Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 14-01-2025 Exécuté par Mouaadiib (administrateur) sur MOUAADIIB69 (Micro-Star International Co., Ltd. MS-7C91) (15-01-2025 21:02:40) Exécuté depuis C:\Users\Mouaadiib\Desktop\FRST64.exe Profils chargés: Mouaadiib Plate-forme: Microsoft Windows 11 Professionnel Version 24H2 26100.2894 (X64) Langue: Français (France) Navigateur par défaut: Edge Mode d'amorçage: Normal ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (Adobe Inc. -> Adobe Systems Inc.) [Fichier non signé] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe (C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (C:\Program Files (x86)\Global Imaging OnLine\GXD5 Spooler\srvany.exe ->) (Global Imaging On Line) [Fichier non signé] C:\Program Files (x86)\Global Imaging OnLine\GXD5 Spooler\DIAMSpooler.exe (C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe ->) (OpenJS Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe (C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe (C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud Experience\js\node_modules\adobe-cr\build\Release\Adobe Crash Processor.exe (C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe (C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe (C:\Program Files\Tablet\Wacom\WacomHost.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (C:\Program Files\Tablet\Wacom\WTabletServicePro.exe ->) (Wacom Co., Ltd. -> ) C:\Program Files\Tablet\Wacom\Wacom_UpdateUtil.exe (C:\Program Files\Tablet\Wacom\WTabletServicePro.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe (C:\Program Files\Tablet\Wacom\WTabletServicePro.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe (C:\Program Files\Tablet\Wacom\WTabletServicePro.exe ->) (Wacom Technology Corp. -> Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe (C:\Riot Games\Riot Client\RiotClientServices.exe ->) () [Fichier non signé] C:\Riot Games\Riot Client\RiotClientCrashHandler.exe (Discord Inc. -> Discord Inc.) C:\Users\Mouaadiib\AppData\Local\Discord\app-1.0.9178\Discord.exe <6> (explorer.exe ->) (Amazon.com Services LLC -> Amazon.com Inc.) C:\Users\Mouaadiib\AppData\Local\Amazon Drive\AmazonPhotos.exe (explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe (explorer.exe ->) (Cloudflare, Inc. -> Cloudflare) C:\Program Files\Cloudflare\Cloudflare WARP\Cloudflare WARP.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <15> (explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Program Files\Riot Vanguard\vgtray.exe (explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\Riot Client\RiotClientServices.exe (explorer.exe ->) (ultracopier.first-world.info) [Fichier non signé] C:\Program Files\Ultracopier\ultracopier.exe (explorer.exe ->) (VLC Mobile Remote) [Fichier non signé] C:\Program Files (x86)\VMR Connect\VMRHub.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (services.exe ->) () [Fichier non signé] C:\Program Files (x86)\Global Imaging OnLine\GXD5 Spooler\srvany.exe (services.exe ->) (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.) C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe (services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (services.exe ->) (Cloudflare, Inc. -> ) C:\Program Files\Cloudflare\Cloudflare WARP\warp-svc.exe (services.exe ->) (Global Imaging On Line) [Fichier non signé] C:\Program Files (x86)\Global Imaging OnLine\GXD5 AutoUpdater\GIOLAutoUpdate.exe (services.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome Remote Desktop\132.0.6834.12\remoting_host.exe <2> (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe (services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordUpdater\NordUpdateService.exe (services.exe ->) (nordvpn s.a. -> nordvpn S.A.) C:\Program Files\NordVPN\nordvpn-service.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3> (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (Oculus VR, LLC -> Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_c3d80190bdb690cb\RtkAudUService64.exe <2> (services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe (services.exe ->) (Wacom Co., Ltd. -> Wacom Co. Ltd.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe (services.exe ->) (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe (services.exe ->) (Wondershare Technology Co.,Ltd -> Wondershare) C:\ProgramData\Wondershare\Service\InstallAssistService.exe (sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.220.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe (sihost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.24112.22.0_x64__cw5n1h2txyewy\CrossDeviceService.exe (svchost.exe ->) (H.D.S. Hungary) [Fichier non signé] E:\2 -Applications\_Performance et securité\Hard Disk Sentinel Pro Portable 5.50.9 (Windows)\HardDiskSentinelPortable\App\Hard Disk Sentinel\HDSentinel.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22114.0_x64__8wekyb3d8bbwe\HxOutlook.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.22114.0_x64__8wekyb3d8bbwe\HxTsr.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.34401.20.0_x64__cw5n1h2txyewy\WidgetBoard.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registre (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_c3d80190bdb690cb\RtkAudUService64.exe [2257864 2024-09-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [4131544 2024-11-21] (Riot Games, Inc. -> Riot Games, Inc.) HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [612304 2019-11-18] (NIKON CORPORATION -> Nikon Corporation) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [4884016 2019-10-17] (Adobe Inc. -> Adobe Systems Inc.) [Fichier non signé] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [750680 2023-12-19] (Oracle America, Inc. -> Oracle Corporation) HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [133128 2024-06-23] (Adobe Inc. -> Adobe Inc.) HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [Discord] => C:\Users\Mouaadiib\AppData\Local\Discord\Update.exe [1512760 2020-12-03] (Discord Inc. -> GitHub) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [365760 2020-09-26] (AVB Disc Soft, SIA -> Disc Soft Ltd) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [36981208 2024-12-04] (Epic Games Inc. -> Epic Games, Inc.) