Académique Documents
Professionnel Documents
Culture Documents
30-08-2022
Exécuté par rapau (22-09-2022 00:39:50)
Exécuté depuis C:\Users\rapau\Desktop\Trolling
Microsoft Windows 10 Famille Version 21H1 19043.2006 (X64) (2020-11-02 21:01:54)
Mode d'amorçage: Normal
==========================================================
Packages:
=========
ASUS ZenLink -> C:\Program Files\WindowsApps\
B9ECED6F.ZenSync_1.0.7.0_x86__qmba6cd70vzyy [2022-09-15] (ASUSTeK COMPUTER INC.)
[MS Ad]
Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\
king.com.BubbleWitch3Saga_7.21.71.0_x64__kgqvnymyfvs32 [2022-07-23] (king.com)
Composant additionnel Photos Media Engine -> C:\Program Files\WindowsApps\
Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-06-20] (Microsoft
Corporation)
Extension Photos -> C:\Program Files\WindowsApps\
Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-03-
12] (Microsoft Corporation)
Extension vidéo MPEG-2 -> C:\Program Files\WindowsApps\
Microsoft.MPEG2VideoExtension_1.0.50901.0_x64__8wekyb3d8bbwe [2022-05-05]
(Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\
AD2F1837.HPPrinterControl_138.2.414.0_x64__v10z8vjag6ke6 [2022-09-08] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\
Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-18] (Microsoft
Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\
Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-18] (Microsoft
Corporation) [MS Ad]
Microsoft Midi gm.dls -> C:\Program Files\WindowsApps\
Microsoft.Midi.GmDls_1.0.1.0_neutral__8wekyb3d8bbwe [2018-10-26] (Microsoft
Platform Extensions)
MyASUS-Service Center -> C:\Program Files\WindowsApps\
B9ECED6F.MyASUS_3.3.11.0_x86__qmba6cd70vzyy [2021-09-10] (ASUSTeK COMPUTER INC.)
[Startup Task]
PowerDirector14 for ASUS -> C:\Program Files\WindowsApps\
F5080380.PowerDirector14forASUS_14.0.5226.0_x64__tfv7c950n6xcr [2021-09-10]
(CyberLink Corp.)
Prime Video for Windows -> C:\Program Files\WindowsApps\
AmazonVideo.PrimeVideo_1.0.111.0_x64__pwbj9vvecjh7j [2022-08-31] (Amazon
Development Centre (London) Ltd)
WinZip Universal -> C:\Program Files\WindowsApps\
WinZipComputing.WinZipUniversal_1.5.13516.0_x64__3ykzqggjzj4z0 [2022-09-15] (WinZip
Computing)
CustomCLSID: HKU\S-1-5-21-1622197607-3246147979-2720308186-1001_Classes\CLSID\
{233525e0-5434-46ef-b464-fd7e45e2e145}\localserver32 -> "C:\Program Files (x86)\
Intel\Driver and Support Assistant\DSATray.exe" -ToastActivated => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1622197607-3246147979-2720308186-1001_Classes\CLSID\
{D1C6E3A7-4E00-4F31-AB65-565A62EE1A83} -> [iCloud Drive] => C:\Users\rapau\
iCloudDrive
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524}
=> C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-
09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282}
=> C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-
09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30}
=> C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-
09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A}
=> C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-
09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}
=> C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-
09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
=> C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-
09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}
=> C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-
09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>
-> Pas de fichier
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-
C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\
FileSyncShell64.dll [2022-09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-
AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\
FileSyncShell64.dll [2022-09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-
2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\
FileSyncShell64.dll [2022-09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-
7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\
FileSyncShell64.dll [2022-09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-
95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\
FileSyncShell64.dll [2022-09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-
24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\
FileSyncShell64.dll [2022-09-21] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-
2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.181.0828.0002\
FileSyncShell64.dll [2022-09-21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>
C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-
21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files (x86)\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [Fichier non signé]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\
Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (win.rar GmbH -> Alexander
Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>
C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander
Roshal)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>
C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-
21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files (x86)\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [Fichier non signé]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>
C:\Program Files\Microsoft OneDrive\22.181.0828.0002\FileSyncShell64.dll [2022-09-
21] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => ->
Pas de fichier
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\
WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_ceba516baea4bed9\
igfxDTCM.dll [2020-04-29] (Microsoft Windows Hardware Compatibility Publisher ->
Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-
BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-01-02] (NVIDIA Corporation -
> NVIDIA Corporation)
ContextMenuHandlers6-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\
Program Files (x86)\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [Fichier non signé]
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\
Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (win.rar GmbH -> Alexander
Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>
C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander
Roshal)
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera
restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
(Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin
d'être supprimés ou restaurés.)
