Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 03-08-2016 Exécuté par Claire Simon (2018-09-28 23:32:11) Exécuté depuis C:\Users\Claire Simon\AppData\Local\Temp\scoped_dir2024_15800 Windows 10 Pro Version 1803 (X64) (2018-09-13 06:15:36) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= Administrateur (S-1-5-21-920058626-1935491540-2611179922-500 - Administrator - Disabled) Claire Simon (S-1-5-21-920058626-1935491540-2611179922-1001 - Administrator - Enabled) => C:\Users\Claire Simon DefaultAccount (S-1-5-21-920058626-1935491540-2611179922-503 - Limited - Disabled) Invité (S-1-5-21-920058626-1935491540-2611179922-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-920058626-1935491540-2611179922-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Emsisoft Anti-Malware (Enabled - Up to date) {67773CDD-EA83-AD98-A2ED-386463EB3B0D} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Spybot - Search and Destroy (Enabled - Out of date) {4C1D9672-63FE-5C90-371E-8FDA591C5B75} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Emsisoft Anti-Malware (Enabled - Up to date) {DC16DD39-CCB9-A216-985D-0316186C71B0} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) Ableton Live 9 Lite (HKLM\...\{DBB6BCCB-3424-4797-B4E7-4F03F4F60E50}) (Version: 9.0.0.0 - Ableton) AIDA64 Extreme v5.98 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 5.98 - FinalWire Ltd.) CCleaner (HKLM\...\CCleaner) (Version: 5.46 - Piriform) Emsisoft Anti-Malware (HKLM\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 2018.8 - Emsisoft Ltd.) FirestormOS-Releasex64 (HKLM\...\FirestormOS-Releasex64) (Version: 5.1.7.55786 - The Phoenix Firestorm Project, Inc.) Focusrite USB 4.36.5.0 (HKLM\...\Focusrite USB_is1) (Version: 4.36.5.0 - Focusrite Audio Engineering Ltd.) Gyazo 3.3.9 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.) HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software) League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc) Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes) Microsoft OneDrive (HKU\S-1-5-21-920058626-1935491540-2611179922-1001\...\OneDriveSetup.exe) (Version: 18.151.0729.0012 - Microsoft Corporation) Opera Stable 55.0.2994.61 (HKU\S-1-5-21-920058626-1935491540-2611179922-1001\...\Opera 55.0.2994.61) (Version: 55.0.2994.61 - Opera Software) Panneau de configuration NVIDIA 388.13 (Version: 388.13 - NVIDIA Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7910 - Realtek Semiconductor Corp.) Skype version 8.30 (HKLM-x32\...\Skype_is1) (Version: 8.30 - Skype Technologies S.A.) Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.7.64.0 - Safer-Networking Ltd.) ==================== Personnalisé CLSID (Avec liste blanche): ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) CustomCLSID: HKU\S-1-5-21-920058626-1935491540-2611179922-1001_Classes\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\localserver32 -> C:\Users\Claire Simon\AppData\Local\Microsoft\OneDrive\18.151.0729.0012\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-920058626-1935491540-2611179922-1001_Classes\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\localserver32 -> C:\Users\Claire Simon\AppData\Local\Microsoft\OneDrive\18.151.0729.0012\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-920058626-1935491540-2611179922-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Claire Simon\AppData\Local\Microsoft\OneDrive\18.151.0729.0012\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-920058626-1935491540-2611179922-1001_Classes\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\localserver32 -> C:\Users\Claire Simon\AppData\Local\Microsoft\OneDrive\18.151.0729.0012\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-920058626-1935491540-2611179922-1001_Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\localserver32 -> C:\Users\Claire Simon\AppData\Local\Microsoft\OneDrive\18.151.0729.0012\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-920058626-1935491540-2611179922-1001_Classes\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\localserver32 -> C:\Users\Claire Simon\AppData\Local\Microsoft\OneDrive\18.151.0729.0012\FileCoAuth.exe (Microsoft Corporation) ==================== Tâches planifiées (Avec liste