Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 12.05.2018 Exécuté par ivanv (16-05-2018 12:50:24) Exécuté depuis C:\Users\ivanv\Desktop Windows 10 Pro Version 1709 16299.431 (X64) (2017-10-31 00:47:42) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= Administrateur (S-1-5-21-484587128-3933791518-1798071367-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-484587128-3933791518-1798071367-503 - Limited - Disabled) Invité (S-1-5-21-484587128-3933791518-1798071367-501 - Limited - Disabled) ivanv (S-1-5-21-484587128-3933791518-1798071367-1001 - Administrator - Enabled) => C:\Users\ivanv WDAGUtilityAccount (S-1-5-21-484587128-3933791518-1798071367-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: COMODO Antivirus (Enabled - Up to date) {08B84BA8-CC77-5A8B-A100-3F522B1B6106} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: COMODO Advanced Protection (Enabled - Up to date) {B3D9AA4C-EA4D-5505-9BB0-0420509C2BBB} FW: COMODO Firewall (Enabled) {3083CA8D-8618-5BD3-8A5F-9667D5C8267D} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach) Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts) Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.54.32003 - Electronic Arts) Battlefield™ Hardline (HKLM-x32\...\{CB4AC3DA-8CC1-4516-86DA-4078B57DB229}) (Version: 1.4.0.10 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) Blender (HKLM\...\{B1DF3793-1651-4AE5-9CA0-E845DD8B526B}) (Version: 2.79.0 - Blender Foundation) cFosSpeed v10.23 (HKLM\...\cFosSpeed) (Version: 10.23 - cFos Software GmbH, Bonn) Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 63.0.3239.108 - Comodo) COMODO Internet Security Premium (HKLM\...\{4F6FC44D-AE9F-472B-8F00-B8388BC9AA04}) (Version: 10.2.0.6526 - COMODO Security Solutions Inc.) Hidden COMODO Internet Security Premium (HKLM\...\COMODO Internet Security) (Version: 10.2.0.6526 - COMODO Security Solutions Inc.) COMODO Secure Shopping (HKLM-x32\...\{D15DF9B0-3A98-4BEF-B7D5-FC3AEA442656}) (Version: 1.3.138.0 - COMODO) Hidden COMODO Secure Shopping (HKLM-x32\...\Comodo Secure_Shopping_list_uninstall) (Version: 1.3.442656.138 - Comodo) Crossout Launcher 1.0.3.36 (HKU\S-1-5-21-484587128-3933791518-1798071367-1001\...\CrossOutLauncher_is1) (Version: - ) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 391.35 - NVIDIA Corporation) Hidden ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) Far Cry 3 Blood Dragon (HKLM-x32\...\Uplay Install 205) (Version: - Ubisoft) FL Studio 12 (HKLM-x32\...\FL Studio 12) (Version: - Image-Line) FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line) GeoGebra Geometry (HKU\S-1-5-21-484587128-3933791518-1798071367-1001\...\GeoGebra_Geometry) (Version: 6.0.388 - International GeoGebra Institute) GeoGebra Graphing (HKU\S-1-5-21-484587128-3933791518-1798071367-1001\...\GeoGebra_Graphing) (Version: 6.0.387 - International GeoGebra Institute) IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1036 - Intel Corporation) Intel(R) Network Connections 21.1.30.0 (HKLM\...\PROSetDX) (Version: 21.1.30.0 - Intel) Intel(R) Online Connect Software Asset Manager (HKLM-x32\...\{AE956AB9-CD98-4F1E-8B9E-C3C66E290D64}) (Version: 3.4.2072 - Intel Corporation) Hidden Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1633.3 - Intel Corporation) Internet Security Essentials (HKLM-x32\...\ComodoIse) (Version: 1.3.438464.135 - Comodo) Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation) LMMS 1.1.3 (HKLM-x32\...\LMMS) (Version: 1.1.3 - LMMS Developers) Logiciel pour périphérique à chipset Intel® (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden Logitech - Assistant pour jeux vidéo 8.96 (HKLM\...\Logitech Gaming Software) (Version: 8.96.88 - Logitech Inc.) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-484587128-3933791518-1798071367-1001\...\OneDriveSetup.exe) (Version: 18.065.0329.0002 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25017 (HKLM-x32\...\{e9d78d68-c26c-4da7-9158-99355d8ef3ad}) (Version: 14.10.25017.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) Mises à jour NVIDIA 31.1.10.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.1.10.0 - NVIDIA Corporation) Hidden Mozilla Firefox 60.0 (x64 en-US) (HKLM\...\Mozilla Firefox 60.0 (x64 en-US)) (Version: 60.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.2 - Mozilla) MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 2.0.0.45 - MSI) MSI Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.1.12 - MSI) MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.2.0.35 - MSI) MSI Gaming Lan Manager (HKLM-x32\...\{3318282C-D4D6-4B29-BBD5-95FC34B54FF0}_is1) (Version: 1.0.0.53 - MSI) MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.2.0.22 - MSI) MSI RAMDisk (HKLM-x32\...\{F29CF050-7278-4CDB-9EF8-2DC6DAA87453}}_is1) (Version: 1.0.0.27 - MSI) MSI Smart Tool (HKLM-x32\...