Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 27.01.2024 01 Exécuté par steph (31-01-2024 21:59:20) Exécuté depuis C:\Users\steph\Downloads Microsoft Windows 10 Professionnel Version 22H2 19045.3930 (X64) (2022-10-18 15:09:56) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) Administrateur (S-1-5-21-2048985721-281637774-1832416837-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2048985721-281637774-1832416837-503 - Limited - Disabled) Invité (S-1-5-21-2048985721-281637774-1832416837-501 - Limited - Disabled) spote (S-1-5-21-2048985721-281637774-1832416837-1002 - Administrator - Enabled) => C:\Users\spote steph (S-1-5-21-2048985721-281637774-1832416837-1001 - Administrator - Enabled) => C:\Users\steph WDAGUtilityAccount (S-1-5-21-2048985721-281637774-1832416837-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.3.0 - Adobe Systems) Hidden Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.3.0 - Adobe Systems) Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\...\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated) Adobe Acrobat 9.3.0 - CPSID_52073 (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}_930) (Version: - Adobe Systems Incorporated) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) Audacity 3.4.2 (HKLM\...\Audacity_is1) (Version: 3.4.2 - Audacity Team) AVG Update Helper (HKLM-x32\...\{EDB7AEE7-E932-4836-AE50-D3B0B7766CB5}) (Version: 1.8.1650.5 - AVG Technologies) Hidden AWS Wickr (HKLM\...\{04405B69-1B62-46DE-86B6-FB5D28A84153}) (Version: 6.20.3 - Amazon Web Services, Wickr) Belgium e-ID middleware 5.0.17 (build 5498) (HKLM\...\{DB942AEA-93D6-4FE4-8862-180D35A75498}) (Version: 5.0.5498 - Belgian Government) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 121.1.62.156 - Auteurs de Brave) Bright VPN 1.318.500 (HKLM-x32\...\54cf4d4c-268a-577e-8fe3-97e36e306708) (Version: 1.318.500 - Bright Data Ltd.) Canon Easy-PhotoPrint Editor (HKLM-x32\...\Canon Easy-PhotoPrint Editor) (Version: 1.6.8 - Canon Inc.) Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.) Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.10.2 - Canon Inc.) Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.10.1.51 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.5.0.69 - Canon Inc.) Canon Inkjet Printer/Scanner/Télécopieur Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.4.0 - Canon Inc.) Canon TR4500 series Manuel à l'écran (HKLM-x32\...\Canon TR4500 series Manuel à l'écran) (Version: 1.0.0 - Canon Inc.) Canon TR4500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TR4500_series) (Version: 1.01 - Canon Inc.) Canon Utilitaire de numérotation rapide 2 (HKLM-x32\...\Speed Dial Utility2) (Version: 2.2.1 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 6.20 - Piriform) Command & Conquer : Alerte Rouge 2 (HKLM\...\{4e50cdad-046a-41e9-a3f7-a62d71fe1c77}.sdb) (Version: - ) Command & Conquer : Alerte Rouge 2 version 4 (HKLM-x32\...\{2744A384-6FBF-422C-9A9D-76EF109A673B}_is1) (Version: 4 - Abandonware-France) Contrôle d’intégrité du PC Windows (HKLM\...\{90C6971F-ABF1-4FBF-BD98-24F14C5F5AB4}) (Version: 3.6.2204.08001 - Microsoft Corporation) Coolsmile (HKLM-x32\...\Coolsmile) (Version: Beta - Coolsmile Chat) Enregistrement de l'imprimante (HKLM-x32\...\Canon EISRegistration) (Version: 1.9.0 - Canon Inc.) Eraser 6.2.0.2979 (HKLM\...\{C5900DE9-D199-4C27-B692-354C9A6A6C8B}) (Version: 6.2.2979 - The Eraser Project) File Shredder 2.5 (HKLM\...\File Shredder_is1) (Version: - Pow Tools) GOG GALAXY (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: 2.0.73.27 - GOG.com) GOG.com Heroes of Might and Magic 3 (HKLM\...\{62a24b39-0106-4990-90ea-3a09e9dda7a6}.sdb) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 121.0.6167.139 - Google LLC) Heroes of Might & Magic III - HD Edition (HKLM-x32\...\Heroes of Might & Magic III - HD Edition_is1) (Version: - ) Heroes of Might and Magic 3 Complete (HKLM-x32\...\1207658787_is1) (Version: 4.0 - GOG.com) Heroes of Might and Magic 4 Complete (HKLM-x32\...\1207658915_is1) (Version: 3.0 win11 - GOG.com) Heroes of Might and Magic V Bundle (HKLM-x32\...\Heroes of Might and Magic V Bundle_is1) (Version: - GOG.com) Java 8 Update 391 (64-bit) (HKLM\...\{71324AE4-039E-4CA4-87B4-2F64180391F0}) (Version: 8.0.3910.13 - Oracle Corporation) Maxthon (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\Maxthon) (Version: 7.1.7.8000 - The Maxthon Authors) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 121.0.2277.83 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 120.0.2210.144 - Microsoft Corporation) Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version: 10.1.22621.3036 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0015-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0019-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-040C-1000-0000000FF1CE}_PROPLUS_{8283FD64-6A3B-4104-9E12-7CA25EF29A1A}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0044-040C-0000-0000000FF1CE}_PROPLUS_{CF3C20A6-47B7-48DA-95C1-6FBB5A439AF8}) (Version: - Microsoft) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-006E-040C-0000-0000000FF1CE}_PROPLUS_{8283FD64-6A3B-4104-9E12-7CA25EF29A1A}) (Version: - Microsoft) Hidden Microsoft Office Access MUI (French) 2007 (HKLM-x32\...