIDIA Corporation) Task: {E5D0E2B8-3260-436F-99EF-97A743FD8CDB} - System32\Tasks\Opera scheduled assistant Autoupdate 1620851538 => C:\Users\battj\AppData\Local\Programs\Opera\launcher.exe -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\battj\AppData\Local\Programs\Opera\assistant" $(Arg0) Task: {CAE5C58D-F2D9-4DDB-9B68-E8914015E2DC} - System32\Tasks\Opera scheduled Autoupdate 1620851536 => C:\Users\battj\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (Pas de fichier) Task: {0F2FFBFA-2D61-465D-AF8B-1DA570A08DB5} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2641416 2023-10-03] (Overwolf Ltd -> Overwolf LTD) Task: {AA92011D-5B44-4973-97DB-6205664BF9B1} - System32\Tasks\Service\Diagnostic => "C:\Users\battj\AppData\Roaming\ServiceGet\Dimasev.exe" -> "C:\Users\battj\AppData\Roaming\ServiceGet\Dimasev.dat" <==== ATTENTION Task: {B9C7313D-8B4D-4120-AF3C-969BC5F3AA52} - System32\Tasks\SIMDB_75b6e096fc79c825286efd6614b8d0f4 => C:\Program Files (x86)\SIMDashboardServer\SIMDashboardServer.exe [7606248 2023-06-12] (Christian Hausmann -> stryder-it) Task: {2046C0C6-77CF-4493-8604-73B280933323} - System32\Tasks\sZbEqUpwGLSmG2 => C:\WINDOWS\system32\forfiles.exe -> /p C:\WINDOWS\system32 /m wscript.exe /c "cmd /C @FNAME ^"C:\ProgramData\GVzmTAMPMBigVtVB\RkVzcyG.wsf^"" Task: {30725205-3718-4F21-AB14-41A2CABF42CE} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1758648 2020-09-08] (Lenovo -> ) Task: {1270AF0E-37D5-436D-9E30-1B49A4D1D67C} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1758648 2020-09-08] (Lenovo -> ) Task: {D81B5AF2-D37F-41F5-A328-8196CAD88B00} - System32\Tasks\vxFBJgPOgoQTQXrBrGM2 => C:\WINDOWS\system32\rundll32.exe [73728 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> "C:\Program Files (x86)\qOWDSetpHctcC\aDJjRfy.dll",#1 <==== ATTENTION Task: {A3493836-F8E4-4080-B20A-A51EB9B9093E} - System32\Tasks\WnkFlydgrUNYLF => C:\WINDOWS\system32\rundll32.exe [73728 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> "C:\Program Files (x86)\OSMCyPkDFJmU2\FrHeHKVFtgYzo.dll",#1 <==== ATTENTION (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{30cf3ee6-035b-42cb-bcb6-dcda1b218c83}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{30cf3ee6-035b-42cb-bcb6-dcda1b218c83}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{3ca1e022-a4d8-4174-a4e5-3b738acc91ad}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{743147ad-94ea-41a7-b78c-854beff7884e}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{97ad42b3-e614-4a08-8c84-8a1cffa1b86e}: [DhcpNameServer] 192.168.99.79 Tcpip\..\Interfaces\{d568d44f-18c4-4b09-b90c-6baca42e7913}: [DhcpNameServer] 192.168.1.1 Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\battj\AppData\Local\Microsoft\Edge\User Data\Default [2023-10-15] Edge Notifications: Default -> hxxps://mystake.bet Edge Extension: (Google Access Offline) - C:\Users\battj\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fileepgfmlpabmkbocijoaggdmlhenbf [2023-10-15] [UpdateUrl:hxxps://clients87.google.com/service/update2/crx] <==== ATTENTION Edge Extension: (Google Docs hors connexion) - C:\Users\battj\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-09] Edge Extension: (Edge relevant text changes) - C:\Users\battj\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-10-09] Edge HKU\S-1-5-21-36739671-87360890-1428175875-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee] Edge HKLM-x32\...\Edge\Extension: [odbmjgikedenicicookngdckhkjbebpd] FireFox: ======== FF DefaultProfile: r6r1si60.default FF ProfilePath: C:\Users\battj\AppData\Roaming\Mozilla\Firefox\Profiles\r6r1si60.default [2022-12-01] FF SearchPlugin: C:\Users\battj\AppData\Roaming\Mozilla\Firefox\Profiles\r6r1si60.default\searchplugins\go-go.xml [2023-01-12] FF ProfilePath: C:\Users\battj\AppData\Roaming\Mozilla\Firefox\Profiles\29y0g6l7.default-release [2023-10-13] FF Homepage: Mozilla\Firefox\Profiles\29y0g6l7.default-release -> hxxps://find-it.pro/?utm_source=distr_m FF Notifications: Mozilla\Firefox\Profiles\29y0g6l7.default-release -> hxxps://mail-notification.info; hxxps://zarabotok-online.xyz; hxxps://supertopfreegames.com; hxxps://best-loan-info.com; hxxps://ccleaner-download.xyz; hxxps://pinghauz.xyz; hxxps://s-tracking.xyz; hxxps://mnthor.xyz FF Extension: (Disney+ Skipper) - C:\Users\battj\AppData\Roaming\Mozilla\Firefox\Profiles\29y0g6l7.default-release\Extensions\{19104dc2-8914-4300-95c6-00934a2e62a6}.xpi [2022-01-01] FF SearchPlugin: C:\Users\battj\AppData\Roaming\Mozilla\Firefox\Profiles\29y0g6l7.default-release\searchplugins\go-go.xml [2023-01-12] FF Extension: (Pas de nom) - C:\Program Files\Mozilla Firefox\browser\features\{DBDE73E2-BC5F-41AD-9E14-0105D4813C2F}.xpi [2023-01-26] [non signé] FF Plugin: @java.com/DTPlugin,version=11.361.2 -> C:\Program Files\Java\jre1.8.0_361\bin\dtplugin\npDeployJava1.dll [2023-01-09] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.361.2 -> C:\Program Files\Java\jre1.8.0_361\bin\plugin2\npjp2.dll [2023-01-09] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-08-04] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [Fichier non signé] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2023-08-04] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-10-03] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN) FF Plugin HKU\S-1-5-21-36739671-87360890-1428175875-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\battj\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2017-05-18] (Unity Technologies SF -> Unity Technologies ApS) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default [2023-10-16] CHR Notifications: Default -> hxxps://aoschat.apple.com; hxxps://aternos.org; hxxps://www.twitch.tv; hxxps://www46.nathanaeldan.pro; hxxps://www57.davisonbarker.pro; hxxps://www86.davisonbarker.pro CHR Extension: (Google Traduction) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2023-03-27] CHR Extension: (Norton Password Manager) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\admmjipmmciaobhojoghlmleefbicajg [2023-10-13] CHR Extension: (Torrent Scanner) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2023-03-01] CHR Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-08-25] CHR Extension: (Watch2Gether) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\cimpffimgeipdhnhjohpbehjkcdpjolg [2023-07-01] CHR Extension: (Adblock pour Youtube™) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2023-05-30] CHR Extension: (Dark Reader) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2023-10-04] CHR Extension: (Mino (anciennement Minty): Coupon automatique) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\fefnkplkicihcoenmljhbihhaaagjhpp [2023-09-02] CHR Extension: (Barre de Confiance CM-CIC) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffjkhaeogkeelkioellpgcebmekedpag [2022-09-08] CHR Extension: (Signets iCloud) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2022-11-19] CHR Extension: (EditThisCookie) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2021-04-16] CHR Extension: (Google Docs hors connexion) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-05-30] CHR Extension: (AdBlock — le meilleur bloqueur de pubs) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2023-10-09] CHR Extension: (Wappalyzer - Technology profiler) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\gppongmhjkpfnbhagpmjfkannfbllamg [2023-08-18] CHR Extension: (Skipflix: auto sauter l'intro de Netflix) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hapiefpnmbcochapdaokomnfiakholbc [2021-12-28] CHR Extension: (Ne jamais terminer Netflix) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdadmgabliibighlbejhlglfjgplfmhb [2022-05-15] CHR Extension: (Adblocker for Youtube™) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hipilpceecbhfpflneijogboalilnfjp [2022-12-01] [UpdateUrl:hxxps://clients71.google.com/service/update2/crx] <==== ATTENTION CHR Extension: (AllCast Receiver) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjbljnpdahefgnopeohlaeohgkiidnoe [2021-04-25] CHR Extension: (Google Sheets Offline) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhgjfmdjomnlhfacokoibjlcmcmgoec [2023-10-15] [UpdateUrl:hxxps://clients25.google.com/service/update2/crx] <==== ATTENTION CHR Extension: (Pas de nom) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhgjfmdjomnlhfacokoibjlcmcmgoecBaXEl [2023-09-09] CHR Extension: (No Scary Parts) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnhpidkcnifgjijogoodnkfgdlpgkaik [2023-07-28] CHR Extension: (Traducteur - Traduction Web, Dictionnaire) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibppednjgooiepmkgdcoppnmbhmieefh [2023-07-22] CHR Extension: (ClickOnce for Google Chrome) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\kekahkplibinaibelipdcikofmedafmb [2023-01-17] CHR Extension: (IGRAAL : Cashback & codes promo) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmhkepipobnjllejbafajoemahjejdcm [2023-09-30] CHR Extension: (NaturalReader - AI Text to Speech) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\kohfgcgbkjodfcfkcackpagifgbcmimk [2023-09-02] CHR Extension: (Netflix Pause Removal) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfekcpndbpdgjjfahekhncdfegkhbghg [2021-12-28] CHR Extension: (Coupert - Codes Promo Automatiques & Cashback) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfidniedemcgceagapgdekdbmanojomk [2023-10-14] CHR Extension: (Shazam : le nom des chansons en un clic) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmioliijnhnoblpgimnlajmefafdfilb [2023-10-11] CHR Extension: (Norton Safe) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpnlkmlkncncpgnnkmkgoobfpnjmblnk [2023-08-04] CHR Extension: (Facebook Screen Sharing) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncfpggehkhmjpdjpefomjchjafhmbnai [2021-04-16] CHR Extension: (Hotspot Shield) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbejmccbhkncgokjcmghpfloaajcffj [2023-09-18] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-04-16] CHR Extension: (Browsec VPN - Free VPN for Chrome) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\omghfjlpggmjjaagoclmmobgdodcjboh [2023-09-30] CHR Extension: (Speedtest by Ookla) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjjikdiikihdfpoppgaidccahalehjh [2023-07-01] CHR Profile: C:\Users\battj\AppData\Local\Google\Chrome\User Data\Guest Profile [2023-10-15] CHR Extension: (Google Access Offline) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Guest Profile\Extensions\hlhgjfmdjomnlhfacokoibjlcmcmgoec [2023-10-15] [UpdateUrl:hxxps://clients89.google.com/service/update2/crx] <==== ATTENTION CHR Profile: C:\Users\battj\AppData\Local\Google\Chrome\User Data\Profile 1 [2023-10-13] CHR Extension: (Torrent Scanner) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2023-05-11] CHR Extension: (Google Docs hors connexion) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-07-01] CHR Extension: (Google Access Offline) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hlhgjfmdjomnlhfacokoibjlcmcmgoec [2023-10-15] [UpdateUrl:hxxps://clients24.google.com/service/update2/crx] <==== ATTENTION CHR Extension: (Malwarebytes Browser Guard) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2023-07-01] CHR Extension: (Web Safety) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhcmdonhekjhfbjmeacdjbhlfgpjabp [2023-05-11] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-05-11] CHR Profile: C:\Users\battj\AppData\Local\Google\Chrome\User Data\System Profile [2023-10-15] CHR Extension: (Google Slides Offline) - C:\Users\battj\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\hlhgjfmdjomnlhfacokoibjlcmcmgoec [2023-10-15] [UpdateUrl:hxxps://clients41.google.com/service/update2/crx] <==== ATTENTION CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] CHR HKLM-x32\...\Chrome\Extension: [mfhcmdonhekjhfbjmeacdjbhlfgpjabp] Opera: ======= OPR Profile: C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable [2023-10-13] OPR Extension: (Video downloader) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\afhdhdllpdmajoopkogfdmdfdgmpjipp [2023-07-28] OPR Extension: (Video downloader for Instagram™) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\anbeheknilinnhalejpdnaobfhlokibb [2023-07-28] OPR Extension: (Music downloader) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\cmkmbhibddfjgokeipcjedbhphkmhied [2023-07-28] OPR Extension: (Anonymous Button) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\deiafejpkkabdfkhhnmdfbndgnckgldj [2023-07-28] OPR Extension: (Image Downloader) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\djlbpfldklgbbcndolfjibbhegnmnmho [2023-07-28] OPR Extension: (Muncher) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\dolflifdbncknmooonbhphlkngcfpmnh [2023-07-28] OPR Extension: (Adblock for Youtube™) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\ijelnahiojlfbmiihbmgkaldffppfelp [2023-07-28] OPR Extension: (Adblocker for Youtube™) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\ioipkkmonpmomecbmggejienahinjkjj [2023-10-12] OPR Extension: (Flappy Bird Purple) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\jampfdkpcoalfbgifjoogcananhneolf [2023-07-28] OPR Extension: (Brick Game) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\kgenkdpnlkjnidkldpbnfplchghdfckb [2023-07-28] OPR Extension: (Pool Billiard Game) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\ldebpgljdepoakcfedmacnjmflebifej [2023-07-28] OPR Extension: (Twitter video downloader) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\ncknaobecnibkpanffkegnkmilafnofh [2023-07-28] OPR Extension: (Battleships Master) - C:\Users\battj\AppData\Roaming\Opera Software\Opera Stable\Extensions\oacepnkmjogghgfoaaogmaknjooaffom [2023-07-28] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) "SAntivirusWD" => service a été déverrouillé. <==== ATTENTION R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [3853384 2022-08-26] (philandro Software GmbH -> AnyDesk Software GmbH) R2 AVerRECentral; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [1930848 2017-10-18] (AVerMedia TECHNOLOGIES, INC. -> AVerMedia TECHNOLOGIES, Inc.) R2 AzureAttestService; C:\Program Files\Microsoft\AzureAttestService\AzureAttestService.dll [151288 2019-07-24] (Microsoft Windows -> Microsoft Corporation) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [15044872 2023-04-12] (BattlEye Innovations e.K. -> ) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12860928 2023-10-07] (Microsoft Corporation -> Microsoft Corporation) S3 CloudBackupRestoreSvc; C:\WINDOWS\System32\CloudRestoreLauncher.dll [1261568 2023-10-11] (Microsoft Windows -> Microsoft Corporation) R2 DFWSIDService; C:\Program