Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 17.01.2018 01 Exécuté par Quentin (17-01-2018 21:39:37) Exécuté depuis C:\Users\Quentin\Desktop Windows 10 Home Version 1709 16299.125 (X64) (2017-12-01 07:01:23) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= Administrateur (S-1-5-21-70007279-1525863979-1083813302-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-70007279-1525863979-1083813302-503 - Limited - Disabled) Invité (S-1-5-21-70007279-1525863979-1083813302-501 - Limited - Disabled) Quentin (S-1-5-21-70007279-1525863979-1083813302-1001 - Administrator - Enabled) => C:\Users\Quentin WDAGUtilityAccount (S-1-5-21-70007279-1525863979-1083813302-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) µTorrent (HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\uTorrent) (Version: 3.4.9.42973 - BitTorrent Inc.) 7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov) 7-Zip 16.02 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1602-000001000000}) (Version: 16.02.00.0 - Igor Pavlov) Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated) Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.7.1 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe Digital Editions 4.5 (HKLM-x32\...\Adobe Digital Editions 4.5) (Version: 4.5.1 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated) Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Premiere Pro CS6 (HKLM-x32\...\{7176B973-6011-43C1-AEBC-2D73FE7C6982}) (Version: 6.0 - Adobe Systems Incorporated) ASUS GIFTBOX Desktop (HKLM-x32\...\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B}) (Version: 1.1.5 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.4.1 - ASUS) ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.12 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.13.0004 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.1.6 - ASUS) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0040 - ASUS) AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.0.99 - ICEpower a/s) Bandicam (HKLM-x32\...\Bandicam) (Version: 1.8.9.371 - Bandisoft.com) Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandisoft.com) BikaQ Rss (HKLM-x32\...\{3678D164-84DB-4F73-AFD6-916342E10764}) (Version: - ) <==== ATTENTION CodeBlocks (HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.16.55 - Conexant) CyberLink PhotoDirector 5 (HKLM\...\{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.5.6515 - CyberLink Corp.) Hidden CyberLink PhotoDirector 5 (HKLM-x32\...\InstallShield_{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.5.6515 - CyberLink Corp.) CyberLink PowerDirector 12 (HKLM\...\{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.4010.0 - CyberLink Corp.) Hidden CyberLink PowerDirector 12 (HKLM-x32\...\InstallShield_{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.4010.0 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Device Setup (HKLM-x32\...\{8D6B05E0-F457-408C-9D13-549334D8FAE1}) (Version: 2.0.2 - ASUSTek Computer Inc.) Epic Games Launcher (HKLM-x32\...\{904D135E-2B44-4B46-A4B4-78A5FCE8F27C}) (Version: 1.1.129.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.4.0 - Seiko Epson Corporation) Epson Event Manager (HKLM-x32\...\{9F205E94-9E42-4486-A92A-DF3F6CB85444}) (Version: 3.10.0061 - Seiko Epson Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{B55DB65D-EF6E-4E04-89D5-B03603BF681B}) (Version: 4.4.5 - SEIKO EPSON CORPORATION) EPSON XP-225 Series Printer Uninstall (HKLM\...\EPSON XP-225 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM\...\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation) Facebook Gameroom 1.10.6515.35995 (HKLM-x32\...\{0B5F75BB-9192-4E2C-A0A6-D07DC31A2E84}) (Version: 1.10.6515.35995 - Facebook) Galerie de photos (HKLM-x32\...\{439B34FF-F74E-4807-B5E2-4B758551DA6B}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{a2d9fda8-65eb-4c06-81ef-31e0a4daa335}) (Version: 10.1.1.11 - Intel(R) Corporation) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.1.10603.192 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1167 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4550 - Intel Corporation) Intel(R) WiDi (HKLM\...\{C7CD6D54-26AF-4D93-B06F-D81ACE8624CB}) (Version: 6.0.40.0 - Intel Corporation) Intel(R) WiDi Software Asset Manager (HKLM-x32\...\{C7D64C31-3F1E-4205-87A5-B61AAE55E64B}) (Version: 3.4.1942 - Intel Corporation) Hidden Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{64FD4757-7186-4F12-9AA8-5EE809CAB282}) (Version: 17.1.1532.1814 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden League of Legends (HKLM-x32\...\{11B73856-A062-4E6B-A80E-A3F380BBAB65}) (Version: 4.2.1 - Riot Games) Hidden League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games) Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 14.0.0.0 - EditShare) Logiciel Intel® PROSet/Wireless (HKLM-x32\...\{5853172b-5520-4089-9ef4-e26c594382b3}) (Version: 19.30.0 - Intel Corporation) Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Microsoft Filter Pack 2.0 (HKLM\...\{95140000-2000-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office 365 ProPlus - fr-fr (HKLM\...\O365ProPlusRetail - fr-fr) (Version: 16.0.8201.2213 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{21764A96-6748-4B83-89E7-7A5063BF156C}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden MyEpson Portal (HKLM-x32\...\{3361D415-BA35-4143-B301-661991BA6219}) (Version: 1.1.2.2 - SEIKO EPSON CORPORATION) Hidden MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8201.2213 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8201.2213 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8201.2213 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-040C-0000-0000000FF1CE}) (Version: 16.0.8201.2075 - Microsoft Corporation) Hidden Package de pilotes Windows - ASUS (ATP) Mouse (11/11/2015 6.0.0.66) (HKLM\...