\{90120000-0015-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (French) 2007 (HKLM-x32\...\{90120000-0016-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (French) 2007 (HKLM-x32\...\{90120000-0044-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (HKLM\...\{90120000-002A-0000-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (French) 2007 (HKLM-x32\...\{90120000-001A-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (French) 2007 (HKLM-x32\...\{90120000-0018-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2007 (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Proof (Arabic) 2007 (HKLM-x32\...\{90120000-001F-0401-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Dutch) 2007 (HKLM-x32\...\{90120000-001F-0413-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (HKLM-x32\...\{90120000-001F-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2007 (HKLM-x32\...\{90120000-001F-0C0A-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (French) 2007 (HKLM-x32\...\{90120000-002C-040C-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0401-0000-0000000FF1CE}_PROPLUS_{3E8EA473-ECCE-405F-A9CA-59446AEADD3A}) (Version: - Microsoft) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{928D7B99-2BEA-49F9-83B8-20FA57860643}) (Version: - Microsoft) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}) (Version: - Microsoft) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}) (Version: - Microsoft) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0413-0000-0000000FF1CE}_PROPLUS_{2C95E7EE-FEA7-4B3A-A6E5-DF90A88B816A}) (Version: - Microsoft) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}) (Version: - Microsoft) Hidden Microsoft Office Publisher MUI (French) 2007 (HKLM-x32\...\{90120000-0019-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (French) 2007 (HKLM\...\{90120000-002A-040C-1000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (French) 2007 (HKLM-x32\...\{90120000-006E-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (French) 2007 (HKLM-x32\...\{90120000-001B-040C-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft OneDrive (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\OneDriveSetup.exe) (Version: 23.246.1127.0002 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2048985721-281637774-1832416837-1002\...\OneDriveSetup.exe) (Version: 23.246.1127.0002 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (HKLM\...\{764384C5-BCA9-307C-9AAC-FD443662686A}) (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (HKLM\...\{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}) (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (HKLM-x32\...\{3D6AD258-61EA-35F5-812C-B7A02152996E}) (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (HKLM-x32\...\{E7D4E834-93EB-351F-B8FB-82CDAE623003}) (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.31.31103 (HKLM-x32\...\{2aaf1df0-eb13-4099-9992-962bb4e596d1}) (Version: 14.31.31103.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 (HKLM-x32\...\{41d7b770-418a-43b7-95a5-f925fff05789}) (Version: 14.31.31103.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.31.31103 (HKLM\...\{A977984B-9244-49E3-BD24-43F0A8009667}) (Version: 14.31.31103 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.31.31103 (HKLM\...\{A181A302-3F6D-4BAD-97A8-A426A6499D78}) (Version: 14.31.31103 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Additional Runtime - 14.31.31103 (HKLM-x32\...\{5720EC03-F26F-40B7-980C-50B5D420B5DE}) (Version: 14.31.31103 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.31.31103 (HKLM-x32\...\{799E3FFF-705C-461F-B400-6DE27398B3E5}) (Version: 14.31.31103 - Microsoft Corporation) Hidden Mise à jour Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{B761869A-B85C-40E2-994C-A1CE78AC8F2C}) (Version: - Microsoft) Mise à jour Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{51EFB347-1F3D-4BAC-8B79-F056B904FE21}) (Version: - Microsoft) Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{C3DCA38E-005E-41BA-A52A-7C3429F351C3}) (Version: - Microsoft) Mise à jour Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{81536A04-DBFB-4DB3-978F-0F284590C223}) (Version: - Microsoft) Mozilla Firefox (x64 fr) (HKLM\...\Mozilla Firefox 122.0 (x64 fr)) (Version: 122.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 106.0.1 - Mozilla) Opera Stable 106.0.4998.66 (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\Opera 106.0.4998.66) (Version: 106.0.4998.66 - Opera Software) PrivaZer (HKLM-x32\...