Système ralenti et processeur tourne beaucoup

gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   -  
jacques.gache Messages postés 34829 Statut Contributeur sécurité -
Bonjour,

Mon ordinateur est très ralenti alors que j'ai supprimé un nombre de programmes, fais des controles anti-virus et malwares. Quelqu'un peut-il m'aider en regardant le rapport Hijackthis :

https://sendbox.fr/index.php?/pro/n1ib5hyt24b9/hijackthis.log.html

Merci

15 réponses

  1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
     
    bonjour, poste un zhpdiag en utilsant les hébergeurs conseillé , merci

    Ouvre ce lien et télécharge ZHPDiag :

    https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

    Enregistres le sur ton Bureau.

    Une fois le téléchargement achevé

    pour XP, double-clique sur ZHPDiag

    pour Vista,et seven tu fais un clic droit sur l'icône et exécute en tant qu'administrateur.

    N'oublies pas de cocher la case qui permet de mettre un raccourci sur le Bureau.

    /|\ l'outil a créé 2 icônes ZHPDiag et ZHPFix.

    Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!

    Cliques sur la loupe pour lancer l'analyse.

    si tu as un message te demandant la validation pour SIGCHECK acceptes avec OK cela est pour nous faire un rapport plus complet et pouvoir en faire une lecture plus approfondis

    Laisses l'outil travailler, il peut être assez long

    A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.

    Fermes ZHPDiag en fin d'analyse.

    Pour me le transmettre clique sur ce lien :

    https://www.cjoint.com/

    Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt

    ou directement en choisissant bureau et ZHPDiag.txt clique dessus

    Clique sur Ouvrir.

    Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://cjoint.com/data/0KAoeRbq7Szgg.htm

    est ajouté dans la page.

    Copie ce lien dans ta réponse.

    et si problème passe par celui ci : http://pjjoint.malekal.com/
    0
  2. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    Bonjour,

    et merci.

    Voici le lien : https://www.cjoint.com/?3CftZc73EbX

    A noter que Citrix est le client serveur que j'utilise à des fins professionnels.

    Le constat est que mon ordinateur rame, qu'il met du temps à ourvir des applications, etc...

    Merci de ton aide
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      ok tu fais se qui suit et tu nous dira comment va le pc !!

      mais il faudra désinstaller un de tes antivirus car tu as ANTIVIR et Microsoft Security Essentials d'actif ,et pour ralentir voir planter le pc on ne fait pas mieux !!!!

      O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe
      O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Avira System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe

      1) tu fais zhpfix comme expliqué

      tu prends le temps de lire la procédure avant de lancer , merci

      . Copie les lignes suivantes en GRAS




      SysRestore
      O2 - BHO: Partner BHO Class [64Bits] - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} . (.Google Inc. - Partner application.) -- C:\ProgramData\Partner\Partner.dll
      [HKLM\Software\Wow6432Node\Iminent]
      O43 - CFD: 20/01/2013 - 16:10:16 - [0,989] ----D C:\Program Files (x86)\Iminent
      O43 - CFD: 12/07/2012 - 22:11:18 - [0] ----D C:\ProgramData\Babylon
      O43 - CFD: 04/05/2011 - 16:38:12 - [1,446] ----D C:\ProgramData\Partner
      O43 - CFD: 12/07/2012 - 22:11:18 - [0,003] ----D C:\Users\XXX\AppData\Roaming\Babylon
      O43 - CFD: 12/01/2013 - 16:40:27 - [1,095] ----D C:\Users\XXX\AppData\Roaming\Iminent
      O43 - CFD: 12/07/2012 - 22:11:19 - [1,221] ----D C:\Users\XXX\AppData\Local\Babylon
      O53 - SMSR:HKLM\...\startupreg\Iminent [Key] . (...) -- C:\Program Files (x86)\Iminent\Iminent.exe (.not file.)
      O53 - SMSR:HKLM\...\startupreg\IminentMessenger [Key] . (...) -- C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (.not file.)
      [MD5.7A8D0014483D71EC0E7E838078A3077C] [SPRF][29/01/2013] (.Bandoo Media Inc - Free mp3 Wma Converter Install.) -- C:\Users\XXX\Desktop\Setup_FreeConverter.exe [458080]
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}]
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}]
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}]
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}]
      C:\Program Files (x86)\Iminent
      C:\ProgramData\Babylon
      C:\ProgramData\Partner
      C:\Users\XXX\AppData\Roaming\Babylon
      C:\Users\XXX\AppData\Roaming\Iminent
      C:\Users\XXX\AppData\Local\Babylon
      C:\Users\XXX\AppData\LocalLow\Toolbar4
      C:\Users\XXX\AppData\Local\Temp\GoogleToolbarInstaller1.log
      C:\Users\XXX\Desktop\Setup_FreeConverter.exe
      C:\program files\partner\partner.dll
      C:\program files\iminent\iminent.exe
      C:\program files\iminent\iminent.messengers.exe
      C:\users\xxx\desktop\setup_freeconverter.exe
      C:\program files\partner\partner.exe
      SR - | Demand 04/05/2011 332272 | (Partner Service) . (.Google Inc..) - C:\ProgramData\Partner\Partner.exe
      FirewallRAZ
      EmptyCLSID
      EmptyTemp
      EmptyFlash




      . Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau

      . double-clique sur ZHPFix accepte l'élévation des droits avec ok


      Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

      si c'est pas le cas: Clique sur gauche sur l'icone du millieu (« coller le presse papier »)

      Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.



      !! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!



      . cliques sur GO confirmes le nettoyage !!

      . Copie/colle la totalité du rapport dans ta prochaine réponse
      tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport

      tuto si besoin merci saachaa !!






      2) fais adwcleaner mode SUPPRESSION


      Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.

      Lance le,et afin de pas supprimer ask qui est liéé à antivir

      # Clique sur "?" (en haut à gauche) puis sur "Options"
      # Coche /DisableAskDetection
      # Clique sur OK pour refermer la fenêtre, ensuite suis la procédure ci-dessous.


      clique sur [Suppression] puis patiente le temps du scan.

      Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.

      Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt



      3) donnes des nouvelle du pc et postes un nouveau zhpdiag pour contrôle

      Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!

      Cliques sur la loupe pour lancer l'analyse.

      si tu as un message te demandant la validation pour SIGCHECK acceptes avec OK cela est pour nous faire un rapport plus complet et pouvoir en faire une lecture plus approfondis

      Laisses l'outil travailler, il peut être assez long

      A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.


      Fermes ZHPDiag en fin d'analyse.


