Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 08.11.2018 Exécuté par k0reD (10-11-2018 09:44:03) Exécuté depuis C:\Users\k0reD\Desktop Windows 10 Home Version 1803 17134.286 (X64) (2018-08-28 19:53:41) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= Administrateur (S-1-5-21-2157465606-1905210227-2452084031-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2157465606-1905210227-2452084031-503 - Limited - Disabled) Invité (S-1-5-21-2157465606-1905210227-2452084031-501 - Limited - Disabled) k0reD (S-1-5-21-2157465606-1905210227-2452084031-1001 - Administrator - Enabled) => C:\Users\k0reD WDAGUtilityAccount (S-1-5-21-2157465606-1905210227-2452084031-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: COMODO Firewall (Enabled) {3083CA8D-8618-5BD3-8A5F-9667D5C8267D} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) 4Story FR 5.3.273 (HKLM-x32\...\4Story_FR_is1) (Version: 5.3.273 - Gameforge4D GmbH) 7-Zip 18.05 (x64) (HKLM\...\7-Zip) (Version: 18.05 - Igor Pavlov) Adobe Flash Player 31 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 31.0.0.122 - Adobe Systems Incorporated) Apple Application Support (32 bits) (HKLM-x32\...\{308F2F8C-9D33-4B22-8A6C-D9C13DBEF8C6}) (Version: 7.0.2 - Apple Inc.) Apple Application Support (64 bits) (HKLM\...\{0CB84A7D-9697-4526-A819-60FB050E8F05}) (Version: 7.0.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{77F8C879-88CD-4145-945A-541C35285285}) (Version: 12.0.0.1039 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.) Araz4Story PvP 5.1 (HKLM-x32\...\Araz4Story PvP 5.1) (Version: 5.1 - Araz Games) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Classic Shell (HKLM\...\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft) COMODO Firewall (HKLM\...\{C10F36A6-C6A4-4027-9219-25E273B751E1}) (Version: 11.0.0.6606 - COMODO Security Solutions Inc.) Hidden COMODO Firewall (HKLM\...\COMODO Internet Security) (Version: 11.0.0.6606 - COMODO Security Solutions Inc.) Discord (HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\Discord) (Version: 0.0.301 - Discord Inc.) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 411.63 - NVIDIA Corporation) Hidden Dolby Audio X2 Windows API SDK (HKLM\...\{F994125B-7BF5-4A38-A569-82833CEB24DC}) (Version: 0.8.4.83 - Dolby Laboratories, Inc.) Epic Games Launcher (HKLM-x32\...\{A98163A6-4350-4195-AB3B-8A5BA4B6C7D8}) (Version: 1.1.163.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Gameforge Live 2.0.13 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.13 - Gameforge) Glary Utilities PRO 5.108 (HKLM-x32\...\Glary Utilities 5) (Version: 5.108.0.133 - Glarysoft Ltd) HxD Hex Editor 2.0 (HKLM\...\HxD_is1) (Version: 2.0 - Maël Hörz) Internet Security Essentials (HKLM-x32\...\ComodoIse) (Version: 1.3.453193.152 - Comodo) iTunes (HKLM\...\{07A7CE9A-1131-4B53-BB1D-5B7F35970DF7}) (Version: 12.9.0.167 - Apple Inc.) KeePass Password Safe 2.40 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.40 - Dominik Reichl) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation) Mises à jour NVIDIA 33.2.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 33.2.0.0 - NVIDIA Corporation) Hidden Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.5.8 - Notepad++ Team) NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.11 - NVIDIA Corporation) Hidden NVIDIA GeForce Experience 3.15.0.186 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.15.0.186 - NVIDIA Corporation) NVIDIA Logiciel système PhysX 9.18.0907 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.18.0907 - NVIDIA Corporation) NVIDIA Pilote 3D Vision 411.63 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 411.63 - NVIDIA Corporation) NVIDIA Pilote audio HD : 1.3.37.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.37.5 - NVIDIA Corporation) NVIDIA Pilote du contrôleur 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) NVIDIA Pilote graphique 411.63 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 411.63 - NVIDIA Corporation) Opera Stable 56.0.3051.52 (HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\Opera 56.0.3051.52) (Version: 56.0.3051.52 - Opera Software) Panneau de configuration NVIDIA 411.63 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 411.63 - NVIDIA Corporation) Hidden Pingzapper version 2.1.3 (HKLM-x32\...