\{DDCCA038-DAB1-4D09-B85C-848020AA75D6}}_is1) (Version: 1.0.0.22 - MSI) MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.3.0.19 - MSI) MSI USB Speed Up (HKLM-x32\...\{79D5FA63-7003-4398-B882-C70ED18778D1}_is1) (Version: 1.0.0.11 - MSI) NVIDIA GeForce Experience 3.13.1.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.13.1.30 - NVIDIA Corporation) NVIDIA Logiciel système PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) NVIDIA Pilote 3D Vision 391.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 391.35 - NVIDIA Corporation) NVIDIA Pilote audio HD : 1.3.36.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.36.6 - NVIDIA Corporation) NVIDIA Pilote du contrôleur 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) NVIDIA Pilote graphique 391.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 391.35 - NVIDIA Corporation) OpenOffice 4.1.4 (HKLM-x32\...\{DAEDCAF7-E42C-41E1-822C-33658A2C6EAD}) (Version: 4.14.9788 - Apache Software Foundation) Origin (HKLM-x32\...\Origin) (Version: 10.5.18.58059 - Electronic Arts, Inc.) Panneau de configuration NVIDIA 391.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 391.35 - NVIDIA Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.994 - Even Balance, Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8245 - Realtek Semiconductor Corp.) RSI Launcher 1.0.0 (HKLM\...\81bfc699-f883-50c7-b674-2483b6baae23) (Version: 1.0.0 - Cloud Imperium Games) Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.) STAR WARS™ Battlefront™ (HKLM-x32\...\{E402D891-4E45-4ce9-B41F-DD35864EF170}) (Version: 1.0.7.64833 - Electronic Arts) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Uplay (HKLM-x32\...\Uplay) (Version: 42.0 - Ubisoft) VirtualDJ 8 (HKLM-x32\...\{E1962904-0960-42F6-9072-3EC7D66A5495}) (Version: 8.2.3994.0 - Atomix Productions) Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden War Thunder Launcher 1.0.3.51 (HKU\S-1-5-21-484587128-3933791518-1798071367-1001\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment) Web Companion (HKLM-x32\...\{59c549ed-e19e-4835-95cc-dbe16011ada9}) (Version: 4.2.1846.3481 - Lavasoft) WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH) ==================== Personnalisé CLSID (Avec liste blanche): ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ContextMenuHandlers1: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2018-03-13] (COMODO) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers2: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2018-03-13] (COMODO) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2018-03-24] (NVIDIA Corporation) ContextMenuHandlers6: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2018-03-13] (COMODO) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal) ==================== Tâches planifiées (Avec liste blanche) ============= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {050126A0-4714-480A-8165-500C9E9AA3DB} - System32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7 => C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2016-09-29] (Intel Corporation) Task: {1EF81218-2210-401E-8079-F84960BA9E99} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2018-03-13] (COMODO) Task: {21FB825E-D601-4521-9A7A-17F1999C1170} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-03-14] (NVIDIA Corporation) Task: {23CF41B2-D909-4F32-8772-FD7F8C0F0B11} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-03-14] (NVIDIA Corporation) Task: {2FFFC25A-3A00-4EB1-AFCC-0A6DA4B871E8} - System32\Tasks\{31DDBD37-5DB7-4030-8064-10B0CAA806C3} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2018-03-13] (COMODO) Task: {3419948F-4659-4CEE-B7A8-1A8D9DA3A6B9} - System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-03-13] (COMODO) Task: {3723F9FA-A5E7-49D0-9CF1-85C91071EC31} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-03-14] (NVIDIA Corporation) Task: {3CE07295-B7D6-4B75-A0AB-67AB652007CA} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-03-13] (COMODO) Task: {3D4C3C16-34FA-44E0-B1CC-9F484D927264} - System32\Tasks\COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-03-13] (COMODO) Task: {5A27EF6E-5148-46E0-9FDC-0A2C8A9CDF71} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe [2017-09-05] (Micro-Star INT'L CO., LTD.) Task: {6EFD5FDB-B041-41CA-AF4D-6AFD7EC6080A} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-03-14] (NVIDIA Corporation) Task: {7DCBD75B-99D2-45C5-93EE-9CE7EA0B7F40} - System32\Tasks\MSIGH_Host => C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey.exe [2017-06-23] (Micro-Star INT'L CO., LTD.) Task: {87DF45F2-0256-47B0-B3F7-D0F36D387C09} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-03-13] (COMODO) Task: {8A6B6CE5-A090-49AA-95FB-1502763A5DD0} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe [2017-09-05] (Micro-Star INT'L CO., LTD.) Task: {8D71E267-0F83-4338-98F1-75AD14BAF319} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe Task: {93DA5CAC-8218-4D09-BC13-8A5C6589597D} - System32\Tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon => C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2016-09-29] (Intel Corporation) Task: {A8C32A41-DDE4-43D3-91E6-5AE6C51A8ADC} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-03-14] (NVIDIA Corporation) Task: {AEBC5FC6-9118-42A0-94B2-33500E94EAC8} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-03-13] (COMODO) Task: {B93266FB-55A4-4A07-9B8B-974863C85D7A} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2016-07-26] (Intel(R) Corporation) Task: {BA2DBB8A-D4F0-47CA-86EF-5101AED2090F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-03-14] (NVIDIA Corporation) Task: {C51D2528-474E-4662-B386-26445A968639} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [2015-08-18] (MSI) Task: {C71DD5C9-23C0-4164-8131-69C7BA0F97CA} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-03-14] (NVIDIA Corporation) Task: {F8FE39A5-6FC1-4DE6-8F4D-C82095ED206B} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-03-14] (NVIDIA Corporation) Task: {FBAE72A6-3F43-46E7-BBFB-C06EBF04AC97} - System32\Tasks\COMODO\COMODO Telemetry {18AD3DFA-30C0-4B5F-84F7-F1870B1A4921} => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [2018-03-13] (COMODO) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) ==================== Raccourcis & WMI ======================== (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) Shortcut: C:\Users\ivanv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\Online Help.lnk -> hxxp://www.virtualdj.com/wiki Shortcut: C:\Users\ivanv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\www.virtualdj.com.lnk -> hxxp://www.virtualdj.com ==================== Modules chargés (Avec liste blanche) ============== 2018-03-28 20:22 - 2018-03-24 03:19 - 000544192 _____ () C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem\DisplayDriverAnalyzer\_DisplayDriverCrashAnalyzer64.dll 2017-08-29 06:57 - 2018-03-13 19:18 - 000160960 _____ () C:\Program Files\COMODO\COMODO Internet Security\cmdwrhlp.dll 2017-08-29 06:56 - 2018-03-13 19:17 - 000107200 _____ () C:\Program Files\COMODO\COMODO Internet Security\cavwpps.dll 2017-08-29 06:56 - 2018-03-13 19:17 - 000244416 _____ () C:\Program Files\COMODO\COMODO Internet Security\cmdcomps.dll 2016-10-05 13:15 - 2016-10-05 13:15 - 000107752 _____ () C:\Program Files\Intel\Intel(R) Online Connect Access\libglog.dll 2016-10-05 13:15 - 2016-10-05 13:15 - 000412904 _____ () C:\Program Files\Intel\Intel(R) Online Connect Access\JsonCpp.dll 2017-10-31 03:27 - 2018-03-14 15:05 - 001267648 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-11-02 03:24 - 2018-02-22 20:26 - 000076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2016-10-04 18:09 - 2016-10-04 18:09 - 000253664 _____ () C:\Program Files\Intel\Intel(R) Online Connect\CSLibWrapper.dll 2017-09-29 15:41 - 2017-09-29 15:41 - 000184432 _____ () C:\Windows\SYSTEM32\inputhost.dll 2017-10-31 03:24 - 2016-06-14 17:35 - 000187392 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\D3D11FontDraw.dll 2018-03-15 14:34 - 2018-02-22 02:26 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2018-03-15 14:34 - 2018-02-22 02:21 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-04-25 14:48 - 2018-04-25 14:48 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-04-25 14:48 - 2018-04-25 14:48 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-04-25 14:48 - 2018-04-25 14:48 - 022320128 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-04-25 14:48 - 2018-04-25 14:48 - 002603008 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\skypert.dll 2018-04-25 14:48 - 2018-04-25 14:48 - 000657408 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 000908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2017-10-20 05:29 - 2017-10-20 05:29 - 001096824 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-07 02:07 - 2015-03-07 02:07 - 000060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2017-10-20 05:29 - 2017-10-20 05:29 - 000241784 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2017-10-20 05:02 - 2017-10-20 05:02 - 000077824 _____ () C:\Program Files\Logitech Gaming Software\LAClient\zlib.dll 2017-10-20 05:02 - 2017-10-20 05:02 - 000144896 _____ () C:\Program Files\Logitech Gaming Software\LAClient\libssh2.dll 2017-07-20 17:03 - 2017-09-07 10:39 - 000073920 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav 2016-10-20 02:28 - 2016-10-20 02:28 - 001243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2017-10-31 03:27 - 2018-03-14 15:05 - 001041344 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-10-31 03:24 - 2016-06-14 17:35 - 