I keep getting those popup windows. Legit? Malware? How do I get rid of them?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • MartinC79
    PCHF Member
    • Apr 2023
    • 2

    #1

    I keep getting those popup windows. Legit? Malware? How do I get rid of them?

    I keep getting those popup windows (see attached screenshots). I suspect they are malware. I tried to get rid of them using a 3rd party app, but it did not work. How can I get rid of this malware?

    As requested here, I ran FRST and am copying text from the 2 files produced after the scan. Any help is appreciated. Thank you.
    [HEADING=1]Résultats d’analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 25-03-2023
    Exécuté par marti (administrateur) sur LAPTOP-OFLICC0A (Acer Swift SF314-43) (01-04-2023 14:01:28)
    Exécuté depuis C:\Users\marti\Downloads
    Profils chargés: marti
    Plate-forme: Microsoft Windows 11 Home Version 22H2 22621.1485 (X64) Langue: Anglais (États-Unis) → Français (Canada)
    Navigateur par défaut: Edge
    Mode d’amorçage: Normal
    ==================== Processus (Avec liste blanche) =================
    (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)
    (C:\Program Files\Acer\Quick Access Service\QASvc.exe ->) (Acer Incorporated → Acer Incorporated) C:\Program Files\Acer\Quick Access Service\QAAdminAgent.exe
    (C:\Program Files\Acer\Quick Access Service\QASvc.exe ->) (Acer Incorporated → Acer Incorporated) C:\Program Files\Acer\Quick Access Service\QAAgent.exe
    (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. → Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (C:\Program Files\WindowsApps\MicrosoftTeams_23047.400.1873.72 04_x64__8wekyb3d8bbwe\msteams.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\111.0.1661 .62\msedgewebview2.exe <12>
    (explorer.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <29>
    (explorer.exe ->) (Opera Software AS → Opera Software) C:\Users\marti\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe <2>
    (services.exe ->) (Acer Incorporated → Acer Incorporated) C:\Program Files (x86)\Acer\Care Center\ACCSvc.exe
    (services.exe ->) (Acer Incorporated → Acer Incorporated) C:\Program Files\Acer\Quick Access Service\QASvc.exe
    (services.exe ->) (Advanced Micro Devices, Inc. → AMD) C:\Windows\System32\DriverStore\FileRepository\u03 64120.inf_amd64_636d39f1d2b33111\B364017\atiesrxx. exe
    (services.exe ->) (DTS, Inc. → DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.ex e
    (services.exe ->) (GoTrustID Inc → GOTrustID Inc.) C:\Program Files\GoTrust ID Plugin\Bridge_Service.exe
    (services.exe ->) (GOTrustID Inc.) [Fichier non signé] C:\Program Files\GoTrust ID Plugin\GoTrust ID Plugin\GTFidoService.exe
    (services.exe ->) (HP Inc. → HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.e xe
    (services.exe ->) (Malwarebytes Inc. → Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (services.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (services.exe ->) (Microsoft Windows Hardware Compatibility Publisher → Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
    (services.exe ->) (Microsoft Windows Publisher → Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MsMpEng.exe
    (services.exe ->) (Microsoft Windows Publisher → Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\NisSrv.exe
    (services.exe ->) (Microsoft Windows Publisher → Microsoft Corporation) C:\Windows\System32\Sgrm\SgrmBroker.exe
    (services.exe ->) (Realtek Semiconductor Corp. → Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\rea ltekservice.inf_amd64_4b6fe1c4e6f1d68a\RtkAudUServ ice64.exe <3>
    (svchost.exe ->) (Acer Incorporated → ) C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
    (svchost.exe ->) (Acer Incorporated → Microsoft) C:\Program Files\Acer\StorPSCTL\StorPSCTL.exe
    (svchost.exe ->) (Microsoft Corporation → Microsoft Corporation) C:\Users\marti\AppData\Local\Microsoft\OneDrive\23 .054.0313.0001\FileCoAuth.exe
    (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.1 3303.0_x64__8wekyb3d8bbwe\Cortana.exe
    (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23022.140. 0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
    (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
