Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 11.06.2024 Exécuté par touggourt (administrateur) sur PÉPÉJANOT (Hewlett-Packard HP Pavilion 17 Notebook PC) (18-06-2024 18:46:49) Exécuté depuis C:\Users\touggourt\Desktop\FRST64.exe Profils chargés: touggourt Plate-forme: Microsoft Windows 10 Famille Version 22H2 19045.4046 (X64) Langue: Français (France) Navigateur par défaut: "C:\Users\touggourt\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1" Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (DriverStore\FileRepository\c0360470.inf_amd64_b06c374aee20d185\B360357\atiesrxx.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0360470.inf_amd64_b06c374aee20d185\B360357\atieclxx.exe (explorer.exe ->) (Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe <22> (explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <32> (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\c0360470.inf_amd64_b06c374aee20d185\B360357\atiesrxx.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8505088 2015-07-03] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-07-03] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation -> Microsoft Corporation) HKLM-x32\...\Run: [USB Security] => C:\Program Files (x86)\USB Disk Security\USBGuard.exe [695528 2015-01-31] (Lanzhou Itanium Software Technology Co., Ltd. -> Zbshareware Lab) HKLM-x32\...\Run: [AutoTransfer PC] => C:\Program Files (x86)\USB Disk Security\backupmaster.exe [397200 2018-04-08] (Bo Zheng -> Bo Zheng) HKU\S-1-5-21-2099052359-4194192794-1698811201-1002\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 6\CyberGhost.exe [1398352 2018-06-11] (CyberGhost SRL -> CyberGhost S.A.) HKU\S-1-5-21-2099052359-4194192794-1698811201-1002\...\Run: [Opera Stable] => C:\Users\touggourt\AppData\Local\Programs\Opera\opera.exe [1581984 2024-04-29] (Opera Norway AS -> Opera Software) HKU\S-1-5-21-2099052359-4194192794-1698811201-1002\...\Run: [MicrosoftEdgeAutoLaunch_E349E25CDDA37349DEA42844FF639202] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3883456 2024-06-15] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-2099052359-4194192794-1698811201-1002\...\RunOnce: [Application Restart #4] => C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe [2867736 2024-06-14] (Brave Software, Inc. -> Brave Software, Inc.) HKLM\...\Windows x64\Print Processors\Canon MG3100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDAR.DLL [30208 2012-03-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Windows x64\Print Processors\Canon MG5100 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDAD.DLL [28672 2010-08-25] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Windows x64\Print Processors\Epson Inkjet: C:\Windows\System32\spool\prtprocs\x64\EP0NPP01.DLL [38912 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3100 series: C:\WINDOWS\system32\CNMLMAR.DLL [385024 2012-03-14] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Canon BJ Language Monitor MG5100 series: C:\WINDOWS\system32\CNMLMAD.DLL [361472 2010-08-25] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.) HKLM\...\Print\Monitors\Epson Inbox Language Monitor01: C:\WINDOWS\system32\EP0SLM01.DLL [77824 2011-08-30] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION) HKLM\...\Print\Monitors\HP Universal Port Monitor: C:\WINDOWS\system32\hpbprtmon.dll [365568 2012-12-01] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard) HKLM\...\Print\Monitors\pdfcmon: C:\WINDOWS\system32\pdfcmon.dll [114872 2015-01-05] (pdfforge GmbH -> pdfforge GmbH) HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\126.1.67.116\Installer\chrmstp.exe [2024-06-17] (Brave Software, Inc. -> Brave Software, Inc.) HKLM\Software\...