Une amie s'est fait pirater sa messagerie messenger et m'a envoyé un message (c'est une femme avec un physique incroyable, ce qui peut expliquer le cerveau débranché sur ce coup...) avec un lien et j'ai bêtement cliqué dessus.
Une fenêtre vide s'est ouverte puis s'est directement fermé.
Mon navigateur m'avait bloqué la page mais je l'ai déverrouillée...
J'ai les 2 rapports FRST, si quelqu'un de compétant et sympathique passait par là...
J'ai multiplié les analyses anti-virus mais il n'y a rien de détecté (proposé sur ce même site).
J'espère ne pas avoir un keylogger ou une fuite de mes mots de passe via navigateur...
FRST
Je n'y connais pas grand chose mais ceci me parait suspect :Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 22-04-2022
Exécuté par jules (administrateur) sur DESKTOP-R7JKUAS (ASUS All Series) (07-05-2022 21:32:15)
Exécuté depuis C:\Users\jules\Desktop
Profils chargés: jules
Plate-forme: Microsoft Windows 10 Professionnel Version 21H2 19044.1645 (X64) Langue: Français (France)
Navigateur par défaut: FF
Mode d'amorçage: Normal
==================== Processus (Avec liste blanche) =================
(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)
(C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe ->) (Plex, Inc. -> ) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe
(C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe ->) (Plex, Inc. -> ) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCopyAccelerator.exe
(explorer.exe ->) (Focusrite Audio Engineering, Ltd.) [Fichier non signé] C:\Program Files\Focusriteusb\Focusrite Notifier.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Plex, Inc. -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(explorer.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\spool\drivers\x64\3\E_YATIWEE.EXE
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <12>
(services.exe ->) (Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(services.exe ->) (Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(services.exe ->) (Focusrite Audio Engineering Ltd.) [Fichier non signé] C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3b12ac0f95b18b9d\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Plex, Inc. -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(services.exe ->) (SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.722.3302.0_x64__8wekyb3d8bbwe\GameBar.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.722.3302.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registre (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
HKLM\...\Run: [Focusrite Notifier] => C:\Program Files\Focusriteusb\Focusrite Notifier.exe [5029376 2020-06-02] (Focusrite Audio Engineering, Ltd.) [Fichier non signé]
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Pas de fichier)
HKU\S-1-5-21-3775889627-1455495015-2339907373-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2635160 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3775889627-1455495015-2339907373-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [24584872 2022-02-28] (Plex, Inc. -> Plex, Inc.)
HKU\S-1-5-21-3775889627-1455495015-2339907373-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIWEE.EXE [418736 2019-08-22] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKU\S-1-5-21-3775889627-1455495015-2339907373-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-18\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [24584872 2022-02-28] (Plex, Inc. -> Plex, Inc.)
HKLM\...\Print\Monitors\EPSON XP-3100 Series 64MonitorBE: C:\Windows\system32\E_YLMBWEE.DLL [187392 2018-06-15] (Microsoft Windows Hardware Compatibility Publisher -> Seiko Epson Corporation)
HKLM\Software\...\AppCompatFlags\Custom\H3Blade.exe: [{62a24b39-0106-4990-90ea-3a09e9dda7a6}.sdb] -> GOG.com Heroes of Might and Magic 3
HKLM\Software\...\AppCompatFlags\Custom\Heroes3.exe: [{62a24b39-0106-4990-90ea-3a09e9dda7a6}.sdb] -> GOG.com Heroes of Might and Magic 3
HKLM\Software\...\AppCompatFlags\InstalledSDB\{62a24b39-0106-4990-90ea-3a09e9dda7a6}: [DatabasePath] -> C:\Windows\AppPatch\CustomSDB\{62a24b39-0106-4990-90ea-3a09e9dda7a6}.sdb [2022-03-11]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Tâches planifiées (Avec liste blanche) ============
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
Task: {31F0D64E-1140-46EE-9EC8-2E1EF012A84F} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144792 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {32126E26-3F5C-4DE2-B6FD-71CD5059F8A7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {370119F5-9FAC-4DF1-9ED2-1EEAA13DF64A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {37DB3DD3-D18E-4BAF-8DDB-FB8F524C2A18} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {412D72D2-0D9C-49F4-B359-6199A809C8E1} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [61336 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {4B9898BA-0299-444B-A865-2BAA236147A7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8376824 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {555A3BFD-AFEE-4D8C-B830-641B0DA6CE54} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144792 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {5CF825A2-5DAC-4EE8-B235-FC276C2C8D2E} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3775889627-1455495015-2339907373-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4200864 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {7836A712-731B-4869-B8D8-DB85B08F0F9D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22890448 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {887B9D7C-5367-4473-86EB-BD7E88D6B652} - System32\Tasks\EPSON XP-3100 Series Update {28565150-337A-4C3A-B88E-0908C69232ED} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSWEE.EXE [680440 2017-06-07] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
