Résultats de correction de Farbar Recovery Scan Tool (x64) Version: 17.04.2019 Exécuté par DAD (18-04-2019 06:17:47) Run:1 Exécuté depuis C:\Users\DAD\Desktop Profils chargés: DAD (Profils disponibles: DAD) Mode d'amorçage: Normal ============================================== fixlist contenu: ***************** CreateRestorePoint: CloseProcesses: HKLM-x32\...\Run: [] => [X] HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION GroupPolicy: Restriction ? <==== ATTENTION CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx 2019-04-17 19:45 - 2019-04-17 19:45 - 003181960 _____ (Avira Operations GmbH & Co. KG) C:\Users\DAD\Downloads\avira_registry_cleaner_en.exe 2019-04-17 18:24 - 2019-04-17 18:24 - 000000000 ____D C:\ProgramData\Avira 2019-04-17 18:19 - 2019-01-15 20:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Game Booster.lnk -> C:\Program Files (x86)\Avira\Game Booster\Avira.GameBooster.UI.Application.exe (Pas de fichier) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira.lnk -> C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Pas de fichier) C:\Program Files (x86)\Avira Reg: REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /V SmartScreenEnabled /T REG_SZ /D RequireAdmin /f Reg: REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction" /V Enable /T REG_SZ /D n /f Reg: REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction" /V OptimizeComplete /T REG_SZ /D no /f Reg: REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /V PowerdownAfterShutdown /T REG_SZ /D 1 /f Reg: REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /V ClearPageFileAtShutdown /T REG_DWORD /D 0 /f Reg: REG ADD "HKEY_CURRENT_USER\Control Panel\Desktop" /V MenuShowDelay /T REG_SZ /D 400 /f Reg: REG ADD "HKEY_CURRENT_USER\Control Panel\Desktop" /V WaitToKillAppTimeout /T REG_SZ /D 1200 /f Reg: REG ADD "HKEY_CURRENT_USER\Control Panel\Desktop" /V HungAppTimeout /T REG_SZ /D 1200 /f Reg: REG ADD "HKEY_CURRENT_USER\Control Panel\Desktop" /V AutoEndTasks /T REG_SZ /D 1 /f Reg: REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control" /V WaitToKillServiceTimeout /T REG_SZ /D 1200 /f StartRegedit: Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Dependencies\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Dependencies\{BE930E27-DF4B-44AF-8037-EB0A1D419787}] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BE930E27-DF4B-44AF-8037-EB0A1D419787}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\72E039EBB4FDFA440873BEA0D1147978] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avira_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Avira_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Chrome\NativeMessagingHosts\com.avira.password.manager] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Avira Safe Shopping_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Avira Safe Shopping_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AviraSoftwareUpdater_RASAPI32] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\AviraSoftwareUpdater_RASMANCS] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BE930E27-DF4B-44AF-8037-EB0A1D419787}] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Avira Phantom VPN] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Avira Software Updater ServiceHost] [-HKEY_USERS\.DEFAULT\Software\Avira] [-HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Avira] EndRegedit: DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Windows\Installer\{BE930E27-DF4B-44AF-8037-EB0A1D419787} DeleteValue: HKLM\SOFTWARE\Classes\Installer\Products\72E039EBB4FDFA440873BEA0D1147978\SourceList\Net|1 DeleteValue: HKLM\SOFTWARE\Classes\Installer\Products\72E039EBB4FDFA440873BEA0D1147978\SourceList|LastUsedSource DeleteValue: HKLM\SOFTWARE\Classes\Installer\Products\72E039EBB4FDFA440873BEA0D1147978|Transforms DeleteValue: HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3683516617-3062157859-298418513-1001|\Device\HarddiskVolume4\ProgramData\Package Cache\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}\Avira.OE.Setup.Bundle.exe DeleteValue: HKLM\SOFTWARE\Classes\Installer\Dependencies\{63FCD992-C7DD-4815-A79C-C54871748B59}|DisplayName DeleteValue: HKLM\SOFTWARE\Classes\Installer\Dependencies\{650B3385-A8EE-4C79-B14F-8AC6380E510B}|DisplayName DeleteValue: HKLM\SOFTWARE\Classes\Installer\Dependencies\{6E83C075-0805-4D11-B403-8BAC84374B81}|DisplayName DeleteValue: HKLM\SOFTWARE\Classes\Installer\Dependencies\{8FB15125-F526-4632-8055-837D0083EA3B}|DisplayName DeleteValue: HKLM\SOFTWARE\Classes\Installer\Dependencies\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}|DisplayName DeleteValue: HKLM\SOFTWARE\Classes\Installer\Dependencies\{BE930E27-DF4B-44AF-8037-EB0A1D419787}|DisplayName DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Avira\Launcher\pages\id-ID\ DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Avira\Launcher\id-ID\ DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Avira\SoftwareUpdater\ DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Avira\Launcher\htmlui\views\templates\ DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|avira_fr_fass0_5c3e2377c8197__ws.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Avira.OE.Setup.Bundle.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Avira\Antivirus\startui.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Avira\Antivirus\avirasecuritycenteragent.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Avira\Antivirus\ipmgui.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\StoreC:\Program Files (x86)\Avira\Antivirus\avgnt.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Avira\Antivirus\administrativerightsprovider_fr.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\DAD\Downloads\avira_registry_cleaner_en.exe DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Package Cache\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}\Avira.OE.Setup.Bundle.exe cmd: cscript %windir%\System32\slmgr.vbs /dli Hosts: EmptyTemp: ***************** Erreur: (0) Impossible de créer un point de restauration. Processus fermé avec succès. "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => supprimé(es) avec succès HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => supprimé(es) avec succès C:\Windows\system32\GroupPolicy\Machine => déplacé(es) avec succès C:\Windows\system32\GroupPolicy\GPT.ini => déplacé(es) avec succès HKLM\SOFTWARE\Google\Chrome\Extensions\caljgklbbfbcjjanaijlacgncafpegll => supprimé(es) avec succès HKLM\SOFTWARE\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => supprimé(es) avec succès HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\caljgklbbfbcjjanaijlacgncafpegll => supprimé(es) avec succès HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => supprimé(es) avec succès C:\Users\DAD\Downloads\avira_registry_cleaner_en.exe => déplacé(es) avec succès C:\ProgramData\Avira => déplacé(es) avec succès C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira => déplacé(es) avec succès "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Game Booster.lnk" => non trouvé(e) "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira.lnk" => non trouvé(e) "C:\Program Files (x86)\Avira" => non trouvé(e) ========= REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /V SmartScreenEnabled /T REG_SZ /D RequireAdmin /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction" /V Enable /T REG_SZ /D n /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction" /V OptimizeComplete /T REG_SZ /D no /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /V PowerdownAfterShutdown /T REG_SZ /D 1 /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /V ClearPageFileAtShutdown /T REG_DWORD /D 0 /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_CURRENT_USER\Control Panel\Desktop" /V MenuShowDelay /T REG_SZ /D 400 /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_CURRENT_USER\Control Panel\Desktop" /V WaitToKillAppTimeout /T REG_SZ /D 1200 /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_CURRENT_USER\Control Panel\Desktop" /V HungAppTimeout /T REG_SZ /D 1200 /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_CURRENT_USER\Control Panel\Desktop" /V AutoEndTasks /T REG_SZ /D 1 /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ========= REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control" /V WaitToKillServiceTimeout /T