000163328 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\D3D11FontDraw.dll 2017-10-31 03:27 - 2018-03-14 15:04 - 081563584 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2017-08-17 17:51 - 2017-08-17 17:51 - 001993184 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll 2018-03-28 20:15 - 2018-03-14 15:04 - 002478016 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\swiftshader\libglesv2.dll 2018-03-28 20:15 - 2018-03-14 15:04 - 000125376 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\swiftshader\libegl.dll 2016-09-29 17:11 - 2016-09-29 17:11 - 000042728 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32api.pyd 2016-09-29 17:10 - 2016-09-29 17:10 - 000060648 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\pywintypes27.dll 2016-09-29 17:10 - 2016-09-29 17:10 - 000126696 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\pythoncom27.dll 2016-09-29 17:11 - 2016-09-29 17:11 - 000023272 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\_multiprocessing.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000045800 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\_ctypes.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000026856 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32service.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000023784 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\servicemanager.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000030440 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\_socket.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000444136 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\_ssl.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000287976 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\_hashlib.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000018152 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\select.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000021224 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32pipe.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000045800 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32file.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000018664 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32event.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000371432 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\_bsddb.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000025320 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32process.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000021224 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32ts.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000019688 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32profile.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000043752 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32security.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000025832 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\win32inet.pyd 2016-09-29 17:11 - 2016-09-29 17:11 - 000190696 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\unicodedata.pyd 2016-09-29 17:10 - 2016-09-29 17:10 - 000023272 _____ () C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\EnvironmentID.dll ==================== Alternate Data Streams (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.) ==================== Mode sans échec (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.) ==================== Association (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.) HKU\S-1-5-21-484587128-3933791518-1798071367-1001\Software\Classes\regfile: regedit.exe "%1" <==== ATTENTION ==================== Internet Explorer sites de confiance/sensibles =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.) IE trusted site: HKU\.DEFAULT\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-484587128-3933791518-1798071367-1001\...\localhost -> localhost ==================== Hosts contenu: =============================== (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2017-09-29 15:46 - 2017-09-29 15:44 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Autres zones ============================ (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-484587128-3933791518-1798071367-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ivanv\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\{2cd6356c-574b-4a2a-afd0-85505ae3569e}.jpg DNS Servers: 156.154.70.25 - 156.154.71.25 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == HKLM\...\StartupApproved\Run32: => "Live Update" HKLM\...