\82D024CBD181D16D72E5AE45A426919815D5F456) (Version: 11/11/2015 6.0.0.66 - ASUS) PhotoFiltre Studio X (HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\PhotoFiltre Studio X) (Version: - ) Project CARS Update v1.2 (HKLM-x32\...\UHJvamVjdENBUlM=_is1) (Version: 1 - ) Service Xperia Companion (HKLM\...\{86C9336F-6376-4E86-A09A-EA7177DEC3D5}) (Version: 1.7.2.0 - Sony) Hidden Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.104 - Skype Technologies S.A.) SpyHunter 4 (HKLM-x32\...\SpyHunter) (Version: 4.28.5.4848 - Enigma Software Group, LLC) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.78313 - TeamViewer) Trials Fusion - Awesome Level Max Edition (HKLM-x32\...\Trials Fusion - Awesome Level Max Edition_is1) (Version: - ) Trials Fusion (HKLM-x32\...\Trials Fusion_is1) (Version: - ) VLC media player (HKLM\...\VLC media player) (Version: 3.0.0-git - VideoLAN) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.3 - VideoLAN) Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows Phone app for desktop (HKLM-x32\...\{639E54EE-95CA-4CAE-9779-6BA32D5EAF48}) (Version: 1.1.2726.0 - Microsoft Corporation) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.0.1 - ASUS) Wondershare Helper Compact 2.5.3 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.3 - Wondershare) Wondershare Streaming Audio Recorder(Build 2.3.5) (HKLM-x32\...\Wondershare Streaming Audio Recorder_is1) (Version: 2.3.5.0 - Wondershare Software) Xperia Companion (HKLM-x32\...\{058506CE-4E1C-4087-878E-61D8B5F8F47A}) (Version: 1.7.2.0 - Sony) Hidden Xperia Companion (HKLM-x32\...\{65415473-2761-4ee3-85c1-5fdf086444c6}) (Version: 1.7.2.0 - Sony) ==================== Personnalisé CLSID (Avec liste blanche): ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) CustomCLSID: HKU\S-1-5-21-70007279-1525863979-1083813302-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Quentin\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-70007279-1525863979-1083813302-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Quentin\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-70007279-1525863979-1083813302-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Quentin\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems Inc.) ContextMenuHandlers1: [iSkysoftVideoConverterFileOpreation] -> {BB35DE05-89D6-4D8F-95DE-A27DF8156D91} => C:\WINDOWS\SysWoW64\ISCM64.dll -> Pas de fichier ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-01-20] (Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_463164d40c3d26ce\igfxDTCM.dll [2016-11-30] (Intel Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems Inc.) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-01-20] (Malwarebytes) ==================== Tâches planifiées (Avec liste blanche) ============= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {0269B8C5-F052-4D87-B86E-0D41F9440911} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-12-23] (Microsoft Corporation) Task: {058FF75E-514A-4297-9EB4-EBEE2E777D7F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-18] (Google Inc.) Task: {07E1F4F0-1CCB-4420-938B-E21DBBAF9A37} - System32\Tasks\microsoft-windowsphone_10-1609-2561 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {07F4D67C-169F-42DD-B932-E40B346A51B4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-18] (Google Inc.) Task: {17321981-E67F-4A1F-B737-644B3E324DC3} - System32\Tasks\microsoft-zunevideo_10-17012 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {1FA4A0F4-495F-454D-B513-4EBC3BBADBD7} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2015-08-25] (ASUS) Task: {1FB52688-E746-4226-BEAD-3A0531CE50B5} - System32\Tasks\microsoft-windows-photos_17 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {2252F872-0177-4815-A690-4E9B20592AC6} - System32\Tasks\microsoft-windowscommunicationsapps_17-7922-42017 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {239CE801-A036-4267-AD8E-CC8C9335CDC7} - System32\Tasks\microsoft-windowscommunicationsapps_17-8004-42017-0_x64__8wekyb3d8bbwe\hxtsr => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {2539FF76-3818-4FEB-B1C9-A2402CDB6A0A} - System32\Tasks\microsoft-windows-photos_17-214-10010-0_x64__8wekyb3d8bbwe\microsoft => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {2867D277-0DBA-477D-B5FE-A7363327CA8E} - System32\Tasks\launcher\avira-servicehost => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {291B9053-861D-43C4-9368-6E4992C02755} - System32\Tasks\microsoft-windowscalculator_10-1702-312-0_x64__8wekyb3d8bbwe\calculator => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {2B87FDF9-B9DF-4CD4-9DF1-50FBE78A69CE} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-05-14] (ASUSTek Computer Inc.) Task: {3B7C1A72-0157-4753-A1CA-54FC0EF37751} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2016-08-12] (Intel Corporation) Task: {3D1266BD-D675-4F66-A698-B67F5FD6869E} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-10] (ASUSTek Computer Inc.) Task: {3D7ED425-EA66-48CA-BC53-B557EB667D23} - System32\Tasks\myepson portal\64driverload => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {406303B5-7EB2-402E-A6C7-C31848E56DFB} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2015-06-05] (Intel Corporation) Task: {41107C1A-670F-4FF8-95C5-ACFFF29B93BC} - System32\Tasks\microsoft-microsoftstickynotes_1-6-2-0_x64__8wekyb3d8bbwe\microsoft-stickynotes => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {42D50164-CF04-475A-8DE9-4C984EB4ADCB} - System32\Tasks\microsoft-windows-photos_17-214-10010 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {454AF3B9-FFC4-4A9F-90F5-15A91A0D6887} - System32\Tasks\microsoft-windowscommunicationsapps_17 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {4886FAA8-2328-49D2-B5CC-9C30601CE5E6} - System32\Tasks\microsoft-windowscalculator_10-1702-312 