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [4412512 2024-12-02] (Valve Corp. -> Valve Corporation) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [133128 2024-06-23] (Adobe Inc. -> Adobe Inc.) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [VMR Connect] => C:\Program Files (x86)\VMR Connect\VMRHub.exe [221696 2023-02-03] (VLC Mobile Remote) [Fichier non signé] HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [Amazon Photos] => C:\Users\Mouaadiib\AppData\Local\Amazon Drive\AmazonPhotos.exe [11017840 2024-12-12] (Amazon.com Services LLC -> Amazon.com Inc.) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [ultracopier] => C:\Program Files\Ultracopier\ultracopier.exe [1505792 2016-01-02] (ultracopier.first-world.info) [Fichier non signé] HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [KeePassXC] => C:\Program Files\KeePassXC\KeePassXC.exe [7140552 2021-06-11] (DroidMonkey Apps, LLC -> KeePassXC Team) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [EADM] => C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe [3412576 2024-12-27] (Electronic Arts, Inc. -> Electronic Arts) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [Battle.net] => C:\Program Files (x86)\Battle.net\Battle.net.exe [981632 2024-11-02] (Blizzard Entertainment, Inc. -> Blizzard Entertainment) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [MicrosoftEdgeAutoLaunch_136B69F2E520D13F123F9A70CE35A732] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3911208 2025-01-09] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe [74279960 2025-01-09] (Riot Games, Inc. -> Riot Games, Inc.) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45381424 2024-12-04] (Gen Digital Inc. -> Piriform Software Ltd) HKU\S-1-5-21-2896008330-159720710-2358065777-1001\...\MountPoints2: {2cbf2177-0014-11eb-9d14-d850e63de249} - "H:\setup.exe" HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\Windows\system32\AdobePDF.dll [65176 2019-10-17] (Adobe Inc. -> Adobe Systems Inc) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\131.0.6778.265\Installer\chrmstp.exe [2025-01-09] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> AppInit_DLLs: C:\PROGRA~1\VIRTUA~1\VIRTUA~4.DLL => C:\Program Files\Virtual Desktop Streamer\VirtualDesktop.Injector64.dll [132376 2022-02-14] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Cloudflare WARP.lnk [2025-01-09] ShortcutTarget: Cloudflare WARP.lnk -> C:\Program Files\Cloudflare\Cloudflare WARP\Cloudflare WARP.exe (Cloudflare, Inc. -> Cloudflare) GroupPolicy: Restriction ? <==== ATTENTION GroupPolicy-Firefox: Restriction <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION ==================== Tâches planifiées (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {E4BB4ADA-D633-4C4D-87E3-9A3519B459BA} - \Nec -> Pas de fichier <==== ATTENTION Task: {88FAF162-3561-4534-BD10-361FFAAA6A33} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Pas de fichier) Task: {B6527279-F40B-4E41-92B5-EEA9E35FDF7F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [566592 2008-07-30] (Apple Inc. -> Apple Inc.) Task: {00297BCA-3113-4F9D-9405-6AE73C4D5744} - System32\Tasks\ASUS\P508PowerAgent_sdk => C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Mouse\ROG STRIX CARRY\P508PowerAgent.exe (Pas de fichier) Task: {B9CF849C-DDD2-4793-94F4-DFFDB35360B9} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [829408 2024-12-04] (Gen Digital Inc. -> Gen Digital Inc.) Task: {5477B876-BC73-4C8A-B978-91FB413C1EB5} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [5983536 2024-12-04] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "3e95973b-d416-4b4a-aecc-8ac200ef5858" --version "6.31.11415" --silent Task: {20AFC0D8-4392-4DE2-9245-4B64FD4642F9} - System32\Tasks\CCleanerSkipUAC - Mouaadiib => C:\Program Files\CCleaner\CCleaner.exe [39151920 2024-12-04] (Gen Digital Inc. -> Piriform Software Ltd) Task: {D926404F-A29C-4E38-85C2-8E3B0E02201D} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe [2864984 2024-12-09] (Microsoft Windows -> Microsoft Corporation) Task: {81A70FB1-BA31-49F1-AF4D-DF37E0083D80} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem132.0.6833.0{C97CEB3D-0518-4F56-90FA-5BC90369D91B} => C:\Program Files (x86)\Google\GoogleUpdater\132.0.6833.0\updater.exe [5591136 2024-11-11] (Google LLC -> Google LLC) Task: {1E14597D-65A2-4366-84E7-3926AE6C1212} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_Mouaadiib => E:\2 -Applications\_Performance et securité\Hard Disk Sentinel Pro Portable 5.50.9 (Windows)\HardDiskSentinelPortable\App\Hard Disk Sentinel\HDSentinel.exe [5768192 2019-12-25] (H.D.S. Hungary) [Fichier non signé] Task: {AFDDB4BF-F2A6-4698-B704-C43D379DDB88} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2113024 2024-06-11] () [Fichier non signé] Task: {A5E7E11D-43A9-4737-A2E1-D33A2D095A26} - System32\Tasks\Launch Adobe CCXProcess => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [194056 2024-06-23] (Adobe Inc. -> Adobe Inc.) Task: {43C6EFB7-0D01-4E61-9A7D-8CCEB7620AC0} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {A5A6C05E-4354-4FD9-9BBE-5E2BD59DE8A0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {CF2FD660-577D-4C36-A7AD-BC39157422A9} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (Pas de fichier) Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (Pas de fichier) Task: {FD2A8214-00D1-45F5-839F-85655136F82F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval => %systemroot%\system32\MusNotification.exe Display (Pas de fichier) Task: {3A4C7681-F9D6-44C9-8DB8-681511A2AAB8} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (Pas de fichier) Task: {139741E0-4689-4423-8FCE-9382E87624F9} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (Pas de fichier) Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Pas de fichier) Task: {6DF79136-8BC0-4192-9222-BD8B0C0D645C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {A429B352-811E-47B0-A583-1285C6BB8566} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {4631326A-D44C-456D-AE5F-0D96615E0D48} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {822A633E-1918-466B-8F07-EA2DE4B33DB1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpCmdRun.exe [1687360 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {9D724D17-2A59-4953-AC64-075C5551F3A4} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [671808 2025-01-07] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (l'élément de données a 6 caractères en plus). Task: {50C1575D-93D1-4C73-B7B7-586EF7EE1BE0} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2896008330-159720710-2358065777-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [671808 2025-01-07] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (l'élément de données a 6 caractères en plus). Task: {6A3D8CD0-F5F5-4B2D-A37F-1A4DFA8FCDF2} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34368 2025-01-07] (Mozilla Corporation -> Mozilla Foundation) Task: {EC2E9261-5290-4836-8904-6D733C010E00} - System32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA app\CEF\NVIDIA app.exe [3333672 2024-12-18] (NVIDIA Corporation -> NVIDIA Corporation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{8a5d0e59-fcde-4cf2-a4d4-4652335be693}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{c9498771-ad2e-4f93-9a59-1dac6e5f30a9}: [NameServer] 127.0.2.2,127.0.2.3 Tcpip\..\Interfaces\{c9498771-ad2e-4f93-9a59-1dac6e5f30a9}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{c9498771-ad2e-4f93-9a59-1dac6e5f30a9}: [DhcpDomain] home Tcpip\..\Interfaces\{db484304-db04-6aa0-a33d-7236836b364d}: [NameServer] 127.0.2.2,127.0.2.3 Tcpip\..\Interfaces\{e680c6a4-4a39-40ce-b9af-4b9893da2134}: [DhcpNameServer] 192.168.1.1 Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default [2025-01-15] Edge Notifications: Default -> hxxps://app.animaker.com; hxxps://calendar.google.com; hxxps://directorzone.cyberlink.com; hxxps://fr.cyberlink.com; hxxps://membership.cyberlink.com; hxxps://reverscaptcha.com; hxxps://team.swile.co; hxxps://update-ready.com; hxxps://vo7.com; hxxps://web.snapchat.com; hxxps://www.20minutes.fr; hxxps://www.aramisauto.com; hxxps://www.belambra.fr; hxxps://www.fnac.com; hxxps://www.joueclub.fr; hxxps://www.kiute.fr; hxxps://www.macifavantages.fr; hxxps://www.ol.fr; hxxps://www.tiktok.com; hxxps://www.yumelise.fr Edge HomePage: Default -> hxxps://? Edge StartupUrls: Default -> "hxxp://www.google.fr/" Edge Extension: (Image Downloader for IW) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bcieicfnbnmlffkgbiemoofinidpgloa [2023-08-14] Edge Extension: (MyJDownloader Browser Extension) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fbcohnmimjicjdomonkcbcpbpnhggkip [2023-09-24] Edge Extension: (NordVPN - the Fastest VPN proxy for privacy) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fphgeikpdcdcheaochkhldmnfblfogla [2025-01-06] Edge Extension: (Google Docs hors connexion) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-12-19] Edge Extension: (Adblock Plus - bloqueur de publicités gratuit) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2025-01-07] Edge Extension: (Edge relevant text changes) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-31] Edge Extension: (Video Downloader PLUS) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\njgehaondchbmjmajphnhlojfnbfokng [2024-07-27] Edge Extension: (uBlock Origin) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\odfafepnkmbhccpbejgmiehpchacaeak [2025-01-02] Edge Extension: (Coupert - Codes Promo Automatiques & Cashback) - C:\Users\Mouaadiib\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pefhciejnkgdgoahgfeklebcbpmhnhhd [2025-01-09] Edge HKLM-x32\...\Edge\Extension: [fphgeikpdcdcheaochkhldmnfblfogla] FireFox: ======== FF DefaultProfile: dloiw0pz.default FF ProfilePath: C:\Users\Mouaadiib\AppData\Roaming\Mozilla\Firefox\Profiles\dloiw0pz.default [2023-06-05] FF Homepage: Mozilla\Firefox\Profiles\dloiw0pz.default -> hxxps://mysearchengine.co/homepage?hp=1&bitmask=9996&pId=JD180501&iDate=2020-09-26 05:04:52&bName= FF SearchPlugin: C:\Users\Mouaadiib\AppData\Roaming\Mozilla\Firefox\Profiles\dloiw0pz.default\searchplugins\mysearchengine.xml [2020-11-23] FF ProfilePath: C:\Users\Mouaadiib\AppData\Roaming\Mozilla\Firefox\Profiles\aaeo4dp1.default-release [2025-01-15] FF Homepage: Mozilla\Firefox\Profiles\aaeo4dp1.default-release -> hxxps://mysearchengine.co/homepage?hp=1&bitmask=9996&pId=JD180501&iDate=2020-09-26 05:04:52&bName= FF Extension: (JavaScript-Java Bridge) - C:\Users\Mouaadiib\AppData\Roaming\Mozilla\Firefox\Profiles\aaeo4dp1.default-release\Extensions\jsjbridge@advancedcontrols.com.au.xpi [2020-12-20] FF Extension: (uBlock Origin) - C:\Users\Mouaadiib\AppData\Roaming\Mozilla\Firefox\Profiles\aaeo4dp1.default-release\Extensions\uBlock0@raymondhill.net.xpi [2024-11-29] FF Extension: (javascript) - C:\Users\Mouaadiib\AppData\Roaming\Mozilla\Firefox\Profiles\aaeo4dp1.default-release\Extensions\{d4bc778f-3a98-44f4-9b2e-45fab92a21db}.xpi [2023-03-01] FF SearchPlugin: C:\Users\Mouaadiib\AppData\Roaming\Mozilla\Firefox\Profiles\aaeo4dp1.default-release\searchplugins\mysearchengine.xml [2020-11-23] FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-10-16] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.12 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2021-01-04] (VideoLAN -> VideoLAN) FF Plugin-x32: @java.com/DTPlugin,version=11.401.