Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 06.06.2018 01 Exécuté par julie (19-06-2018 16:06:41) Exécuté depuis C:\Users\julie\Desktop Windows 10 Pro Version 1803 17134.112 (X64) (2018-05-20 12:13:09) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= Administrateur (S-1-5-21-2635931543-1816589094-1858053538-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2635931543-1816589094-1858053538-503 - Limited - Disabled) Invité (S-1-5-21-2635931543-1816589094-1858053538-501 - Limited - Disabled) julie (S-1-5-21-2635931543-1816589094-1858053538-1001 - Administrator - Enabled) => C:\Users\julie WDAGUtilityAccount (S-1-5-21-2635931543-1816589094-1858053538-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.113 - Adobe Systems Incorporated) APOInstallerMSISetup (HKLM\...\{6D8108E5-FBDD-4547-9C04-B052336E4046}) (Version: 1.0.19 - Nahimic) Hidden AudioDeviceFXPluginSampleUIMSISetup (HKLM\...\{A6A8AE0B-30CC-4641-8BE4-8A70E44A2448}) (Version: 1.0.1901 - Nahimic) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.43 - Piriform) cFosSpeed v10.25 (HKLM\...\cFosSpeed) (Version: 10.25 - cFos Software GmbH, Bonn) Cheat Engine 6.7 (HKLM-x32\...\Cheat Engine 6.7_is1) (Version: - Cheat Engine) Discord (HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\...\Discord) (Version: 0.0.301 - Discord Inc.) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 398.11 - NVIDIA Corporation) Hidden dwdinst (HKLM-x32\...\{F4BA8483-1DF9-41B9-9B00-229B7DECA061}) (Version: 1.0.0.0 - HanWIS GmbH) EndpointMonitoring Install MSISetup (HKLM\...\{F1F90F23-6FFC-481E-B72A-B2D51C6DA257}) (Version: 1.0.1901 - Nahimic) Hidden Epic Games Launcher (HKLM-x32\...\{A7D43B07-A0E2-4DB9-9843-01EA269F6F67}) (Version: 1.1.147.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden FACEIT (HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\...\FACEITApp) (Version: 0.17.3 - FACEIT Ltd.) Glary Utilities 5.99 (HKLM-x32\...\Glary Utilities 5) (Version: 5.99.0.121 - Glarysoft Ltd) Google Earth Pro (HKLM\...\{D9EF644E-2FAE-493B-8180-5617CC774C4F}) (Version: 7.3.1.4507 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1058 - Intel Corporation) Intel(R) Network Connections 22.9.16.0 (HKLM\...\PROSetDX) (Version: 22.9.16.0 - Intel) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.9.0.1015 - Intel Corporation) Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.48.139.0 - Intel Corporation) Hidden Intel(R) Trusted Connect Services Client (HKLM-x32\...\{fd62de85-bda9-4280-a95b-fa2f86e0dc58}) (Version: 1.48.139.0 - Intel Corporation) Hidden Intel® Software Guard Extensions Platform Software (HKLM\...\{2DF17C75-9627-4213-8612-17955E92F782}) (Version: 1.6.101.32869 - Intel Corporation) Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Logiciel pour périphérique à chipset Intel® (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden Logitech - Assistant pour jeux vidéo 9.00 (HKLM\...\Logitech Gaming Software) (Version: 9.00.42 - Logitech Inc.) Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech) Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes) Microsoft OneDrive (HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\...\OneDriveSetup.exe) (Version: 18.065.0329.0002 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation) Mises à jour NVIDIA 31.2.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.2.0.0 - NVIDIA Corporation) Hidden Mozilla Firefox 60.0.2 (x64 fr) (HKLM\...\Mozilla Firefox 60.0.2 (x64 fr)) (Version: 60.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.2 - Mozilla) MSI Afterburner 4.4.2 (HKLM-x32\...\Afterburner) (Version: 4.4.2 - MSI Co., LTD) MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 3.0.0.65 - MSI) MSI DPC Latency Tuner (HKLM-x32\...\{1AAC56F3-3F60-47DB-BE6B-088F36ADFDC5}_is1) (Version: 1.0.0.30 - MSI) MSI Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.1.13 - MSI) MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.2.0.74 - MSI) MSI Gaming Lan Manager (HKLM-x32\...\{3318282C-D4D6-4B29-BBD5-95FC34B54FF0}_is1) (Version: 1.0.0.66 - MSI) MSI Kombustor 3.5.0 (HKLM\...\{9598DA62-2AE8-426D-9C86-BEA96AC6721E}_is1) (Version: - MSI Co., LTD) MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.2.0.35 - MSI) MSI RAMDisk (HKLM-x32\...\{F29CF050-7278-4CDB-9EF8-2DC6DAA87453}}_is1) (Version: 1.0.0.31 - MSI) MSI Smart Tool (HKLM-x32\...\{DDCCA038-DAB1-4D09-B85C-848020AA75D6}}_is1) (Version: 1.0.0.33 - MSI) MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.3.0.22 - MSI) MSI X Boost (HKLM-x32\...\{515143BB-7A11-4D85-B941-D520AAAA099C}_is1) (Version: 1.0.0.41 - MSI) MSIRegister (HKLM-x32\...