Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 20-05-2017 Exécuté par didier (21-05-2017 06:48:54) Exécuté depuis C:\Users\didier\Downloads Windows 10 Home Version 1607 (X64) (2016-10-01 12:49:09) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= Administrateur (S-1-5-21-4145378659-3646147737-513564761-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-4145378659-3646147737-513564761-503 - Limited - Disabled) didier (S-1-5-21-4145378659-3646147737-513564761-1001 - Administrator - Enabled) => C:\Users\didier HomeGroupUser$ (S-1-5-21-4145378659-3646147737-513564761-1003 - Limited - Enabled) Invité (S-1-5-21-4145378659-3646147737-513564761-501 - Limited - Disabled) UpdatusUser (S-1-5-21-4145378659-3646147737-513564761-1004 - Limited - Enabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Bitdefender Antivirus (Enabled - Up to date) {3FB17364-4FCC-0FA7-6BBF-973897395371} AS: Bitdefender Antispyware (Enabled - Up to date) {84D09280-69F6-0029-510F-AC4AECBE19CC} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Bitdefender Pare-feu (Enabled) {078AF241-05A3-0EFF-40E0-3E0D69EA140A} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.10.2001 - Acer Incorporated) abDocs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.02.2001 - Acer Incorporated) Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.12.2004 - Acer Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.2.1.260 - Adobe Systems Incorporated) Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated) AllFrTV version 5.1 (HKLM-x32\...\{B32CEC1E-1FDA-46DD-A429-31E63C270007}_is1) (Version: 5.1 - Racacax) AlphaGo (HKLM-x32\...\{118B6258-BF13-47C9-8D46-B2A349196B5D}) (Version: 1.0.0 - Default Company Name) <==== ATTENTION AlphaGo (HKLM-x32\...\{2C652C0A-EC71-4797-8077-F67649177AB0}) (Version: 1.0.2 - Default Company Name) <==== ATTENTION AlphaGo (HKLM-x32\...\{B7CB7055-EFAE-4CD2-928A-15DB5F4FF7C7}) (Version: 1.2.5 - AlphaGo) <==== ATTENTION AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.22.2001.0 - Acer Incorporated) Apple Application Support (32 bits) (HKLM-x32\...\{05E07D23-91E9-4E70-A4CC-EF505088F967}) (Version: 5.4.1 - Apple Inc.) Apple Application Support (64 bits) (HKLM\...\{741291DA-2B34-4D44-8FB6-58EDE21261D8}) (Version: 5.4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{DB18F1C0-846F-46F5-A074-5B97C8AF5C8E}) (Version: 10.3.1.2 - Apple Inc.) Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.) Arma 3 (HKLM\...\Steam App 107410) (Version: - Bohemia Interactive) Belgium e-ID middleware 4.2.2 (build 3170) (HKLM\...\{DB942AEA-93D6-4FE4-8862-180D35A73170}) (Version: 4.2.3170 - Belgian Government) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 20.0.23.1252 - Bitdefender) Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: 21.0.25.80 - Bitdefender) Bitdefender Total Security 2017 (HKLM\...\Bitdefender) (Version: 21.0.25.80 - Bitdefender) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Call of Duty 2 (HKLM\...\Steam App 2630) (Version: - Infinity Ward) Call of Duty 4: Modern Warfare (HKLM\...\Steam App 7940) (Version: - Infinity Ward) clear.fi SDK - Video 2 (x32 Version: 2.1.1925 - CyberLink Corp.) Hidden clear.fi SDK- Movie 2 (x32 Version: 2.1.2008 - CyberLink Corp.) Hidden Counter-Strike (HKLM\...\Steam App 10) (Version: - Valve) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) CyberLink MediaEspresso 6.5 (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.3103_44819 - CyberLink Corp.) Dropbox (HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\Dropbox) (Version: 26.4.24 - Dropbox, Inc.) Eid Reader plugin 1.0.1 (HKLM-x32\...\2008-1418-6737-7883) (Version: 1.0.1 - ) eMule (HKLM-x32\...\eMule) (Version: - ) Euro Truck Simulator 2 (HKLM-x32\...\{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1) (Version: 1.0.5 - SCS Software) Feu Vert pour le permis de conduire (HKLM-x32\...\{26284E06-C005-4C6A-ADA6-1E99D843B08E}) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.96 - Google Inc.) Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.) Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden Hercules Webcam Station Evolution (HKLM\...\{B60D61FD-1CB1-4ED5-974E-8C959F14208E}) (Version: - ) HiSuite (HKLM-x32\...\Hi Suite) (Version: 1.0 - Huawei Technologies Co.,Ltd) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) iCloud (HKLM\...\{724A887F-2B55-4306-B6F9-8F0E7A04B1B5}) (Version: 5.2.2.87 - Apple Inc.) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.0.1207 - Intel Corporation) iTunes (HKLM\...\{6C01A0A7-7440-4D48-93C6-2927A1E93FE6}) (Version: 12.6.0.100 - Apple Inc.) Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Logiciel pour périphérique à chipset Intel® (x32 Version: 10.1.1.38 - Intel(R) Corporation) Hidden Ludi (HKLM-x32\...\Ludi) (Version: - ) Medal of Honor(TM) Multiplayer (HKLM-x32\...\Steam App 47830) (Version: - Electronic Arts) Microsoft Office Professionnel Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710F4C1C-CC18-4C49-8CBF-51240C89A1A2}) (Version: - ) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{AD8A2FA1-06E7-4B0D-927D-6E54B3D31028}) (Version: - ) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Module linguistique Microsoft Visual Studio 2010 Tools pour Office Runtime (x64) - FRA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 49.0.2 (x86 fr) (HKLM-x32\...\Mozilla Firefox 49.0.2 (x86 fr)) (Version: 49.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2.6136 - Mozilla) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.3 - Notepad++ Team) NVIDIA 3D Vision Controller Driver 305.29 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 305.29 - NVIDIA Corporation) NVIDIA PhysX System Software 9.12.0213 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation) NVIDIA Pilote 3D Vision 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.54 - NVIDIA Corporation) NVIDIA Pilote audio HD : 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA Pilote graphique 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation) Online.io Application (x32 Version: 2.1.0 - Microleaves) Hidden <==== ATTENTION Orange Cloud (HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\Orange Cloud) (Version: 2.0.0 - Orange-Belgium) Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Package de pilotes Windows - Fedict SmartCard (02/22/2017 4.2.2) (HKLM\...\5C41EE2EBE4AD57429660F64CD25501617C1B29C) (Version: 02/22/2017 4.2.2 - Fedict) Panneau de configuration NVIDIA 376.54 (Version: 376.54 - NVIDIA Corporation) Hidden PhotoPad Image Editor (HKLM-x32\...\PhotoPad) (Version: 2.43 - NCH Software) Powersuite (HKLM-x32\...\{793A260C-CDBF-499C-ABBA-B51E8E076867}_is1) (Version: 4.5.1.0 - Uniblue Systems Limited) <==== ATTENTION Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7960 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.2.8400.30137 - Realtek Semiconductor Corp.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skypeâ„¢ 7.28 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.28.101 - Skype Technologies S.A.) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.0.15064.11 - Samsung Electronics Co., Ltd.) SXi-Q (HKLM-x32\...\{9A1E32FD-ACB6-4247-8E53-CA7608AFE515}) (Version: 2.0.3 - YiHiEcigar) Traffic Exchange (x32 Version: 2.1.0 - Microleaves) Hidden <==== ATTENTION Unity Web Player (HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\UnityWebPlayer) (Version: 5.3.6f1 - Unity Technologies ApS) Update for Skype for Business 2015 (KB3191873) 64-Bit Edition (HKLM\...