\StartupApproved\Run32: => "USB_Speed_Up" ==================== RèglesPare-feu (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [{1B58A7F2-C190-42E0-9214-566307E2ACF7}] => (Allow) C:\Program Files\DriversCloud.com\DriversCloud.exe FirewallRules: [{F6FE0DF8-042C-4376-BD81-5502B09A0F8C}] => (Allow) C:\Program Files\DriversCloud.com\DriversCloud.exe FirewallRules: [{313E44F4-80D9-4915-896F-68AF74CDE5E9}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{AB31D08E-2198-433E-B547-64D396FD39E8}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{3259FB6C-B572-4DBE-83C7-90506CCD3EC9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{AEAB1A9B-49A9-44B7-8FA7-3EF70957CBE0}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{938BF356-3FAA-4F06-9C6A-6B33EB6F2582}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{A211FC48-F151-40A8-A497-FB978ED3A1B4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{796461B6-D1D1-49F9-B2D7-2FD9FDA71FE9}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed Unity\ACU.exe FirewallRules: [{47E372CE-961D-4FEB-83AC-3C2C92378924}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed Unity\ACU.exe FirewallRules: [{E913CD27-1168-4349-98A3-8691EC6F07A2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher 3\bin\x64\witcher3.exe FirewallRules: [{8716C760-C69C-4196-9CFF-CFF9AC20A758}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Witcher 3\bin\x64\witcher3.exe FirewallRules: [{E4A165DC-1FEC-4F39-9B34-CF3096C3CFE9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{076B6D57-406A-4E9A-9FAC-D0DF23C37F12}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [TCP Query User{6585888C-E4EF-431B-8701-6B77E7F88C47}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [UDP Query User{0D94F11C-024C-4033-ABF8-AD363E04CC57}C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [TCP Query User{4D46C9D8-F3AC-4BBD-8534-A5B821FFE7A6}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{4F479114-F81D-4D2A-99F4-91FB1ED6B094}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{BB92D5C7-2224-4D88-B079-37A7A9B46EB6}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{8FC74EAE-8C3A-463B-92F2-5C627515E7FF}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe FirewallRules: [{0294FBC6-66E3-4085-9304-3E08403BC116}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{9CD526CA-AC49-43B5-B90E-6783CB3F7A5C}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{4A7B325D-6EA4-4663-9FE0-F3E76FA557F5}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe FirewallRules: [{1161480A-C810-4B3E-BEDF-2277351E13B3}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher.exe FirewallRules: [{C1D3C55F-B63F-43ED-9138-BC83FC9DCF45}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe FirewallRules: [{6E5456AB-F0D6-4790-8D44-A518CB7E85EE}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\BFLauncher_x86.exe FirewallRules: [TCP Query User{55FF3739-8B6E-4479-9C3E-D3C68A3156C6}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe FirewallRules: [UDP Query User{F7C387FA-929A-41D6-8806-2ECE147D43C4}C:\program files (x86)\origin games\battlefield 4\bf4.exe] => (Allow) C:\program files (x86)\origin games\battlefield 4\bf4.exe FirewallRules: [{71447DC0-5E35-4BC9-AF05-FFCEE25C52F4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{A9ED81D5-4FDA-4E1E-9291-3003707127B5}C:\users\ivanv\appdata\local\warthunder\launcher.exe] => (Allow) C:\users\ivanv\appdata\local\warthunder\launcher.exe FirewallRules: [UDP Query User{FEF19B81-B040-4041-A132-0EE68459FC4B}C:\users\ivanv\appdata\local\warthunder\launcher.exe] => (Allow) C:\users\ivanv\appdata\local\warthunder\launcher.exe FirewallRules: [TCP Query User{CFE45ED5-8530-46A4-8440-AC86C4E35A88}C:\users\ivanv\appdata\local\warthunder\win64\aces.exe] => (Allow) C:\users\ivanv\appdata\local\warthunder\win64\aces.exe FirewallRules: [UDP Query User{5AF6954D-87DD-4F32-9F9B-F8BE68635420}C:\users\ivanv\appdata\local\warthunder\win64\aces.exe] => (Allow) C:\users\ivanv\appdata\local\warthunder\win64\aces.exe FirewallRules: [{212FA43E-6F40-4E01-B435-F1A05BD32B61}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto IV\GTAIV\LaunchGTAIV.exe FirewallRules: [{1E970E79-C365-4603-8BC7-5FFAFEA6145A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto IV\GTAIV\LaunchGTAIV.exe FirewallRules: [TCP Query User{CD9BBF46-9C60-4233-9821-EE3E74B13F37}C:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe FirewallRules: [UDP Query User{089631F3-0759-4DCA-9E65-7DC3D54D3989}C:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe FirewallRules: [TCP Query User{F1F7E3E8-B2C9-4192-8182-1F0DED9BC450}C:\program files (x86)\origin games\star wars battlefront\starwarsbattlefront.exe] => (Allow) C:\program files (x86)\origin games\star wars battlefront\starwarsbattlefront.exe FirewallRules: [UDP Query User{6AB55481-6C02-4339-AE38-C7CD32CCB6EF}C:\program files (x86)\origin games\star wars battlefront\starwarsbattlefront.exe] => (Allow) C:\program files (x86)\origin games\star wars battlefront\starwarsbattlefront.exe