\Authentication\Credential Providers: [{538C240D-3DEE-4032-AB4C-08A3A6EB0861}] -> Startup: C:\Users\touggourt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeepL auto-start.lnk [2024-01-08] ShortcutTarget: DeepL auto-start.lnk -> C:\Users\touggourt\AppData\Roaming\0install.net\desktop-integration\stubs\1eae01f3cdb5ff0ecf683b15a60a1489573c1188cb34abc205fcf7a924b4e54d\auto-start.exe () [Fichier non signé] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2024-04-24] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH) ==================== Tâches planifiées (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {C2D17328-8FBC-4F6A-AAC3-1379B2849F21} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1547208 2024-01-31] (Adobe Inc. -> Adobe Inc.) Task: {3223B411-0241-4ABD-9C14-967505F747B0} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [155848 2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) Task: {B1AC6451-C7C7-4366-94D6-E0FF544D2AAC} - System32\Tasks\BraveSoftwareUpdateTaskMachineUA => C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [155848 2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) Task: {69CC7351-248D-4500-91DD-FFB1E4444EF9} - System32\Tasks\CCleaner Update => C:\Program Files\Cleaner\CCUpdate.exe [714256 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) Task: {EE2F2752-41F4-4684-B9EB-F67588257A14} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\Cleaner\CCleanerBugReport.exe [4703648 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\Cleaner\LOG" --programpath "C:\Program Files\Cleaner" --guid "bd77af6f-ca2f-4e6e-8666-7d2e924dade5" --version "6.18.10838" --silent Task: {4C4B99D8-61C8-4D91-92EB-076706D06DA4} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [184096 2017-05-31] (Maxthon (Asia) Limited. -> Maxthon International ltd.) Task: {778ED82B-1E1F-457C-9105-4673A965DC90} - System32\Tasks\Maxthon5 Update => C:\Program Files (x86)\Maxthon5\bin\Maxthon.exe [170776 2020-02-21] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) Task: {5E413AE2-4805-478B-B689-6BFC90B1402B} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1} Task: {C9DCF59E-6B97-4C0C-8641-B8261089C8CA} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E} Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371} Task: {9C41A5EC-F56C-455E-905E-295D7F84B133} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA} Task: {094CD275-5C71-4753-B57E-5566CA859498} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316} Task: {DB21EF32-6BA9-4118-BBC1-BC4FF48961E5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61} Task: {8B6759EE-1C08-4B8F-955C-774AB5A6544E} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1} Task: {0F6DBBD1-1FA5-490B-A482-1F43FCC689E6} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969} Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE} Task: {DB7D758D-C24D-483A-97ED-988C713284B8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24030.9-0\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance (Pas de fichier) Task: {338A4FC1-4FAD-487C-9A9E-87F0399C8BDB} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2099052359-4194192794-1698811201-1002 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [675744 2024-06-17] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (l'élément de données a 6 caractères en plus). Task: {FBDA6E11-A9A2-40C4-AB37-341D9AA35875} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33696 2024-06-17] (Mozilla Corporation -> Mozilla Foundation) Task: {55F976AA-0D78-4BA2-8207-39B0F50AD49F} - System32\Tasks\Opera scheduled Autoupdate 1676712353 => C:\Users\touggourt\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5668768 2024-04-25] (Opera Norway AS -> Opera Software) Task: {82C3068F-F8BC-49C0-BF77-10CE80A3FCC3} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [61624 2020-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {AC89AD10-E447-49AD-AA6A-CD61C8D970DB} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [69304 2020-08-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {9EFF7721-0DD2-4126-A008-C52F68D38C30} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [4397144 ] (Synaptics Incorporated -> Synaptics Incorporated) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\Cleaner\CCleanerBugReport.