Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 18-11-2022
Exécuté par xavie (administrateur) sur NOUVEAU-PC-XAVI (HP HP Notebook) (18-11-2022 23:21:40)
Exécuté depuis C:\Users\xavie\Desktop
Profils chargés: xavie
Plate-forme: Microsoft Windows 10 Famille Version 21H1 19043.2130 (X64) Langue: Français (France)
Navigateur par défaut: Chrome
Mode d'amorçage: Normal

==================== Processus (Avec liste blanche) =================

(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)

(C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\Install\{D0396A20-97B7-438E-8451-33EEC110575D}\107.0.5304.107_chrome_installer.exe
(C:\Program Files (x86)\Google\Update\Install\{D0396A20-97B7-438E-8451-33EEC110575D}\107.0.5304.107_chrome_installer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\Install\{D0396A20-97B7-438E-8451-33EEC110575D}\CR_B545B.tmp\setup.exe <2>
(C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTDevMgr.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTServer.exe
(C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\BridgeCommunication.exe <2>
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCopyAccelerator.exe
(C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\mpam-ec983438.exe ->) (Accès refusé) [Fichier non signé] C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\62F1A5EC-6226-45F1-BF5B-9DCEED496AE8\MpSigStub.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\xavie\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\mpam-ec983438.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (CyberLink Corp. -> ) C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(services.exe ->) (Hewlett-Packard Company -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe
(services.exe ->) (HP Inc.) [Fichier non signé] C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe
(services.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTDevMgr.exe
(services.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(services.exe ->) (WildTangent Inc -> WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(svchost.exe ->) (Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe <2>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22072.207.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

==================== Registre (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8811776 2017-02-23] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [231640 2016-05-13] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [657424 2016-01-11] (Hewlett-Packard Company -> HP Inc.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\...\Run: [Chromium] => "c:\users\xavie\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session [4145152 2017-09-18] (The Chromium Authors) [Fichier non signé]
HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [91667312 2020-05-12] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\...\Run: [MicrosoftEdgeAutoLaunch_B678DB9773B25F51EE6C2027CF0E36FE] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3891624 2022-10-29] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\Canon MG2400 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBW.DLL [30208 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\Canon MG2500 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDBX.DLL [30208 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\Canon MG3600 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDCT.DLL [30208 2015-03-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG2500 series: C:\WINDOWS\system32\CNMLMBX.DLL [391168 2013-03-24] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG3600 series: C:\WINDOWS\system32\CNMLMCT.DLL [406528 2015-03-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\HP E311 Status Monitor: C:\WINDOWS\system32\hpinkstsE311LM.dll [393392 2016-07-21] (Hewlett Packard -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\105.0.5195.127\Installer\chrmstp.exe [2022-09-18] (Google LLC -> Google LLC)

==================== Tâches planifiées (Avec liste blanche) ============

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

Task: {1785F7F0-BF13-4595-BD0C-89B2842FDA46} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [847392 2022-08-17] (HP Inc. -> HP Inc.)
Task: {25B35293-AD92-469D-BB55-66A0EA1DA817} - System32\Tasks\GoogleUpdateTaskMachineCore1d6fe112b1ef7f6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-27] (Google Inc -> Google Inc.)
Task: {3ECDE335-7C4A-4BA7-B6C9-0779C87624EB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /DeviceScanR6 (Pas de fichier)
Task: {4CE67E2C-B1FB-437D-B9F7-AF59F4610897} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116096 2022-10-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {4FB6F8C1-A453-48F6-B0E7-7E9A59472FDB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-10-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {52D49DC5-0054-482F-AE3C-F0FB1D009A48} - System32\Tasks\HPDAS => C:\Program [Argument = Files\HP\HP ePrint\HP.DeliveryAndStatus.Desktop.App.exe /CheckJobs]
Task: {687AC6E5-7F12-4778-A0F0-2EE3FD004BB2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN6953P03K => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /ForDevice:CN6953P03K (Pas de fichier)
Task: {6A332A9E-E5E6-454E-856E-B6914FECEC0C} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26166200 2022-10-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {6D1BB211-5494-45AA-82B3-35A03264880B} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [666592 2022-10-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {73479831-D181-4FBC-AF4C-71BC3B6DBFE4} - System32\Tasks\HPCustParticipation HP DeskJet 3630 series => C:\Program Files\HP\HP DeskJet 3630 series\Bin\HPCustPartic.exe [6438536 2017-02-08] (Hewlett Packard -> HP Inc.)
Task: {73AF8DF8-093E-4F78-A8EF-49CC25791B48} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {75F1CC93-F451-4DA7-9B6D-F3E4AAF8E4FD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7E69368B-34F1-4113-BD7E-5DD31A4B89E2} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [855352 2016-02-19] (Intel(R) Trusted Connect Service -> Intel(R) Corporation)
Task: {8DEA0625-C1AE-4ECC-9CB2-1961373C6CD8} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116096 2022-10-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {8EBD0811-EB8E-40F1-977F-45BD5F2FFBAE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9E1A622F-C3CC-481A-B9BA-009332D7D0A0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-27] (Google Inc -> Google Inc.)
Task: {A342D3FF-784F-4AEE-8080-917CBD774693} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-27] (Google Inc -> Google Inc.)
Task: {A8774E29-1A7E-4F2C-AA73-5E1131126508} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [138328 2022-08-17] (HP Inc. -> HP Inc.)
Task: {B199B17A-E387-4EE2-B93C-3204A7118922} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1149512 2022-08-17] (HP Inc. -> HP Inc.)
Task: {B5EBF693-250E-40EA-950E-1EE116CB84E1} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [146960040 2022-11-17] (Microsoft Windows -> Microsoft Corporation)
Task: {B71E89A6-36D6-4F11-A597-BEE9AE9ED0DB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [221328 2022-08-17] (HP Inc. -> )
Task: {BCF6945C-760A-47DB-995F-C15C222ED60D} - System32\Tasks\{364E1AEC-29A1-D2B5-128E-696B78EA3194} => C:\Users\xavie\AppData\Roaming\Lepigod\SYNHEL~1.EXE /Check (Pas de fichier)
Task: {CD639208-9A0C-462D-9E34-F80C80D510E0} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
Task: {e7c24d1e-22bf-4adb-a949-56a5f528c42f} - pas de chemin du fichier
Task: {ED1D957E-9A63-412C-8667-905650ECFB97} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {F27CA074-E6A8-453D-B160-A8F5B26344D5} - System32\Tasks\Microsoft\Windows\WaaSMedic\MaintenanceWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32}

