Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 22-08.2024 Exécuté par jacqu (03-09-2024 09:04:14) Exécuté depuis C:\Users\jacqu\Downloads Microsoft Windows 11 Famille Version 24H2 26120.1542 (X64) (2024-04-06 07:49:38) Mode d'amorçage: Normal ========================================================== ==================== Comptes: ============================= (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) Administrateur (S-1-5-21-2611112945-1519522136-3444468991-500 - Administrator - Disabled) chant (S-1-5-21-2611112945-1519522136-3444468991-1002 - Limited - Enabled) => C:\Users\chant DefaultAccount (S-1-5-21-2611112945-1519522136-3444468991-503 - Limited - Disabled) Invité (S-1-5-21-2611112945-1519522136-3444468991-501 - Limited - Disabled) jacqu (S-1-5-21-2611112945-1519522136-3444468991-1001 - Administrator - Enabled) => C:\Users\jacqu WDAGUtilityAccount (S-1-5-21-2611112945-1519522136-3444468991-504 - Limited - Disabled) ==================== Centre de sécurité ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Programmes installés ====================== (Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.) Amazon Appstore (HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\...\com.amazon.venezia) (Version: release-60.09.1.0.207035.0_209610 - amazon.com) Bel Atout 6.53 (HKLM-x32\...\BelAtoutFr_is1) (Version: - Vincent Brévart) CCleaner (HKLM\...\CCleaner) (Version: 6.27 - Piriform) Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 128.0.6613.114 - Google LLC) Google Earth Pro (HKLM-x32\...\{F8CAED34-88F3-477B-B459-1CE05F087875}) (Version: 7.3.6.9796 - Google) Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 4.1.22.0 - Lenovo Group Ltd.) Lenovo Voice Service (HKLM\...\{C59A85F5-DB04-4D09-BE1F-1B49B49EA9DA}_is1) (Version: 2.5.42.0 - Lenovo Group Ltd.) Lenovo Welcome (HKLM-x32\...\Lenovo Welcome) (Version: 3.6.1.2 - Lenovo Group Ltd.) Microsoft .NET Host - 6.0.26 (x64) (HKLM\...\{87EBA554-A002-4EF4-A612-4FFD06092B5B}) (Version: 48.104.7000 - Microsoft Corporation) Hidden Microsoft .NET Host FX Resolver - 6.0.26 (x64) (HKLM\...\{D81A418F-966D-4069-B3E8-5EE4843CA862}) (Version: 48.104.7000 - Microsoft Corporation) Hidden Microsoft .NET Runtime - 6.0.26 (x64) (HKLM\...\{1A02C1B1-05BB-49F7-9DFF-99A66C6877FC}) (Version: 48.104.7000 - Microsoft Corporation) Hidden Microsoft 365 - fr-fr (HKLM\...\O365HomePremRetail - fr-fr) (Version: 16.0.18025.20006 - Microsoft Corporation) Microsoft ASP.NET Core 6.0.26 - Shared Framework (x64) (HKLM-x32\...\{fc672bf5-721d-4dd3-98e9-c9ffcf762507}) (Version: 6.0.26.23605 - Microsoft Corporation) Microsoft ASP.NET Core 6.0.26 Shared Framework (x64) (HKLM\...\{ED755FBF-3CAE-3206-A32D-16E67F7CC9A3}) (Version: 6.0.26.23605 - Microsoft Corporation) Hidden Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 129.0.2792.12 - Microsoft Corporation) Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 128.0.2739.54 - Microsoft Corporation) Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 24.166.0818.0002 - Microsoft Corporation) Microsoft OneNote - fr-fr (HKLM\...\OneNoteFreeRetail - fr-fr) (Version: 16.0.18025.20006 - Microsoft Corporation) Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.05401 - Microsoft) Microsoft Update Health Tools (HKLM\...\{43D501A5-E5E3-46EC-8F33-9E15D2A2CBD5}) (Version: 5.70.0.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation) Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532 (HKLM\...\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}) (Version: 14.36.32532 - Microsoft Corporation) Hidden Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532 (HKLM\...\{D5D19E2F-7189-42FE-8103-92CD1FA457C2}) (Version: 14.36.32532 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 6.0.26 (x64) (HKLM\...\{1F0EB53C-BE30-436A-BC54-FA364227A870}) (Version: 48.104.6996 - Microsoft Corporation) Hidden Microsoft Windows Desktop Runtime - 6.0.26 (x64) (HKLM-x32\...\{b2476903-b8da-4dcc-903f-378730bb4c48}) (Version: 6.0.26.33205 - Microsoft Corporation) MyHeritage Family Tree Builder (HKLM-x32\...\Family Tree Builder) (Version: 8.0.0.8642 - MyHeritage.com) Numpad_1.6 version 1.6 (HKLM-x32\...\{3BFE5BB6-096D-4405-8184-325292E5D87C}_is1) (Version: 1.6 - Timur Abdrazyakov) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.18025.20006 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.18025.20006 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-040C-1000-0000000FF1CE}) (Version: 16.0.18025.20006 - Microsoft Corporation) Hidden PowerToys (Preview) (HKLM\...\{6F3910F2-DA29-490C-811F-D3691B134A61}) (Version: 0.77.0 - Microsoft Corporation) Hidden PowerToys (Preview) x64 (HKLM-x32\...\{1aada4d0-ca73-4389-8f63-73923c771fd4}) (Version: 0.77.0 - Microsoft Corporation) Proton VPN (HKLM\...\Proton VPN_is1) (Version: 3.2.11 - Proton AG) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 2.00.01.36 - HP Inc.) Samsung Easy Wireless Setup (HKLM-x32\...\Easy Wireless Setup) (Version: 3.70.18.0 - Samsung Electronics Co., Ltd.) Samsung Scan Process Machine (HKLM-x32\...