Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-12-2017 Ran by fan (20-12-2017 15:37:41) Running from C:\Users\fan\Desktop Windows 10 Pro Version 1709 16299.125 (X64) (2017-11-22 22:23:39) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= 5805D1B356C2411AAA57 (S-1-5-21-72047652-2448835880-2394339217-1005 - Limited - Enabled) 7A7F89670DE84E429D80 (S-1-5-21-72047652-2448835880-2394339217-1009 - Limited - Enabled) Administrator (S-1-5-21-72047652-2448835880-2394339217-500 - Administrator - Disabled) B7AF9926518B4B1A8A3F (S-1-5-21-72047652-2448835880-2394339217-1013 - Limited - Enabled) D6844348EA8E4C7D881D (S-1-5-21-72047652-2448835880-2394339217-1018 - Limited - Enabled) DefaultAccount (S-1-5-21-72047652-2448835880-2394339217-503 - Limited - Disabled) fan (S-1-5-21-72047652-2448835880-2394339217-1001 - Administrator - Enabled) => C:\Users\fan Guest (S-1-5-21-72047652-2448835880-2394339217-501 - Limited - Enabled) => C:\Users\Guest HomeGroupUser$ (S-1-5-21-72047652-2448835880-2394339217-1002 - Limited - Enabled) WDAGUtilityAccount (S-1-5-21-72047652-2448835880-2394339217-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov) Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.126 - Adobe Systems Incorporated) AIR Xpand!2 (HKLM\...\{69A89482-FEC4-4E34-97F9-46BB287D0953}) (Version: 12.0.0.615 - AIR Music Technology) AMD Catalyst Install Manager (HKLM\...\{F564317A-AB84-BEE8-A670-B6C09BC08AFB}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.13 - Michael Tippach) Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) Avid Audio Drivers (x64) (HKLM\...\{2F227ACA-204C-4529-BA33-D095C42C72DB}) (Version: 8.0.4 - Avid Technology) Avid Pro Tools SE 8.0.3 (HKLM-x32\...\{371F27A1-9502-4762-AE97-1C1938B21055}) (Version: 8.0.3 - Digidesign, une division d'Avid Technology, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.30 - Piriform) CDex - Digital Audio CD Extractor and Converter (HKLM-x32\...\CDex) (Version: 1.81.0.2016 - Georgy Berdyshev) Contenu supplémentaire de Vita 2 (HKLM\...\{EF321080-727C-476F-96BE-809005BBAF5F}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden CPUID CPU-Z 1.81 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.81 - ) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.5.1.0232 - Disc Soft Ltd) Digidesign ElevenRack Driver 1.0.8 (x64) (HKLM\...\{DFE96CF0-A611-40C4-AE24-2E4C21E3FF3E}) (Version: 1.0.8 - Digidesign) eJay Dance 7 Demo (HKLM-x32\...\{20EEA8A7-7DDF-489F-A2CA-ACE63295EF4E}) (Version: 1.89 - Empire Interactive) Hidden eJay Dance 7 Demo (HKLM-x32\...\InstallShield_{20EEA8A7-7DDF-489F-A2CA-ACE63295EF4E}) (Version: 1.89 - Empire Interactive) Elastik v2.6.3 (HKLM\...\{F1B1B18B-A084-42A5-8C7F-2E2F9DC55963}_is1) (Version: - ) Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG) Free DigiRack Plug-Ins 8.0.3 (HKLM-x32\...\{A24C2C43-4312-493E-96B3-5D1DCE24DEBF}) (Version: 8.0.3 - Digidesign, A Division of Avid Technology, Inc.) HiSuite (HKLM-x32\...\Hi Suite) (Version: 1.0 - Huawei Technologies Co.,Ltd) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1035 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.8.1.1007 - Intel Corporation) Interlok driver setup x64 (HKLM\...\{25613C10-27D2-410B-942B-D922D5C3A7BE}) (Version: 5.8.13 - PACE Anti-Piracy) License Support (HKLM\...\{3165EA9B-36CC-499B-96FF-36FC30E10EF4}) (Version: 1.3.0.8766 - PACE Anti-Piracy, Inc.) Hidden License Support (HKLM-x32\...\InstallShield_{3165EA9B-36CC-499B-96FF-36FC30E10EF4}) (Version: 1.3.0.8766 - PACE Anti-Piracy, Inc.) MAGIX Common Components 1 (HKLM-x32\...