(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)

Task: C:\WINDOWS\Tasks\{364E1AEC-29A1-D2B5-128E-696B78EA3194}.job => C:\Users\xavie\AppData\Roaming\Lepigod\SYNHEL~1.EXE

==================== Internet (Avec liste blanche) ====================

(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{22961289-ec15-4a41-9c15-753f84475ef7}: [DhcpNameServer] 192.168.1.1

Edge:
=======
Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)]
Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)]
Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)]
Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\WINDOWS\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)]
Edge DefaultProfile: Default
Edge Profile: C:\Users\xavie\AppData\Local\Microsoft\Edge\User Data\Default [2022-11-18]

FireFox:
========
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1219159.dll [2015-06-26] (Adobe Systems, Inc.) [Fichier non signé]
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [Fichier non signé]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-08-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-02-27] (VideoLAN -> VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2015-12-22] (WildTangent Inc -> )

Chrome:
=======
CHR Profile: C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default [2022-11-18]
CHR NewTab: Default -> Not-active:"chrome-extension://glmfdkfmoamfkgkncklicdngnfabhaim/ntp1.html", Not-active:"chrome-extension://fmgfhejnhlniacgkjnmakangponnkggd/ntp1.html", Not-active:"chrome-extension://ngamdaobhhgfhjakfmgggafaochpccmc/ntp1.html", Not-active:"chrome-extension://ognogdhldnmmaggmfoahbdnagnbhhlmj/ntp1.html", Not-active:"chrome-extension://hnbgobejilpaolpojoabbojignjgpmbk/ntp.html", Not-active:"chrome-extension://fdfbclphcjellccklfdjfeodadjigbhh/ntp1.html", Not-active:"chrome-extension://kjkkeblfbjbklichcnfhecghafokbcol/ntp1.html", Not-active:"chrome-extension://lmoldlhgiephbciccnbglieahfjkmhkh/ntp1.html", Not-active:"chrome-extension://gnmjknmalpknlmhpbfmnidbgkncebohg/ntp1.html", Not-active:"chrome-extension://gdfjhgpdpolhjcnmcphnpedcnigbfknd/stubby.html"
CHR Extension: (Ask Web Search) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\eocnnoackodjagdbaoddhjbkpjabimed [2020-07-02]
CHR Extension: (EasyFileConvert) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdfbclphcjellccklfdjfeodadjigbhh [2020-06-13]
CHR Extension: (ProductivityBoss) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmgfhejnhlniacgkjnmakangponnkggd [2020-06-10]
CHR Extension: (EmailFanatic) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdfjhgpdpolhjcnmcphnpedcnigbfknd [2020-06-13]
CHR Extension: (ProPDFConverter) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\glmfdkfmoamfkgkncklicdngnfabhaim [2020-06-10]
CHR Extension: (EasyDocMerge) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnmjknmalpknlmhpbfmnidbgkncebohg [2020-06-13]
CHR Extension: (PConverter) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnbgobejilpaolpojoabbojignjgpmbk [2020-06-10]
CHR Extension: (Ask Web Search) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbldcomffojmkkjbblhcebeicbncmjpf [2020-07-16]
CHR Extension: (SmartEasyMaps) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjkkeblfbjbklichcnfhecghafokbcol [2020-06-10]
CHR Extension: (DownSpeedTest) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmoldlhgiephbciccnbglieahfjkmhkh [2020-06-13]
CHR Extension: (QuickPDFMerger) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngamdaobhhgfhjakfmgggafaochpccmc [2020-06-10]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-08]
CHR Extension: (MySocialShortcut) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognogdhldnmmaggmfoahbdnagnbhhlmj [2020-06-10]
CHR Extension: (Search Selector Beta) - C:\Users\xavie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfnciekpafndamlomnebbfophenfehbc [2020-07-02]
CHR HKLM\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKLM\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj]
CHR HKLM\...\Chrome\Extension: [gboaiodgdajeapekadgejlbmabjganof]
CHR HKLM\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKLM\...\Chrome\Extension: [ocilpnnapnkmcdabaeoobbamlniheaep]