blanche) ============= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {00217EEC-9D44-401D-B01A-0240E4335944} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2018-08-08] (Nota Inc.) Task: {01F7D0A1-E7FA-488E-B638-9E17C0C57C85} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => C:\Windows\System32\UNP\UpdateNotificationMgr.exe [2018-07-15] (Microsoft Corporation) Task: {0763BA20-7348-4A44-8255-D4687D8F30DE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2018-04-20] (Safer-Networking Ltd.) Task: {18C32A03-4148-42F4-8703-62B924FB87F5} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2018-08-08] (Nota Inc.) Task: {1E7AD1DA-9523-4865-889F-E13531E78CEC} - System32\Tasks\Microsoft\Windows\InstallService\WakeUpAndContinueUpdates Task: {24168BA3-A510-43D4-8645-7DF58835E844} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\HandleCommand Task: {27B7D13E-CBB1-4E5A-965B-94D4189371D8} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged Task: {2B2A56B3-E127-467B-ADF1-A1CEF2D1F3C6} - System32\Tasks\Microsoft\Windows\InstallService\SmartRetry Task: {2CAB4133-3DA2-4487-89B3-EE91E40F403C} - System32\Tasks\Microsoft\Windows\EDP\EDP Auth Task Task: {3740A369-3D20-4B04-BCD4-81CF9C74D83D} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-920058626-1935491540-2611179922-1001 => C:\Users\Claire Simon\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe [2018-09-23] (Microsoft Corporation) Task: {4094A643-A939-45C6-AE7F-C1FC67592125} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand Task: {4852840B-FC91-46B0-BC71-85BABAD9884F} - System32\Tasks\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh Task: {53BB2FFD-0827-4ECD-A8CB-52EF5E5F40C6} - System32\Tasks\microsoft\windows\applicationdata\appuriverifierdaily => C:\Windows\system32\AppHostRegistrationVerifier.exe [2018-05-20] (Microsoft Corporation) Task: {569FCFB4-24F1-4A79-AA69-2FD226C04DE2} - System32\Tasks\Microsoft\Windows\Device Information\Device => C:\Windows\system32\devicecensus.exe [2018-07-06] (Microsoft Corporation) Task: {5DCE7FFF-26FB-4287-B211-3EBC0579C843} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\Windows\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] () Task: {5E40052E-DF83-43F0-BB8F-BF2DF5ED7990} - System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\ReconcileLanguageResources Task: {5EB26DA1-91A0-4CB5-A211-FCAC1320845D} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefreshTask Task: {5FCEDBE9-91E2-4E9F-9779-99F04D75ACC4} - System32\Tasks\Microsoft\Windows\PushToInstall\LoginCheck => Sc.exe start pushtoinstall login Task: {635B7055-436D-40D1-ACAF-D4B280B72420} - System32\Tasks\Microsoft\Windows\InstallService\ScanForUpdates Task: {63DB3E45-BD0B-42E5-9DEA-39CCF0021610} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-08-24] (Piriform Ltd) Task: {67A6039E-7E12-4250-9F49-226BCFE13E20} - System32\Tasks\Microsoft\Windows\WaaSMedic\PerformRemediation Task: {69689F24-C10D-4B66-9CDF-F45886AA5E2F} - System32\Tasks\Microsoft\Windows\EDP\EDP Inaccessible Credentials Task Task: {7584A52F-F06B-492E-BE40-466773CF0B68} - System32\Tasks\Microsoft\Windows\InstallService\ScanForUpdatesAsUser Task: {805AFE0E-7F5C-4F18-BA8A-E2DD385B9D33} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-08-24] (Piriform Ltd) Task: {83EDEDF3-2386-4215-873B-A4E3A02E76DE} - System32\Tasks\Microsoft\Windows\SharedPC\Account Cleanup => Rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance Task: {84860C3A-932F-4E62-ADA3-675F0D33427A} - System32\Tasks\Microsoft\Windows\Printing\EduPrintProv => C:\Windows\system32\eduprintprov.exe [2018-04-12] (Microsoft Corporation) Task: {855B5820-5492-4B2A-9992-12897847C283} - System32\Tasks\Microsoft\Windows\InstallService\WakeUpAndScanForUpdates Task: {87270D86-25E9-4A09-BB5D-2BAF7977BAC2} - System32\Tasks\Microsoft\Windows\DiskFootprint\StorageSense Task: {8987AEC6-A7A2-4002-A57A-8D62484ED919} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitorToastTask Task: {8E986C22-91E1-40AF-9AF0-AA7414CAF77A} - System32\Tasks\microsoft\windows\applicationdata\appuriverifierinstall => C:\Windows\system32\AppHostRegistrationVerifier.exe [2018-05-20] (Microsoft Corporation) Task: {915367AD-903A-42A5-B985-C49ACC94BB8E} - System32\Tasks\Microsoft\Windows\Subscription\EnableLicenseAcquisition => C:\Windows\system32\ClipRenew.exe [2018-04-12] (Microsoft Corporation) Task: {95905B0F-8DDD-439B-9C4B-A02E520C031F} - System32\Tasks\Microsoft\Windows\USB\Usb-Notifications Task: {9AFD5400-0B78-4AB0-BD2F-4FFA7D7BBB2A} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession Task: {A85114B8-019C-4CB0-88A4-07DC37C5F91D} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange Task: {AC2D3641-27A5-49FF-95E1-3CE7E8EA3F30} - System32\Tasks\Microsoft\Windows\PushToInstall\Registration => Sc.exe start pushtoinstall registration Task: {B1B3FD99-0BE4-4B44-B8D1-D0087606B7AE} - System32\Tasks\Microsoft\Windows\EDP\StorageCardEncryption Task Task: {BC43ACD9-6654-48A6-85CB-FB2D1C5CBCC3} - System32\Tasks\Microsoft\XblGameSave\XblGameSaveTask => C:\Windows\System32\XblGameSaveTask.exe [2018-04-12] (Microsoft Corporation) Task: {C2E45528-D467-49B3-8117-1E9B2BA9A292} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2018-04-20] (Safer-Networking Ltd.) Task: {C6326339-9E19-4A68-80DE-9D3F390277E8} - System32\Tasks\Microsoft\Windows\BrokerInfrastructure\BgTaskRegistrationMaintenanceTask Task: {C687EB34-2867-4FC2-B6A4-CFA7916C3700} - System32\Tasks\CreateExplorerShellUnelevatedTask => /NOUACCHECK Task: {C762A5DA-93F7-4B49-925B-9017DFBCCBFB} - System32\Tasks\Opera scheduled Autoupdate 1537365502 => C:\Users\Claire Simon\AppData\Local\Programs\Opera\launcher.exe [2018-09-13] (Opera Software) Task: {C97FA64B-974A-4711-9F55-8AC9E510957C} - System32\Tasks\Microsoft\Windows\Speech\HeadsetButtonPress => C:\Windows\system32\speech_onecore\common\SpeechRuntime.exe [2018-05-20] (Microsoft Corporation) Task: {E17E39DF-009A-4C26-B047-5EC30F52D1B9} - System32\Tasks\Microsoft\Windows\Subscription\LicenseAcquisition => C:\Windows\system32\ClipRenew.exe [2018-04-12] (Microsoft Corporation) Task: {E7D76BBB-5A49-4276-B4A8-8A8CDD089526} - System32\Tasks\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange Task: {E7ED7D59-5881-4606-8FFD-099E16D56F34} - System32\Tasks\Microsoft\Windows\BitLocker\BitLocker MDM policy Refresh Task: {F3FFB99F-BF5F-453A-A226-D422097CAC05} - System32\Tasks\Microsoft\Windows\Chkdsk\SyspartRepair => C:\Windows\system32\bcdboot.exe [2018-04-12] (Microsoft Corporation) Task: {F7A930A7-2531-4B1F-9E8C-C36FC3249293} - System32\Tasks\Microsoft\Windows\DirectX\DXGIAdapterCache => C:\Windows\system32\dxgiadaptercache.exe [2018-04-12] (Microsoft Corporation) Task: {F8EDD8D0-F6AD-4333-A48B-F004CE9D4C3F} - System32\Tasks\Microsoft\Windows\EDP\EDP App Launch Task Task: {F902F023-ABFC-4FC0-8713-D2217E4B56F4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2018-04-20] (Safer-Networking Ltd.) Task: {FC8FA4B0-ED31-4EC1-B437-9F4039AF2B2D} - System32\Tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask => C:\Windows\system32\speech_onecore\common\SpeechModelDownload.exe [2018-04-12] (Microsoft Corporation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) ==================== Raccourcis ============================= (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) ==================== Modules chargés (Avec liste blanche) ============== 2018-09-19 11:53 - 2018-07-24 12:32 - 02681424 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2018-09-19 11:53 - 2018-08-06 14:20 - 02769768 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 00491744 ____N () C:\Windows\System32\InputHost.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 00472064 ____N () C:\Windows\ShellExperiences\TileControl.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 02759168 ____N () C:\Windows\ShellComponents\TaskFlowUI.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 00491744 ____N () C:\Windows\SYSTEM32\InputHost.dll 2018-09-19 12:41 - 2018-09-15 04:17 - 02185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-09-13 09:12 - 2018-09-13 09:13 - 00086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-09-13 09:12 - 2018-09-13 09:13 - 00195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-09-13 09:12 - 2018-09-13 09:13 - 22373888 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-09-13 09:12 - 2018-09-13 09:13 - 02610176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\skypert.dll 2018-04-12 01:34 - 2018-04-12 01:34 - 00491744 ____N () C:\Windows\SYSTEM32\inputhost.dll 2016-08-19 00:49 - 2016-08-19 00:49 - 00105312 _____ () C:\Windows\SYSTEM32\audioLibVc.dll 2018-09-22 19:31 - 2018-09-22 19:32 - 00479232 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2018-09-22 19:31 - 2018-09-22 19:32 - 69128192 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 02523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 00009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll 2018-09-22 19:31 - 2018-09-22 19:32 - 00010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 03699200 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 00035328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 02280960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\opencv_core320.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 02480640 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\opencv_imgproc320.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 02283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll 2018-09-22 19:31 - 2018-09-22 19:32 - 14171648 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 03544576 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\MediaEngine.dll 2018-09-22 19:31 - 2018-09-22 19:32 - 02866176 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 00973312 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll 2018-09-13 09:10 - 2018-09-13 09:16 - 04584960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-09-19 15:58 - 2018-09-13 11:38 - 102216792 _____ () C:\Users\Claire Simon\AppData\Local\Programs\Opera\55.0.2994.61\opera_browser.dll 2018-09-19 15:58 - 2018-09-13 11:38 - 04832856 _____ () C:\Users\Claire Simon\AppData\Local\Programs\Opera\55.0.2994.61\libglesv2.dll 2018-09-19 15:58 - 2018-09-13 11:38 - 00116312 _____ () C:\Users\Claire Simon\AppData\Local\Programs\Opera\55.0.2994.61\libegl.dll 2018-09-28 23:21 - 2018-09-28 23:21 - 03167616 _____ () C:\Users\Claire Simon\ZHPDiag3.exe ==================== Alternate Data Streams (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.) ==================== Mode sans échec (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318} => ""="Media" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318} => "SafeBootDrivers"="1" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioEndpointBuilder => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AudioSrv => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudAddService.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HdAudBus.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetSetupSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SerCx2.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\usbaudio.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96C-E325-11CE-BFC1-08002BE10318} => ""="Media" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96C-E325-11CE-BFC1-08002BE10318} => "SafeBootDrivers"="1" ==================== Association (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.) ==================== Internet Explorer sites de confiance/sensibles =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.) ==================== Hosts contenu: =============================== (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2018-09-13 09:06 - 2018-09-13 09:05 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Autres zones ============================ (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-920058626-1935491540-2611179922-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-920058626-1935491540-2611179922-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-920058626-1935491540-2611179922-1001\...