Mon PC est lent depuis une installation
Fermé
Pyradax
Messages postés
13
Date d'inscription
mercredi 15 avril 2020
Statut
Membre
Dernière intervention
4 novembre 2024
-
19 avril 2020 à 17:29
billmaxime Messages postés 50434 Date d'inscription dimanche 20 novembre 2011 Statut Contributeur Dernière intervention 15 décembre 2024 - 20 avril 2020 à 22:28
billmaxime Messages postés 50434 Date d'inscription dimanche 20 novembre 2011 Statut Contributeur Dernière intervention 15 décembre 2024 - 20 avril 2020 à 22:28
A voir également:
- Epowerbutton_nb
- Mon pc est lent - Guide
- Test performance pc - Guide
- Mon mac est lent comment le nettoyer - Guide
- Reinitialiser pc - Guide
- Mon pc est trop lent et se bloque - Guide
7 réponses
billmaxime
Messages postés
50434
Date d'inscription
dimanche 20 novembre 2011
Statut
Contributeur
Dernière intervention
15 décembre 2024
6 008
19 avril 2020 à 17:47
19 avril 2020 à 17:47
salut
fait ceci et poste les rapports
télécharge FRST de (Fabar) sur ton bureau --> clique ici
PS: prends celui correspondant à ton pc (32 ou 64 bits) --> clique ici
exécute le en tant qu'administrateur (clic droit)
à la fin du scan, les rapports FRST et ADDITION s'afficheront sur ton bureau et dans C:\FRST\LOG
poste les rapports via cjoint --> clique ici
@+
fait ceci et poste les rapports
télécharge FRST de (Fabar) sur ton bureau --> clique ici
PS: prends celui correspondant à ton pc (32 ou 64 bits) --> clique ici
exécute le en tant qu'administrateur (clic droit)
à la fin du scan, les rapports FRST et ADDITION s'afficheront sur ton bureau et dans C:\FRST\LOG
poste les rapports via cjoint --> clique ici
@+
Pyradax
Messages postés
13
Date d'inscription
mercredi 15 avril 2020
Statut
Membre
Dernière intervention
4 novembre 2024
20 avril 2020 à 18:46
20 avril 2020 à 18:46
Résultat du Scan FRST :
Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 19-04-2020
Exécuté par aubry (administrateur) sur LAPTOP-FECASOB5 (Acer Aspire E5-772G) (20-04-2020 16:24:22)
Exécuté depuis C:\Users\aubry\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads
Profils chargés: aubry (Profils disponibles: aubry)
Platform: Windows 10 Home Version 1809 17763.1158 (X64) Langue: Français (France)
Navigateur par défaut: Edge
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processus (Avec liste blanche) =================
(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)
(Acer Incorporated -> ) C:\OEM\Preload\FubTracking\FubTracking.exe
(Acer Incorporated -> ) C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAdminAgent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAgent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALockHandler.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALSvc.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe <3>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(Amazon Services LLC -> ) C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\SecureLine\Vpn.exe <2>
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
(CACAOWEB Ltd -> ) C:\Users\aubry\AppData\Roaming\cacaoweb\cacaoweb.exe
(Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(Dashlane -> Dashlane SAS) C:\Program Files (x86)\Dashlane\Upgrade\DashlaneUpgradeService.exe
(Filseclab Corporation -> Filseclab Corporation Limited) C:\Program Files (x86)\ScreenShot\SSSvc.exe
(Google LLC -> Google LLC) C:\Users\aubry\AppData\Local\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Users\aubry\AppData\Local\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) [Fichier non signé] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation -> © 2015 Microsoft Corporation) C:\Users\aubry\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\aubry\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12004.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe <5>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mshta.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(Node.js Foundation -> Node.js) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe
==================== Registre (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16418560 2016-01-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2631824 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1710056 2015-07-14] (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [Fichier non signé]
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1284680 2014-01-17] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2042424 2020-03-16] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646160 2019-12-11] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Chromium] => "c:\users\aubry\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [cacaoweb] => C:\Users\aubry\AppData\Roaming\cacaoweb\cacaoweb.exe [567192 2018-09-03] (CACAOWEB Ltd -> )
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [BingSvc] => C:\Users\aubry\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (Microsoft Corporation -> © 2015 Microsoft Corporation)
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Dashlane] => "C:\Users\aubry\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Google Update] => C:\Users\aubry\AppData\Local\Google\Update\1.3.35.452\GoogleUpdateCore.exe [217544 2020-03-20] (Google LLC -> Google LLC)
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3371296 2020-04-04] (Valve -> Valve Corporation)
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [648328 2020-03-09] (Adobe Inc. -> Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast SecureLine VPN.lnk [2019-12-08]
ShortcutTarget: Avast SecureLine VPN.lnk -> C:\Program Files\AVAST Software\SecureLine\Vpn.exe (AVAST Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAndroidAppHelper.lnk [2020-01-19]
ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAndroidAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAppHelper.lnk [2020-01-19]
ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft)
GroupPolicy: Restriction ? <==== ATTENTION
==================== Tâches planifiées (Avec liste blanche) ============
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
Task: {0E2227A7-6873-4894-8A5D-00C5C235119B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3743041002-4164144641-2799150064-1001Core => C:\Users\aubry\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-10-13] (Google Inc -> Google Inc.)
Task: {19FD2D84-C017-4B10-97A6-6F304F1EC839} - System32\Tasks\{1B840C4B-BC8D-6B3D-0DC9-6C9908A0B0F8} => C:\Users\aubry\AppData\Roaming\1b840c4bbc8d6b3d0dc96c9908a0b0f8\updane.exe [920064 2013-05-02] () [Fichier non signé]
Task: {1EA27249-CD79-497D-B053-749822E0E53B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3743041002-4164144641-2799150064-1001UA => C:\Users\aubry\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-10-13] (Google Inc -> Google Inc.)
Task: {1F458393-C714-4FC8-9EC2-D45EC0070CFD} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [384256 2015-05-14] (Acer Incorporated -> Acer Incorporated)
Task: {22261FCB-F8AA-4F72-B1D2-D4F842F853BE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {2FDEF2A6-0B44-4D5E-95CF-A9E152CEFD02} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
Task: {4F117C79-2706-4FBF-A748-C0259F51CEFA} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [472928 2015-07-10] (Acer Incorporated -> Acer Incorporated)
Task: {4F3AF95E-5BCB-4948-BB1A-5070B1E60830} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-aubry.dreano@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {67B17592-110C-46A2-B0E4-B62F2D6BFABB} - System32\Tasks\Pakipabobe\{6CBEEB67-58B8-EEF2-9892-72B765354EE9} => C:\Users\aubry\AppData\Roaming\brick\PAKIPA~1.EXE
Task: {6A1AECEC-0766-473B-AE79-EAAA31DE758F} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [40288 2015-07-10] (Acer Incorporated -> )
Task: {6A204B36-9C2A-4929-BF5D-54742FBC4ED9} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} - System32\Tasks\ACCBackgroundApplication => C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [4696880 2018-05-28] (Acer Incorporated -> )
Task: {739CBB63-10C1-46DB-B3ED-8322A659DCEC} - System32\Tasks\Tudaco\{6CBEEB67-58B8-EEF2-9892-72B765354EE9} => C:\Users\aubry\AppData\Roaming\brick\Tudaco.exe [2351104 2013-04-20] () [Fichier non signé]
Task: {75DCAE8B-0C8C-478C-9471-3D1BE5937D01} - System32\Tasks\Ralul\{6CBEEB67-58B8-EEF2-9892-72B765354EE9} => C:\Users\aubry\AppData\Roaming\brick\Ralul.exe [500224 2013-04-09] () [Fichier non signé]
Task: {7A92FCF9-005C-44B4-BF05-E1EEE39AEB98} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [383840 2015-09-04] (Acer Incorporated -> Acer Incorporated)
Task: {83B9987E-5C97-4FB5-B1E8-CC9097BD8C9F} - System32\Tasks\{1793B6A0-BA2A-8EFD-C071-3692DB5E39E6} => C:\Users\aubry\AppData\Roaming\Gopego\TOPADO~1.EXE [629248 2013-05-04] () [Fichier non signé]
Task: {86B3B092-08E0-48D2-8030-18E73C3EFBBD} - System32\Tasks\Borutunube\{6CBEEB67-58B8-EEF2-9892-72B765354EE9} => C:\Users\aubry\AppData\Roaming\brick\BORUTU~1.EXE
Task: {92341393-6805-4A86-B2F5-5F66C8C9C943} - System32\Tasks\FUBTrackingByPLD => C:\OEM\Preload\FubTracking\FubTracking.exe [30976 2015-05-14] (Acer Incorporated -> )
Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - System32\Tasks\Avast SecureLine => C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [3438680 2016-05-24] (AVAST Software a.s. -> AVAST Software)
Task: {9A84FE45-ED70-485C-92BE-85EA1DC73560} - System32\Tasks\App Explorer => C:\Users\aubry\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe <==== ATTENTION
Task: {A3B6CEC7-72E5-4253-87C3-BEC11844AE1C} - System32\Tasks\Secured Yahoo Powered ditel => C:\Windows\system32\wscript.exe "C:\ProgramData\{395BFC38-B319-76FE-35DF-E8BCAF9D6372}\lido" "68747470733a2f2f64337331746b67396634323534712e636c6f756466726f6e742e6e6574" "433a5c50726f6772616d446174615c7b33393542464333382d423331392d373646452d333544462d4538424341463944363337327d5c636f73656e6f" "433a5c50726f6772616d446174615c7b333935 (l'élément de données a 116 caractères en plus).