CHR HKLM\...\Chrome\Extension: [oonbcpdabjcggcklopgbdagbfnkhbgbe]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gboaiodgdajeapekadgejlbmabjganof]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ocilpnnapnkmcdabaeoobbamlniheaep]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oonbcpdabjcggcklopgbdagbfnkhbgbe]
CHR HKU\S-1-5-21-3317908826-1146592389-1670111846-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pfnciekpafndamlomnebbfophenfehbc]
CHR HKLM-x32\...\Chrome\Extension: [afgeoapebnkefelmpoepnmjiflidjjce]
CHR HKLM-x32\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj]
CHR HKLM-x32\...\Chrome\Extension: [gboaiodgdajeapekadgejlbmabjganof]
CHR HKLM-x32\...\Chrome\Extension: [iicdcmjmlnliniifciehlchmdepfndfn]
CHR HKLM-x32\...\Chrome\Extension: [oonbcpdabjcggcklopgbdagbfnkhbgbe]

==================== Services (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [125656 2016-05-13] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12477392 2022-10-06] (Microsoft Corporation -> Microsoft Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [349728 2015-12-22] (WildTangent Inc -> WildTangent)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1309184 2016-10-07] (HP Inc.) [Fichier non signé]
R2 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [771088 2022-08-17] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [769568 2022-08-17] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [766504 2022-08-17] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [770088 2022-08-17] (HP Inc. -> HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [606224 2016-01-11] (Hewlett-Packard Company -> HP Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [399296 2019-11-28] (Canon Inc. -> )
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] (CyberLink Corp. -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe [3125112 2022-09-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe [133560 2022-09-08] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Pilotes (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)

S3 HPMoA407; C:\WINDOWS\System32\drivers\HPMoA407.sys [25088 2011-10-31] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S3 HPubA407; C:\WINDOWS\System32\Drivers\HPubA407.sys [18944 2012-06-14] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard.)
S3 MpKsld9be0fc1; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9255CF3E-CE5D-48FA-B87A-6C9E11B908BA}\MpKslDrv.sys [228632 2022-11-17] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49576 2022-09-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [453904 2022-09-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [94480 2022-09-08] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [40104 2022-06-17] (HP Inc. -> HP)

==================== NetSvcs (Avec liste blanche) ===================

(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)


==================== Un mois (créés) (Avec liste blanche) =========

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2022-11-18 23:21 - 2022-11-18 23:27 - 000026962 _____ C:\Users\xavie\Desktop\FRST.txt
2022-11-18 23:20 - 2022-11-18 23:26 - 000000000 ____D C:\FRST
2022-11-18 23:17 - 2022-11-18 23:17 - 002375680 _____ (Farbar) C:\Users\xavie\Desktop\FRST64.exe
2022-11-17 12:30 - 2022-11-17 12:30 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2022-11-17 12:30 - 2022-11-17 12:30 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2022-11-17 12:30 - 2022-11-17 12:30 - 000012253 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-11-17 12:29 - 2022-11-17 12:29 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2022-11-17 12:29 - 2022-11-17 12:29 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2022-11-17 12:28 - 2022-11-17 12:28 - 002260480 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2022-11-17 12:28 - 2022-11-17 12:28 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-11-09 10:45 - 2022-11-09 10:46 - 000229048 _____ C:\Users\xavie\Downloads\OSCAISS_DPP_editionRib.pdf
2022-10-31 10:00 - 2022-10-31 10:00 - 000000000 ___HD C:\$WinREAgent

==================== Un mois (modifiés) ==================

(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)