Files (x86)\Wondershare\Wondershare dr.fone (CPC)\WsidService.exe [1051648 2022-02-11] (wondershare) [Fichier non signé] R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [5030080 2021-12-13] (AVB Disc Soft, SIA -> Disc Soft Ltd) R2 DiskOptimizer; C:\ProgramData\DiskOptimizer\DiskOptimizer.exe [6062074 2022-12-01] (TGMDev) [Fichier non signé] <==== ATTENTION R2 DolbyDAXAPI; C:\WINDOWS\system32\dolbyaposvc\DAX3API.exe [1926600 2019-09-02] (Dolby Laboratories, Inc. -> ) R3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [11126376 2023-10-11] (Electronic Arts, Inc. -> Electronic Arts) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [811496 2022-07-06] (EasyAntiCheat Oy -> Epic Games, Inc) R2 ElevationService; C:\Program Files (x86)\Wondershare\Wondershare dr.fone (CPC)\Addins\SocialApps\ElevationService.exe [913408 2022-05-25] () [Fichier non signé] S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029456 2022-07-13] (Epic Games Inc. -> Epic Games, Inc.) R2 FileOptimizer; C:\ProgramData\FileOptimizer\FileOptimizer.exe [1892351 2022-12-01] (O&O Software GmbH) [Fichier non signé] <==== ATTENTION R2 FMAPOService; C:\WINDOWS\System32\FMService64.exe [359808 2019-08-16] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [230352 2023-09-13] (HP Inc. -> HP Inc.) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] (Canon Inc. -> ) R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [10195200 2023-05-30] (Logitech Inc -> Logitech, Inc.) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [206808 2022-05-12] (Logitech Inc -> Logitech Inc.) R2 MSSQL$SQLTOPSOLID; c:\Program Files\Microsoft SQL Server\MSSQL15.SQLTOPSOLID\MSSQL\Binn\sqlservr.exe [624680 2023-08-16] (Microsoft Corporation -> Microsoft Corporation) S3 OverwolfUpdater; C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe [2641416 2023-10-03] (Overwolf Ltd -> Overwolf LTD) S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [1846768 2023-04-04] (Rockstar Games, Inc. -> Rockstar Games) R2 SAntivirusSvc; C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusService.exe [690704 2022-03-28] (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) <==== ATTENTION R2 SAntivirusWD; C:\Program Files (x86)\Digital Communications\SAntivirus\SAntivirusWD.exe [74770848 2023-04-10] (Segurazo Security -> DlGlTAL COMMUNICATIONS INC) [Fichier non signé] <==== ATTENTION S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [402264 2023-10-11] (Microsoft Windows Publisher -> Microsoft Corporation) R2 ShadowUSB; C:\Program Files\Shadow\ShadowUSB-2.1.3\ShadowUSB.exe [4241664 2023-05-16] (Shadow -> Shadow) R2 spacedeskService; C:\WINDOWS\System32\spacedeskService.exe [4816336 2023-04-26] (Datronicsoft Inc. -> ) S4 SQLAgent$SQLTOPSOLID; c:\Program Files\Microsoft SQL Server\MSSQL15.SQLTOPSOLID\MSSQL\Binn\SQLAGENT.EXE [690216 2023-08-16] (Microsoft Corporation -> Microsoft Corporation) R2 SQLTELEMETRY$SQLTOPSOLID; c:\Program Files\Microsoft SQL Server\MSSQL15.SQLTOPSOLID\MSSQL\Binn\sqlceip.exe [284608 2023-08-16] (Microsoft Corporation -> Microsoft Corporation) R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2021-11-25] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) R2 ss_conn_service2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [920768 2021-11-25] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [14614960 2022-02-15] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) R2 UsbService; C:\Users\battj\AppData\Local\Programs\shadow\resources\app.asar.unpacked\release\native\eltima10\service\UsbService64.exe [4262824 2022-03-29] (Blade -> Electronic Team) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe [3116904 2023-10-06] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe [133584 2023-10-06] (Microsoft Windows Publisher -> Microsoft Corporation) R2 Wondershare InstallAssist; C:\ProgramData\Wondershare\Service\InstallAssistService.exe [256000 2022-04-18] (Wondershare) [Fichier non signé] S3 XSplit_VCam_Updater; C:\Program Files\XSplit\VCam\XSplit_VCam_Updater.exe [3199096 2021-03-25] (SplitmediaLabs Limited -> XSplit) R2 XSpltVidSvc; C:\Program Files\XSplit\VCam\service\XSpltVidSvc.exe [259192 2021-03-25] (SplitmediaLabs Limited -> SplitmediaLabs Limited) S2 MEmuSVC; "D:\Program Files\Microvirt\MEmu\MemuService.exe" [X] R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvltsi.inf_amd64_81b761923f254c78\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvltsi.inf_amd64_81b761923f254c78\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S3 AVer330USB; C:\WINDOWS\system32\DRIVERS\AVer330USB.sys [1551616 2015-04-09] (Microsoft Windows Hardware Compatibility Publisher -> AVerMedia TECHNOLOGIES, Inc.) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-11-25] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2021-05-24] (AVB Disc Soft, SIA -> Disc Soft Ltd) R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2021-05-24] (AVB Disc Soft, SIA -> Disc Soft Ltd) R3 e2esoft_ivcamaudio_simple; C:\WINDOWS\system32\drivers\iVCamAud.sys [255464 2020-11-04] (Shanghai Yitu Information Technology Co., Ltd. -> e2eSoft) R3 EUsbHubFilter; C:\WINDOWS\system32\drivers\fusbhub.sys [131960 2022-03-29] (Electronic Team, Inc. -> Electronic Team, Inc.) R3 eustub; C:\WINDOWS\System32\drivers\eusbstub.sys [46408 2022-03-29] (Electronic Team, Inc. -> Electronic Team, Inc.) R3 iVCam; C:\WINDOWS\system32\DRIVERS\iVCam.sys [1198664 2022-12-06] (Shanghai Yitu Information Technology Co., Ltd. -> e2eSoft) R3 LGBusEnum; C:\WINDOWS\system32\drivers\LGBusEnum64.sys [46264 2022-05-12] (Logitech Inc -> Logitech Inc.) S3 LGJoyHidFilter; C:\WINDOWS\System32\drivers\LGJoyHidFilter64.sys [67768 2022-05-12] (Logitech Inc -> Logitech Inc.) S3 LGJoyHidLo; C:\WINDOWS\System32\drivers\LGJoyHidLo64.sys [54456 2022-05-12] (Logitech Inc -> Logitech Inc.) R3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore64.sys [76480 2022-05-12] (Logitech Inc -> Logitech Inc.) R3 LGVirHid; C:\WINDOWS\system32\drivers\LGVirHid64.sys [34496 2022-05-12] (Logitech Inc -> Logitech Inc.) S3 logi_generic_hid_filter; C:\WINDOWS\system32\drivers\logi_generic_hid_filter.sys [62288 2022-09-23] (Logitech Inc -> Logitech) R3 logi_joy_bus_enum; C:\WINDOWS\system32\drivers\logi_joy_bus_enum.sys [44880 2023-01-18] (Logitech Inc -> Logitech) S3 logi_joy_hid_filter; C:\WINDOWS\system32\drivers\logi_joy_hid_filter.sys [63824 2022-09-23] (Logitech Inc -> Logitech) S3 logi_joy_hid_lo; C:\WINDOWS\system32\drivers\logi_joy_hid_lo.sys [51536 2022-09-23] (Logitech Inc -> Logitech) S3 logi_joy_vir_hid; C:\WINDOWS\system32\drivers\logi_joy_vir_hid.sys [32080 2022-09-23] (Logitech Inc -> Logitech) R3 logi_joy_xlcore; C:\WINDOWS\system32\drivers\logi_joy_xlcore.sys [73040 2023-01-18] (Logitech Inc -> Logitech) R1 MEmuDrv; C:\WINDOWS\system32\DRIVERS\MEmuDrv.sys [320360 2021-01-04] (Shanghai Microvirt Software Technology Co., Ltd. -> Maiwei Corporation) R3 NewTek_AudioPortClass_Multi; C:\WINDOWS\System32\drivers\NewTek_AudioPortClass_Multi.sys [50544 2023-03-31] (VI(Z)RT INC. -> NewTek) R3 NewTek_WDM_KS_Multi; C:\WINDOWS\System32\drivers\NewTek_WDM_KS_Multi.sys [46952 2023-03-31] (VI(Z)RT INC. -> ) R3 NvModuleTracker; C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys [45656 2022-07-14] (Nvidia Corporation -> NVIDIA Corporation) S3 PAC207; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [686592 2009-06-25] (Microsoft Windows Hardware Compatibility Publisher -> PixArt Imaging Inc.) R1 ReasonCamFilter; C:\WINDOWS\System32\DRIVERS\ReasonCamFilter.sys [49992 2022-09-24] (Reason CyberSecurity Inc. -> Reason Software Company) S4 RsFx0600; C:\WINDOWS\System32\DRIVERS\RsFx0600.sys [286976 2019-09-24] (Microsoft Corporation -> Microsoft Corporation) R3 spacedeskDriverAndroidControl; C:\WINDOWS\System32\drivers\spacedeskDriverAndroidControl.sys [49120 2023-02-20] (Datronicsoft Inc. -> ) R3 spacedeskDriverBus; C:\WINDOWS\System32\drivers\spacedeskDriverBus.sys [107960 2023-04-04] (Datronicsoft Inc. -> datronicsoft Inc.) S3 spacedeskKtmInputMouse; C:\WINDOWS\System32\drivers\spacedeskKtmInputMouse.sys [42448 2022-11-04] (Datronicsoft Inc. -> ) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167544 2021-11-25] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) R1 TASANTIVIRUSKD; C:\Program Files (x86)\Digital Communications\SAntivirus\TASAntivirusKD.sys [86024 2022-03-28] (Digital Communications Inc -> DlGlTAL COMMUNICATIONS INC) <==== ATTENTION S4 UCPD; C:\WINDOWS\System32\drivers\UCPD.sys [29184 2023-09-13] (Microsoft Windows -> Microsoft Corporation) R3 UsbDk; C:\WINDOWS\System32\Drivers\UsbDk.sys [103128 2020-03-13] (Red Hat, Inc. -> Red Hat Inc.) R3 vmulti; C:\WINDOWS\System32\drivers\vmulti.sys [10752 2018-12-11] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) R3 vuhub; C:\WINDOWS\System32\drivers\vuhub.sys [138056 2022-03-29] (Electronic Team, Inc. -> Electronic Team, Inc.) R3 vuhub3; C:\WINDOWS\System32\drivers\vuhub3.SYS [112464 2022-03-29] (Electronic Team, Inc. -> Electronic Team, Inc.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-10-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [169232 2022-05-07] (Microsoft Windows -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [572712 2023-10-06] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105872 2023-10-06] (Microsoft Windows -> Microsoft Corporation) R2 WIBUKEY; C:\WINDOWS\System32\DRIVERS\WibuKey64.sys [118200 2020-03-18] (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) S3 XSplit_Dummy; C:\WINDOWS\system32\drivers\xspltspk.sys [26200 2016-06-15] (Splitmedialabs Limited -> SplitmediaLabs Limited) R3 XSpltVid; C:\WINDOWS\system32\DRIVERS\XSpltVid.sys [121864 2021-03-17] (Microsoft Windows Hardware Compatibility Publisher -> SplitmediaLabs Limited) S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X] ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-10-16 00:01 - 2023-10-16 00:02 - 000062679 _____ C:\Users\battj\Downloads\FRST.txt 2023-10-16 00:00 - 2023-10-16 00:01 - 000000000 ____D C:\FRST 2023-10-15 23:59 - 2023-10-15 23:59 - 002383360 _____ (Farbar) C:\Users\battj\Downloads\FRST64.exe 2023-10-14 18:19 - 2023-10-14 18:19 - 022980096 _____ C:\Users\battj\Downloads\241877 Pentatonix - Daft Punk.osz 2023-10-14 18:17 - 2023-10-14 18:17 - 026388812 _____ C:\Users\battj\Downloads\1937777 Indila - Tourner Dans Le Vide.osz 2023-10-14 18:17 - 2023-10-14 18:17 - 011393265 _____ C:\Users\battj\Downloads\1488666 Mylene Farmer - Desenchantee.osz 2023-10-14 18:17 - 2023-10-14 18:17 - 007403727 _____ C:\Users\battj\Downloads\1755670 Indila - Derniere Danse.osz 2023-10-14 17:57 - 2023-10-14 17:57 - 000000000 ____D C:\Users\battj\node_modules 2023-10-14 16:04 - 2023-10-14 16:04 - 000813244 _____ C:\WINDOWS\system32\perfh00C.dat 2023-10-14 16:04 - 2023-10-14 16:04 - 000158618 _____ C:\WINDOWS\system32\perfc00C.dat 2023-10-14 15:55 - 2023-10-14 15:56 - 000000000 ____D C:\WINDOWS\Minidump 2023-10-13 00:09 - 2023-10-13 00:09 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView 2023-10-13 00:08 - 2023-10-14 23:01 - 000000000 ____D C:\ProgramData\GVzmTAMPMBigVtVB 2023-10-13 00:08 - 2023-10-13 00:08 - 000003356 _____ C:\WINDOWS\system32\Tasks\WnkFlydgrUNYLF 2023-10-13 00:08 - 2023-10-13 00:08 - 000003164 _____ C:\WINDOWS\system32\Tasks\sZbEqUpwGLSmG2 2023-10-13 00:08 - 2023-10-13 00:08 - 000003034 _____ C:\WINDOWS\system32\Tasks\eLrbrmhzYfSdNwVFx2 2023-10-13 00:08 - 2023-10-13 00:08 - 000003026 _____ C:\WINDOWS\system32\Tasks\vxFBJgPOgoQTQXrBrGM2 2023-10-13 00:08 - 2023-10-13 00:08 - 000003008 _____ C:\WINDOWS\system32\Tasks\MpekihZbrkVPEIu2 2023-10-13 00:08 - 2023-10-13 00:08 - 000000000 ____D C:\Program Files (x86)\qOWDSetpHctcC 2023-10-13 00:08 - 2023-10-13 00:08 - 000000000 ____D C:\Program Files (x86)\OSMCyPkDFJmU2 2023-10-13 00:08 - 2023-10-13 00:08 - 000000000 ____D C:\Program Files (x86)\kgMACCGfSlUn 2023-10-13 00:08 - 2023-10-13 00:08 - 000000000 ____D C:\Program Files (x86)\jykPaGRYedLqSIhqEsR 2023-10-12 21:13 - 2023-10-12 21:13 - 000000000 ____D C:\Users\battj\AppData\Roaming\4kdownload.com 2023-10-12 21:12 - 2023-10-12 21:12 - 000000000 ____D C:\Users\battj\Downloads\ApoalMusique 2023-10-12 19:22 - 2023-10-13 00:08 - 000000000 ____D C:\Program Files (x86)\WNQerUHUU 2023-10-12 19:21 - 2023-10-12 19:21 - 000014388 __RSH C:\ProgramData\ntuser.pol 2023-10-11 21:34 - 2023-10-11 21:34 - 000001937 _____ C:\Users\battj\Desktop\TLauncher.lnk 2023-10-11 21:33 - 2023-10-11 21:41 - 000000000 ____D C:\Users\battj\AppData\Roaming\.tlauncher 2023-10-11 21:33 - 2023-10-11 21:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TLauncher 2023-10-11 21:32 - 2023-10-11 21:32 - 023679584 _____ (TLauncher Inc.) C:\Users\battj\Downloads\TLauncher-2.885-Installer-1.1.3.exe 2023-10-11 21:32 - 2023-10-11 21:32 - 000060462 _____ C:\WINDOWS\SysWOW64\ctac.json 2023-10-11 21:31 - 2023-10-11 21:31 - 000060462 _____ C:\WINDOWS\system32\ctac.json 2023-10-11 21:31 - 2023-10-11 21:31 - 000016239 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json 2023-10-11 21:24 - 2023-10-11 21:27 - 000000000 ___HD C:\$WinREAgent 2023-10-04 02:26 - 2023-10-04 02:26 - 000000222 _____ C:\Users\battj\Desktop\Game Dev Tycoon.url 2023-10-03 20:31 - 2023-10-03 20:31 - 000000000 ____D C:\Program Files\Common Files\DESIGNER 2023-09-30 01:27 - 2023-09-30 01:27 - 000000000 ____D C:\Users\battj\Documents\Ghost Games 2023-09-30 01:22 - 2023-09-30 01:22 - 000001112 _____ C:\Users\Public\Desktop\Need for Speed™ Rivals.lnk 2023-09-30 01:22 - 2023-09-30 01:22 - 000001088 _____ C:\Users\Public\Desktop\Need for Speed™ Rivals(64 bit).lnk ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2023-10-16 00:03 - 2022-12-01 23:38 - 000000004 _____ C:\ProgramData\rc.dat 2023-10-16 00:03 - 2022-12-01 23:37 - 000000004 _____ C:\ProgramData\lock.dat 2023-10-15 23:57 - 2022-12-01 23:37 - 000000428 _____ C:\ProgramData\lir.bats 2023-10-15 23:57 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemTemp 2023-10-15 23:56 - 2023-05-17 00:56 - 000003066 _____ C:\WINDOWS\system32\Tasks\SIMDB_75b6e096fc79c825286efd6614b8d0f4 2023-10-15 23:56 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2023-10-15 23:56 - 2021-04-18 20:22 - 000000000 ____D C:\Program Files\TeamViewer 2023-10-15 23:56 - 2021-04-16 13:48 - 000000000 ____D C:\ProgramData\NVIDIA 2023-10-15 23:55 - 2023-05-20 03:14 - 000000000 ____D C:\Users\Public\.shadow 2023-10-15 23:55 - 2023-03-02 14:36 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2023-10-15 23:55 - 2023-03-02 14:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2023-10-15 23:55 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ServiceState 2023-10-15 23:55 - 2021-04-16 16:47 - 000012288 ___SH C:\DumpStack.log.tmp 