FirewallRules: [{F915B245-30EC-4965-8FDE-540167910995}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Lego Star Wars Saga\LEGOStarWarsSaga.exe FirewallRules: [{B6BB9CEE-92FD-4324-9FA8-5D8EB435F2B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Lego Star Wars Saga\LEGOStarWarsSaga.exe FirewallRules: [TCP Query User{F1A45B25-1A00-41C2-BADC-0536678D4AE5}C:\program files\cloud imperium games\patcher\cigpatcher.exe] => (Allow) C:\program files\cloud imperium games\patcher\cigpatcher.exe FirewallRules: [UDP Query User{5DB73BC1-8B15-4BE7-A6E8-A8399C1566FD}C:\program files\cloud imperium games\patcher\cigpatcher.exe] => (Allow) C:\program files\cloud imperium games\patcher\cigpatcher.exe FirewallRules: [TCP Query User{B9484113-7A57-400E-B007-77FC2225070B}C:\program files\cloud imperium games\starcitizen\public\bin64\starcitizen.exe] => (Allow) C:\program files\cloud imperium games\starcitizen\public\bin64\starcitizen.exe FirewallRules: [UDP Query User{550FAF25-9769-4AFE-A24C-40F9C816FB25}C:\program files\cloud imperium games\starcitizen\public\bin64\starcitizen.exe] => (Allow) C:\program files\cloud imperium games\starcitizen\public\bin64\starcitizen.exe FirewallRules: [TCP Query User{230DB853-3AB6-41BF-B2B3-766B16B8B505}C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe FirewallRules: [UDP Query User{D31425A1-8BDA-4CF8-84D7-8721B7BD7C9F}C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\pubg_test\tslgame\binaries\win64\tslgame.exe FirewallRules: [TCP Query User{28ADA6B6-D20C-4786-B466-207BAF5B8717}C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe] => (Allow) C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe FirewallRules: [UDP Query User{905F6709-003E-44F7-8A51-09EF2CE26B14}C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe] => (Allow) C:\program files\roberts space industries\starcitizen\live\bin64\starcitizen.exe FirewallRules: [{7D0507FB-CB3A-4B12-A796-CDB783BBF242}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops\BlackOps.exe FirewallRules: [{BC95E38A-C95B-425D-A2AC-7B1812D80129}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops\BlackOps.exe FirewallRules: [{73D58F9F-D872-446D-80A8-192A7D0297E3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops\BlackOpsMP.exe FirewallRules: [{FC20A27E-FA7C-493D-AC29-ECB47E51FB68}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops\BlackOpsMP.exe FirewallRules: [{0D23158C-AFCE-4999-8A11-588631232B6D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Napoleon Total War\Napoleon.exe FirewallRules: [{4514AF5E-162C-48A8-A69F-EF236DF55DF7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Napoleon Total War\Napoleon.exe FirewallRules: [{1FB0FB9B-E227-4D29-ACCB-CF5FF75EFE2D}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{CB84022C-2EAC-4C60-8D0C-4A92E8C48F8D}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{05F57907-4413-4381-BB5C-86FDD1D54F5C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{4BF0B0C0-29C0-4BEA-8736-4D4E457DFFDF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{EE96B395-7D7D-4D97-9ABB-67FE06F69A50}] => (Allow) C:\Program Files (x86)\Origin Games\BFH\BFHWebHelper.exe FirewallRules: [{FDDADCFD-A4BD-4DAC-BD60-BEAE400A31DA}] => (Allow) C:\Program Files (x86)\Origin Games\BFH\BFHWebHelper.exe FirewallRules: [TCP Query User{40651A12-73CC-4D06-81BD-8CC31B0CC201}C:\program files (x86)\origin games\bfh\bfh.exe] => (Allow) C:\program files (x86)\origin games\bfh\bfh.exe FirewallRules: [UDP Query User{4D53A161-C437-4ACA-B3B5-BABC4C6EF04D}C:\program files (x86)\origin games\bfh\bfh.exe] => (Allow) C:\program files (x86)\origin games\bfh\bfh.exe FirewallRules: [TCP Query User{E509DFE2-76C6-4C1D-9095-0A8AE35C02F9}C:\users\ivanv\appdata\local\crossout\launcher.exe] => (Allow) C:\users\ivanv\appdata\local\crossout\launcher.exe FirewallRules: [UDP Query User{81CC24BE-178D-4062-8DB5-356C09A2902D}C:\users\ivanv\appdata\local\crossout\launcher.exe] => (Allow) C:\users\ivanv\appdata\local\crossout\launcher.exe FirewallRules: [{7D16E944-330F-40C3-9DA2-31DB78BB45E5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{EF7EA080-5DCD-43F5-B327-2BBA83F3309F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{83198D90-FD09-43F8-9326-689B69A5AE32}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{5E34ED21-71FE-4E8D-8CBF-88F76FFFE232}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{F2F8BF03-0A40-42B7-A9D1-373CBCA9BCAC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{22D0E1E4-4E4B-48E4-9509-92496E682675}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{A92C6C58-F58D-4179-B079-B5D33957FB2E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe FirewallRules: [{4589AE4A-813D-45F0-8D6A-B50579C55770}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe FirewallRules: [{091F44E0-1892-4EE0-B6E2-553DC5B23D25}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe FirewallRules: [{B422D2F4-000A-450F-951F-C501B1730D44}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe FirewallRules: [{55D3BBDE-9E4A-425B-A113-30D9380FDB42}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe FirewallRules: [{0DFAF4A2-B37C-4ABE-8D6B-D7D7F8BFBF36}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe FirewallRules: [{64E0419E-E9F9-4B25-85D3-4A96E44F6675}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{36564E94-F960-4A47-B9B4-8DA91C1DBEE5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{CD68EDE2-3976-4EBC-9501-DBF996B42661}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{33FE3E75-2F56-420A-9E2B-0F8EB1B2B40E}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 1\bf1Trial.exe FirewallRules: [{6AD5AEA5-8CFB-49BD-8B1C-8AA69CE72865}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 1\bf1.exe FirewallRules: [{B84761D4-5A72-4BFF-AE49-EB3998E97DFF}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 1\bf1.exe ==================== Points de restauration ========================= 15-05-2018 17:25:55 Windows Update ==================== Éléments en erreur du Gestionnaire de périphériques ============= Name: Souris Microsoft PS/2 Description: Souris Microsoft PS/2 Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Erreurs du Journal des événements: ========================= Erreurs Application: ================== Error: (05/16/2018 12:45:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante MSIDDRService.exe, version : 3.0.0.10, horodatage : 0x5844e133 Nom du module défaillant : MSIDDRService.exe, version : 3.0.0.10, horodatage : 0x5844e133 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000261df ID du processus défaillant : 0x5ec Heure de début de l’application défaillante : 0x01d3ed02f5f8456d Chemin d’accès de l’application défaillante : C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe Chemin d’accès du module défaillant: C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe ID de rapport : 87d40f61-07a2-474c-a53a-c9cf5e930d7a Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (05/16/2018 12:45:10 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante MSI_LiveUpdate_Service.exe, version : 1.0.0.51, horodatage : 0x59c2255c Nom du module défaillant : NDA.dll_unloaded, version : 1.0.0.15, horodatage : 0x581aa4cc Code d’exception : 0xc0000005 Décalage d’erreur : 0x000f650e ID du processus défaillant : 0xc58 Heure de début de l’application défaillante : 0x01d3ec70e772c04e Chemin d’accès de l’application défaillante : C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe Chemin d’accès du module défaillant: NDA.dll ID de rapport : ec02ea0f-b1ad-4934-9881-abcbcdde5fe1 Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (05/15/2018 08:23:17 PM) (Source: IntelDalJhi) (EventID: 4) (User: ) Description: Intel(R) Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid. Error: (05/15/2018 08:23:17 PM) (Source: IntelDalJhi) (EventID: 4) (User: ) Description: Intel(R) Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid. Error: (05/15/2018 07:19:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante MSIDDRService.exe, version : 3.0.0.10, horodatage : 0x5844e133 Nom du module défaillant : MSIDDRService.exe, version : 3.0.0.10, horodatage : 0x5844e133 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000261df ID du processus défaillant : 0xc3c Heure de début de l’application défaillante : 0x01d3ec70e770956b Chemin d’accès de l’application défaillante : C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe Chemin d’accès du module défaillant: C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe ID de rapport : 100763d4-9602-4de3-9eaf-6daa4a33fb51 Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (05/15/2018 07:15:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante MSIDDRService.exe, version : 3.0.0.10, horodatage : 0x5844e133 Nom du module défaillant : MSIDDRService.exe, version : 3.0.0.10, horodatage : 0x5844e133 Code d’exception : 0xc0000005 Décalage d’erreur : 0x000261df ID du processus défaillant : 0xc18 Heure de début de l’application défaillante : 0x01d3ec705936e697 Chemin d’accès de l’application défaillante : C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe Chemin d’accès du module défaillant: C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe ID de rapport : 878b169a-66e0-4195-b852-11fc6edc21ea Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (05/15/2018 06:49:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante backgroundTaskHost.exe, version : 10.0.16299.15, horodatage : 0x290d9f78 Nom du module défaillant : twinapi.appcore.dll, version : 10.0.16299.19, horodatage : 0x63553d36 Code d’exception : 0xc0000409 Décalage d’erreur : 0x000000000007335b ID du