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Tcpip\Parameters: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{00ff6b89-d220-4306-bd49-f1e8f79d4f1c}: [DhcpNameServer] 109.0.66.20 109.0.66.10 Tcpip\..\Interfaces\{00ff6b89-d220-4306-bd49-f1e8f79d4f1c}\14E64627F696461405: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{00ff6b89-d220-4306-bd49-f1e8f79d4f1c}\35642502759664960264F4E4F5235485: [DhcpNameServer] 192.168.9.2 Tcpip\..\Interfaces\{00ff6b89-d220-4306-bd49-f1e8f79d4f1c}\35642502759664960264F4E4F5235485: [DhcpDomain] extender.com Tcpip\..\Interfaces\{00ff6b89-d220-4306-bd49-f1e8f79d4f1c}\C457D69616025353030283732313: [DhcpNameServer] 192.168.137.1 Tcpip\..\Interfaces\{00ff6b89-d220-4306-bd49-f1e8f79d4f1c}\C457D69616025353030283732313: [DhcpDomain] mshome.net Tcpip\..\Interfaces\{2d86388d-f132-416c-a9fe-1b39133c4907}: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{2d86388d-f132-416c-a9fe-1b39133c4907}\35642502759664960264F4E4: [DhcpNameServer] 109.0.66.20 109.0.66.10 Tcpip\..\Interfaces\{2d86388d-f132-416c-a9fe-1b39133c4907}\35642502759664960264F4E4F5235485: [DhcpNameServer] 109.0.66.20 109.0.66.10 Tcpip\..\Interfaces\{2d86388d-f132-416c-a9fe-1b39133c4907}\6427565626F687D223438627A7: [DhcpNameServer] 192.168.0.254 Tcpip\..\Interfaces\{2d86388d-f132-416c-a9fe-1b39133c4907}\C457D69616: [DhcpNameServer] 192.168.137.1 Tcpip\..\Interfaces\{2d86388d-f132-416c-a9fe-1b39133c4907}\C457D69616: [DhcpDomain] mshome.net Tcpip\..\Interfaces\{532d4ce3-b0a6-4bc7-9caf-e9e017009f95}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{532d4ce3-b0a6-4bc7-9caf-e9e017009f95}\14E64627F696461405: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{532d4ce3-b0a6-4bc7-9caf-e9e017009f95}\544696D61687548545E23556475707022383: [DhcpNameServer] 192.168.9.2 Tcpip\..\Interfaces\{532d4ce3-b0a6-4bc7-9caf-e9e017009f95}\544696D61687548545E23556475707022383: [DhcpDomain] extender.com Tcpip\..\Interfaces\{6754f4a9-fbca-4404-962f-2e31e8b84c61}: [DhcpNameServer] 192.168.15.133 Tcpip\..\Interfaces\{e3b538e6-dc83-42f2-af4c-4edc9e8d04f3}: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{e3b538e6-dc83-42f2-af4c-4edc9e8d04f3}\356425F543731464: [DhcpNameServer] 109.0.66.20 109.0.66.10 Tcpip\..\Interfaces\{e9bfdbe2-591b-4d99-9769-35591778d733}: [NameServer] 192.168.1.1 Tcpip\..\Interfaces\{e9bfdbe2-591b-4d99-9769-35591778d733}\14E64627F696461405: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{e9bfdbe2-591b-4d99-9769-35591778d733}\544696D61687548545E23556475707022383: [DhcpNameServer] 192.168.9.2 Tcpip\..\Interfaces\{e9bfdbe2-591b-4d99-9769-35591778d733}\544696D61687548545E23556475707022383: [DhcpDomain] extender.com Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\touggourt\AppData\Local\Microsoft\Edge\User Data\Default [2024-06-18] Edge Extension: (Google Docs hors connexion) - C:\Users\touggourt\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-04-18] Edge Extension: (Edge relevant text changes) - C:\Users\touggourt\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-04-18] FireFox: ======== FF DefaultProfile: hnxqmrcx.default FF ProfilePath: C:\Users\touggourt\AppData\Roaming\Mozilla\Firefox\Profiles\hnxqmrcx.default [2024-06-18] FF ProfilePath: C:\Users\touggourt\AppData\Roaming\Mozilla\Firefox\Profiles\kvfxxutz.default-release [2024-06-18] FF Extension: (Chrome Remote Desktop) - C:\Users\touggourt\AppData\Roaming\Mozilla\Firefox\Profiles\kvfxxutz.default-release\Extensions\remotedesktop@google.com.xpi [2024-05-14] [UpdateUrl:hxxps://www.gstatic.com/chromoting/firefox_extension/update.json] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2024-05-04] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) FF Plugin-x32: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Program Files (x86)\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) Chrome: ======= CHR HKU\S-1-5-21-2099052359-4194192794-1698811201-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] Opera: ======= OPR DefaultProfile: Default Brave: ======= BRA DefaultProfile: Default BRA Profile: C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default [2024-06-18] BRA Extension: (Google Traduction) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-06-17] BRA Extension: (Adobe Acrobat : outils de modif., de conversion et de signature de PDF) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-06-17] BRA Extension: (Brave Ad Block Updater (Brave Ad Block First Party Filters (plaintext))) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\adcocjohghhfpidemphmcmlmhnfgikei [2024-06-18] BRA Extension: (Brave Local Data Files Updater) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\afalakplffnnnlkncjhbmahjfjhmlkal [2024-06-18] BRA Extension: (Brave NTP background images) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\aoojcmojmmcbpfgoecoadbdpnagfchel [2024-02-03] BRA Extension: (Brave Ad Block Updater (Fanboy's Mobile Notifications (plaintext))) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\bfpgedeaaibpoidldhjcknekahbikncb [2024-06-18] BRA Extension: (Brave Ads Resources) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\bgifagoclclhhoflocdefiklgodpihog [2024-06-17] BRA Extension: (Wallet Data Files Updater) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\BraveWallet [2024-06-17] BRA Extension: (Brave Ad Block Updater (EasyList Cookie (plaintext))) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\cdbbhgbmjhfnhnmgeddbliobbofkgdhe [2024-06-18] BRA Extension: (Brave Ad Block Updater (Brave Ad Block Updater)) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\cffkpbalmllkdoenhmdmpbkajipdjfam [2024-02-13] BRA Extension: (Brave Tor Client Updater (Windows)) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\cpoalefficncklhjfpglfiplenlpccdb [2021-09-23] BRA Extension: (Brave Ad Block Updater (AdGuard Français)) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\emaecjinaegfkoklcdafkiocjhoeilao [2023-04-14] BRA Extension: (Brave Ad Block Updater (AdGuard Français (plaintext))) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\flnkmpokemfpaajmiimmjeiandgoodgg [2024-06-18] BRA Extension: (Brave Ad Block Updater (Regional Catalog)) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\gkboaolpopklhgplhaaiboijnklogmbc [2024-06-17] BRA Extension: (Brave Ad Block Updater (Brave Ad Block Updater (plaintext))) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\iodkpdagapdfkphljnddpjlldadblomo [2024-06-18] BRA Extension: (Brave SpeedReader Updater) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\jicbkmdloagakknpihibphagfckhjdih [2022-03-10] BRA Extension: (Brave NTP sponsored images) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\lcenblphbmngnohghkhpojmpflebkcpd [2024-06-18] BRA Extension: (Brave Ad Block Updater (Resources)) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\mfddibmblmbccpadfndgakiopmmhebop [2024-06-17] BRA Extension: (Brave HTTPS Everywhere Updater) - C:\Users\touggourt\AppData\Local\BraveSoftware\Brave-Browser\User Data\oofiananboodjbbmdelgdommihjbkfag [2023-11-13] StartMenuInternet: Brave - C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [155016 2017-09-22] (Advanced Micro Devices, Inc. -> ) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-01-31] (Adobe Inc. -> Adobe Inc.) S3 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [106952 2015-07-03] (Andrea Electronics -> Andrea Electronics Corporation) S3 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-16] (Advanced Micro Devices, Inc.) [Fichier non signé] S2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [5323592 2024-04-24] (AnyDesk Software GmbH -> AnyDesk Software GmbH) S3 brave; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [155848 2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) S3 BraveElevationService; C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\126.1.67.116\elevation_service.exe [2700312 2024-06-14] (Brave Software, Inc. -> Brave