2023-10-15 23:55 - 2021-04-16 13:50 - 000000134 _____ C:\WINDOWS\system32\regtest.txt 2023-10-15 12:58 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps 2023-10-15 12:58 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\AppReadiness 2023-10-15 12:06 - 2023-01-17 11:10 - 000002280 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2023-10-15 12:06 - 2021-04-16 14:06 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2023-10-15 02:16 - 2023-08-04 01:03 - 000000000 ____D C:\Users\battj\AppData\Local\osu! 2023-10-14 23:03 - 2021-04-17 17:01 - 000000000 ____D C:\Users\battj\AppData\Local\CrashDumps 2023-10-14 19:08 - 2021-04-19 00:04 - 000000000 ____D C:\Users\battj\AppData\Roaming\.minecraft 2023-10-14 17:57 - 2023-03-02 14:30 - 000000000 ____D C:\Users\battj 2023-10-14 16:04 - 2023-03-02 14:40 - 001975122 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2023-10-14 16:04 - 2022-05-07 07:22 - 000000000 ____D C:\WINDOWS\INF 2023-10-14 15:57 - 2021-04-23 18:43 - 000000000 ____D C:\ProgramData\Riot Games 2023-10-14 15:55 - 2023-01-23 21:34 - 003445705 ____N C:\WINDOWS\Minidump\101423-11906-01.dmp 2023-10-13 22:21 - 2023-03-02 14:36 - 000003576 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-36739671-87360890-1428175875-1001 2023-10-13 22:21 - 2023-03-02 14:36 - 000003372 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-36739671-87360890-1428175875-1001 2023-10-13 22:21 - 2021-04-16 15:10 - 000002413 _____ C:\Users\battj\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2023-10-13 22:13 - 2021-04-16 14:12 - 000000000 ____D C:\Program Files\Microsoft Office 2023-10-13 22:08 - 2021-04-16 13:51 - 000000000 ____D C:\WINDOWS\system32\MRT 2023-10-13 22:06 - 2021-04-16 13:45 - 000000000 ____D C:\Users\battj\AppData\Local\Packages 2023-10-13 00:12 - 2022-05-07 07:17 - 001048576 _____ C:\WINDOWS\system32\config\BBI 2023-10-13 00:12 - 2021-12-01 23:52 - 000000000 ____D C:\Program Files (x86)\AnyDesk 2023-10-13 00:10 - 2023-03-02 14:28 - 000630304 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2023-10-13 00:09 - 2022-05-07 12:35 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\UUS 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemResources 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\setup 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\oobe 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\migwiz 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Dism 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\appraiser 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellExperiences 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ShellComponents 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\Provisioning 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2023-10-13 00:09 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\bcastdvr 2023-10-12 23:59 - 2021-04-16 20:24 - 000000000 ____D C:\Users\battj\AppData\Roaming\slobs-client 2023-10-12 20:53 - 2021-04-27 22:33 - 000000000 ____D C:\Users\battj\AppData\Roaming\Microsoft\MMC 2023-10-12 19:26 - 2022-05-07 07:17 - 000000000 ____D C:\WINDOWS\CbsTemp 2023-10-12 19:12 - 2021-12-09 22:16 - 000000000 ____D C:\Program Files\Streamlabs OBS 2023-10-11 23:56 - 2021-04-16 13:51 - 181553176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2023-10-11 21:43 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\USOPrivate 2023-10-11 21:41 - 2021-04-29 18:06 - 000000000 ____D C:\Users\battj\Desktop\mods 2023-10-11 21:35 - 2022-12-01 23:43 - 000000000 ____D C:\Users\battj\AppData\Roaming\Java 2023-10-11 21:32 - 2023-03-02 14:29 - 003210752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2023-10-11 21:22 - 2021-12-12 16:41 - 000000000 ____D C:\WINDOWS\SysWOW64\1033 2023-10-11 21:22 - 2021-12-12 16:41 - 000000000 ____D C:\WINDOWS\system32\1033 2023-10-11 21:22 - 2021-12-12 16:07 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2023-10-11 21:21 - 2021-12-12 16:07 - 000000000 ____D C:\Program Files\Microsoft SQL Server 2023-10-09 21:00 - 2021-04-16 13:45 - 000000000 ____D C:\Users\battj\AppData\Local\ConnectedDevicesPlatform 2023-10-09 19:40 - 2021-04-16 14:15 - 000000000 ____D C:\Program Files (x86)\Steam 2023-10-07 22:10 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2023-10-06 01:48 - 2021-04-16 13:39 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2023-10-05 05:28 - 2021-04-18 01:28 - 000000000 ____D C:\Program Files (x86)\Overwolf 2023-10-04 23:31 - 2022-10-23 18:15 - 000095736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe 2023-10-04 23:31 - 2022-10-23 18:15 - 000075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe 2023-10-04 23:31 - 2021-11-18 00:51 - 000181864 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll 2023-10-04 23:31 - 2021-04-17 22:44 - 002709096 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll 2023-10-04 23:31 - 2021-04-17 22:44 - 