\{80B995A4-3A86-4690-98A6-563F1A788835}_is1) (Version: 2.0.0.13 - MSI) Nahimic VR (HKLM-x32\...\{3d84610f-4cfb-4165-aa15-bb859bd0f0e3}) (Version: 1.0.19 - Nahimic) NineEarsSettings Install Configurator (HKLM\...\{A909659E-FC98-4D8F-AC40-8C5344C86F7A}) (Version: 1.0.1901 - Nahimic) Hidden NVIDIA GeForce Experience 3.14.0.139 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.14.0.139 - NVIDIA Corporation) NVIDIA Logiciel système PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) NVIDIA Pilote 3D Vision 398.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 398.11 - NVIDIA Corporation) NVIDIA Pilote audio HD : 1.3.37.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.4 - NVIDIA Corporation) NVIDIA Pilote du contrôleur 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) NVIDIA Pilote graphique 398.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 398.11 - NVIDIA Corporation) osu! (HKLM-x32\...\{3709d731-ebaf-4262-96e0-3573123d1c26}) (Version: latest - ppy Pty Ltd) Panneau de configuration NVIDIA 398.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 398.11 - NVIDIA Corporation) Hidden PeerBlock 1.2 (r693) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC) ProductDaemon Install Setup (HKLM\...\{32D62D40-F8F6-408E-8F8C-6A6593E3ACE9}) (Version: 1.0.1901 - Nahimic) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8412 - Realtek Semiconductor Corp.) RivaTuner Statistics Server 7.0.2 (HKLM-x32\...\RTSS) (Version: 7.0.2 - Unwinder) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.8 - Rockstar Games) SSAudioDaemon Install MSISetup (HKLM\...\{F77EA0C2-B0EB-47C7-990D-EACA981D75E8}) (Version: 1.0.19 - Nahimic) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.1.9 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\...\TeamSpeak 3 Client) (Version: 3.1.8 - TeamSpeak Systems GmbH) Tom Clancy's Rainbow Six Siege (HKLM-x32\...\Uplay Install 635) (Version: - Ubisoft Montreal) Uplay (HKLM-x32\...\Uplay) (Version: 54.0 - Ubisoft) VLC media player (HKLM\...\VLC media player) (Version: 3.0.3 - VideoLAN) ==================== Personnalisé CLSID (Avec liste blanche): ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => D:\Programe Files 2\Glary Utilities 5\x64\ContextHandler.dll [2018-03-02] (Glarysoft Ltd) ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => D:\Programe Files 2\Glary Utilities 5\x64\ContextHandler.dll [2018-03-02] (Glarysoft Ltd) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => D:\Programe Files 2\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-06-01] (NVIDIA Corporation) ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => D:\Programe Files 2\Glary Utilities 5\x64\ContextHandler.dll [2018-03-02] (Glarysoft Ltd) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => D:\Programe Files 2\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ==================== Tâches planifiées (Avec liste blanche) ============= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {124CEB10-D385-429D-A551-0E8B74B20543} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-05-20] (NVIDIA Corporation) Task: {268A4894-5977-4FA4-913F-BF48814881E6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-05-24] (Piriform Ltd) Task: {2F2BC904-F800-4AC7-99CE-4B0569187086} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-05-20] (NVIDIA Corporation) Task: {389BFC92-D145-4835-935A-483728DD851D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MpCmdRun.exe [2018-05-30] (Microsoft Corporation) Task: {3B199E89-F74B-4806-920A-E6D596CAB7D6} - System32\Tasks\MSIGH_Host => C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey.exe [2018-03-22] (Micro-Star INT'L CO., LTD.) Task: {41D8D894-2DC1-493C-AEB5-DA1324F6F282} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-05-20] (NVIDIA Corporation) Task: {4BF47679-A0BB-4791-9AF6-1B29D67ABE1C} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [2015-08-18] (MSI) Task: {53E56450-4EDB-4379-8962-85C6E4A7D6DE} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe Task: {59801A44-5103-44A2-8C6D-E56FC8E68A76} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-08] (Adobe Systems Incorporated) Task: {5C6AD6D5-E1DB-4E93-AF0B-2FBD24A532F2} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-05-20] (NVIDIA Corporation) Task: {60EC7CCB-E8B2-45D8-8AE9-811EE4F74746} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe Task: {640BB800-1C0E-4CBE-B3A1-311B56A7BF0C} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-05-20] (NVIDIA Corporation) Task: {64625225-E063-4B5D-BD07-9BA4C5BBA955} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-05-17] (Google Inc.) Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] () Task: {6A0A3760-6BAD-44C8-ABC6-B07CAD3899A3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MpCmdRun.exe [2018-05-30] (Microsoft Corporation) Task: {75413999-5AC7-4C22-A4F0-E30AC199D201} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-05-20] (NVIDIA Corporation) Task: {79700E44-2B31-475C-ABD9-D1477ACEBCFB} - System32\Tasks\NahimicVRSvc64Run => C:\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRSvc64.exe [2018-02-05] (A-Volute) Task: {8A9A03B4-FB29-4C9A-A732-E76F7104DDD3} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\IntelPTTEKRecertification.exe [2017-11-08] (Intel(R) Corporation) Task: {9951BFC6-AFA8-4C7F-B2FE-5ACBDA181ACC} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-05-20] (NVIDIA Corporation) Task: {9ECCDF2C-CA55-4F9E-B075-9050DB9BA324} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MpCmdRun.exe [2018-05-30] (Microsoft Corporation) Task: {A8AD3F11-F475-4FC7-ABF4-7CDA4466C6F4} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-05-20] (NVIDIA Corporation) Task: {AA7F1F92-3F08-406E-BB45-07DBEEB90C0D} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe Task: {BA7BADF0-4E05-4F78-AFE5-E3C2C5855F89} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-05-20] (NVIDIA Corporation) Task: {C4468DF6-BA1F-4B1B-9514-36B476B2170E} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-05-20] (NVIDIA Corporation) Task: {C93C4224-70A6-4774-8C76-98C37397407E} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_113_Plugin.exe [2018-06-08] (Adobe Systems Incorporated) Task: {D83EEEC4-85F4-4054-AE8A-0C8CD1B9BE3A} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-05-24] (Piriform Ltd) Task: {DE365EB5-5D81-4980-934C-F39B9D30AE5F} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-05-20] (NVIDIA Corporation) Task: {E096C891-01BA-409E-9A54-822404300ABF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-05-17] (Google Inc.) Task: {E100F611-42AF-4894-ACB8-C96B3441003A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MpCmdRun.exe [2018-05-30] (Microsoft Corporation) Task: {E3462572-0409-4EDE-97C1-E8F3B6DBD199} - System32\Tasks\GlaryInitialize 5 => D:\Programe Files 2\Glary Utilities 5\Initialize.exe [2018-06-04] (Glarysoft Ltd) Task: {F4B4B3AA-14C6-4074-A158-4E0368812D65} - System32\Tasks\NahimicVRSvc32Run => C:\Program Files\Nahimic\Nahimic VR\Foundation\NahimicVRSvc32.exe [2018-02-05] (A-Volute) Task: {FEAE68A5-098A-42BA-A381-DE342A67D583} - System32\Tasks\Driver Booster SkipUAC (julie) => C:\Program Files (x86)\IObit\Driver Booster\5.3.0\DriverBooster.exe (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe Task: C:\WINDOWS\Tasks\Intel PTT EK Recertification.job => C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\IntelPTTEKRecertification.exe Task: C:\WINDOWS\Tasks\MSISW_Host.job => C:\WINDOWS\SysWOW64\muachost.exe ==================== Raccourcis & WMI ======================== (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) ==================== Modules chargés (Avec liste blanche) ============== 2018-04-04 00:06 - 2018-06-01 10:39 - 000137664 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2018-05-23 13:30 - 2018-05-20 19:36 - 001315296 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-06-09 02:02 - 2018-06-09 02:02 - 000023040 _____ () C:\WINDOWS\System32\hnsproxy.dll 2018-04-12 01:33 - 2018-04-12 01:33 - 000031744 _____ () C:\WINDOWS\system32\HvSocket.dll 2018-02-05 18:10 - 2018-02-05 18:10 - 000222256 _____ () C:\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll 2018-06-12 21:51 - 2018-06-08 10:56 - 002185216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-05-26 04:16 - 2018-05-26 04:16 - 027118080 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\Video.UI.exe 2018-05-23 13:56 - 2018-05-23 13:57 - 000306176 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\SharedUI.dll 2018-05-23 13:56 - 2018-05-23 13:56 - 006748672 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\EntCommon.dll 2018-03-30 20:08 - 2018-03-30 20:08 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-05-23 13:56 - 2018-05-23 13:56 - 009358848 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\EntPlat.dll 2018-03-30 22:14 - 2018-03-30 22:14 - 098275328 _____ () C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll 2018-03-30 22:14 - 2018-03-30 22:14 - 003922432 _____ () C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll 2018-03-30 22:14 - 2018-03-30 22:14 - 000092672 _____ () C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll 2018-05-23 13:30 - 2018-05-20 19:36 - 095437792 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2018-05-23 13:30 - 2018-05-20 19:36 - 003029472 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\swiftshader\libglesv2.dll 2018-05-23 13:30 - 2018-05-20 19:36 - 000149984 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\swiftshader\libegl.dll 2018-06-19 15:04 - 2018-06-19 15:02 - 003140480 _____ () C:\Users\julie\Desktop\ZHPDiag3.exe 2018-06-17 07:18 - 2005-07-18 13:43 - 000160256 _____ () C:\Program Files (x86)\MSI\Live Update\unrar.dll 2018-02-05 18:07 - 2018-02-05 18:07 - 000187952 _____ () C:\Program Files\Nahimic\Nahimic VR\Foundation\NahimicVRDevProps.dll 2018-06-17 07:32 - 2017-08-02 14:48 - 000237568 _____ () C:\Program Files (x86)\MSI\Gaming APP\LEDControl.dll 2018-05-23 13:30 - 2018-05-20 19:36 - 001033184 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-02-05 18:12 - 2018-02-05 18:12 - 000172544 _____ () C:\Program Files\Nahimic\Nahimic VR\AnalogDriver\EndpointMonitoring.dll 2018-05-01 20:29 - 2018-04-30 23:01 - 001891672 _____ () C:\Users\julie\AppData\Local\Discord\app-0.0.301\ffmpeg.dll 2018-05-02 00:44 - 2018-05-02 00:44 - 001910104 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_spellcheck\node_modules\cld\build\Release\cld.node 2018-05-02 00:44 - 2018-05-02 00:44 - 000422744 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_spellcheck\node_modules\spellchecker\build\Release\spellchecker.node 2018-05-02 00:44 - 2018-05-02 00:44 - 000145240 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_spellcheck\node_modules\keyboard-layout\build\Release\keyboard-layout-manager.node 2018-05-02 00:44 - 2018-05-23 03:01 - 009820504 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_voice\discord_voice.node 2018-05-02 00:44 - 2018-05-02 00:44 - 001530712 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_utils\discord_utils.node 2018-05-02 00:44 - 2018-05-02 00:44 - 000512856 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_erlpack\discord_erlpack.node 2018-05-02 00:44 - 2018-05-03 10:23 - 001578840 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_game_utils\discord_game_utils.node 2018-05-02 00:44 - 2018-05-02 00:44 - 002722648 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_rpc\discord_rpc.node 2018-05-02 00:44 - 2018-05-02 00:44 - 002760536 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_contact_import\discord_contact_import.node 2018-05-02 00:44 - 2018-05-02 00:44 - 001249112 _____ () \\?\C:\Users\julie\AppData\Roaming\discord\0.0.301\modules\discord_vigilante\discord_vigilante.node 2018-03-28 17:09 - 2018-03-28 17:09 - 068505088 _____ () C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\libcef.dll ==================== Alternate Data Streams (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.) AlternateDataStreams: C:\Users\Public\AppData:CSM [474] ==================== Mode sans échec (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.) ==================== Association (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.) ==================== Internet Explorer sites de confiance/sensibles =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.) IE trusted site: HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\...\localhost -> localhost ==================== Hosts contenu: =============================== (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2017-09-29 15:46 - 2017-09-29 15:44 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Autres zones ============================ (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == HKLM\...\StartupApproved\Run: => "Launch LCore" HKLM\...\StartupApproved\Run: => "Start WingMan Profiler" HKLM\...\StartupApproved\Run32: => "Live Update" HKLM\...\StartupApproved\Run32: => "MSI Gaming Lan Manager" HKLM\...\StartupApproved\Run32: => "Command Center" HKLM\...\StartupApproved\Run32: => "Fast Boot" HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-2635931543-1816589094-1858053538-1001\...