    (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (svchost.exe ->) (Microsoft Windows → Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (svchost.exe ->) (Microsoft Windows) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExper ience_423.3400.0.0_x64__cw5n1h2txyewy\Dashboard\Wi dgetService.exe
    ==================== Registre (Avec liste blanche) ===================
    (Si un élément est inclus dans le fichier fixlist.txt, l’élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
    HKLM...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\rea ltekservice.inf_amd64_4b6fe1c4e6f1d68a\RtkAudUServ ice64.exe [1256520 2021-03-31] (Realtek Semiconductor Corp. → Realtek Semiconductor)
    HKLM...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher → Logitech)
    HKLM...\Run: =>
    HKLM-x32...\Run: =>
    HKU\S-1-5-19...\Run: [OneDriveSetup] => C:\Windows\System32\OneDriveSetup.exe [50312608 2022-05-07] (Microsoft Corporation → Microsoft Corporation)
    HKU\S-1-5-20...\Run: [OneDriveSetup] => C:\Windows\System32\OneDriveSetup.exe [50312608 2022-05-07] (Microsoft Corporation → Microsoft Corporation)
    HKU\S-1-5-21-4235641016-2069265453-480244600-1001...\Run: [MicrosoftEdgeAutoLaunch_4A886EB596DDE810C696BFE47B AAC943] => “C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe” --no-startup-window --win-session-start /prefetch:5 [4056016 2023-03-29] (Microsoft Corporation → Microsoft Corporation)
    HKU\S-1-5-21-4235641016-2069265453-480244600-1001...\Run: [Opera GX Stable] => C:\Users\marti\AppData\Local\Programs\Opera GX\launcher.exe [2637208 2023-03-22] (Opera Norway AS → Opera Software)
    HKU\S-1-5-21-4235641016-2069265453-480244600-1001...\Run: [Opera GX Browser Assistant] => C:\Users\marti\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS → Opera Software)
    HKU\S-1-5-21-4235641016-2069265453-480244600-1001...\Run: =>
    HKLM\Software...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] →
    ==================== Tâches planifiées (Avec liste blanche) ============
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s’il est inscrit séparément.)
    Task: {01A8093B-0A95-4880-984D-C411107DE09F} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [58352 2023-03-05] (HP Inc. → HP Inc.)
    Task: {04B4685D-A1CE-4A24-9887-36C9219A64D7} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1710472 2020-12-21] (Advanced Micro Devices, Inc. → Advanced Micro Devices, Inc.)
    Task: {0600DD45-FAF2-4131-A006-0B17509B9F78} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => %windir%\system32\sc.exe start InventorySvc
    Task: {0D66473D-1527-4BD2-A201-B9CCDBD53425} - System32\Tasks\Oem\AcerJumpstartTask => C:\Program Files (x86)\Acer\Acer Jumpstart\hermes.exe [70792 2022-08-15] (Acer Incorporated → )
    Task: {0EF07161-0F04-4894-B176-ADF5B612AF5A} - System32\Tasks\StorPSCTL => C:\Program Files\Acer\StorPSCTL\StorPSCTL.exe [153640 2020-09-17] (Acer Incorporated → Microsoft)
    Task: {11F0DAC5-42F5-4069-9D2A-999A8D4E1FFA} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144264 2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Task: {1570B4EE-D8A6-44BB-9A9D-07A76F81CC85} - System32\Tasks\Microsoft\Windows\UpdateOrchestrato r\Reboot_AC => C:\WINDOWS\system32\MusNotification.exe /RunOnAC ReadyToReboot (Pas de fichier)
    Task: {16D8AE9B-9AD9-47BB-BA8D-2F4A1588FD1D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MpCmdRun.exe [1645904 2023-03-27] (Microsoft Windows Publisher → Microsoft Corporation)
    Task: {1CE73B3F-9B7B-4FD1-9B3D-E00FF6C0A23D} - System32\Tasks\ACCBackgroundApplication => C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [4836512 2021-12-30] (Acer Incorporated → )
    Task: {210B3BCA-77BB-49E5-82D2-2FFCA33BAA07} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MpCmdRun.exe [1645904 2023-03-27] (Microsoft Windows Publisher → Microsoft Corporation)
    Task: {21BC3EB8-1CA5-4621-BA50-52EECCDAA850} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MpCmdRun.exe [1645904 2023-03-27] (Microsoft Windows Publisher → Microsoft Corporation)
    Task: {339B1510-DB11-42F9-95B2-D830C2E7E45D} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1710472 2020-12-21] (Advanced Micro Devices, Inc. → Advanced Micro Devices, Inc.)