\{7A8B2204-574B-42A2-A3DC-52AE142D197F}) (Version: 1.2.0.0 - MAGIX AG) MAGIX Contenu et Soundpools (HKLM-x32\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX Fonts Package 1 (HKLM-x32\...\{3859AC53-3C30-4885-AA6B-5DAC442AC871}) (Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Music Maker 2014 Premium (HKLM-x32\...\MAGIX Music Maker 2014 Premium_is1) (Version: - ) MAGIX Music Maker Trial Live Pads (HKLM\...\{B3415446-09BC-4B5C-B535-92126E7115CB}) (Version: 24.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Music Maker Trial Soundpools (HKLM\...\{ADD97B18-F22D-44FE-92E8-F07B67759445}) (Version: 24.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Screenshare (HKLM-x32\...\{DFDD2913-557D-4EB5-8745-47749E521760}) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Soundpool Music Maker - Feel good (HKLM\...\{2407E836-55C8-4F9E-900F-0A8F859CB930}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden MAGIX Speed burnR (HKLM\...\{026B6EBC-0F55-425F-9112-9304BCC3B8ED}) (Version: 7.0.1.27 - MAGIX Software GmbH) Hidden MAGIX Speed burnR (HKLM-x32\...\MX.{026B6EBC-0F55-425F-9112-9304BCC3B8ED}) (Version: 7.0.1.27 - MAGIX Software GmbH) Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes) M-Audio Fast Track 6.1.12 (x64) (HKLM\...\{102B819F-54FB-4CD3-8B48-B80C210D55BC}) (Version: 6.1.12 - M-Audio) Microsoft OneDrive (HKU\S-1-5-21-72047652-2448835880-2394339217-1001\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation) Microsoft Text-to-Speech Engine 4.0 (English) (HKLM-x32\...\MSTTS) (Version: - ) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{f9b04b37-35d5-4a19-a51b-fcf4a8734851}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.1 (HKLM\...\{A20F7882-20B6-49CD-812C-ECB4F61981CF}) (Version: 1.10.123.0 - Microsoft) Mises à jour NVIDIA 29.1.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 29.1.0.0 - NVIDIA Corporation) Hidden Mozilla Firefox 24.0 (x86 fr) (HKLM-x32\...\Mozilla Firefox 24.0 (x86 fr)) (Version: 24.0 - Mozilla) Mozilla Firefox 57.0.2 (x64 fr) (HKLM\...\Mozilla Firefox 57.0.2 (x64 fr)) (Version: 57.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 57.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.0 - Mozilla) MSI to redistribute MS VS2005 CRT libraries (HKLM-x32\...\{A8D93648-9F7F-407D-915C-62044644C3DA}) (Version: 8.0.50727.42 - The Firebird Project) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) Music Maker (HKLM\...\{D5FF45D3-3AE3-4490-85DE-04D059606382}) (Version: 25.0.2.44 - MAGIX Software GmbH) Hidden Music Maker (HKLM-x32\...\MX.{D5FF45D3-3AE3-4490-85DE-04D059606382}) (Version: 25.0.2.44 - MAGIX Software GmbH) Native Instruments Kontakt 5 (HKLM-x32\...\Native Instruments Kontakt 5) (Version: 5.2.1.6382 - Native Instruments) Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - Native Instruments) Natural Color Pro (HKLM-x32\...\{6FE2F5A6-8DC6-41B9-84AE-9FB32BCF7C02}) (Version: 1.0.0.6 - SEC) Hidden Natural Color Pro (HKLM-x32\...\{FC2C7405-BC58-4E11-8F51-29671BEAC06B}) (Version: 1.0.0.6 - SEC) NVIDIA 3D Vision Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 388.13 - NVIDIA Corporation) NVIDIA GeForce Experience 3.10.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.10.0.95 - NVIDIA Corporation) NVIDIA Graphics Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.13 - NVIDIA Corporation) NVIDIA Logiciel système PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) NVIDIA Pilote du contrôleur 3D Vision 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 10.5.8.11002 - Electronic Arts, Inc.) PACE License Support Win64 (HKLM\...