\{7FD61982-5436-439B-B5D0-36F0536FF8BF}_is1) (Version: 2.1.3 - Pingzapper) PrivaZer (HKLM-x32\...\PrivaZer) (Version: 3.0.55.0 - Goversoft LLC) PuTTY release 0.70 (64-bit) (HKLM\...\{45B3032F-22CC-40CD-9E97-4DA7095FA5A2}) (Version: 0.70.0.0 - Simon Tatham) Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.2 r3111 - Rainmeter) Razer Chroma SDK Core Components (HKLM-x32\...\Razer Chroma SDK) (Version: 2.10.0 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.20.606 - Razer Inc.) Revo Uninstaller Pro 4.0.1 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 4.0.1 - VS Revo Group, Ltd.) Simple DNSCrypt x64 (HKLM\...\{5AE8E892-624A-4CEE-99FE-F0B75180D774}) (Version: 0.5.8 - bitbeans) Spotify (HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\Spotify) (Version: 1.0.92.390.g2ce5ec7d - Spotify AB) SRWare Iron version 69.0.3600.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: 69.0.3600.0 - SRWare) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.2.2 - TeamSpeak Systems GmbH) UltraUXThemePatcher (HKLM-x32\...\UltraUXThemePatcher) (Version: 3.3.4.0 - Manuel Hoefs (Zottel)) USBPcap 1.2.0.4 (HKLM\...\USBPcap) (Version: 1.2.0.4 - Tomasz Mon) Winaero Tweaker (HKLM\...\Winaero Tweaker_is1) (Version: 0.11.2.0 - Winaero) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinSCP 5.13.4 (HKLM-x32\...\winscp3_is1) (Version: 5.13.4 - Martin Prikryl) Wireshark 2.6.4 64-bit (HKLM-x32\...\Wireshark) (Version: 2.6.4 - The Wireshark developer community, hxxps://www.wireshark.org) ==================== Personnalisé CLSID (Avec liste blanche): ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Pas de fichier ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (IvoSoft) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> Pas de fichier ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (IvoSoft) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2018-07-23] () ContextMenuHandlers1: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2018-06-18] (COMODO) ContextMenuHandlers1: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu5.dll [2018-08-31] () ContextMenuHandlers2: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2018-06-18] (COMODO) ContextMenuHandlers2: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu5.dll [2018-08-31] () ContextMenuHandlers2: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => C:\Program Files (x86)\VMware\VMware Workstation\x64\vmdkShellExt64.dll [2018-08-07] (VMware, Inc.) ContextMenuHandlers3: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu5.dll [2018-08-31] () ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) ContextMenuHandlers4: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu5.dll [2018-08-31] () ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_e8abe176c7b553b5\igfxDTCM.dll [2018-08-08] (Intel Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-09-18] (NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) ContextMenuHandlers6: [Comodo Antivirus] -> {4255A182-CAD9-4214-A19B-7BA7FB633BBD} => C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll [2018-06-18] (COMODO) ContextMenuHandlers6: [PrivaZer] -> {7691BE2F-3D79-AADE-9C87-4D6EBCC76682} => C:\Program Files (x86)\PrivaZer\PrivaMenu5.dll [2018-08-31] () ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2018-09-06] (VS Revo Group) ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\system32\StartMenuHelper64.dll [2018-07-15] (IvoSoft) FolderExtensions: [] -> {27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5} => D:\Thèmes cleo\Aero Dark ThemeWin10 April 1803up1\OldNewExplorer\OldNewExplorer64.dll [2017-08-16] (www.startisback.com) ==================== Tâches planifiées (Avec liste blanche) ============= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) Task: {09C70950-FA7B-49E5-AAF7-0C736393B050} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-10-10] (NVIDIA Corporation) Task: {0EC7ED1B-17F0-4898-BC5F-1C7E13D39808} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_122_pepper.exe [2018-10-16] (Adobe Systems Incorporated) Task: {13C19585-28E7-423A-A231-0CE241F15361} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] () Task: {175B84EA-9C7B-4E6B-90CE-3E6A6434F051} - System32\Tasks\S-1-5-21-2157465606-1905210227-2452084031-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-04-11] (Microsoft Corporation) Task: {20C7EF5F-BC67-4DBE-917C-230C10ADB4BA} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-10-16] (Adobe Systems Incorporated) Task: {28A11849-D0AE-4C73-B7DB-8AC8FB5F3DC8} - System32\Tasks\Opera scheduled Autoupdate 1538425357 => C:\Users\k0reD\AppData\Local\Programs\Opera\launcher.exe [2018-10-17] (Opera Software) Task: {2FA6A583-863F-4E85-8E50-F8D5028E837D} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-10-10] (NVIDIA Corporation) Task: {31E4696F-2348-481E-ADA3-B16648AE75FF} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-10-10] (NVIDIA Corporation) Task: {36C4A082-51C1-4760-9907-0C52ADB066D7} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK Task: {46420DA3-9E00-4CC2-9855-DFD9A1B85AA3} - System32\Tasks\PrivaZer_SkipUAC => C:\Program Files (x86)\PrivaZer\PrivaZer.exe [2018-11-01] (Goversoft LLC) Task: {4BA949F1-08C5-457F-8BF8-C05D0C8D78D1} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-10-10] (NVIDIA Corporation) Task: {8706AA93-DAC2-4A89-8C73-6F59D160881F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.) Task: {8729BF53-487D-4F3E-8737-CC0E9EA14AB9} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-06-18] (COMODO) Task: {8AC061AD-DD37-4BD9-A13C-0D13B747A6DF} - System32\Tasks\COMODO\COMODO Telemetry {18AD3DFA-30C0-4B5F-84F7-F1870B1A4921} => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [2018-06-18] (COMODO) Task: {926BC42C-6146-429F-B510-F79E591821BF} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-10-10] (NVIDIA Corporation) Task: {9CA6B7DA-32A8-457C-9DF3-6C27122B8CBA} - System32\Tasks\GlaryUpdate 5 => C:\Program Files (x86)\Glary Utilities 5\CheckUpdate.exe [2018-10-29] (Glarysoft Ltd) Task: {A2930DEB-3DBF-4308-AA91-4A64383920CA} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-10-10] (NVIDIA Corporation) Task: {ADA26D96-F4BE-4BA2-BECF-79E34C924BD4} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-10-10] (NVIDIA Corporation) Task: {BB705517-0306-4C0C-9529-8EE4193CB5EE} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-06-18] (COMODO) Task: {BB8468EE-0DAD-4F82-9931-02DE80AEA12A} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-10-10] (NVIDIA Corporation) Task: {BE68EEA7-82E5-4B3D-A7B7-E0C4C0E457E4} - System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-06-18] (COMODO) Task: {D07A9C7F-9F7E-4E5C-BEB2-0109FC204FBB} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-10-10] (NVIDIA Corporation) Task: {D1A47C99-5DC4-47E0-A02F-7C027C144767} - System32\Tasks\COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2018-06-18] (COMODO) Task: {DC148F50-8F8B-4C35-AAC6-BE313CFBD8F4} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-10-10] (NVIDIA Corporation) Task: {E03BC116-1C87-4D2F-A7D2-180E13418855} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2018-06-18] (COMODO) Task: {EF325CDD-B76B-4308-A56B-91B51FC78162} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-10-10] (NVIDIA Corporation) (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.) ==================== Raccourcis & WMI ======================== (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) ==================== Modules chargés (Avec liste blanche) ============== 2018-08-22 21:18 - 2018-08-22 21:18 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2018-08-22 21:18 - 2018-08-22 21:18 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2018-07-09 18:23 - 2018-07-09 18:23 - 006314648 _____ () C:\Program Files\bitbeans\Simple DNSCrypt x64\dnscrypt-proxy\dnscrypt-proxy.exe 2018-09-12 21:16 - 2016-05-22 13:27 - 000632320 ___SH () C:\Program Files (x86)\Pingzapper\PZService.exe 2018-09-21 13:06 - 2018-10-10 20:04 - 001314856 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-06-18 22:43 - 2018-06-18 22:43 - 000107200 _____ () C:\Program Files\COMODO\COMODO Internet Security\cavwpps.dll 2018-06-18 22:44 - 2018-06-18 22:44 - 000245952 _____ () C:\Program Files\COMODO\COMODO Internet Security\cmdcomps.dll 2018-04-11 23:34 - 2018-04-11 23:34 - 000491744 ____N () C:\WINDOWS\SYSTEM32\inputhost.dll 