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-12-19] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.401.2 -> C:\Program Files (x86)\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-12-19] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2019-10-17] (Adobe Inc. -> Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Profile 1 CHR Profile: C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Default [2022-09-30] CHR HomePage: Default -> hxxps://? CHR StartupUrls: Default -> "hxxps://?" CHR DefaultSearchURL: Default -> hxxps://find.fnavigate-now.com/results.aspx?q={searchTerms}&gd=SY1004294&searchsource=58&d=092620&n=9998 CHR DefaultSearchKeyword: Default -> Yahoo Search CHR DefaultSuggestURL: Default -> hxxp://api.bing.com/osjson.aspx?query={searchTerms} CHR Extension: (Adobe Acrobat) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-09-30] CHR Extension: (Google Docs hors connexion) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-30] CHR Extension: (Chromebook Recovery Utility) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Default\Extensions\jndclpdbaamdhonoechobihbbiimdgai [2022-09-30] CHR Extension: (Video Downloader PLUS) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Default\Extensions\njgehaondchbmjmajphnhlojfnbfokng [2022-09-30] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-22] CHR Profile: C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Guest Profile [2021-10-01] CHR Profile: C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 1 [2025-01-10] CHR Notifications: Profile 1 -> hxxps://meet.google.com; hxxps://www.youtube.com CHR HomePage: Profile 1 -> hxxps://? CHR StartupUrls: Profile 1 -> "hxxps://?" CHR DefaultSearchURL: Profile 1 -> hxxps://find.fnavigate-now.com/results.aspx?q={searchTerms}&gd=SY1004294&searchsource=58&d=092620&n=9998 CHR DefaultSearchKeyword: Profile 1 -> yahoo search CHR DefaultSuggestURL: Profile 1 -> hxxp://api.bing.com/osjson.aspx?query={searchTerms} CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-12-19] CHR Extension: (Google Docs hors connexion) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-01-06] CHR Extension: (Chrome Remote Desktop) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2022-12-19] CHR Extension: (MetaMask) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn [2025-01-06] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-08-09] CHR Extension: (Chromebook Recovery Utility) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pocpnlppkickgojjlmhdmidojbmbodfm [2024-03-12] CHR Profile: C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 2 [2024-03-12] CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2024-03-12] CHR Extension: (Google Docs hors connexion) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-03-12] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-03-12] CHR Profile: C:\Users\Mouaadiib\AppData\Local\Google\Chrome\User Data\System Profile [2024-09-23] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] ==================== Services (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.02.12\atkexComSvc.exe [457544 2022-08-02] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.) R2 AsusCertService; C:\Program Files (x86)\ASUS\AsusCertService\AsusCertService.exe [502632 2024-07-04] (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.) S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [3279488 2024-11-02] (Blizzard Entertainment, Inc. -> Blizzard Entertainment) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [15747368 2024-04-20] (BattlEye Innovations e.K. -> ) S3 CCleanerPerformanceOptimizerService; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [1087792 2024-12-04] (Gen Digital Inc. -> Piriform Software Ltd) R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\132.0.6834.12\remoting_host.exe [73824 2024-11-19] (Google LLC -> Google LLC) R2 CloudflareWARP; C:\Program Files\Cloudflare\Cloudflare WARP\warp-svc.exe [44038200 2025-01-09] (Cloudflare, Inc. -> ) R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4581568 2020-09-26] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [19068000 2024-12-27] (Electronic Arts, Inc. -> Electronic Arts) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1135648 2022-10-25] (EasyAntiCheat Oy -> Epic Games, Inc) S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [965872 2024-10-12] (EasyAntiCheat Oy -> Epic Games, Inc.) S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2022-11-16] (Epic Games Inc. -> Epic Games, Inc.) R2 GIOL Auto Updater; C:\Program Files (x86)\Global Imaging OnLine\GXD5 AutoUpdater\GIOLAutoUpdate.exe [345088 2016-01-27] (Global Imaging On Line) [Fichier non signé] R2 GXD5 Spooler; C:\Program Files (x86)\Global Imaging OnLine\GXD5 Spooler\DIAMSpooler.exe [653312 2015-06-25] (Global Imaging On Line) [Fichier non signé] R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-01-14] (HP Inc. -> HP Inc.) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe [1447680 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation) S3 nordsec-threatprotection-service; C:\Program Files\NordVPN\NordSec ThreatProtection\nordsec-threatprotection-service.exe [320088 2023-09-25] (nordvpn s.a. -> nordvpn S.A.) R2 NordUpdaterService; C:\Program Files\NordUpdater\NordUpdateService.exe [297848 2022-12-21] (nordvpn s.a. -> nordvpn S.A.) R2 nordvpn-service; C:\Program Files\NordVPN\nordvpn-service.exe [263256 2023-09-25] (nordvpn s.a. -> nordvpn S.A.) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\Display.NvContainer\NVDisplay.Container.exe [1275568 2024-12-04] (NVIDIA Corporation -> NVIDIA Corporation) S3 OVRLibraryService; C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe [148024 2023-06-08] (Oculus VR, LLC -> Facebook Technologies, LLC) R2 OVRService; C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe [508984 2023-06-08] (Oculus VR, LLC -> Facebook Technologies, LLC) S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [7499752 2024-10-26] (Rockstar Games, Inc. -> Rockstar Games) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559304 2024-12-06] (Microsoft Windows Publisher -> Microsoft Corporation) R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [16360768 2022-08-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\UNCHEATER\ucldr_battlegrounds_gl.exe [6020336 2022-09-13] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) S3 Updater; C:\Program Files\Virtual Desktop Streamer\Updater.exe [1127192 2022-02-14] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.) S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [13658344 2024-11-21] (Riot Games, Inc. -> Riot Games, Inc.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe [3199672 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe [141952 2024-10-30] (Microsoft Windows Publisher -> Microsoft Corporation) R2 Wondershare InstallAssist; C:\ProgramData\Wondershare\Service\InstallAssistService.exe [269200 2020-04-02] (Wondershare Technology Co.,Ltd -> Wondershare) R2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [83232 2019-06-26] (Wondershare Technology Co.,Ltd -> Wondershare) S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [10099288 2022-09-13] (PUBG CORPORATION -> KRAFTON, Inc) S3 AppShellElevationService; "C:\Program Files (x86)\TikTok LIVE Studio\0.63.0\elevation_service.exe" [X] ===================== Pilotes (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R1 aehd; C:\WINDOWS\system32\DRIVERS\aehd.sys [403080 2024-11-01] (Google LLC -> Google LLC) R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [36928 2022-09-16] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc) S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.) S1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15368 2015-05-13] (Microsoft Windows Hardware Compatibility Publisher -> ) R1 Asusgio3; C:\WINDOWS\system32\drivers\AsIO3.sys [58928 2024-07-03] (ASUSTeK COMPUTER INC. -> Asustek Computer Inc.) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-09-26] (AVB Disc Soft, SIA -> Disc Soft Ltd) R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-09-26] (AVB Disc Soft, SIA -> Disc Soft Ltd) S3 e2eVAWdm; C:\WINDOWS\System32\drivers\VAud_WDM.sys [121328 2020-12-01] (Shanghai Yitu Information Technology Co., Ltd. -> e2eSoft) S3 HarmanAudioService; C:\WINDOWS\System32\drivers\HarmanFilter.sys [63656 2022-11-05] (Harman International Industries, Inc -> Harman International) S3 HoYoProtect; C:\WINDOWS\system32\HoYoKProtect.sys [3762224 2024-09-04] (Microsoft Windows Hardware Compatibility Publisher -> miHoYo) S3 Larmkanal; C:\WINDOWS\System32\drivers\Larmkanal.sys [33112 2015-09-02] (ADORIASOFT LLC -> Adoriasoft LLC) S3 libusbK; C:\WINDOWS\System32\drivers\libusbK.sys [47928 2020-06-02] (Travis Lee Robinson -> hxxp://libusb-win32.sourceforge.net) S3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (ManyCam -> Visicom Media Inc.) S3 MFDriver_Driver; C:\WINDOWS\system32\drivers\MFDriver.sys [32224 2023-09-27] (Microsoft Windows Hardware Compatibility Publisher -> ) S3 MpKslfa835e6a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B861CB9A-CCF0-4870-B45E-1D6D46E81FC1}\MpKslDrv.sys [267552 2025-01-15] (Microsoft Windows -> Microsoft Corporation) R1 MSIO; C:\WINDOWS\system32\drivers\MsIo64.sys [19672 2023-12-10] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd) R2 NDivert; C:\Program Files\NordVPN\7.31.8.0\Drivers\NDivert.sys [131472 2024-10-31] (nordvpn s.a. -> Nordvpn S.A.) R1 nordlwf; C:\WINDOWS\system32\DRIVERS\nordlwf.sys [38608 2020-10-14] (TEFINCOM S.A. -> TEFINCOM S.A.) S3 oculusvad_oculusvad; C:\WINDOWS\System32\drivers\oculusvad.sys [75280 2021-10-03] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2021-10-03] (Oculus VR, LLC -> Facebook Inc.) R3 ovpn-dco; C:\WINDOWS\System32\drivers\ovpn-dco.sys [104600 2024-09-12] (WDKTestCert lev,133391533294737317 -> OpenVPN, Inc) S3 Phosgene; C:\WINDOWS\system32\DRIVERS\Phosgene.sys [34136 2015-09-02] (ADORIASOFT LLC -> Adoriasoft LLC) S3 Revoflt; C:\WINDOWS\System32\DRIVERS\revoflt.sys [38400 2021-11-17] (Microsoft Windows Hardware Compatibility Publisher -> VS Revo Group) R3 rt25cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt25cx21x64.inf_amd64_24c6d07c63f39347\rt25cx21x64.sys [887792 2024-11-18] (Realtek Semiconductor Corp. -> Realtek) R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_362e830323b2aee2\rt68cx21x64.sys [887792 2024-11-18] (Realtek Semiconductor Corp. -> Realtek) S3 SnapCameraVirtualDevice; C:\WINDOWS\System32\drivers\SnapCameraVirtualDevice.sys [2800232 2020-10-12] (Snap Inc. -> Windows (R) Win 7 DDK provider) S3 SSub8505; C:\WINDOWS\System32\drivers\DEUnify.sys [13696 2016-03-24] (Microsoft Windows Hardware Compatibility Publisher -> Primax Electronics Ltd.) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R1 steamxbox; C:\WINDOWS\System32\drivers\steamxbox.sys [278208 2023-02-21] (Valve Corp. -> Valve Corporation) S3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [41120 2024-09-12] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project) S3 usbscan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_971c769b103df369\usbscan.sys [90112 2024-12-06] (Microsoft Windows -> Microsoft Corporation) R3 VCamSDK; C:\WINDOWS\system32\DRIVERS\VCamSDK.sys [1092456 2020-12-01] (Shanghai Yitu Information Technology Co., Ltd. -> e2eSoft) S3 vdvad_WaveExtensible; C:\WINDOWS\System32\drivers\vdvad.sys [44936 2022-02-14] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.) R3 vdvge; C:\WINDOWS\System32\drivers\vdvge.sys [77864 2021-05-17] (Virtual Desktop, Inc. -> Virtual Desktop, Inc.) R1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [31525392 2024-11-20] (Riot Games, Inc. -> Riot Games, Inc.) S3 VoiceAIDriver; C:\WINDOWS\System32\DriverStore\FileRepository\voiceaidriver.inf_amd64_214d6aacf9c41414\voiceaidriver.sys [73616 2023-06-20] (Voice AI LLC -> Windows (R) Win 7 DDK provider) S3 WacHidRouterPro; C:\WINDOWS\System32\drivers\wachidrouter.sys [131288 2021-11-19] (WDKTestCert dant_ppxe9ny,132779414088034662 -> Wacom Technology, Corp.) S3 wacomrouterfilter; C:\WINDOWS\System32\drivers\wacomrouterfilter.sys [29368 2021-11-19] (WDKTestCert dant_ppxe9ny,132779414088034662 -> Wacom Technology, Corp.) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [22104 2024-10-30] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [606624 2024-10-30] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105888 2024-10-30] (Microsoft Windows -> Microsoft Corporation) R3 wintun; C:\WINDOWS\System32\drivers\wintun.sys [29592 2023-04-06] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) R3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2024-10-21] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2024-12-06] (Microsoft Windows -> Microsoft Corporation) R3 WSDScan; C:\WINDOWS\System32\DriverStore\FileRepository\sti.inf_amd64_971c769b103df369\WSDScan.sys [61440 2024-12-06] (Microsoft Windows -> Microsoft Corporation) S3 xhunter1; C:\WINDOWS\xhunter1.sys [1432232 2023-08-09] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois (créés) (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2025-01-15 21:02 - 2025-01-15 21:03 - 000045033 _____ C:\Users\Mouaadiib\Desktop\FRST.txt 2025-01-15 21:02 - 2025-01-15 21:02 - 000790768 _____ C:\WINDOWS\system32\perfh00C.dat 2025-01-15 21:02 - 2025-01-15 21:02 - 000463936 _____ C:\WINDOWS\system32\perfh011.dat 2025-01-15 21:02 - 2025-01-15 21:02 - 000158516 _____ C:\WINDOWS\system32\perfc00C.dat 2025-01-15 21:02 - 2025-01-15 21:02 - 000135672 _____ C:\WINDOWS\system32\perfc011.dat 2025-01-15 20:41 - 2025-01-15 20:56 - 000000000 ____D C:\Program Files\CCleaner 2025-01-15 20:41 - 2025-01-15 20:55 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2025-01-15 20:41 - 2025-01-15 20:55 - 000003380 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting 2025-01-15 20:41 - 2025-01-15 20:55 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job 2025-01-15 20:41 - 2025-01-15 20:41 - 000002912 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Mouaadiib 2025-01-15 20:41 - 2025-01-15 20:41 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk 2025-01-15 20:41 - 2025-01-15 20:41 - 000000000 ____D C:\ProgramData\Piriform 2025-01-15 20:41 - 2025-01-15 20:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2025-01-15 20:11 - 2025-01-15 21:03 - 000000000 ____D C:\FRST 2025-01-15 19:58 - 2025-01-15 19:58 - 000000000 ____D C:\Users\Mouaadiib\Downloads\Autoruns 2025-01-15 10:17 - 2025-01-15 10:17 - 000027888 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_3509828591248.dll 2025-01-15 08:38 - 2025-01-15 08:38 - 000027888 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_18074943005100.dll 2025-01-15 07:32 - 2025-01-15 21:02 - 000000000 ____D C:\Users\Mouaadiib\Downloads\Outils Securité 2025-01-15 07:30 - 2025-01-15 07:30 - 002403328 _____ (Farbar) C:\Users\Mouaadiib\Desktop\FRST64.exe 2025-01-15 00:53 - 2025-01-15 00:54 - 000001740 _____ C:\Users\Mouaadiib\Desktop\kprm-20250115005354.txt 2025-01-15 00:53 - 2025-01-15 00:53 - 000000000 ____D C:\KPRM 2025-01-15 00:11 - 2025-01-15 17:25 - 000000000 ____D C:\WINDOWS\CbsTemp 2025-01-14 23:26 - 2025-01-14 23:26 - 641920034 _____ C:\registre.reg 2025-01-14 22:16 - 2025-01-15 20:16 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Malwarebytes 2025-01-14 21:46 - 2025-01-14 21:46 - 000027888 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_1035262714636.dll 2025-01-14 21:30 - 2025-01-14 21:30 - 000027888 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_553579715604.dll 2025-01-14 21:21 - 2025-01-14 21:21 - 000027888 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_150039018905364.dll 2025-01-14 15:39 - 2025-01-14 21:29 - 000000000 ____D C:\Program Files\Mozilla Thunderbird 2025-01-09 20:34 - 2025-01-09 20:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cloudflare 2025-01-08 21:14 - 2025-01-08 21:14 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\Hulubulu 2025-01-08 21:13 - 2025-01-08 21:13 - 000000885 _____ C:\Users\Mouaadiib\Desktop\Advanced Renamer.lnk 2025-01-08 21:13 - 2025-01-08 21:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Renamer 2025-01-08 21:13 - 2025-01-08 21:13 - 000000000 ____D C:\Program Files\Advanced Renamer 2025-01-02 10:41 - 2025-01-02 11:28 - 000000501 _____ C:\Users\Mouaadiib\Downloads\Citation Incontournable.txt 2024-12-30 14:51 - 2024-12-30 14:51 - 004488360 _____ C:\Users\Mouaadiib\Downloads\Snapchat-592569090.mp4 2024-12-29 22:45 - 2024-12-29 22:45 - 000000845 _____ C:\Users\Public\Desktop\Ruined King - A League of Legends Story.lnk 2024-12-27 10:38 - 2024-12-27 10:38 - 000447752 _____ (On2.com) C:\WINDOWS\SysWOW64\vp6vfw.dll 2024-12-27 10:38 - 2024-12-27 10:38 - 000001373 _____ C:\Users\Public\Desktop\Les Sims 4.lnk 2024-12-27 10:38 - 2024-12-27 10:38 - 000000000 ___HD C:\Program Files\Common Files\EAInstaller 2024-12-27 10:32 - 2024-12-27 10:32 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Link2EA 2024-12-27 09:56 - 2024-12-27 09:56 - 000048507 _____ C:\Users\Mouaadiib\Downloads\facture_9073731031_2024-12-02.pdf 2024-12-27 09:55 - 2024-12-27 09:55 - 000046750 _____ C:\Users\Mouaadiib\Downloads\facture_9010845592_2024-12-16.pdf 2024-12-27 09:54 - 2024-12-27 09:54 - 000156588 _____ C:\Users\Mouaadiib\Downloads\LNKD_INVOICE_78152574063.pdf 2024-12-27 09:40 - 2024-12-27 09:40 - 000233655 _____ C:\Users\Mouaadiib\Downloads\2024-12-27_093916.pdf 