\Samsung Scan Process Machine) (Version: 1.03.05.28 - Samsung Electronics Co., Ltd.) Hidden SetIP (HKLM-x32\...\SetIP) (Version: 1.05.08.00 - Samsung Electronics Co., Ltd.) Suuntolink (HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\...\Suuntolink) (Version: 4.1.11 - Suunto) Telegram Desktop (HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 5.4.1 - Telegram FZ-LLC) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.20 - VideoLAN) Xiaomi Camera Viewer 1.5.3.2 (HKLM-x32\...\D00A840B-B52D-4F84-BFDF-66DD6CAF85C5_is1) (Version: 1.5.3.2 - Xiaomi, Inc.) Chrome apps: ============ Docs (HKU\S-1-5-21-2611112945-1519522136-3444468991-1002\...\bd4d18192e2abe6995c37402c4845be7) (Version: 1.0 - Google\Chrome) Feuilles de calcul (HKU\S-1-5-21-2611112945-1519522136-3444468991-1002\...\49dcfed1a2081719a26f03b8f219936d) (Version: 1.0 - Google\Chrome) Gmail (HKU\S-1-5-21-2611112945-1519522136-3444468991-1002\...\31559d725ee7265d8210f5bce7aa83ba) (Version: 1.0 - Google\Chrome) Google Drive (HKU\S-1-5-21-2611112945-1519522136-3444468991-1002\...\224b118e0280109e0135c053a8dc1169) (Version: 1.0 - Google\Chrome) Présentations (HKU\S-1-5-21-2611112945-1519522136-3444468991-1002\...\b87abf01c8d658f2ee1f6c53d99a0452) (Version: 1.0 - Google\Chrome) YouTube (HKU\S-1-5-21-2611112945-1519522136-3444468991-1002\...\0093e24b63861a85a14e7f77a494e561) (Version: 1.0 - Google\Chrome) Packages: ========= @{MicrosoftWindows.Client.AIX_1000.26100.12.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.AIX/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.AIX_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.Client.AIX_1000.26100.16.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.AIX/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.AIX_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.Client.AIX_1000.26100.17.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.AIX/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.AIX_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.Client.AIX_1000.26100.18.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.AIX/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.AIX_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.Client.AIX_1000.26100.20.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.AIX/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.AIX_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.Client.AIX_1000.26100.26.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.AIX/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.AIX_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.Client.AIX_1000.26100.3.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.AIX/resources/ProductPkgDisplayName} -> C:\Windows\SystemApps\MicrosoftWindows.Client.AIX_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.Client.LKG_1000.26100.1350.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.LKG/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\LKG\MicrosoftWindows.Client.LKG_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.Client.OOBE_1000.26052.1100.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.OOBE/resources/ProductPkgDisplayName} -> C:\Windows\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) @{MicrosoftWindows.Client.OOBE_1000.26058.1100.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.OOBE/resources/ProductPkgDisplayName} -> C:\Windows\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) @{MicrosoftWindows.Client.OOBE_1000.26100.1.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.OOBE/resources/ProductPkgDisplayName} -> C:\Windows\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) @{MicrosoftWindows.Client.Photon_1000.26052.1100.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Photon/resources/ProductPkgDisplayName} -> C:\Windows\SystemApps\MicrosoftWindows.Client.Photon_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) @{MicrosoftWindows.Client.Photon_1000.26058.1100.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Photon/resources/ProductPkgDisplayName} -> C:\Windows\SystemApps\MicrosoftWindows.Client.Photon_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) @{MicrosoftWindows.Client.Photon_1000.26100.1.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Photon/resources/ProductPkgDisplayName} -> C:\Windows\SystemApps\MicrosoftWindows.Client.Photon_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) @{MicrosoftWindows.Client.Photon_1000.26100.2.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Photon/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.Photon_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) @{MicrosoftWindows.Client.Photon_1000.26100.3.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.Client.Photon/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.Photon_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) @{MicrosoftWindows.LKG.AccountsService_1000.26100.1350.