2018-04-11 23:34 - 2018-04-11 23:34 - 000472064 ____N () C:\Windows\ShellExperiences\TileControl.dll 2018-04-11 23:34 - 2018-04-11 23:34 - 002759168 ____N () C:\Windows\ShellComponents\TaskFlowUI.dll 2018-06-18 22:45 - 2018-06-18 22:45 - 000158912 _____ () C:\Program Files\COMODO\COMODO Internet Security\cmdwrhlp.dll 2018-09-21 13:06 - 2018-10-10 20:03 - 101252136 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2018-09-21 13:06 - 2018-10-10 20:03 - 004619816 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libglesv2.dll 2018-09-21 13:06 - 2018-10-10 20:03 - 000108584 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libegl.dll 2017-07-29 02:45 - 2017-07-29 02:45 - 000298448 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe 2018-09-21 13:06 - 2018-10-10 20:04 - 001032744 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-05-08 11:53 - 2018-05-08 11:53 - 000143824 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2018-08-29 14:39 - 2017-09-08 21:22 - 050656768 _____ () C:\Users\k0reD\AppData\Local\razer\InGameEngine\cache\RzSynapse\cef\libcef.dll 2018-08-29 14:39 - 2017-09-08 21:22 - 050656768 _____ () C:\Users\k0reD\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll 2018-08-29 14:39 - 2017-09-08 21:22 - 001874944 _____ () C:\Users\k0reD\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll 2018-08-29 14:39 - 2017-09-08 21:22 - 000075264 _____ () C:\Users\k0reD\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll 2018-08-29 14:39 - 2017-09-08 21:22 - 001874944 _____ () C:\Users\k0reD\AppData\Local\razer\InGameEngine\cache\RzSynapse\cef\libglesv2.dll 2018-08-29 14:39 - 2017-09-08 21:22 - 000075264 _____ () C:\Users\k0reD\AppData\Local\razer\InGameEngine\cache\RzSynapse\cef\libegl.dll 2018-08-28 22:53 - 2018-10-08 14:49 - 004313224 _____ () C:\Program Files (x86)\SRWare Iron\libglesv2.dll 2018-08-28 22:53 - 2018-10-08 14:49 - 000095880 _____ () C:\Program Files (x86)\SRWare Iron\libegl.dll ==================== Alternate Data Streams (Avec liste blanche) ========= (Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.) ==================== Mode sans échec (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.) ==================== Association (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.) ==================== Internet Explorer sites de confiance/sensibles =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.) ==================== Hosts contenu: ========================== (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2018-08-28 17:39 - 2018-09-28 20:59 - 000046685 _____ C:\WINDOWS\system32\Drivers\etc\hosts 0.0.0.0 a.ads1.msn.com 0.0.0.0 a.ads2.msn.com 0.0.0.0 a23-218-212-69.deploy.static.akamaitechnologies.com 0.0.0.0 a248.e.akamai.net 0.0.0.0 a1961.g.akamai.net 0.0.0.0 a1856.g2.akamai.net 0.0.0.0 a1621.g.akamai.net 0.0.0.0 ads.msn.com 0.0.0.0 ads.msn.com.nsatc.net 0.0.0.0 ads1.msn.com 0.0.0.0 ads1.msads.net 0.0.0.0 adnexus.net 0.0.0.0 adnxs.com 0.0.0.0 az361816.vo.msecnd.net 0.0.0.0 az512334.vo.msecnd.net 0.0.0.0 choice.microsoft.com 0.0.0.0 choice.microsoft.com.nsatc.net 0.0.0.0 compatexchange.cloudapp.net 0.0.0.0 corpext.msitadfs.glbdns2.microsoft.com 0.0.0.0 cdnjs.cloudflare.com.cdn.cloudflare.net 0.0.0.0 cs1.wpc.v0cdn.net 0.0.0.0 cdp1.public-trust.com 0.0.0.0 corp.sts.microsoft.com 0.0.0.0 diagnostics.support.microsoft.com 0.0.0.0 df.telemetry.microsoft.com 0.0.0.0 e2835.dspb.akamaiedge.net 0.0.0.0 e8218.ce.akamaiedge.net 0.0.0.0 e7341.g.akamaiedge.net 0.0.0.0 e7502.ce.akamaiedge.net 0.0.0.0 feedback.windows.com Il y a 1381 plus de lignes. ==================== Autres zones ============================ (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\Control Panel\Desktop\\Wallpaper -> D:\C;Images\All Desktop\Fond d'écran\téléchargement (3).jpg DNS Servers: 127.0.