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {48D8DCFC-FB01-434A-84E6-2163772544C5} - System32\Tasks\microsoft-windowscalculator_10-1702-312-0_x64__8wekyb3d8bbwe\calculator-exe => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {4AA60784-3192-4FAB-BF11-F4FAE3F42FA1} - System32\Tasks\microsoft-zunemusic_10-17012-10311-0_x64__8wekyb3d8bbwe\music-ui => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {4E761B94-AAA8-4282-B944-EEA8A2676BE7} - System32\Tasks\{98371490-F5D9-43FD-96A2-638B8E4C2492} => C:\WINDOWS\system32\pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\" Task: {4EEC0EDB-4EE9-45BB-B0E7-CA18E09E7443} - System32\Tasks\antivirus\avshadow => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {5333DEEB-5FDC-4E16-84BF-94DA59451DE2} - System32\Tasks\{16289562-657D-45D3-A82F-57D8C2D053C6} => C:\WINDOWS\system32\pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\" Task: {53C5E306-46E7-407D-8823-D31A2F38E3FC} - System32\Tasks\microsoft-skypeapp_11-11-110 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {5BEB9A68-C3B2-4638-93BC-3FC29E0B7EC1} - System32\Tasks\microsoft-skypeapp_11-11 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {5D8FFF88-6779-4637-B308-34B062139846} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-12-02] (Microsoft Corporation) Task: {5E3C36D9-580B-4763-B8B2-602C8F21584E} - System32\Tasks\microsoft-windowscalculator_10 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {5E4994B8-C619-48B4-9AC4-2AE69D923108} - System32\Tasks\microsoft-skypeapp_11 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {61DDB5EA-C07F-4D06-992A-4C05AE3EE207} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe Task: {62ADFE85-CCDA-442D-A69A-F0F56BE81E98} - System32\Tasks\microsoft-zunemusic_10-17012-10301-0_x64__8wekyb3d8bbwe\music-ui-exe => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {62D6D5EF-7209-4A3C-B1DC-8A004DD1BC5B} - System32\Tasks\acrobat dc\acrobat\acrotray-exe => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {63C5E778-CD13-4D65-A6E4-AC7D7B55E524} - System32\Tasks\antivirus\avscan => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {67889EEC-D7B4-43D3-B82C-D0DBA3522591} - System32\Tasks\Microsoft\Windows\WCM\WiFiTask Task: {68FAE2E6-F993-46D4-BC4B-7E865830D5D1} - System32\Tasks\myepson portal\64driverload-exe => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {72E58729-6EEA-4F4F-9B46-EFDE6917C515} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2016-08-12] (Intel Corporation) Task: {75B0A7EC-F7F7-4540-8294-73C85DA8D1B3} - System32\Tasks\microsoft-windowscommunicationsapps_17-8004-42017 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {762A79E2-0001-45C7-ADA1-C57F4E5146DF} - System32\Tasks\microsoft-zunemusic_10-17012-10301 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {7AC58FEB-7FA7-40CC-ACB8-E30EE288959D} - System32\Tasks\microsoft-windowscommunicationsapps_17-7920-40507-0_x64__8wekyb3d8bbwe\hxtsr => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {7BDCE740-B3D2-4537-B867-E323AB72ED93} - System32\Tasks\microsoft-zunevideo_10-17012-10301 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {8642EBFE-A373-482E-9C2B-617C661A346E} - System32\Tasks\microsoft-windows-photos_16-1118-10000-0_x64__8wekyb3d8bbwe\microsoft-photos => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {88B6F5B4-2C12-4B93-821A-EC59CB1A4C48} - System32\Tasks\microsoft-windows-photos_16-1118 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {8AA639AC-9D82-4518-83C2-8584400EA123} - System32\Tasks\microsoft-windowscommunicationsapps_17-7912 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {90572FB7-B9B7-4E20-8FA5-8A2ADA52C9EC} - System32\Tasks\microsoft-windowscommunicationsapps_17-7912-40507-0_x64__8wekyb3d8bbwe\hxtsr => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {92794134-5D94-496E-9823-0CD7365C9216} - System32\Tasks\microsoft-windowsphone_10-1609-2561-0_x64__8wekyb3d8bbwe\companionapp => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {930D8A09-A47D-4D71-BBFA-E79C0D7A796C} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2015-12-14] (AsusTek) Task: {93145A6F-6B46-4902-8644-6561CDA36499} - System32\Tasks\{9CAE88F4-1237-4F66-A08F-CECA015148A6} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe" Task: {944ACC73-A904-47D1-8A2F-7C216593B48B} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-10] (ASUSTek Computer Inc.) Task: {97EA9DE1-4B39-4D9C-B9C9-CAD885F4652D} - System32\Tasks\microsoft-zunemusic_10 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {98DF7D18-1EF6-4D68-8605-3FE0613B1457} - System32\Tasks\microsoft-zunemusic_10-17012-10311 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {994600DE-95FE-4145-8CD4-C8F383F1A979} - System32\Tasks\updater\updater => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {9BC306BF-CA3C-4E52-B3A6-39C03B8886D9} - System32\Tasks\acrobat dc\acrobat\acrocef\acrocef => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {9EA8D873-D1F5-4BF1-8D01-9F25870A90A5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated) Task: {9ED71A53-C0A9-42DD-B89E-FADB554B2ECB} - System32\Tasks\EPSON XP-225 Series Update {9382EEC5-E637-4BB5-BD83-ECDDB0F8990E} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSNFE.EXE [2013-11-22] (SEIKO EPSON CORPORATION) Task: {A050F827-9F8E-46BF-8F04-122D982DB487} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-09-28] () Task: {A12367D5-65A1-4638-BB7E-9D1FA0E8B707} - System32\Tasks\antivirus\updrgui => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {A48F95D7-0008-4196-B575-870DC57A55FF} - System32\Tasks\microsoft-windows => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {A81B9DEC-38A3-435C-89DB-64F50E6DC9E1} - System32\Tasks\microsoft-zunevideo_10-17012-10301-0_x64__8wekyb3d8bbwe\video-ui => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {A8D5066A-B164-4D92-A09D-0733EEB4B840} - System32\Tasks\acrobat dc\acrobat\acrotray => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {A9F35256-83EA-442A-95E0-2AE6981108BE} - System32\Tasks\microsoft-windows-photos_16-1118-10000 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {AA7D3BEA-266D-4E77-BD33-6ADE6FAADB50} - System32\Tasks\antivirus\update => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {AA8F726F-F384-4D62-BD5C-66BA44589311} - System32\Tasks\intel(r) security assist\isa => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {AC101F92-B8D6-4886-B3A3-E2F929077D9D} - System32\Tasks\microsoft-zunemusic_10-17012-10301-0_x64__8wekyb3d8bbwe\music => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {B795A4B8-1364-41CA-AA6B-53939D400D0E} - System32\Tasks\microsoft-windows-photos_17-214-10010-0_x64__8wekyb3d8bbwe\microsoft-photos => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {BEECCB3D-B8DB-4CFA-8375-B7CE0CB90505} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION Task: {C17087D3-1FCE-40C1-915B-A89B49019072} - System32\Tasks\acrobat dc\acrobat\acrobat_sl-exe => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {C2BFE0FC-4282-4BAC-B345-1D379BBCFC56} - System32\Tasks\microsoft-zunemusic_10-17012-10301-0_x64__8wekyb3d8bbwe\music-ui => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {C355FDB4-AA15-41AC-A70A-9F86A0D6A4FD} - System32\Tasks\microsoft-zunevideo_10-17012-10301-0_x64__8wekyb3d8bbwe\video => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {C4289319-F1F2-4A59-A1DC-A2F5735E22DD} - System32\Tasks\microsoft-windows-photos_16-1118-10000-0_x64__8wekyb3d8bbwe\microsoft => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {C712BF27-41B6-4346-B3C1-72CE9B32F178} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2015-05-25] (ASUSTek Computer Inc.) Task: {C80C2F5C-74B7-4815-A85A-D1AF8D71F6ED} - System32\Tasks\antivirus\checkt => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {CAC0B13C-95D3-4DDE-8D36-FAF3E210D853} - System32\Tasks\microsoft-windowscommunicationsapps_17-7912-40507 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {CFDB1BD4-C20D-46FC-9306-10CD6636EF28} - System32\Tasks\microsoft-windowsphone_10-1609 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {D1BFBB06-137D-40A7-9E1C-B7AF1E2EF012} - System32\Tasks\microsoft-windowscommunicationsapps_17-7920-40507 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {D49CE8E7-D853-4A81-8789-20FB48B39FC1} - System32\Tasks\microsoft-windows-photos_17-214 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {DAC82BCC-BDB8-4CD0-A29B-920FB7F7C440} - System32\Tasks\microsoft-skypeapp_11-11-110-0_x64__kzf8qxf38zg5c\skypehost => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {DCC4FBDA-3A1E-4BBC-A523-3AC8DAA5C12A} - System32\Tasks\antivirus\updrgui-exe => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {DD7D2D0A-BB35-4527-941A-06ADE6346DE3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-12-23] (Microsoft Corporation) Task: {E0DDB345-B589-4449-80F5-586B44649ECB} - System32\Tasks\microsoft-windowscommunicationsapps_17-7922-42017-0_x64__8wekyb3d8bbwe\hxtsr => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {E1083C98-992E-4C97-8385-81D3595468BA} - System32\Tasks\microsoft-windowscommunicationsapps_17-7920 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {E514355F-E11D-41E5-AFDB-DBF9FEC47FAB} - System32\Tasks\{33CA0CDD-DDB1-44D1-82B1-21665A702482} => C:\WINDOWS\system32\pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\" Task: {E6769874-1AFA-4D75-938D-40EFED283DB5} - System32\Tasks\acrobat dc\acrobat\acrodist => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {E68D829C-7D9C-4392-A040-C23397EAD8F6} - System32\Tasks\acrobat dc\acrobat\acrobat_sl => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {E7E45915-350C-4E93-A796-EF5269C9C260} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-12-02] (Microsoft Corporation) Task: {E9C2C0EB-AA60-44A3-A0D4-2ACC3658965B} - System32\Tasks\microsoft-zunevideo_10 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {EB27B254-9B54-4AD3-8AAC-5C401DD7EE9C} - System32\Tasks\antivirus\avwsc-exe => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {EE838C30-460F-4FED-AFAE-5E15BB862992} - System32\Tasks\microsoft-windowscalculator_10-1702 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {F1D02F16-E1EE-4545-B978-F7C15D9C030A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-09-28] () Task: {F3E1E516-799D-4C26-9184-7F37832C1167} - System32\Tasks\microsoft-zunemusic_10-17012-10311-0_x64__8wekyb3d8bbwe\music => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {F46F1275-3749-4F73-9744-F15EFD11D030} - System32\Tasks\antivirus\avwsc => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {F612FFEB-B32A-4F2C-894A-BC42AD4424DD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-12-23] (Microsoft Corporation) Task: {F7800B11-31FC-4815-9BA8-C4D1FC4F7E6B} - System32\Tasks\microsoft-windowscommunicationsapps_17-7922 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {FB35DA62-5B6C-4AE0-BA48-C6B08AECEF9D} - System32\Tasks\acrobat reader dc\reader\reader_sl => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {FB6214DE-AD34-4CC3-BF49-2EA0FBA2D0D0} - System32\Tasks\microsoft-windows-photos_16 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {FE928B64-80FC-495B-AEC3-6A4BA402B952} - System32\Tasks\microsoft-zunemusic_10-17012 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI Task: {FF346C4D-E3BD-4053-B37D-F44BFCBF1FE7} - System32\Tasks\microsoft-windowsphone_10 => C:\WINDOWS\system32\rundll32.exe "C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll",SJupFraI (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\EPSON XP-225 Series Update {9382EEC5-E637-4BB5-BD83-ECDDB0F8990E}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSNFE.EXE:/EXE:{9382EEC5-E637-4BB5-BD83-ECDDB0F8990E} /F:UpdateWORKGROUP\QUENTIN$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-70007279-1525863979-1083813302-1001Core.job => C:\Users\Quentin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-70007279-1525863979-1083813302-1001Core1d16bffd08b317e.job => C:\Users\Quentin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-70007279-1525863979-1083813302-1001Core1d1aafb528dce91.job => C:\Users\Quentin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\microsoft.job => rundll32.exe C:\ProgramData\8446S20J0u2334\8446S20J0u2334.dll ==================== Raccourcis & WMI ======================== (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) ShortcutWithArgument: C:\Users\Quentin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\LOL - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2" ==================== Modules chargés (Avec liste blanche) ============== 2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2015-10-12 17:07 - 2014-04-14 18:59 - 000389896 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2017-12-12 16:41 - 2017-12-12 16:42 - 000948736 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_2.0.5.0_x64__8wekyb3d8bbwe\e_sqlite3.dll 2017-12-12 16:41 - 2017-12-12 16:42 - 002360512 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_2.0.5.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll 2017-12-12 16:41 - 2017-12-12 16:42 - 000381440 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_2.0.5.0_x64__8wekyb3d8bbwe\Microsoft.Notes.Upgrade.dll 2017-09-29 14:41 - 2017-09-29 14:41 - 004069888 _____ () C:\Windows\System32\Windows.UI.Input.Inking.Analysis.dll 2017-12-01 07:46 - 2017-12-01 07:46 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-12-01 07:46 - 2017-12-01 07:46 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-01-03 13:44 - 2018-01-03 13:46 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-01-03 13:44 - 2018-01-03 13:46 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-01-06 07:45 - 2018-01-03 10:20 - 004063064 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\libglesv2.dll 2018-01-06 07:45 - 2018-01-03 10:20 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\libegl.dll 2018-01-09 17:52 - 2018-01-09 17:52 - 004698840 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.11.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-12-15 14:20 - 2017-12-15 14:20 - 004307968 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1712.3351.0_x64__8wekyb3d8bbwe\Calculator.exe 2015-08-25 09:40 - 2015-08-25 09:40 - 000027648 _____ () C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll 2015-08-25 09:40 - 2015-08-25 09:40 - 000124928 _____ () C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll 2015-09-04 20:34 - 2015-09-04 20:34 - 001243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.) ==================== Mode sans échec (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.) ==================== Association (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.) ==================== Internet Explorer sites de confiance/sensibles =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.) ==================== Hosts contenu: =============================== (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2015-07-10 12:04 - 2017-03-27 22:17 - 000000027 ____N C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Autres zones ============================ (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-70007279-1525863979-1083813302-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Quentin\desktop\fiona\13918811_1485827728110052_502349583_o.jpg DNS Servers: 89.2.0.1 - 89.2.0.2 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run32: => "WebStorage" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKLM\...\StartupApproved\Run32: => "Avira SystrayStartTrigger" HKLM\...\StartupApproved\Run32: => "avgnt" HKLM\...\StartupApproved\Run32: => "DelaypluginInstall" HKLM\...\StartupApproved\Run32: => "iSkysoft Helper Compact.exe" HKLM\...\StartupApproved\Run32: => "AdobeCS6ServiceManager" HKLM\...\StartupApproved\Run32: => "SwitchBoard" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "EEventManager" HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\StartupFolder: => "EvernoteClipper.lnk" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\StartupFolder: => "FacebookGamesNotifier.exe.lnk" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\StartupFolder: => "Facebook Games Arcade (BETA).lnk" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\StartupFolder: => "Envoyer à OneNote.lnk" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "Google Update" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "RESTART_STICKY_NOTES" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "Lync" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "BingSvc" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_8EA379742504899D1127D17F59A4BB90" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "XperiaCompanionAgent" HKU\S-1-5-21-70007279-1525863979-1083813302-1001\...