Task: {932751E2-42BA-44B2-93C1-F5565C5F6B61} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22890448 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {937EDB55-1F99-4D59-9285-0019CA3461DC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCmdRun.exe [993000 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B1BF5420-E966-4B04-9A7C-695D27165CB5} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {D32832F4-AA7D-404F-983F-6EB8548363EB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8376824 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {FF482492-EF24-4CF7-A69D-024BD1DA21E4} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4200864 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)
Task: C:\Windows\Tasks\EPSON XP-3100 Series Update {28565150-337A-4C3A-B88E-0908C69232ED}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSWEE.EXE:/EXE:{28565150-337A-4C3A-B88E-0908C69232ED} /F:UpdateWORKGROUP\DESKTOP-R7JKUAS$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Internet (Avec liste blanche) ====================
(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)
Tcpip\Parameters: [DhcpNameServer] 80.67.169.12
Tcpip\..\Interfaces\{285d362f-5ab0-448b-b6b0-054f1c1ecd8b}: [DhcpNameServer] 80.67.169.12
Edge:
=======
Edge Profile: C:\Users\jules\AppData\Local\Microsoft\Edge\User Data\Default [2022-05-07]
FireFox:
========
FF DefaultProfile: 26fsmizs.default
FF ProfilePath: C:\Users\jules\AppData\Roaming\Mozilla\Firefox\Profiles\26fsmizs.default [non trouvé(e)] <==== ATTENTION
FF ProfilePath: C:\Users\jules\AppData\Roaming\Mozilla\Firefox\Profiles\bv7wza72.default-release [2022-05-07]
FF Homepage: Mozilla\Firefox\Profiles\bv7wza72.default-release -> hxxp://www.google.fr/
FF NewTab: Mozilla\Firefox\Profiles\bv7wza72.default-release -> hxxp://www.bing.com/?pc=COSP&ptag=D031319-N060 ... =CT3335818
FF Notifications: Mozilla\Firefox\Profiles\bv7wza72.default-release -> hxxps://www.romstation.fr
FF Extension: (Dictionnaire français) - C:\Users\jules\AppData\Roaming\Mozilla\Firefox\Profiles\bv7wza72.default-release\Extensions\[email protected] [2022-03-10]
FF Extension: (Français Language Pack) - C:\Users\jules\AppData\Roaming\Mozilla\Firefox\Profiles\bv7wza72.default-release\Extensions\[email protected] [2022-05-05]
FF Extension: (uBlock Origin) - C:\Users\jules\AppData\Roaming\Mozilla\Firefox\Profiles\bv7wza72.default-release\Extensions\[email protected] [2022-04-12]
FF Extension: (Dark space - The best dynamic theme) - C:\Users\jules\AppData\Roaming\Mozilla\Firefox\Profiles\bv7wza72.default-release\Extensions\{22b0eca1-8c02-4c0d-a5d7-6604ddd9836e}.xpi [2022-03-14]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-04-17] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-04-17] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-04-17] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
==================== Services (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11758536 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934368 2021-10-01] (Epic Games Inc. -> Epic Games, Inc.)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [145224 2019-07-04] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.077.0410.0007\FileSyncHelper.exe [3399584 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
R2 Focusrite Control Server; C:\Program Files\Focusrite\Focusrite Control\Server\ControlServer.exe [1554432 2020-06-02] (Focusrite Audio Engineering Ltd.) [Fichier non signé]
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [1959776 2022-02-15] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6484832 2022-02-15] (GOG Sp. z o.o. -> GOG.com)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.077.0410.0007\OneDriveUpdaterService.exe [3847072 2022-05-03] (Microsoft Corporation -> Microsoft Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2575064 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3494672 2022-03-31] (Electronic Arts, Inc. -> Electronic Arts)
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [572072 2022-02-28] (Plex, Inc. -> Plex, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6254352 2022-04-18] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\NisSrv.exe [3116848 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MsMpEng.exe [133544 2022-04-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\Video Converter Ultimate\Transfer\DriverInstall.exe [107624 2018-10-10] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3b12ac0f95b18b9d\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3b12ac0f95b18b9d\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Pilotes (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Fichier non signé]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Fichier non signé]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 FocusritePCIeSwRoot; C:\Windows\System32\drivers\FocusritePCIeSwRoot.sys [97480 2016-11-16] (Focusrite Audio Engineering Ltd. -> Focusrite Audio Engineering Ltd.)