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Le Pare-feu est activé. ==================== MSCONFIG/TASK MANAGER éléments désactivés == Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé. MSCONFIG\Services: AESMService => 2 MSCONFIG\Services: Apple Mobile Device Service => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: cmdvirth => 3 MSCONFIG\Services: cphs => 3 MSCONFIG\Services: cplspcon => 2 MSCONFIG\Services: Dolby DAX2 API Service => 2 MSCONFIG\Services: iaStorAfsService => 3 MSCONFIG\Services: igfxCUIService2.0.0.0 => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: npggsvc => 3 MSCONFIG\Services: Razer Chroma SDK Server => 2 MSCONFIG\Services: Razer Chroma SDK Service => 2 MSCONFIG\Services: Razer Game Scanner Service => 2 MSCONFIG\Services: RstMwService => 2 MSCONFIG\Services: VMAuthdService => 2 MSCONFIG\Services: VMnetDHCP => 2 MSCONFIG\Services: VMUSBArbService => 2 MSCONFIG\Services: VMware NAT Service => 2 MSCONFIG\Services: VMwareHostd => 2 HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "SynTPEnh" HKLM\...\StartupApproved\Run: => "RtHDVBg_Dolby" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run32: => "4StoryPrePatch" HKLM\...\StartupApproved\Run32: => "Kraken0502Launcher" HKLM\...\StartupApproved\Run32: => "vmware-tray.exe" HKLM\...\StartupApproved\Run32: => "IseUI" HKLM\...\StartupApproved\Run32: => "KeePass 2 PreLoad" HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\StartupApproved\StartupFolder: => "Rainmeter.lnk" HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\StartupApproved\Run: => "EpicGamesLauncher" HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning" HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\StartupApproved\Run: => "NordVPN" HKU\S-1-5-21-2157465606-1905210227-2452084031-1001\...\StartupApproved\Run: => "GUDelayStartup" ==================== RèglesPare-feu (Avec liste blanche) =============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [TCP Query User{C034F47E-5F5B-4927-A440-797836FDB1B8}C:\users\k0red\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\k0red\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{A3BF88BC-5522-4E4C-9993-EDAA18036D73}C:\users\k0red\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\k0red\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{A25182A6-4BFA-4925-A27B-ADEAC88F69CC}C:\program files\rainmeter\rainmeter.exe] => (Allow) C:\program files\rainmeter\rainmeter.exe FirewallRules: [UDP Query User{06D7D99B-E722-47FD-8B7E-6A4F233AEC1D}C:\program files\rainmeter\rainmeter.exe] => (Allow) C:\program files\rainmeter\rainmeter.exe FirewallRules: [{2F062E21-9D8F-4E34-8AFB-8E8C33EF3D56}] => (Allow) C:\Program Files (x86)\GameforgeLive\gfl_client.exe FirewallRules: [{60E6D465-398E-4850-BE86-7EF7620A2377}] => (Block) C:\windows\system32\svchost.exe FirewallRules: [TCP Query User{B4980DF0-7CA3-4128-99D8-1E81D6F436DB}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [UDP Query User{2B356415-D705-4B60-9744-082C839A1B58}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [TCP Query User{F1B469C8-DCE4-4CE9-91D8-DE9649C30398}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{69F8CFAB-27FA-4AB8-BB93-2DADDE72A7B9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [TCP Query User{9692B736-0116-42CB-852B-BF6A69F0E662}C:\program files (x86)\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files (x86)\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [UDP Query User{0F9D29D4-C10F-4849-A4A9-73DC82FB151E}C:\program files (x86)\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files (x86)\fortnite\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [{2765E0F4-2918-4A46-B9C9-43CDD8FCBA2B}] => (Block) C:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe FirewallRules: [{085F97C0-6782-4B0A-BCC3-A9E3760D03F2}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe FirewallRules: [{195395E8-4182-4004-8658-96E6A31363C1}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe FirewallRules: [{76F864CA-8D32-4D40-A614-95D65558F53C}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe FirewallRules: [{A97D734E-C94C-4DFD-98D8-D1AE6E17931B}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe FirewallRules: [{1F12B1DA-2327-41C1-9D46-529A90568772}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{770422B9-AC55-4516-8398-B864B80D354D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{65A8942F-CD05-4DDB-8F57-FB18580C8788}] => (Block) C:\Windows\explorer.exe FirewallRules: [{80CE615A-C306-491D-A91A-D1B5F160BED0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{A88A2299-7C16-4ADB-933A-97E56EC7ACDF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{5450C45B-D92E-4A3E-9E31-22123DF78990}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{7D52B3DA-C65B-4890-816C-90B434EE167D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{9653DEF1-D976-4319-8DD5-D8E994ACEF67}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe FirewallRules: [{FEC0562A-8B6A-421E-98DB-3936499E117F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{35451992-1D46-417B-A493-F3051D96659F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{69D0F693-7D31-4DBF-9FAB-ACA79A3F94F1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E70EEB10-B480-4501-9BD5-994381A764EB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{3061F247-1402-4F47-82EC-149F83EBEA3E}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Points de restauration ========================= 02-11-2018 20:30:27 Point de contrôle planifié 03-11-2018 18:52:20 Installed DriversCloud.com (64 bits) 08-11-2018 18:16:33 Revo Uninstaller Pro's restore point - Adobe Flash Player 31 PPAPI 08-11-2018 18:17:28 Revo Uninstaller Pro's restore point - Glary Utilities PRO 5.108 08-11-2018 18:18:16 Revo Uninstaller Pro's restore point - Internet Security Essentials 08-11-2018 18:18:55 Revo Uninstaller Pro's restore point - CCleaner 08-11-2018 23:19:25 Revo Uninstaller Pro's restore point - Discord 08-11-2018 23:29:09 Revo Uninstaller Pro's restore point - Discord 09-11-2018 18:58:51 Revo Uninstaller Pro's restore point - Discord Canary 09-11-2018 20:07:40 Restore Point Created by FRST 10-11-2018 09:34:17 Revo Uninstaller Pro's restore point - CCleaner ==================== Éléments en erreur du Gestionnaire de périphériques ============= Name: WAN Miniport (PPPOE) Description: Miniport WAN (PPPOE) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: RasPppoe Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: VMware Virtual Ethernet Adapter for VMnet1 Description: VMware Virtual Ethernet Adapter for VMnet1 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: VMware, Inc. Service: VMnetAdapter Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: VMware Virtual Ethernet Adapter for VMnet8 Description: VMware Virtual Ethernet Adapter for VMnet8 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: VMware, Inc. Service: VMnetAdapter Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: WAN Miniport (PPTP) Description: Miniport WAN (PPTP) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: PptpMiniport Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Compteur d'événement de haute précision Description: Compteur d'événement de haute précision Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: (Périphériques système standard) Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Intel(R) Pinning Shell Extensions Description: Intel(R) Pinning Shell Extensions Class Guid: {5c4c3332-344d-483c-8739-259e934c9cc8} Manufacturer: Intel Corporation Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: WAN Miniport (Network Monitor) Description: Miniport WAN (moniteur réseau) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: NdisWan Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Intel(R) Software Guard Extensions Software Description: Intel(R) Software Guard Extensions Platform Software Component Class Guid: {5c4c3332-344d-483c-8739-259e934c9cc8} Manufacturer: (Standard system devices) Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Contrôleur High Definition Audio Description: Contrôleur High Definition Audio Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HDAudBus Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Contrôleur High Definition Audio Description: Contrôleur High Definition Audio Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HDAudBus Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: VMware VMCI Host Device Description: VMware VMCI Host Device Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: VMware, Inc. Service: vmci Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: NVIDIA Virtual Audio Device (Wave Extensible) (WDM) Description: NVIDIA Virtual Audio Device (Wave Extensible) (WDM) Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: NVIDIA Service: nvvad_WaveExtensible Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Realtek Bluetooth Adapter Description: Realtek Bluetooth Adapter Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Realtek Semiconductor Corp. Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: WAN Miniport (IPv6) Description: Miniport WAN (IPv6) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: NdisWan Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: WAN Miniport (L2TP) Description: Miniport WAN (L2TP) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: Rasl2tp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Erreurs du Journal des événements: ========================= Erreurs Application: ================== Error: (11/10/2018 09:34:17 AM) (Source: VSS) (EventID: 8194) (User: ) Description: Erreur du service de cliché instantané des volumes : erreur lors de l’interrogation de l’interface IVssWriterCallback. hr = 0x80070005, Accès refusé. . Cette erreur est souvent due à des paramètres de sécurité incorrects dans le processus du rédacteur ou du demandeur. Opération : Données du rédacteur en cours de collecte Contexte : ID de classe du rédacteur: {e8132975-6f93-4464-a53e-1050253ae220} Nom du rédacteur: System Writer ID d’instance du rédacteur: {f5fdef6a-0ec5-4751-b4e2-ee7313af7433} Error: (11/10/2018 09:28:55 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0x80072EE7 Arguments de la ligne de commande : RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0567073a-7d74-403b-b2d5-6b35da372d8d;NotificationInterval=1440;Trigger=TimerEvent Error: (11/10/2018 09:28:55 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: L’acquisition de la licence d’utilisateur final a échoué. hr=0x80072EE7 Id Sku=0567073a-7d74-403b-b2d5-6b35da372d8d Error: (11/10/2018 09:28:55 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Détails de l’échec d’acquisition de la licence. hr=0x80072EE7 Error: (11/10/2018 09:28:51 AM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\KOZX$ via https://INTC-KeyId-5e73c89aa3e902b272b9f0741f7d8730e3ec724a.microsoftaik.azure.net/templates/Aik/scep : GetCACaps Méthode : GET(12078ms) Étape : GetCACaps L’adresse ou le nom de serveur n’a pas pu être résolu 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED) Error: (11/10/2018 09:28:43 AM) (Source: Software Protection Platform Service) (EventID: 1014) (User: ) Description: L’acquisition de la licence d’utilisateur final a échoué. hr=0x80072EE7 Id Sku=0567073a-7d74-403b-b2d5-6b35da372d8d Error: (11/10/2018 09:28:43 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Détails de l’échec d’acquisition de la licence. hr=0x80072EE7 Error: (11/10/2018 09:28:32 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: Échec de l’activation des licences (slui.exe) avec le code d’erreur suivant : hr=0xC004E028 Arguments de la ligne de commande : RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=0567073a-7d74-403b-b2d5-6b35da372d8d;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Erreurs système: ============= Error: (11/10/2018 09:29:28 AM) (Source: DCOM) (EventID: 10016) (User: KOZX) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID KOZX\k0reD de l’utilisateur (S-1-5-21-2157465606-1905210227-2452084031-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (11/10/2018 09:29:22 AM) (Source: DCOM) (EventID: 10016) (User: KOZX) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID KOZX\k0reD de l’utilisateur (S-1-5-21-2157465606-1905210227-2452084031-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (11/10/2018 09:28:41 AM) (Source: DCOM) (EventID: 10010) (User: KOZX) Description: Le serveur Microsoft.Windows.Cortana_1.10.7.17134_neutral_neutral_cw5n1h2txyewy!CortanaUI ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (11/10/2018 09:28:39 AM) (Source: DCOM) (EventID: 10010) (User: KOZX) Description: Le serveur Microsoft.Windows.Cortana_1.10.7.17134_neutral_neutral_cw5n1h2txyewy!CortanaUI ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (11/10/2018 09:28:35 AM) (Source: DCOM) (EventID: 10010) (User: KOZX) Description: Le serveur Microsoft.Windows.Cortana_1.10.7.17134_neutral_neutral_cw5n1h2txyewy!CortanaUI ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (11/10/2018 