000503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll 2023-10-04 23:31 - 2021-04-17 22:44 - 000210536 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll 2023-10-04 23:31 - 2021-04-17 22:44 - 000145000 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll 2023-10-04 03:58 - 2021-09-13 01:01 - 000000000 ____D C:\Users\battj\AppData\Local\Game Dev Tycoon - Steam 2023-10-04 02:26 - 2021-04-16 22:36 - 000000000 ____D C:\Users\battj\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2023-10-04 02:25 - 2021-04-16 14:18 - 000000000 ____D C:\Users\battj\AppData\Local\Steam 2023-10-03 21:24 - 2021-05-10 10:13 - 000000000 ____D C:\Users\battj\AppData\Local\ElevatedDiagnostics 2023-09-30 01:15 - 2021-04-16 14:25 - 000000000 ____D C:\Users\battj\AppData\Local\D3DSCache 2023-09-30 01:08 - 2021-10-02 02:59 - 000000000 ____D C:\Program Files\EA Games 2023-09-30 01:03 - 2021-05-06 20:49 - 000001638 ___SH C:\Users\battj\AppData\Roaming\Microsoft\LastFlashConfig.wfc 2023-09-22 02:17 - 2021-04-16 13:48 - 000000000 ____D C:\ProgramData\Packages 2023-09-18 19:23 - 2023-07-22 02:19 - 000000000 ____D C:\Users\battj\AppData\Local\NDI 2023-09-17 04:08 - 2022-05-07 12:35 - 000000000 ___SD C:\WINDOWS\system32\AppV 2023-09-17 02:05 - 2023-04-22 21:41 - 000000000 ____D C:\wwz ==================== Fichiers à la racine de certains dossiers ======== 2022-09-05 11:49 - 2022-09-05 11:49 - 000685392 _____ (Mozilla Foundation) C:\ProgramData\freebl3.dll 2022-12-01 23:37 - 2023-10-16 00:03 - 000000004 _____ () C:\ProgramData\lock.dat 2022-09-05 11:49 - 2022-09-05 11:49 - 000608080 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll 2022-09-05 11:49 - 2022-09-05 11:49 - 000450024 _____ (Microsoft Corporation) C:\ProgramData\msvcp140.dll 2022-09-05 11:49 - 2022-09-05 11:49 - 002046288 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll 2022-12-01 23:38 - 2023-10-16 00:05 - 000000004 _____ () C:\ProgramData\rc.dat 2022-06-12 23:58 - 2022-06-12 23:58 - 000009072 _____ () C:\ProgramData\SMRResults540.dat 2022-09-05 11:49 - 2022-09-05 11:49 - 000257872 _____ (Mozilla Foundation) C:\ProgramData\softokn3.dll 2022-12-01 23:37 - 2022-12-01 23:37 - 000000008 _____ () C:\ProgramData\ts.dat 2022-09-05 11:49 - 2022-09-05 11:49 - 000080880 _____ (Microsoft Corporation) C:\ProgramData\vcruntime140.dll 2021-10-11 21:44 - 2022-03-14 18:11 - 000000032 _____ () C:\Users\battj\AppData\Roaming\.machineId 2021-07-25 21:34 - 2021-07-25 21:34 - 000000012 _____ () C:\Users\battj\AppData\Roaming\2457fe3357cbf1220231e8917326f70f 2023-04-25 03:18 - 2023-04-25 03:18 - 009028096 _____ () C:\Users\battj\AppData\Roaming\5yVHzv21.exe 2021-07-25 21:43 - 2021-07-25 21:43 - 000000012 _____ () C:\Users\battj\AppData\Roaming\67fa1b1ba5b0ed2fad9c840a61e47ada 2021-04-24 01:33 - 2021-03-05 01:32 - 000000017 _____ () C:\Users\battj\AppData\Roaming\buildof.txt 2021-04-24 01:33 - 2021-03-05 01:32 - 000014949 _____ () C:\Users\battj\AppData\Roaming\changelog.txt 2022-01-23 16:23 - 2022-01-23 16:23 - 000000068 _____ () C:\Users\battj\AppData\Roaming\changzhi_leidian.data 2022-01-23 16:23 - 2022-01-23 16:23 - 000000128 _____ () C:\Users\battj\AppData\Roaming\changzhi_leidianmac.data 2021-04-24 01:33 - 2021-03-05 01:32 - 000006657 _____ () C:\Users\battj\AppData\Roaming\files.txt 2021-04-24 01:33 - 2021-03-05 01:32 - 000250994 _____ () C:\Users\battj\AppData\Roaming\flattening_ids.txt 2023-04-28 03:35 - 2023-04-28 03:35 - 008054784 _____ () C:\Users\battj\AppData\Roaming\id2E6PqH.exe 2021-04-24 01:33 - 2021-03-05 01:32 - 000015900 _____ () C:\Users\battj\AppData\Roaming\launchwrapper-of-2.2.jar 2021-04-24 01:33 - 2021-03-05 01:32 - 000000003 _____ () C:\Users\battj\AppData\Roaming\launchwrapper-of.txt 2021-04-24 01:33 - 2021-03-05 01:32 - 000005534 _____ () C:\Users\battj\AppData\Roaming\patch.cfg 2021-04-24 01:33 - 2021-03-05 01:32 - 000022595 _____ () C:\Users\battj\AppData\Roaming\patch2.cfg 2021-04-24 01:33 - 2021-03-05 01:32 - 000006802 _____ () C:\Users\battj\AppData\Roaming\ToCheck.txt 2022-11-16 23:28 - 2022-11-16 23:28 - 000000000 _____ () C:\Users\battj\AppData\Local\curF897.tmp 2021-05-07 19:00 - 2021-05-07 19:00 - 000003584 _____ () C:\Users\battj\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2021-12-02 14:33 - 2021-12-17 22:58 - 000002846 _____ () C:\Users\battj\AppData\Local\krita-sysinfo.log 2021-12-02 14:33 - 2021-12-18 00:58 - 000024415 _____ () C:\Users\battj\AppData\Local\krita.log 2021-12-18 00:58 - 2021-12-18 00:58 - 000000039 _____ () C:\Users\battj\AppData\Local\kritadisplayrc 2021-12-02 14:33 - 2021-12-18 00:58 - 000018619 _____ () C:\Users\battj\AppData\Local\kritarc 2021-05-13 00:47 - 2021-05-31 18:13 - 000007596 _____ () C:\Users\battj\AppData\Local\Resmon.ResmonCfg 2021-06-15 00:35 - 2022-01-03 17:12 - 164366632 _____ () C:\Users\battj\AppData\Local\_run.qx ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================