Software, Inc.) S3 bravem; C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe [155848 2020-08-13] (Brave Software, Inc. -> BraveSoftware Inc.) S3 CCleanerPerformanceOptimizerService; C:\Program Files\Cleaner\CCleanerPerformanceOptimizerService.exe [1083808 2023-11-21] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) S3 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [204880 2018-06-11] (CyberGhost SRL -> CyberGhost S.A.) S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\124.0.6367.18\remoting_host.exe [74016 2024-03-26] (Google LLC -> Google LLC) S2 MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [178464 2020-02-21] (Maxthon Technology Co, Ltd. -> Maxthon International ltd.) S3 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-16] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S3 ampa; C:\WINDOWS\system32\ampa.sys [38320 2017-02-28] (CHENGDU AOMEI Tech Co., Ltd. -> ) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) S3 ddmdrv; C:\WINDOWS\system32\ddmdrv.sys [35760 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> ) R3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R1 ElRawDisk; C:\WINDOWS\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation -> EldoS Corporation) S3 GridinSoftInetSecurityDriver; C:\WINDOWS\system32\DRIVERS\gsInetSecurity.sys [107784 2024-02-28] (GridinSoft, LLC -> GridinSoft LLC) S3 GSDriver; C:\WINDOWS\System32\drivers\GSDriver64.sys [55488 2024-02-28] (Microsoft Windows Hardware Compatibility Publisher -> ) R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-29] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) S3 RtlWlanu; C:\WINDOWS\System32\drivers\n300ma.sys [1577792 2012-11-20] (On Networks -> Realtek Semiconductor Corporation) R3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22080 2024-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [602520 2024-06-05] (Microsoft Windows -> Microsoft Corporation) S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [159936 2016-08-16] (NGO -> MBB) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105880 2024-06-05] (Microsoft Windows -> Microsoft Corporation) R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34944 2018-05-11] (HP Inc. -> HP) S3 XUIF; C:\WINDOWS\System32\Drivers\x10ufx2.sys [33048 2006-11-30] (X10 Wireless Technology Inc. -> X10 Wireless Technology, Inc.) U4 nxdm; pas de ImagePath U4 nxfs; pas de ImagePath U4 nxpcap; pas de ImagePath U4 nxsshd; pas de ImagePath U4 nxtun; pas de ImagePath U4 nxusbd; pas de ImagePath U4 nxusbh; pas de ImagePath U4 nxusbs; pas de ImagePath ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2024-06-18 18:03 - 2024-06-18 18:03 - 000000008 _____ C:\ProgramData\ntuser.pol 2024-06-18 16:10 - 2024-06-18 18:00 - 000056244 _____ C:\Users\touggourt\Desktop\Fixlog.txt 2024-06-17 17:37 - 2024-06-17 17:41 - 321682824 _____ C:\Users\touggourt\Desktop\dr web cure it.exe 2024-06-17 16:34 - 2024-06-17 16:34 - 000000000 ____D C:\Users\touggourt\AppData\LocalLow\AMD 2024-06-17 16:28 - 2024-06-17 16:28 - 000062573 _____ C:\Users\touggourt\Desktop\Shortcut.txt 2024-06-17 16:22 - 2024-06-17 16:28 - 000052549 _____ C:\Users\touggourt\Desktop\Addition.txt 2024-06-17 16:07 - 2024-06-18 18:53 - 000025835 _____ C:\Users\touggourt\Desktop\FRST.txt 2024-06-17 16:03 - 2024-06-17 16:03 - 000016631 _____ C:\Users\touggourt\Desktop\ZHPCleaner (R).txt 2024-06-17 15:58 - 2024-06-17 15:58 - 000016607 _____ C:\Users\touggourt\Desktop\ZHPCleaner (S).txt 2024-06-17 15:12 - 2024-06-17 15:12 - 008790880 _____ (Malwarebytes) C:\Users\touggourt\Desktop\adwcleaner(1).exe 2024-06-17 15:11 - 2024-06-17 15:11 - 008791352 _____ (Malwarebytes) C:\Users\touggourt\Desktop\AdwCleaner.exe 2024-06-17 15:10 - 2024-06-17 15:10 - 002395136 _____ (Farbar) C:\Users\touggourt\Desktop\FRST64.exe 2024-06-17 14:50 - 2024-06-17 15:20 - 000000886 _____ C:\Users\touggourt\Desktop\ZHPCleaner.lnk 2024-06-17 14:48 - 2024-06-17 14:49 - 003364512 _____ (Nicolas