\{90150000-012B-040C-1000-0000000FF1CE}_Office15.PROPLUS_{D6E29338-0D16-4873-8F8B-0DED5CDD4B67}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3191876) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{63B92B9B-BAA1-4708-BB4B-216BB5FD6322}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3191876) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{63B92B9B-BAA1-4708-BB4B-216BB5FD6322}) (Version: - Microsoft) Update for Skype for Business 2015 (KB3191876) 64-Bit Edition (HKLM\...\{90150000-012B-040C-1000-0000000FF1CE}_Office15.PROPLUS_{63B92B9B-BAA1-4708-BB4B-216BB5FD6322}) (Version: - Microsoft) Viber (HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\Viber) (Version: 5.0.1.42 - Viber Media Inc) Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) War Thunder Launcher 1.0.1.604 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment) Webcam Station Evolution (HKLM-x32\...\{B60D61FD-1CB1-4ED5-974E-8C959F14208E}) (Version: 4.1.1.2 - Hercules) Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation) WinRAR 5.00 (32 bits) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) WINSNARE (HKLM-x32\...\{56D19032-B59F-4020-994B-15912A49CD96}) (Version: 4.4.6 - WINSNARE) <==== ATTENTION Xtra Controller Ex (HKLM-x32\...\{59579B12-97E6-437E-B988-BA032165D355}) (Version: 4.0.2.1 - Hercules) YAC(Yet Another Cleaner!) (HKLM-x32\...\iSafe) (Version: - ELEX DO BRASIL PARTICIPAÇÕES LTDA) <==== ATTENTION ==================== Personnalisé CLSID (Avec liste blanche): ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\ChromeHTML: -> C:\Program Files (x86)\Bookness\Application\chrome.exe (Google Inc.) <==== ATTENTION CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> pas de chemin du fichier CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> pas de chemin du fichier CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> pas de chemin du fichier CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\didier\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4145378659-3646147737-513564761-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> pas de chemin du fichier ==================== Tâches planifiées (Avec liste blanche) ============= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {01FDA7C7-AE7D-43E1-8A85-9F0C656BF02E} - System32\Tasks\Traffic Exchange v2 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION Task: {0208851A-863D-4CE9-8A28-E23794037BED} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Pas de fichier <==== ATTENTION Task: {03AD0135-E4A7-4C52-833D-A15ED283F588} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-4145378659-3646147737-513564761-1001Core1d23717301d2818 => C:\Users\didier\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.) Task: {08B91B4B-0DD5-4F18-8D3B-E93D6BB1750E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Pas de fichier <==== ATTENTION Task: {0B0983D5-AF60-4213-8DC1-F7307161D011} - System32\Tasks\Online Application v209 Guard => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: {10523A41-EC6E-4412-ABD0-5F5A8BC3B7CE} - System32\Tasks\GoogleUpdateTaskMachineUA1d0908d3ddba36 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {17517A08-AA3D-45B1-9419-E297CF359062} - System32\Tasks\Traffic Exchange v209 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: {19EEBC11-9553-4DFB-B845-D2F9E2F38177} - System32\Tasks\GoogleUpdateTaskMachineCore1cf488b379adc56 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {217FA7DC-456C-48A5-9ED0-22E5392ACFD8} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender 2015\bdproductdata.exe Task: {252B1527-AD6D-4863-93CC-79C7C4276545} - System32\Tasks\Online Application v209 => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: {3014B9B3-F5EA-4034-9656-A3462E02F89E} - \DealPlyLiveUpdateTaskMachineCore -> Pas de fichier <==== ATTENTION Task: {30695894-C533-4FCD-BD39-4700375F1547} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe Task: {32223648-A43B-4A62-AEFF-987B344CC75B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.) Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe Task: {3BA4154E-ADC1-49D2-B052-60B70191C471} - System32\Tasks\Traffic Exchange v209 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: {3DC70EE9-CBB2-494D-887F-36AA76B59DD3} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe Task: {3F4197D5-18DC-4B34-BE32-39F756537C1A} - System32\Tasks\Metoghsezertion Server => C:\Program Files (x86)\Qumase\ivuty.exe [2017-03-18] (Glarysoft Ltd) Task: {47751CF7-446C-46A3-B045-1B465EC25C02} - System32\Tasks\Traffic Exchange v209 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: {4867B1E5-2E8A-40D8-BFBE-7D741A66229A} - System32\Tasks\Hotkey Utility => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2012-07-06] (Acer Incorporated) Task: {4C3A65E2-97DC-4311-8894-4340E2E28749} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender 2017\bdagent.exe [2017-04-20] (Bitdefender) Task: {53893357-1923-4E56-83BD-4F10EC7B9051} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Pas de fichier <==== ATTENTION Task: {541E29E1-7FE6-4B71-86AB-50A8F4249DB9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Pas de fichier <==== ATTENTION Task: {635EF394-7151-47E6-B4B8-BF87F7F83DB2} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4145378659-3646147737-513564761-1001 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe Task: {63700C6F-EA33-4393-8289-B482449CE6A5} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-07-04] (CyberLink) Task: {63BFF8F9-54EF-45B3-8598-F0A7208B71E8} - System32\Tasks\VisualBee-chromeinstaller => C:\Program Files (x86)\VisualBee\VisualBee-chromeinstaller.exe <==== ATTENTION Task: {6876DA6A-D0A9-4448-83A5-0F9B2805AA20} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\didier\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe Task: {6E71E60F-331B-40DA-B6F6-7DEAC281E0C5} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Pas de fichier <==== ATTENTION Task: {6F7AD47E-8A78-4745-B7C4-00070439B7AD} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-4145378659-3646147737-513564761-1001UA1d23717304f77c9 => C:\Users\didier\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.) Task: {705FEEC1-D08A-4EB6-BF7B-D90548EA94B7} - System32\Tasks\Online Application v209 Guardian => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: {7274D463-733D-4C89-A7A3-B8847C2D827E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Pas de fichier <==== ATTENTION Task: {77E48ADA-FA8B-406E-A57D-F6BCC80818BF} - System32\Tasks\Traffic Exchange v2 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION Task: {7A3E2DAA-B97F-41CA-B862-A8F18EBE8953} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {8480F7DF-CA0B-4666-B3DB-DBD74438726B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {85522674-AF92-46C5-A030-8ED90DB18C34} - System32\Tasks\Milimili => C:\Program Files (x86)\MIO\MIO.exe [2017-05-17] () <==== ATTENTION Task: {8560B6EC-D86D-4411-9869-E9BBEC2671AB} - System32\Tasks\{3B017C61-38E3-4386-A84F-4C469783EE79} => pcalua.exe -a J:\Permis.exe -d J:\ Task: {8874FF69-22AD-4E53-980F-00E122321443} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [2016-08-30] (Acer Incorporated) Task: {89363553-FFBD-493A-A79B-80BFF317D90D} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Pas de fichier <==== ATTENTION Task: {8B83BD2C-991F-4F92-BA3F-FAFBC7C1AA9F} - \ElectroLyrics-1-updater -> Pas de fichier <==== ATTENTION Task: {8FB6AAE3-92D4-43F3-A895-CFEEB2117ED6} - System32\Tasks\abDocsDllLoader => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe [2016-08-15] () Task: {99AB868E-98F1-40DC-837C-C3C0D05AD89E} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Pas de fichier <==== ATTENTION Task: {9FD61DA9-C3F1-4DAC-AB86-181E801E0A2D} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2012-08-24] () Task: {9FF985BB-CD01-4CF3-87DE-81CED4CB3D8F} - System32\Tasks\VisualBee-firefoxinstaller => C:\Program Files (x86)\VisualBee\VisualBee-firefoxinstaller.exe <==== ATTENTION Task: {B01FED8B-28B6-42C7-B64B-3D7225011A63} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-pietquin.didier@gmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-09-25] (Adobe Systems Incorporated) Task: {B23FFB04-2C85-4D1D-A5D5-F9C94AC7570A} - System32\Tasks\GoogleUpdateTaskMachineUA1cf488b3a759535 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {B417FCBC-975D-49EE-8929-F7EB7788872A} - \ElectroLyrics-1-codedownloader -> Pas de fichier <==== ATTENTION Task: {B6D51A21-3BCB-4FA6-B9E0-10AE7552DD36} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Pas de fichier <==== ATTENTION Task: {B7F9E219-BD21-4ACA-9281-E57F45825C59} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Pas de fichier <==== ATTENTION Task: {BDCB632E-6920-46F3-8FBC-D97B34636948} - System32\Tasks\VisualBee-codedownloader => C:\Program Files (x86)\VisualBee\VisualBee-codedownloader.exe <==== ATTENTION Task: {C201ECD9-EAB5-4AC8-B012-3D3F7DA66519} - System32\Tasks\Windows-PG => powershell.exe C:\windows\psgo\psgo.ps1 Task: {C271C0DE-542F-4858-BF55-790863CF1467} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2012-06-22] () Task: {C2C22D35-C311-4BEE-B841-2A76EC756962} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {CA3EE631-2BD4-4D5B-84C6-0D0C2C9110D1} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2017-02-02] (Bitdefender) Task: {CF1D99FB-50B1-4F19-8D49-B366BE09C395} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\ezprint.exe Task: {D0442519-464F-415A-98F4-D377FE276DCF} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {D0C8AA95-0DD8-48BF-92C9-406C313B73ED} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "hxxp://www.roboform.com/uninstall.html?aaa=KICMOJHMHMHMHMOMJJOJCNLJGMIMPMCNLMOJMMJMCNOJOJKJNMCNLMGMNMMMIMMJPMGMKJMJNMNJJNJICMIMCNGMCNNMFMGMCNOMPMCNGMNMPMPMFMJMCNNMCNGMNMPMPMCNNMJNPICMPMFMFMPMJNHICMPIIJKJOMPMJNBJCMLJGJLJGJKJNIJNKJCMJNNICMJNDJCMJJNI" Task: {D1750378-BB51-47A4-AE30-7AACE8D8B9FD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-11] (Adobe Systems Incorporated) Task: {D8E87561-EF15-4E4A-BF0B-254802A892ED} - System32\Tasks\Traffic Exchange v2 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION Task: {DC42DAD9-201D-4094-AF84-F251BFD0A4FC} - \ElectroLyrics-1-chromeinstaller -> Pas de fichier <==== ATTENTION Task: {DD20DA61-2B9B-4476-958E-E9DA1802319F} - System32\Tasks\GoogleUpdateTaskMachineCore1d0908d2ba4139 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {DEEC0525-15AC-467D-951F-97359B64BF3B} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2012-08-23] (Acer Incorporated) Task: {E043901C-853B-4499-999B-F276B85C3B1D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-05-10] (Microsoft Corporation) Task: {E9FEDBA4-4000-4C92-BE5B-F83CFA7A4B62} - \ElectroLyrics-1-enabler -> Pas de fichier <==== ATTENTION Task: {ECBABE2C-07E4-4CFA-B145-D39A866E0909} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {F0F457B3-8C3A-4B80-ADDF-4BBD099D842D} - \AmiUpdXp -> Pas de fichier <==== ATTENTION Task: {F5C80CE3-61DE-461A-B275-21690629D45E} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2016-09-09] (Acer) Task: {F81CCAB3-82DF-416D-80DA-2FA7C01C79D9} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Pas de fichier <==== ATTENTION Task: {F92A937F-216C-4BD7-8250-F20A7B411A0B} - System32\Tasks\HPCustParticipation HP Photosmart 5520 series => C:\Program Files\HP\HP Photosmart 5520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-4145378659-3646147737-513564761-1001Core1d23717301d2818.job => C:\Users\didier\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-4145378659-3646147737-513564761-1001UA1d23717304f77c9.job => C:\Users\didier\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf488b379adc56.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf488b3a759535.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Online Application v209 Guard.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Online Application v209 Guardian.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Online Application v209.job => C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\VisualBee-chromeinstaller.job => C:\Program Files (x86)\VisualBee\VisualBee-chromeinstaller.exe̘/installcrx /agentregpath='VisualBee' /extensionfilepath C:\Program Files (x86)\VisualBee\33906.crx' /appid=33906 /srcid='000196' /subid='verticals-ads,' /zdata='0' /bic=3E1D31BB888E464E85A6CDD1DD920474IE /verifier=1362ac7ac721691b259c1f52e7a65cc1 /installerversion=1_27_153 /installerfullversion=1.27.153.8 /installationtime=1381264243 /statsdomain=hxxp:/stats.update-apps.com /errorsdomain=hxxp:/errors.update-apps.com <==== ATTENTION Task: C:\WINDOWS\Tasks\VisualBee-codedownloader.job => C:\Program Files (x86)\VisualBee\VisualBee-codedownloader.exeƹ/reinstallapp /agentregpath='VisualBee' /appid=33906 /srcid='000196' /subid='verticals-ads,' /zdata='0' /bic=3E1D31BB888E464E85A6CDD1DD920474IE /verifier=1362ac7ac721691b259c1f52e7a65cc1 /installerversion=1_27_153 /installerfullversion=1.27.153.8 /installationtime=1381264243 /statsdomain=hxxp:/stats.update-apps.com /errorsdomain=hxxp:/errors.update-apps.com /codedownloaddomain=hxxp:/app-static.crossrider.com <==== ATTENTION Task: C:\WINDOWS\Tasks\VisualBee-firefoxinstaller.job => C:\Program Files (x86)\VisualBee\VisualBee-firefoxinstaller.exe˱/installxpi /agentregpath='VisualBee' /extensionfilepath C:\Program Files (x86)\VisualBee\33906.xpi' /appid=33906 /srcid='000196' /subid='verticals-ads,' /zdata='0' /bic=3E1D31BB888E464E85A6CDD1DD920474IE /verifier=1362ac7ac721691b259c1f52e7a65cc1 /installerversion=1_27_153 /installerfullversion=1.27.153.8 /installationtime=1381264243 /statsdomain=hxxp:/stats.update-apps.com /errorsdomain=hxxp:/errors.update-apps.com /waitforbrowser=300 /extensionid=67314b39-24e6-4f05-99f3-3f88c7cddd17@6c5fa560-13a3-4d42-8e90-53d9930111f9.com /extensionversion=0.91 /prefsbranch=a67314b3924e64f0599f33f88c7cddd176c5fa56013a34d428e9053d9930111f9com33906 /updateurl=hxxps:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/33906.rdf <==== ATTENTION ==================== Raccourcis ============================= (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) Shortcut: C:\Users\didier\Favorites\Acer\Acer.lnk -> hxxp://www.acer.com Shortcut: C:\Users\didier\Documents\tv ip\Simple_TV.BY.ovnisland\Simple.TV\work\Channel\logo\logo - Ярлык.lnk -> E:\PortableApps\SimpleTV Pre\work\Channel\logo (Pas de fichier) <===== Cyrillic Shortcut: C:\Users\didier\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Bookness\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Bookness\Application\chrome.exe (Google Inc.) ShortcutWithArgument: C:\Users\didier\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\didier\Desktop\big_bang_empire.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://www.bigbangempire.com/?ref=281-000-000-005 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14202\C\Users\didier\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14202\C\Users\didier\Desktop\big_bang_empire.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://www.bigbangempire.com/?ref=281-000-000-005 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14174\C\Users\didier\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14174\C\Users\didier\Desktop\big_bang_empire.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://www.bigbangempire.com/?ref=281-000-000-005 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14172\C\Users\didier\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14172\C\Users\didier\Desktop\big_bang_empire.