processus défaillant : 0x1e10 Heure de début de l’application défaillante : 0x01d3ec6cc1aa8e1d Chemin d’accès de l’application défaillante : C:\Windows\system32\backgroundTaskHost.exe Chemin d’accès du module défaillant: C:\Windows\System32\twinapi.appcore.dll ID de rapport : f60f7d4c-84bf-48a2-9565-28b5a3e3dce4 Nom complet du package défaillant : Microsoft.Windows.Cortana_1.9.6.16299_neutral_neutral_cw5n1h2txyewy ID de l’application relative au package défaillant : CortanaUI Error: (05/15/2018 06:18:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante linker.exe, version : 1.0.0.1, horodatage : 0x5afb04fb Nom du module défaillant : KERNELBASE.dll, version : 10.0.16299.402, horodatage : 0x81d25214 Code d’exception : 0xe0434f4d Décalage d’erreur : 0x00103f12 ID du processus défaillant : 0x2d58 Heure de début de l’application défaillante : 0x01d3ec6853097369 Chemin d’accès de l’application défaillante : C:\Users\ivanv\AppData\Local\Temp\whex2p0apdg\linker.exe Chemin d’accès du module défaillant: C:\Windows\System32\KERNELBASE.dll ID de rapport : 2a28a5ba-b4b7-4e91-b3e7-e6ac7d38fe8f Nom complet du package défaillant : ID de l’application relative au package défaillant : Erreurs système: ============= Error: (05/16/2018 12:45:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Le service MSI Command Center DDR Service s’est terminé de façon inattendue pour la 2ème fois. Error: (05/16/2018 12:45:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Le service MSI Live Update Service s’est terminé de façon inattendue pour la 1ème fois. Error: (05/16/2018 12:45:11 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} et l’APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (05/16/2018 12:45:11 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} et l’APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (05/16/2018 12:45:11 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} et l’APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (05/16/2018 12:45:11 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} et l’APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} au SID AUTORITE NT\SERVICE LOCAL de l’utilisateur (S-1-5-19) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (05/15/2018 08:23:15 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-SH9VGUE) Description: Le serveur microsoft.windowscommunicationsapps_17.9226.21485.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (05/15/2018 07:21:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Le service Service antivirus Windows Defender n’a pas pu démarrer en raison de l’erreur : Windows ne peut pas vérifier la signature numérique de ce fichier. Il est possible qu’une modification matérielle ou logicielle récente ait installé un fichier endommagé ou dont la signature est incorrecte, ou qu’il s’agisse d’un logiciel malveillant provenant d’une source inconnue. CodeIntegrity: =================================== Date: 2018-05-15 20:21:45.028 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\cssguard64.dll that did not meet the Windows signing level requirements. Date: 2018-05-15 20:21:45.020 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-05-15 20:16:37.076 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\cssguard64.dll that did not meet the Windows signing level requirements. Date: 2018-05-15 20:16:37.070 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-05-15 20:10:20.081 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\cssguard64.dll that did not meet the Windows signing level requirements. Date: 2018-05-15 20:10:20.078 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-05-15 20:06:00.739 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\dllhost.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\cssguard64.dll that did not meet the Microsoft signing level requirements. Date: 2018-05-15 20:06:00.733 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\guard64.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Infos Mémoire =========================== Processeur: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz Pourcentage de mémoire utilisée: 44% Mémoire physique - RAM - totale: 8155.03 MB Mémoire physique - RAM - disponible: 4488.21 MB Mémoire virtuelle totale: 16859.03 MB Mémoire virtuelle disponible: 12416.53 MB ==================== Lecteurs ================================ Drive b: (RAMDisk) (Fixed) (Total:0.25 GB) (Free:0.25 GB) FAT Drive c: () (Fixed) (Total:930.91 GB) (Free:372.52 GB) NTFS \\?\Volume{8bef7235-6e5b-4f6a-bbca-48680ed715d0}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Table des partitions ================== ======================================================== Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== Fin de Addition.txt ============================