\{233E2172-6B0E-4444-8BBA-C0D2BB9D7C37}) (Version: 3.1.7.1901 - PACE Anti-Piracy, Inc.) Hidden PACE License Support Win64 (HKLM-x32\...\InstallShield_{233E2172-6B0E-4444-8BBA-C0D2BB9D7C37}) (Version: 3.1.7.1901 - PACE Anti-Piracy, Inc.) QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.370.162 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.21.811.2017 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8036 - Realtek Semiconductor Corp.) Remotr version 1.3.1438 (HKLM-x32\...\Remotr_is1) (Version: 1.3.1438 - RemoteMyApp sp. z o.o.) Revo Uninstaller 2.0.1 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.1 - VS Revo Group, Ltd.) Second Sight (HKLM-x32\...\Second Sight_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Styx Shards of Darkness (HKLM-x32\...\Styx Shards of Darkness_is1) (Version: - ) Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH) VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden Visual C++ 64-bit Redistributables (HKLM-x32\...\InstallShield_{FB03650C-B373-4B20-ACA5-B7BA1A8EEE33}) (Version: 1.3.0.8766 - PACE Anti-Piracy, Inc.) Visual C++ Redistributables (HKLM-x32\...\InstallShield_{F03117FA-9270-46B0-9666-0B4BC2CDEBF5}) (Version: 1.3.0.8766 - PACE Anti-Piracy, Inc.) Vita 2 (HKLM\...\{3903996D-A68F-4426-92B1-E2D64EBC75DE}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden Vita Concert Grand LE (HKLM\...\{172623AB-BC59-4D94-A1D9-E51F126FC3E3}) (Version: 2.4.0.95 - MAGIX Software GmbH) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation) WinUtilities Professional Edition 14.5 (HKLM-x32\...\{FC274982-5AAD-4C20-848D-4424A5043009}_is1) (Version: 14.5 - YL Computing, Inc) Wondershare Helper Compact 2.5.2 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare) YouTube By Click (HKLM-x32\...\{77099314-912F-47E8-AF74-6D63C83B6956}) (Version: 2.2.71 - ByClick) Hidden YouTube By Click (HKLM-x32\...\YouTube By Click 2.2.71) (Version: 2.2.71 - ByClick) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers: [TortoiseOverlay] -> {CBF88FC2-F150-4F29-BC80-CE30EFD1B62C} => C:\Users\fan\AppData\Roaming\Subversion\TortoiseSVN.dll [2017-12-18] () ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-27] (NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {15AF15E3-1FE2-4D55-838A-C8748FD4850A} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-10-11] (NVIDIA Corporation) Task: {2DA59E78-E92A-4438-8424-713ADEF34168} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation) Task: {3800A859-1B54-476E-83A6-401CBF9CE5E7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {3F84BC22-CCF9-43E5-9DCB-D57293E5A9D3} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11] (NVIDIA Corporation) Task: {45EE5371-0D52-4A40-91F5-1D21BE3AF6E1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-05-19] (Piriform Ltd) Task: {4D0250A3-436A-4F7F-8849-3662226E63C8} - \MicrosoftServic -> No File <==== ATTENTION Task: {531791BA-C1AD-4967-87F3-7D7A0DF76806} - System32\Tasks\JPEGpremeMaker => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\JPEGpremeMaker\JPEGpremeMaker.dll",RmVOAN <==== ATTENTION Task: {59F33A3D-5D33-4828-AB23-D56503024646} - System32\Tasks\Update\RevoUninstaller => cmd /c type "C:\Users\fan\AppData\Local\Temp\RevoUninstaller.txt" | cmd <==== ATTENTION Task: {5E2F9B8A-5B19-446C-B9D1-746373D6AD03} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation) Task: {66731103-0B32-44A6-B175-DB60CC8532E3} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation) Task: {682A3104-2F73-4A32-8E28-0E0B3E21A89F} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-10-11] (NVIDIA