R3 Focusriteusb; C:\Windows\System32\drivers\Focusriteusb.sys [123456 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.)
R3 FocusriteusbSwRoot; C:\Windows\System32\drivers\FocusriteusbSwRoot.sys [92568 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.)
R3 Focusriteusb_AUDIO; C:\Windows\system32\drivers\FocusriteusbAudio.sys [87912 2020-06-02] (WDKTestCert builds,132265248139626354 -> Focusrite Audio Engineering Ltd.)
R3 MpKsl3319cf34; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C9759A12-DFDA-4372-9635-30EC2D390DB1}\MpKslDrv.sys [137464 2022-05-07] (Microsoft Windows -> Microsoft Corporation)
R3 sshid; C:\Windows\system32\DRIVERS\sshid.sys [48800 2022-02-23] (SteelSeries ApS -> SteelSeries ApS)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 tapnordvpn; C:\Windows\System32\drivers\tapnordvpn.sys [49744 2021-06-13] (nordvpn s.a. -> The OpenVPN Project)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [49600 2022-04-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [443664 2022-04-08] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [90384 2022-04-08] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\Windows\System32\drivers\wintun.sys [29592 2022-03-22] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
==================== NetSvcs (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
==================== Un mois (créés) (Avec liste blanche) =========
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2022-05-07 21:32 - 2022-05-07 21:32 - 000019052 _____ C:\Users\jules\Desktop\FRST.txt
2022-05-07 21:28 - 2022-05-07 14:53 - 002366976 _____ (Farbar) C:\Users\jules\Desktop\FRST64-2.1.exe
2022-05-07 14:32 - 2022-05-07 14:55 - 000000000 ____D C:\Program Files\RogueKiller
2022-05-07 14:32 - 2022-05-07 14:32 - 043520560 _____ (Adlice Software ) C:\Users\jules\Downloads\RogueKiller_setup.exe
2022-05-07 13:42 - 2022-05-07 13:42 - 098566144 _____ C:\Windows\system32\config\SOFTWARE
2022-05-07 13:39 - 2022-05-07 13:42 - 000000000 ____D C:\Windows\Microsoft Antimalware
2022-05-07 13:03 - 2022-05-07 13:03 - 000044933 _____ C:\Users\jules\Downloads\Shortcut.txt
2022-05-07 13:01 - 2022-05-07 13:03 - 000039316 _____ C:\Users\jules\Downloads\Addition.txt
2022-05-07 12:57 - 2022-05-07 13:03 - 000121489 _____ C:\Users\jules\Downloads\FRST.txt
2022-05-07 12:53 - 2022-05-07 21:32 - 000000000 ____D C:\FRST
2022-05-07 12:53 - 2022-05-07 14:57 - 000000000 ____D C:\Users\jules\Downloads\FRST-OlderVersion
2022-05-07 12:53 - 2022-05-07 12:53 - 002366976 _____ (Farbar) C:\Users\jules\Downloads\FRST64-2.1(2).exe
2022-05-05 21:21 - 2022-05-05 21:21 - 000078659 _____ C:\Users\jules\Downloads\Bouyguestelecom_Facture_20220502.pdf
2022-05-05 20:58 - 2022-05-05 20:58 - 000419275 _____ C:\Users\jules\Downloads\pass-maj.pdf
2022-05-05 20:42 - 2022-05-05 20:42 - 000019609 _____ C:\Users\jules\Downloads\XH5B5CJF6P-1-recapitulatif-passeport.pdf
2022-05-05 20:14 - 2022-05-05 20:14 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2022-05-05 18:20 - 2022-05-07 08:28 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-05-05 12:35 - 2022-05-05 12:35 - 000067508 _____ C:\Users\jules\Downloads\tifastheme.zip
2022-05-04 10:02 - 2022-05-04 10:07 - 000000000 ____D C:\Users\jules\Documents\NBGI