\StartupApproved\Run: => "Skype for Desktop" ==================== RèglesPare-feu (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [WirelessDisplay-Infra-In-TCP] => (Allow) %systemroot%\system32\CastSrv.exe FirewallRules: [TCP Query User{8F9923C7-73D7-49F4-AE82-59966DCB20BC}D:\league of legends\rads\projects\league_client\releases\0.0.0.162\deploy\leagueclient.exe] => (Allow) D:\league of legends\rads\projects\league_client\releases\0.0.0.162\deploy\leagueclient.exe FirewallRules: [UDP Query User{5485A5DA-17E1-463F-A712-9BA283A51C3D}D:\league of legends\rads\projects\league_client\releases\0.0.0.162\deploy\leagueclient.exe] => (Allow) D:\league of legends\rads\projects\league_client\releases\0.0.0.162\deploy\leagueclient.exe FirewallRules: [TCP Query User{E0339D49-8183-42CF-B6C9-385F9E416D60}D:\league of legends\rads\projects\league_client\releases\0.0.0.163\deploy\leagueclient.exe] => (Allow) D:\league of legends\rads\projects\league_client\releases\0.0.0.163\deploy\leagueclient.exe FirewallRules: [UDP Query User{1A91B6D6-8ACF-4879-8E36-70598473B8CB}D:\league of legends\rads\projects\league_client\releases\0.0.0.163\deploy\leagueclient.exe] => (Allow) D:\league of legends\rads\projects\league_client\releases\0.0.0.163\deploy\leagueclient.exe FirewallRules: [TCP Query User{74B09A08-9660-439A-9D7C-95CC3B0FCE82}D:\firestormos-releasex64\slvoice.exe] => (Allow) D:\firestormos-releasex64\slvoice.exe FirewallRules: [UDP Query User{B013DA8F-A20D-4048-9878-F170895228CC}D:\firestormos-releasex64\slvoice.exe] => (Allow) D:\firestormos-releasex64\slvoice.exe FirewallRules: [{AC2FF172-EA02-445C-B62F-3882DA347C22}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe FirewallRules: [{E62048F9-0C7C-4FFA-B888-19FDBE1A755E}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe FirewallRules: [{35F54908-07DE-4632-A0E4-A76BE4F2C86D}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{C46649A2-3327-416E-B67A-CC23D9DDDF26}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [TCP Query User{79D526BC-4394-42DD-9960-7C4579C8B522}D:\league of legends\rads\projects\league_client\releases\0.0.0.164\deploy\leagueclient.exe] => (Allow) D:\league of legends\rads\projects\league_client\releases\0.0.0.164\deploy\leagueclient.exe FirewallRules: [UDP Query User{75E98377-02AF-47F7-AC4B-BA9E0AC580A2}D:\league of legends\rads\projects\league_client\releases\0.0.0.164\deploy\leagueclient.exe] => (Allow) D:\league of legends\rads\projects\league_client\releases\0.0.0.164\deploy\leagueclient.exe StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Points de restauration ========================= 22-09-2018 20:24:44 Point de contrôle planifié 28-09-2018 23:00:35 Windows Update ==================== Éléments en erreur du Gestionnaire de périphériques ============= ==================== Erreurs du Journal des événements: ========================= Erreurs Application: ================== Error: (09/28/2018 10:54:04 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: L’acquisition de la licence d’utilisateur final a échoué. hr=0xC004C003 Id Sku=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Error: (09/28/2018 10:54:04 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Détails de l’échec d’acquisition de la licence. hr=0xC004C003 Error: (09/28/2018 10:53:59 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: L’acquisition de la licence d’utilisateur final a échoué. hr=0xC004C003 Id Sku=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Error: (09/28/2018 10:53:59 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Détails de l’échec d’acquisition de la licence. hr=0xC004C003 Error: (09/28/2018 10:53:53 PM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: L’acquisition de la licence d’utilisateur final a échoué. hr=0xC004C003 Id Sku=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c Error: (09/28/2018 10:53:53 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Détails de l’échec d’acquisition de la licence. hr=0xC004C003 Error: (09/28/2018 06:39:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante ATKEX_cmd.exe, version : 0.0.0.0, horodatage : 0x00000000 Nom du module défaillant : KERNELBASE.dll, version : 10.0.17134.165, horodatage : 0xfa43f4b2 Code d’exception : 0x0eedfade Décalage d’erreur : 0x0010ddc2 ID du processus défaillant : 0x2ea8 Heure de début de l’application défaillante : 0xATKEX_cmd.exe0 Chemin d’accès de l’application défaillante : ATKEX_cmd.exe1 Chemin d’accès du module défaillant: ATKEX_cmd.exe2 ID de rapport : ATKEX_cmd.exe3 Nom complet du package défaillant : ATKEX_cmd.exe4 ID de l’application relative au package défaillant : ATKEX_cmd.exe5 Error: (09/28/2018 06:39:54 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante ATKEX_cmd.exe, version : 0.0.0.0, horodatage : 0x00000000 Nom du module défaillant : KERNELBASE.dll, version : 10.0.17134.165, horodatage : 