Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 13-12-2020 Exécuté par Estelle (13-12-2020 13:08:21) Exécuté depuis C:\Users\Estelle\Desktop Windows 10 Home Version 1909 18363.1256 (X64) (2020-04-21 11:46:00) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= Administrateur (S-1-5-21-1423560274-1372257107-856294686-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1423560274-1372257107-856294686-503 - Limited - Disabled) Estelle (S-1-5-21-1423560274-1372257107-856294686-1001 - Administrator - Enabled) => C:\Users\Estelle Invité (S-1-5-21-1423560274-1372257107-856294686-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-1423560274-1372257107-856294686-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) Apple Application Support (32 bits) (HKLM-x32\...\{6CF0CAEE-54B6-4D84-A055-3AF110F189D3}) (Version: 8.4 - Apple Inc.) Apple Application Support (64 bits) (HKLM\...\{8B127943-89E7-4691-A7A4-D05807920A84}) (Version: 8.4 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.) Assistant Mise à jour de Windows 10 (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22899 - Microsoft Corporation) Brave (HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\BraveSoftware Brave-Browser) (Version: 71.0.58.21 - Auteurs de Brave) CCleaner (HKLM\...\CCleaner) (Version: 5.75 - Piriform) CCleaner Browser (HKLM-x32\...\CCleaner Browser) (Version: 86.1.6938.201 - Auteurs de CCleaner Browser) CCleaner Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.7.913.0 - Piriform Software) Hidden Centre Souris et Claviers Microsoft (HKLM\...\{F4716768-755D-42A9-A770-60467247CC4D}) (Version: 13.221.137.0 - Microsoft Corporation) Hidden Centre Souris et Claviers Microsoft (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 13.221.137.0 - Microsoft Corporation) iCloud (HKLM\...\{A3616230-EF97-44F3-83D3-1AE29DC639D3}) (Version: 7.18.0.22 - Apple Inc.) Intel(R) Graphics Driver Software (HKLM-x32\...\{7d2bdb54-268a-4ce6-8063-a6cad97dba41}) (Version: 3.11.1.0 - Intel) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.7870 - Intel Corporation) Les Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.69.57.1020 - Electronic Arts Inc.) Logiciel pour périphérique à chipset Intel® (HKLM-x32\...\{33d722f3-efb1-4136-a274-b033ad7f5335}) (Version: 10.1.17570.8068 - Intel(R) Corporation) Hidden Malwarebytes version 4.3.0.98 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.3.0.98 - Malwarebytes) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 87.0.664.60 - Microsoft Corporation) Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.139.59 - ) Mozilla Firefox 83.0 (x64 fr) (HKLM\...\Mozilla Firefox 83.0 (x64 fr)) (Version: 83.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 83.0 - Mozilla) OBDuCAN (HKLM-x32\...\{57EDAA35-4897-418C-B2AF-CAD9A4C5B20C}) (Version: 1.0.0 - OBDuCAN®) Origin (HKLM-x32\...\Origin) (Version: 10.5.89.45622 - Electronic Arts, Inc.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.16299.31241 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8454 - Realtek Semiconductor Corp.) Realtek USB Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{04201224-2B34-4EE7-862B-B7BBF89DB3AB}) (Version: 10.37.1216.2019 - Realtek) Suuntolink (HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\Suuntolink) (Version: 3.0.2 - Suunto) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{3BAE4496-6F6C-4330-A8AA-B93D3D346FA5}) (Version: 2.53.0.0 - Microsoft Corporation) UpdateAssistant (HKLM\...\{F339C545-24DC-4870-AA32-6EB6B0500B95}) (Version: 1.24.0.0 - Microsoft Corporation) Hidden Vulkan Run Time Libraries 1.1.70.1 (HKLM\...\VulkanRT1.1.70.1) (Version: 1.1.70.1 - LunarG, Inc.) Hidden Windows Driver Package - OPTO ELECTRONICS CO.,LTD (optousb) Ports (06/02/2008 2.0.5.5) (HKLM\...