1/ disque dur si lenteur a surveilller ou changer
Le temps d’accès et le débit d’un disque dur permettent de mesurer ses performances.
Le temps de latence maximal de lecture d’un HDD est fonction de la vitesse de rotation des plateaux.
Une remarque s’affiche dans le cas où le temps de lecture serait supérieur à 20 ms pour les HDD
RE - N3 - Temps de latence maximal de lecture (Maximum read latency) (ms): 30.486
2/ Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
cmd: Net stop wuauserv
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-550326541-3461068889-1564362134-1001\...\Run: [Taskbarify] => C:\Users\ash\AppData\Local\Programs\Taskbarify\Taskbarify.exe (Pas de fichier)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X]
CustomCLSID: HKU\S-1-5-21-550326541-3461068889-1564362134-1001_Classes\CLSID\{2EF7E390-2F7C-4F9A-9B7D-4A87B56B711D}\InprocServer32 -> C:\Users\ash\AppData\Local\Microsoft\EdgeUpdate\1.3.173.51\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-550326541-3461068889-1564362134-1001_Classes\CLSID\{608D599A-DCA6-4A7C-BED7-AFCD8465345A}\InprocServer32 -> C:\Users\ash\AppData\Local\Microsoft\EdgeUpdate\1.3.175.29\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-550326541-3461068889-1564362134-1001_Classes\CLSID\{7C9A348D-C321-47AC-904F-150312A5430F}\InprocServer32 -> C:\Users\ash\AppData\Local\Microsoft\EdgeUpdate\1.3.175.27\psuser_64.dll => Pas de fichier
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0]
AlternateDataStreams: C:\ProgramData\UpdateLock-3A98C3EEB723152E:9D10997606 [3434]
StartRegedit:
Windows Registry Editor Version 5.00
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
@=""
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[-HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
@=""
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P]
EndRegedit:
FirewallRules: [TCP Query User{9087DFD5-B162-447C-811A-017B7AA7A1CB}C:\users\ash\appdata\local\discord\app-1.0.9013\discord.exe] => (Allow) C:\users\ash\appdata\local\discord\app-1.0.9013\discord.exe => Pas de fichier
FirewallRules: [UDP Query User{5ADB0324-B6D5-4226-A07A-0673D0CC992D}C:\users\ash\appdata\local\discord\app-1.0.9013\discord.exe] => (Allow) C:\users\ash\appdata\local\discord\app-1.0.9013\discord.exe => Pas de fichier
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|GoogleChromeAutoLaunch_31EC8AA2ABFB04B5AFA84DC51656817C
DeleteValue: HKEY_USERS\S-1-5-21-550326541-3461068889-1564362134-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
DeleteValue: HKEY_USERS\S-1-5-21-550326541-3461068889-1564362134-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|GoogleChromeAutoLaunch_31EC8AA2ABFB04B5AFA84DC51656817C
DeleteKey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{31a23e4c-4354-4af8-9aab-354b8470c1dd}
DeleteKey: HKU\S-1-5-21-550326541-3461068889-1564362134-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
DeleteKey: HKCU\Software\Lavasoft\Web Companion
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Lavasoft\Web Companion
DeleteKey: HKLM\SOFTWARE\Lavasoft\Web Companion
DeleteKey: HKLM\SOFTWARE\1de14785-dd8c-5cd2-aae8-d4a376f81d78
DeleteKey: HKLM\SOFTWARE\WOW6432Node\da60f423-202e-5908-a438-cd6fbbc819c8
DeleteKey: HKCU\SOFTWARE\03ceac78-9166-585d-b33a-90982f435933
DeleteKey: HKCU\SOFTWARE\66c8fa15-218d-5617-9c2c-d43580ea5eb5
DeleteKey: HKCU\SOFTWARE\da60f423-202e-5908-a438-cd6fbbc819c8
DeleteKey: HKU\S-1-5-21-550326541-3461068889-1564362134-1001\SOFTWARE\03ceac78-9166-585d-b33a-90982f435933
DeleteKey: HKU\S-1-5-21-550326541-3461068889-1564362134-1001\SOFTWARE\66c8fa15-218d-5617-9c2c-d43580ea5eb5
DeleteKey: HKU\S-1-5-21-550326541-3461068889-1564362134-1001\SOFTWARE\da60f423-202e-5908-a438-cd6fbbc819c8
C:\Windows\Temp\ *.*
C:\Users\CurrentUserName\Appdata\Local\Temp\ *.*
C:\Windows\SoftwareDistribution\Download\ *
EmptyTemp:
cmd: dism.exe /online /cleanup-image /restorehealth
cmd: sfc /scannow
cmd: Net start wuauserv
Reboot:
end::
Corrige et heberge le rapport fixlog
@+