\StartupApproved\Run: => "FACEIT" ==================== RèglesPare-feu (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [{03D8FD50-1DDA-4B10-84D0-123A4EFD13E1}] => (Allow) C:\Program Files (x86)\BlueStacks\HD-Player.exe FirewallRules: [UDP Query User{3304569B-4299-409A-9AFB-1280859FCBBA}D:\programe files 2\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\programe files 2\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [TCP Query User{279C8C32-BAB0-45B3-A17F-0F11786827C8}D:\programe files 2\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\programe files 2\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [{21D8938D-1FD3-4D8B-854A-3B917B41E6D1}] => (Allow) D:\Programe Files 2\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{9DE62954-AF4D-4D27-9907-75A6FF0106FC}] => (Allow) D:\Programe Files 2\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{C28DEB5F-80AC-4A83-A7F1-9D7347672864}] => (Allow) D:\Programe Files 2\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe FirewallRules: [{E2AE5BD4-6968-467E-BBE3-2DA3471DFF2A}] => (Allow) D:\Programe Files 2\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe FirewallRules: [{08E08E93-B766-435A-8121-C91DF862C446}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe FirewallRules: [{0EED871F-F19A-496B-AA34-AA820666C527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe FirewallRules: [{C6598805-8042-4480-ACD7-E7A8E866484C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{E4F5C387-7963-461F-82A2-0A5AC6195B18}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{E2506CD1-1E77-4D94-957F-7924C7C4A45D}] => (Allow) D:\Programe Files 2\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{24A06A1C-79CC-4D98-926C-245C663F985A}] => (Allow) D:\Programe Files 2\steamapps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [UDP Query User{6F7E0F89-DBFF-42C6-B64F-ECA2A24D0E14}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{C9DF8D2B-9DCD-4A46-86C7-9C030D830B82}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{DDF69A83-691C-4FFA-A161-DC5303ECB16A}D:\programe files 2\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\programe files 2\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [TCP Query User{640B71CC-973E-431A-96DB-0758F9AEB1A0}D:\programe files 2\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\programe files 2\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [UDP Query User{B223C7E2-9117-49E3-8711-33A3CD6DCEC5}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [TCP Query User{E6A2EF94-6642-4253-B783-1D074A72D28B}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [UDP Query User{AAB8D262-4828-4A84-B79A-F5DC743696DB}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe FirewallRules: [TCP Query User{AC2BA804-3AFA-42BF-9DD3-D955E1D3A210}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{DE880B96-24D8-499D-A3E6-8BFC1205B9E1}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [TCP Query User{5997F8E4-3D29-49EC-AEFC-FBD62D22B1B6}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{F97136C0-C307-477D-921B-F423BB13B741}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [TCP Query User{3BE2D241-622B-4209-AF30-955A3656484C}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [{33443EAE-4CF3-4172-A592-D84BE5A6B9EA}] => (Allow) D:\Programe Files 2\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{608D2C8A-E9CA-414F-A344-E6348A297439}] => (Allow) D:\Programe Files 2\Tom Clancy's Rainbow Six Siege\RainbowSix.exe FirewallRules: [{75CB8F42-A0FB-4FB1-82B4-5EBBB1655AE2}] => (Allow) D:\Programe Files 2\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe FirewallRules: [{702E97CA-7851-416C-9BF8-F5CD02484B8A}] => (Allow) D:\Programe Files 2\Tom Clancy's Rainbow Six Siege\RainbowSix_BE.exe FirewallRules: [{47F4B3C8-C69E-4C09-9229-065AD4E1970B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{16F15D4D-7326-45A0-A362-55E94DF9BD26}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{1176A868-4EFD-4856-B955-D270ED8877A8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{DB336B7A-E638-44ED-AE28-57BDB7D88EE6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{509C5690-C66D-4A32-9C52-5924B840DF7C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{3BAF55F2-2A09-4F0C-9D6B-EE885AD13C76}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{9510DC47-6210-4BAF-83E5-54BC362AA0E2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{B4587077-53C1-4101-8CDF-BFDE6138A209}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{56A9FCB3-3148-4841-8FAF-86A5E5C09AEE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{3AB38A8A-66ED-4C56-B153-0FF5C3DE13B0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{BD49514A-5CD5-4B48-8E3D-2FD9862E1B00}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0D4E397E-87AF-43F2-A7B0-B51F3E26B130}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{47AF71A2-E699-4962-B8A6-9269B9EF8990}D:\programe files 2\tom clancy's rainbow six siege\rainbowsix.exe] => (Allow) D:\programe files 2\tom clancy's rainbow six siege\rainbowsix.exe FirewallRules: [UDP Query User{CEC17C5B-3E94-4B67-BCE7-368D759D1157}D:\programe