Task: {AA0B7D74-B8EC-4B03-B638-379AA1ED5E41} - System32\Tasks\Avast SecureLine VPN Update => c:\program files\avast software\secureline\vpnupdate.exe [1390472 2019-11-16] (AVAST Software s.r.o. -> AVAST Software)
Task: {B71D84D9-3140-4413-9086-27B3DFEA6FFB} - System32\Tasks\{72939656-6F1F-4437-90E5-9113625D2ECF} => "c:\windows\system32\launchwinapp.exe" hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.22.0.109&LastError=404
Task: {CE64CD54-EBDE-41F8-9A2E-BE8972E2846C} - System32\Tasks\sedelonola\{0B0ACF0C-4CB8-A4B5-98F2-079851D2A57B} => C:\Users\aubry\AppData\Roaming\0b0acf0c4cb8a4b598f20\sedelonola.exe [2174464 2013-04-29] () [Fichier non signé]
Task: {D2C60EC1-91E4-4851-A533-D0DC4D8D5DC1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {D39AEEDA-9A0A-4832-9753-B66C7F23309B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {D7CB4FE6-DA9A-4B2B-A1E9-1DF9D989E89B} - System32\Tasks\Power Button => C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe [2770688 2015-05-14] (Acer Incorporated -> Acer Incorporated)
Task: {DE02721D-8C8B-4C2E-9C76-917E15F182BC} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {EF688526-6C65-42F1-B1B3-AA4AB13C08E3} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [65752 2017-03-20] (Acer Incorporated -> Acer Incorporated)
Task: {FBE1992D-A1B2-44DD-9601-A1A2F799B096} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2920752 2018-05-28] (Acer Incorporated -> )
(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)
Task: C:\WINDOWS\Tasks\Secured Yahoo Powered ditel.job => Wscript exe
Task: C:\WINDOWS\Tasks\{1793B6A0-BA2A-8EFD-C071-3692DB5E39E6}.job => C:\Users\aubry\AppData\Roaming\Gopego\TOPADO~1.EXE
Task: C:\WINDOWS\Tasks\{1B840C4B-BC8D-6B3D-0DC9-6C9908A0B0F8}.job => C:\Users\aubry\AppData\Roaming\1B840C~1\updane.exe <==== ATTENTION
==================== Internet (Avec liste blanche) ====================
(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{b233b376-bd0b-4936-8ee9-c0cd95545095}: [DhcpNameServer] 192.17.128.24
Tcpip\..\Interfaces\{e0bcf4e1-ee05-49d5-b4ba-9c28065345cf}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=shnl&hsimp=yhs-001&type=c110d0dc585dc49770830874990¶m1=IE¶m2=1¶m3=campaignID%3D113%26UserID%3D1054629261¶m4=XPbueSzfBeG6K2MlxBpfELmmgzh8mOsLvk1mNxKnkuDQzAGYaclIXjiYGxEsx2yN4hFTH1CPkETBiBKHFz+GQ+EL0TTnafB8KbRFu5RAu1+yzlYZvE45/a+f/QtDV5R1cyCEZmQAxVMQkQ8GftukH7KKIP9OBwyoELeCMWlcu3Fyf5eBqUz0IQmRawETVER4hk0YGXa1Z39ah93C1yAei1qru5KJZzoXd5duK5q3FLvSzk9epT9PwDOaghNKSHvoTHYgmZMKY2XrD1DLIEVRpwuFYz+WUgCyfxXvWSpkF04BLjdq8F4zSxoZFksEV1gC2p8ZmEdjeYyrv+79qPq9jAFflmWbMtDZqIREPgi5znWhJS42nwkUcpVWp/n+as6pB7RGv20tBWkPgiZX3ewXof3qxhP0qRZaur1mGoi6gLGQZpPcbokhDn8wcsrSLfAek1O/U+ykSOPGuSZSNcHJt+N5/pB6aek1ouZtlyjR/XxHcj4ZX+YOVKKXMDnkEvDS/csX9eEHsurhMmGgPkjxnDBuz21Nq+LTLnMxTWpzeFc+Z2yNoCagAxH4lXu4NbvhYWc38JBw3rXgHc1fQeUUweWbeI/ZgrZQgFqWDpZJ7kXEBUSBbjuqTfVqTI3kfFEj+jsbv2sgm1klgQN5xYZ5uciTuMtoOa5h8+JNTvja2DXdN70B5qv7Yb0M8yKMfwtX94wCPJTbPZ4pIzOAfssVyQ==
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.monconvertisseur.com/?source=gdfrcosc728290-iei&uid=a29f715d-15b5-285f-5d0c-5ce4a7589abe&i_id=converter__1.30&uc=20190629&ap=romb
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer15.msn.com/?pc=ACTE
SearchScopes: HKLM -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKLM -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKLM -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM -> {f79e5d1c-5148-469e-9f98-a11d8d7863f4} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKLM-x32 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKLM-x32 -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> {f79e5d1c-5148-469e-9f98-a11d8d7863f4} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\.DEFAULT -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL =
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> DefaultScope {33F660BB-482C-4070-A8F2-45C0CB6003E6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL =
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {33F660BB-482C-4070-A8F2-45C0CB6003E6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {6D9D88A1-FEF4-4891-A806-E279252FCC4C} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {7E9949AB-6011-46E8-8FA8-C9033ADA4597} URL = hxxps://fr.search.yahoo.com/search?fr=mcafee&type=C011FR662D20160218&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxp://query.monconvertisseur.com/s?source=gdfrcosc728290-iei&uid=a29f715d-15b5-285f-5d0c-5ce4a7589abe&i_id=converter__1.30&uc=20190629&ap=romb&query={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {f79e5d1c-5148-469e-9f98-a11d8d7863f4} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
BHO: Amazon Assistant -> {0ddcea2a-7b00-4349-8acb-af7ba6da251f} -> C:\Program Files (x86)\Amazon\Amazon Assistant\aaMessenger.dll [2018-02-22] (Amazon Services LLC -> )
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (Canon Inc. -> CANON INC.)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll => Pas de fichier
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation -> Microsoft Corporation)
BHO: OffresShopping -> {F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB} -> C:\Program Files\ItinéraireInfoInstaller\BHO.dll [2015-02-10] (Prestafind) [Fichier non signé]
BHO-x32: Amazon Assistant -> {0ddcea2a-7b00-4349-8acb-af7ba6da251f} -> C:\Program Files (x86)\Amazon\Amazon Assistant\aaMessenger.dll [2018-02-22] (Amazon Services LLC -> )
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Users\aubry\Documents\Minecraft\bin\ssv.dll [2020-04-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll => Pas de fichier
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Users\aubry\Documents\Minecraft\bin\jp2ssv.dll [2020-04-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: OffresShopping -> {F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB} -> C:\Program Files (x86)\ItinéraireInfoInstaller\BHO.dll [2015-02-10] (Prestafind) [Fichier non signé]
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (Canon Inc. -> CANON INC.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll Pas de fichier
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll Pas de fichier
Edge:
======
DownloadDir: C:\Users\aubry\Downloads
Edge Notifications: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> hxxps://www.marmiton.org
FireFox:
========
FF DefaultProfile: 5p0v3990.default
FF ProfilePath: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default [2020-03-20]
FF Homepage: Mozilla\Firefox\Profiles\5p0v3990.default -> hxxps://fr.search.yahoo.com/yhs/web?hspart=coco&hsimp=yhs-001&type=7ZMihdXhSES7iOliRQieetQO¶m2=XPbueSzfBeG6K2MlxBpfEEdaMnVz4fEPIxImUbRDFbSlltbkA92Q%2bNtDImiu0fRpDv0rk4kOah9uIx3SvMiwvaSf3LCQyz4OKdhWMQm2ERM65gyQ9c6%2fUqFS%2bjYkR10if3G8lYZxXERcuqAgvBXi7%2bcCCoce6kK5mpQT2r4VbTnVfPX%2bEHQia1zAo6QNFNrDpTJWJCYTrL%2b%2fWXdt45HikHL4TozpWnuDmrP9xfcDcKSd2fvkdVBJLALaPAydhHk7zRarH7i3TqwoByPM5H6STSY%2bD3z4VnlDxh6q4EUq7lmjijtDqG5%2bUMJVFVehGl9vgMs5yxuyyU%2fi3wzaMWqUYrLs2AYIZ4lyH3HrO%2bXbUUOnFWxTbqbHSFosdTLjqWY4uzRIRoAi2zG6ZI%2fVVTueyC6HINOUHeTQwqPgubyRRnVGYD5VWGNCFPr3oSC2JtmEHTI3gG6fQ2VDYYfFVISqwv7hRb3SSpXA3yz3pWy4qJFGKhZ2gTDr6IqvtQYBHhf3%2b2IC563r7T1JgkfVuj0Hln%2f2UMysMKU9FLGZSwHo69Y4WM9L1mxSanvaq3pFUpC3gTgdTj7aEowWMotG6rthFbfkUSnfuAUizrzjo%2bb6F%2fl4NcvREYbcuBCS3ff3amaS~vi06X1TR0Z02
FF Extension: (Amazon Assistant for Firefox) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\abb@amazon.com.xpi [2016-02-17] []
FF Extension: (Bing Search) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\bingsearch.full@microsoft.com.xpi [2017-03-30] []
FF Extension: (cacaoweb) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\cacaoweb@cacaoweb.org [2016-03-18] [] [non signé]
FF Extension: (Dashlane) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\jetpack-extension@dashlane.com.xpi [2017-01-05] []
FF Extension: (Français Language Pack) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\langpack-fr@firefox.mozilla.org [2016-02-17] [] [non signé]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\bing provided search.xml [2018-12-12]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\bing search engine.xml [2020-03-20]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\bing-.xml [2017-03-30]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\Search Provided by Yahoo.xml [2016-03-05]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\Web Search.xml [2016-02-20]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\YHS Search.xml [2016-05-30]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => non trouvé(e)
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi => non trouvé(e)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2020-03-16] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.) [Fichier non signé]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.241.2 -> C:\Users\aubry\Documents\Minecraft\bin\dtplugin\npDeployJava1.dll [2020-04-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.241.2 -> C:\Users\aubry\Documents\Minecraft\bin\plugin2\npjp2.dll [2020-04-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2020-03-16] (Adobe Inc. -> Adobe Systems)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR Profile: C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default [2020-03-20]
CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?fr=mcafee&type=D211FR662G0&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
CHR Extension: (Slides) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-13]
CHR Extension: (Selected Search) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\afgeoapebnkefelmpoepnmjiflidjjce [2019-12-19]
CHR Extension: (Docs) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-24]
CHR Extension: (Google Drive) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-24]
CHR Extension: (The Search Selector) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhdinjalofclbacjijgifpahcnjapclb [2020-03-20]
CHR Extension: (YouTube) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-24]
CHR Extension: (Sheets) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-10-13]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-01-09]
CHR Extension: (Google Docs hors connexion) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-11-24]
CHR Extension: (Search Selector) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\iicdcmjmlnliniifciehlchmdepfndfn [2019-12-19]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-19]
CHR Extension: (Gmail) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-12-19]
CHR Extension: (Chrome Media Router) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-01-09]
CHR HKLM\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKLM\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <non trouvé(e)>
CHR HKLM\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb]
CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pfnciekpafndamlomnebbfophenfehbc]
CHR HKLM-x32\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKLM-x32\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <non trouvé(e)>
CHR HKLM-x32\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
==================== Services (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [820280 2020-03-16] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3374160 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3103824 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [105136 2018-02-22] (Amazon Services LLC -> )
R2 Dashlane Upgrade Service; C:\Program Files (x86)\Dashlane\Upgrade\DashlaneUpgradeService.exe [82944 2015-12-04] (Dashlane -> Dashlane SAS)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573568 2015-05-14] (Acer Incorporated -> Acer Incorporated)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [184064 2016-12-12] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373720 2017-06-27] (Intel(R) pGFX -> Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] (Canon Inc. -> )
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel® Trusted Connect Service -> Intel(R) Corporation)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Fichier non signé]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Fichier non signé]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-07-06] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-06-12] (Intel Corporation-Wireless Connectivity Solutions -> )