\245A139F08D3D69654D8822673D0B5EBFB63EF38) (Version: 06/02/2008 2.0.5.5 - OPTO ELECTRONICS CO.,LTD) WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH) Packages: ========= Centre de configuration des graphiques Intel® -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.2970.0_x64__8j3eq9eme6ctt [2020-11-12] (INTEL CORP) [Startup Task] Composant additionnel Photos Media Engine -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-05-10] (Microsoft Corporation) iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa [2020-11-22] (Apple Inc.) [Startup Task] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-14] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-14] (Microsoft Corporation) [MS Ad] Votre téléphone -> C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20101.99.0_x64__8wekyb3d8bbwe [2020-11-22] (Microsoft Corporation) ==================== Personnalisé CLSID (Avec liste blanche): ============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) CustomCLSID: HKU\S-1-5-21-1423560274-1372257107-856294686-1001_Classes\CLSID\{06C9646D-2807-44C0-97D2-6DA0DB623DB4}\localserver32 -> C:\Users\Estelle\AppData\Local\BraveSoftware\Brave-Browser\Application\71.0.58.21\notification_helper.exe (Brave Software, Inc. -> Brave Software, Inc.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2020-03-22] (Apple Inc. -> Apple Inc.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-03-23] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-03-23] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-26] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com) HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com) ==================== Raccourcis & WMI ======================== ==================== Modules chargés (Avec liste blanche) ============= ==================== Alternate Data Streams (Avec liste blanche) ======== ==================== Mode sans échec (Avec liste blanche) ================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Avec liste blanche) ================= ==================== Internet Explorer (Avec liste blanche) ========== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKU\S-1-5-21-1423560274-1372257107-856294686-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP HKU\S-1-5-21-1423560274-1372257107-856294686-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://oem17win10.msn.com/?pc=NMTE SearchScopes: HKLM -> DefaultScope {FEEC09C2-2978-4051-BAC1-2C7E661805C2} URL = SearchScopes: HKLM-x32 -> DefaultScope {FEEC09C2-2978-4051-BAC1-2C7E661805C2} URL = SearchScopes: HKU\S-1-5-21-1423560274-1372257107-856294686-1001 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE15 SearchScopes: HKU\S-1-5-21-1423560274-1372257107-856294686-1001 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE15 ==================== Hosts contenu: ========================= (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2018-04-12 00:38 - 2020-03-23 13:52 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Autres zones =========================== (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-1423560274-1372257107-856294686-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Estelle\Desktop\Vacaances cauterets 2020\IMG_2720.JPG DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) HKLM\...\StartupApproved\Run: => "RTHDVCPL" HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run32: => "TeamsMachineInstaller" HKLM\...\StartupApproved\Run32: => "AirBackupHelper" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "Chromium" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_C665CACB3D9235D12DE8D38583E86272" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "CCleanerBrowserAutoLaunch_5765494E612D5F80CAA1804CCEC671E4" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "iCloudServices" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "iCloudDrive" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "ApplePhotoStreams" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "AnyTransToolHelper" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "SuuntolinkLauncher" HKU\S-1-5-21-1423560274-1372257107-856294686-1001\...\StartupApproved\Run: => "EC6697E8B480BEDC77E3028091F799ECEC08B782._service_run" ==================== RèglesPare-feu (Avec liste blanche) ================ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [{4B1BFFFA-0026-49E0-9943-E0610AE6E1A9}] => (Allow) C:\Users\Estelle\AppData\Roaming\uTorrent\uTorrent.exe => Pas de fichier FirewallRules: [{5ED7EB54-AB5C-4B45-8E9D-CD5BDBF5AFB6}] => (Allow) C:\Users\Estelle\AppData\Roaming\uTorrent\uTorrent.exe => Pas de fichier FirewallRules: [{48A9E817-867C-4711-80B1-5D5D854F69B9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => Pas de fichier FirewallRules: [{3159832C-3A8D-4562-B9EF-634F6CFEA005}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => Pas de fichier FirewallRules: [{A4A04710-FDF3-47C7-BFEB-1B48F3D16941}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => Pas de fichier