files 2\tom clancy's rainbow six siege\rainbowsix.exe] => (Allow) D:\programe files 2\tom clancy's rainbow six siege\rainbowsix.exe FirewallRules: [TCP Query User{C528B687-D225-4C80-927B-C0CACD903E17}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{9511DF02-125E-4D87-8975-873B94924998}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [{DE3A82F5-8006-49EE-9076-2D7EF3681B3E}] => (Allow) D:\Programe Files 2\steamapps\common\DCSWorld\Run.exe FirewallRules: [{B59EBA9F-D114-4994-AC11-13EB23EF7704}] => (Allow) D:\Programe Files 2\steamapps\common\DCSWorld\Run.exe FirewallRules: [{1B90D39C-6474-4CAA-9E93-5D63B6713BC5}] => (Allow) D:\Programe Files 2\steamapps\common\DCSWorld\bin\DCS.exe FirewallRules: [{5166C79D-49C6-4EB3-B0DF-402BCBAFBBDF}] => (Allow) D:\Programe Files 2\steamapps\common\DCSWorld\bin\DCS.exe FirewallRules: [TCP Query User{DA0D1A69-61A4-4C97-9034-0A0821B001A9}D:\programe files 2\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\programe files 2\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [UDP Query User{99365BF5-F4E7-4681-98C7-EB29DD99FF26}D:\programe files 2\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\programe files 2\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [TCP Query User{AFCB27E9-7CEF-429E-88CA-BEBEE53F14B6}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{02D155C2-320A-43A0-BE71-76EC0531844A}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{F06B35FB-BF55-4B73-8A71-D798E0AB3E25}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{167E6C1A-F373-49AE-ABCE-75946D3FCF07}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{86D56D18-3C35-48D6-8F0F-794DC9AA33C2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{DCC0AAFE-90D0-4833-A95C-DB7BC4EFD686}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{FB662F19-A1FB-4D64-A751-640CE35EC016}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{4F075F6D-8C6E-4D74-9528-629D043EC11F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{F47D0861-ED1D-4141-A60C-A03F56929D67}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{5AE5B5C2-AF7B-4293-BD82-53394BC68769}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\Spotify.exe FirewallRules: [{E180E2B9-8D9F-45C0-9D36-589C38455BA5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe FirewallRules: [{0D69C635-BAA3-42ED-8420-F2951F037151}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.82.454.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe FirewallRules: [VIRT-MIGL-In-TCP-NoScope] => (Allow) %systemroot%\system32\vmms.exe FirewallRules: [VIRT-REMOTEDESKTOP-In-TCP-NoScope] => (Allow) %systemroot%\system32\vmms.exe FirewallRules: [{516929AE-8F9F-4D84-AC90-61D98BCE7C8B}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{6C7911C2-A934-4BA3-BCF6-91D0E3D78988}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{7A84AE97-4BE4-433C-AB52-E85A996CB5F6}] => (Allow) LPort=26789 FirewallRules: [DNS Server Forward Rule - TCP - 61b880e1-1e5f-48c7-891c-a5321bc2d67e - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 61b880e1-1e5f-48c7-891c-a5321bc2d67e - 0] => (Allow) LPort=53 ==================== Points de restauration ========================= 19-06-2018 15:52:35 avant desinfection ==================== Éléments en erreur du Gestionnaire de périphériques ============= Name: Clavier standard PS/2 Description: Clavier standard PS/2 Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Claviers standard) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Hyper-V Virtual Ethernet Adapter Description: Carte Ethernet virtuelle Hyper-V Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: VMSNPXYMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Hyper-V Virtual Ethernet Adapter #2 Description: Carte Ethernet virtuelle Hyper-V Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: VMSNPXYMP Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Souris Microsoft PS/2 Description: Souris Microsoft PS/2 Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Erreurs du Journal des événements: ========================= Erreurs Application: ================== Error: (06/19/2018 03:44:28 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: DESKTOP-NOOT84K) Description: httphttp-2147467263 Error: (06/19/2018 03:42:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante SystemSettingsAdminFlows.exe, version : 10.0.17134.1, horodatage : 0x58378cfc Nom du module défaillant : wintypes.dll, version : 10.0.17134.112, horodatage : 0xfa824cee Code d’exception : 0xc0000005 Décalage d’erreur : 0x000000000000d751 ID du processus défaillant : 0x6c0 Heure de début de l’application défaillante : 0x01d407d3676c369b Chemin d’accès de l’application défaillante : C:\WINDOWS\system32\SystemSettingsAdminFlows.