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
R3 QALSvc; C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [401248 2015-09-04] (Acer Incorporated -> Acer Incorporated)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [453984 2015-09-04] (Acer Incorporated -> Acer Incorporated)
R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [6828424 2019-11-16] (AVAST Software s.r.o. -> AVAST Software)
R2 SSSvc; C:\Program Files (x86)\ScreenShot\SSSvc.exe [139712 2017-04-24] (Filseclab Corporation -> Filseclab Corporation Limited)
S3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [247040 2015-05-27] (Acer Incorporated -> acer)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\NisSrv.exe [3917016 2018-10-24] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MsMpEng.exe [114208 2018-10-24] (Microsoft Corporation -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe [495720 2018-08-29] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [83232 2019-07-09] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 WsDrvInst; C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe [130336 2019-10-30] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831200 2015-06-12] (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
===================== Pilotes (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 ETDI2C; C:\WINDOWS\system32\DRIVERS\ETDI2C.sys [175152 2015-06-09] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronic Corp.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [253184 2016-12-12] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [31000 2018-05-15] (Acer Incorporated -> Acer Incorporated)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7708160 2018-09-15] (Microsoft Windows -> Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47976 2015-07-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 qcusbnet; C:\WINDOWS\System32\drivers\qcusbnet.sys [428600 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [25368 2018-05-15] (Acer Incorporated -> Acer Incorporated)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek Semiconductor Corp -> Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [411712 2015-05-19] (Microsoft Windows Hardware Compatibility Publisher -> Realsil Semiconductor Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46184 2018-10-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [328696 2018-10-24] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60408 2018-10-24] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
==================== Un mois (créés) ===================
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2020-04-20 16:23 - 2020-04-20 16:26 - 000000000 ____D C:\FRST
2020-04-19 01:42 - 2020-04-19 01:42 - 000000000 ___HD C:\OneDriveTemp
2020-04-15 22:50 - 2020-04-15 22:52 - 000000447 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2020-04-15 18:26 - 2020-04-15 18:26 - 005436696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 003550400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 002469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 002323696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 001709560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 001024920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 000982016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-04-15 18:25 - 2020-04-15 18:26 - 002749800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 026806784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 023463424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 020816384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 019020800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 015222272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 008907264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 007923712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 007871488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 006543528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 006318840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 006060032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 005608120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 004872704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 004695552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 004628480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003933184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003887640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 003703808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003656704 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003493376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003097600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 002942976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 002917688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-04-15 18:25 - 2020-04-15 18:25 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 002801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 002706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 002182472 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 002078392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001675008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001674480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001668968 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001465344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001465272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001346192 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-04-15 18:25 - 2020-04-15 18:25 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001257984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001249792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001200920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 001012224 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000976896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000837120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000808272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000773200 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000730112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000725904 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000672256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000661056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000649272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000638264 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000553784 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000535056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-04-15 18:25 - 2020-04-15 18:25 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000452920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-04-15 18:25 - 2020-04-15 18:25 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSATAPI.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSATAPI.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000280136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000261944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2020-04-15 18:25 - 2020-04-15 18:25 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000180736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000164152 _____ (Microsof
Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 19-04-2020
Exécuté par aubry (administrateur) sur LAPTOP-FECASOB5 (Acer Aspire E5-772G) (20-04-2020 16:24:22)
Exécuté depuis C:\Users\aubry\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads
Profils chargés: aubry (Profils disponibles: aubry)
Platform: Windows 10 Home Version 1809 17763.1158 (X64) Langue: Français (France)
Navigateur par défaut: Edge
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processus (Avec liste blanche) =================
(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)
(Acer Incorporated -> ) C:\OEM\Preload\FubTracking\FubTracking.exe
(Acer Incorporated -> ) C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAdminAgent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAgent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALockHandler.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALSvc.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Inc. -> Adobe Inc) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe <3>
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
(Adobe Systems Incorporated) C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe
(Amazon Services LLC -> ) C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\SecureLine\Vpn.exe <2>
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
(CACAOWEB Ltd -> ) C:\Users\aubry\AppData\Roaming\cacaoweb\cacaoweb.exe
(Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(Dashlane -> Dashlane SAS) C:\Program Files (x86)\Dashlane\Upgrade\DashlaneUpgradeService.exe
(Filseclab Corporation -> Filseclab Corporation Limited) C:\Program Files (x86)\ScreenShot\SSSvc.exe
(Google LLC -> Google LLC) C:\Users\aubry\AppData\Local\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Users\aubry\AppData\Local\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) [Fichier non signé] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation -> © 2015 Microsoft Corporation) C:\Users\aubry\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\aubry\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12004.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe <5>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\mshta.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Node.js Foundation -> Node.js) C:\Program Files\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(Node.js Foundation -> Node.js) C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe
==================== Registre (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16418560 2016-01-14] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2631824 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1710056 2015-07-14] (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [Fichier non signé]
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1284680 2014-01-17] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2042424 2020-03-16] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646160 2019-12-11] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Chromium] => "c:\users\aubry\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [cacaoweb] => C:\Users\aubry\AppData\Roaming\cacaoweb\cacaoweb.exe [567192 2018-09-03] (CACAOWEB Ltd -> )
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [BingSvc] => C:\Users\aubry\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (Microsoft Corporation -> © 2015 Microsoft Corporation)
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Dashlane] => "C:\Users\aubry\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Google Update] => C:\Users\aubry\AppData\Local\Google\Update\1.3.35.452\GoogleUpdateCore.exe [217544 2020-03-20] (Google LLC -> Google LLC)
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3371296 2020-04-04] (Valve -> Valve Corporation)
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [CCXProcess] => C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [648328 2020-03-09] (Adobe Inc. -> Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast SecureLine VPN.lnk [2019-12-08]
ShortcutTarget: Avast SecureLine VPN.lnk -> C:\Program Files\AVAST Software\SecureLine\Vpn.exe (AVAST Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAndroidAppHelper.lnk [2020-01-19]
ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAndroidAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAppHelper.lnk [2020-01-19]
ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft)
GroupPolicy: Restriction ? <==== ATTENTION
==================== Tâches planifiées (Avec liste blanche) ============
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
Task: {0E2227A7-6873-4894-8A5D-00C5C235119B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3743041002-4164144641-2799150064-1001Core => C:\Users\aubry\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-10-13] (Google Inc -> Google Inc.)