    Task: {3B2FFACE-794D-4FE9-8F1A-7642657EBE01} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [168880 2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Task: {3EE12F8F-B4B7-424E-8830-E258BB446369} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [461472 2021-12-30] (Acer Incorporated → Acer Incorporated)
    Task: {43703415-4763-40F1-9806-96227EE283CC} - System32\Tasks\Opera GX scheduled Autoupdate 1678805962 => C:\Users\marti\AppData\Local\Programs\Opera GX\launcher.exe [2637208 2023-03-22] (Opera Norway AS → Opera Software)
    Task: {465EC0EA-3725-47A5-BE48-78509AEC1BCB} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26405352 2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Task: {5C190CE2-5C3A-466B-A369-46B52669B619} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2971808 2021-12-30] (Acer Incorporated → )
    Task: {5E787C58-94BB-4A0C-BF16-4E887CEED25C} - System32\Tasks\AcerCMUpdateTask2.5.22250 => C:\Program Files (x86)\Acer\Amundsen\2.5.22250\awc.exe [96904 2022-09-25] (Acer Incorporated → )
    Task: {658EAAA1-1467-4A28-93EA-733976F463AE} - System32\Tasks\Quick Access => C:\Program Files\Acer\Quick Access Service\QALauncher.exe [446624 2022-01-03] (Acer Incorporated → Acer Incorporated)
    Task: {73D722E6-DE9B-4611-8388-25CA83320EF5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26405352 2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Task: {813B2C56-6F2D-484E-B86B-DF76C2F855FB} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [676256 2023-03-24] (Mozilla Corporation → Mozilla Corporation) → --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump :5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundup date.moz_log --backgroundtask backgroundupdate
    Task: {8170D08E-C704-4FCE-923C-D677D2E15478} - System32\Tasks\GoTrust ID Driver => C:\Program Files\GoTrust ID Plugin\Resource\GO-Trust_ID_Driver.exe [68192 2020-09-08] (GoTrustID Inc → )
    Task: {88621C38-F695-4912-AEF9-5BB0D49C126F} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program Service\Framework\TriggerFramework.exe [268328 2020-11-19] (Acer Incorporated → Acer Incorporated)
    Task: {909402D5-5385-48F4-9EF5-636CE46AB87E} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1710472 2020-12-21] (Advanced Micro Devices, Inc. → Advanced Micro Devices, Inc.)
    Task: {9F1757B3-F7D3-4B8C-BE53-4CA17987853F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [718752 2023-03-24] (Mozilla Corporation → Mozilla Foundation)
    Task: {B33FBB97-F1FA-440A-8EDB-21D6BB7249DF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrato r\MusUx_LogonUpdateResults => C:\WINDOWS\system32\MusNotification.exe LogonUpdateResults (Pas de fichier)
    Task: {BA2A96DE-5BCB-4FC3-B351-01323816CB02} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [41632 2021-12-30] (Acer Incorporated → )
    Task: {BBE20386-9427-4620-8998-B55C875A9187} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MpCmdRun.exe [1645904 2023-03-27] (Microsoft Windows Publisher → Microsoft Corporation)
    Task: {C7847B8E-6F52-47B2-99CE-9B5D71B1C03E} - System32\Tasks\UEIPInvitation => C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UEIPOOBECheck.exe [2211368 2020-11-19] (Acer Incorporated → Acer Incorporated)
    Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (Pas de fichier)
    Task: {DC916C0A-D8DB-4A09-BD85-D99C9770FFD8} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [58352 2023-03-05] (HP Inc. → HP Inc.)
    Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrato r\USO_UxBroker => C:\WINDOWS\system32\MusNotification.exe (Pas de fichier)
    Task: {EAC219FB-53D0-4246-975D-E1412A5513E4} - \Opera GX scheduled assistant Autoupdate 1679494619 → Pas de fichier <==== ATTENTION
    Task: {F2B21506-C943-453E-9FD1-00F0C5B4CB59} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144264 2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Task: {F2C355BB-9AEB-4D05-AF3D-BF97AB07A50F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrato r\Reboot_Battery => C:\WINDOWS\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Pas de fichier)
    (Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)
    ==================== Internet (Avec liste blanche) ====================
    (Si un élément est inclus dans le fichier fixlist.txt, s’il s’agit d’un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)
    ProxyServer: [S-1-5-21-4235641016-2069265453-480244600-1001] => 64.235.204.107:3128
    Tcpip\Parameters: [DhcpNameServer] 24.200.243.189
    Tcpip..\Interfaces{530e4e9f-72bd-4859-b913-715ad06691f7}: [DhcpNameServer] 150.200.3.1
    Tcpip..\Interfaces{77aa0e95-1ed9-4d23-af4d-cb853f56a2e9}: [DhcpNameServer] 24.200.243.189
    Edge:[/HEADING]
    [HEADING=1]Edge DefaultProfile: Default
    Edge Profile: C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-01]
    Edge Notifications: Default → hxxps://malwaretips.com; hxxps://reianter.com
    Edge HomePage: Default → hxxp://google.ca/
    Edge StartupUrls: Default → “hxxp://google.ca/”
    Edge HKLM...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
    Edge HKLM-x32...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
    FireFox:[/HEADING]
    [HEADING=1]FF DefaultProfile: m2ecii3o.default
    FF ProfilePath: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Pro files\m2ecii3o.default [2022-09-19]
    FF ProfilePath: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Pro files\5r4zelcq.default-release [2023-04-01]
    FF Plugin: @microsoft.com/SharePoint,version=14.0 → C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-01] (Microsoft Corporation → Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-01] (Microsoft Corporation → Microsoft Corporation)
    Chrome:[/HEADING]
    [HEADING=1]CHR HKLM...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
    CHR HKLM-x32...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
    Opera:[/HEADING]
    StartMenuInternet: (HKU\S-1-5-21-4235641016-2069265453-480244600-1001) Opera GXStable - “C:\Users\marti\AppData\Local\Programs\Opera GX\Launcher.exe”
    ==================== Services (Avec liste blanche) ===================
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s’il est inscrit séparément.)