2022-05-04 10:02 - 2022-05-04 10:02 - 000000000 ____D C:\Users\jules\AppData\Local\NBGI
2022-05-04 10:02 - 2022-05-04 10:02 - 000000000 ____D C:\ProgramData\Steam
2022-05-03 16:27 - 2022-05-03 16:27 - 000001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2022-05-03 16:27 - 2022-05-03 16:27 - 000000000 ____D C:\Program Files\PCHealthCheck
2022-04-24 01:57 - 2022-04-24 01:57 - 226954009 _____ C:\Users\jules\Downloads\DC.rar
2022-04-23 15:01 - 2022-04-23 15:01 - 000139014 _____ C:\Users\jules\Downloads\Declaration_automatique_des_revenus_2021(1).pdf
2022-04-22 22:21 - 2022-04-22 22:21 - 011818224 _____ (Tim Kosse) C:\Users\jules\Downloads\FileZilla_3.59.0_win64-setup.exe
2022-04-21 20:52 - 2022-04-21 20:52 - 000014967 _____ C:\Users\jules\Downloads\ReleveMensuelDecembre2021(1).pdf
2022-04-21 20:52 - 2022-04-21 20:52 - 000011738 _____ C:\Users\jules\Downloads\ReleveMensuelJanvier2022.pdf
2022-04-21 20:50 - 2022-04-21 20:50 - 000014967 _____ C:\Users\jules\Downloads\ReleveMensuelDecembre2021.pdf
2022-04-21 20:50 - 2022-04-21 20:50 - 000011669 _____ C:\Users\jules\Downloads\ReleveMensuelNovembre2021.pdf
2022-04-21 20:49 - 2022-04-21 20:49 - 000012334 _____ C:\Users\jules\Downloads\ReleveMensuelOctobre2021.pdf
2022-04-21 20:47 - 2022-04-21 20:47 - 000012890 _____ C:\Users\jules\Downloads\ReleveMensuelMai2021.pdf
2022-04-21 20:46 - 2022-04-21 20:46 - 000011745 _____ C:\Users\jules\Downloads\ReleveMensuelFevrier2021.pdf
2022-04-21 20:35 - 2022-04-21 20:35 - 000139061 _____ C:\Users\jules\Downloads\Declaration_automatique_des_revenus_2021.pdf
2022-04-19 11:17 - 2022-04-19 11:17 - 000054548 _____ C:\Users\jules\Downloads\pdf(1)
2022-04-19 11:17 - 2022-04-19 11:17 - 000054548 _____ C:\Users\jules\Downloads\11528-7,CR d'imagerie médicale,LOINC de 202110141314.pdf
2022-04-19 11:16 - 2022-04-19 11:16 - 000036615 _____ C:\Users\jules\Downloads\pdf
2022-04-19 11:16 - 2022-04-19 11:16 - 000036615 _____ C:\Users\jules\Downloads\LDL gynécologie.pdf
2022-04-18 11:52 - 2022-04-18 11:52 - 000048640 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2022-04-18 11:52 - 2022-04-18 11:52 - 000039936 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2022-04-18 11:52 - 2022-04-18 11:52 - 000011803 _____ C:\Windows\system32\DrtmAuthTxt.wim
2022-04-18 11:51 - 2022-04-18 11:51 - 000162816 _____ C:\Windows\system32\DataStoreCacheDumpTool.exe
2022-04-17 19:33 - 2022-04-17 19:33 - 000000000 ___HD C:\$WinREAgent
2022-04-17 15:56 - 2022-04-17 15:56 - 000013655 _____ C:\Users\jules\Downloads\ACFrOgAOabkPeU7XEH9WXzQatcISatJOyU4FG2-TKiFoMivJXP6sbFtIpgQMaaKHK6OUwS1MrdUkZpQccenkrKzsjx7nMVa91gY1-h4o9mD0vq2ER8YIlOaknLFoojc=(1).pdf
2022-04-17 15:55 - 2022-04-17 15:55 - 000013655 _____ C:\Users\jules\Downloads\ACFrOgAOabkPeU7XEH9WXzQatcISatJOyU4FG2-TKiFoMivJXP6sbFtIpgQMaaKHK6OUwS1MrdUkZpQccenkrKzsjx7nMVa91gY1-h4o9mD0vq2ER8YIlOaknLFoojc=.pdf
2022-04-17 15:53 - 2022-04-17 15:54 - 013561364 _____ C:\Users\jules\Downloads\FISCALITE - FDX.pdf
2022-04-17 15:36 - 2022-04-17 15:36 - 002310622 _____ C:\Users\jules\Downloads\Multicanal - FDX .pptx
2022-04-17 15:32 - 2022-04-17 15:32 - 002596700 _____ C:\Users\jules\Downloads\MULTICANAL 1.pptx
2022-04-17 15:01 - 2022-04-17 15:01 - 000000000 ____D C:\Users\jules\Documents\Modèles Office personnalisés
2022-04-17 13:50 - 2022-04-17 13:50 - 000035703 _____ C:\Users\jules\Downloads\JustificatifsEbillet_20220417(6).pdf