Coolman) C:\Users\touggourt\Desktop\ZHPCleaner.exe 2024-06-17 11:46 - 2024-06-18 18:02 - 000000000 ____D C:\Program Files\Mozilla Firefox 2024-06-17 09:39 - 2024-06-17 11:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashPeak Slimjet (64 bit) 2024-06-17 09:39 - 2024-06-17 09:39 - 000000000 ____D C:\Users\touggourt\AppData\Local\Slimjet 2024-06-17 09:38 - 2024-06-17 11:21 - 000000000 ____D C:\Program Files\Slimjet 2024-05-31 20:50 - 2024-06-16 20:28 - 001974784 _____ C:\Users\touggourt\Documents\CODES Divers (version 1) (Enregistré automatiquement) (Enregistré automatiquement) (Enregistré automatiquement) (Enregistré automatiquement).xls 2024-05-30 16:30 - 2024-06-02 15:38 - 000000000 ____D C:\Users\touggourt\Desktop\ZIP 16 avril 2024 2024-05-28 15:36 - 2024-05-29 10:29 - 000000000 ____D C:\Users\touggourt\Desktop\ios pa converi 2024-05-28 15:36 - 2024-05-28 19:06 - 000000000 ____D C:\Users\touggourt\Desktop\ios converti 2024-05-24 20:52 - 2024-05-24 20:52 - 000000512 _____ C:\Users\touggourt\Documents\BDBE0A60 2024-05-24 14:27 - 2024-05-26 06:49 - 000000000 ____D C:\Users\touggourt\Desktop\Nouveau dossier 2024-05-23 16:38 - 2024-05-23 16:45 - 000000000 ____D C:\Users\touggourt\Desktop\ZIP ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2024-06-18 18:52 - 2023-02-15 19:12 - 000000000 ___DC C:\FRST 2024-06-18 18:20 - 2024-05-12 15:16 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2024-06-18 18:09 - 2023-11-29 19:08 - 000000000 ___HD C:\Users\touggourt\Downloads\.opera 2024-06-18 18:09 - 2023-11-29 19:08 - 000000000 ___HD C:\Users\touggourt\.opera 2024-06-18 18:07 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2024-06-18 18:03 - 2022-10-28 03:10 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2024-06-18 18:03 - 2022-10-27 23:50 - 000000000 ____D C:\Users\touggourt 2024-06-18 18:03 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState 2024-06-18 18:02 - 2024-05-12 15:15 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2024-06-18 18:02 - 2021-03-07 01:24 - 000008192 ___SH C:\DumpStack.log.tmp 2024-06-18 18:01 - 2019-12-07 11:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI 2024-06-18 18:01 - 2017-09-15 22:51 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin 2024-06-18 18:00 - 2022-10-28 02:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2024-06-18 17:57 - 2014-10-26 11:51 - 000000000 ____D C:\Users\touggourt\AppData\LocalLow\Temp 2024-06-18 17:12 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2024-06-18 16:57 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps 2024-06-18 16:55 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2024-06-18 16:53 - 2020-07-15 07:28 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2024-06-18 16:12 - 2013-08-22 17:36 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2024-06-18 16:09 - 2014-10-02 18:39 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\Microsoft\Excel 2024-06-18 16:08 - 2024-01-19 11:09 - 001975296 _____ C:\Users\touggourt\Documents\CODES Divers (version 1) (Enregistré automatiquement) (Enregistré automatiquement) (Enregistré automatiquement).xls 2024-06-18 15:48 - 2022-05-20 11:00 - 000000000 ____D C:\Users\touggourt\Desktop\Pál 2024-06-17 23:05 - 2023-12-12 11:02 - 000004208 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2024-06-17 21:01 - 2022-01-22 16:49 - 000000000 ____D C:\Users\touggourt\Doctor Web 2024-06-17 18:41 - 2024-05-12 15:16 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2024-06-17 18:40 - 2024-05-12 15:15 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2024-06-17 16:03 - 2017-06-25 12:32 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\ZHP 2024-06-17 15:19 - 2019-03-29 16:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2024-06-17 15:19 - 2016-11-02 19:06 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\Samsung 2024-06-17 15:19 - 2016-11-02 19:05 - 000000000 ____D C:\Program Files (x86)\Samsung 2024-06-17 14:44 - 2020-08-13 11:31 - 000002423 