    R2 ACCSvc; C:\Program Files (x86)\Acer\Care Center\ACCSvc.exe [259232 2021-12-30] (Acer Incorporated → Acer Incorporated)
    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12634512 2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    R2 DtsApo4Service; C:\WINDOWS\System32\DTS\PC\APO4x\DtsApo4Service.ex e [201376 2020-10-17] (DTS, Inc. → DTS Inc.)
    R2 GoTrust ID Plugin; C:\Program Files\GoTrust ID Plugin\GoTrust ID Plugin\GTFidoService.exe [15360 2020-09-08] (GOTrustID Inc.) [Fichier non signé]
    R2 GoTrustID Service; C:\Program Files\GoTrust ID Plugin\Bridge_Service.exe [336992 2020-09-08] (GoTrustID Inc → GOTrustID Inc.)
    R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.e xe [229360 2023-03-05] (HP Inc. → HP Inc.)
    S3 InventorySvc; C:\WINDOWS\system32\inventorysvc.dll [304480 2023-03-09] (Microsoft Windows → Microsoft Corporation)
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9094440 2023-04-01] (Malwarebytes Inc. → Malwarebytes)
    S3 QALSvc; C:\Program Files\Acer\Quick Access Service\QALSvc.exe [466080 2022-01-03] (Acer Incorporated → Acer Incorporated)
    R3 QASvc; C:\Program Files\Acer\Quick Access Service\QASvc.exe [504480 2022-01-03] (Acer Incorporated → Acer Incorporated)
    R2 SgrmBroker; C:\WINDOWS\system32\Sgrm\SgrmBroker.exe [414632 2022-05-07] (Microsoft Windows Publisher → Microsoft Corporation)
    R2 TextInputManagementService; C:\WINDOWS\System32\TabSvc.dll [266240 2023-03-16] (Microsoft Windows → Microsoft Corporation)
    S3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UBTService.exe [342568 2020-11-19] (Acer Incorporated → Acer Incorporated)
    R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\NisSrv.exe [3224328 2023-03-27] (Microsoft Windows Publisher → Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MsMpEng.exe [133544 2023-03-27] (Microsoft Windows Publisher → Microsoft Corporation)
    S2 SecurityService; “C:\Program Files (x86)\TotalAV\SecurityService.exe” <==== ATTENTION
    ===================== Pilotes (Avec liste blanche) ===================
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s’il est inscrit séparément.)
    R3 AcerAirplaneModeController; C:\WINDOWS\System32\drivers\AcerAirplaneModeContro ller.sys [36800 2022-06-02] (Acer Incorporated → Acer Incorporated)
    R3 AMDAfdAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\amd acpafd.inf_amd64_07e32c567a3649e1\amdacpafd.sys [266048 2021-01-04] (Advanced Micro Devices, Inc. → Advanced Micro Devices)
    S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 → Apple Inc.)
    R2 bfs; C:\WINDOWS\system32\drivers\bfs.sys [91480 2023-03-09] (Microsoft Windows → Microsoft Corporation)
    S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [106496 2022-05-07] (Microsoft Corporation) [Fichier non signé]
    S0 GenPass; C:\WINDOWS\System32\DriverStore\FileRepository\gen pass.inf_amd64_bef88a423225ecdc\genpass.sys [62800 2022-05-07] (Microsoft Windows → Microsoft Corporation)
    R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223176 2023-04-01] (Microsoft Windows Hardware Compatibility Publisher → Malwarebytes)
    S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-04-01] (Microsoft Windows Early Launch Anti-malware Publisher → Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-04-01] (Microsoft Windows Hardware Compatibility Publisher → Malwarebytes)
    R3 MTKBTFilterX64; C:\WINDOWS\system32\DRIVERS\mtkbtfilterx.sys [284496 2022-03-01] (Microsoft Windows Hardware Compatibility Publisher → MediaTek Inc.)