0xfa43f4b2 Code d’exception : 0x0eedfade Décalage d’erreur : 0x0010ddc2 ID du processus défaillant : 0x2ea8 Heure de début de l’application défaillante : 0xATKEX_cmd.exe0 Chemin d’accès de l’application défaillante : ATKEX_cmd.exe1 Chemin d’accès du module défaillant: ATKEX_cmd.exe2 ID de rapport : ATKEX_cmd.exe3 Nom complet du package défaillant : ATKEX_cmd.exe4 ID de l’application relative au package défaillant : ATKEX_cmd.exe5 Error: (09/28/2018 06:39:53 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante ATKEX_cmd.exe, version : 0.0.0.0, horodatage : 0x00000000 Nom du module défaillant : KERNELBASE.dll, version : 10.0.17134.165, horodatage : 0xfa43f4b2 Code d’exception : 0x0eedfade Décalage d’erreur : 0x0010ddc2 ID du processus défaillant : 0x66c Heure de début de l’application défaillante : 0xATKEX_cmd.exe0 Chemin d’accès de l’application défaillante : ATKEX_cmd.exe1 Chemin d’accès du module défaillant: ATKEX_cmd.exe2 ID de rapport : ATKEX_cmd.exe3 Nom complet du package défaillant : ATKEX_cmd.exe4 ID de l’application relative au package défaillant : ATKEX_cmd.exe5 Error: (09/28/2018 06:39:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante ATKEX_cmd.exe, version : 0.0.0.0, horodatage : 0x00000000 Nom du module défaillant : KERNELBASE.dll, version : 10.0.17134.165, horodatage : 0xfa43f4b2 Code d’exception : 0x0eedfade Décalage d’erreur : 0x0010ddc2 ID du processus défaillant : 0x66c Heure de début de l’application défaillante : 0xATKEX_cmd.exe0 Chemin d’accès de l’application défaillante : ATKEX_cmd.exe1 Chemin d’accès du module défaillant: ATKEX_cmd.exe2 ID de rapport : ATKEX_cmd.exe3 Nom complet du package défaillant : ATKEX_cmd.exe4 ID de l’application relative au package défaillant : ATKEX_cmd.exe5 Erreurs système: ============= Error: (09/28/2018 11:06:07 PM) (Source: DCOM) (EventID: 10016) (User: AUTORITE NT) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}AUTORITE NTSERVICE LOCALS-1-5-19LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 10:47:05 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 09:29:47 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 06:42:08 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 02:10:59 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 01:39:39 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 01:35:24 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 12:54:14 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 12:16:05 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible Error: (09/28/2018 12:00:25 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5QQIFOD) Description: propres à l’applicationLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-5QQIFODClaire SimonS-1-5-21-920058626-1935491540-2611179922-1001LocalHost (avec LRPC)Non disponibleNon disponible CodeIntegrity: =================================== Date: 2018-09-28 23:29:18.669 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 23:29:18.037 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 23:28:34.327 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 23:28:09.995 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 23:28:09.466 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 23:28:08.948 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 23:27:59.126 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 23:27:59.113 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 22:38:15.678 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2018-09-28 22:38:15.158 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Infos Mémoire =========================== Processeur: Intel(R) Core(TM) i7-6700K CPU @ 4.00GHz Pourcentage de mémoire utilisée: 22% Mémoire physique - RAM - totale: 16314.72 MB Mémoire physique - RAM - disponible: 12678.33 MB Mémoire virtuelle totale: 18746.72 MB Mémoire virtuelle disponible: 13806.72 MB ==================== Lecteurs ================================ Drive c: () (Fixed) (Total:222.16 GB) (Free:179.82 GB) NTFS Drive d: () (Fixed) (Total:931.39 GB) (Free:918.86 GB) NTFS ==================== MBR & Table des partitions ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 00000000) Partition: GPT. ==================== Fin de Addition.txt ============================