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://www.bigbangempire.com/?ref=281-000-000-005 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14101\C\Users\didier\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14101\C\Users\didier\Desktop\big_bang_empire.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://www.bigbangempire.com/?ref=281-000-000-005 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14079\C\Users\didier\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14079\C\Users\didier\Desktop\big_bang_empire.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://www.bigbangempire.com/?ref=281-000-000-005 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14045\C\Users\didier\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\didier\AppData\Local\Microsoft\Windows\FileHistory\Data\14025\C\Users\didier\Desktop\BigFarm.lnk -> C:\Program Files (x86)\Boxfat\Application\chrome.exe (Google Inc.) -> hxxp://bigfarm.goodgamestudios.com/?w=239064 ShortcutWithArgument: C:\Users\didier\AppData\Local\Google\Chrome\User Data\Lanceur d'applications Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list ShortcutWithArgument: C:\Users\didier\AppData\Local\Boxfat\User Data\Lanceur d'applications Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list ==================== Modules chargés (Avec liste blanche) ============== 2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-05-10 06:28 - 2017-04-28 02:49 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2017-05-01 08:09 - 2013-09-03 14:29 - 00111832 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\bdmetrics.dll 2017-05-01 08:09 - 2017-02-07 12:34 - 01008448 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_001_001\ashttpbr.mdl 2017-05-01 08:09 - 2017-02-07 12:34 - 00541952 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_001_001\ashttpdsp.mdl 2017-05-01 08:09 - 2017-02-07 12:34 - 03243920 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_001_001\ashttpph.mdl 2017-05-01 08:09 - 2017-02-07 12:34 - 01544568 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_001_001\ashttprbl.mdl 2017-04-07 08:19 - 2017-04-12 04:26 - 00246272 _____ () C:\Users\didier\AppData\Local\AMD\amd.exe 2017-03-16 16:08 - 2017-03-16 16:08 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2017-03-16 16:08 - 2017-03-16 16:08 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-11-25 08:16 - 2016-11-25 08:16 - 00192200 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe 2016-10-01 14:17 - 2016-12-29 15:16 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-05-10 06:28 - 2017-04-28 02:49 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2013-10-16 19:02 - 2013-10-16 19:02 - 03358064 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll 2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll 2016-10-01 15:09 - 2016-10-01 15:09 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-15 15:04 - 2017-03-04 08:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-03-15 15:05 - 2017-03-04 08:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-15 15:05 - 2017-03-04 08:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-15 15:05 - 2017-03-04 08:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-05-10 06:28 - 2017-04-28 01:36 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-05-10 06:29 - 2017-04-28 01:37 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 00092472 _____ () C:\Program Files\iTunes\zlib1.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 01354040 _____ () C:\Program Files\iTunes\libxml2.dll 2017-05-02 15:38 - 2017-05-02 15:38 - 00023840 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\lang\fr-FR\bdsystray.txtui 2016-08-15 15:24 - 2016-08-15 15:24 - 01769312 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe 2017-05-09 05:35 - 2017-05-09 05:35 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-05-09 05:35 - 2017-05-09 05:35 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-03-22 13:13 - 2017-04-18 02:35 - 01023416 _____ () C:\Program Files (x86)\Elex-tech\YAC\iImportLib.dll 2017-03-22 13:13 - 2016-05-23 04:37 - 00065696 _____ () C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll 2017-04-18 09:57 - 2017-05-04 15:00 - 00124928 _____ () c:\users\didier\appdata\local\kitty\kitty.dll 2017-03-22 13:13 - 2017-03-22 04:23 - 00106496 _____ () c:\programdata\microsoft\phone tools\corecon\12.0\addons\sdkfilesver.dll 2013-01-18 08:01 - 2012-07-18 05:55 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2017-03-16 16:09 - 2017-03-16 16:09 - 01041720 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2017-03-16 16:09 - 2017-03-16 16:09 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2017-05-09 11:32 - 2017-05-09 16:40 - 00323584 _____ () C:\Users\didier\AppData\Local\background_fault\bf.dll 2017-05-04 10:06 - 2017-04-11 08:36 - 67718656 _____ () C:\Users\didier\AppData\Local\background_fault\libcef.dll 2017-05-04 10:06 - 2017-04-11 08:36 - 01922560 _____ () C:\Users\didier\AppData\Local\background_fault\libglesv2.dll 2017-05-04 10:06 - 2017-04-11 08:36 - 00079872 _____ () C:\Users\didier\AppData\Local\background_fault\libegl.dll 2017-05-20 07:07 - 2017-05-20 07:07 - 00098816 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32api.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00110080 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\pywintypes27.dll 2017-05-20 07:07 - 2017-05-20 07:07 - 00364544 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\pythoncom27.dll 2017-05-20 07:07 - 2017-05-20 07:07 - 00320512 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32com.shell.shell.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00914432 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\_hashlib.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 01176576 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\wx._core_.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00806400 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\wx._gdi_.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00816128 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\wx._windows_.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 01067008 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\wx._controls_.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00733184 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\wx._misc_.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00682496 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\pysqlite2._sqlite.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00088064 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\_ctypes.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00686080 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\unicodedata.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00119808 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32file.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00108544 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32security.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00007168 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\hashobjs_ext.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00017920 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\thumbnails_ext.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00088064 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\usb_ext.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00012800 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\common.time34.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00018432 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32event.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00167936 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32gui.