FirewallRules: [{86365C52-E752-40BB-BB0A-04CBC2AA2144}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => Pas de fichier FirewallRules: [{B3D42F2D-6EF0-46F3-ADD2-0621F45C46D9}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts Inc.) [Fichier non signé] FirewallRules: [{B94A856C-7E3D-4216-86D8-1C031BC0B6D0}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts Inc.) [Fichier non signé] FirewallRules: [{828F318D-4689-4ED4-9C01-99E5BC51B316}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe => Pas de fichier FirewallRules: [{501C8EB2-9E07-4B9A-9DC5-18690CF174E0}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe => Pas de fichier FirewallRules: [UDP Query User{5CC3B9E3-392C-42D1-AD6B-E663FB077EAC}C:\users\estelle\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\estelle\appdata\roaming\spotify\spotify.exe => Pas de fichier FirewallRules: [TCP Query User{CEABACB6-318C-4722-A51B-CF77EDB93EA3}C:\users\estelle\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\estelle\appdata\roaming\spotify\spotify.exe => Pas de fichier FirewallRules: [UDP Query User{81B40AF6-C5E6-4911-8B3E-5A944D0E27E3}C:\users\estelle\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\estelle\appdata\roaming\spotify\spotify.exe => Pas de fichier FirewallRules: [TCP Query User{43F9410A-0614-4B97-B9E5-25CAD229B304}C:\users\estelle\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\estelle\appdata\roaming\spotify\spotify.exe => Pas de fichier FirewallRules: [{994F0C93-1A34-48BC-BDC1-DA5CEE00508D}] => (Allow) C:\Users\Estelle\AppData\Local\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.) FirewallRules: [{CB711BE6-F033-4BD0-BE51-ED8DF32E03DD}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{F746667E-83EF-413C-BD7A-DC118EB721FD}] => (Allow) C:\Program Files (x86)\iMobie\AnyTrans\xldownload\download\MiniThunderPlatform.exe => Pas de fichier FirewallRules: [{C2234F08-88ED-4C59-8D78-1FEFFEEB360E}] => (Allow) C:\Program Files (x86)\iMobie\AnyTrans\xldownload\download\MiniThunderPlatform.exe => Pas de fichier FirewallRules: [TCP Query User{B61EA550-8DE3-4FA6-8780-F0D40259934B}C:\program files (x86)\imobie\anytrans\anytrans for ios.exe] => (Allow) C:\program files (x86)\imobie\anytrans\anytrans for ios.exe => Pas de fichier FirewallRules: [UDP Query User{0D9DBD18-1AB5-4DD4-BEB3-3B9EBFA1B3E0}C:\program files (x86)\imobie\anytrans\anytrans for ios.exe] => (Allow) C:\program files (x86)\imobie\anytrans\anytrans for ios.exe => Pas de fichier FirewallRules: [TCP Query User{9139182F-71F1-4F4A-AAD4-BAE7EB8AA101}C:\program files (x86)\imobie\anytrans\airbackuphelper.exe] => (Block) C:\program files (x86)\imobie\anytrans\airbackuphelper.exe => Pas de fichier FirewallRules: [UDP Query User{FCCB94E4-C527-4DAF-A490-A09721543545}C:\program files (x86)\imobie\anytrans\airbackuphelper.exe] => (Block) C:\program files (x86)\imobie\anytrans\airbackuphelper.exe => Pas de fichier FirewallRules: [{8D15E9FA-9E76-4A56-A5FC-1C1B2EC4DD77}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => Pas de fichier FirewallRules: [{604404F7-8D29-4E26-864B-E38E54BA7ABF}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => Pas de fichier FirewallRules: [TCP Query User{9B24E610-EB1F-46A6-8F35-DC688F736B37}C:\program files (x86)\imobie\anytrans\anytrans.exe] => (Block) C:\program files (x86)\imobie\anytrans\anytrans.exe => Pas de fichier FirewallRules: [UDP Query User{E4D216A8-8012-4779-9CB2-BD5C4C8B80D4}C:\program files (x86)\imobie\anytrans\anytrans.exe] => (Block) C:\program files (x86)\imobie\anytrans\anytrans.exe => Pas de fichier FirewallRules: [TCP Query User{BF9BDBA1-7058-4AC4-87FF-FEB367E9E874}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [UDP Query User{EA2157F7-3B30-4C64-94FC-BFE36808F069}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [{17DB470A-67DF-4BE7-8FEE-810473238C7A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{245F11B2-CAE5-4245-ACA8-D633E638E600}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{A34636F9-F091-414A-8784-54741CB982CD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{1B7E1C9D-0021-45B6-A3DA-B78E1CDEA689}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{54747998-8DE9-4A4D-97CF-F5C4DD8C8B45}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{7732D90F-5A23-4B73-94A9-540EDA0CF0DB}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{FDBB3DE2-4BD7-4BE4-864E-C848C24F46E6}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{8A8B86E9-0656-4A01-97D0-6533D678563E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{36FE44B9-5D1B-4FFC-AEAB-99B21ECC22B2}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{3E2BD5BD-F6A5-46A0-9F09-0756D87ADFB2}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{B8BCFD59-8786-4B01-8A3D-17723A83204E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{DD331C23-5D20-43A2-A4D2-85E7A02F6DDA}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12110.26.53016.