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.LKG.AccountsService/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\LKG\MicrosoftWindows.LKG.AccountsService_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.LKG.IrisService_1000.26100.1350.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.LKG.IrisService/resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\LKG\MicrosoftWindows.LKG.IrisService_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) @{MicrosoftWindows.LKG.Search_1000.26100.1350.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.LKG.Search/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\LKG\MicrosoftWindows.LKG.Search_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) Amazon Alexa -> C:\Program Files\WindowsApps\57540AMZNMobileLLC.AmazonAlexa_3.25.1177.0_x64__22t9g3sebte08 [2024-02-03] (AMZN Mobile LLC.) [Startup Task] AMD Radeon Software -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.19009.0_x64__0a9344xs7nr4m [2024-08-13] (Advanced Micro Devices Inc.) [Startup Task] Dev Home (Preview) -> C:\Program Files\WindowsApps\Microsoft.Windows.DevHome_0.1701.597.0_x64__8wekyb3d8bbwe [2024-08-22] (Microsoft Corporation) [Startup Task] Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_2024.3.211.0_neutral__6rarf9sa4v8jt [2024-03-26] (Disney) Dolby Audio -> C:\Program Files\WindowsApps\dolbylaboratories.dolbyaudio_3.30100.101.0_x64__rz1tebttyb220 [2022-09-13] (Dolby Laboratories) Flipboard -> C:\Program Files\WindowsApps\Flipboard.Flipboard_2.1.3.0_neutral__3f5azkryzdbc4 [2024-01-27] (Flipboard) HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_155.1.1088.0_x64__v10z8vjag6ke6 [2024-08-07] (HP Inc.) Ink.Handwriting.fr-FR.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.fr-FR.1.0_0.520.2316.0_x86__8wekyb3d8bbwe [2024-06-10] (Microsoft Corporation) Ink.Handwriting.fr-FR.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.fr-FR.1.0_0.550.149.0_x64__8wekyb3d8bbwe [2024-07-06] (Microsoft Corporation) Ink.Handwriting.fr-FR.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.fr-FR.1.0_0.598.1811.0_x64__8wekyb3d8bbwe [2024-08-23] (Microsoft Corporation) Ink.Handwriting.Main.fr-FR.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.Main.fr-FR.1.0_0.237.110.0_x64__8wekyb3d8bbwe [2023-08-30] (Microsoft Corporation) Lenovo Companion -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2406.36.0_x64__k1h2ywk1493x8 [2024-07-12] (LENOVO INC.) Lenovo Hotkeys -> C:\Program Files\WindowsApps\E0469640.LenovoUtility_4.6.12.0_x64__5grkq8ppsgwt4 [2024-04-02] (LENOVO INC) [Startup Task] Lenovo Pen Settings -> C:\Program Files\WindowsApps\WacomTechnologyCorp.157535B83C264_8.2.6.0_neutral__ss941bf8mfs8a [2024-07-02] (Wacom Technology Corp.) Lenovo Voice -> C:\Program Files\WindowsApps\E046963F.LenovoVoiceWorldWide_3.0.26.0_x64__k1h2ywk1493x8 [2024-01-27] (LENOVO INC.) LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_3.0.34.0_x64__w1wdnht996qgy [2024-08-21] (LinkedIn) [Startup Task] Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.39.0_x64__8wekyb3d8bbwe [2023-01-03] (Microsoft Corp.) Microsoft Henri (Natural) - French (France) -> C:\Program Files\WindowsApps\MicrosoftWindows.Voice.fr-FR.Henri.1_1.0.2.0_x64__cw5n1h2txyewy [2024-02-09] (Microsoft Windows) Microsoft Teams -> C:\Program Files\WindowsApps\MSTeams_24193.1805.3040.8975_x64__8wekyb3d8bbwe [2024-08-19] (Microsoft) [Startup Task] Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_53.21110.548.0_x64__8wekyb3d8bbwe [2024-03-15] (Microsoft Corporation) Microsoft.ApplicationCompatibilityEnhancements -> C:\Program Files\WindowsApps\Microsoft.ApplicationCompatibilityEnhancements_1.2405.3.0_x64__8wekyb3d8bbwe [2024-05-14] (Microsoft Corporation) Microsoft.AV1VideoExtension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.2.2331.0_x64__8wekyb3d8bbwe [2024-08-21] (Microsoft Corporation) Microsoft.AVCEncoderVideoExtension -> C:\Program Files\WindowsApps\Microsoft.AVCEncoderVideoExtension_1.0.661.0_x64__8wekyb3d8bbwe [2024-03-08] (Microsoft Corporation) Microsoft.BingSearch -> C:\Program Files\WindowsApps\Microsoft.BingSearch_1.0.95.0_x64__8wekyb3d8bbwe [2024-07-23] (Microsoft Corporation) Microsoft.MPEG2VideoExtension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.61931.0_x64__8wekyb3d8bbwe [2024-04-06] (Microsoft Corporation) Microsoft.Photos.MediaEngineDLC -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-11-05] (Microsoft Corporation) Microsoft.StartExperiencesApp -> C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.1.158.0_x64__8wekyb3d8bbwe [2024-09-03] (Microsoft Corporation) [Startup Task] Microsoft.Windows.AugLoop.CBS -> C:\Windows\SystemApps\Microsoft.Windows.AugLoop.CBS_8wekyb3d8bbwe [2024-04-01] (Microsoft Corporation) MicrosoftCorporationII.QuickAssist -> C:\Program Files\WindowsApps\MicrosoftCorporationII.QuickAssist_2.0.29.0_neutral_split.scale-100_8wekyb3d8bbwe [2024-04-06] (Microsoft Corp.) MicrosoftWindows.CrossDevice -> C:\Program Files\WindowsApps\MicrosoftWindows.CrossDevice_1.24081.51.0_x64__cw5n1h2txyewy [2024-08-22] (Microsoft Windows) [Startup Task] Mozilla Firefox -> C:\Program