\PrivaZer) (Version: 4.0.81.0 - Goversoft LLC) qTox (HKLM\...\qTox) (Version: 1.17.6 - The qTox Project) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) TAP-Windows 9.24.2 (HKLM\...\TAP-Windows) (Version: 9.24.2 - OpenVPN Technologies, Inc.) Telegram Desktop (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 4.7.1 - Telegram FZ-LLC) TeleGuard (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\93443beb-f105-47fe-bac0-709583ac44cb_is1) (Version: 3.2.1-beta - Swisscows) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.50 - Ghisler Software GmbH) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{7B63012A-4AC6-40C6-B6AF-B24A84359DD5}) (Version: 8.93.0.0 - Microsoft Corporation) UrbanVPN (HKLM\...\{782C60F6-442A-49E6-8F56-CD79F0135029}) (Version: 2.2.14 - Urban Security) Hidden UrbanVPN (HKLM\...\UrbanVPN 2.2.14) (Version: 2.2.14 - Urban Security) uTorrent Web (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\utweb) (Version: 1.4.0 - BitTorrent Limited) Videodownloader (HKLM-x32\...\{FEEBD562-6B8E-457A-9133-89B8C1E14443}) (Version: 1.1.8 - Videodownloader) Vivaldi (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\Vivaldi) (Version: 6.5.3206.57 - Vivaldi Technologies AS.) VLC media player (HKLM\...\VLC media player) (Version: 3.0.18 - VideoLAN) Waterfox (x64 en-US) (HKLM\...\Waterfox 102.12.0 (x64 en-US)) (Version: 102.12.0 - WaterfoxLimited) WebAdvisor par McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.861 - McAfee, LLC) Wire (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\wire) (Version: 3.34.4566 - Wire) Wondershare Filmora 13(Build 13.0.51.4714) (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\Wondershare Filmora 13_is1) (Version: - Wondershare Software) Wondershare Helper Compact 2.6.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.6.0 - Wondershare) Wondershare NativePush(Build 1.0.1.0) (HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\Wondershare NativePush_is1) (Version: - Wondershare Software) Packages: ========= Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_3.1.0.0_neutral__6e5tt8cgb93ep [2023-10-31] (Canon Inc.) Centre de configuration des graphiques Intel® -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5287.0_x64__8j3eq9eme6ctt [2024-01-27] (INTEL CORP) [Startup Task] Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_2023.11.13.0_neutral__6rarf9sa4v8jt [2023-11-21] (Disney) Driver FRVR -> C:\Program Files\WindowsApps\www.msn.com-A00475D7_1.0.0.0_neutral__q77jw2zwjvy92 [2023-07-05] (www.msn.com) Driver FRVR -> C:\Program Files\WindowsApps\www.msn.com-E9D5DDCC_1.0.0.1_neutral__q77jw2zwjvy92 [2023-10-15] (www.msn.com) ETD Properties For I2C -> C:\Program Files\WindowsApps\ELANMicroelectronicsCorpo.ETDPropertiesForI2C_1.0.5.0_x64__stws0m115j6hg [2024-01-27] (ELAN Microelectronics Corporation) Minecraft Launcher -> C:\Program Files\WindowsApps\Microsoft.4297127D64EC6_1.7.2.0_x64__8wekyb3d8bbwe [2023-12-21] (Microsoft Studios) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.29.256.0_x64__dt26b99r8h8gj [2023-10-31] (Realtek Semiconductor Corp) Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.18.11020.0_x64__8wekyb3d8bbwe [2024-01-27] (Microsoft Studios) [MS Ad] Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0 [2024-01-19] (Spotify AB) [Startup Task] Waves MaxxAudio For Fujitsu -> C:\Program Files\WindowsApps\WavesAudio.WavesMaxxAudioForFujitsu_1.0.93.0_x64__fh4rh281wavaa [2023-10-31] (Waves Audio) ==================== Personnalisé CLSID (Avec liste blanche): ============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) CustomCLSID: HKU\S-1-5-21-2048985721-281637774-1832416837-1001_Classes\CLSID\{14100442-9664-1407-2647-000000000000}\localserver32 -> C:\Users\steph\AppData\Local\Wondershare\Wondershare NativePush\WsToastNotification.exe (Wondershare Technology Group Co.,Ltd -> Wondershare) CustomCLSID: HKU\S-1-5-21-2048985721-281637774-1832416837-1001_Classes\CLSID\{635EFA6F-08D6-4EC9-BD14-8A0FDE975159}\localserver32 -> C:\Users\steph\AppData\Local\Maxthon\Application\7.1.7.8000\notification_helper.exe (Maxthon Technology Co, Ltd. -> Maxthon Ltd.) CustomCLSID: HKU\S-1-5-21-2048985721-281637774-1832416837-1001_Classes\CLSID\{E91C93F1-6A49-4DF5-868B-D99F7A79D210}\localserver32 -> C:\Users\steph\AppData\Local\Vivaldi\Application\6.5.3206.57\notification_helper.exe (Vivaldi Technologies AS -> Vivaldi Technologies AS) ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers1: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2016-08-28] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers1: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu6.dll [2024-01-22] (Goversoft LLC -> ) ContextMenuHandlers2: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2016-08-28] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers2: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu6.dll [2024-01-22] (Goversoft LLC -> ) ContextMenuHandlers3: [DeleteFiles] -> {736AF091-C361-49B4-A928-87C586130D33} => C:\Program Files\File Shredder\fsshell.dll [2012-04-01] () [Fichier non signé] ContextMenuHandlers3: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu6.dll [2024-01-22] (Goversoft LLC -> ) ContextMenuHandlers4: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2016-08-28] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers4: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu6.dll [2024-01-22] (Goversoft LLC -> ) ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2023-06-02] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) ContextMenuHandlers5: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2016-08-28] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers6: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2016-08-28] (Heidi Computers Ltd -> The Eraser Project) ContextMenuHandlers6: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu6.dll [2024-01-22] (Goversoft LLC -> ) ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2023-06-02] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd) ==================== Codecs (Avec liste blanche) ==================== ==================== Raccourcis & WMI ======================== (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) ShortcutWithArgument: C:\Users\steph\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__hhgnadpbhibepakmboedeadlkbncaffg\Driver FRVR.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=hhgnadpbhibepakmboedeadlkbncaffg --app-url=hxxps://www.msn.com/fr-be/play/driver-frvr/cg-9nkpmp84pwk7?ocid=cgpwa --app-launch-source=4 ShortcutWithArgument: C:\Users\steph\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Driver FRVR.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=hhgnadpbhibepakmboedeadlkbncaffg --app-url=hxxps://www.msn.com/fr-be/play/driver-frvr/cg-9nkpmp84pwk7?ocid=cgpwa --app-launch-source=4 ==================== Modules chargés (Avec liste blanche) ============= 2023-05-27 12:23 - 2009-02-27 15:32 - 000020480 _____ () [Fichier non signé] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.fra 2023-03-06 21:47 - 2023-03-06 21:47 - 002586624 _____ () [Fichier non signé] C:\Program Files (x86)\Bright VPN\ffmpeg.dll 2023-03-06 21:47 - 2023-03-06 21:47 - 000354816 _____ () [Fichier non signé] C:\Program Files (x86)\Bright VPN\libegl.dll 2023-03-06 21:47 - 2023-03-06 21:47 - 006924800 _____ () [Fichier non signé] C:\Program Files (x86)\Bright VPN\libglesv2.dll 2024-01-14 04:15 - 2016-07-21 10:54 - 000137728 _____ () [Fichier non signé] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll 2024-01-14 04:15 - 2017-09-12 10:34 - 001506304 _____ () [Fichier non signé] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll 2023-12-07 20:26 - 2023-12-07 20:26 - 001490944 _____ () [Fichier non signé] C:\Users\steph\AppData\Roaming\uTorrent Web\avcodec-58.dll 2023-12-07 20:26 - 2023-12-07 20:26 - 000949248 _____ () [Fichier non signé] C:\Users\steph\AppData\Roaming\uTorrent Web\avformat-58.dll 2023-12-07 20:26 - 2023-12-07 20:26 - 000635392 _____ () [Fichier non signé] C:\Users\steph\AppData\Roaming\uTorrent Web\avutil-56.dll 2023-12-07 20:26 - 2023-12-07 20:26 - 000153088 _____ () [Fichier non signé] C:\Users\steph\AppData\Roaming\uTorrent Web\swresample-3.dll 2022-10-22 16:44 - 2016-10-21 15:06 - 000318976 _____ (CANON INC) [Fichier non signé] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\scchmpm.dll 2022-10-22 16:44 - 2017-06-27 09:59 - 000219648 _____ (CANON INC.) [Fichier non signé] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\cnmpu2.dll 2022-10-22 16:44 - 2017-11-02 14:36 - 000008704 _____ (CANON INC.) [Fichier non signé] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_FRA.DLL 2022-10-22 16:44 - 2017-11-02 14:36 - 000104960 _____ (CANON INC.) [Fichier non signé] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNS2_IMG.dll 2023-12-07 20:26 - 2023-12-07 20:26 - 002554880 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [Fichier non signé] C:\Users\steph\AppData\Roaming\uTorrent Web\libcrypto-1_1.dll 2023-12-07 20:26 - 2023-12-07 20:26 - 000537600 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [Fichier non signé] C:\Users\steph\AppData\Roaming\uTorrent Web\libssl-1_1.dll 2024-01-14 04:15 - 2017-09-12 10:36 - 000708608 _____ (Wondershare) [Fichier non signé] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSProducstInfo.dll ==================== Alternate Data Streams (Avec liste blanche) ======== (Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.) AlternateDataStreams: C:\Users\steph\Desktop\forum_questions_reponses.doc:com.dropbox.attrs [54] ==================== Mode sans échec (Avec liste blanche) ================== ==================== Association (Avec liste blanche) ================= ==================== Internet Explorer (Avec liste blanche) ========== BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre-1.8\bin\ssv.