      Pour me le transmettre clique sur ce lien :

      https://www.cjoint.com/


      Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt

      ou directement en choisissant bureau et ZHPDiag.txt clique dessus

      Clique sur Ouvrir.

      Clique sur "Cliquez ici pour déposer le fichier".

      Un lien de cette forme :

      http://cjoint.com/data/0KAoeRbq7Szgg.htm

      est ajouté dans la page.

      Copie ce lien dans ta réponse.


      et si problème passe par celui ci : http://pjjoint.malekal.com/
      0
  3. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    Merci pour tout... mais le système reste lent : 5 mn pour s'ouvrir et même temps pour se fermer.

    Voici les liens :

    https://www.cjoint.com/?3CfwIk7CTOj

    et les rapports

    Rapport de ZHPFix 1.4.01 par Nicolas Coolman, Update du 02/03/2013
    Fichier d'export Registre :
    Run by H GIRAUD at 05/03/2013 21:59:33
    High Elevated Privileges : OK
    Windows 7 Business Edition, 64-bit Service Pack 1 (Build 7601)

    Corbeille vidée

    ========== Clé(s) du Registre ==========
    ERREUR Key****: CLSID BHO: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
    ERREUR Key****: HKLM\Software\Wow6432Node\Iminent
    ERREUR Key****: StartupReg: Iminent
    ERREUR Key****: StartupReg: IminentMessenger
    SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
    SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
    ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    ERREUR Key****: Service: Partner Service

    ========== Valeur(s) du Registre ==========
    ABSENT Valeur Standard Profile: FirewallRaz :
    ABSENT Valeur Domain Profile: FirewallRaz :
    Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)

    ========== Dossier(s) ==========
    SUPPRIME Folder: C:\Users\H GIRAUD\AppData\Local\{26206A91-1001-43BD-AADB-05CAF70E4DFD}
    SUPPRIME Folder: C:\Users\H GIRAUD\AppData\Local\{3709A7BF-FF33-4D99-8843-25A18ECA5771}
    SUPPRIME Folder: C:\Users\H GIRAUD\AppData\Local\{54ABB6B0-71BB-4848-B77F-23D9EF9AFC08}
    SUPPRIME Folder: C:\Users\H GIRAUD\AppData\Local\{6CEECF45-61A5-4E5E-A0B9-2B6E80E67D82}
    SUPPRIME Folder: C:\Users\H GIRAUD\AppData\Local\{7DE70B67-AEC8-47F5-9DFD-FE79FA5138AE}
    SUPPRIME Temporaires Windows
    SUPPRIME Flash Cookies

    ========== Fichier(s) ==========
    SUPPRIME Reboot c:\programdata\partner\partner.dll
    ABSENT File: c:\program files (x86)\iminent\iminent.exe
    ABSENT Folder/File: c:\users\xxx\desktop\setup_freeconverter.exe
    ABSENT Folder/File: c:\users\xxx\appdata\roaming\babylon
    ABSENT Folder/File: c:\users\xxx\appdata\roaming\iminent
    ABSENT Folder/File: c:\users\xxx\appdata\local\babylon
    ABSENT Folder/File: c:\users\xxx\appdata\locallow\toolbar4
    ABSENT Folder/File: c:\users\xxx\appdata\local\temp\googletoolbarinstaller1.log
    ABSENT Folder/File: c:\program files\partner\partner.dll
    ABSENT Folder/File: c:\program files\iminent\iminent.exe
    ABSENT Folder/File: c:\program files\iminent\iminent.messengers.exe
    ABSENT Folder/File: c:\program files\partner\partner.exe
    SUPPRIME Reboot c:\programdata\partner\partner.exe
    SUPPRIME Temporaires Windows
    SUPPRIME Flash Cookies

    ========== Restauration Système ==========
    Point de restauration non crée

    ========== Récapitulatif ==========
    9 : Clé(s) du Registre
    3 : Valeur(s) du Registre
    7 : Dossier(s)
    15 : Fichier(s)
    1 : Restauration Système

    End of clean in 00mn 16s

    ========== Chemin de fichier rapport ==========
    C:\ZHP\ZHPFix[R1].txt - 05/03/2013 21:59:33 [2920]

    # AdwCleaner v2.114 - Rapport créé le 05/03/2013 à 22:14:16
    # Mis à jour le 05/03/2013 par Xplode
    # Système d'exploitation : Windows 7 Professional Service Pack 1 (64 bits)
    # Nom d'utilisateur : H GIRAUD - HGIRAUD
    # Mode de démarrage : Normal
    # Exécuté depuis : D:\Temp\adwcleaner.exe
    # Option [Suppression]
    # Commutateur(s) utilisé(s) : /DisableAskDetection

    ***** [Services] *****

    Arrêté & Supprimé : Partner Service

    ***** [Fichiers / Dossiers] *****

    Dossier Supprimé : C:\Program Files (x86)\Conduit
    Dossier Supprimé : C:\Program Files (x86)\Iminent
    Dossier Supprimé : C:\ProgramData\Babylon
    Dossier Supprimé : C:\ProgramData\boost_interprocess
    Dossier Supprimé : C:\ProgramData\Partner
    Dossier Supprimé : C:\Users\H GIRAUD\AppData\Local\Babylon
    Dossier Supprimé : C:\Users\H GIRAUD\AppData\Local\Conduit
    Dossier Supprimé : C:\Users\H GIRAUD\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl
    Dossier Supprimé : C:\Users\H GIRAUD\AppData\Local\Wajam
    Dossier Supprimé : C:\Users\H GIRAUD\AppData\LocalLow\Conduit
    Dossier Supprimé : C:\Users\H GIRAUD\AppData\LocalLow\Toolbar4
    Dossier Supprimé : C:\Users\H GIRAUD\AppData\Roaming\Babylon
    Dossier Supprimé : C:\Users\H GIRAUD\AppData\Roaming\Iminent

    ***** [Registre] *****

    Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    Clé Supprimée : HKCU\Software\Softonic
    Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{28A88B70-D874-4F73-BBBA-9B2B222FB7D6}
    Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
    Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\kt_bho_dll.dll
    Clé Supprimée : HKLM\SOFTWARE\Classes\kt_bho.KettleBho
    Clé Supprimée : HKLM\SOFTWARE\Classes\kt_bho.KettleBho.1
    Clé Supprimée : HKLM\SOFTWARE\Classes\Prod.cap
    Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
    Clé Supprimée : HKLM\Software\Iminent
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
    Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
    Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}

    ***** [Navigateurs] *****

    #NOM?

    [OK] Le registre ne contient aucune entrée illégitime.