Files\WindowsApps\Mozilla.Firefox_129.0.2.0_x64__n80bbvh6b1yt2 [2024-08-22] (Mozilla) [Startup Task] MSN Finance -> C:\Program Files\WindowsApps\www.msn.com-C5326BA9_1.0.0.1_neutral__q77jw2zwjvy92 [2024-06-24] (www.msn.com) MSN Finance -> C:\Program Files\WindowsApps\www.msn.com-D7475688_1.0.0.0_neutral__q77jw2zwjvy92 [2024-06-24] (www.msn.com) Photos -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2024.11070.31001.0_x64__8wekyb3d8bbwe [2024-08-01] (Microsoft Corporation) [Startup Task] PowerToys ImageResizer Context Menu -> C:\Program Files\PowerToys [2024-01-11] (Microsoft) PowerToys PowerRename Context Menu -> C:\Program Files\PowerToys\WinUI3Apps [2024-01-11] (Microsoft) Prime Video for Windows -> C:\Program Files\WindowsApps\AmazonVideo.PrimeVideo_1.0.160.0_x64__pwbj9vvecjh7j [2024-08-20] (Amazon Development Centre (London) Ltd) Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.41.288.0_x64__dt26b99r8h8gj [2023-08-03] (Realtek Semiconductor Corp) Samsung Printer Experience -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungPrinterExperience_1.3.15.0_x64__3c1yjt4zspk6g [2022-09-20] (Samsung Electronics Co. Ltd.) Smart Microphone Setting -> C:\Program Files\WindowsApps\4505Fortemedia.FMAPOControl_1.0.38.0_x64__4pejv7q2gmsnr [2024-01-26] (Fortemedia) Sous-système Windows pour Android™ -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForAndroid_2407.40000.0.0_x64__8wekyb3d8bbwe [2024-07-25] (Microsoft Corp.) [Startup Task] Speech Pack - English (United States) -> C:\Program Files\WindowsApps\MicrosoftWindows.Speech.en-US.1_1.0.17.0_x64__cw5n1h2txyewy [2024-05-22] (Microsoft Windows) Speech Pack - French (France) -> C:\Program Files\WindowsApps\MicrosoftWindows.Speech.fr-FR.1_1.0.8.0_x64__cw5n1h2txyewy [2024-08-30] (Microsoft Windows) WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2434.5.0_x64__cv1g1gvanyjgm [2024-08-29] (WhatsApp Inc.) [Startup Task] Widgets Platform Runtime -> C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.4.0.0_x64__8wekyb3d8bbwe [2024-08-01] (Microsoft Corporation) WinAppRuntime.Main.1.2 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.2_2000.802.31.0_x64__8wekyb3d8bbwe [2024-03-21] (Microsoft Corp.) WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.214.1843.0_x64__8wekyb3d8bbwe [2024-08-14] (Microsoft Corp.) WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_5001.214.1843.0_x64__8wekyb3d8bbwe [2024-08-14] (Microsoft Corp.) Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\LKG\MicrosoftWindows.Client.LKG_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\LKG\MicrosoftWindows.LKG.AccountsService_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\LKG\MicrosoftWindows.LKG.IrisService_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\LKG\MicrosoftWindows.LKG.Search_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.AIX_cw5n1h2txyewy [2024-08-22] (Microsoft Windows) Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.OOBE_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) Windows Feature Experience Pack -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.Photon_cw5n1h2txyewy [2024-08-11] (Microsoft Windows) ==================== Personnalisé CLSID (Avec liste blanche): ============== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{10144713-1526-46C9-88DA-1FB52807A9FF}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.SvgThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{50726f74-6f6e-2e56-504e-000000000000}\localserver32 -> C:\Program Files\Proton\VPN\v3.2.11\ProtonVPN.exe (Proton AG -> ) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{5ea9a442-5352-ed6e-d37f-9d511e7e2caa}\localserver32 -> C:\Program Files\PowerToys\PowerToys.PowerLauncher.exe (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{60789D87-9C3C-44AF-B18C-3DE2C2820ED3}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.MarkdownPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{729B72CD-B72E-4FE9-BCBF-E954B33FE699}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.QoiPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{77257004-6F25-4521-B602-50ECC6EC62A6}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.StlThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{A0257634-8812-4CE8-AF11-FA69ACAEAFAE}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.GcodePreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{AD856B15-D25E-4008-AFB7-AFAA55586188}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.QoiThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{D8034CFA-F34B-41FE-AD45-62FCBB52A6DA}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.MonacoPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{F2847CBE-CD03-4C83-A359-1A8052C1B9D5}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.GcodeThumbnailProviderCpp.dll (Microsoft Corporation -> Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001_Classes\CLSID\{FCDD4EED-41AA-492F-8A84-31A1546226E0}\InprocServer32 -> C:\Program Files\PowerToys\PowerToys.SvgPreviewHandlerCpp.dll (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers2: [FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Program Files\PowerToys\WinUI3Apps\PowerToys.FileLocksmithExt.dll [2024-01-05] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers3: [FileLocksmithExt] -> {84D68575-E186-46AD-B0CB-BAEB45EE29C0} => C:\Program Files\PowerToys\WinUI3Apps\PowerToys.FileLocksmithExt.dll [2024-01-05] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers3: [PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Program Files\PowerToys\WinUI3Apps\PowerToys.PowerRenameExt.dll [2024-01-05] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.166.0818.0002\FileSyncShell64.dll [2024-08-29] (Microsoft Corporation -> Microsoft Corporation) ContextMenuHandlers5: [PowerRenameExt] -> {0440049F-D1DC-4E46-B27B-98393D79486B} => C:\Program Files\PowerToys\WinUI3Apps\PowerToys.PowerRenameExt.dll [2024-01-05] (Microsoft Corporation -> Microsoft Corporation) ==================== Codecs (Avec liste blanche) ==================== ==================== Raccourcis & WMI ======================== (Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.) ShortcutWithArgument: C:\Users\jacqu\AppData\Local\Microsoft\Edge\User Data\Snapshots\128.0.2739.42\Default\Web Applications\_crx__ahocihnchhknegfoalnlmaackifapfji\MSN Finance.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=ahocihnchhknegfoalnlmaackifapfji --app-url=hxxps://www.msn.com/fr-fr/finance?ocid=financepwa --app-launch-source=4 ShortcutWithArgument: C:\Users\jacqu\AppData\Local\Microsoft\Edge\User Data\Snapshots\127.0.2651.74\Default\Web Applications\_crx__ahocihnchhknegfoalnlmaackifapfji\MSN Finance.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=ahocihnchhknegfoalnlmaackifapfji --app-url=hxxps://www.msn.com/fr-fr/finance?ocid=financepwa --app-launch-source=4 ShortcutWithArgument: C:\Users\jacqu\AppData\Local\Microsoft\Edge\User Data\Snapshots\126.0.2592.68\Default\Web Applications\_crx__ahocihnchhknegfoalnlmaackifapfji\MSN Finance.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=ahocihnchhknegfoalnlmaackifapfji --app-url=hxxps://www.msn.com/fr-fr/finance?ocid=financepwa --app-launch-source=4 ShortcutWithArgument: C:\Users\jacqu\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__ahocihnchhknegfoalnlmaackifapfji\MSN Finance.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=ahocihnchhknegfoalnlmaackifapfji --app-url=hxxps://www.msn.com/fr-fr/finance?ocid=financepwa --app-launch-source=4 ShortcutWithArgument: C:\Users\jacqu\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\MSN Finance.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=ahocihnchhknegfoalnlmaackifapfji --app-url=hxxps://www.msn.com/fr-fr/finance?ocid=financepwa --app-launch-source=4 ==================== Modules chargés (Avec liste blanche) ============= 2014-09-08 14:38 - 2014-09-08 14:38 - 000051200 _____ () [Fichier non signé] C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2022-03-01 09:00 - 2022-03-01 09:00 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll 2022-03-01 09:00 - 2022-03-01 09:00 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\root\Office16\c2r64.dll 2023-03-29 15:47 - 2023-03-29 15:47 - 000123904 _____ (Samsung Electronics Co., Ltd.) [Fichier non signé] C:\Program Files (x86)\Samsung\Easy Printer Manager\SmartScreenPrint\CDAKEYMonitor64.dll ==================== Alternate Data Streams (Avec liste blanche) ======== ==================== Mode sans échec (Avec liste blanche) ================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\cdd.dll => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{13cfe1b1-6b17-424c-ac3f-16ace8733898} => ""="I3C devices" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\cdd.dll => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ExecutionContext.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\netadaptercx.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinHttpAutoProxySvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{13cfe1b1-6b17-424c-ac3f-16ace8733898} => ""="I3C devices" ==================== Association (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.) HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\Software\Classes\regfile: <==== ATTENTION HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\Software\Classes\.reg: => <==== ATTENTION HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\Software\Classes\.bat: => <==== ATTENTION HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\Software\Classes\.cmd: => <==== ATTENTION ==================== Internet Explorer (Avec liste blanche) ============= BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-08-31] (Microsoft Corporation -> Microsoft Corporation) (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.) IE trusted site: HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\...\sharepoint.com -> hxxps://laposte-files.sharepoint.com ==================== Hosts contenu: ========================= (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.) 