Corporation) Task: {8D6DF486-B2EF-4463-AC42-00DE219B82F7} - System32\Tasks\Simple MPEG4 Digital Connector => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Simple MPEG4 Digital Connector\Simple MPEG4 Digital Connector.dll",KIFSWEy <==== ATTENTION Task: {9E83E2EA-205C-4D2D-A187-A6017A0C98D1} - System32\Tasks\memory\memory => C:\Users\fan\AppData\Roaming\memory\recover.exe Task: {AEF5A9D0-6867-43F3-8873-CE21202ECF7B} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2017-02-24] (Intel(R) Corporation) Task: {B3B6A17A-6451-4DF1-820B-79BDBAD07D1F} - System32\Tasks\Microsoft\Windows\srman\run => C:\Users\fan\AppData\Roaming\xszman\platforms.exe [2017-12-18] () Task: {BD6673E7-65C2-4474-8301-2C95C55AFF84} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation) Task: {EA2B5ABB-E3F7-4FA2-946D-3BF838B088DE} - System32\Tasks\Microsoft Windows Mail => C:\Users\fan\AppData\Roaming\Origin\Windows Mail\wabmig.exe Task: {ED4DB8B4-DD7D-4679-9D00-9C8341934869} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-10-11] (NVIDIA Corporation) Task: {F6E8EA44-79EC-41D0-AF43-E9959CBC6AC5} - System32\Tasks\S-1-5-21-72047652-2448835880-2394339217-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2017-09-29] (Microsoft Corporation) Task: {FB190ABD-5987-4383-882E-E375AA1332BB} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-12-15] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DQXMIZcMVgHaIkOHb.job => C:\Program Files (x86)\LrPZBDjUwpLSlrNHbUR\JYkHJeF.dll Task: C:\WINDOWS\Tasks\lJBQppWImNhefKN.job => C:\Program Files (x86)\lBrXsaBrU\QPksQI.dll ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-07-26 08:58 - 2017-07-26 08:58 - 000192200 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe 2017-06-12 20:51 - 2017-10-11 02:05 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-12-18 20:12 - 2017-12-18 20:12 - 000148992 _____ () C:\Users\fan\AppData\Roaming\Subversion\TortoiseSVN.dll 2017-12-14 12:17 - 2017-11-26 13:23 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-12-14 12:16 - 2017-11-26 13:01 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-12-18 20:02 - 2017-12-18 20:02 - 004555776 _____ () C:\Users\fan\AppData\Roaming\xszman\platforms.exe 2017-06-12 20:51 - 2017-10-11 02:05 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-08-28 18:22 - 2017-02-27 19:52 - 000076408 _____ () C:\Program Files (x86)\Remotr\General.dll 2017-08-28 18:22 - 2017-02-27 19:52 - 000057976 _____ () C:\Program Files (x86)\Remotr\Audio.dll 2017-06-26 12:24 - 2017-06-26 12:24 - 001244304 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Microsoft:2DA0GW0uuk0nwCbdVb8 [2690] AlternateDataStreams: C:\ProgramData\Microsoft:4tDLbX3vx4Yydvm1wigOEsxn [2228] AlternateDataStreams: C:\ProgramData\Microsoft:7wki8RQ6z4R0Ea48FKoar3A [2312] AlternateDataStreams: C:\ProgramData\Microsoft:82Qmtp5r44i4d65CgmVSo7w6ClX [2550] AlternateDataStreams: C:\ProgramData\Microsoft:iMAIfgzkeNuSpm7NOrGksN [2300] AlternateDataStreams: C:\ProgramData\Microsoft:JFYsZQk9QJRdCda2FIOe [2332] AlternateDataStreams: C:\ProgramData\Microsoft:r9wuKSYzmzTbFHXd8YjlKPkW [2102] AlternateDataStreams: C:\ProgramData\Microsoft:uSFlYIZzfgxgTGyZP [2174] AlternateDataStreams: C:\Users\fan\Cookies:459ZuxewdcggNWyeia [2246] AlternateDataStreams: C:\Users\fan\Local Settings.[unlocksupp@airmail.cc or BM-2cTVHx6b7RYhJ9gGKZn6yTuBpBBq3LHRkz@bitmessage.ch]-id-22CC.wallet:e5rpWejR5TvNSiDzxEYdjsbMyK [2404] AlternateDataStreams: C:\Users\fan\Local Settings.