2022-11-18 23:23 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-11-18 23:20 - 2016-10-27 16:19 - 000000000 ____D C:\Program Files (x86)\Google
2022-11-18 23:03 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-11-18 22:59 - 2021-02-08 12:49 - 001926126 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-11-18 22:59 - 2019-12-07 15:49 - 000834610 _____ C:\WINDOWS\system32\perfh00C.dat
2022-11-18 22:59 - 2019-12-07 15:49 - 000168324 _____ C:\WINDOWS\system32\perfc00C.dat
2022-11-18 22:59 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2022-11-18 22:53 - 2020-04-27 18:24 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2022-11-18 22:53 - 2016-10-27 10:41 - 000000000 __SHD C:\Users\xavie\IntelGraphicsProfiles
2022-11-18 22:52 - 2021-02-08 12:36 - 000000000 ____D C:\Users\xavie
2022-11-18 22:51 - 2021-02-08 13:02 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-11-18 22:51 - 2021-02-08 12:29 - 000008192 ___SH C:\DumpStack.log.tmp
2022-11-18 22:51 - 2021-02-08 12:29 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-11-18 22:51 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-11-17 23:53 - 2021-02-08 12:29 - 000472904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-11-17 23:52 - 2019-12-07 10:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-11-17 23:50 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-11-17 13:59 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-11-17 12:57 - 2016-10-27 13:45 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-11-17 12:50 - 2016-10-27 13:45 - 146960040 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-11-17 12:49 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-11-17 12:42 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2022-11-17 12:42 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2022-11-17 12:28 - 2021-02-08 12:33 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-11-06 09:28 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-11-06 09:20 - 2019-05-08 11:03 - 000000000 ____D C:\ProgramData\CanonIJPLM
2022-11-06 09:17 - 2021-01-18 17:48 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-11-06 09:17 - 2021-01-18 17:48 - 000002287 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2022-10-31 09:53 - 2021-02-08 13:02 - 000003690 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-10-31 09:53 - 2021-02-08 13:02 - 000003566 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore

==================== Fichiers à la racine de certains dossiers ========

2020-06-10 10:24 - 2020-06-10 10:24 - 000000000 ____D () C:\ProgramData\DUNotifier.exe
2019-03-15 18:20 - 2019-03-15 18:20 - 000213983 _____ () C:\Users\xavie\AppData\Roaming\Datofopacot
2020-02-10 12:22 - 2020-02-10 12:22 - 000224098 _____ () C:\Users\xavie\AppData\Roaming\Fanugiteco
2019-03-24 10:20 - 2019-03-24 10:20 - 000313251 _____ () C:\Users\xavie\AppData\Roaming\Fecomu
2019-04-05 10:20 - 2019-04-05 10:20 - 000234176 _____ () C:\Users\xavie\AppData\Roaming\Holesuhesifa
2019-05-07 10:41 - 2019-05-07 10:41 - 000147257 _____ () C:\Users\xavie\AppData\Roaming\Meham
2020-01-30 11:22 - 2020-01-30 11:22 - 000279923 _____ () C:\Users\xavie\AppData\Roaming\Mepokofecaha
2019-04-29 08:20 - 2019-04-29 08:20 - 000176995 _____ () C:\Users\xavie\AppData\Roaming\Nesabelipo
2019-04-16 00:20 - 2019-04-16 00:20 - 000185662 _____ () C:\Users\xavie\AppData\Roaming\Rasebo
2017-07-27 08:21 - 2020-02-10 12:22 - 000000661 _____ () C:\Users\xavie\AppData\Roaming\WB.CFG
2016-10-27 10:41 - 2022-11-18 22:54 - 002091553 _____ () C:\Users\xavie\AppData\Local\BTServer.log
2020-01-16 10:28 - 2020-01-16 10:28 - 000326427 _____ () C:\Users\xavie\AppData\Local\lJbzX
2019-08-08 16:25 - 2020-01-16 10:17 - 000326427 _____ () C:\Users\xavie\AppData\Local\lJbzXp
2020-03-31 16:28 - 2020-03-31 16:28 - 000185073 _____ () C:\Users\xavie\AppData\Local\lJbzXpNf
2017-12-12 09:17 - 2018-01-03 18:28 - 000000052 _____ () C:\Users\xavie\AppData\Local\lJbzXpNfDV
2017-12-14 09:35 - 2017-12-14 09:35 - 000000052 _____ () C:\Users\xavie\AppData\Local\ntz58bhntz
2018-01-03 18:01 - 2018-01-03 18:01 - 000000017 _____ () C:\Users\xavie\AppData\Local\resmon.resmoncfg

==================== SigCheck ============================

(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)

==================== Fin de FRST.txt ========================