    -\\ Google Chrome v [Impossible d'obtenir la version]

    Fichier : C:\Users\H GIRAUD\AppData\Local\Google\Chrome\User Data\Default\Preferences

    [OK] Le fichier ne contient aucune entrée illégitime.

    *************************

    AdwCleaner[S1].txt - [4080 octets] - [05/03/2013 22:14:16]

    ########## EOF - C:\AdwCleaner[S1].txt - [4140 octets] ##########
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      bon il y a des reste tu refais un zhpfix avec les choses donnés et puis après un redémarrage tu postes un nouveau zhpdiag !! merci

      tu fais zhpfix comme expliqué , tu prends le temps de lire la procédure avant de lancer , merci

      . Copie les lignes suivantes en GRAS




      SysRestore
      O53 - SMSR:HKLM\...\startupreg\Iminent [Key] . (...) -- C:\Program Files (x86)\Iminent\Iminent.exe (.not file.)
      O53 - SMSR:HKLM\...\startupreg\IminentMessenger [Key] . (...) -- C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (.not file.)
      [MD5.7A8D0014483D71EC0E7E838078A3077C] [SPRF][29/01/2013] (.Bandoo Media Inc - Free mp3 Wma Converter Install.) -- C:\Users\H AAA\Desktop\Setup_FreeConverter.exe [458080]
      [HKLM\Software\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}]
      [HKLM\Software\Wow6432Node\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}]
      [HKLM\Software\Classes\TypeLib\{93e3d79c-0786-48ff-9329-93bc9f6dc2b3}]
      [HKLM\Software\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}]
      [HKLM\Software\Wow6432Node\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}]
      [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Iminent]
      C:\Users\H AAA\Desktop\Setup_FreeConverter.exe
      C:\program files\iminent\iminent.exe
      C:\program files\iminent\iminent.messengers.exe
      C:\users\h aaa\desktop\setup_freeconverter.exe
      FirewallRAZ
      EmptyCLSID
      EmptyTemp
      EmptyFlash




      . Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau

      . double-clique sur ZHPFix accepte l'élévation des droits avec ok


      Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

      si c'est pas le cas: Clique sur gauche sur l'icone du millieu (« coller le presse papier »)

      Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.



      !! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!



      . cliques sur GO confirmes le nettoyage !!

      . Copie/colle la totalité du rapport dans ta prochaine réponse
      tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport

      tuto si besoin merci saachaa !!
      0
  4. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    J'avauis une première fois fait ZHPFix sans arrêter l'explorateur (1er rapport) donc j'ai fait un deuxième passage (2eme rapport)

    1ere rapport
    Rapport de ZHPFix 1.4.01 par Nicolas Coolman, Update du 02/03/2013
    Fichier d'export Registre :
    Run by H GIRAUD at 05/03/2013 23:06:11
    High Elevated Privileges : OK
    Windows 7 Business Edition, 64-bit Service Pack 1 (Build 7601)

    Corbeille vidée

    ========== Clé(s) du Registre ==========
    SUPPRIME Key*: StartupReg: Iminent
    SUPPRIME Key*: StartupReg: IminentMessenger
    SUPPRIME Key*: HKLM\Software\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}
    ABSENT Key: HKLM\Software\Wow6432Node\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}
    SUPPRIME Key: HKLM\Software\Classes\TypeLib\{93e3d79c-0786-48ff-9329-93bc9f6dc2b3}
    SUPPRIME Key*: HKLM\Software\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}
    ABSENT Key: HKLM\Software\Wow6432Node\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}
    ABSENT Key: HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Iminent

    ========== Valeur(s) du Registre ==========
    ABSENT Valeur Standard Profile: FirewallRaz :
    ABSENT Valeur Domain Profile: FirewallRaz :

    ========== Dossier(s) ==========
    Aucun dossiers CLSID Local utilisateur vide
    SUPPRIME Temporaires Windows
    SUPPRIME Flash Cookies

    ========== Fichier(s) ==========
    ABSENT File: c:\program files (x86)\iminent\iminent.exe
    ABSENT Folder/File: c:\users\h aaa\desktop\setup_freeconverter.exe
    ABSENT Folder/File: c:\program files\iminent\iminent.exe
    ABSENT Folder/File: c:\program files\iminent\iminent.messengers.exe
    SUPPRIME Temporaires Windows
    SUPPRIME Flash Cookies

    ========== Restauration Système ==========
    Point de restauration du système créé avec succès

    ========== Récapitulatif ==========
    8 : Clé(s) du Registre
    2 : Valeur(s) du Registre
    3 : Dossier(s)
    6 : Fichier(s)
    1 : Restauration Système

    End of clean in 00mn 39s

    ========== Chemin de fichier rapport ==========
    C:\ZHP\ZHPFix[R1].txt - 05/03/2013 21:59:33 [2972]
    C:\ZHP\ZHPFix[R2].txt - 05/03/2013 23:06:11 [1905]

    2eme rapport
    Rapport de ZHPFix 1.4.01 par Nicolas Coolman, Update du 02/03/2013
    Fichier d'export Registre :
    Run by H GIRAUD at 05/03/2013 23:09:43
    High Elevated Privileges : OK
    Windows 7 Business Edition, 64-bit Service Pack 1 (Build 7601)

    Corbeille vidée

    ========== Clé(s) du Registre ==========
    ABSENT Key: StartupReg: Iminent
    ABSENT Key: StartupReg: IminentMessenger
    ABSENT Key: HKLM\Software\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}
    ABSENT Key: HKLM\Software\Wow6432Node\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}
    ABSENT Key: HKLM\Software\Classes\TypeLib\{93e3d79c-0786-48ff-9329-93bc9f6dc2b3}
    ABSENT Key: HKLM\Software\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}
    ABSENT Key: HKLM\Software\Wow6432Node\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}
    ABSENT Key: HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Iminent

    ========== Valeur(s) du Registre ==========
    ABSENT Valeur Standard Profile: FirewallRaz :
    ABSENT Valeur Domain Profile: FirewallRaz :

    ========== Dossier(s) ==========
    Aucun dossiers CLSID Local utilisateur vide
    SUPPRIME Temporaires Windows
    SUPPRIME Flash Cookies

    ========== Fichier(s) ==========
    ABSENT File: c:\program files (x86)\iminent\iminent.exe
    ABSENT Folder/File: c:\users\h aaa\desktop\setup_freeconverter.exe
    ABSENT Folder/File: c:\program files\iminent\iminent.exe
    ABSENT Folder/File: c:\program files\iminent\iminent.messengers.exe
    SUPPRIME Temporaires Windows
    SUPPRIME Flash Cookies

    ========== Restauration Système ==========
    Point de restauration du système créé avec succès

    ========== Récapitulatif ==========
    8 : Clé(s) du Registre
    2 : Valeur(s) du Registre
    3 : Dossier(s)
    6 : Fichier(s)
    1 : Restauration Système

    End of clean in 00mn 11s

    ========== Chemin de fichier rapport ==========
    C:\ZHP\ZHPFix[R1].txt - 05/03/2013 21:59:33 [2972]
    C:\ZHP\ZHPFix[R2].txt - 05/03/2013 23:06:11 [1957]
    C:\ZHP\ZHPFix[R3].txt - 05/03/2013 23:09:43 [1943]
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    Bonjour,

    Je pense que vous devez être saturé de messages; mais si nous pouvions finaliser le nettoyage car ordinateur toujours lent à s'ouvrir.