2022-04-17 13:50 - 2022-04-17 13:50 - 000018196 _____ C:\Users\jules\Downloads\JustificatifsEbillet_20220417(5).pdf
2022-04-17 13:49 - 2022-04-17 13:49 - 000018198 _____ C:\Users\jules\Downloads\JustificatifsEbillet_20220417(4).pdf
2022-04-17 13:48 - 2022-04-17 13:48 - 000018198 _____ C:\Users\jules\Downloads\JustificatifsEbillet_20220417(3).pdf
2022-04-17 13:48 - 2022-04-17 13:48 - 000018196 _____ C:\Users\jules\Downloads\JustificatifsEbillet_20220417(2).pdf
2022-04-17 13:45 - 2022-04-17 13:45 - 000018198 _____ C:\Users\jules\Downloads\JustificatifsEbillet_20220417.pdf
2022-04-17 13:45 - 2022-04-17 13:45 - 000018196 _____ C:\Users\jules\Downloads\JustificatifsEbillet_20220417(1).pdf
2022-04-17 13:38 - 2022-05-05 05:18 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-04-17 13:19 - 2022-05-03 13:01 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-04-17 13:19 - 2022-05-03 13:01 - 000002170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-04-17 13:19 - 2022-04-17 13:19 - 000000000 ___RD C:\Users\Default\OneDrive
2022-04-17 13:19 - 2022-04-17 13:19 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2022-04-17 13:18 - 2022-04-17 13:18 - 000002546 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Entreprise.lnk
2022-04-17 13:18 - 2022-04-17 13:18 - 000002472 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2022-04-17 13:18 - 2022-04-17 13:18 - 000002472 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2022-04-17 13:18 - 2022-04-17 13:18 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2022-04-17 13:18 - 2022-04-17 13:18 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk
2022-04-17 13:18 - 2022-04-17 13:18 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2022-04-17 13:18 - 2022-04-17 13:18 - 000002433 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2022-04-17 13:18 - 2022-04-17 13:18 - 000002395 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2022-04-17 13:18 - 2022-04-17 13:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office
2022-04-17 13:13 - 2022-05-03 13:08 - 000000000 ____D C:\Program Files\Microsoft Office
2022-04-17 13:13 - 2022-04-17 13:13 - 000000000 ____D C:\Program Files\Microsoft Office 15
2022-04-17 12:14 - 2022-04-17 12:14 - 000109145 _____ C:\Users\jules\Downloads\INCIVILITES.pdf
2022-04-12 18:55 - 2022-04-12 18:55 - 000142221 _____ C:\Users\jules\Downloads\AttestationDroits.pdf
2022-04-12 18:55 - 2022-04-12 18:55 - 000142221 _____ C:\Users\jules\Downloads\AttestationDroits(1).pdf
2022-04-11 14:10 - 2022-04-11 14:10 - 000000921 _____ C:\Users\jules\Downloads\Firefox.Update.eb00a9.zip
2022-04-08 22:30 - 2022-04-08 22:30 - 001771891 _____ C:\Users\jules\Downloads\Protections-auditives-Qeos.pdf
2022-04-08 20:54 - 2022-04-08 20:54 - 005463488 _____ C:\Users\jules\Downloads\FormulesMariage_Chaletang(1).pdf
2022-04-07 15:40 - 2022-04-07 15:40 - 000000000 ____D C:\Users\jules\AppData\Local\cache
2022-04-07 14:57 - 2022-04-07 14:57 - 000000000 ____D C:\Users\jules\AppData\Local\Rufus
2022-04-07 14:52 - 2022-04-07 14:52 - 001380936 _____ (Akeo Consulting) C:\Users\jules\Desktop\rufus-3.18.exe
2022-04-07 14:51 - 2022-04-07 15:06 - 000000432 __RSH C:\ProgramData\ntuser.pol
2022-04-07 13:14 - 2022-04-07 13:14 - 000026416 _____ C:\Users\jules\Downloads\Expedition-62315264.pdf