[unlocksupp@airmail.cc or BM-2cTVHx6b7RYhJ9gGKZn6yTuBpBBq3LHRkz@bitmessage.ch]-id-22CC.wallet:WDdaIbXiT15cPdeSw3Vc7LP6 [2744] AlternateDataStreams: C:\Users\fan\AppData\Local:e5rpWejR5TvNSiDzxEYdjsbMyK [2404] AlternateDataStreams: C:\Users\fan\AppData\Local:WDdaIbXiT15cPdeSw3Vc7LP6 [2744] AlternateDataStreams: C:\Users\fan\AppData\Local\Application Data:e5rpWejR5TvNSiDzxEYdjsbMyK [2404] AlternateDataStreams: C:\Users\fan\AppData\Local\Application Data:WDdaIbXiT15cPdeSw3Vc7LP6 [2744] AlternateDataStreams: C:\Users\fan\AppData\Local\Temporary Internet Files:69ooqq4YFyCd2I6oDNSZUJUYt [2306] AlternateDataStreams: C:\Users\fan\AppData\Local\Y44x5Gry18:MYlYgvinoJBiAdJw4plx3w [2170] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) HKU\S-1-5-21-72047652-2448835880-2394339217-1001\Software\Classes\regfile: regedit.exe "%1" <==== ATTENTION ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2017-06-03 00:31 - 2017-07-16 21:48 - 000001146 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 cpm.paneladmin.pro 127.0.0.1 publisher.hmdiadmingate.xyz 127.0.0.1 distribution.hmdiadmingate.xyz 127.0.0.1 hmdicrewtracksystem.xyz 127.0.0.1 linkmate.space 127.0.0.1 space1.adminpressure.space 127.0.0.1 trackpressure.website 127.0.0.1 doctorlink.space 127.0.0.1 plugpackdownload.net 127.0.0.1 dscdn.pw 127.0.0.1 beautifllink.xyz ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-72047652-2448835880-2394339217-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 35.177.46.238 - 46.101.28.31 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{AD9352DA-A559-40A1-A627-BDB2BF5D8A07}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{EBC3BA81-A4DC-45F7-91AC-4879AFCA75D8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{192D940A-670C-44B6-94FC-CD806A9CAD52}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{102C4D39-C0A2-4B34-AE84-1AF1DA990927}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{4DACD7E5-E8FE-494F-B00F-A7BDA0E9FCCB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{58314A1B-DC68-4BF0-80F5-E2205E9E5087}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Steam360VideoPlayer\Steam360VideoPlayer.exe FirewallRules: [{22854ABC-1520-4B02-BB24-DF327C4545AD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Steam360VideoPlayer\Steam360VideoPlayer.exe FirewallRules: [{5137FE5D-FA8D-430C-BAFC-1B2D1E7412C5}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [{D6BA4FA8-EEEF-45B4-A687-3C2F886C8DF3}] => (Allow) C:\Program Files (x86)\MAGIX\Music Maker\25\MusicMaker.exe FirewallRules: [{97F16E63-902B-4EF4-89C0-83BCBB163583}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{882CA0A1-7F35-43FE-A94A-059BE27EB237}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{4F26AD58-7332-4DA2-B6A9-32E378152C14}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{3CACC474-C021-44FD-9765-DCB4F0B6707F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{3FDBC6F9-299A-4927-9962-128D604CD191}] => (Allow) C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe FirewallRules: [{76E4D2F6-BB4F-44FA-A9DB-010C5A7D98E3}] => (Allow) C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe FirewallRules: [{41FFB3F4-747C-4000-9864-BF317C8A4FA1}] => (Allow) LPort=1900 FirewallRules: [{04633A1B-6528-482D-8C62-5A3BBCD8A1F9}] => (Allow) LPort=2869 FirewallRules: [{096B8721-569A-4730-829F-9054170D7BEB}] => (Allow) LPort=0 FirewallRules: [{955B1186-5F32-4CB3-B47D-718FB712E998}] => (Allow) C:\Program Files (x86)\Remotr\RemotrServer.exe FirewallRules: [{A5C4126F-372F-4391-BF10-BDF8678DE6DC}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{1A0B5468-A2D6-42B6-A756-2E28A05978F4}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{EB6DA6B2-5C0D-4DAE-9005-A138D4E5775D}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [UDP