Task: {19FD2D84-C017-4B10-97A6-6F304F1EC839} - System32\Tasks\{1B840C4B-BC8D-6B3D-0DC9-6C9908A0B0F8} => C:\Users\aubry\AppData\Roaming\1b840c4bbc8d6b3d0dc96c9908a0b0f8\updane.exe [920064 2013-05-02] () [Fichier non signé]
Task: {1EA27249-CD79-497D-B053-749822E0E53B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3743041002-4164144641-2799150064-1001UA => C:\Users\aubry\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-10-13] (Google Inc -> Google Inc.)
Task: {1F458393-C714-4FC8-9EC2-D45EC0070CFD} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [384256 2015-05-14] (Acer Incorporated -> Acer Incorporated)
Task: {22261FCB-F8AA-4F72-B1D2-D4F842F853BE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {2FDEF2A6-0B44-4D5E-95CF-A9E152CEFD02} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
Task: {4F117C79-2706-4FBF-A748-C0259F51CEFA} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [472928 2015-07-10] (Acer Incorporated -> Acer Incorporated)
Task: {4F3AF95E-5BCB-4948-BB1A-5070B1E60830} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-aubry.dreano@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {67B17592-110C-46A2-B0E4-B62F2D6BFABB} - System32\Tasks\Pakipabobe\{6CBEEB67-58B8-EEF2-9892-72B765354EE9} => C:\Users\aubry\AppData\Roaming\brick\PAKIPA~1.EXE
Task: {6A1AECEC-0766-473B-AE79-EAAA31DE758F} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [40288 2015-07-10] (Acer Incorporated -> )
Task: {6A204B36-9C2A-4929-BF5D-54742FBC4ED9} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} - System32\Tasks\ACCBackgroundApplication => C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [4696880 2018-05-28] (Acer Incorporated -> )
Task: {739CBB63-10C1-46DB-B3ED-8322A659DCEC} - System32\Tasks\Tudaco\{6CBEEB67-58B8-EEF2-9892-72B765354EE9} => C:\Users\aubry\AppData\Roaming\brick\Tudaco.exe [2351104 2013-04-20] () [Fichier non signé]
Task: {75DCAE8B-0C8C-478C-9471-3D1BE5937D01} - System32\Tasks\Ralul\{6CBEEB67-58B8-EEF2-9892-72B765354EE9} => C:\Users\aubry\AppData\Roaming\brick\Ralul.exe [500224 2013-04-09] () [Fichier non signé]
Task: {7A92FCF9-005C-44B4-BF05-E1EEE39AEB98} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [383840 2015-09-04] (Acer Incorporated -> Acer Incorporated)
Task: {83B9987E-5C97-4FB5-B1E8-CC9097BD8C9F} - System32\Tasks\{1793B6A0-BA2A-8EFD-C071-3692DB5E39E6} => C:\Users\aubry\AppData\Roaming\Gopego\TOPADO~1.EXE [629248 2013-05-04] () [Fichier non signé]
Task: {86B3B092-08E0-48D2-8030-18E73C3EFBBD} - System32\Tasks\Borutunube\{6CBEEB67-58B8-EEF2-9892-72B765354EE9} => C:\Users\aubry\AppData\Roaming\brick\BORUTU~1.EXE
Task: {92341393-6805-4A86-B2F5-5F66C8C9C943} - System32\Tasks\FUBTrackingByPLD => C:\OEM\Preload\FubTracking\FubTracking.exe [30976 2015-05-14] (Acer Incorporated -> )
Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - System32\Tasks\Avast SecureLine => C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [3438680 2016-05-24] (AVAST Software a.s. -> AVAST Software)
Task: {9A84FE45-ED70-485C-92BE-85EA1DC73560} - System32\Tasks\App Explorer => C:\Users\aubry\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe <==== ATTENTION
Task: {A3B6CEC7-72E5-4253-87C3-BEC11844AE1C} - System32\Tasks\Secured Yahoo Powered ditel => C:\Windows\system32\wscript.exe "C:\ProgramData\{395BFC38-B319-76FE-35DF-E8BCAF9D6372}\lido" "68747470733a2f2f64337331746b67396634323534712e636c6f756466726f6e742e6e6574" "433a5c50726f6772616d446174615c7b33393542464333382d423331392d373646452d333544462d4538424341463944363337327d5c636f73656e6f" "433a5c50726f6772616d446174615c7b333935 (l'élément de données a 116 caractères en plus).
Task: {AA0B7D74-B8EC-4B03-B638-379AA1ED5E41} - System32\Tasks\Avast SecureLine VPN Update => c:\program files\avast software\secureline\vpnupdate.exe [1390472 2019-11-16] (AVAST Software s.r.o. -> AVAST Software)
Task: {B71D84D9-3140-4413-9086-27B3DFEA6FFB} - System32\Tasks\{72939656-6F1F-4437-90E5-9113625D2ECF} => "c:\windows\system32\launchwinapp.exe" hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.22.0.109&LastError=404
Task: {CE64CD54-EBDE-41F8-9A2E-BE8972E2846C} - System32\Tasks\sedelonola\{0B0ACF0C-4CB8-A4B5-98F2-079851D2A57B} => C:\Users\aubry\AppData\Roaming\0b0acf0c4cb8a4b598f20\sedelonola.exe [2174464 2013-04-29] () [Fichier non signé]
Task: {D2C60EC1-91E4-4851-A533-D0DC4D8D5DC1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {D39AEEDA-9A0A-4832-9753-B66C7F23309B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {D7CB4FE6-DA9A-4B2B-A1E9-1DF9D989E89B} - System32\Tasks\Power Button => C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe [2770688 2015-05-14] (Acer Incorporated -> Acer Incorporated)
Task: {DE02721D-8C8B-4C2E-9C76-917E15F182BC} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {EF688526-6C65-42F1-B1B3-AA4AB13C08E3} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [65752 2017-03-20] (Acer Incorporated -> Acer Incorporated)
Task: {FBE1992D-A1B2-44DD-9601-A1A2F799B096} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2920752 2018-05-28] (Acer Incorporated -> )
(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)
Task: C:\WINDOWS\Tasks\Secured Yahoo Powered ditel.job => Wscript exe
Task: C:\WINDOWS\Tasks\{1793B6A0-BA2A-8EFD-C071-3692DB5E39E6}.job => C:\Users\aubry\AppData\Roaming\Gopego\TOPADO~1.EXE
Task: C:\WINDOWS\Tasks\{1B840C4B-BC8D-6B3D-0DC9-6C9908A0B0F8}.job => C:\Users\aubry\AppData\Roaming\1B840C~1\updane.exe <==== ATTENTION
==================== Internet (Avec liste blanche) ====================
(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{b233b376-bd0b-4936-8ee9-c0cd95545095}: [DhcpNameServer] 192.17.128.24
Tcpip\..\Interfaces\{e0bcf4e1-ee05-49d5-b4ba-9c28065345cf}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=shnl&hsimp=yhs-001&type=c110d0dc585dc49770830874990¶m1=IE¶m2=1¶m3=campaignID%3D113%26UserID%3D1054629261¶m4=XPbueSzfBeG6K2MlxBpfELmmgzh8mOsLvk1mNxKnkuDQzAGYaclIXjiYGxEsx2yN4hFTH1CPkETBiBKHFz+GQ+EL0TTnafB8KbRFu5RAu1+yzlYZvE45/a+f/QtDV5R1cyCEZmQAxVMQkQ8GftukH7KKIP9OBwyoELeCMWlcu3Fyf5eBqUz0IQmRawETVER4hk0YGXa1Z39ah93C1yAei1qru5KJZzoXd5duK5q3FLvSzk9epT9PwDOaghNKSHvoTHYgmZMKY2XrD1DLIEVRpwuFYz+WUgCyfxXvWSpkF04BLjdq8F4zSxoZFksEV1gC2p8ZmEdjeYyrv+79qPq9jAFflmWbMtDZqIREPgi5znWhJS42nwkUcpVWp/n+as6pB7RGv20tBWkPgiZX3ewXof3qxhP0qRZaur1mGoi6gLGQZpPcbokhDn8wcsrSLfAek1O/U+ykSOPGuSZSNcHJt+N5/pB6aek1ouZtlyjR/XxHcj4ZX+YOVKKXMDnkEvDS/csX9eEHsurhMmGgPkjxnDBuz21Nq+LTLnMxTWpzeFc+Z2yNoCagAxH4lXu4NbvhYWc38JBw3rXgHc1fQeUUweWbeI/ZgrZQgFqWDpZJ7kXEBUSBbjuqTfVqTI3kfFEj+jsbv2sgm1klgQN5xYZ5uciTuMtoOa5h8+JNTvja2DXdN70B5qv7Yb0M8yKMfwtX94wCPJTbPZ4pIzOAfssVyQ==
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.monconvertisseur.com/?source=gdfrcosc728290-iei&uid=a29f715d-15b5-285f-5d0c-5ce4a7589abe&i_id=converter__1.30&uc=20190629&ap=romb
HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer15.msn.com/?pc=ACTE
SearchScopes: HKLM -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKLM -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKLM -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM -> {f79e5d1c-5148-469e-9f98-a11d8d7863f4} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKLM-x32 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKLM-x32 -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKLM-x32 -> {f79e5d1c-5148-469e-9f98-a11d8d7863f4} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\.DEFAULT -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL =
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> DefaultScope {33F660BB-482C-4070-A8F2-45C0CB6003E6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL =
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {33F660BB-482C-4070-A8F2-45C0CB6003E6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {6D9D88A1-FEF4-4891-A806-E279252FCC4C} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {7E9949AB-6011-46E8-8FA8-C9033ADA4597} URL = hxxps://fr.search.yahoo.com/search?fr=mcafee&type=C011FR662D20160218&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxp://query.monconvertisseur.com/s?source=gdfrcosc728290-iei&uid=a29f715d-15b5-285f-5d0c-5ce4a7589abe&i_id=converter__1.30&uc=20190629&ap=romb&query={searchTerms}
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {f79e5d1c-5148-469e-9f98-a11d8d7863f4} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
BHO: Amazon Assistant -> {0ddcea2a-7b00-4349-8acb-af7ba6da251f} -> C:\Program Files (x86)\Amazon\Amazon Assistant\aaMessenger.dll [2018-02-22] (Amazon Services LLC -> )
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (Canon Inc. -> CANON INC.)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll => Pas de fichier