REG_SZ /D 1200 /f ========= L'op‚ration a r‚ussi. ========= Fin de Reg: ========= ====> Registre "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Windows\Installer\{BE930E27-DF4B-44AF-8037-EB0A1D419787}" => non trouvé(e) "HKLM\SOFTWARE\Classes\Installer\Products\72E039EBB4FDFA440873BEA0D1147978\SourceList\Net\\1" => supprimé(es) avec succès "HKLM\SOFTWARE\Classes\Installer\Products\72E039EBB4FDFA440873BEA0D1147978\SourceList\\LastUsedSource" => supprimé(es) avec succès "HKLM\SOFTWARE\Classes\Installer\Products\72E039EBB4FDFA440873BEA0D1147978\\Transforms" => supprimé(es) avec succès "HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3683516617-3062157859-298418513-1001\\\Device\HarddiskVolume4\ProgramData\Package Cache\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}\Avira.OE.Setup.Bundle.exe" => non trouvé(e) "HKLM\SOFTWARE\Classes\Installer\Dependencies\{63FCD992-C7DD-4815-A79C-C54871748B59}\\DisplayName" => supprimé(es) avec succès "HKLM\SOFTWARE\Classes\Installer\Dependencies\{650B3385-A8EE-4C79-B14F-8AC6380E510B}\\DisplayName" => supprimé(es) avec succès "HKLM\SOFTWARE\Classes\Installer\Dependencies\{6E83C075-0805-4D11-B403-8BAC84374B81}\\DisplayName" => supprimé(es) avec succès "HKLM\SOFTWARE\Classes\Installer\Dependencies\{8FB15125-F526-4632-8055-837D0083EA3B}\\DisplayName" => supprimé(es) avec succès "HKLM\SOFTWARE\Classes\Installer\Dependencies\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}\\DisplayName" => non trouvé(e) "HKLM\SOFTWARE\Classes\Installer\Dependencies\{BE930E27-DF4B-44AF-8037-EB0A1D419787}\\DisplayName" => non trouvé(e) "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Avira\Launcher\pages\id-ID\" => supprimé(es) avec succès "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Avira\Launcher\id-ID\" => supprimé(es) avec succès "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Avira\SoftwareUpdater\" => supprimé(es) avec succès "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Avira\Launcher\htmlui\views\templates\" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\\avira_fr_fass0_5c3e2377c8197__ws.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\\Avira.OE.Setup.Bundle.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Avira\Antivirus\startui.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Avira\Antivirus\avirasecuritycenteragent.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Avira\Antivirus\ipmgui.exe" => supprimé(es) avec succès "DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\StoreC:\Program Files (x86)\Avira\Antivirus\avgnt.exe\\DeleteValue: HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\StoreC:\Program Files (x86)\Avira\Antivirus\avgnt.exe" => non trouvé(e) "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Avira\Antivirus\administrativerightsprovider_fr.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\DAD\Downloads\avira_registry_cleaner_en.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-3683516617-3062157859-298418513-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\ProgramData\Package Cache\{9c4627af-2a2f-4e06-aa50-e0d70979e4b6}\Avira.OE.Setup.Bundle.exe" => supprimé(es) avec succès ========= cscript %windir%\System32\slmgr.vbs /dli ========= Microsoft (R) Windows Script Host Version 5.812 Copyright (C) Microsoft Corporation. Tous droits r‚serv‚s. Nomÿ: Windows(R), Professional edition Description : Windows(R) Operating System, RETAIL channel Cl‚ de produit partielleÿ: 43KTT tat de la licenceÿ: avec licence ========= Fin de CMD: ========= C:\Windows\System32\Drivers\etc\hosts => déplacé(es) avec succès Hosts restauré(es) avec succès. =========== EmptyTemp: ========== BITS transfer queue => 7626752 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 103713904 B Java, Flash, Steam htmlcache => 343 B Windows/system/drivers => 1039702 B Edge => 230400 B Chrome => 0 B Firefox => 72414704 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 7314 B LocalService => 0 B NetworkService => 0 B NetworkService => 0 B DAD => 45119843 B RecycleBin => 0 B EmptyTemp: => 219.5 MB données temporaires supprimées. ================================ Le système a dû redémarrer. ==== Fin de Fixlog 06:19:32 ====