    Merci beaucoup
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      fais se qui suit , merci

      1) delfix pour nettoyer les outils et leurs rapports

      télécharge delfix ( merci xplode)

      compatible avec Windows XP, Vista, 7, 8 versions 32 & 64 bits.

      lances delfix

      et coche Suppression des outils de désinfection

      et coche Purger la restauration système

      et puis Réinitialiser les paramètres système

      ne pas oublier de cliquer sur "executer"

      une fois fais tu cliques droit sur un espace vide de ton bureau

      et puis nouveau document texte

      tu l'ouvre et tu fais clique droit dedans et copier

      normalement tu devrait avoir le rapport de delfix tu me le postes

      par le biais d'un hébergeur !!

      http://pjjoint.malekal.com/



      2) fais un nettoyage avec ccleaner et les réglages donnés


      télécharges Ccleaner à partir de cette adresses

      https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/


      .enregistres le sur le bureau
      .double-cliques si sous XP sinon pour vista et seven clique droit et en tant que administrateur sur le fichier pour lancer l'installation
      .sur la fenêtre de l'installation langage bien choisir français et OK
      .cliques sur suivant
      .lis la licence et j'accepte
      .cliques sur suivant
      .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner

      ATTENTION refuse l'installation de tous ce qui est google si pas intéressé !!

      .cliques sur intaller
      .cliques sur fermer
      .double-cliques si sous XP sinon pour vista et seven clique droit et en tant que administrateur sur l'icône de Ccleaner pour l'ouvrir
      .une fois ouvert tu cliques sur option et puis avancé
      .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures
      .cliques sur nettoyeur
      .cliques sur windows et dans la colonne avancé
      .cochesla première case vieilles données du perfetch que celle-la
      .cliques sur analyse une fois l'analyse terminé
      .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
      .cliques maintenant sur registre et puis sur rechercher les erreurs
      .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
      .il te demande de sauvegarder OUI
      .tu lui donnes un nom pour pouvoir la retrouver et enregistre
      .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
      .il supprime et fermer tu vériffis en relancant rechercher les erreurs
      .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
      .tu peux fermer Ccleaner

      pour aider si besion tutoriel: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
      0
  7. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    cela semble aller un peu mieux, mais rame toujours pour ouvrir plusieurs fichiers; par exemple mets 1mn à ouvrir un fichier Excel quand il y en a un d'ouvert ????

    Merci pour ton aide
    0
  8. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    up svp
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      ton pc est un fixe ou un portable ??

      y a t'il longtemps que tu as fais une défragmentation ?? et un nettoyage disque ??
      0
  9. gramond
     
    Bonjour,

    Un portable et régulièrement je fais un scandisk /F /R

    Veux-tu que je te refasse un ZHPDiag pour voir où il en est ?

    Merci
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      ok mais un chkdsk /f /r ne règle pas tous vois avec une défragmentaion


      Pour défragmenter votre disque dur

      Pour ouvrir Défragmenteur de disque, cliquez sur le bouton Démarrer. Dans la zone de recherche, tapez Défragmenteur de disque, puis, dans la liste des résultats, cliquez sur Défragmenteur de disque.

      Sous État actuel, sélectionnez le disque à défragmenter.

      Pour déterminer si le disque doit être défragmenté ou non, cliquez sur Analyser le disque. Si vous êtes invité à fournir un mot de passe administrateur ou une confirmation, fournissez le mot de passe ou la confirmation.

      Une fois que Windows a terminé l'analyse du disque, vous pouvez vérifier le pourcentage de fragmentation sur le disque dans la colonne Dernière exécution. Si le chiffre est supérieur à 10%, vous devez défragmenter le disque.

      Cliquez sur Défragmenter le disque. Si vous êtes invité à fournir un mot de passe administrateur ou une confirmation, fournissez le mot de passe ou la confirmation.
      0
  10. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    En fait 0% fragenté donc pas besoin de défragmentation

    Merci de me dire ce qu'il est possible de faire pour accélérer cet ordi
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      bon c'est bizarre !!! passes combofix c'est un outils des plus puissant dans le dommaine de la désinfection, tu suis bien la procédure ni plus ni moins et pas de problèmes !!

      Désactive le contrôle des comptes utilisateurs
      (tu le réactiveras après ta désinfection):

      .Rendez-vous dans le panneau de configuration.

      .Cliquez ensuite sur "Comptes et protection des utilisateurs"

      .Puis sur "Comptes d'utilisateurs".

      .Cliquez ensuite sur "Modifier les paramètres de contrôle de compte d'utilisateur"

      .Sur la fenêtre suivante placez le curseur tout en bas sur "Ne jamais m'avertir".

      .Validez puis confirmez une dernière fois votre identité.


      Attention, la désactivation de cette fonctionnalité peut entrainer la diminution de la sécurité au sein de votre ordinateur.




      PS: pensez à remettre le contrôle après désinfection



      tuto : http://www.depannetonpc.net/fiches-pratiques/lire_62_1_desactiver-l-uac-sous-windows-7.html



      Avant d'utiliser ComboFix :

      Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection.

      si tu as ce genre de d'outils sur ton pc Utilise Defogger pour les désactiver temporairement : sinon passe directement à combofix

      . Télécharge http://www.jpshortstuff.247fixes.com/Defogger.exe Defogger (de jpshortstuff) sur ton Bureau

      . Lance le

      Une fenêtre apparait : clique sur "Disable"

      . Fais redémarrer l'ordinateur si l'outil te le demande

      Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"




      Tutoriel officiel prends le temps de le regarder : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

      et note bien cette manipe https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix#restore car des fois après combofix la connection internet est déactivée



      télécharge combofix (par sUBs) ici :

      http://download.bleepingcomputer.com/sUBs/ComboFix.exe

      et enregistre le sur le bureau.

      déconnecte toi d'internet et ferme toutes tes applications.

      désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

      cliques droit sur combofix.exe et exécuter en tant que administrateur et suis les instructions

      Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

      sauf pour répondre quand il de le demande !!