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre-1.8\bin\jp2ssv.dll [2023-10-04] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.) IE trusted site: HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2048985721-281637774-1832416837-1001\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts contenu: ========================= (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2019-12-07 10:14 - 2019-12-07 10:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts ==================== Autres zones =========================== (Actuellement, il n'y a pas de correction automatique pour cette section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\ HKU\S-1-5-21-2048985721-281637774-1832416837-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg HKU\S-1-5-21-2048985721-281637774-1832416837-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == ==================== RèglesPare-feu (Avec liste blanche) ================ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [{B21149F4-7DF0-49CD-8BAC-46F0C8D1F761}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{982FFFC8-B050-415B-BC47-ABC76C0D7B86}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [TCP Query User{342DD71F-BA41-40F3-A4C4-6A815746BF0C}C:\users\steph\appdata\local\programs\opera\opera.exe] => (Allow) C:\users\steph\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [UDP Query User{55822B48-7E3E-42DE-A7AC-D8B256A825D7}C:\users\steph\appdata\local\programs\opera\opera.exe] => (Allow) C:\users\steph\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software) FirewallRules: [TCP Query User{11D0E49A-2086-4C67-A664-0A3A4997B375}C:\games\cncnet\redalert1_online\cncnet5.exe] => (Allow) C:\games\cncnet\redalert1_online\cncnet5.exe (FunkyFr3sh) [Fichier non signé] FirewallRules: [UDP Query User{49CE1276-9FC0-4702-B943-75BFFB0E32EB}C:\games\cncnet\redalert1_online\cncnet5.exe] => (Allow) C:\games\cncnet\redalert1_online\cncnet5.exe (FunkyFr3sh) [Fichier non signé] FirewallRules: [TCP Query User{2D9DA893-D24B-4F79-A729-1C7307E4B8D9}C:\games\cncnet\redalert1_online\ra95-spawn.exe] => (Block) C:\games\cncnet\redalert1_online\ra95-spawn.exe () [Fichier non signé] FirewallRules: [UDP Query User{4F9FB55F-E156-400E-AE50-D3D4172AB0CD}C:\games\cncnet\redalert1_online\ra95-spawn.exe] => (Block) C:\games\cncnet\redalert1_online\ra95-spawn.exe () [Fichier non signé] FirewallRules: [TCP Query User{84C8AAB7-3C38-40F1-9EBB-C614F9A4A1AC}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [UDP Query User{FA96B888-B040-48C9-9626-0C826C55A0B0}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{15FB104B-8E5C-42A3-B826-C6F6A39754F0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{6A891809-07DC-4B64-9D5F-F8187A2CDEC4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{3352D5CA-9ACD-4A67-B193-0F240EE97D88}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{2B9D5927-1719-4A97-8CBF-4B19F9875F86}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{9F98E4DB-B545-4EB5-9FE8-46DD440B186E}] => (Allow) C:\Users\steph\AppData\Local\Maxthon\Application\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon Ltd.) FirewallRules: [{D806C446-CFB7-43B6-9CFE-03312DCA3BBC}] => (Allow) C:\Users\steph\AppData\Local\Maxthon\Application\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon Ltd.) FirewallRules: [{51EC7827-07E9-4DC3-8277-014B25691904}] => (Allow) C:\Users\steph\AppData\Local\Maxthon\Application\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon Ltd.) FirewallRules: [{E294284B-1E7E-434F-9D03-F0B6A4243C5A}] => (Allow) C:\Users\steph\AppData\Local\Maxthon\Application\Maxthon.exe (Maxthon Technology Co, Ltd. -> Maxthon Ltd.) FirewallRules: [{F5D23FA4-E75B-4E25-9024-0AC664097A11}] => (Allow) C:\Program Files\Waterfox\waterfox.exe (WATERFOX LIMITED -> Waterfox Limited) FirewallRules: [{43561DF2-9573-44F3-BF49-19F38F1D7527}] => (Allow) C:\Program Files\Waterfox\waterfox.exe (WATERFOX LIMITED -> Waterfox Limited) FirewallRules: [TCP Query User{4CBB9808-070A-483F-BB44-49184DE27F73}C:\users\steph\appdata\local\vivaldi\application\vivaldi.exe] => (Allow) C:\users\steph\appdata\local\vivaldi\application\vivaldi.exe (Vivaldi Technologies AS -> Vivaldi Technologies AS) FirewallRules: [UDP Query User{C9EFD198-6573-46DC-98AC-354B2B29A302}C:\users\steph\appdata\local\vivaldi\application\vivaldi.exe] => (Allow) C:\users\steph\appdata\local\vivaldi\application\vivaldi.exe (Vivaldi Technologies AS -> Vivaldi Technologies AS) FirewallRules: [TCP Query