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2018-05-15] (Microsoft Corporation -> Microsoft Corporation)
BHO: OffresShopping -> {F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB} -> C:\Program Files\ItinéraireInfoInstaller\BHO.dll [2015-02-10] (Prestafind) [Fichier non signé]
BHO-x32: Amazon Assistant -> {0ddcea2a-7b00-4349-8acb-af7ba6da251f} -> C:\Program Files (x86)\Amazon\Amazon Assistant\aaMessenger.dll [2018-02-22] (Amazon Services LLC -> )
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Users\aubry\Documents\Minecraft\bin\ssv.dll [2020-04-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll => Pas de fichier
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Users\aubry\Documents\Minecraft\bin\jp2ssv.dll [2020-04-04] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: OffresShopping -> {F4A9D6FE-8C16-4D72-B845-7AE0FFAB2DAB} -> C:\Program Files (x86)\ItinéraireInfoInstaller\BHO.dll [2015-02-10] (Prestafind) [Fichier non signé]
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (Canon Inc. -> CANON INC.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll Pas de fichier
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll Pas de fichier
Edge:
======
DownloadDir: C:\Users\aubry\Downloads
Edge Notifications: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> hxxps://www.marmiton.org
FireFox:
========
FF DefaultProfile: 5p0v3990.default
FF ProfilePath: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default [2020-03-20]
FF Homepage: Mozilla\Firefox\Profiles\5p0v3990.default -> hxxps://fr.search.yahoo.com/yhs/web?hspart=coco&hsimp=yhs-001&type=7ZMihdXhSES7iOliRQieetQO¶m2=XPbueSzfBeG6K2MlxBpfEEdaMnVz4fEPIxImUbRDFbSlltbkA92Q%2bNtDImiu0fRpDv0rk4kOah9uIx3SvMiwvaSf3LCQyz4OKdhWMQm2ERM65gyQ9c6%2fUqFS%2bjYkR10if3G8lYZxXERcuqAgvBXi7%2bcCCoce6kK5mpQT2r4VbTnVfPX%2bEHQia1zAo6QNFNrDpTJWJCYTrL%2b%2fWXdt45HikHL4TozpWnuDmrP9xfcDcKSd2fvkdVBJLALaPAydhHk7zRarH7i3TqwoByPM5H6STSY%2bD3z4VnlDxh6q4EUq7lmjijtDqG5%2bUMJVFVehGl9vgMs5yxuyyU%2fi3wzaMWqUYrLs2AYIZ4lyH3HrO%2bXbUUOnFWxTbqbHSFosdTLjqWY4uzRIRoAi2zG6ZI%2fVVTueyC6HINOUHeTQwqPgubyRRnVGYD5VWGNCFPr3oSC2JtmEHTI3gG6fQ2VDYYfFVISqwv7hRb3SSpXA3yz3pWy4qJFGKhZ2gTDr6IqvtQYBHhf3%2b2IC563r7T1JgkfVuj0Hln%2f2UMysMKU9FLGZSwHo69Y4WM9L1mxSanvaq3pFUpC3gTgdTj7aEowWMotG6rthFbfkUSnfuAUizrzjo%2bb6F%2fl4NcvREYbcuBCS3ff3amaS~vi06X1TR0Z02
FF Extension: (Amazon Assistant for Firefox) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\abb@amazon.com.xpi [2016-02-17] []
FF Extension: (Bing Search) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\bingsearch.full@microsoft.com.xpi [2017-03-30] []
FF Extension: (cacaoweb) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\cacaoweb@cacaoweb.org [2016-03-18] [] [non signé]
FF Extension: (Dashlane) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\jetpack-extension@dashlane.com.xpi [2017-01-05] []
FF Extension: (Français Language Pack) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\langpack-fr@firefox.mozilla.org [2016-02-17] [] [non signé]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\bing provided search.xml [2018-12-12]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\bing search engine.xml [2020-03-20]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\bing-.xml [2017-03-30]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\Search Provided by Yahoo.xml [2016-03-05]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\Web Search.xml [2016-02-20]
FF SearchPlugin: C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\searchplugins\YHS Search.xml [2016-05-30]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => non trouvé(e)
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi => non trouvé(e)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2020-03-16] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.) [Fichier non signé]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.241.2 -> C:\Users\aubry\Documents\Minecraft\bin\dtplugin\npDeployJava1.dll [2020-04-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.241.2 -> C:\Users\aubry\Documents\Minecraft\bin\plugin2\npjp2.dll [2020-04-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2020-03-16] (Adobe Inc. -> Adobe Systems)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR Profile: C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default [2020-03-20]
CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?fr=mcafee&type=D211FR662G0&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
CHR Extension: (Slides) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-10-13]
CHR Extension: (Selected Search) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\afgeoapebnkefelmpoepnmjiflidjjce [2019-12-19]
CHR Extension: (Docs) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-11-24]
CHR Extension: (Google Drive) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-24]
CHR Extension: (The Search Selector) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhdinjalofclbacjijgifpahcnjapclb [2020-03-20]
CHR Extension: (YouTube) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-11-24]
CHR Extension: (Sheets) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-10-13]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-01-09]
CHR Extension: (Google Docs hors connexion) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-11-24]
CHR Extension: (Search Selector) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\iicdcmjmlnliniifciehlchmdepfndfn [2019-12-19]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-19]
CHR Extension: (Gmail) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-12-19]
CHR Extension: (Chrome Media Router) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-01-09]
CHR HKLM\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKLM\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <non trouvé(e)>
CHR HKLM\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb]
CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pfnciekpafndamlomnebbfophenfehbc]
CHR HKLM-x32\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKLM-x32\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <non trouvé(e)>
CHR HKLM-x32\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
==================== Services (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [820280 2020-03-16] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3374160 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3103824 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 Amazon Assistant Service; C:\Program Files (x86)\Amazon\Amazon Assistant\amazonAssistantService.exe [105136 2018-02-22] (Amazon Services LLC -> )
R2 Dashlane Upgrade Service; C:\Program Files (x86)\Dashlane\Upgrade\DashlaneUpgradeService.exe [82944 2015-12-04] (Dashlane -> Dashlane SAS)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573568 2015-05-14] (Acer Incorporated -> Acer Incorporated)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [184064 2016-12-12] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373720 2017-06-27] (Intel(R) pGFX -> Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] (Canon Inc. -> )
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel® Trusted Connect Service -> Intel(R) Corporation)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [Fichier non signé]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [Fichier non signé]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-07-06] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-06-12] (Intel Corporation-Wireless Connectivity Solutions -> )
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
R3 QALSvc; C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [401248 2015-09-04] (Acer Incorporated -> Acer Incorporated)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [453984 2015-09-04] (Acer Incorporated -> Acer Incorporated)
R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [6828424 2019-11-16] (AVAST Software s.r.o. -> AVAST Software)
R2 SSSvc; C:\Program Files (x86)\ScreenShot\SSSvc.exe [139712 2017-04-24] (Filseclab Corporation -> Filseclab Corporation Limited)
S3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [247040 2015-05-27] (Acer Incorporated -> acer)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\NisSrv.exe [3917016 2018-10-24] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MsMpEng.exe [114208 2018-10-24] (Microsoft Corporation -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe [495720 2018-08-29] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [83232 2019-07-09] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 WsDrvInst; C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe [130336 2019-10-30] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831200 2015-06-12] (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