2021-06-05 14:08 - 2023-12-21 17:47 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 localhost 2022-09-27 19:38 - 2022-09-27 19:38 - 000000432 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics 172.25.48.1 PC2en1.mshome.net # 2027 9 0 26 17 38 16 781 ==================== Autres zones =========================== (Actuellement, il n'y a pas de correction automatique pour cette section.) HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\jacqu\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\17340372764363702058\133693245666445201.jpg HKU\S-1-5-21-2611112945-1519522136-3444468991-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\chant\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Microsoft\IrisService\9943830601568397563\133691522028213615.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Le Pare-feu est activé. Network Binding: ============= Wi-Fi: MediaTek Wi-Fi 6 MT7921 Wireless LAN Card -> mtkwl6ex.sys Connexion réseau Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys vms_vsf: Filtre d’extension de commutateur virtuel Hyper-V ms_l1vhlwf: Virtualisation de réseau imbriqué vms_vsp: Protocole d’extension de commutateur virtuel Hyper-V ==================== MSCONFIG/TASK MANAGER éléments désactivés == (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.) HKLM\...\StartupApproved\Run: => "LVAW" HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\...\StartupApproved\Run: => "BatteryWidgetHost" HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\...\StartupApproved\Run: => "LenovoVantage" HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\...\StartupApproved\Run: => "SuuntolinkLauncher" HKU\S-1-5-21-2611112945-1519522136-3444468991-1001\...\StartupApproved\Run: => "ProtonVPN" ==================== RèglesPare-feu (Avec liste blanche) ================ (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) FirewallRules: [{04958C48-F344-4781-A771-AA1BECF32C64}] => (Allow) C:\Program Files\PowerToys\PowerToys.MouseWithoutBorders.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [TCP Query User{5E9C0805-50DB-4AC9-8954-0D6D5FA61EB1}C:\program files\google\chrome\application\chrome.exe] => (Allow) C:\program files\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [UDP Query User{209CF0E4-BA7B-452F-986A-5EB8781AF97E}C:\program files\google\chrome\application\chrome.exe] => (Allow) C:\program files\google\chrome\application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{013ED2E2-FB18-4EFE-ABD4-489801C5DF9F}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> ) FirewallRules: [{82D77744-C2AE-401E-A90D-AAD84111A47A}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> ) FirewallRules: [{2611CF83-597A-4B05-8EB8-3EEBB2CE69E7}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe (HP Development Company, L.P.) [Fichier non signé] FirewallRules: [{BB94F5FA-9F03-4945-893D-D3F75FB927BA}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe (HP Development Company, L.P.) [Fichier non signé] FirewallRules: [{4EB114E9-220C-4F73-BA29-790ECCE78497}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2AlertList.exe (HP Development Company, L.P.) [Fichier non signé] FirewallRules: [{1B7A34BE-265C-4E27-9178-355767C920D2}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2Migrator.exe (HP Development Company, L.P.) [Fichier non signé] FirewallRules: [{ABE7698B-6C98-400D-8AA6-EE31AE8A3D07}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> ) FirewallRules: [{C141ADDC-D452-41D9-97B3-44FB8553BE9F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{70EF7B21-D06E-4936-9000-BBCD3223B562}] => (Allow) C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForAndroid_2407.40000.0.0_x64__8wekyb3d8bbwe\WsaClient\WsaClient.exe (Microsoft Corporation -> ) FirewallRules: [{E8237EDD-7D44-4C96-B86F-2E2ECDEA3179}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24193.1805.3040.8975_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{9A17D4AD-47C7-40EE-A9BD-A56988371438}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24193.1805.3040.8975_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{061850D7-2367-4979-BDFB-0BFB80B25187}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24215.1105.3082.1600_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{D86D39E6-430D-412D-BE79-C7A0590CE9FA}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_24215.1105.3082.1600_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{B570430F-C5F1-495C-AC90-A77206FE6C3E}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\128.0.2739.54\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{719578BA-9D7F-45C4-88B4-E354B2F9F0B3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{07FBF7CC-9D3D-47CF-B32A-2D8882A4864D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{6F0AE7B0-4B44-4DFB-A227-B969673F3E8D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{C0718A69-912F-4F71-9D1F-0878B4427ECB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{871A671F-7416-4C88-9217-1C51FC1EF50B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{0EF7734D-5D3D-4079-B5A2-9742302B1913}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{F2B2FB77-88FA-412A-AB02-48005155950F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{FF05C532-E52C-40E5-B7A8-C8538333039F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{6DCF5AFD-F461-4159-B959-F9243512578E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [{41D4A957-3815-4EBB-92F5-C2EB63A6BC7D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.245.454.