2022-04-07 08:41 - 2022-04-07 08:41 - 000070161 _____ C:\Users\jules\Downloads\Bulletin salaire_SALVADOR_03_2022.pdf
==================== Un mois (modifiés) ==================
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2022-05-07 21:29 - 2022-03-11 15:08 - 000000000 ____D C:\Users\jules\AppData\Roaming\discord
2022-05-07 21:29 - 2022-03-11 15:08 - 000000000 ____D C:\Users\jules\AppData\Local\Discord
2022-05-07 21:13 - 2022-03-10 18:56 - 000000000 ____D C:\Windows\system32\SleepStudy
2022-05-07 19:36 - 2022-03-10 19:05 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-05-07 19:35 - 2022-03-10 19:05 - 000000000 ____D C:\Users\jules\AppData\LocalLow\Mozilla
2022-05-07 13:13 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-05-07 12:51 - 2022-03-10 19:03 - 001771434 _____ C:\Windows\system32\PerfStringBackup.INI
2022-05-07 12:51 - 2019-12-07 16:50 - 000791886 _____ C:\Windows\system32\perfh00C.dat
2022-05-07 12:51 - 2019-12-07 16:50 - 000150052 _____ C:\Windows\system32\perfc00C.dat
2022-05-07 12:51 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2022-05-07 12:43 - 2022-03-11 12:47 - 000000000 ____D C:\ProgramData\NVIDIA
2022-05-07 12:43 - 2022-03-11 12:38 - 000000000 ____D C:\Users\jules\AppData\Local\Plex Media Server
2022-05-07 12:43 - 2022-03-10 19:03 - 000000000 ___RD C:\Users\jules\OneDrive
2022-05-07 12:43 - 2022-03-10 18:56 - 000008192 ___SH C:\DumpStack.log.tmp
2022-05-07 12:43 - 2022-03-10 18:56 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-05-07 12:43 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2022-05-07 12:39 - 2019-12-07 11:03 - 000524288 _____ C:\Windows\system32\config\BBI
2022-05-07 12:36 - 2022-03-11 15:20 - 000000000 ____D C:\Users\jules\AppData\Local\Battle.net
2022-05-07 10:27 - 2022-03-11 16:04 - 000000000 ____D C:\Users\jules\Documents\StarCraft II
2022-05-07 10:27 - 2022-03-11 16:04 - 000000000 ____D C:\Program Files (x86)\StarCraft II
2022-05-07 10:27 - 2022-03-11 15:18 - 000000000 ____D C:\Users\jules\AppData\Local\Blizzard Entertainment
2022-05-07 10:26 - 2022-03-11 15:21 - 000000000 ____D C:\ProgramData\Blizzard Entertainment
2022-05-07 10:23 - 2022-03-11 15:19 - 000000000 ____D C:\Program Files (x86)\Battle.net
2022-05-07 08:43 - 2022-03-10 18:56 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-05-07 08:43 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-05-07 08:43 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2022-05-07 08:28 - 2022-03-10 19:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-05-06 23:30 - 2022-03-11 14:58 - 000000000 ____D C:\Users\jules\AppData\Roaming\FileZilla
2022-05-06 23:20 - 2022-03-11 15:10 - 000000000 ____D C:\Program Files (x86)\Steam
2022-05-06 08:43 - 2022-03-11 19:25 - 000000000 ____D C:\Users\jules\AppData\Roaming\Cuphead
2022-05-05 21:31 - 2022-03-11 14:36 - 000000000 ____D C:\ProgramData\Riot Games
2022-05-05 20:14 - 2022-03-10 19:05 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-05-05 05:36 - 2022-03-10 19:50 - 000000000 ____D C:\Users\jules\Desktop\Divers
2022-05-04 09:49 - 2022-03-11 11:41 - 000000000 ____D C:\ProgramData\Package Cache
2022-05-03 13:01 - 2022-03-10 19:03 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3775889627-1455495015-2339907373-1001