===================== Pilotes (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R3 ETDI2C; C:\WINDOWS\system32\DRIVERS\ETDI2C.sys [175152 2015-06-09] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronic Corp.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [253184 2016-12-12] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [31000 2018-05-15] (Acer Incorporated -> Acer Incorporated)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7708160 2018-09-15] (Microsoft Windows -> Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_bdd6ea477d4e2fba\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47976 2015-07-03] (NVIDIA Corporation -> NVIDIA Corporation)
S3 qcusbnet; C:\WINDOWS\System32\drivers\qcusbnet.sys [428600 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [25368 2018-05-15] (Acer Incorporated -> Acer Incorporated)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek Semiconductor Corp -> Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [411712 2015-05-19] (Microsoft Windows Hardware Compatibility Publisher -> Realsil Semiconductor Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46184 2018-10-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [328696 2018-10-24] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60408 2018-10-24] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
==================== Un mois (créés) ===================
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2020-04-20 16:23 - 2020-04-20 16:26 - 000000000 ____D C:\FRST
2020-04-19 01:42 - 2020-04-19 01:42 - 000000000 ___HD C:\OneDriveTemp
2020-04-15 22:50 - 2020-04-15 22:52 - 000000447 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2020-04-15 18:26 - 2020-04-15 18:26 - 005436696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 003550400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 002469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 002323696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 001709560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 001024920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 000982016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-04-15 18:26 - 2020-04-15 18:26 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-04-15 18:25 - 2020-04-15 18:26 - 002749800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 026806784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 023463424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 020816384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 019020800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 015222272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 008907264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 007923712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 007871488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 006543528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 006318840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 006060032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 005608120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 004872704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 004695552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 004628480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003933184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003887640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 003703808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003656704 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003493376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 003097600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 002942976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 002917688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-04-15 18:25 - 2020-04-15 18:25 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 002801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 002706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 002182472 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 002078392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001675008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001674480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001668968 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001465344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001465272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001346192 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-04-15 18:25 - 2020-04-15 18:25 - 001323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001257984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001249792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001200920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 001183296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 001012224 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000976896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000837120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000808272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000773200 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000730112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000725904 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000672256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000661056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000649272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000638264 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000553784 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000535056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-04-15 18:25 - 2020-04-15 18:25 - 000534016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000452920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-04-15 18:25 - 2020-04-15 18:25 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSATAPI.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2020-04-15 18:25 - 2020-04-15 18:25 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSATAPI.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000280136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000261944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2020-04-15 18:25 - 2020-04-15 18:25 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000180736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-04-15 18:25 - 2020-04-15 18:25 - 000164152 _____ (Microsof
billmaxime
Messages postés
50434
Date d'inscription
dimanche 20 novembre 2011
Statut
Contributeur
Dernière intervention
15 décembre 2024
6 008
20 avril 2020 à 18:58
20 avril 2020 à 18:58
re
il faut poster les rapports avec Cjoint, car ils sont trop longs pour le forum
@+
il faut poster les rapports avec Cjoint, car ils sont trop longs pour le forum
@+
Pyradax
Messages postés
13
Date d'inscription
mercredi 15 avril 2020
Statut
Membre
Dernière intervention
4 novembre 2024
20 avril 2020 à 19:38
20 avril 2020 à 19:38
J'ai les deux liens du scan tenez :
https://www.cjoint.com/c/JDuqXcI8FkS
https://www.cjoint.com/c/JDuqYgXlFyS
https://www.cjoint.com/c/JDuqXcI8FkS
https://www.cjoint.com/c/JDuqYgXlFyS
billmaxime
Messages postés
50434
Date d'inscription
dimanche 20 novembre 2011
Statut
Contributeur
Dernière intervention
15 décembre 2024
6 008
20 avril 2020 à 21:00
20 avril 2020 à 21:00
re
via programmes et fonctionnalités du panneau de configuration, désinstalle ceci:
AVAST SecureLine Vpn
Wondershare
dit moi quand c'est fait
@+
via programmes et fonctionnalités du panneau de configuration, désinstalle ceci:
AVAST SecureLine Vpn
Wondershare
dit moi quand c'est fait
@+
Pyradax
Messages postés
13
Date d'inscription
mercredi 15 avril 2020
Statut
Membre
Dernière intervention
4 novembre 2024
20 avril 2020 à 21:29
20 avril 2020 à 21:29
C'est fait c'est désinstaller
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
billmaxime
Messages postés
50434
Date d'inscription
dimanche 20 novembre 2011
Statut
Contributeur
Dernière intervention
15 décembre 2024
6 008
Modifié le 20 avril 2020 à 21:42
Modifié le 20 avril 2020 à 21:42
re
ok, fait ceci:
ouvre le bloc-note
copie/colle le texte ci-dessous:
quand le texte est copié/collé, clique sur "fichier">>"enregistrer sous" et choisi le "bureau" dans la colonne de gauche
en bas de page, dans "nom de fichier", tape fixlist.txt et clique sur "enregistrer"
exécute FRST et clique sur "corriger"
quand la correction sera terminée, un fichier texte apparaîtra sur ton bureau, copie/colle le résultat dans ta prochaine réponse
@+
ok, fait ceci:
ouvre le bloc-note