2022-08-19 08:54 - 2022-08-19 08:54 - 001453056 _____ () [Fichier non signé] \\?\
C:\Windows\Prey\versions\1.10.10\node_modules\sqlite3\lib\binding\napi-v3-win32-
x64\node_sqlite3.node
2017-07-03 11:51 - 2017-07-03 11:51 - 001937408 _____ () [Fichier non signé] C:\
Program Files (x86)\ASUS\Giftbox\ffmpeg.dll
2017-07-03 11:51 - 2017-07-03 11:51 - 000079360 _____ () [Fichier non signé] C:\
Program Files (x86)\ASUS\Giftbox\libegl.dll
2017-07-03 11:51 - 2017-07-03 11:51 - 002177536 _____ () [Fichier non signé] C:\
Program Files (x86)\ASUS\Giftbox\libglesv2.dll
2017-07-03 11:51 - 2017-07-03 11:51 - 003561984 _____ () [Fichier non signé] C:\
Program Files (x86)\ASUS\Giftbox\node.dll
2022-09-22 00:19 - 2022-09-22 00:19 - 000009728 _____ () [Fichier non signé] C:\
Users\rapau\AppData\Local\Temp\nsvA22F.tmp\nsDialogs.dll
2022-09-22 00:19 - 2022-09-22 00:19 - 000006656 _____ () [Fichier non signé] C:\
Users\rapau\AppData\Local\Temp\nsvA22F.tmp\nsExec.dll
2022-09-22 00:19 - 2022-09-22 00:19 - 000011776 _____ () [Fichier non signé] C:\
Users\rapau\AppData\Local\Temp\nsvA22F.tmp\System.dll
2009-09-16 18:44 - 2009-09-16 18:44 - 000153088 _____ (Hewlett Packard) [Fichier
non signé] C:\WINDOWS\System32\hptcpmib.dll
2009-09-16 18:45 - 2009-09-16 18:45 - 000331264 _____ (Hewlett Packard) [Fichier
non signé] C:\WINDOWS\System32\HpTcpMon.dll
2009-09-16 11:44 - 2009-09-16 11:44 - 000132096 _____ (Hewlett Packard) [Fichier
non signé] C:\WINDOWS\System32\hpzjrd01.dll
2011-04-13 16:08 - 2011-04-13 16:08 - 000050688 _____ (Hewlett-Packard) [Fichier
non signé] c:\windows\system32\hpzinw12.dll
2011-04-13 16:08 - 2011-04-13 16:08 - 000066048 _____ (Hewlett-Packard) [Fichier
non signé] c:\windows\system32\hpzipm12.dll
2009-09-16 18:45 - 2009-09-16 18:45 - 000317440 _____ (Microsoft Corporation)
[Fichier non signé] C:\WINDOWS\System32\HPTcpMUI.dll
2017-07-03 11:51 - 2017-07-03 11:51 - 073507840 _____ (The NWJS Community) [Fichier
non signé] C:\Program Files (x86)\ASUS\Giftbox\nw.dll
2017-07-03 11:51 - 2017-07-03 11:51 - 000124928 _____ (The NWJS Community) [Fichier
non signé] C:\Program Files (x86)\ASUS\Giftbox\nw_elf.dll
(Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt
afin de réinitialiser le fichier hosts.)
HKU\S-1-5-21-1622197607-3246147979-2720308186-1001\...\StartupApproved\Run: =>
"Discord"
HKU\S-1-5-21-1622197607-3246147979-2720308186-1001\...\StartupApproved\Run: =>
"Steam"
Erreurs Application:
==================
Error: (09/22/2022 12:28:24 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center n'a pas pu valider l'appelant. Erreur %1.
Erreurs système:
=============
Error: (09/21/2022 11:50:33 PM) (Source: Service Control Manager) (EventID: 7000)
(User: )
Description: Le service McAfee WebAdvisor n’a pas pu démarrer en raison de
l’erreur :
Le fichier spécifié est introuvable.
Error: (09/21/2022 11:49:49 PM) (Source: Service Control Manager) (EventID: 7031)
(User: )
Description: Le service NVIDIA LocalSystem Container s’est terminé de manière
inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être
effectuée dans 6000 millisecondes : Redémarrer le service.
Error: (09/21/2022 11:49:49 PM) (Source: Service Control Manager) (EventID: 7031)
(User: )
Description: Le service Microsoft Office Click-to-Run Service s’est terminé de
manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être
effectuée dans 0 millisecondes : Redémarrer le service.
Error: (09/21/2022 11:49:48 PM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: Le service Intel(R) Content Protection HECI Service s’est terminé de
façon inattendue pour la 1ème fois.
Error: (09/21/2022 11:49:48 PM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: Le service Intel(R) PROSet/Wireless Zero Configuration Service s’est
terminé de façon inattendue pour la 1ème fois.
Error: (09/21/2022 11:49:48 PM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: Le service Intel(R) Content Protection HDCP Service s’est terminé de
façon inattendue pour la 1ème fois.
Error: (09/21/2022 11:49:48 PM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: Le service Intel(R) PROSet/Wireless Registry Service s’est terminé de
façon inattendue pour la 1ème fois.
Error: (09/21/2022 11:49:48 PM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: Le service myCANAL Server s’est terminé de façon inattendue pour la
1ème fois.
Windows Defender:
================
Date: 2022-09-22 00:34:28
Description:
Antivirus Microsoft Defender a détecté un logiciel malveillant ou potentiellement
indésirable.
Pour plus d’informations, reportez-vous aux éléments suivants :
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Wacatac.H!
ml&threatid=2147814524&enterprise=0
Nom : Trojan:Script/Wacatac.H!ml
ID : 2147814524
Gravité : Grave
Catégorie : Cheval de Troie
Chemin : file:_C:\Users\rapau\Pictures\Minor Policy\66ZUlz3FB1QTUVoMWmZxtPfn.exe;
file:_C:\Users\rapau\Pictures\Minor Policy\e4bUrYRFPGp09FloREFoPEXY.exe
Origine de la détection : Ordinateur local
Type de détection : Chemin rapide
Source de détection : Protection en temps réel
Utilisateur : AUTORITE NT\Système
Nom du processus : C:\Program Files (x86)\PCProtect\SecurityService.exe
Version de la veille de sécurité : AV: 1.375.758.0, AS: 1.375.758.0, NIS:
1.375.758.0
Version du moteur : AM: 1.1.19600.3, NIS: 1.1.19600.3
CodeIntegrity:
===============
Date: 2022-09-22 00:12:54
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\
Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe) attempted to load \
Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\
igdlh64.inf_amd64_ceba516baea4bed9\igd10iumd64.dll that did not meet the Custom 3 /
Antimalware signing level requirements.
==========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 9E270CB2)
Partition: GPT.
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: C8D8444C)
Partition: GPT.