      à la fin, il va produire un rapport C:\ComboFix.txt

      réactive ton parefeu, ton antivirus, la garde de ton antispyware et l'UAC

      copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.
      0
  11. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    Bonsoir

    ComboFix 13-03-13.02 - H GIRAUD 13/03/2013 21:47:21.1.4 - x64
    Microsoft Windows 7 Professionnel 6.1.7601.1.1252.33.1036.18.3884.1671 [GMT 1:00]
    Lancé depuis: d:\temp\ComboFix.exe
    AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
    SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
    c:\programdata\AMMYY
    c:\programdata\AMMYY\hr
    c:\programdata\AMMYY\hr3
    c:\programdata\AMMYY\settings3.bin
    c:\programdata\FullRemove.exe
    c:\windows\AsPatch10430001.exe
    c:\windows\msvcr71.dll
    D:\install.exe
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2013-02-13 au 2013-03-13 ))))))))))))))))))))))))))))))))))))
    .
    .
    2013-03-13 17:55 . 2013-02-02 06:38 96768 ----a-w- c:\windows\system32\mshtmled.dll
    2013-03-13 15:51 . 2013-03-13 16:08 -------- d-----w- c:\users\H GIRAUD\AppData\Roaming\WindSolutions
    2013-03-13 15:51 . 2013-03-13 16:01 -------- d-----w- c:\programdata\WindSolutions
    2013-03-13 15:33 . 2013-03-13 15:33 -------- d-----w- c:\users\H GIRAUD\AppData\Roaming\iPodtoComputer
    2013-03-13 15:32 . 2008-12-17 12:22 57344 ----a-w- c:\windows\SysWow64\ff_vfw.dll
    2013-03-13 15:32 . 2008-06-15 08:13 6144 ----a-w- c:\windows\SysWow64\ff_acm.acm
    2013-03-13 15:32 . 2008-06-14 21:01 60273 ----a-w- c:\windows\SysWow64\pthreadGC2.dll
    2013-03-13 15:32 . 2008-06-14 21:01 258352 ----a-w- c:\windows\SysWow64\unicows.dll
    2013-03-13 15:32 . 2003-03-24 17:49 98304 ----a-w- c:\windows\SysWow64\L3CODECX.AX
    2013-03-13 15:28 . 2013-03-13 15:29 -------- d-----w- c:\users\H GIRAUD\AppData\Roaming\iPhone Tool Kits
    2013-03-13 15:28 . 2009-07-01 01:16 94854 ----a-w- c:\windows\system32\HKCU_GNU.reg
    2013-03-13 15:28 . 2009-02-26 02:34 2004 ----a-w- c:\windows\system32\HKLM_GNU.reg
    2013-03-13 15:28 . 2008-12-17 11:22 57344 ----a-w- c:\windows\system32\ff_vfw.dll
    2013-03-13 15:28 . 2008-06-15 07:13 6144 ----a-w- c:\windows\system32\ff_acm.acm
    2013-03-13 15:28 . 2008-06-14 20:01 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
    2013-03-13 15:28 . 2008-06-14 20:01 258352 ----a-w- c:\windows\system32\unicows.dll
    2013-03-13 15:28 . 2006-07-17 07:42 14909 ----a-w- c:\windows\system32\A_reg.reg
    2013-03-13 15:28 . 2003-03-24 16:49 98304 ----a-w- c:\windows\system32\L3CODECX.AX
    2013-03-13 15:28 . 2003-03-18 08:20 1060864 ----a-w- c:\windows\system32\MFC71.DLL
    2013-03-13 15:28 . 2003-03-18 07:14 499712 ----a-w- c:\windows\system32\MSVCP71.DLL
    2013-03-13 15:28 . 2003-02-20 15:42 348160 ----a-w- c:\windows\system32\MSVCR71.DLL
    2013-03-12 18:14 . 2013-03-13 20:49 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9301590E-0959-4146-ACFB-E85BCE976BE4}\offreg.dll
    2013-03-12 11:26 . 2013-02-19 02:57 9162192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9301590E-0959-4146-ACFB-E85BCE976BE4}\mpengine.dll
    2013-03-11 15:52 . 2013-03-11 15:53 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
    2013-03-11 15:52 . 2013-03-11 15:53 -------- d-----w- c:\program files\iTunes
    2013-03-11 15:52 . 2013-03-11 15:53 -------- d-----w- c:\program files (x86)\iTunes
    2013-03-11 15:52 . 2013-03-11 15:52 -------- d-----w- c:\program files\iPod
    2013-03-05 17:18 . 2013-03-05 17:18 388096 ----a-r- c:\users\H GIRAUD\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2013-02-26 08:55 . 2013-02-26 08:55 -------- d-----w- c:\users\H GIRAUD\AppData\Local\Programs
    2013-02-14 10:47 . 2013-01-09 01:10 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
    2013-02-14 10:47 . 2013-01-08 22:01 768000 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
    2013-02-14 09:23 . 2013-01-05 05:53 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe
    2013-02-14 09:23 . 2013-01-05 05:00 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
    2013-02-14 09:23 . 2013-01-05 05:00 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
    2013-02-14 09:23 . 2013-01-04 03:26 3153408 ----a-w- c:\windows\system32\win32k.sys
    2013-02-14 09:23 . 2013-01-04 05:46 215040 ----a-w- c:\windows\system32\winsrv.dll
    2013-02-14 09:23 . 2013-01-04 04:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll
    2013-02-14 09:23 . 2013-01-04 02:47 25600 ----a-w- c:\windows\SysWow64\setup16.exe
    2013-02-14 09:23 . 2013-01-04 02:47 7680 ----a-w- c:\windows\SysWow64\instnm.exe
    2013-02-14 09:23 . 2013-01-04 02:47 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
    2013-02-14 09:23 . 2013-01-04 02:47 2048 ----a-w- c:\windows\SysWow64\user.exe
    2013-02-14 09:22 . 2013-01-03 06:00 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2013-02-14 09:22 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-03-13 21:09 . 2012-03-27 21:07 45056 ----a-w- c:\windows\system32\acovcnt.exe
    2013-03-13 18:46 . 2012-03-28 03:16 72013344 ----a-w- c:\windows\system32\MRT.exe
    2013-02-12 05:45 . 2013-03-13 14:50 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
    2013-02-12 05:45 . 2013-03-13 14:50 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
    2013-02-12 05:45 . 2013-03-13 14:50 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
    2013-02-12 05:45 . 2013-03-13 14:50 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
    2013-02-12 04:48 . 2013-03-13 14:50 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
    2013-02-12 04:48 . 2013-03-13 14:50 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
    2013-01-17 00:28 . 2012-03-27 21:41 273840 ------w- c:\windows\system32\MpSigStub.exe
    2013-01-14 11:15 . 2012-11-08 22:24 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-01-14 11:15 . 2012-11-08 22:24 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2013-01-04 04:43 . 2013-02-14 09:23 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    2012-12-28 12:11 . 2012-12-28 12:11 95184 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
    2012-12-28 12:11 . 2012-12-28 12:11 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2012-12-28 12:11 . 2012-12-28 12:11 859072 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
    2012-12-16 17:11 . 2012-12-21 14:10 46080 ----a-w- c:\windows\system32\atmlib.dll
    2012-12-16 14:45 . 2012-12-21 14:09 367616 ----a-w- c:\windows\system32\atmfd.dll
    2012-12-16 14:13 . 2012-12-21 14:09 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
    2012-12-16 14:13 . 2012-12-21 14:10 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
    2012-12-14 15:49 . 2012-03-31 06:16 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 129272 ----a-w- c:\users\H GIRAUD\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 129272 ----a-w- c:\users\H GIRAUD\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 129272 ----a-w- c:\users\H GIRAUD\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-05-04 39408]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-02-12 385248]
    "ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2012-04-05 371864]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "EnableLUA"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "LoadAppInit_DLLs"=1 (0x1)
    "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll c:\progra~2\Citrix\ICACLI~1\RSHook.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
    "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "c:\programdata\Nuance\PDF Reader\Ereg\Ereg.ini"
    "Bonus.SSR.FR10"="c:\program files (x86)\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" /autorun
    "ownCloud"=c:\program files (x86)\ownCloud\owncloud.exe
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    "ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" /startup
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
    R3 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2010-07-22 814344]
    R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-05-11 99384]
    R3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\DRIVERS\DisplayLinkUsbPort_6.1.36484.0.sys [2012-02-08 17408]