copie/colle le texte ci-dessous:
Start:: CreateRestorePoint: CloseProcesses: (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe [495720 2018-08-29] (Wondershare Technology Co.,Ltd -> Wondershare) R2 WsAppService3; C:\Program Files (x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe [83232 2019-07-09] (Wondershare Technology Co.,Ltd -> Wondershare) R2 WsDrvInst; C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe [130336 2019-10-30] (Wondershare Technology Co.,Ltd -> Wondershare) Wondershare Recoverit(Build 8.0.4.3) (HKLM-x32\...\{829555DC-31E5-4FEA-B350-8FCF24CECD95}_is1) (Version: 8.0.4.3 - Wondershare Software Co.,Ltd.) (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\SecureLine\Vpn.exe <2> (AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast SecureLine VPN.lnk [2019-12-08] ShortcutTarget: Avast SecureLine VPN.lnk -> C:\Program Files\AVAST Software\SecureLine\Vpn.exe (AVAST Software s.r.o. -> AVAST Software) Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - System32\Tasks\Avast SecureLine => C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [3438680 2016-05-24] (AVAST Software a.s. -> AVAST Software) Task: {AA0B7D74-B8EC-4B03-B638-379AA1ED5E41} - System32\Tasks\Avast SecureLine VPN Update => c:\program files\avast software\secureline\vpnupdate.exe [1390472 2019-11-16] (AVAST Software s.r.o. -> AVAST Software) R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [6828424 2019-11-16] (AVAST Software s.r.o. -> AVAST Software) 2020-04-20 15:36 - 2019-11-15 12:37 - 000004294 _____ C:\WINDOWS\system32\Tasks\Avast SecureLine VPN Update Avast SecureLine (HKLM\...\{2CD3C92F-EDC5-4B02-9B0A-9C1D37C58EF5}_is1) (Version: 1.0.239.4 - AVAST Software) 2019-11-16 19:22 - 2019-11-16 19:21 - 002095104 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Fichier non signé] C:\Program Files\AVAST Software\SecureLine\libcrypto-1_1.dll (CACAOWEB Ltd -> ) C:\Users\aubry\AppData\Roaming\cacaoweb\cacaoweb.exe HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [Chromium] => "c:\users\aubry\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Run: [cacaoweb] => C:\Users\aubry\AppData\Roaming\cacaoweb\cacaoweb.exe [567192 2018-09-03] (CACAOWEB Ltd -> ) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAndroidAppHelper.lnk [2020-01-19] ShortcutTarget: WSAndroidAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAndroidAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WSAppHelper.lnk [2020-01-19] ShortcutTarget: WSAppHelper.lnk -> C:\Program Files (x86)\Wondershare\dr.fone\Addins\SocialApps\WSAppHelper.exe (Wondershare Technology Co.,Ltd -> Microsoft) GroupPolicy: Restriction ? <==== ATTENTION Task: {19FD2D84-C017-4B10-97A6-6F304F1EC839} - System32\Tasks\{1B840C4B-BC8D-6B3D-0DC9-6C9908A0B0F8} => C:\Users\aubry\AppData\Roaming\1b840c4bbc8d6b3d0dc96c9908a0b0f8\updane.exe [920064 2013-05-02] () [Fichier non signé] Task: {2FDEF2A6-0B44-4D5E-95CF-A9E152CEFD02} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION Task: {9A84FE45-ED70-485C-92BE-85EA1DC73560} - System32\Tasks\App Explorer => C:\Users\aubry\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe <==== ATTENTION Task: {A3B6CEC7-72E5-4253-87C3-BEC11844AE1C} - System32\Tasks\Secured Yahoo Powered ditel => C:\Windows\system32\wscript.exe "C:\ProgramData\{395BFC38-B319-76FE-35DF-E8BCAF9D6372}\lido" "68747470733a2f2f64337331746b67396634323534712e636c6f756466726f6e742e6e6574" "433a5c50726f6772616d446174615c7b33393542464333382d423331392d373646452d333544462d4538424341463944363337327d5c636f73656e6f" "433a5c50726f6772616d446174615c7b333935 (l'élément de données a 116 caractères en plus). Task: C:\WINDOWS\Tasks\Secured Yahoo Powered ditel.job => Wscript exe Task: C:\WINDOWS\Tasks\{1793B6A0-BA2A-8EFD-C071-3692DB5E39E6}.job => C:\Users\aubry\AppData\Roaming\Gopego\TOPADO~1.EXE Task: C:\WINDOWS\Tasks\{1B840C4B-BC8D-6B3D-0DC9-6C9908A0B0F8}.job => C:\Users\aubry\AppData\Roaming\1B840C~1\updane.exe <==== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://fr.search.yahoo.com/yhs/web?hspart=shnl&hsimp=yhs-001&type=c110d0dc585dc49770830874990¶m1=IE¶m2=1¶m3=campaignID%3D113%26UserID%3D1054629261¶m4=XPbueSzfBeG6K2MlxBpfELmmgzh8mOsLvk1mNxKnkuDQzAGYaclIXjiYGxEsx2yN4hFTH1CPkETBiBKHFz+GQ+EL0TTnafB8KbRFu5RAu1+yzlYZvE45/a+f/QtDV5R1cyCEZmQAxVMQkQ8GftukH7KKIP9OBwyoELeCMWlcu3Fyf5eBqUz0IQmRawETVER4hk0YGXa1Z39ah93C1yAei1qru5KJZzoXd5duK5q3FLvSzk9epT9PwDOaghNKSHvoTHYgmZMKY2XrD1DLIEVRpwuFYz+WUgCyfxXvWSpkF04BLjdq8F4zSxoZFksEV1gC2p8ZmEdjeYyrv+79qPq9jAFflmWbMtDZqIREPgi5znWhJS42nwkUcpVWp/n+as6pB7RGv20tBWkPgiZX3ewXof3qxhP0qRZaur1mGoi6gLGQZpPcbokhDn8wcsrSLfAek1O/U+ykSOPGuSZSNcHJt+N5/pB6aek1ouZtlyjR/XxHcj4ZX+YOVKKXMDnkEvDS/csX9eEHsurhMmGgPkjxnDBuz21Nq+LTLnMxTWpzeFc+Z2yNoCagAxH4lXu4NbvhYWc38JBw3rXgHc1fQeUUweWbeI/ZgrZQgFqWDpZJ7kXEBUSBbjuqTfVqTI3kfFEj+jsbv2sgm1klgQN5xYZ5uciTuMtoOa5h8+JNTvja2DXdN70B5qv7Yb0M8yKMfwtX94wCPJTbPZ4pIzOAfssVyQ== HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.monconvertisseur.com/?source=gdfrcosc728290-iei&uid=a29f715d-15b5-285f-5d0c-5ce4a7589abe&i_id=converter__1.30&uc=20190629&ap=romb HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer15.msn.com/?pc=ACTE SearchScopes: HKLM -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms} SearchScopes: HKLM -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms} SearchScopes: HKLM -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms} SearchScopes: HKLM-x32 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM-x32 -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms} SearchScopes: HKLM-x32 -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> DefaultScope {33F660BB-482C-4070-A8F2-45C0CB6003E6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms} SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {33F660BB-482C-4070-A8F2-45C0CB6003E6} URL = hxxps://fr.search.yahoo.com/yhs/search?hspart=shnl&hsimp=yhs-001&type=c11001eb40d0eeeb9f44a3635af¶m1=IE¶m2=4¶m3=campaignID%3D690%26UserID%3D1120391359¶m4=XPbueSzfBeG6K2MlxBpfEDPN+SxVpua8beXQzoS1GYKYX9iWjIAFEmvclWBbrhjndV++0pf457ScwisW9HijmNGowuBYfJKV0GXs74+/VeGFEAes+IlOfR+nC1GRWwVyvCcl6c69sKX68ekpvnMmLMQONLGMzeNkqt6IMP8p2LPsKqQxRABnogH9bXzajCVIfeiJYvdDXcWh/JGpx5jSuKYh+rrXdfLOLMHqL3NYYySD5+s6p8eI5p/tETNyV0+9dbDvRtRSls84QJ1ixIUQ/5De1CDCcHPMSgVVGXQs4++makCQZpy8JnWjGtjvLR+Wisp9V8aVJgQ0utSDIDT4sArHXYyP02hgUIPEp00Jxr9gvUylGSfG6P+JTjbmVy3/PNWMoaOUc9RFkIYHePWyc5Uw2O6XwqxMfX/kv8XyLoUK/kQxRTbnBmgDDckqPMif77v6YaAa0TJpJDMzhI2cZbmUdEKPuSVy6AWS/skpjyfUoVN6B/MH7KWJIj7xAFxOJrPXxGXbzgxVoWVtGNBOt2lUIQb0yqjleFyC3e3gNWivRHvjui7baHVw9qpsEGn+5QPLG9t2oSBw0ohLiMsd0K8UQ7eB+UFm9p7dO+OGdJP7uYQIOWs+5YhnbGf0gRhhIw0Wm6zxzs6x7GSIaSARi72EvXslvfBOhbsyiwo2X0Y=&p={searchTerms} SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {7E9949AB-6011-46E8-8FA8-C9033ADA4597} URL = hxxps://fr.search.yahoo.com/search?fr=mcafee&type=C011FR662D20160218&p={searchTerms} SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001 -> {CB4118AB-7522-4EC0-969F-85112BFB6FB6} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_18_48_jny_soverj_00_00¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutAtDyCyD0E0Czz0F0ByE0FtAtD0DyD0CtN0D0TzutN1L2XzuyEtFtAtBtFtDtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2S1StD1P1StB1PzytDtGyE1P1S1StGyE1PyEtAtG1T1Ozz1OtGtA1PyC1Pzz1T1OyDzyzzzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtAzytC0ByDtBtGyCzyzy0AtGyEtA0CtAtG0ByEtC0EtG0BtCyCtD0EyDyEtD0AyC0B0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutN1Q2Z1B1P1Rzu%26cr%3D45824312%26a%3Dhdr_s_18_48_jny_soverj_00_00%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms} BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll => Pas de fichier BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll => Pas de fichier Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll Pas de fichier Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll Pas de fichier FF Homepage: Mozilla\Firefox\Profiles\5p0v3990.default -> hxxps://fr.search.yahoo.com/yhs/web?hspart=coco&hsimp=yhs-001&type=7ZMihdXhSES7iOliRQieetQO¶m2=XPbueSzfBeG6K2MlxBpfEEdaMnVz4fEPIxImUbRDFbSlltbkA92Q%2bNtDImiu0fRpDv0rk4kOah9uIx3SvMiwvaSf3LCQyz4OKdhWMQm2ERM65gyQ9c6%2fUqFS%2bjYkR10if3G8lYZxXERcuqAgvBXi7%2bcCCoce6kK5mpQT2r4VbTnVfPX%2bEHQia1zAo6QNFNrDpTJWJCYTrL%2b%2fWXdt45HikHL4TozpWnuDmrP9xfcDcKSd2fvkdVBJLALaPAydhHk7zRarH7i3TqwoByPM5H6STSY%2bD3z4VnlDxh6q4EUq7lmjijtDqG5%2bUMJVFVehGl9vgMs5yxuyyU%2fi3wzaMWqUYrLs2AYIZ4lyH3HrO%2bXbUUOnFWxTbqbHSFosdTLjqWY4uzRIRoAi2zG6ZI%2fVVTueyC6HINOUHeTQwqPgubyRRnVGYD5VWGNCFPr3oSC2JtmEHTI3gG6fQ2VDYYfFVISqwv7hRb3SSpXA3yz3pWy4qJFGKhZ2gTDr6IqvtQYBHhf3%2b2IC563r7T1JgkfVuj0Hln%2f2UMysMKU9FLGZSwHo69Y4WM9L1mxSanvaq3pFUpC3gTgdTj7aEowWMotG6rthFbfkUSnfuAUizrzjo%2bb6F%2fl4NcvREYbcuBCS3ff3amaS~vi06X1TR0Z02 FF Extension: (cacaoweb) - C:\Users\aubry\AppData\Roaming\Mozilla\Firefox\Profiles\5p0v3990.default\Extensions\cacaoweb@cacaoweb.org [2016-03-18] [] [non signé] FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => non trouvé(e) FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi => non trouvé(e) CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?fr=mcafee&type=D211FR662G0&p={searchTerms} CHR DefaultSearchKeyword: Default -> mcafee CHR Extension: (McAfee® WebAdvisor) - C:\Users\aubry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-01-09] CHR HKLM\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] CHR HKLM\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <non trouvé(e)> CHR HKLM\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn] CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb] CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn] CHR HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pfnciekpafndamlomnebbfophenfehbc] CHR HKLM-x32\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce] CHR HKLM-x32\...