\StartupApproved\Run: => "Steam" ==================== RèglesPare-feu (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [UDP Query User{7CA4F340-C5B3-4D85-9EE6-8F18CDBF891B}C:\gog games\broforce\broforce_beta.exe] => (Allow) C:\gog games\broforce\broforce_beta.exe FirewallRules: [TCP Query User{F33C37B2-13F3-4F80-8028-1EC854316E1F}C:\gog games\broforce\broforce_beta.exe] => (Allow) C:\gog games\broforce\broforce_beta.exe FirewallRules: [UDP Query User{63333571-2A96-40C3-808B-317210D90EEF}C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_44090.exe] => (Allow) C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_44090.exe FirewallRules: [TCP Query User{CBE150A7-D35E-4BFA-A9CD-D3D0FC0DD2B3}C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_44090.exe] => (Allow) C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_44090.exe FirewallRules: [UDP Query User{911F8A18-4C6D-44E7-956B-979A5516BD1D}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [TCP Query User{072526F6-40AB-43C2-B7EF-5085B2530822}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [UDP Query User{CD8CD7AD-F3E2-4A48-9B3E-4A271D6C43B8}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [TCP Query User{3290D25A-0037-41F6-858A-EFC6DA731B3C}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{E0589515-3845-4A5A-AE76-184AAD837938}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [TCP Query User{756448BC-C623-4F10-997C-4D71C74232E7}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [UDP Query User{6B7EB09C-324E-4F35-AC1C-AE3321DC82A3}C:\program files (x86)\the good drive\thegooddrive.exe] => (Allow) C:\program files (x86)\the good drive\thegooddrive.exe FirewallRules: [TCP Query User{54A547A8-2077-4478-B9D1-38B253DA5F45}C:\program files (x86)\the good drive\thegooddrive.exe] => (Allow) C:\program files (x86)\the good drive\thegooddrive.exe FirewallRules: [UDP Query User{961514DC-33A3-4E81-9C3C-B440D525CE03}C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_44090.exe] => (Block) C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_44090.exe FirewallRules: [TCP Query User{92819A18-0F7A-4554-A8F9-49BA60D2F7E2}C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_44090.exe] => (Block) C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_44090.exe FirewallRules: [{A0987FCE-0837-471A-875C-8717B06109B1}] => (Allow) C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanion.exe FirewallRules: [{D661B4D3-31B9-4AC8-A732-CD2B0BFF24E7}] => (Allow) C:\Program Files (x86)\Steam\Nouveau dossier\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{D9BE2D87-9A9B-4002-96FA-7A33F438BE79}] => (Allow) C:\Program Files (x86)\Steam\Nouveau dossier\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{6CF3A12C-8017-47E4-8BAF-0779D64196AC}] => (Allow) C:\Program Files (x86)\Steam\Nouveau dossier\Steam.exe FirewallRules: [{203948A2-E882-4ACF-B635-66AEE7541B80}] => (Allow) C:\Program Files (x86)\Steam\Nouveau dossier\Steam.exe FirewallRules: [{947C0DA9-5D5C-41E1-80D2-52A7454FA298}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [UDP Query User{84AB4374-2990-4131-96DF-5FC40323FA3B}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [TCP Query User{CCEC7491-9826-4A4C-BC5A-582A541AB314}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [{0A81E548-479A-4138-ACB9-9EFD93124A4D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{639581FF-33A7-41C2-88A2-93A703ABFD66}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{9D235E0D-D34D-469D-81BA-3C226E97844E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{7A3F771C-93E1-45FE-91B1-442CA0657E53}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{7C3BE067-A695-4985-87FA-78B03A269327}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{430B17A0-693B-4EC0-9746-75DB43D14FEA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [UDP Query User{AFC5870D-742B-43D8-BAC4-CC9F8D059C2D}C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_43804.exe] => (Allow) C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_43804.exe FirewallRules: [TCP Query User{B3992785-B67F-452F-98EB-863FF5B071A0}C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_43804.exe] => (Allow) C:\users\quentin\appdata\roaming\utorrent\updates\3.5.0_43804.exe FirewallRules: [{A78E4103-755B-423C-90BD-4EC876C2CA13}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{3F498BDD-C6CF-40DF-B0DD-52878FB6B4DE}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{3DBAECB5-30B2-4495-9FF9-5600FE2FC5BA}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{7DDF771C-0576-4B8F-8096-46EA69B711C9}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{25B4F81C-C935-4AE4-B7BF-9F60CC6F47A3}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{1BC88063-17C5-420A-BE71-D274D7945706}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Online Phone Manager\iOS Recorder.exe FirewallRules: [{C234ACD5-DCDF-41B0-A614-8EC8F023B1A2}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Online Phone Manager\iOS Recorder.exe FirewallRules: [{2A40A76F-3332-481B-AB5F-526E742F370D}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Online Phone Manager\ApowersoftAndroidDaemon.exe FirewallRules: [{0FC33828-9649-4915-AD42-AD5B164D1BC7}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Online Phone Manager\ApowersoftAndroidDaemon.exe FirewallRules: [{72450F4B-4ABF-41A8-ADF3-4A565E134778}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Online Phone Manager\Online Phone Manager.exe FirewallRules: [{59848A42-30EE-47B1-9608-DC8A6465EAC6}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Online Phone Manager\Online Phone Manager.exe FirewallRules: [{781BC825-48C0-4889-87FF-9561AE925B97}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe FirewallRules: [{C096B130-5C85-4E9E-9F4F-BC2A41DF1029}] => (Allow) C:\Users\Quentin\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup\Data\ENEasyApp.exe FirewallRules: [{2DDEED6F-06E3-4EF0-8B72-D7DA48FE0C9F}] => (Allow) C:\Users\Quentin\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup\Data\ENEasyApp.exe FirewallRules: [{B31C789D-1848-4E20-85BC-9183231475C9}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{B79C5D4E-B8ED-4B9F-8755-0B6344721264}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{21982FEC-EF5C-4B2D-92B3-F2FA742D90B4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{D82E1D8F-8EE0-4241-9058-562979B492AD}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{E093EFB6-0D90-415E-B9F5-9319F68E1F51}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Steep