    R3 driverhardwarev2x64;driverhardwarev2x64;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys [2011-07-21 16640]
    R3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\DRIVERS\USBMAC64.SYS [2009-12-08 55296]
    R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
    R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-05-11 203320]
    R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-12-13 54784]
    R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-03-28 1255736]
    R4 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2010-11-30 379520]
    R4 maconfservice;Ma-Config Service;c:\program files\ma-config.com\x64\maconfservice.exe [2011-11-25 427640]
    R4 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
    R4 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
    R4 VideAceWindowsService;VideAceWindowsService;c:\expressgateutil\VAWinService.exe [2010-08-21 77312]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
    S0 AiCharger;AiCharger; [x]
    S0 dlkmdldr;dlkmdldr;c:\windows\system32\drivers\dlkmdldr.sys [2012-02-08 15184]
    S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2012-04-03 28992]
    S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [2012-09-07 101688]
    S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-09-24 27800]
    S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2012-02-13 93272]
    S1 RapportCerberus_43926;RapportCerberus_43926;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys [2012-10-30 505720]
    S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2012-09-07 55096]
    S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2012-09-07 297240]
    S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2013-02-12 86752]
    S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
    S2 BotkindSyncService;Botkind Service;c:\program files (x86)\Allway Sync\Bin\SyncService.exe service [x]
    S2 DisplayLinkService;DisplayLinkManager;c:\program files\DisplayLink Core Software\DisplayLinkManager.exe [2012-02-08 8454064]
    S2 FPLService;TrueSuiteService;c:\program files\TrueSuite\TrueSuite.Service.exe [2010-12-10 290632]
    S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-02-01 13592]
    S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2012-09-07 976728]
    S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2009-07-13 11576]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-04-03 382272]
    S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2012-05-29 2143072]
    S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-04-16 13832]
    S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-04-16 134928]
    S3 ATSwpWDF;AuthenTec TruePrint WBF Driver;c:\windows\system32\DRIVERS\ATSwpWDF.sys [2012-01-27 1073200]
    S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
    S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
    S3 dlkmd;dlkmd;c:\windows\system32\drivers\dlkmd.sys [2012-02-08 308560]
    S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [2010-11-19 210944]
    S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\DRIVERS\FLxHCIh.sys [2010-11-19 49664]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
    S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 158976]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
    S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2012-05-03 11856]
    .
    .
    --- Autres Services/Pilotes en mémoire ---
    .
    *NewlyCreated* - WS2IFSL
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2012-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-04 15:37]
    .
    2012-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-04 15:37]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
    @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
    [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
    2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
    @="{64174815-8D98-4CE6-8646-4C039977D808}"
    [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
    2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 162552 ----a-w- c:\users\H GIRAUD\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 162552 ----a-w- c:\users\H GIRAUD\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 162552 ----a-w- c:\users\H GIRAUD\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2012-11-13 23:32 162552 ----a-w- c:\users\H GIRAUD\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TSFPLOlayIcon]
    @="{F4DD9208-8229-492D-BCBF-2955F7AC38F4}"
    [HKEY_CLASSES_ROOT\CLSID\{F4DD9208-8229-492D-BCBF-2955F7AC38F4}]
    2010-12-10 09:49 298312 ----a-w- c:\program files\TrueSuite\TrueSuite.FPLOlayIcon.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
    FontCache
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.fr/
    uLocal Page = c:\windows\system32\blank.htm
    mStart Page = hxxp://asus.msn.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: Ajouter la cible du lien à un fichier PDF existant
    IE: Ajouter à un fichier PDF existant
    IE: Convertir au format Adobe PDF
    IE: Convertir la cible du lien au format Adobe PDF
    TCP: DhcpNameServer = 192.168.100.254
    .
    - - - - ORPHELINS SUPPRIMES - - - -
    .
    Toolbar-Locked - (no file)
    Wow6432Node-HKLM-Run-<NO NAME> - (no file)
    Toolbar-Locked - (no file)
    .
    .
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\066EC3472722869529D5FCF16DEA9447\6116D6C8427B0184F8D20D746E7B6DE8]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="Microsoft.WlcProfile.dll"
    "ComponentVersion"="3.0.40723.0"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\077222B419FAC715EBCBA0B9D42FEB38\6116D6C8427B0184F8D20D746E7B6DE8]
    @DACL=(02 0000)
    "PatchGUID"="{F8B9A3E9-B39A-4264-9B49-3B98D5A7549B}"
    "MediaCabinet"="Mesh_RTM_15.4.5727.26"
    "File"="MOE.exe"
    "ComponentVersion"="15.4.5727.26"
    "ProductVersion"="15.4.5722"
    "PatchSize"="2028"
    "PatchAttributes"="0"
    "PatchSequence"="10011"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\09DE0C32C713F3A5A820A4B7C6FCBB21\6116D6C8427B0184F8D20D746E7B6DE8]
    @DACL=(02 0000)
    "PatchGUID"="{F8B9A3E9-B39A-4264-9B49-3B98D5A7549B}"
    "MediaCabinet"="Mesh_RTM_15.4.5727.26"
    "File"="commengine.dll"
    "ComponentVersion"="15.4.5727.26"
    "ProductVersion"="15.4.5722"
    "PatchSize"="6268"
    "PatchAttributes"="0"
    "PatchSequence"="10001"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\0A4356EE41FB88F57AD002365A6F6CAF\6116D6C8427B0184F8D20D746E7B6DE8]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="System.Runtime.Serialization.Json.dll"
    "ComponentVersion"="3.0.40723.0"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\0A7CABAD55AF7665380C27C892D28949\06E1A36C4A6BB044985AF16C4ECAC149]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="logging.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\0A7CABAD55AF7665380C27C892D28949\2FD86640F23D5554C9E75325D3DC5644]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="logging.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\0A7CABAD55AF7665380C27C892D28949\389F20921C4BAB448BD5C5D6252E4C14]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="logging.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\0A7CABAD55AF7665380C27C892D28949\4F300D559959FB44ABE9590D0637D03D]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="logging.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\0A7CABAD55AF7665380C27C892D28949\98A8935CC615FAD4AB70EE979490E065]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="logging.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\0A7CABAD55AF7665380C27C892D28949\C55EC23CAB21159478799076DFFE55F6]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="logging.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\0A7CABAD55AF7665380C27C892D28949\D5BEE45EDE14EF044B8A5856BD1864B9]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="logging.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\14428D67F56C1735B943FD4865B3F162\6116D6C8427B0184F8D20D746E7B6DE8]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="System.Core.dll"
    "ComponentVersion"="3.0.40723.0"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\195B6659BAE0D2051844F796D33EA347\6116D6C8427B0184F8D20D746E7B6DE8]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="System.Xml.Serialization.dll"