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\wintypes.dll ID de rapport : fd92067f-a894-416c-b98c-7ab754505907 Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (06/19/2018 03:42:47 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: L’acquisition de la licence d’utilisateur final a échoué. hr=0xC004C003 Id Sku=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Error: (06/19/2018 03:42:47 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Détails de l’échec d’acquisition de la licence. hr=0xC004C003 Error: (06/19/2018 03:42:44 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: L’acquisition de la licence d’utilisateur final a échoué. hr=0xC004C003 Id Sku=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Error: (06/19/2018 03:42:44 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Détails de l’échec d’acquisition de la licence. hr=0xC004C003 Error: (06/19/2018 02:59:09 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0xC004C003 Arguments de la ligne de commande : RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable Error: (06/19/2018 02:59:09 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: L’acquisition de la licence d’utilisateur final a échoué. hr=0xC004C003 Id Sku=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Erreurs système: ============= Error: (06/19/2018 03:00:02 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Exécution pour l’application serveur COM avec le CLSID Windows.SecurityCenter.WscBrokerManager et l’APPID Non disponible au SID AUTORITE NT\Système de l’utilisateur (S-1-5-18) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Windows Defender: =================================== Date: 2018-06-09 11:43:33.196 Description: L’analyse Antivirus Windows Defender a été arrêtée avant la fin. ID de l’analyse : {C2A17998-F32C-4D89-A7C4-43E68E754822} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse complète Utilisateur : DESKTOP-NOOT84K\julie Date: 2018-06-09 11:33:53.385 Description: Antivirus Windows Defender a détecté un logiciel malveillant ou potentiellement indésirable. Pour plus d’informations, reportez-vous aux éléments suivants : https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/CoinMiner.CZ&threatid=2147726774&enterprise=0 Nom : Trojan:Win32/CoinMiner.CZ ID : 2147726774 Gravité : Grave Catégorie : Cheval de Troie Chemin : file:_C:\Users\julie\AppData\Local\Mozilla\Firefox\Profiles\yelvssy2.default\cache2\entries\0BA0429867F3D06ABCD9C9D44AC26C31827930AF Origine de la détection : Ordinateur local Type de détection : Concret Source de détection : Protection en temps réel Utilisateur : DESKTOP-NOOT84K\julie Nom du processus : C:\Program Files\Mozilla Firefox\firefox.exe Version de la signature : AV: 1.269.929.0, AS: 1.269.929.0, NIS: 1.269.929.0 Version du moteur : AM: 1.1.14901.4, NIS: 1.1.14901.4 Date: 2018-06-09 11:33:20.495 Description: Antivirus Windows Defender a détecté un logiciel malveillant ou potentiellement indésirable. Pour plus d’informations, reportez-vous aux éléments suivants : https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/CoinMiner.CZ&threatid=2147726774&enterprise=0 Nom : Trojan:Win32/CoinMiner.CZ ID : 2147726774 Gravité : Grave Catégorie : Cheval de Troie Chemin : file:_C:\Users\julie\AppData\Local\Mozilla\Firefox\Profiles\yelvssy2.default\cache2\entries\0BA0429867F3D06ABCD9C9D44AC26C31827930AF Origine de la détection : Ordinateur local Type de détection : Concret Source de détection : Système Utilisateur : AUTORITE NT\Système Nom du processus : Unknown Version de la signature : AV: 1.269.929.0, AS: 1.269.929.0, NIS: 1.269.929.0 Version du moteur : AM: 1.1.14901.4, NIS: 1.1.14901.4 Date: 2018-06-09 11:33:14.922 Description: Antivirus Windows Defender a détecté un logiciel malveillant ou potentiellement indésirable. Pour plus d’informations, reportez-vous aux éléments suivants : https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/CoinMiner.CZ&threatid=2147726774&enterprise=0 Nom : Trojan:Win32/CoinMiner.CZ ID : 2147726774 Gravité : Grave Catégorie : Cheval de Troie Chemin : file:_C:\Users\julie\AppData\Local\Mozilla\Firefox\Profiles\yelvssy2.default\cache2\entries\0BA0429867F3D06ABCD9C9D44AC26C31827930AF Origine de la détection : Ordinateur local Type de détection : Concret Source de détection : Système Utilisateur : AUTORITE NT\Système Nom du processus : Unknown Version de la signature : AV: 1.269.929.0, AS: 