User{E9FE501D-D276-41B3-AE70-4FC41A0117DE}C:\games\cncnet\redalert1_online\qt\cncnetqm.exe] => (Block) C:\games\cncnet\redalert1_online\qt\cncnetqm.exe () [Fichier non signé] FirewallRules: [UDP Query User{E5208EC3-1680-436E-B64C-086FFEC4DE92}C:\games\cncnet\redalert1_online\qt\cncnetqm.exe] => (Block) C:\games\cncnet\redalert1_online\qt\cncnetqm.exe () [Fichier non signé] FirewallRules: [{DCEC65EE-5083-4FA8-8ACE-A2634EF39B27}] => (Allow) C:\Program Files\UrbanVPN\bin\urbanvpn.exe (Urban Cyber Security Inc. -> Urban Cyber Security Inc.) FirewallRules: [{C20B993C-04C2-41AB-A2CB-BD86FF626819}] => (Allow) C:\Windows\SysWOW64\TCPSVCS.EXE (Microsoft Windows -> Microsoft Corporation) FirewallRules: [TCP Query User{8378EC4A-C47A-47D0-9310-12BE9DFF1B96}C:\users\spote\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Block) C:\users\spote\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe FirewallRules: [UDP Query User{99E44803-71F8-4F17-8AA9-B56982DDC08C}C:\users\spote\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe] => (Block) C:\users\spote\appdata\local\packages\microsoft.4297127d64ec6_8wekyb3d8bbwe\localcache\local\runtime\java-runtime-gamma\windows-x64\java-runtime-gamma\bin\javaw.exe FirewallRules: [TCP Query User{66F79F2B-0D82-4F40-875C-FB0FF97E0D67}C:\program files\qtox\bin\qtox.exe] => (Allow) C:\program files\qtox\bin\qtox.exe () [Fichier non signé] FirewallRules: [UDP Query User{B73FA35D-6F4F-4BB9-AD07-EA562F55ABB2}C:\program files\qtox\bin\qtox.exe] => (Allow) C:\program files\qtox\bin\qtox.exe () [Fichier non signé] FirewallRules: [{A3F5566C-CBC1-4E4C-BE75-9EC5D7016500}] => (Allow) C:\Users\steph\AppData\Local\Wondershare\Wondershare NativePush\WsToastNotification.exe (Wondershare Technology Group Co.,Ltd -> Wondershare) FirewallRules: [{22351026-4E96-4968-AF12-A2D791509EFD}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\120.0.2210.144\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{F0D16593-78D6-4CAF-A37D-8F0A264E1936}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{1C13B002-8136-4302-9E02-30596B0F5D1D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{28F88A30-171B-4756-8E9B-AD0C4752FCAE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{7A99F8E6-5E1F-4843-9610-F91D4AB6F708}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{7E3B24E3-BE6D-4B6E-A6B5-6B0C2F9E54DC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{7F698C20-3BAE-4E25-B14C-C13696878533}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{5509E314-F419-43DB-AD9A-EA8663C86C7A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{5B8FA811-3A2C-4472-9CDA-D251F5EA8095}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{0F03EA24-5E0E-479F-A39F-907D3E999756}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{5F62B912-502C-498C-924B-EB2914CEF50F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.229.605.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{9EC927AD-ECA6-4995-810A-6ABD13FCF48E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.111.3607.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{A09BC188-25DE-4AFD-8C1A-47EBD6FB7D56}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.111.3607.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{562D2427-D550-4B02-9883-0AD5D18EDA95}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.111.3607.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{1DD2F426-3DA9-491B-9455-747BF3AF74F5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.111.3607.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{023FB5E4-5CDE-434D-B3F4-02BB3883AAF4}] => (Allow) C:\Users\steph\AppData\Roaming\uTorrent Web\utweb.exe (BitTorrent Inc -> BitTorrent Limited) FirewallRules: [{E0523F78-8178-4B10-832D-E04A34D2C0E7}] => (Allow) C:\Users\steph\AppData\Roaming\uTorrent Web\utweb.exe (BitTorrent Inc -> BitTorrent Limited) FirewallRules: [{BCE8DAC4-8AEF-4F70-874F-33D61B46FDFA}] => (Allow) C:\Program Files (x86)\GOG Galaxy\Games\HoMM 4 Complete\heroes4.exe (The 3DO Company) [Fichier non signé] FirewallRules: [{3A9005D6-F406-4B3F-A51B-28C8C0D6327E}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{A6DDDB96-AE0F-4A8D-B048-1E007BD612B4}] => (Allow) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.) ==================== Points de restauration ========================= 30-01-2024 17:22:35 Removed SmashApp ==================== Éléments en erreur du Gestionnaire de périphériques ============ Name: Contrôleur PCI de communications simplifiées Description: Contrôleur PCI de communications simplifiées Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Acquisition de données PCI et contrôleur de traitement du signal Description: Acquisition de données PCI et contrôleur de traitement du signal Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Contrôleur de bus SM Description: Contrôleur de bus