    "ComponentVersion"="3.0.40723.0"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\226DC0EBA5C28EB5DAC753C594071F4A\06E1A36C4A6BB044985AF16C4ECAC149]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="utilclasses.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\226DC0EBA5C28EB5DAC753C594071F4A\2FD86640F23D5554C9E75325D3DC5644]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="utilclasses.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\226DC0EBA5C28EB5DAC753C594071F4A\389F20921C4BAB448BD5C5D6252E4C14]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="utilclasses.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\226DC0EBA5C28EB5DAC753C594071F4A\4F300D559959FB44ABE9590D0637D03D]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="utilclasses.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\226DC0EBA5C28EB5DAC753C594071F4A\98A8935CC615FAD4AB70EE979490E065]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="utilclasses.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\226DC0EBA5C28EB5DAC753C594071F4A\C55EC23CAB21159478799076DFFE55F6]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="utilclasses.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\226DC0EBA5C28EB5DAC753C594071F4A\D5BEE45EDE14EF044B8A5856BD1864B9]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="utilclasses.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2618C21E12EA7B154B468ADDCAF10B73\06E1A36C4A6BB044985AF16C4ECAC149]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="wlcmstscax.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2618C21E12EA7B154B468ADDCAF10B73\2FD86640F23D5554C9E75325D3DC5644]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="wlcmstscax.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2618C21E12EA7B154B468ADDCAF10B73\389F20921C4BAB448BD5C5D6252E4C14]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="wlcmstscax.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2618C21E12EA7B154B468ADDCAF10B73\4F300D559959FB44ABE9590D0637D03D]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="wlcmstscax.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2618C21E12EA7B154B468ADDCAF10B73\98A8935CC615FAD4AB70EE979490E065]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="wlcmstscax.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2618C21E12EA7B154B468ADDCAF10B73\C55EC23CAB21159478799076DFFE55F6]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="wlcmstscax.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2618C21E12EA7B154B468ADDCAF10B73\D5BEE45EDE14EF044B8A5856BD1864B9]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="wlcmstscax.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\007B61DEF19D0B4468C7E75B52C33AD8]
    @DACL=(02 0000)
    "PatchGUID"="{D18358D9-EA47-43FE-8EDD-AE236BA81AD0}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\0FB3B06AB459FA248B8DC2D1436B31AA]
    @DACL=(02 0000)
    "PatchGUID"="{7BF57B4D-05D3-4544-B9B9-D496F9CA3BC3}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\19A2C00C3BC6F384083B92852E49861F]
    @DACL=(02 0000)
    "PatchGUID"="{57BD0561-0FBF-4B81-A5F5-48BB8DE3CE3F}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\24199FEE7533C2042B89ED3C301ED229]
    @DACL=(02 0000)
    "PatchGUID"="{A5E1D52D-4B1D-4F5A-87F1-08CFF2221A4F}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\4A9D4F432C248434EB4F5E358C54947E]
    @DACL=(02 0000)
    "PatchGUID"="{58EEF18D-042C-4EC5-9963-DC289CE6035B}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\675B0CE09F093C34F8DA4A09D24F8B4F]
    @DACL=(02 0000)
    "PatchGUID"="{88A77F6E-FA53-4B26-8005-3F17FA76B885}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\7430F8847A4C4734197A0318B8DE7A01]
    @DACL=(02 0000)
    "PatchGUID"="{8A5DC760-0D2F-44E3-A71D-FE64E8D1FB7B}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\90F929EC35830814DB090367B4FF1763]
    @DACL=(02 0000)
    "PatchGUID"="{2B2FD0BF-7A97-442F-8154-45339D5803C8}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\C81D311B0B767BF43B928EB96691A46E]
    @DACL=(02 0000)
    "PatchGUID"="{57D00F5A-F226-4532-9287-02B48B3E4275}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\298A63D81D2067C4B81BB9F02033F636\CFE4A58E2F28EEC4A8E826DFDA53A366]
    @DACL=(02 0000)
    "PatchGUID"="{D529FB22-C2B3-4F44-9B70-2CD9E73C88AB}"
    "MediaCabinet"="PhotoLibraryLang_RTM_15.4.3555.0308"
    "File"="WLXPhotoAcq.dll.mui"
    "ComponentVersion"="15.4.3555.308"
    "ProductVersion"="15.4.3502"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="10002"
    "SharedComponent"="0"
    "IsFullFile"="1"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2A142A43F349FF751AAE191837F7F986\06E1A36C4A6BB044985AF16C4ECAC149]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="lkrhwlc.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2A142A43F349FF751AAE191837F7F986\2FD86640F23D5554C9E75325D3DC5644]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="lkrhwlc.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2A142A43F349FF751AAE191837F7F986\389F20921C4BAB448BD5C5D6252E4C14]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="lkrhwlc.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2A142A43F349FF751AAE191837F7F986\4F300D559959FB44ABE9590D0637D03D]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="lkrhwlc.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2A142A43F349FF751AAE191837F7F986\98A8935CC615FAD4AB70EE979490E065]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="lkrhwlc.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2A142A43F349FF751AAE191837F7F986\C55EC23CAB21159478799076DFFE55F6]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="lkrhwlc.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2A142A43F349FF751AAE191837F7F986\D5BEE45EDE14EF044B8A5856BD1864B9]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="lkrhwlc.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2C0B0827498FF8C58924C2FBF879ED5C\06E1A36C4A6BB044985AF16C4ECAC149]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="blackpipe.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2C0B0827498FF8C58924C2FBF879ED5C\2FD86640F23D5554C9E75325D3DC5644]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="blackpipe.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2C0B0827498FF8C58924C2FBF879ED5C\389F20921C4BAB448BD5C5D6252E4C14]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="blackpipe.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2C0B0827498FF8C58924C2FBF879ED5C\4F300D559959FB44ABE9590D0637D03D]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="blackpipe.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2C0B0827498FF8C58924C2FBF879ED5C\98A8935CC615FAD4AB70EE979490E065]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="blackpipe.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2C0B0827498FF8C58924C2FBF879ED5C\C55EC23CAB21159478799076DFFE55F6]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="blackpipe.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2C0B0827498FF8C58924C2FBF879ED5C\D5BEE45EDE14EF044B8A5856BD1864B9]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="blackpipe.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2CDAEC3A1CD5CD353B63AC65B259A6C0\06E1A36C4A6BB044985AF16C4ECAC149]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="WLRemoteResource.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2CDAEC3A1CD5CD353B63AC65B259A6C0\2FD86640F23D5554C9E75325D3DC5644]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="WLRemoteResource.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    "SharedComponent"="0"
    "IsFullFile"="0"
    .
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\2CDAEC3A1CD5CD353B63AC65B259A6C0\389F20921C4BAB448BD5C5D6252E4C14]
    @DACL=(02 0000)
    "PatchGUID"=""
    "MediaCabinet"=""
    "File"="WLRemoteResource.dll"
    "ComponentVersion"="15.4.5722.2"
    "ProductVersion"="15.4.5722"
    "PatchSize"="0"
    "PatchAttributes"="0"
    "PatchSequence"="0"
    &
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      ok comment il va le pc depuis ce que combofix à supprimé ??
      0
  12. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    Bonjour,