Open Beta\steep.exe FirewallRules: [{3B42F85E-23A9-40F6-92DB-61E9616FD839}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Steep Open Beta\steep.exe FirewallRules: [{4A2EF0D9-7D36-4FE3-AADE-56CFC51F52AC}] => (Allow) C:\Program Files (x86)\Plagiarism Detector\Plagiarism Detector.exe FirewallRules: [{042DA6FD-1F23-430B-8F5F-B8E9C15E54EC}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{89CE7750-A5CE-4024-B59E-5482E2F83ED0}] => (Allow) LPort=2869 FirewallRules: [{18878002-6FEB-46BE-9865-C78EA2AEE97A}] => (Allow) LPort=1900 FirewallRules: [{50DD2A66-A08F-468B-840D-AE9F5E2EE1BF}] => (Allow) C:\Users\Quentin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{FA350D95-F83F-488A-8219-8667D387D32E}] => (Allow) C:\Users\Quentin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{39C0B127-956F-41ED-934E-1685CB56F3D4}] => (Allow) C:\Users\Quentin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{61B5F5D5-FF89-4135-BF79-331232070D92}] => (Allow) C:\Users\Quentin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{CABC69A0-B929-4BE1-8D8D-EC55834FF21B}] => (Allow) C:\Users\Quentin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{B88E8469-E0EB-464F-877E-B92EB91F39D8}] => (Allow) C:\Users\Quentin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{59E8AB48-21B1-49DC-8590-CE18D6568AB3}C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43085.exe] => (Block) C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43085.exe FirewallRules: [UDP Query User{A1A45D8D-C814-48AC-8197-776D9EC0C274}C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43085.exe] => (Block) C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43085.exe FirewallRules: [TCP Query User{AF38A3C3-D3A8-4790-A741-7B0E6F552ADE}C:\users\quentin\downloads\drlsimulator_1-0-12_win\simulator\drlsimulator.exe] => (Allow) C:\users\quentin\downloads\drlsimulator_1-0-12_win\simulator\drlsimulator.exe FirewallRules: [UDP Query User{8F814BCA-54A3-4C72-A549-CDD3A2B543E8}C:\users\quentin\downloads\drlsimulator_1-0-12_win\simulator\drlsimulator.exe] => (Allow) C:\users\quentin\downloads\drlsimulator_1-0-12_win\simulator\drlsimulator.exe FirewallRules: [TCP Query User{D62F8EAE-1C4A-4543-B72D-5FDC8C1B1413}C:\users\quentin\downloads\pigeonpoopvr_x86_64\pigeonpoopvr_x86_64\pigeonpoop.exe] => (Allow) C:\users\quentin\downloads\pigeonpoopvr_x86_64\pigeonpoopvr_x86_64\pigeonpoop.exe FirewallRules: [UDP Query User{A2A9E2F6-B84A-4530-90A6-E1E91872C6B1}C:\users\quentin\downloads\pigeonpoopvr_x86_64\pigeonpoopvr_x86_64\pigeonpoop.exe] => (Allow) C:\users\quentin\downloads\pigeonpoopvr_x86_64\pigeonpoopvr_x86_64\pigeonpoop.exe FirewallRules: [TCP Query User{28AD23CA-5B32-4699-994B-B9D30BBB1B35}C:\program files (x86)\trinusvr\tgserver.exe] => (Allow) C:\program files (x86)\trinusvr\tgserver.exe FirewallRules: [UDP Query User{942A721D-FEEF-48CB-97B8-F41EAE5EF936}C:\program files (x86)\trinusvr\tgserver.exe] => (Allow) C:\program files (x86)\trinusvr\tgserver.exe FirewallRules: [TCP Query User{D32CFD75-3B03-4202-B41D-E0D9963D9E8D}C:\users\quentin\downloads\pigeonpoopvr_x86_64\pigeonpoopvr_x86_64\pigeonpoop.exe] => (Allow) C:\users\quentin\downloads\pigeonpoopvr_x86_64\pigeonpoopvr_x86_64\pigeonpoop.exe FirewallRules: [UDP Query User{ACA8C65A-A00C-4E89-8F5E-1EED468E035B}C:\users\quentin\downloads\pigeonpoopvr_x86_64\pigeonpoopvr_x86_64\pigeonpoop.exe] => (Allow) C:\users\quentin\downloads\pigeonpoopvr_x86_64\pigeonpoopvr_x86_64\pigeonpoop.exe FirewallRules: [TCP Query User{39C3588E-6B0F-4D2C-B76B-4496A84AF320}C:\program files (x86)\trinusvr\tgserver.exe] => (Allow) C:\program files (x86)\trinusvr\tgserver.exe FirewallRules: [UDP Query User{51826B5E-8526-44C8-9B13-353332712A20}C:\program files (x86)\trinusvr\tgserver.exe] => (Allow) C:\program files (x86)\trinusvr\tgserver.exe FirewallRules: [{E26B663F-EB96-4AF2-99F6-48AEDF0B38DC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{CB3CB101-B2F8-4F15-A6BB-30EFD5B79F22}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [TCP Query User{E857B51F-9904-4C52-95A9-83B6EA4F399E}C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43085.exe] => (Allow) C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43085.exe FirewallRules: [UDP Query User{C7392E85-34C1-42C1-B312-EB451643B9BE}C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43085.exe] => (Allow) C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43085.exe FirewallRules: [{91A287A9-4482-46F7-AFBB-74EF8643B166}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe FirewallRules: [{9D1D138E-8E6E-4243-97E0-534AA74E30F9}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Apowersoft Online Launcher\Apowersoft Online Launcher.exe FirewallRules: [{601B280C-D38F-49AF-BA21-D642CFA70890}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Online Video Converter\Online Video Converter.exe FirewallRules: [{0A469EDA-671E-47F1-BC0F-6326E9646EAC}] => (Allow) C:\Users\Quentin\AppData\Local\Apowersoft\Online Video Converter\Online Video Converter.exe FirewallRules: [{022128B7-8F94-4596-B2C7-A6AC66206944}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Converter Studio\Video Converter Studio.exe FirewallRules: [{4E7B5888-FCDE-4E17-B42E-9242EE0F4DCA}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Converter Studio\Video Converter Studio.exe FirewallRules: [{A18F9DB4-AF4A-4B2B-9E25-1783D2263123}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [TCP Query User{53DE22DB-E0B8-4521-8CFA-64B8CFF9BB8C}C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43295.exe] => (Allow) C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43295.exe FirewallRules: [UDP Query User{EFE28F1E-09BF-41C5-8367-3A18B2CE246F}C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43295.exe] => (Allow) C:\users\quentin\appdata\roaming\utorrent\updates\3.4.9_43295.exe