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd) FirewallRules: [TCP Query User{7BEA9243-34C7-4CFC-B6A1-EE7B6348921C}C:\users\jacqu\appdata\roaming\telegram desktop\telegram.exe] => (Block) C:\users\jacqu\appdata\roaming\telegram desktop\telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC) FirewallRules: [UDP Query User{A8F4EECE-C0F6-4367-8AF2-7C22B0A77B00}C:\users\jacqu\appdata\roaming\telegram desktop\telegram.exe] => (Block) C:\users\jacqu\appdata\roaming\telegram desktop\telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC) FirewallRules: [{C1DB52B2-2594-451D-900B-4BF54B2B3C25}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Points de restauration ========================= 28-08-2024 15:15:28 Windows Update 31-08-2024 18:53:47 Windows Update ==================== Éléments en erreur du Gestionnaire de périphériques ============ ==================== Erreurs du Journal des événements: ======================== Erreurs Application: ================== Error: (09/02/2024 07:41:26 AM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\PC2EN1$ via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep : GetCACaps Méthode : GET(0ms) Étape : GetCACaps L’adresse ou le nom de serveur n’a pas pu être résolu 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED) Error: (09/02/2024 07:41:19 AM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\PC2EN1$ via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep : GetCACaps Méthode : GET(0ms) Étape : GetCACaps L’adresse ou le nom de serveur n’a pas pu être résolu 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED) Error: (09/02/2024 07:41:19 AM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour Système local via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep : GetCACaps Méthode : GET(172ms) Étape : GetCACaps L’adresse ou le nom de serveur n’a pas pu être résolu 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED) Error: (08/31/2024 07:15:12 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\PC2EN1$ via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Sat, 31 Aug 2024 17:15:12 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: 094ed0ae-e96a-404c-a8df-415ae0be052a Méthode : GET(828ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Error: (08/31/2024 07:15:11 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\PC2EN1$ via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Sat, 31 Aug 2024 17:15:11 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: d9089404-614c-47f5-844f-4a7e46c3d2f6 Méthode : GET(688ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Error: (08/31/2024 07:15:08 PM) (Source: CertEnroll) (EventID: 86) (User: AUTORITE NT) Description: Échec de l’initialisation de l’inscription du certificat SCEP pour Système local via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep : GetCACaps GetCACaps: Not Found {"Message":"The authority \"amd-keyid-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net\" does not exist."} HTTP/1.1 404 Not Found Date: Sat, 31 Aug 2024 17:15:08 GMT Content-Length: 121 Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000;includeSubDomains x-ms-request-id: 76791336-fc66-4f44-9495-b365669b5c36 Méthode : GET(843ms) Étape : GetCACaps Non trouvé (404). 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND) Error: (08/31/2024 07:14:18 PM) (Source: VSS) (EventID: 13) (User: ) Description: Informations du service de cliché instantané de volumes : impossible de démarrer le serveur COM de CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} et de nom CEventSystem. [0x8007045b, Un arrêt système est en cours.] Error: (08/31/2024 09:19:58 AM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: PC2EN1) Description: Impossible de fermer l’application ou le service « Microsoft Office SDX Helper ». Erreurs système: ============= Error: (09/03/2024 08:10:12 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: AUTORITE NT) Description: Échec de l’installation : l’installation de la mise à jour suivante a échoue avec l’erreur 0x80073d02 : 9NTXGKQ8P7N0-MicrosoftWindows.CrossDevice. Error: (09/02/2024 07:43:07 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Le service Service Google Update (gupdate) n’a pas pu démarrer en raison de l’erreur : Le service n’a pas répondu assez vite à la demande de lancement ou de contrôle. Error: (09/02/2024 07:43:07 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service Service Google Update (gupdate). Error: (09/02/2024 07:41:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Le service l1vhlwf n’a pas pu démarrer en raison de