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{498E4243-B3CD-4836-8353-BDEDC406E263}] => (Allow) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe (Piriform Software Ltd -> Piriform Software) FirewallRules: [{65054AA8-A8A6-41C7-8A11-16F92CA33AF8}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin_LE\TS4.exe (Electronic Arts Inc.) [Fichier non signé] FirewallRules: [{2914CE14-E021-4D84-903E-F7D6FE723ECB}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin_LE\TS4.exe (Electronic Arts Inc.) [Fichier non signé] FirewallRules: [{5718EF71-F230-45AA-87DC-342FF2A11E53}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts Inc.) [Fichier non signé] FirewallRules: [{4DC840F9-985B-42E4-B66E-F07369E3E30B}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts Inc.) [Fichier non signé] FirewallRules: [{235ABCF4-D78D-426A-A864-1E0800546F33}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{C54CDC61-9EF2-412F-956A-C502667C0647}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) ==================== Points de restauration ========================= 12-12-2020 21:25:47 Windows Update ==================== Éléments en erreur du Gestionnaire de périphériques ============ Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: PS/2 Port Compatible Pointing Device Description: PS/2 Port Compatible Pointing Device Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: TP Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Erreurs du Journal des événements: ======================== Erreurs Application: ================== Error: (12/13/2020 12:50:27 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (184,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (12/13/2020 12:31:37 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (3200,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (12/13/2020 12:03:34 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (3560,R,98) TILEREPOSITORYS-1-5-18: L’erreur -1023 (0xfffffc01) s’est produite lors de l’ouverture d’un fichier journal C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (12/13/2020 11:38:59 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante TiWorker.exe, version : 10.0.18362.1190, horodatage : 0xcb5dc212 Nom du module défaillant : cbscore.dll, version : 10.0.18362.1190, horodatage : 0xc5891c35 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00000000000060f6 ID du processus défaillant : 0xae8 Heure de début de l’application défaillante : 0x01d6d13b8ce4b101 Chemin d’accès de l’application défaillante : C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\TiWorker.exe Chemin d’accès du module défaillant: C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\cbscore.dll ID de rapport : ffea69e0-adb3-4cfe-9e2d-02e6e01ba4ac Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (12/13/2020 10:56:23 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Le programme YourPhone.exe version 1.20101.99.0 a cessé d'interagir avec Windows et a été fermé. Pour voir si plus d'informations sur le problème sont disponibles, vérifiez l'historique des problèmes dans le Panneau de configuration Sécurité et maintenance. ID de processus : 2214 Heure de début : 01d6d13533e5887e Heure d'arrêt : 4294967295 Chemin d'accès à l'application : C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20101.99.0_x64__8wekyb3d8bbwe\YourPhone.exe ID de rapport : 5926cdf4-701e-4324-b7a1-c8fe78d8b9d1 Nom complet du package défectueux : Microsoft.YourPhone_1.20101.99.0_x64__8wekyb3d8bbwe ID de l'application relative à un package défectueux : App Type de blocage : Quiesce Error: (12/13/2020 10:53:56 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante TiWorker.exe, version : 10.0.18362.1190, horodatage : 0xcb5dc212 Nom du module défaillant : cbscore.dll, version : 10.0.18362.1190, horodatage : 0xc5891c35 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00000000000060f6 