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00046080 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\_socket.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 01303552 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\_ssl.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00128512 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\_elementtree.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00127488 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\pyexpat.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00038912 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32inet.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00036864 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\_psutil_windows.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00524248 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\windows._lib_cacheinvalidation.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00011264 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32crypt.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00123392 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\wx._wizard.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00077312 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\wx._html2.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00027648 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\_multiprocessing.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00020480 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\_yappi.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00035840 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32process.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00078848 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\wx._animate.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00024064 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32pipe.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00010240 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\select.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00025600 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32pdh.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00017408 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32profile.pyd 2017-05-20 07:07 - 2017-05-20 07:07 - 00022528 ____R () C:\Users\didier\AppData\Local\Temp\_MEI80522\win32ts.pyd 2017-05-10 06:28 - 2017-04-28 02:49 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2017-03-16 16:08 - 2017-03-16 16:08 - 00189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll 2016-09-09 10:51 - 2016-09-09 10:51 - 00202456 _____ () C:\Program Files (x86)\Acer\Acer Portal\curllib.dll 2016-09-09 10:51 - 2016-09-09 10:51 - 00119000 _____ () C:\Program Files (x86)\Acer\Acer Portal\OpenLDAP.dll 2016-10-01 14:24 - 2016-10-01 14:24 - 00015064 _____ () C:\WINDOWS\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll 2016-08-30 15:09 - 2016-08-30 15:09 - 00013016 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll 2016-08-30 15:05 - 2016-08-30 15:05 - 00277856 _____ () C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll 2016-09-21 05:23 - 2016-08-30 09:10 - 00063192 _____ () C:\Program Files (x86)\Acer\AOP Framework\acer\inteldll.dll 2017-03-22 13:13 - 2017-03-09 07:31 - 02187096 _____ () C:\Program Files (x86)\Boxfat\Application\libglesv2.dll 2017-03-22 13:13 - 2017-03-09 07:31 - 00086360 _____ () C:\Program Files (x86)\Boxfat\Application\libegl.dll ==================== Alternate Data Streams (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.) AlternateDataStreams: C:\Users\didier\Downloads\FRST64.exe:BDU [0] AlternateDataStreams: C:\Users\didier\Downloads\winchk_2.0.exe:BDU [0] AlternateDataStreams: C:\Users\didier\Downloads\ZHPDiag3.exe:BDU [0] ==================== Mode sans échec (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.) ==================== Association (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.) ==================== Internet Explorer sites de confiance/sensibles =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.) ==================== Hosts contenu: =============================== (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2013-08-22 15:25 - 2017-05-21 06:04 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Autres zones ============================ (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-4145378659-3646147737-513564761-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\didier\Pictures\KAWASAKI-GTR-1400-front-side-view_1127x800.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "EzPrint" HKLM\...\StartupApproved\Run: => "lxdumon.exe" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "KiesTrayAgent" HKLM\...\StartupApproved\Run32: => "beid" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\StartupFolder: => "Dropbox.lnk" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\StartupFolder: => "Envoyer à OneNote.lnk" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\StartupFolder: => "TunesNINJA.lnk" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\Run: => "KiesPreload" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\Run: => "" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\Run: => "Wahoo" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\Run: => "Dropbox Update" HKU\S-1-5-21-4145378659-3646147737-513564761-1001\...\StartupApproved\Run: => "Viber" ==================== RèglesPare-feu (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [{9A69DE08-811A-47DC-8FCD-F9425929782A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 4\iw3mp.exe FirewallRules: [{28DCC1F0-C1CF-4656-BFDA-D9DCC185D1C8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 4\iw3mp.exe FirewallRules: [{53463DCD-8D88-4763-AEB9-1998822341A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 4\iw3sp.exe FirewallRules: [{2B3C002F-FC34-48A1-B04C-CB5D05292383}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 4\iw3sp.exe FirewallRules: [{6D5F0595-075D-4EC5-8B43-D128647C7185}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS4E68\HPDiagnosticCoreUI.exe FirewallRules: [{F4C444E5-5A15-4E8A-A3D1-05C86A167B6F}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS4E68\HPDiagnosticCoreUI.exe FirewallRules: [{521000BA-5631-4BBD-BFE9-3476161A1465}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS3B53\HPDiagnosticCoreUI.exe FirewallRules: [{AA67EF6B-81D2-4ADC-8061-A2F03B3B8BA4}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS3B53\HPDiagnosticCoreUI.exe FirewallRules: [{04D40010-96B1-4A2C-869B-7D5B6290D935}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS3194\HPDiagnosticCoreUI.exe FirewallRules: [{ACEE8B36-217A-4D90-8913-E145C595E5CA}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS3194\HPDiagnosticCoreUI.exe FirewallRules: [{1C704D61-A18F-4254-9F74-D4EC815F17E0}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS3153\HPDiagnosticCoreUI.exe FirewallRules: [{825C6C77-3CA3-4B50-8345-883773B7CA91}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS3153\HPDiagnosticCoreUI.exe FirewallRules: [{1E07A101-EB88-4EC3-BB5A-68F22E9443B9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{C19441B5-B717-420C-A1A0-B9F19D353BD3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{3D31A55A-DF57-4ED7-AA07-D59EC64F068C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{9CB61086-418E-4E73-8E4E-BA3CCFC7FC90}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [UDP Query User{CFAF717A-727F-4EAA-8AF0-BEA7F285C279}C:\warthunder\win64\aces.exe] => (Allow) C:\warthunder\win64\aces.exe FirewallRules: [TCP Query User{4AF68C73-99D1-4456-B7A9-397185486C66}C:\warthunder\win64\aces.exe] => (Allow) C:\warthunder\win64\aces.exe