l’erreur : Aucune fonctionnalité d’hyperviseur n’est disponible pour l’utilisateur. Error: (09/02/2024 07:40:37 AM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3503) (User: AUTORITE NT) Description: Device Association Service a détecté un échec de découverte de point de terminaison. Error: (09/02/2024 07:40:37 AM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3503) (User: AUTORITE NT) Description: Device Association Service a détecté un échec de découverte de point de terminaison. Error: (09/02/2024 07:40:37 AM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3503) (User: AUTORITE NT) Description: Device Association Service a détecté un échec de découverte de point de terminaison. Error: (09/02/2024 07:40:37 AM) (Source: Microsoft-Windows-DeviceAssociationService) (EventID: 3503) (User: AUTORITE NT) Description: Device Association Service a détecté un échec de découverte de point de terminaison. Windows Defender: ================ Date: 2024-08-29 10:07:31 Description: L’analyse Antivirus Microsoft Defender a été arrêtée avant la fin. ID de l’analyse : {9168D6AB-6D0E-4D75-A634-8253C7BA08C5} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Date: 2024-08-28 15:22:59 Description: L’analyse Antivirus Microsoft Defender a été arrêtée avant la fin. ID de l’analyse : {77FDB0A6-65B3-4ABF-B770-7FDAEB795D59} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Date: 2024-08-27 11:03:10 Description: L’analyse Antivirus Microsoft Defender a été arrêtée avant la fin. ID de l’analyse : {BAD6BEFB-4FC4-4DD1-B5A9-05076DA4803C} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Date: 2024-08-23 10:21:24 Description: L’analyse Antivirus Microsoft Defender a été arrêtée avant la fin. ID de l’analyse : {A5B6CD02-92C2-4AFF-A16D-B6114102191B} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Date: 2024-08-21 08:28:27 Description: L’analyse Antivirus Microsoft Defender a été arrêtée avant la fin. ID de l’analyse : {71D5895A-0612-44E7-9C9D-E5CC4F3319A8} Type de l’analyse : Logiciel anti-programme malveillant Paramètres de l’analyse : Analyse rapide Utilisateur : AUTORITE NT\Système Event[0] Date: 2024-05-08 20:10:05 Description: Antivirus Microsoft Defender a rencontré une erreur lors de la mise à jour de la veille de sécurité. Nouvelle version de la veille de sécurité : Version précédente de la veille de sécurité : 1.411.31.0 Source de mise à jour : Serveur Microsoft Update Type de veille de sécurité : Anti-virus Type de mise à jour : Complet Utilisateur : AUTORITE NT\Système Version actuelle du moteur : Version précédente du moteur : 1.1.24040.1 Code d’erreur : 0x80070102 Description de l’erreur : Dépassement du délai d’attente. Date: 2024-05-08 20:10:05 Description: Antivirus Microsoft Defender a rencontré une erreur lors de la mise à jour de la veille de sécurité. Nouvelle version de la veille de sécurité : Version précédente de la veille de sécurité : 1.411.31.0 Source de mise à jour : Serveur Microsoft Update Type de veille de sécurité : Anti-virus Type de mise à jour : Complet Utilisateur : AUTORITE NT\Système Version actuelle du moteur : Version précédente du moteur : 1.1.24040.1 Code d’erreur : 0x80070102 Description de l’erreur : Dépassement du délai d’attente. Date: 2024-04-06 09:49:42 Description: Antivirus Microsoft Defender a rencontré une erreur lors de la mise à jour de la veille de sécurité et va tenter de rétablir une version précédente. Veille de sécurité tentée : Actuelle Code d’erreur : 0x80070003 Description de l’erreur : Le chemin d’accès spécifié est introuvable. Version de la veille de sécurité : 0.0.0.0;0.0.0.0 Version du moteur : 0.0.0.0 CodeIntegrity: =============== Date: 2024-08-17 15:54:17 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\fcon.dll because the set of per-page image hashes could not be found on the system. ==================== Infos Mémoire =========================== BIOS: LENOVO GJCN34WW 12/20/2023 Carte mère: LENOVO LNVNB161216 Processeur: AMD Ryzen 5 5500U with Radeon Graphics Pourcentage de mémoire utilisée: 44% Mémoire physique - RAM - totale: 15709.99 MB Mémoire physique - RAM - disponible: 8796 MB Mémoire virtuelle totale: 18909.99 MB Mémoire virtuelle disponible: 8392.27 MB ==================== Lecteurs ================================ Drive c: (Windows-SSD) (Fixed) (Total:474.72 GB) (Free:381.05 GB) (Model: Micron MTFDHBA512QFD) NTFS Drive d: () (Removable) (Total:7.44 GB) (Free:3.63 GB) FAT32 \\?\Volume{c1560c33-5a34-43bb-8df3-cd5ff34c9a78}\ (WINRE_DRV) (Fixed) (Total:1.95 GB) (Free:1.38 GB) NTFS \\?\Volume{a64e3787-f832-43b4-9603-c642b7d7650e}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.21 GB) FAT32 ==================== MBR & Table des partitions ==================== ========================================================== Disk: 0 (Size: 476.9 GB) (Disk ID: 3D739D35) Partition: GPT. ========================================================== Disk: 1 (Protective MBR) (Size: 7.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== Fin de Addition.txt =======================