ID du processus défaillant : 0xd24 Heure de début de l’application défaillante : 0x01d6d1348adb034f Chemin d’accès de l’application défaillante : C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\TiWorker.exe Chemin d’accès du module défaillant: C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.18362.1190_none_1716e3ef2a15f08c\cbscore.dll ID de rapport : 276e546f-4b97-47bd-b888-2adb786ff8f1 Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (12/12/2020 06:57:01 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 51000 Error: (12/12/2020 06:57:00 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 51000 Erreurs système: ============= Error: (12/13/2020 12:40:01 PM) (Source: DCOM) (EventID: 10010) (User: NEO17C-4WH500) Description: Le serveur Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (12/13/2020 12:15:00 PM) (Source: DCOM) (EventID: 10010) (User: NEO17C-4WH500) Description: Le serveur Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (12/13/2020 12:11:20 PM) (Source: DCOM) (EventID: 10010) (User: NEO17C-4WH500) Description: Le serveur Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (12/13/2020 12:10:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Le service Origin Web Helper Service n’a pas pu démarrer en raison de l’erreur : Le service n’a pas répondu assez vite à la demande de lancement ou de contrôle. Error: (12/13/2020 12:10:26 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Le dépassement de délai (45000 millisecondes) a été atteint lors de l’attente de la connexion du service Origin Web Helper Service. Error: (12/13/2020 12:09:40 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: AUTORITE NT) Description: Le module d’extensibilité WLAN n’a pas pu démarrer. Chemin d’accès du module : C:\WINDOWS\system32\Rtlihvs.dll Code d’erreur : 126 Error: (12/13/2020 12:09:36 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Le service cphs s’est arrêté avec l’erreur : Erreur non spécifiée Error: (12/13/2020 12:08:03 PM) (Source: DCOM) (EventID: 10005) (User: AUTORITE NT) Description: DCOM a reçu l’erreur « 1115 » lors de la tentative de démarrage du service wuauserv avec les arguments « Non disponible » pour exécuter le serveur : {E60687F7-01A1-40AA-86AC-DB1CBF673334} CodeIntegrity: =================================== Date: 2020-12-13 11:40:43.264 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\PROGRAM FILES\AVAST SOFTWARE\Avast\aswhook.dll that did not meet the Microsoft signing level requirements. Date: 2020-12-13 11:40:40.691 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\PROGRAM FILES\AVAST SOFTWARE\Avast\aswhook.dll that did not meet the Microsoft signing level requirements. Date: 2020-12-13 11:40:40.575 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\PROGRAM FILES\AVAST SOFTWARE\Avast\aswhook.dll that did not meet the Microsoft signing level requirements. Date: 2020-12-13 11:39:27.485 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements. Date: 2020-12-13 11:39:27.475 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements. Date: 2020-12-13 11:39:27.448 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements. Date: 2020-12-13 11:36:10.024 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. Date: 2020-12-13 11:36:10.006 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume3\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements. ==================== Infos Mémoire =========================== BIOS: A133C.thomsonM2.P0 5.12 09/26/2018 Carte mère: N/A NEO17C.4WH500 Processeur: Intel(R) Celeron(R) CPU N3350 @ 1.10GHz Pourcentage de mémoire utilisée: 80% Mémoire physique - RAM - totale: 3945.3 MB Mémoire physique - RAM - disponible: 770.43 MB Mémoire virtuelle totale: 5673.3 MB Mémoire virtuelle disponible: 1839.38 MB ==================== Lecteurs ================================ Drive c: (Windows) (Fixed) (Total:464.99 GB) (Free:359.88 GB) NTFS \\?\Volume{4e6a2802-8a7f-4763-a76a-62aa71afec73}\ () (Fixed) (Total:0.54 GB) (Free:0.08 GB) NTFS \\?\Volume{d2eb8b52-f288-4b0d-bf01-78f0882ac8f6}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.05 GB) FAT32 ==================== MBR & Table des partitions ==================== ========================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 046C6343) Partition: GPT. ==================== Fin de Addition.txt =======================