FirewallRules: [UDP Query User{4189556A-B337-4A9D-A15D-E9DE28876F9B}C:\warthunder\aces.exe] => (Block) C:\warthunder\aces.exe FirewallRules: [TCP Query User{830F747E-9BAC-43D5-949D-2B794A4256CC}C:\warthunder\aces.exe] => (Block) C:\warthunder\aces.exe FirewallRules: [{FF50D670-95A5-427D-9E56-29E1A277CD07}] => (Allow) C:\WarThunder\bpreport.exe FirewallRules: [{AE45BF7E-C0F0-4649-9FD5-5C86AB6A135E}] => (Allow) C:\WarThunder\bpreport.exe FirewallRules: [{1D25CC94-CEA4-478F-94AF-64E231558947}] => (Allow) C:\WarThunder\launcher.exe FirewallRules: [{0748BFDC-0EC2-4D4C-B56F-1CCC170083BC}] => (Allow) C:\WarThunder\launcher.exe FirewallRules: [UDP Query User{324210A4-38F1-475F-B86F-FFB1B0349295}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [TCP Query User{D0AA7587-2111-45F8-89FB-BEDBF28959EB}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [{7AEE3E1B-09A2-4A7F-8BCA-E8B78F030DA6}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{A99DA294-B80F-49DE-BEA6-363186269CDE}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{9AE4D147-A172-45E0-A6B9-274A949B8D23}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{F9C8AA54-C6FC-4898-9376-A9B45751F34C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{385EDCA5-C2DC-4C40-90D9-4055E148411B}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS079A\HPDiagnosticCoreUI.exe FirewallRules: [{D6D97448-2AE7-47A3-B8BD-667FBD15FEC1}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS079A\HPDiagnosticCoreUI.exe FirewallRules: [{B64E45DF-C1EB-4FFC-AC55-23267518A754}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS2612\HPDiagnosticCoreUI.exe FirewallRules: [{0DFC7685-25F5-426E-ACAD-AA2DF3FBB1BC}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS2612\HPDiagnosticCoreUI.exe FirewallRules: [{EA839CBF-6737-4851-9A53-C338CAF38CB1}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS15F3\HPDiagnosticCoreUI.exe FirewallRules: [{3B67E718-535B-4355-96DA-43210C74B597}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS15F3\HPDiagnosticCoreUI.exe FirewallRules: [{D6E388FE-7437-4BFF-833D-01E22DA13BBC}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS109A\HPDiagnosticCoreUI.exe FirewallRules: [{EBDF6237-6D8F-40FC-B428-08D57AF1A861}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS109A\HPDiagnosticCoreUI.exe FirewallRules: [{7F1000CC-8AD2-4BA0-8B59-AF0B24B9BE1B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Source\hl2.exe FirewallRules: [{FA14FD8B-5A4B-4229-AC7A-BFA5CA8CA884}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Source\hl2.exe FirewallRules: [{25130241-4E95-4B3C-9D50-7655650814D3}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS07DA\HPDiagnosticCoreUI.exe FirewallRules: [{58FC407E-0D01-4720-8EC4-200651917C72}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS07DA\HPDiagnosticCoreUI.exe FirewallRules: [{A0C67014-7F09-4A5A-B8AB-B362101A4F1F}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe FirewallRules: [{D13A83D1-96FD-4595-A980-CA656CA796CB}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe FirewallRules: [UDP Query User{6B48DFF6-47D0-43CE-A764-DFE25AC3EA99}C:\program files (x86)\hercules\dualpix hd\xtrctrlex.exe] => (Allow) C:\program files (x86)\hercules\dualpix hd\xtrctrlex.exe FirewallRules: [TCP Query User{5E111E3A-DD87-4222-BF0B-B9C6C8459C86}C:\program files (x86)\hercules\dualpix hd\xtrctrlex.exe] => (Allow) C:\program files (x86)\hercules\dualpix hd\xtrctrlex.exe FirewallRules: [{E7D7C61A-2AC9-4F26-96CD-BEDB7B4B3C35}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS569B\HPDiagnosticCoreUI.exe FirewallRules: [{5202554D-F33C-4BBF-B7DE-8072B15D4EBA}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS569B\HPDiagnosticCoreUI.exe FirewallRules: [{DC3C14D8-D4FD-48F5-91BF-A2B73A48C10D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{7C1EB92B-9F0B-4928-A483-75C33DA0FC03}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{309CFBC5-81D7-42FE-8E74-C647799D50E4}] => (Block) J:\tl-wa830re\easysetupassistant.exe FirewallRules: [{67C39B8B-EF95-48CF-A077-BDC8F6CC5AD7}] => (Block) J:\tl-wa830re\easysetupassistant.exe FirewallRules: [UDP Query User{ABB0A9F9-B4A9-470A-9982-EAA464DA99F1}J:\tl-wa830re\easysetupassistant.exe] => (Allow) J:\tl-wa830re\easysetupassistant.exe FirewallRules: [TCP Query User{20B3AA00-7150-4563-B273-06A8D0DA4792}J:\tl-wa830re\easysetupassistant.exe] => (Allow) J:\tl-wa830re\easysetupassistant.exe FirewallRules: [{41098955-2FF6-43DD-BA7F-F090A9B017F6}] => (Allow) C:\Program Files (x86)\GameSpy Arcade\Aphex.exe FirewallRules: [{C34D11E3-1F98-47C9-9553-C7826620EB58}] => (Allow) C:\Program Files (x86)\GameSpy Arcade\Aphex.exe FirewallRules: [{9B42D3B6-44EC-47D0-9381-11210ADBA9E4}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{B9D5B385-5DBF-413C-8CBA-ABF22BFDBB93}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [UDP Query User{27E8D993-1437-45EF-9BB9-5CAA4D699BED}C:\users\didier\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\didier\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{729C32BC-DF8A-456B-95D7-D9A33487659D}C:\users\didier\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\didier\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{96455BE8-5BBB-4145-9DA3-9F8056FD32CD}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{C2BE2EF7-187F-4D2B-917B-1838C9DF0F12}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{580CEE38-D6ED-4C02-93FA-1D5805A18F06}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{92EBE596-DD31-457E-B82B-96E87C6F3AD0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{FA510188-1040-4E5F-B55C-8016A2557DA4}C:\program files (x86)\hercules\webcam station evolution\stationev.exe] => (Allow) C:\program files (x86)\hercules\webcam station evolution\stationev.exe FirewallRules: [TCP Query User{EBAC2A49-D0B2-4980-9B7E-2C73B6197A04}C:\program files (x86)\hercules\webcam station evolution\stationev.exe] => (Allow) C:\program files (x86)\hercules\webcam station evolution\stationev.exe FirewallRules: [{2BC92AE7-7865-4425-A698-38FAE0491A5E}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{06DC3720-C90C-4AA9-9736-4CE6B788441F}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{427221D0-1A57-441A-9976-B8C2888571DD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe FirewallRules: [{D0650060-65B7-416A-A65E-64486C7E0FF1}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe FirewallRules: [{F3C8EF1F-C453-4700-84AA-BD6406A78266}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe FirewallRules: [{2452BB69-29F7-4828-8F67-CE97789ECFE4}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe FirewallRules: [{3455AEBA-CE36-4621-B750-159BF5B735D4}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Video\VideoPlayer.exe FirewallRules: [{9667E489-C94B-4E98-BD38-22857758A267}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Video\MusicPlayer.exe FirewallRules: [{7BAEC217-D4F1-4458-908E-5DB04ABE67D7}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Movie\PlayMovie.exe FirewallRules: [{F9169336-FF57-4FC9-9928-D89EF24A67AD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe FirewallRules: [{78518A7C-DD6B-4149-A30A-1AF06BD9E461}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe FirewallRules: [{3DD45F37-9475-4AB2-BE05-81108D4B99D0}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe FirewallRules: [{7CCE1FC9-01AF-4295-A86E-24D1D633483E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe FirewallRules: [{44BB0F4B-56E3-4C99-A812-F1A1E3B0A119}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe FirewallRules: [{300455B5-AA4C-40E8-A457-3C49A1C8B2D0}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe FirewallRules: [{FC4F1348-1ADC-4488-B89E-F118E62F8957}] => (Allow) C:\Users\didier\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{1EC98BAE-D968-4CCA-B4CA-AC952DDBFFA1}] => (Allow) C:\Users\didier\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{0B92FABE-ACCF-4BE7-A479-EB61A7545D9D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{B44510C9-9251-46A9-BDD1-0821DA5B3169}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{041BD938-E52B-436D-A2A4-AE1D6E64DA26}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Medal of Honor\MP\mohmpgame.exe FirewallRules: [{0000DB19-B230-4DC5-957E-9FA2E59BB2CC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Medal of Honor\MP\mohmpgame.exe FirewallRules: [{D3A4183E-D0E7-4C18-A29A-ADC0A2DA80AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Medal of Honor\Support\EA Help\Electronic_Arts_Technical_Support.htm FirewallRules: [{46425DEB-C862-4983-8021-75BC5975812F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Medal of Honor\Support\EA Help\Electronic_Arts_Technical_Support.htm FirewallRules: [{77A34417-B3CC-476C-8A7D-309737D6C4B8}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{0CB38B7D-588B-4FE8-87EC-700C483DF45D}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{728EC0E2-9ADB-4D90-9620-12E86CE0CB39}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{CF14F322-367A-4108-BDF0-06364FD30ABF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{84F6F65A-13A4-4DEF-907F-1833791B57F1}] => (Allow) C:\Users\didier\AppData\Local\DProtect\DProtectSvc.exe FirewallRules: [{01376405-9531-4FC0-98AF-BE1227A8229E}] => (Allow) C:\ProgramData\eSafe\eGdpSvc.exe FirewallRules: [{8BB0FBC3-4AFB-4375-A482-38D7B533CC66}] => (Allow) C:\Users\didier\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{2C24CFD4-6FE0-49FD-ACBD-CD8FE6B1A980}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{5A4DAB3E-9CC7-4089-A2D3-9E8C3FE87099}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{677066EF-8CD8-4CC4-A0B9-D11B7C9391D9}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [TCP Query User{3B1683C6-6E0C-4AB8-A176-F7C5039983CF}C:\users\didier\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\didier\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{CD069B79-A101-4A48-9AE1-17F9CCB9DD76}C:\users\didier\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\didier\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{77DCD4D4-82E4-4D6F-A59C-1EE4FE104D16}C:\program files (x86)\hercules\dualpix hd\xtrctrlex.exe] => (Allow) C:\program files (x86)\hercules\dualpix hd\xtrctrlex.exe FirewallRules: [UDP Query User{49323BFB-23A7-4B05-BF94-47529495D41C}C:\program files (x86)\hercules\dualpix hd\xtrctrlex.exe] => (Allow) C:\program files (x86)\hercules\dualpix hd\xtrctrlex.exe FirewallRules: [{77017DE8-7E16-4FE8-B819-9299FB74EEAC}] => (Allow) C:\Windows\System32\lxducoms.exe FirewallRules: [{8367CFF4-037A-4B6B-97A1-06237C3A194E}] => (Allow) C:\Windows\System32\lxducoms.exe FirewallRules: [{CDF4EED0-E2E3-4A35-8560-0A4D51352229}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdupswx.exe FirewallRules: [{A73159E7-1D60-4149-879D-BCF80E67AE25}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdupswx.exe FirewallRules: [TCP Query User{FDC1AFDF-56A8-4AC3-8D23-17918C41B35D}C:\program files (x86)\emule\emule.exe] => (Block) C:\program files (x86)\emule\emule.exe FirewallRules: [UDP Query User{BF861BBB-74F9-4A96-8873-A23A3694498A}C:\program files (x86)\emule\emule.exe] => (Block) C:\program files (x86)\emule\emule.exe FirewallRules: [{6B556F02-3457-453A-8263-A4F6670592CB}] => (Allow) C:\Program Files\HP\HP Photosmart 5520 series\Bin\DeviceSetup.exe FirewallRules: [{026A9153-DD90-4DC6-879B-A817FA830532}] => (Allow) C:\Program Files\HP\HP Photosmart 5520 series\Bin\HPNetworkCommunicator.exe FirewallRules: [{28DD7729-9E31-4341-8864-23B1A968ABB3}] => (Allow) C:\Program Files\HP\HP Photosmart 5520 series\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{D109ACAD-6857-4E57-B44A-0599775878DE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{C060BF9B-908C-42F3-ACA3-0BF61A28AEDE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{B2A6DB7C-B596-47C2-AC55-AE426503D201}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS7DEC\HPDiagnosticCoreUI.exe FirewallRules: [{EC238A35-092D-45FB-AF90-9AF28181A7C8}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS7DEC\HPDiagnosticCoreUI.exe FirewallRules: [{D65CE546-88FA-4A73-9079-ACC031B77B1C}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS7E31\HPDiagnosticCoreUI.exe FirewallRules: [{6C82A468-3208-4406-85E0-6FE24B3A01AF}] => (Allow) C:\Users\didier\AppData\Local\Temp\7zS7E31\HPDiagnosticCoreUI.exe FirewallRules: [{575FCBB0-33DF-4F33-B1FC-98BD0C16DBA0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{460F9239-F6B8-4E5D-855F-D0651B5040CF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{D941919C-0C92-4BF5-B295-3DDCC88FB74D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 2\CoD2SP_s.exe FirewallRules: [{4BE1017C-4A29-41F9-A35D-C20B4EC9EAA0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 2\CoD2SP_s.exe FirewallRules: [{EF524284-0094-4F57-B8A0-11283F3578DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 2\CoD2MP_s.exe FirewallRules: [{EEC70E19-538A-42EC-BDDF-4043D4FAE6B1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty 2\CoD2MP_s.exe FirewallRules: [{5E8FFC83-EB9D-4977-AB4F-C4BFA2F815ED}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{0ECF95FF-E0EB-4BA3-B1A4-88A2B20B352C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{F9EA02BD-2717-45BF-810F-8C63E5C27B87}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Arma 3\arma3launcher.exe FirewallRules: [{BE0D5504-1610-4D1F-9575-00F9CEA12039}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Arma 3\arma3launcher.exe FirewallRules: [TCP Query User{20A82FBB-55A6-4059-A5F3-1BBD007BE26E}C:\program files (x86)\steam\steamapps\common\arma 3\arma3.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\arma 3\arma3.exe FirewallRules: [UDP Query User{CC0C0797-5CDD-4559-8235-0EE07CBDF1E1}C:\program files (x86)\steam\steamapps\common\arma 3\arma3.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\arma 3\arma3.exe FirewallRules: [{FAB29139-D29B-4FAF-A726-D1DD264BCE86}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Half-Life\hl.exe FirewallRules: [{9D97EE05-FB2E-43F4-800B-331009A7BE02}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Half-Life\hl.exe FirewallRules: [TCP Query User{5FC96BFD-1F03-41C2-8EA0-D4E5F792100A}C:\program files\windowsapps\xbmcfoundation.kodi_16.9.903.0_x86__4n2hpmxwrvr6p\kodi.exe] => (Allow) C:\program files\windowsapps\xbmcfoundation.kodi_16.9.903.0_x86__4n2hpmxwrvr6p\kodi.exe FirewallRules: [UDP Query User{0E847FC1-666B-4AB8-84EF-FC6A0F438707}C:\program files\windowsapps\xbmcfoundation.kodi_16.9.903.0_x86__4n2hpmxwrvr6p\kodi.exe] => (Allow) C:\program files\windowsapps\xbmcfoundation.kodi_16.9.903.0_x86__4n2hpmxwrvr6p\kodi.exe FirewallRules: [TCP Query User{0FEE69EF-C44C-48A3-95EC-966BC80674F8}C:\program files\windowsapps\xbmcfoundation.kodi_16.9.904.0_x86__4n2hpmxwrvr6p\kodi.exe] => (Allow) C:\program files\windowsapps\xbmcfoundation.kodi_16.9.904.0_x86__4n2hpmxwrvr6p\kodi.exe FirewallRules: [UDP Query User{F4C4FED4-7EB9-4AA8-8617-22902C9FD84A}C:\program files\windowsapps\xbmcfoundation.kodi_16.9.904.0_x86__4n2hpmxwrvr6p\kodi.exe] => (Allow) C:\program files\windowsapps\xbmcfoundation.kodi_16.9.904.0_x86__4n2hpmxwrvr6p\kodi.exe FirewallRules: [{11D2FFF0-0B7E-4BFE-9F8D-5787606E1AFA}] => (Allow) C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe FirewallRules: [{8F63F2D0-76A8-4389-9A7D-9CD5A21DC23E}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe FirewallRules: [{1CA2DB0A-D6AF-4FDE-B7D7-89994ED602FA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{C3DE99BD-7425-4CF3-B96B-DACCEA1D0B51}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{FA66BF15-86AA-4071-90BD-ACAC9107BAB3}] => (Allow) C:\Program Files (x86)\Bookness\Application\chrome.exe FirewallRules: [{830241D7-4573-4342-9433-E1F7C3D75622}] => (Allow) C:\Program Files (x86)\MIO\loader\st1000dm003-1ch162_z1d30lqwxxxxz1d30lqw.dat FirewallRules: [{FC05744A-7711-4748-9DFD-4DDE11C1CB69}] => (Allow) C:\Program Files (x86)\MIO\loader\st1000dm003-1ch162_z1d30lqwxxxxz1d30lqw.dat ==================== Points de restauration ========================= 13-05-2017 07:41:15 Windows Update 16-05-2017 19:19:42 Windows Update 16-05-2017 19:20:28 Windows Update 20-05-2017 07:13:06 Windows Update ==================== Éléments en erreur du Gestionnaire de périphériques ============= Name: Périphérique USB inconnu (échec de demande de descripteur de périphérique) Description: Périphérique USB inconnu (échec de demande de descripteur de périphérique) Class Guid: {36fc9e60-c465-11cf-8056-444553540000} Manufacturer: (Contrôleur hôte USB standard) Service: Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Erreurs du Journal des événements: ========================= Erreurs Application: ================== Error: (05/21/2017 02:44:01 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Event-ID 0 Error: (05/20/2017 07:22:28 AM) (Source: MsiInstaller) (EventID: 11921) (User: AUTORITE NT) Description: Product: Nero Update -- Error 1921.Service Nero Update (NAUpdate) could not be stopped. Verify that you have sufficient privileges to stop system services. Error: (05/20/2017 07:18:24 AM) (Source: MsiInstaller) (EventID: 11921) (User: AUTORITE NT) Description: Product: Nero Update -- Error 1921.Service Nero Update (NAUpdate) could not be stopped. Verify that you have sufficient privileges to stop system services. Error: (05/20/2017 07:13:32 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Les services de chiffrement ont échoué lors du traitement de l’appel OnIdentity() dans l’objet System Writer. Details: AddLegacyDriverFiles: Unable to back up image of binary Protocole LLDP (Link Layer Discovery Protocol) Microsoft. System Error: Accès refusé. . Error: (05/20/2017 07:10:15 AM) (Source: MsiInstaller) (EventID: 11921) (User: AUTORITE NT) Description: Product: Nero Update -- Error 1921.Service Nero Update (NAUpdate) could not be stopped. Verify that you have sufficient privileges to stop system services. Error: (05/20/2017 07:07:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante XtrCtrlEx.exe, version : 4.0.2.1, horodatage : 0x4e671a00 Nom du module défaillant : MFC80.DLL, version : 8.0.50727.6195, horodatage : 0x4dcde15e Code d’exception : 0xc0000005 Décalage d’erreur : 0x000000000006f1e2 ID du processus défaillant : 0x1eac Heure de début de l’application défaillante : 0x01d2d127065b4ec9 Chemin d’accès de l’application défaillante : C:\Program Files (x86)\Hercules\Dualpix HD\XtrCtrlEx.exe Chemin d’accès du module défaillant: C:\WINDOWS\WinSxS\amd64_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_8448b2bd328df189\MFC80.DLL ID de rapport : 5931c641-f285-4ee5-9465-01b2edc5a33c Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (05/20/2017 07:01:33 AM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Erreur lors de la mise à jour de l’état Bitdefender Pare-feu vers SECURITY_PRODUCT_STATE_OFF (erreur %3). Error: (05/20/2017 07:01:33 AM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Erreur lors de la mise à jour de l’état Bitdefender Antispyware vers SECURITY_PRODUCT_STATE_SNOOZED (erreur %3). Error: (05/20/2017 07:01:33 AM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Erreur lors de la mise à jour de l’état Bitdefender Antivirus vers SECURITY_PRODUCT_STATE_SNOOZED (erreur %3). Error: (05/20/2017 07:01:15 AM) (Source: MsiInstaller) (EventID: 11921) (User: AUTORITE NT) Description: Product: Nero Update -- Error 1921.Service Nero Update (NAUpdate) could not be stopped. Verify that you have sufficient privileges to stop system services. Erreurs système: ============= Error: (05/20/2017 01:38:03 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Le service NPASRE s’est terminé de façon inattendue pour la 1ème fois. Error: (05/20/2017 01:18:31 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Le service CWASRE s’est arrêté avec l’erreur : Accès refusé. Error: (05/20/2017 08:57:53 AM) (Source: DCOM) (EventID: 10010) (User: AUTORITE NT) Description: Le serveur {F3B4E234-7A68-4E43-B813-E4BA55A065F6} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (05/20/2017 07:18:32 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Le service NPASRE s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 21600000 millisecondes : Redémarrer le service. Error: (05/20/2017 07:18:31 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Le service CWASRE s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 21600000 millisecondes : Redémarrer le service. Error: (05/20/2017 07:14:04 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: AUTORITE NT) Description: Échec de l’installation : l’installation de la mise à jour suivante a échoue avec l’erreur 0x8024200b : Hewlett-Packard - Imaging - Null Print - HP Photosmart 5520 series. Error: (05/20/2017 07:12:27 AM) (Source: DCOM) (EventID: 10016) (User: MAISON) Description: Les paramètres d’autorisation par défaut de l’ordinateur n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} et l’APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} au SID maison\didier de l’utilisateur (S-1-5-21-4145378659-3646147737-513564761-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy du conteneur d’applications (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (05/20/2017 07:10:26 AM) (Source: DCOM) (EventID: 10010) (User: AUTORITE NT) Description: Le serveur {784E29F4-5EBE-4279-9948-1E8FE941646D} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (05/20/2017 07:07:25 AM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} et l’APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (05/20/2017 07:07:25 AM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} et l’APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. CodeIntegrity: =================================== Date: 2017-05-21 06:33:47.168 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 06:15:46.805 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 06:03:47.103 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 05:48:47.098 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 05:33:47.138 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 05:18:47.097 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 05:03:47.112 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 04:48:47.160 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 04:43:31.332 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2017-05-21 04:33:47.171 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. ==================== Infos Mémoire =========================== Processeur: Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz Pourcentage de mémoire utilisée: 60% Mémoire physique - RAM - totale: 8134.06 MB Mémoire physique - RAM - disponible: 3226.39 MB Mémoire virtuelle totale: 11204.06 MB Mémoire virtuelle disponible: 2872.82 MB ==================== Lecteurs ================================ Drive c: (Acer) (Fixed) (Total:452.25 GB) (Free:205.56 GB) NTFS Drive d: (DATA) (Fixed) (Total:453.11 GB) (Free:426.04 GB) NTFS ==================== MBR & Table des partitions ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 31996953) Partition: GPT. ==================== Fin de Addition.txt ============================