Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 22-01-2022 Exécuté par mathp (24-01-2022 21:55:08) Exécuté depuis C:\Users\mathp\Desktop Microsoft Windows 11 Famille Version 21H2 22000.434 (X64) (2022-01-17 16:09:28) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) Administrateur (S-1-5-21-1284622802-2355258884-3150684603-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1284622802-2355258884-3150684603-503 - Limited - Disabled) Invité (S-1-5-21-1284622802-2355258884-3150684603-501 - Limited - Disabled) mathp (S-1-5-21-1284622802-2355258884-3150684603-1001 - Administrator - Enabled) => C:\Users\mathp WDAGUtilityAccount (S-1-5-21-1284622802-2355258884-3150684603-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) Adobe Premiere Pro 2020 (HKLM-x32\...\PPRO_14_0) (Version: 14.0 - Adobe Systems Incorporated) BakkesMod version 3.0 (HKLM\...\{BF029534-4334-4CFC-B771-50B7EE54346F}_is1) (Version: 3.0 - BakkesMod) Discord (HKU\S-1-5-21-1284622802-2355258884-3150684603-1001\...\Discord) (Version: 1.0.9003 - Discord Inc.) Elgato Control Center (HKLM\...\{CB72964D-4492-48D9-86A1-39FDC4800A5A}) (Version: 1.1.4.792 - Elgato Systems) Elgato Stream Deck (HKLM\...\{9CD2D935-33D5-4397-BF83-DC655D58B9AA}) (Version: 5.1.4.14753 - Elgato Systems GmbH) Epic Games Launcher (HKLM-x32\...\{BE9FFAD2-2901-4F9B-8A0C-59EA51773212}) (Version: 1.3.0.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Epic Online Services (HKLM-x32\...\{32C68D93-D32F-4B01-8250-61642BFC22F8}) (Version: 2.0.28.0 - Epic Games, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 97.0.4692.71 - Google LLC) Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 97.0.1072.69 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 97.0.1072.69 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1284622802-2355258884-3150684603-1001\...\OneDriveSetup.exe) (Version: 21.245.1128.0002 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{2FA9DAAC-895B-4E99-99D9-DC2965FBE79C}) (Version: 2.87.0.0 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.29.30139 (HKLM-x32\...\{8d5fdf81-7022-423f-bd8b-b513a1050ae1}) (Version: 14.29.30139.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.30.30708 (HKLM-x32\...\{ee198d9f-cfe1-4f8a-bf5f-7b1be355b63d}) (Version: 14.30.30708.0 - Microsoft Corporation) NVIDIA Broadcast 1.3.0.45 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIABroadcast) (Version: 1.3.0.45 - NVIDIA Corporation) NVIDIA FrameView SDK 1.2.4999.30397803 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk) (Version: 1.2.4999.30397803 - NVIDIA Corporation) NVIDIA GeForce Experience 3.24.0.126 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.24.0.126 - NVIDIA Corporation) NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Streamlabs Desktop 1.7.0 (HKLM\...\029c4619-0385-5543-9426-46f9987161d9) (Version: 1.7.0 - General Workings, Inc.) Tom Clancys Rainbow Six Extraction (HKLM-x32\...\Uplay Install 5271) (Version: - Ubisoft) Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 128.0.10632 - Ubisoft) VLC media player (HKLM\...\VLC media player) (Version: 3.0.16 - VideoLAN) Voicemod (HKLM\...\{8435A407-F778-4647-9CDB-46E5EC50BAD0}_is1) (Version: 2.26.0.1 - Voicemod S.L.) WinRAR 6.02 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.02.0 - win.rar GmbH) Packages: ========= Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_1.22.3.0_x64__6rarf9sa4v8jt [2022-01-17] (Disney) Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.1050.0_x64__8wekyb3d8bbwe [2022-01-17] (Microsoft Studios) [MS Ad] Nobody Saves the World -> C:\Program Files\WindowsApps\DrinkboxStudios.NobodySavestheWorld_1.0.6.0_x64__n8jvyy2pw6mya [2022-01-19] (Drinkbox Studios) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.29.256.0_x64__dt26b99r8h8gj [2022-01-17] (Realtek Semiconductor Corp) Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0 [2022-01-22] (Spotify AB) [Startup Task] Windjammers 2 -> C:\Program Files\WindowsApps\DotEmu.Windjammers2_22.1.13.0_x64__map6zyh9ym1xy [2022-01-21] (DotEmu) ==================== Personnalisé CLSID (Avec liste blanche): ============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) CustomCLSID: HKU\S-1-5-21-1284622802-2355258884-3150684603-1001_Classes\CLSID\{89b2b650-c4dd-d68b-46e7-3176f1973c8b}\localserver32 -> C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod Sociedad Limitada -> Voicemod) CustomCLSID: HKU\S-1-5-21-1284622802-2355258884-3150684603-1001_Classes\CLSID\{e13cc75c-3ffc-4561-9482-33bbaa8b710c}\localserver32 -> C:\Program Files\Elgato\ControlCenter\ControlCenter.exe (Corsair Memory, Inc. -> Elgato Systems) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_015fa42d67826549\nvshext.dll [2022-01-11] (Nvidia Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Avec liste blanche) ==================== ==================== Raccourcis & WMI ======================== (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) ShortcutWithArgument: C:\Users\mathp\Desktop\Mathieu - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default" ==================== Modules chargés (Avec liste blanche) ============= 2022-01-17 22:47 - 2019-05-03 10:41 - 001140736 _____ () [Fichier non signé] [Fichier en cours d'utilisation] C:\Program Files\Voicemod Desktop\CefSharp.BrowserSubprocess.Core.dll 2022-01-17 22:47 - 2019-05-03 10:41 - 001750016 _____ () [Fichier non signé] [Fichier en cours d'utilisation] C:\Program Files\Voicemod Desktop\CefSharp.Core.dll 2022-01-17 17:36 - 2021-10-06 02:30 - 126961152 _____ () [Fichier non signé] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libcef.dll 2022-01-17 17:36 - 2021-10-06 02:30 - 000384000 _____ () [Fichier non signé] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libegl.dll 2022-01-17 17:36 - 2021-10-06 02:30 - 008006656 _____ () [Fichier non signé] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libglesv2.dll 2020-11-06 11:53 - 2020-11-06 11:53 - 001044480 _____ () [Fichier non signé] C:\Program Files\Elgato\ControlCenter\e_sqlite3.DLL 2021-09-03 15:19 - 2021-09-03 15:19 - 000038400 _____ () [Fichier non signé] C:\Program Files\Elgato\StreamDeck\giflib5.dll 2021-09-03 15:19 - 2021-09-03 15:19 - 000098816 _____ () [Fichier non signé] C:\Program Files\Elgato\StreamDeck\QtZeroConf.dll 2021-09-03 15:19 - 2021-09-03 15:19 - 000720384 _____ () [Fichier non signé] C:\Program Files\Elgato\StreamDeck\turbojpeg.dll 2022-01-17 22:47 - 2019-04-25 09:23 - 109914112 _____ () [Fichier non signé] C:\Program Files\Voicemod Desktop\libcef.dll 2022-01-24 09:30 - 2022-01-24 09:30 - 002253824 _____ (deniszykov) [Fichier non signé] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\deniszykov.615d72e4#\09e071ba5cd8670ee72e857e36da2870\deniszykov.WebSocketListener.ni.dll 2022-01-24 09:30 - 2022-01-24 09:30 - 000559104 _____ (Krueger Systems, Inc.) [Fichier non signé] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\SQLite-net\ce8b3baa627e68338dd7a0a2beb37169\SQLite-net.ni.dll 2022-01-02 18:07 - 2022-01-02 18:07 - 000137184 _____ (Microsoft Windows -> Microsoft Corporation) [Fichier non signé] C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20050.505.0_x64__cw5n1h2txyewy\Dashboard\WebView2Loader.dll 2022-01-24 09:30 - 2022-01-24 09:30 - 002888192 _____ (Newtonsoft) [Fichier non signé] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Newtonsoft.Json\799a779712f9c4b30f9fc0098fe538ce\Newtonsoft.Json.ni.dll 2021-09-03 15:19 - 2021-09-03 15:19 - 001742848 _____ (SQLite Development Team) [Fichier non signé] C:\Program Files\Elgato\StreamDeck\sqlite3.dll 2022-01-17 17:36 - 2021-10-06 02:30 - 000983552 _____ (The Chromium Authors) [Fichier non signé] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\chrome_elf.dll 2022-01-17 22:47 - 2019-04-25 09:22 - 000799744 _____ (The Chromium Authors) [Fichier non signé] C:\Program Files\Voicemod Desktop\chrome_elf.dll 2022-01-17 23:01 - 2020-04-26 15:10 - 003000832 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Fichier non signé] C:\Users\mathp\AppData\Roaming\Elgato\StreamDeck\Plugins\net.voicemod.windowsdesktop.sdPlugin\libcrypto-1_1-x64.dll 2021-09-03 15:19 - 2021-09-03 15:19 - 002696704 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [Fichier non signé] C:\Program Files\Elgato\StreamDeck\libcrypto-1_1-x64.dll 2021-09-03 15:19 - 2021-09-03 15:19 - 000642560 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [Fichier non signé] C:\Program Files\Elgato\StreamDeck\libssl-1_1-x64.dll 2022-01-24 09:30 - 2022-01-24 09:30 - 000228864 _____ (Zumero, LLC) [Fichier non signé] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\SQLitePCLRa2ebdfdd6#\45da391005c199e069d59daf8568e00a\SQLitePCLRaw.provider.e_sqlite3.ni.dll 2022-01-24 09:30 - 2022-01-24 09:30 - 000010752 _____ (Zumero, LLC) [Fichier non signé] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\SQLitePCLRaf488fa76#\294d810fb8f04a5fc8cc9c700dc372c5\SQLitePCLRaw.batteries_v2.ni.dll 2022-01-24 09:30 - 2022-01-24 09:30 - 000185856 _____ (Zumero, LLC) [Fichier non signé] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\SQLitePCLRaw.core\a990993fb14b9ee935073feb2d3c8cf7\SQLitePCLRaw.core.ni.dll ==================== Alternate Data Streams (Avec liste blanche) ======== ==================== Mode sans échec (Avec liste blanche) ================== ==================== Association (Avec liste blanche) ================= ==================== Internet Explorer (Avec liste blanche) ========== ==================== Hosts contenu: ========================= (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2021-06-05 13:08 - 2021-06-05 13:08 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Autres zones =========================== (Actuellement, il n'y a pas de correction automatique pour cette section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR HKU\S-1-5-21-1284622802-2355258884-3150684603-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == ==================== RèglesPare-feu (Avec liste blanche) ================ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [{605055A0-24FC-43E2-9619-2BC7C2FBC22D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{917195EA-E70C-47A8-A9C5-C0541ADE1C8C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{131E7638-26A4-4DC1-A1CE-E0895156B41D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{AB9496F5-D76B-4D4F-95BC-21C2BE999BA4}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{D7C9D45E-AA5B-467B-B538-815EE668B104}] => (Allow) C:\Program Files\WindowsApps\microsoftteams_21354.200.1118.3091_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{117B4193-E186-443F-8313-0873CC5F2B08}] => (Allow) C:\Program Files\WindowsApps\microsoftteams_21354.200.1118.3091_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{342EBB12-C0A2-4ADD-BFF8-EC2C3E9568CF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{A1618C38-85D0-46B2-94F5-2D193F85CFB7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{3876C8D3-9969-473F-9067-4B7B1DED2CD4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{2186D892-9043-4887-AA45-1E28BC1819E3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation) FirewallRules: [{88DBAE85-7BB8-4CD1-92B3-EDE6F05B1172}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [Fichier non signé] FirewallRules: [{701FC83F-5699-4852-BBFB-0852C76FC615}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win64\RocketLeague.exe (Psyonix, LLC) [Fichier non signé] FirewallRules: [{06B70D5C-A7A5-44C4-852E-AB253C44AC07}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sekiro\sekiro.exe (Activision Publishing Inc -> FromSoftware, Inc.) FirewallRules: [{DC2A7941-D9D1-49B0-9E36-015BF4467739}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sekiro\sekiro.exe (Activision Publishing Inc -> FromSoftware, Inc.) FirewallRules: [{1864D9EB-71ED-4763-9C3E-E6503B683E7C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe () [Fichier non signé] FirewallRules: [{0D78B45D-79E3-4346-B525-609769B380C6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe () [Fichier non signé] FirewallRules: [{79B5486F-40B1-4AFA-8B80-AF77C9C57F90}] => (Allow) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod Sociedad Limitada -> Voicemod) FirewallRules: [{FEA43387-E6C4-484D-A8AB-81261751CC58}] => (Allow) C:\Program Files\Elgato\StreamDeck\StreamDeck.exe (Corsair Memory, Inc. -> Corsair Memory, Inc) FirewallRules: [{41F0FE3A-4E8A-4466-93DA-759256C73EEB}] => (Allow) C:\Program Files\Elgato\ControlCenter\ControlCenter.exe (Corsair Memory, Inc. -> Elgato Systems) FirewallRules: [{67EED8FF-1585-4B03-AB5F-2B2654388BBF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade Assault\BladeAssault.exe () [Fichier non signé] FirewallRules: [{C557AD40-44F7-4020-B671-3DD400CD52FE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blade Assault\BladeAssault.exe () [Fichier non signé] FirewallRules: [{ED90C6CE-173E-4223-AE26-1FE6F6B43C9E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Nobody Saves the World\NStW_x64.exe (DrinkBox Studios Inc.) [Fichier non signé] FirewallRules: [{A4C820AC-640F-41D1-A5CF-1D622640AFDC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Nobody Saves the World\NStW_x64.exe (DrinkBox Studios Inc.) [Fichier non signé] FirewallRules: [{54ED4773-D4E4-4A52-BDB6-7FC272E13D01}] => (Allow) C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (Voicemod Sociedad Limitada -> Voicemod) FirewallRules: [{BA5284B1-F240-476C-8BB8-A60242985FEB}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{D6E12F1A-4D1B-47C7-8FD8-2050F837FD8B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yu-Gi-Oh! Master Duel\masterduel.exe () [Fichier non signé] FirewallRules: [{4D044B69-07A9-4D24-BBA5-A4B5B5E63DB1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Yu-Gi-Oh! Master Duel\masterduel.exe () [Fichier non signé] FirewallRules: [{4C9E0735-23CB-4368-92A7-98F56B0F3C5D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{3A413542-F1C7-4402-860D-635089B92EC7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{9C21C489-7762-42AC-84D2-C048C0BD045B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{4C317EB8-3D9E-48D1-ADE5-BDEE2A431328}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{44757D95-B071-4B44-9307-E2C89A5065A5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{0FA9A07A-E88D-4335-A603-4B3BED5D991A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation) FirewallRules: [{6DAF224F-9664-4D94-87D5-E8C6AFC09AF2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{9D262234-6429-47CA-885F-D05F903E34AD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{844AF17D-08D7-4070-B7A5-257E95D290D0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{3C0DCDA0-4916-454C-8021-B6B96A7E644E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{706E5D19-0B9D-4777-BCE5-A99142E66897}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{A74A2830-8872-43D4-87FB-6D58F1CBFBFB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{6FE83B25-20D7-4A62-8F9D-D5CADAE11123}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{B3416857-6EDD-46DB-87D9-D1B05D25FA69}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.177.645.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{C7F7175C-BAF5-4A4B-BF5B-347D218DFCE4}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\97.0.1072.69\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{BCA0D5B2-221C-44FC-B043-E675AC0E6FB6}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy’s Rainbow Six Extraction\R6-Extraction_BE.exe (BattlEye Innovations e.K. -> BattlEye Innovations) FirewallRules: [{704A044E-FA7F-4ACE-B17D-C09CAF848C0D}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy’s Rainbow Six Extraction\R6-Extraction_BE.exe (BattlEye Innovations e.K. -> BattlEye Innovations) FirewallRules: [{9D81BD3B-9200-468F-AF3D-2697D023459F}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy’s Rainbow Six Extraction\R6-Extraction.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft) FirewallRules: [{AF3ACB9E-39CA-4A4A-93E1-A6B2E6770D97}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Tom Clancy’s Rainbow Six Extraction\R6-Extraction.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft) ==================== Points de restauration ========================= 24-01-2022 10:14:15 Point de contrôle planifié ==================== Éléments en erreur du Gestionnaire de périphériques ============ ==================== Erreurs du Journal des événements: ======================== Erreurs Application: ================== Error: (01/24/2022 09:34:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante dwm.exe, version : 10.0.22000.1, horodatage : 0x7cbe2305 Nom du module défaillant : ism.dll, version : 10.0.22000.434, horodatage : 0x31c36439 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00000000000b4c0a ID du processus défaillant : 0x574 Heure de début de l’application défaillante : 0x01d8115a2b9c227c Chemin d’accès de l’application défaillante : C:\WINDOWS\system32\dwm.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ism.dll ID de rapport : 923f5f46-8aa9-4f0f-b68b-f3946a0184f7 Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (01/24/2022 08:40:02 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\MIHAWK$ via https://AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Mon, 24 Jan 2022 19:40:03 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: 2528ea97-7f47-4e65-b5ff-502afcc058d4 Méthode : GET(156ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Error: (01/24/2022 08:40:02 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour Système local via https://AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Mon, 24 Jan 2022 19:40:03 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: 6dfd1ef2-088a-494c-bfee-6b047cd7df87 Méthode : GET(203ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Error: (01/24/2022 08:38:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante dwm.exe, version : 10.0.22000.1, horodatage : 0x7cbe2305 Nom du module défaillant : ism.dll, version : 10.0.22000.434, horodatage : 0x31c36439 Code d’exception : 0xc0000005 Décalage d’erreur : 0x00000000000b4c0a ID du processus défaillant : 0x574 Heure de début de l’application défaillante : 0x01d81138070f5f28 Chemin d’accès de l’application défaillante : C:\WINDOWS\system32\dwm.exe Chemin d’accès du module défaillant: C:\WINDOWS\SYSTEM32\ism.dll ID de rapport : 9295b3b5-e7f3-407a-b18d-b114b043f37d Nom complet du package défaillant : ID de l’application relative au package défaillant : Error: (01/24/2022 04:35:42 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\MIHAWK$ via https://AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Mon, 24 Jan 2022 15:35:43 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: 076ff9b6-b074-4324-b0f7-c406bcdeeb82 Méthode : GET(172ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Error: (01/24/2022 04:35:41 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour Système local via https://AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Mon, 24 Jan 2022 15:35:42 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: 6f719043-ff97-4fa5-9a2b-c385dc39cc4d Méthode : GET(562ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Error: (01/24/2022 12:48:41 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\MIHAWK$ via https://AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Mon, 24 Jan 2022 11:48:42 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: 9ebfe462-d919-49a5-a7d7-7a44b8515512 Méthode : GET(157ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Error: (01/24/2022 12:48:41 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour Système local via https://AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Mon, 24 Jan 2022 11:48:42 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: b88324b9-9481-4a17-9eb4-7ca289992e94 Méthode : GET(235ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Erreurs système: ============= Error: (01/24/2022 08:39:58 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: L’arrêt système précédant à 20:35:34 le ‎24/‎01/‎2022 n’était pas prévu. Error: (01/24/2022 04:35:05 PM) (Source: DCOM) (EventID: 10010) (User: MIHAWK) Description: Le serveur Microsoft.ZuneVideo_10.21111.10511.0_x64__8wekyb3d8bbwe!Microsoft.ZuneVideo ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (01/24/2022 04:35:04 PM) (Source: DCOM) (EventID: 10010) (User: MIHAWK) Description: Le serveur {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (01/24/2022 04:35:04 PM) (Source: DCOM) (EventID: 10010) (User: MIHAWK) Description: Le serveur {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (01/24/2022 04:35:04 PM) (Source: DCOM) (EventID: 10010) (User: MIHAWK) Description: Le serveur {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (01/24/2022 04:35:04 PM) (Source: DCOM) (EventID: 10010) (User: MIHAWK) Description: Le serveur {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (01/24/2022 04:35:04 PM) (Source: DCOM) (EventID: 10010) (User: MIHAWK) Description: Le serveur {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (01/24/2022 04:35:04 PM) (Source: DCOM) (EventID: 10010) (User: MIHAWK) Description: Le serveur {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Windows Defender: ================ Date: 2022-01-19 09:48:07 Description: L’analyse Antivirus Microsoft Defender a été arrêtée avant la fin. ID de l’analyse : {A80C8F02-8778-4D79-B7CC-C4FCDFD97A98} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système਍  ==================== Infos Mémoire =========================== BIOS: American Megatrends International, LLC. 1.61 03/02/2021 Carte mère: Micro-Star International Co., Ltd. MPG B550 GAMING PLUS (MS-7C56) Processeur: AMD Ryzen 5 5600X 6-Core Processor Pourcentage de mémoire utilisée: 40% Mémoire physique - RAM - totale: 16310.23 MB Mémoire physique - RAM - disponible: 9646.11 MB Mémoire virtuelle totale: 26038.23 MB Mémoire virtuelle disponible: 15078.19 MB ==================== Lecteurs ================================ Drive c: () (Fixed) (Total:930.75 GB) (Free:608.74 GB) NTFS \\?\Volume{c7d450c5-50fc-44b7-9945-53f518b2f002}\ () (Fixed) (Total:0.65 GB) (Free:0.08 GB) NTFS \\?\Volume{5a9be6ff-93ec-8de5-5238-8067c9d060bd}\ () (Fixed) (Total:0.7 GB) (Free:0 GB) NTFS \\?\Volume{3b9a7fb9-7631-800a-30bb-8af4aee82e3c}\ () (Fixed) (Total:0.41 GB) (Free:0 GB) NTFS \\?\Volume{4354ec82-3e16-4a74-8f2d-98e49b96ac8b}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Table des partitions ==================== ========================================================== Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. Attempted reading MBR returned 0 bytes. Could not read MBR for disk 1. Attempted reading MBR returned 0 bytes. Could not read MBR for disk 2. ==================== Fin de Addition.txt =======================