2024-12-27 09:32 - 2024-12-27 09:32 - 000010610 _____ C:\Users\Mouaadiib\Downloads\facture 1 mr charretier.pdf 2024-12-27 09:32 - 2024-12-27 09:32 - 000010514 _____ C:\Users\Mouaadiib\Downloads\facture 2 mr charretier.pdf 2024-12-24 13:55 - 2024-12-24 13:55 - 000001590 _____ C:\Users\Mouaadiib\Downloads\Demande Application.txt 2024-12-24 13:53 - 2024-12-24 13:53 - 000006960 _____ C:\Users\Mouaadiib\Downloads\The Blacklist.txt 2024-12-23 16:20 - 2024-12-23 16:20 - 000094990 _____ C:\Users\Mouaadiib\Downloads\OkadiObaibi_a679b363-eb43-4ada-a225-6df07aca00b7_XCZWGAATFO.pdf 2024-12-22 21:42 - 2024-12-22 21:42 - 000654683 _____ C:\Users\Mouaadiib\Downloads\ticketdirect1672989345 (1).pdf 2024-12-21 21:40 - 2024-12-21 21:40 - 000000000 ____D C:\Users\Mouaadiib\Documents\Electronic Arts ==================== Un mois (modifiés) ================== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2025-01-15 21:02 - 2024-12-07 00:01 - 002374618 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2025-01-15 21:02 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF 2025-01-15 20:58 - 2020-09-26 17:44 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat 2025-01-15 20:57 - 2020-09-26 17:52 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\discord 2025-01-15 20:56 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness 2025-01-15 20:56 - 2022-07-07 18:50 - 000000000 ____D C:\ProgramData\Cloudflare 2025-01-15 20:55 - 2024-12-06 23:58 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2025-01-15 20:55 - 2024-12-06 23:53 - 000009928 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 2025-01-15 20:55 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp 2025-01-15 20:55 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2025-01-15 20:55 - 2021-10-03 09:34 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Oculus 2025-01-15 20:55 - 2021-05-27 18:00 - 000000000 ____D C:\Program Files\TeamViewer 2025-01-15 20:55 - 2021-03-30 18:33 - 000012288 ___SH C:\DumpStack.log.tmp 2025-01-15 20:55 - 2020-12-13 19:05 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\WTablet 2025-01-15 20:55 - 2020-09-26 18:12 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\CrashDumps 2025-01-15 20:55 - 2020-09-26 18:05 - 000000000 ____D C:\ProgramData\NVIDIA 2025-01-15 20:55 - 2020-09-26 17:52 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Discord 2025-01-15 20:54 - 2024-12-06 19:25 - 000000000 ____D C:\Users\Mouaadiib 2025-01-15 20:54 - 2024-04-01 08:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2025-01-15 20:54 - 2020-09-26 17:52 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\qBittorrent 2025-01-15 20:45 - 2020-09-26 18:04 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\JDownloader 2.0 2025-01-15 20:42 - 2024-09-02 19:26 - 000000000 ____D C:\Program Files (x86)\TVRename 2025-01-15 20:42 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps 2025-01-15 20:42 - 2023-10-12 20:23 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Voice ai 2025-01-15 20:41 - 2020-09-26 18:14 - 000000000 ____D C:\Program Files\NewBlue 2025-01-15 20:41 - 2020-09-26 18:14 - 000000000 ____D C:\Program Files (x86)\NewBlue 2025-01-15 20:39 - 2023-09-18 07:49 - 000000000 ____D C:\ProgramData\SUPPORTDIR 2025-01-15 20:39 - 2020-12-15 20:50 - 000000000 ____D C:\Program Files (x86)\NSIS Uninstall Information 2025-01-15 20:39 - 2020-09-26 18:14 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2025-01-15 20:39 - 2020-09-26 18:09 - 000000000 ____D C:\ProgramData\install_clap 2025-01-15 20:28 - 2022-11-05 09:44 - 000000000 ____D C:\Program Files\Malwarebytes 2025-01-15 19:57 - 2022-02-09 20:00 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2025-01-15 19:25 - 2024-12-06 23:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2025-01-15 15:27 - 2020-09-26 19:50 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\EasyAntiCheat 2025-01-15 07:41 - 2020-09-26 17:47 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\D3DSCache 2025-01-15 00:42 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\USOPrivate 2025-01-15 00:41 - 2023-12-30 22:53 - 000002916 _____ C:\Users\Mouaadiib\Downloads\Citations Films.txt 2025-01-15 00:26 - 2024-12-06 23:51 - 001324152 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2025-01-15 00:19 - 2021-09-11 15:50 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware 2025-01-15 00:18 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources 2025-01-15 00:18 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Sgrm 2025-01-15 00:18 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2025-01-15 00:18 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr 2025-01-15 00:18 - 2020-09-26 19:57 - 000000000 ____D C:\WINDOWS\system32\MRT 2025-01-15 00:17 - 2022-07-07 18:50 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Cloudflare 2025-01-15 00:15 - 2020-09-26 19:57 - 206927936 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2025-01-14 22:23 - 2020-09-26 17:50 - 000000000 ____D C:\Program Files (x86)\Steam 2025-01-14 22:19 - 2020-09-26 18:09 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\PlaceholderTileLogoFolder 2025-01-14 22:19 - 2020-09-26 17:47 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Packages 2025-01-14 22:08 - 2024-12-06 23:58 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2896008330-159720710-2358065777-1001 2025-01-14 22:08 - 2024-12-06 23:58 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2896008330-159720710-2358065777-1001 2025-01-14 22:08 - 2021-03-30 18:34 - 000002429 _____ C:\Users\Mouaadiib\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2025-01-14 22:00 - 2020-09-26 17:51 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Steam 2025-01-14 21:50 - 2020-10-16 09:42 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\ElevatedDiagnostics 