09:23:23 AM) (Source: DCOM) (EventID: 10016) (User: KOZX) Description: Les paramètres d’autorisation propres à l’application n’accordent pas l’autorisation Local Activation pour l’application serveur COM avec le CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} et l’APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} au SID KOZX\k0reD de l’utilisateur (S-1-5-21-2157465606-1905210227-2452084031-1001) depuis l’adresse LocalHost (avec LRPC) s’exécutant dans le SID Non disponible du conteneur d’applications (Non disponible). Cette autorisation de sécurité peut être modifiée à l’aide de l’outil d’administration Services de composants. Error: (11/10/2018 09:19:58 AM) (Source: DCOM) (EventID: 10010) (User: KOZX) Description: Le serveur Microsoft.Windows.Cortana_1.10.7.17134_neutral_neutral_cw5n1h2txyewy!CortanaUI ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Error: (11/10/2018 09:19:56 AM) (Source: DCOM) (EventID: 10010) (User: KOZX) Description: Le serveur Microsoft.Windows.Cortana_1.10.7.17134_neutral_neutral_cw5n1h2txyewy!CortanaUI ne s’est pas enregistré sur DCOM avant la fin du temps imparti. Windows Defender: =================================== Date: 2018-08-30 18:01:41.126 Description: L’analyse Antivirus Windows Defender a été arrêtée avant la fin. ID de l’analyse : {2561FF22-CA1B-42A8-83E8-EB2046CE5288} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Date: 2018-08-30 16:36:36.727 Description: L’analyse Antivirus Windows Defender a été arrêtée avant la fin. ID de l’analyse : {D9A82B58-FB3C-4CC6-B8EC-ECA180C21027} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Date: 2018-08-30 14:54:33.868 Description: L’analyse Antivirus Windows Defender a été arrêtée avant la fin. ID de l’analyse : {82267E11-78F8-4783-A2F6-4C4E9C3091EC} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Date: 2018-08-30 13:42:57.778 Description: L’analyse Antivirus Windows Defender a été arrêtée avant la fin. ID de l’analyse : {1EEA373B-4D4C-4ADE-9B49-F39E5C3B710A} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système CodeIntegrity: =================================== Date: 2018-11-10 09:43:23.585 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-11-10 09:43:23.584 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-11-10 09:43:23.103 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-11-10 09:43:23.102 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-11-10 09:43:22.904 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-11-10 09:43:22.902 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-11-10 09:43:22.525 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2018-11-10 09:43:22.524 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Infos Mémoire =========================== Processeur: Intel(R) Core(TM) i5-7400 CPU @ 3.00GHz Pourcentage de mémoire utilisée: 35% Mémoire physique - RAM - totale: 8068.05 MB Mémoire physique - RAM - disponible: 5176.78 MB Mémoire virtuelle totale: 12668.05 MB Mémoire virtuelle disponible: 7887.43 MB ==================== Lecteurs ================================ Drive c: (Système) (Fixed) (Total:221.98 GB) (Free:147.51 GB) NTFS Drive d: (Files) (Fixed) (Total:909.18 GB) (Free:693.97 GB) NTFS \\?\Volume{dfc435c3-8bd9-4b6d-8f0a-2ac4f8faa76e}\ (Récupération) (Fixed) (Total:0.49 GB) (Free:0.47 GB) NTFS \\?\Volume{cce4b817-b71b-4f2f-8344-24a43fcbd695}\ () (Fixed) (Total:0.88 GB) (Free:0.33 GB) NTFS \\?\Volume{72798ead-7c6d-403c-b5ee-98f5fbefdbc6}\ (WinRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.57 GB) NTFS \\?\Volume{95b1ab05-6e4c-4249-b923-bd55a48cfecc}\ (LENOVO_PART) (Fixed) (Total:20 GB) (Free:6.78 GB) NTFS \\?\Volume{c62e7631-559f-4bd1-973f-557c78c1c231}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 \\?\Volume{9f9c4ba2-ab28-4bd6-b446-bd604ef8f2d5}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32 ==================== MBR & Table des partitions ================== ======================================================== Disk: 0 (Size: 223.6 GB) (Disk ID: 3B35A373) Partition: GPT. ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: B47B5C90) Partition: GPT. ==================== Fin de Addition.txt ============================