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk 2024-06-17 14:43 - 2022-09-08 05:11 - 000000000 ____D C:\WINDOWS\SystemTemp 2024-06-17 14:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF 2024-06-17 11:37 - 2022-10-28 03:10 - 000003690 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2024-06-17 11:37 - 2022-10-28 03:10 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2024-06-17 11:36 - 2020-04-20 09:27 - 000000000 ____D C:\Program Files\Cleaner 2024-06-17 11:29 - 2023-05-21 18:35 - 000000000 ____D C:\ProgramData\AnyDesk 2024-06-17 11:28 - 2022-10-28 03:10 - 000000000 ____D C:\WINDOWS\system32\Tasks\NCH Software 2024-06-17 11:22 - 2024-05-14 13:47 - 000000000 ____D C:\Program Files (x86)\Google 2024-06-17 11:22 - 2024-04-24 16:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyDesk 2024-06-17 11:22 - 2023-05-21 18:35 - 000000000 ____D C:\Program Files (x86)\AnyDesk 2024-06-17 11:22 - 2023-05-18 09:53 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\AnyDesk 2024-06-17 11:22 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF 2024-06-17 11:22 - 2018-06-12 18:48 - 000000000 ____D C:\Users\touggourt\AppData\Local\Microsoft Help 2024-06-17 11:22 - 2015-01-07 22:15 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\XnView 2024-06-17 11:22 - 2014-11-20 20:48 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\vlc 2024-06-17 11:22 - 2014-10-02 20:36 - 000000000 ____D C:\Users\touggourt\AppData\Roaming\Microsoft\Word 2024-06-17 10:37 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\registration 2024-06-17 10:32 - 2018-03-19 12:40 - 000000000 __HDC C:\$SysReset 2024-06-17 09:50 - 2018-03-20 20:20 - 000000000 ____D C:\Users\touggourt\AppData\Local\Packages 2024-06-17 09:41 - 2018-06-13 15:24 - 000000000 ____D C:\Users\touggourt\AppData\Local\D3DSCache 2024-06-17 09:06 - 2024-04-24 09:41 - 000000000 ____D C:\Users\touggourt\Desktop\RTM 2024-06-16 20:40 - 2024-02-16 20:53 - 000000000 ____D C:\Users\touggourt\Desktop\opera 2024-06-13 09:38 - 2018-12-16 09:52 - 000000000 ____D C:\Users\touggourt\AppData\Local\CrashDumps 2024-06-05 18:47 - 2018-03-03 15:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2024-05-31 20:56 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2024-05-24 20:51 - 2024-05-13 21:15 - 000000273 _____ C:\Users\touggourt\Desktop\adresse formation carnegie.txt ==================== Fichiers à la racine de certains dossiers ======== 2024-01-11 15:43 - 2024-01-11 15:43 - 000000025 _____ () C:\Users\touggourt\liste.bat 2016-06-13 09:15 - 2016-06-13 09:15 - 000000096 _____ () C:\Users\touggourt\AppData\Roaming\version2.xml 2017-02-15 19:41 - 2017-02-15 19:41 - 000132803 _____ () C:\Users\touggourt\AppData\Local\ars.cache 2017-02-15 19:43 - 2017-02-15 19:43 - 000389166 _____ () C:\Users\touggourt\AppData\Local\census.cache 2020-04-13 15:53 - 2023-01-06 18:45 - 000016896 _____ () C:\Users\touggourt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-02-15 18:13 - 2017-02-15 18:13 - 000000036 _____ () C:\Users\touggourt\AppData\Local\housecall.guid.cache 2023-06-23 11:13 - 2023-06-23 11:13 - 000000477 _____ () C:\Users\touggourt\AppData\Local\kdeglobals 2023-06-23 11:04 - 2023-06-23 11:04 - 000008337 _____ () C:\Users\touggourt\AppData\Local\kdenlive-layoutsrc 2023-06-23 11:04 - 2023-06-23 11:15 - 000004645 _____ () C:\Users\touggourt\AppData\Local\kdenliverc 2015-10-11 11:16 - 2015-10-11 11:16 - 000000888 _____ () C:\Users\touggourt\AppData\Local\recently-used.xbel 2018-02-24 17:42 - 2022-02-03 09:54 - 000007597 _____ () C:\Users\touggourt\AppData\Local\Resmon.ResmonCfg 2023-06-23 11:05 - 2023-06-23 11:05 - 000005174 _____ () C:\Users\touggourt\AppData\Local\user-places.xbel 2023-06-23 11:05 - 2023-06-23 11:05 - 000004490 _____ () C:\Users\touggourt\AppData\Local\user-places.xbel.bak 2023-06-23 11:05 - 2023-06-23 11:05 - 000000000 _____ () C:\Users\touggourt\AppData\Local\user-places.xbel.tbcache ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================