    Merci pour ton aide.

    malheureusement, il met toujours 3 à 4 mn pour arriver sur le bureau au démarrage; et quand je travaille sous Excel par exemple, il a toujours du mal à ouvrir 2 fichiers en même temps; à l'ouverture du 2eme, il semble être freiné par ????

    Si tu as des idées :

    - pour accélere le démarrage, sachant que par MSconfig, j'ai supprimé un maximum d'applications au démarrage

    - comprendre pourquoi il ouvre difficilement (15 s) 2 doc

    Merci
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      bon on va regarder , tu fais pré scan , tu postes le rapport et puis tu le relanceras et tu cliqueras sur DIAG et tu me postera le rapport aussi par le biais d'un hébergeur , merci

      Attention !!! : Seuls ces liens sont officiels ne pas telecharger l'outil sur d'autres liens !!
      Attention !!! : cet outil peut etre détecté à tort comme virus
      Attention !!! : cet outil est puissant suivre scrupuleusement les instructions ci-dessous

      tous les processus "non vitaux de windows" vont être coupés , enregistre ton travail. Il y aura une extinction du bureau pendant le scan --> pas de panique.

      Désactive toutes tes protections si possible , antivirus , sandbox , pare-feux , etc....: https://forum.pcastuces.com/default.asp

      telecharge et enregistre Pre_Scan sur ton bureau :

      http://services.service-webmaster.fr/cpt-clics/clics-30453-6820.html (renommé winlogon)

      ou , si le lien n'est pas fonctionnel :

      http://www.security-helpzone.com/Tools/g3n/winlogon.exe (renommé winlogon)

      si l'outil est relancé plusieurs fois , il te proposera un menu et qu'aucune option n'est demandée, lance l'option "Scan|Kill"

      si l'outil est bloqué par l'infection utilise cette version avec ces autres extensions :

      http://www.security-helpzone.com/Tools/g3n/Pre_Scan.scr
      http://www.security-helpzone.com/Tools/g3n/Pre_Scan.pif
      http://www.security-helpzone.com/Tools/g3n/Pre_Scan.com

      si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

      Il se peut que des fenêtres noires clignotent , laisse-le travailler.

      Laisse l'outil redemarrer ton pc.

      Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra à la racine de ton disque système ( généralement C:\ )

      NE LE POSTE PAS SUR LE FORUM !!! (il est trop long)

      Heberge le rapport sur https://www.cjoint.com/ puis donne le lien obtenu en echange sur le forum où tu te fais aider
      0
  13. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    Bonjour,

    Après pas mal de temps où le systeme a tourné *, voici le lien : https://www.cjoint.com/?3CtjcasvxdJ

    Merci
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      ok pourrais tu le relancer comme demander et cliquer sur DIAG et me poster le rapport de la même façon , merci
      0
  14. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    Bonjour,

    Après une semaine d'absence, j'ai lancé le Diag; mais n'arrive pas à trouver où se cache le rapport; ai pourtant screené tout l'ordi. rien à la racine de C:....

    As-tu une idée de là où il se cache ou sous quel nom ?

    Merci
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      tu as bien regarder dans C ???
      0
  15. gramond Messages postés 82 Date d'inscription   Statut Membre Dernière intervention   2
     
    Oui

    mais nada
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      relance le et refait le diag des fois que !!
      0