SM Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Périphérique PCI Description: Périphérique PCI Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Erreurs du Journal des événements: ======================== Erreurs Application: ================== Error: (01/31/2024 09:41:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Local Hostname DESKTOP-EBMP54N.local already in use; will try DESKTOP-EBMP54N-2.local instead Error: (01/31/2024 09:41:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 16 DESKTOP-EBMP54N.local. AAAA 2A02:A03F:A123:6400:8D76:E741:1B4D:411A Error: (01/31/2024 09:41:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:85F3:3564:BC8D:1DD8:5353 4 DESKTOP-EBMP54N.local. Addr 192.168.1.30 Error: (01/31/2024 08:48:14 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application : DownloadHelperTray.exe Version du Framework : v4.0.30319 Description : le processus a été arrêté en raison d'une exception non gérée. Informations sur l'exception : System.InvalidOperationException à System.Linq.Enumerable.First[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.Collections.Generic.IEnumerable`1, System.Func`2) à SilentBrowserForms.Form1.KVw6EHj9B() à SilentBrowserForms.Form1.k8vaMQKHH() à System.Threading.ThreadHelper.ThreadStart_Context(System.Object) à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) à System.Threading.ThreadHelper.ThreadStart() Error: (01/30/2024 05:36:24 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Le programme msedge.exe version 121.0.2277.83 a cessé d'interagir avec Windows et a été fermé. Pour voir si plus d'informations sur le problème sont disponibles, vérifiez l'historique des problèmes dans le Panneau de configuration Sécurité et maintenance. ID de processus : 524c Heure de début : 01da537b41125eb7 Heure d'arrêt : 4294967295 Chemin d'accès à l'application : C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe ID de rapport : e1f62298-7b3d-4b30-a0f0-579cb5a35717 Nom complet du package défectueux : ID de l'application relative à un package défectueux : Type de blocage : Top level window is idle Error: (01/30/2024 05:20:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nom de l’application défaillante utweb.exe, version : 1.4.0.5759, horodatage : 0x65721c5b Nom du module défaillant : ntdll.dll, version : 10.0.19041.3693, horodatage : 0x3ab9e7d5 Code d’exception : 0xc0000005 Décalage d’erreur : 0x0005f603 ID du processus défaillant : 0x3a58 Heure de début de l’application défaillante : 0x01da537168658975 Chemin d’accès de l’application défaillante : C:\Users\steph\AppData\Roaming\uTorrent Web\utweb.exe Chemin d’accès du module défaillant: C:\Windows\SYSTEM32\ntdll.dll ID de rapport : fa55e9cc-c64a-44ab-91c5-77d00efe16e7 Nom complet du package défaillant : ID de l’application relative au package défaillant : Erreurs système: ============= Error: (01/31/2024 09:57:12 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Le service Intel(R) Content Protection HECI Service s’est arrêté avec l’erreur : Erreur non spécifiée Error: (01/31/2024 09:41:44 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Le service Intel(R) Content Protection HECI Service s’est arrêté avec l’erreur : Erreur non spécifiée Error: (01/31/2024 09:00:09 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-EBMP54N) Description: Le serveur {49F171DD-B51A-40D3-9A6C-52D674CC729D} ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (01/31/2024 08:47:39 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Le service Intel(R) Content Protection HECI Service s’est arrêté avec l’erreur : Erreur non spécifiée Error: (01/31/2024 08:47:15 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Le service Intel(R) Content Protection HECI Service s’est arrêté avec l’erreur : Erreur non spécifiée Error: (01/31/2024 08:47:09 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-EBMP54N) Description: Le serveur Microsoft.Windows.ContentDeliveryManager_10.0.19041.3636_neutral_neutral_cw5n1h2txyewy!App.AppX447jn8wbjb1qsw3jxkndb19cwgsrtrkk.mca ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (01/30/2024 05:28:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Le service obupdate s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 5000 millisecondes : Redémarrer le service. Windows Defender: ================ Date: 2024-01-31 07:55:12 Description: L’analyse Antivirus Microsoft Defender a été arrêtée avant la fin. ID de l’analyse : {35D23059-AA26-45D1-9242-C1C3E0D35C77} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Date: 2024-01-30 18:29:14 Description: Antivirus Microsoft Defender a détecté un logiciel malveillant ou potentiellement indésirable. Pour plus d’informations, reportez-vous aux éléments suivants : https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0 Nom : Trojan:Win32/Wacatac.H!ml ID : 2147814523 Gravité : Grave Catégorie : Cheval de Troie Chemin : containerfile:_C:\Users\steph\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\4\Attachments\MarcheNoel[847].zip; containerfile:_C:\Users\steph\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\4\Attachments\MarcheNoel[848].zip; file:_C:\Users\steph\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\4\Attachments\MarcheNoel[847].zip->MarcheNoel/MarcheNoel01/Debug/MarcheNoel00.exe; file:_C:\Users\steph\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Files\S0\4\Attachments\MarcheNoel[848].zip->MarcheNoel/MarcheNoel01/Debug/MarcheNoel00.exe Origine de la détection : Ordinateur local Type de détection : Chemin rapide Source de détection : Utilisateur Utilisateur : DESKTOP-EBMP54N\steph Nom du processus : Unknown Version de la veille de sécurité : AV: 1.403.2943.0, AS: 1.403.2943.0, NIS: 1.403.2943.0 Version du moteur : AM: 1.1.23110.2, NIS: 1.1.23110.2 Date: 2024-01-30 18:29:14 Description: Antivirus Microsoft Defender a détecté un logiciel malveillant ou potentiellement indésirable. Pour plus d’informations, reportez-vous aux éléments suivants : https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Crack!pz&threatid=2147890699&enterprise=0 Nom : HackTool:Win32/Crack!pz ID : 2147890699 Gravité : Élevée Catégorie : Outil Chemin : containerfile:_C:\Users\steph\Desktop\stephane\Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9\IGG-Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9.iso; containerfile:_C:\Users\steph\Desktop\stephane\jeux_installation\Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9\IGG-Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9.iso; file:_C:\Program Files (x86)\Ubisoft\Heroes of Might & Magic III - HD Edition\CN_CS\steam_api.dll; file:_C:\Users\steph\Desktop\stephane\Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9\IGG-Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9.iso->PROPHET\CN_CS\steam_api.dll; file:_C:\Users\steph\Desktop\stephane\Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9\IGG-Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9.iso->PROPHET\steam_api.dll; file:_C:\Users\steph\Desktop\stephane\jeux_installation\Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9\IGG-Heroes.of.Might.and.Magic.III.HD.Edition.MULTi9.iso->PROPHET\CN_CS\steam_api.dll; file:_C:\Users\steph\Desktop\stephane\jeux_installation\Heroes.of.Might.an Origine de la détection : Ordinateur local Type de détection : Concret Source de détection : Utilisateur Utilisateur : DESKTOP-EBMP54N\steph Nom du processus : Unknown Version de la veille de sécurité : AV: 1.403.2943.0, AS: 1.403.2943.0, NIS: 1.403.2943.0 Version du moteur : AM: 1.1.23110.2, NIS: 1.1.23110.2 Date: 2024-01-30 18:29:14 Description: Antivirus Microsoft Defender a détecté un logiciel malveillant ou potentiellement indésirable. Pour plus d’informations, reportez-vous aux éléments suivants : https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AutoKMS&threatid=2147685180&enterprise=0 Nom : HackTool:Win32/AutoKMS ID : 2147685180 Gravité : Élevée Catégorie : Outil Chemin : file:_C:\Program Files\KMSpico\scripts\Install_Service.cmd; file:_C:\Program Files\KMSpico\scripts\Install_Task.cmd; file:_C:\Program Files\KMSpico\scripts\UnInstall_Service.cmd Origine de la détection : Ordinateur local Type de détection : Concret Source de détection : Utilisateur Utilisateur : DESKTOP-EBMP54N\steph Nom du processus : Unknown Version de la veille de sécurité : AV: 1.403.2943.0, AS: 1.403.2943.0, NIS: 1.403.2943.0 Version du moteur : AM: 1.1.23110.2, NIS: 1.1.23110.2  CodeIntegrity: =============== Date: 2024-01-31 21:56:43 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2024-01-31 21:45:20 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_3016c0527f191034\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Infos Mémoire =========================== BIOS: FUJITSU // Insyde Software Corp. Version 2.12 10/04/2019 Carte mère: FUJITSU FJNB2CA Processeur: Intel(R) Core(TM) i7-8565U CPU @ 1.80GHz Pourcentage de mémoire utilisée: 53% Mémoire physique - RAM - totale: 16058.49 MB Mémoire physique - RAM - disponible: 7507.54 MB Mémoire virtuelle totale: 27779.89 MB Mémoire virtuelle disponible: 18158.08 MB ==================== Lecteurs ================================ Drive c: () (Fixed) (Total:237.86 GB) (Free:13.88 GB) (Model: SAMSUNG MZVLB256HAHQ-00007) (Protected) NTFS \\?\Volume{eded2059-e108-408c-a0f2-93ac77b8970f}\ () (Fixed) (Total:0.5 GB) (Free:0.08 GB) NTFS \\?\Volume{d47f47eb-8ea0-49ec-a0f4-d17544ef4654}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Table des partitions ==================== ========================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: 6A311F5D) Partition: GPT. ==================== Fin de Addition.txt =======================