2022-04-23 17:32 - 2022-03-11 14:54 - 000000000 ____D C:\Users\jules\AppData\Roaming\Blitz
2022-04-23 16:36 - 2022-03-11 14:54 - 000000032 _____ C:\Users\jules\AppData\Roaming\.machineId
2022-04-23 16:05 - 2022-03-11 14:58 - 000000000 ____D C:\Users\jules\AppData\Local\FileZilla
2022-04-23 10:10 - 2022-03-11 11:44 - 000001927 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2022-04-23 10:10 - 2022-03-11 11:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2022-04-23 10:10 - 2022-03-11 11:44 - 000000000 ____D C:\Program Files\FileZilla FTP Client
2022-04-22 19:59 - 2022-03-10 19:02 - 000000000 ____D C:\Users\jules\AppData\Local\D3DSCache
2022-04-22 11:37 - 2022-03-24 00:01 - 000001653 _____ C:\Users\jules\Desktop\Elden Ring.lnk
2022-04-21 21:25 - 2022-03-10 19:43 - 000000000 ____D C:\Users\jules\Desktop\Musique Nini
2022-04-18 23:26 - 2022-03-10 18:56 - 000481080 _____ C:\Windows\system32\FNTCACHE.DAT
2022-04-18 23:25 - 2019-12-07 16:53 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellExperiences
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\Provisioning
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\PolicyDefinitions
2022-04-18 23:25 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2022-04-18 11:54 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2022-04-17 15:50 - 2022-03-11 14:50 - 000000000 ____D C:\Users\jules\AppData\Roaming\vlc
2022-04-17 15:36 - 2022-03-10 19:02 - 000000000 ____D C:\Users\jules\AppData\Local\Packages
2022-04-17 13:19 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2022-04-16 19:06 - 2022-03-11 15:33 - 000000000 ____D C:\Program Files (x86)\Origin
2022-04-16 11:49 - 2022-03-11 11:48 - 000000000 ____D C:\Windows\system32\MRT
2022-04-16 11:47 - 2022-03-11 11:48 - 143823848 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2022-04-10 11:37 - 2022-03-10 18:56 - 000003634 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-04-10 11:37 - 2022-03-10 18:56 - 000003510 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-04-08 07:14 - 2022-03-10 18:56 - 000000000 ____D C:\Windows\system32\Drivers\wd
2022-04-07 17:43 - 2022-04-02 12:44 - 000000000 ____D C:\Users\jules\Bibliothèque calibre
2022-04-07 17:43 - 2022-04-02 12:41 - 000000000 ____D C:\Users\jules\AppData\Roaming\calibre
2022-04-07 17:42 - 2022-03-10 19:00 - 000000000 ____D C:\Users\jules
2022-04-07 15:40 - 2022-04-02 12:44 - 000000000 ____D C:\Users\jules\AppData\Local\calibre-cache
2022-04-07 14:51 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2022-04-07 14:51 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
==================== Fichiers à la racine de certains dossiers ========
2022-03-11 14:54 - 2022-04-23 16:36 - 000000032 _____ () C:\Users\jules\AppData\Roaming\.machineId
==================== SigCheck ============================
(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)
==================== Fin de FRST.txt ========================
"2022-04-07 13:14 - 2022-04-07 13:14 - 000026416 _____ C:\Users\jules\Downloads\Expedition-62315264.pdf
2022-04-07 08:41 - 2022-04-07 08:41 - 000070161 _____ C:\Users\jules\Downloads\Bulletin salaire_SALVADOR_03_2022.pdf"
et ceci
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Le lien ressemblait à https:/ /4xxx.short. gy/(plein de lettres)