Query User{0DC277E2-AC09-41A0-8368-7DDF58861DAE}D:\program files (x86)\dz.repack-fifa14\fifa14\game\fifa14.exe] => (Allow) D:\program files (x86)\dz.repack-fifa14\fifa14\game\fifa14.exe FirewallRules: [TCP Query User{67208F80-3EA7-4E5A-8BAF-7FB6FB4E29C1}D:\program files (x86)\dz.repack-fifa14\fifa14\game\fifa14.exe] => (Allow) D:\program files (x86)\dz.repack-fifa14\fifa14\game\fifa14.exe FirewallRules: [{6E7FC23C-F8B4-4FDF-A3B9-0F85A909AF95}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{41495BA9-7F98-42F5-94A5-7BCBA3E7538E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{EF4773E2-87BA-45E1-B6F9-BCDF1A5CA548}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{DF36F91F-A7DD-4CE0-895D-E67D06181D49}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{61F06273-8873-447C-9100-8C016DB1C50C}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{D5CD3963-6F1E-4A0C-BD7A-532AFB7F0D1B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3BD7CCD0-4C5A-432D-A7F8-7E64B45C6409}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{8D18AF2B-3B3E-4C9C-8FC1-641D2E72202E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{F02319D6-E368-4183-BC22-CBE1650B14F6}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{F52BFAFE-63BE-4C19-B035-4FF6CECC4F93}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe FirewallRules: [{3D9F6A4D-421A-474A-AF61-97A83ADBE4B0}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe FirewallRules: [{23CB87AC-205D-4B8C-A5CD-1E565C665702}] => (Allow) C:\Users\fan\AppData\Local\yc\Application\yc.exe FirewallRules: [TCP Query User{F0FC4FB0-5BC6-408F-96D3-CCB0AD7DE241}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{7D8E38E3-4F61-46F4-AB01-C136F316B56C}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe ==================== Restore Points ========================= 20-12-2017 15:08:49 Restauration système ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/20/2017 01:07:12 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007007B Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (12/20/2017 01:07:03 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007139F Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable Error: (12/20/2017 12:45:28 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007007B Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable Error: (12/20/2017 12:45:28 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007007B Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (12/20/2017 11:58:05 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007007B Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (12/20/2017 11:57:58 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007139F Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable Error: (12/20/2017 11:30:10 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007007B Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error: (12/20/2017 11:30:08 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007007B Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable Error: (12/20/2017 11:16:55 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante mbamservice.exe, version : 3.1.0.595, horodatage : 0x59f745cb Nom du module défaillant : mbamservice.exe, version : 3.1.0.595, horodatage : 0x59f745cb Code d’exception : 0xc0000005 Décalage d’erreur : 0x00000000001c6e66 ID du processus défaillant : 0x1bac Heure de début de l’application défaillante : 0x01d3797ba8602983 Chemin d’accès de l’application défaillante : C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe Chemin d’accès du module défaillant: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe ID de rapport : 820d9156-8bb7-4765-88c5-faa3d7404363 Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (12/20/2017 11:16:05 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x8007007B Arguments de la ligne de commande : RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable System errors: ============= Error: (12/20/2017 03:23:31 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (12/20/2017 03:23:28 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (12/20/2017 12:44:38 PM) (Source: volmgr) (EventID: 46) (User: ) Description: L'initialisation du fichier de vidage sur incident a échoué. Error: (12/20/2017 12:45:03 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: L’arrêt système précédant à 12:41:32 PM le ‎12/‎20/‎2017 n’était pas prévu. Error: (12/20/2017 12:42:45 PM) (Source: DCOM) (EventID: 10005) (User: FAN7-PC) Description: DCOM a reçu l’erreur « 1084 » lors de la tentative de démarrage du service wuauserv avec les arguments « Unavailable » pour exécuter le serveur : {E60687F7-01A1-40AA-86AC-DB1CBF673334} Error: (12/20/2017 12:41:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Le service iphlpsvc dépend du service WinHttpAutoProxySvc qui n’a pas pu démarrer en raison de l’erreur : Le service ou le groupe de dépendance n’a pas pu démarrer. Error: (12/20/2017 12:41:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Le service simptcp dépend du service AFD qui n’a pas pu démarrer en raison de l’erreur : Un périphérique attaché au système ne fonctionne pas correctement. Error: (12/20/2017 12:41:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Le service NlaSvc dépend du service Dhcp qui n’a pas pu démarrer en raison de l’erreur : Le service ou le groupe de dépendance n’a pas pu démarrer. Error: (12/20/2017 12:41:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Le service WinHttpAutoProxySvc dépend du service Dhcp qui n’a pas pu démarrer en raison de l’erreur : Le service ou le groupe de dépendance n’a pas pu démarrer. Error: (12/20/2017 12:41:32 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: Le service mrxsmb20 dépend du service mrxsmb qui n’a pas pu démarrer en raison de l’erreur : Le service ou le groupe de dépendance n’a pas pu démarrer. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU G4400 @ 3.30GHz Percentage of memory in use: 43% Total physical RAM: 8119.29 MB Available physical RAM: 4593.99 MB Total Virtual: 9399.29 MB Available Virtual: 5005.09 MB ==================== Drives ================================ Drive c: (1) (Fixed) (Total:116.5 GB) (Free:41.95 GB) NTFS Drive d: (2) (Fixed) (Total:931.32 GB) (Free:226.87 GB) NTFS Drive e: (3) (Fixed) (Total:115.84 GB) (Free:8.92 GB) NTFS Drive f: (LWS_2_2) (CDROM) (Total:0.13 GB) (Free:0 GB) CDFS Drive g: (NIKONTAKT530U) (CDROM) (Total:0.31 GB) (Free:0 GB) CDFS Drive k: (MULTIBOOT) (Removable) (Total:15.08 GB) (Free:15.08 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 0C6EB9BA) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=116.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) Partition 4: (Not Active) - (Size=115.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: 13BDA6EC) Partition: GPT. Partition 2: (Not Active) - (Size=931.3 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 15.1 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=15.1 GB) - (Type=0C) ==================== End of Addition.txt ============================