1.269.929.0, NIS: 1.269.929.0 Version du moteur : AM: 1.1.14901.4, NIS: 1.1.14901.4 Date: 2018-06-09 11:32:54.091 Description: Antivirus Windows Defender a détecté un logiciel malveillant ou potentiellement indésirable. Pour plus d’informations, reportez-vous aux éléments suivants : https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/CoinMiner.CZ&threatid=2147726774&enterprise=0 Nom : Trojan:Win32/CoinMiner.CZ ID : 2147726774 Gravité : Grave Catégorie : Cheval de Troie Chemin : file:_C:\Users\julie\AppData\Local\Mozilla\Firefox\Profiles\yelvssy2.default\cache2\entries\0BA0429867F3D06ABCD9C9D44AC26C31827930AF Origine de la détection : Ordinateur local Type de détection : Concret Source de détection : Protection en temps réel Utilisateur : DESKTOP-NOOT84K\julie Nom du processus : C:\Program Files\Mozilla Firefox\firefox.exe Version de la signature : AV: 1.269.929.0, AS: 1.269.929.0, NIS: 1.269.929.0 Version du moteur : AM: 1.1.14901.4, NIS: 1.1.14901.4 Date: 2018-06-14 15:14:47.018 Description: Antivirus Windows Defender a rencontré une erreur lors d la mise à jour des signatures. Nouvelle version de la signature : Version précédente de la signature : 1.269.1192.0 Source de mise à jour : Serveur Microsoft Update Type de signature : Anti-virus Type de mise à jour : Complet Utilisateur : AUTORITE NT\Système Version actuelle du moteur : Version précédente du moteur : 1.1.14901.4 Code d’erreur : 0x8024402c Description de l’erreur : Un problème inattendu s’est produit lors de la vérification des mises à jour. Pour plus d’informations sur l’installation ou la résolution des problèmes de mise à jour, voir Aide et support. Date: 2018-06-09 11:40:49.332 Description: Antivirus Windows Defender a rencontré une erreur lors d la mise à jour des signatures. Nouvelle version de la signature : Version précédente de la signature : 1.269.929.0 Source de mise à jour : Serveur Microsoft Update Type de signature : Anti-virus Type de mise à jour : Complet Utilisateur : AUTORITE NT\Système Version actuelle du moteur : Version précédente du moteur : 1.1.14901.4 Code d’erreur : 0x80072efd Description de l’erreur : Impossible d’établir une connexion avec le serveur CodeIntegrity: =================================== Date: 2018-06-19 13:51:30.031 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll that did not meet the Store signing level requirements. Date: 2018-06-17 08:28:29.072 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll that did not meet the Store signing level requirements. Date: 2018-06-16 17:46:26.141 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll that did not meet the Store signing level requirements. Date: 2018-06-15 21:33:27.519 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll that did not meet the Store signing level requirements. Date: 2018-06-15 14:48:49.787 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll that did not meet the Store signing level requirements. Date: 2018-06-14 21:35:03.113 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll that did not meet the Store signing level requirements. Date: 2018-06-14 15:13:18.505 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll that did not meet the Store signing level requirements. Date: 2018-06-13 11:55:34.440 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume4\Program Files\Nahimic\Nahimic VR\Foundation\x64\NahimicVRDevProps.dll that did not meet the Store signing level requirements. ==================== Infos Mémoire =========================== Processeur: Intel(R) Core(TM) i5-7600K CPU @ 3.80GHz Pourcentage de mémoire utilisée: 30% Mémoire physique - RAM - totale: 16343.35 MB Mémoire physique - RAM - disponible: 11297.93 MB Mémoire virtuelle totale: 18775.35 MB Mémoire virtuelle disponible: 11816.82 MB ==================== Lecteurs ================================ Drive b: (RAMDisk) (Fixed) (Total:0.25 GB) (Free:0.25 GB) FAT Drive c: () (Fixed) (Total:110.77 GB) (Free:10.28 GB) NTFS Drive d: (JUX) (Fixed) (Total:931.39 GB) (Free:400.3 GB) NTFS \\?\Volume{3c5ef593-9474-4847-b1e5-941757b6b6f1}\ (Récupération) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS \\?\Volume{baecc58b-b851-4776-8e34-3783e7730e75}\ () (Fixed) (Total:0.47 GB) (Free:0.08 GB) NTFS \\?\Volume{b65a2b32-bf16-45ea-973d-4cec4e6ea8a0}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Table des partitions ================== ======================================================== Disk: 0 (Protective MBR) (Size: 111.8 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== Fin de Addition.txt ============================