\Chrome\Extension: [bhdinjalofclbacjijgifpahcnjapclb] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <non trouvé(e)> CHR HKLM-x32\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn] (Filseclab Corporation -> Filseclab Corporation Limited) C:\Program Files (x86)\ScreenShot\SSSvc.exe 2020-04-20 16:22 - 2018-09-15 09:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-04-20 16:04 - 2016-03-18 22:36 - 000000000 ____D C:\Users\aubry\AppData\Roaming\cacaoweb 2020-04-20 15:59 - 2017-10-24 19:20 - 000000000 ____D C:\ProgramData\{395BFC38-B319-76FE-35DF-E8BCAF9D6372} 2020-04-20 15:32 - 2017-08-02 19:17 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2020-04-01 20:55 - 2020-04-01 20:55 - 000000737 _____ () C:\Users\aubry\AppData\Roaming\AdobeWLCMR2Cache.dat 2016-02-17 18:45 - 2020-04-19 01:48 - 000000244 _____ () C:\Users\aubry\AppData\Roaming\WB.CFG 2017-12-12 19:21 - 2017-12-12 19:21 - 000000068 _____ () C:\Users\aubry\AppData\Local\eb82wtqnkh 2017-12-13 20:20 - 2017-12-20 16:46 - 000000068 _____ () C:\Users\aubry\AppData\Local\gzSfyRexQd 2018-09-28 23:43 - 2018-09-28 23:43 - 000000000 _____ () C:\Users\aubry\AppData\Local\oobelibMkey.log 2017-02-23 22:24 - 2017-03-06 19:02 - 000000552 _____ () C:\Users\aubry\AppData\Local\TroubleshooterConfig.json McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.7.213 - McAfee, Inc.) Privacy Protector Plus v3.0 (HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\Privacy Protector Plus_is1) (Version: 3.0 - Avanquest) Search the Web (Yahoo) (HKLM-x32\...\{F4621CA2-A4E2-CD22-1562-BDA2C5E26E22}) (Version: - ) <==== ATTENTION Secured Yahoo Powered (HKLM-x32\...\{72089AC8-2288-4B48-9308-3BC84388E848}) (Version: - ) <==== ATTENTION Web Search (Yahoo! Provided) (HKLM-x32\...\{0129E9E9-51A9-3869-E029-48E930A99B69}) (Version: - ) CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{46406D82-6EC0-47CC-8A75-1F33C6DEDBBE}\InprocServer32 -> C:\Users\aubry\AppData\Local\Google\Update\1.3.35.442\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{540C17A8-04F2-4B66-95D7-B2FEF9A19B54}\InprocServer32 -> C:\Users\aubry\AppData\Local\Google\Update\1.3.35.422\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{62634D95-960B-4834-8E71-A70408AD8FD9}\InprocServer32 -> C:\Users\aubry\AppData\Local\Google\Update\1.3.34.7\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{84EB3779-151B-4C71-AEF0-A0FEE9481401}\InprocServer32 -> C:\Users\aubry\AppData\Local\Google\Update\1.3.35.342\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{86508D42-E5D7-4D10-9C6F-D427AEEB85B5}\InprocServer32 -> C:\Users\aubry\AppData\Local\Google\Update\1.3.34.11\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\localserver32 -> C:\Users\aubry\AppData\Local\Google\Chrome\Application\80.0.3987.163\notification_helper.exe (Google LLC -> Google LLC) CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{A804CF1A-91E5-4F0C-9E8C-DB39E74056DD}\InprocServer32 -> C:\Users\aubry\AppData\Local\Google\Update\1.3.33.23\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{EA724FD3-844D-43A9-A8C9-A5BC35FC20E4}\InprocServer32 -> C:\Users\aubry\AppData\Local\Google\Update\1.3.33.17\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-3743041002-4164144641-2799150064-1001_Classes\CLSID\{EF076C91-DC9E-43E3-84ED-3D219E065A4F}\InprocServer32 -> C:\Users\aubry\AppData\Local\Google\Update\1.3.35.302\psuser_64.dll => Pas de fichier ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier ShortcutWithArgument: C:\Users\aubry\Desktop\Google.lnk -> C:\Users\aubry\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) -> --profile-directory=Default --app-id=panhfjbapmcigaeaebakhnfjocpelhmm ShortcutWithArgument: C:\Users\aubry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chromium\Google.lnk -> C:\Users\aubry\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) -> --profile-directory=Default --app-id=panhfjbapmcigaeaebakhnfjocpelhmm ShortcutWithArgument: C:\Users\aubry\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google.lnk -> C:\Users\aubry\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) -> --profile-directory=Default --app-id=panhfjbapmcigaeaebakhnfjocpelhmm HKU\S-1-5-21-3743041002-4164144641-2799150064-1001\...\StartupApproved\Run: => "Chromium" FirewallRules: [{772FF1F8-333D-4DAA-A76B-4E8B33662E09}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe Pas de fichier FirewallRules: [{6899F784-3E8F-4F01-AE27-5407C89F956A}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe Pas de fichier FirewallRules: [{6264A8F1-5E9B-4B10-805E-3B1A14208B5D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe Pas de fichier FirewallRules: [{3EA72CEF-E332-460C-AA6C-41D85DB28A26}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe Pas de fichier FirewallRules: [{6C1E3DFC-08DA-45FA-99DD-F1AD8E0FF18D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe Pas de fichier FirewallRules: [TCP Query User{4D8FEA53-B72A-460C-B2EF-CFED0EF38BF5}C:\users\aubry\appdata\roaming\.tlauncher\jvms\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\users\aubry\appdata\roaming\.tlauncher\jvms\jre1.8.0_51\bin\javaw.exe FirewallRules: [UDP Query User{F1D9336E-3B7A-442D-BF35-497092584374}C:\users\aubry\appdata\roaming\.tlauncher\jvms\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\users\aubry\appdata\roaming\.tlauncher\jvms\jre1.8.0_51\bin\javaw.exe FirewallRules: [TCP Query User{3805C738-0956-41C5-97AA-5AD5CE8352A2}C:\users\aubry\appdata\roaming\cacaoweb\cacaoweb.exe] => (Block) C:\users\aubry\appdata\roaming\cacaoweb\cacaoweb.exe (CACAOWEB Ltd -> ) FirewallRules: [UDP Query User{64BC254C-9A09-42D2-B928-592293DC0833}C:\users\aubry\appdata\roaming\cacaoweb\cacaoweb.exe] => (Block) C:\users\aubry\appdata\roaming\cacaoweb\cacaoweb.exe (CACAOWEB Ltd -> ) FirewallRules: [{85F3F45B-3392-4A2F-A8DE-A37F79ED9243}] => (Allow) %systemroot%\system32\alg.exe Pas de fichier FirewallRules: [{8BB50786-EB76-4C90-8A68-7942E816C021}] => (Allow) %systemroot%\system32\alg.exe Pas de fichier FirewallRules: [{5FCE5DC4-C45B-4D4A-BF15-9FC918FF750C}] => (Allow) %systemroot%\system32\alg.exe Pas de fichier FirewallRules: [{AC33AFAD-AE89-4324-A49A-AD5DD050BE26}] => (Allow) %systemroot%\system32\alg.exe Pas de fichier (Acer Incorporated -> ) C:\OEM\Preload\FubTracking\FubTracking.exe Task: {92341393-6805-4A86-B2F5-5F66C8C9C943} - System32\Tasks\FUBTrackingByPLD => C:\OEM\Preload\FubTracking\FubTracking.exe [30976 2015-05-14] (Acer Incorporated -> ) RemoveProxy: Hosts: EmptyTemp: RemoveProxy: Reboot: End::
quand le texte est copié/collé, clique sur "fichier">>"enregistrer sous" et choisi le "bureau" dans la colonne de gauche
en bas de page, dans "nom de fichier", tape fixlist.txt et clique sur "enregistrer"
exécute FRST et clique sur "corriger"
quand la correction sera terminée, un fichier texte apparaîtra sur ton bureau, copie/colle le résultat dans ta prochaine réponse
@+
Pyradax
Messages postés
13
Date d'inscription
mercredi 15 avril 2020
Statut
Membre
Dernière intervention
4 novembre 2024
20 avril 2020 à 22:24
20 avril 2020 à 22:24
La correction a bien eu lieu puis mon ordinateur a redémarrer mais ou se trouve le fichier texte ? Comme s'appelle-il
billmaxime
Messages postés
50434
Date d'inscription
dimanche 20 novembre 2011
Statut
Contributeur
Dernière intervention
15 décembre 2024
6 008
20 avril 2020 à 22:28
20 avril 2020 à 22:28
re
le fichier.txt, s'appelle FIXLOG et devrait être afficher sur ton bureau
si tu as des questions...
@+
le fichier.txt, s'appelle FIXLOG et devrait être afficher sur ton bureau
si tu as des questions...
@+