FirewallRules: [{5D75B8DE-7DE1-4411-99A9-85BDB99A75F2}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{84DB45F0-3F55-427B-85ED-31A627568E5B}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{8578278C-E123-403B-B063-0D59D2B6BCA5}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{E9B707E4-87C3-4D65-96DC-D7AF7C7CE72F}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe FirewallRules: [{F9CD04C9-3386-4518-A598-20AF9307C977}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{23CF6FC4-85DC-4298-9068-7B617968B4E2}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{78DCF83D-AB2B-4DFC-819D-531AA47C78DE}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe FirewallRules: [{A3964F4A-C366-4C1E-BB89-4FF6610B54D8}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{E8F6930C-852D-4DE5-9C0E-2E83B5713AF2}] => (Allow) C:\Program Files\Lightworks\lightworks.exe FirewallRules: [{DE0A60BC-1CD8-4E99-9A82-0A94B007AA19}] => (Allow) C:\Program Files\Lightworks\lightworks.exe FirewallRules: [{28B3EA9F-586F-4869-B715-F4A899FE15A3}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe FirewallRules: [{2CC9D0A5-11BF-4C8A-96A0-C61EF151B50F}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe FirewallRules: [TCP Query User{EB617796-9B32-4AF0-BACC-47822DF1F861}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{05486295-E0B5-43A0-8060-60BEB7A28F61}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [{3A9E62D2-288F-45AD-90F0-8110E5C9B794}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{FCD76AF7-835A-4D9A-B2E1-AEC7D0DD1195}] => (Allow) %systemroot%\system32\alg.exe ==================== Points de restauration ========================= 29-12-2017 12:38:58 Point de contrôle planifié 07-01-2018 11:11:12 Point de contrôle planifié 11-01-2018 17:33:43 Windows Update ==================== Éléments en erreur du Gestionnaire de périphériques ============= ==================== Erreurs du Journal des événements: ========================= Erreurs Application: ================== Error: (01/17/2018 09:39:42 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:39:42Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:39:12 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:39:12Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:38:42 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:38:42Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:38:12 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:38:12Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:37:42 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:37:42Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:37:12 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:37:12Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:36:42 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:36:42Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:36:12 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:36:12Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:35:42 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:35:42Z. Code d’erreur : 0x80070005. Error: (01/17/2018 09:35:12 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: ) Description: Échec de la planification du redémarrage du service de protection logicielle à 2117-12-24T20:35:12Z. Code d’erreur : 0x80070005. Erreurs système: ============= Error: (01/17/2018 08:43:27 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 08:41:20 PM) (Source: DCOM) (EventID: 10016) (User: QUENTIN) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID QUENTIN\Quentin de l’utilisateur (S-1-5-21-70007279-1525863979-1083813302-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 08:38:23 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 08:28:54 PM) (Source: DCOM) (EventID: 10016) (User: QUENTIN) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID QUENTIN\Quentin de l’utilisateur (S-1-5-21-70007279-1525863979-1083813302-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 08:28:27 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} et l’APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 08:28:27 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} et l’APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 08:25:36 PM) (Source: DCOM) (EventID: 10016) (User: QUENTIN) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID QUENTIN\Quentin de l’utilisateur (S-1-5-21-70007279-1525863979-1083813302-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 08:24:44 PM) (Source: DCOM) (EventID: 10016) (User: QUENTIN) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID QUENTIN\Quentin de l’utilisateur (S-1-5-21-70007279-1525863979-1083813302-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 08:19:22 PM) (Source: DCOM) (EventID: 10016) (User: QUENTIN) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID QUENTIN\Quentin de l’utilisateur (S-1-5-21-70007279-1525863979-1083813302-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (01/17/2018 07:49:28 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. ==================== Infos Mémoire =========================== Processeur: Intel(R) Core(TM) i5-6200U CPU @ 2.30GHz Pourcentage de mémoire utilisée: 43% Mémoire physique - RAM - totale: 8091.01 MB Mémoire physique - RAM - disponible: 4605.83 MB Mémoire virtuelle totale: 10395.01 MB Mémoire virtuelle disponible: 6834.03 MB ==================== Lecteurs ================================ Drive c: (OS) (Fixed) (Total:237.72 GB) (Free:85.27 GB) NTFS ==>[système avec composants d'amorçage (obtenu depuis lecteur)] ==================== MBR & Table des partitions ================== ======================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: 5AE8264E) Partition: GPT. ==================== Fin de Addition.txt ============================