2025-01-14 21:44 - 2024-12-06 23:58 - 000003834 _____ C:\WINDOWS\system32\Tasks\NVIDIA app SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2025-01-14 21:44 - 2024-11-15 22:01 - 000001430 _____ C:\Users\Public\Desktop\NVIDIA.lnk 2025-01-14 21:44 - 2020-09-26 18:07 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\NVIDIA Corporation 2025-01-14 21:44 - 2020-09-26 18:05 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2025-01-14 21:29 - 2020-09-26 22:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2025-01-14 15:47 - 2022-07-10 09:46 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk 2025-01-14 10:19 - 2020-09-26 18:08 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\Microsoft\Word 2025-01-14 09:56 - 2024-12-06 23:58 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP 2025-01-14 09:56 - 2021-05-08 08:36 - 000000000 ____D C:\Program Files\HPPrintScanDoctor 2025-01-14 00:20 - 2020-09-26 18:04 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\vlc 2025-01-11 08:37 - 2020-09-26 17:51 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2025-01-11 08:37 - 2020-09-26 17:51 - 000002280 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2025-01-08 08:32 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth 2025-01-08 08:07 - 2024-12-12 13:26 - 000000000 ____D C:\Program Files\Mozilla Firefox 2025-01-07 22:21 - 2024-12-06 23:58 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2025-01-07 22:21 - 2020-09-26 22:50 - 000001069 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2025-01-07 22:21 - 2020-09-26 22:50 - 000001057 _____ C:\Users\Public\Desktop\Firefox.lnk 2025-01-07 18:37 - 2024-10-21 16:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NordSec 2025-01-07 18:37 - 2024-10-21 16:55 - 000000000 ____D C:\Program Files\NordVPN 2025-01-01 20:24 - 2020-09-26 17:54 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2025-01-01 16:57 - 2024-12-12 17:29 - 000000000 ____D C:\Users\Mouaadiib\Downloads\Logo Movie 2025-01-01 12:06 - 2024-09-02 19:05 - 000000000 ____D C:\Tiktok 2024-12-31 13:36 - 2024-09-29 11:32 - 000003074 _____ C:\Users\Mouaadiib\Downloads\Citation faites.txt 2024-12-31 08:09 - 2024-11-30 17:27 - 134222904 _____ C:\WINDOWS\392667600.dat 2024-12-30 11:38 - 2022-05-25 12:42 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Ubisoft Game Launcher 2024-12-27 10:35 - 2023-08-06 13:13 - 000000000 ____D C:\ProgramData\EA Desktop 2024-12-27 10:35 - 2023-08-06 13:13 - 000000000 ____D C:\Program Files\EA Games 2024-12-26 12:01 - 2021-01-11 21:17 - 000000000 ____D C:\Users\Mouaadiib\Bibliothèque calibre 2024-12-26 12:01 - 2021-01-11 21:13 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\calibre 2024-12-22 08:21 - 2024-12-06 23:58 - 000003690 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2024-12-22 08:21 - 2024-12-06 23:58 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2024-12-21 21:42 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2024-12-20 22:13 - 2022-11-05 13:01 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\TikTok LIVE Studio 2024-12-20 22:09 - 2022-11-05 13:00 - 000000000 ____D C:\Program Files (x86)\TikTok LIVE Studio 2024-12-20 19:45 - 2022-11-05 13:00 - 000001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TikTok LIVE Studio.lnk 2024-12-20 19:45 - 2022-11-05 13:00 - 000001366 _____ C:\Users\Public\Desktop\TikTok LIVE Studio.lnk 2024-12-20 19:44 - 2022-08-24 20:08 - 000000000 ____D C:\Users\Mouaadiib\AppData\Local\Bytedance 2024-12-18 13:26 - 2024-11-15 22:01 - 003074088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2024-12-18 13:26 - 2024-11-15 22:01 - 002369064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2024-12-18 13:26 - 2020-11-11 09:30 - 000270888 _____ C:\WINDOWS\system32\FvSDK_x64.dll 2024-12-18 13:26 - 2020-11-11 09:30 - 000245288 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll 2024-12-18 13:07 - 2020-09-26 18:05 - 000180760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll 2024-12-18 13:07 - 2020-09-26 18:05 - 000159768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2024-12-18 13:06 - 2021-10-03 08:05 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat 2024-12-18 10:13 - 2024-12-06 18:39 - 000000000 ___DC C:\WINDOWS\Panther 2024-12-17 10:44 - 2020-12-06 12:22 - 000000000 ____D C:\Users\Mouaadiib\AppData\Roaming\Microsoft\Excel ==================== Fichiers à la racine de certains dossiers ======== 2024-11-01 21:56 - 2024-11-01 21:57 - 000000078 _____ () C:\Users\Mouaadiib\AppData\Roaming\.flutter 2024-11-01 21:56 - 2024-11-01 22:15 - 000000076 _____ () C:\Users\Mouaadiib\AppData\Roaming\.flutter_tool_state 2020-10-28 19:29 - 2020-10-28 19:29 - 000000171 _____ () C:\Users\Mouaadiib\AppData\Roaming\822f02e4-9e9a-4077-a765-71edfca16ad0 2023-10-20 13:28 - 2023-10-20 13:28 - 000978542 _____ () C:\Users\Mouaadiib\AppData\Roaming\cloverleaf.asp 2021-11-26 22:26 - 2021-11-26 22:29 - 000012288 _____ () C:\Users\Mouaadiib\AppData\Roaming\emp.bin 2022-06-25 17:22 - 2022-05-01 08:09 - 000000701 _____ () C:\Users\Mouaadiib\AppData\Roaming\nefcodec.dll 2022-08-15 13:32 - 2022-09-15 08:20 - 000000016 _____ () C:\Users\Mouaadiib\AppData\Roaming\obs-virtualcam.txt 2022-06-25 17:23 - 2022-06-25 23:34 - 000000019 _____ () C:\Users\Mouaadiib\AppData\Roaming\settingnef.ini 2023-10-20 13:28 - 2023-10-20 13:28 - 003654872 _____ (ThinPrint GmbH) C:\Users\Mouaadiib\AppData\Roaming\TPAutoConnect.old 2024-12-07 22:14 - 2024-12-07 22:14 - 000000048 ____R () C:\Users\Mouaadiib\AppData\Local\69FAD8045114D070AF5389968070E19F 2020-09-26 18:06 - 2024-04-20 10:19 - 000000615 _____ () C:\Users\Mouaadiib\AppData\Local\oobelibMkey.log 2021-09-11 14:38 - 2021-09-11 14:38 - 000007615 _____ () C:\Users\Mouaadiib\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) ==================== Fin de FRST.txt ========================