    R3 mtkwlex; C:\WINDOWS\System32\drivers\mtkwl6ex.sys [1408472 2022-02-25] (Microsoft Windows Hardware Compatibility Publisher → MediaTek Inc.)
    S0 ProtectedELAM; C:\WINDOWS\System32\drivers\protected_elam.sys [18912 2023-02-17] (Microsoft Windows Early Launch Anti-malware Publisher → TODO: )
    S0 pvscsi; C:\WINDOWS\System32\drivers\pvscsii.sys [45408 2022-05-07] (Microsoft Windows → VMware, Inc.)
    S3 RoutePolicy; C:\WINDOWS\System32\drivers\RoutePolicy.sys [98304 2022-05-07] (Microsoft Windows → )
    S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49608 2023-03-27] (Microsoft Windows Early Launch Anti-malware Publisher → Microsoft Corporation)
    R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [495896 2023-03-27] (Microsoft Windows → Microsoft Corporation)
    R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99624 2023-03-27] (Microsoft Windows → Microsoft Corporation)
    R1 webshieldfilter; C:\WINDOWS\System32\drivers\webshieldfilter.sys [96264 2023-02-17] (Microsoft Windows Hardware Compatibility Publisher → Windows (R) Win 7 DDK provider) <==== ATTENTION
    R2 wtd; C:\WINDOWS\System32\drivers\wtd.sys [118784 2023-03-16] (Microsoft Windows → Microsoft Corporation)
    S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys
    ==================== NetSvcs (Avec liste blanche) ===================
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s’il est inscrit séparément.)
    ==================== Un mois (créés) (Avec liste blanche) =========
    (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
    2023-04-01 14:01 - 2023-04-01 14:02 - 000022388 _____ C:\Users\marti\Downloads\FRST.txt
    2023-04-01 14:01 - 2023-04-01 14:01 - 000000000 ____D C:\FRST
    2023-04-01 14:00 - 2023-04-01 14:00 - 002379264 _____ (Farbar) C:\Users\marti\Downloads\Non confirmé 700523.crdownload
    2023-04-01 14:00 - 2023-04-01 14:00 - 002379264 _____ (Farbar) C:\Users\marti\Downloads\Non confirmé 621581.crdownload
    2023-04-01 13:58 - 2023-04-01 14:01 - 002379264 _____ (Farbar) C:\Users\marti\Downloads\FRST64.exe
    2023-04-01 13:58 - 2023-04-01 13:58 - 002379264 _____ (Farbar) C:\Users\marti\Downloads\Non confirmé 443631.crdownload
    2023-04-01 13:40 - 2023-04-01 13:40 - 000806226 _____ C:\WINDOWS\system32\perfh00C.dat
    2023-04-01 13:40 - 2023-04-01 13:40 - 000154624 _____ C:\WINDOWS\system32\perfc00C.dat
    2023-04-01 12:24 - 2023-04-01 12:24 - 000000000 ___HD C:$WinREAgent
    2023-04-01 12:07 - 2023-04-01 12:07 - 002649088 _____ (Malwarebytes) C:\Users\marti\Downloads\MBSetup-38EEE4E8 (1).exe
    2023-04-01 11:51 - 2023-04-01 11:51 - 002649088 _____ (Malwarebytes) C:\Users\marti\Downloads\MBSetup-38EEE4E8.exe
    2023-04-01 11:34 - 2023-04-01 11:34 - 000000000 ____D C:\Users\marti\OneDrive\Documents\TotalAV
    2023-04-01 11:32 - 2023-04-01 11:32 - 000000000 ____D C:\ProgramData\SecuritySuite
    2023-04-01 11:31 - 2023-04-01 12:02 - 000000000 ____D C:\Program Files (x86)\TotalAV
    2023-04-01 11:31 - 2023-04-01 11:31 - 000000000 ____D C:\Users\marti\AppData\Local\GUI
    2023-04-01 11:31 - 2023-04-01 11:31 - 000000000 ____D C:\ProgramData\TotalAV
    2023-04-01 11:30 - 2023-04-01 11:31 - 057278304 _____ C:\Users\marti\Downloads\TotalAV_Setup.exe
    2023-04-01 11:20 - 2023-04-01 11:52 - 000002037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
    2023-04-01 11:20 - 2023-04-01 11:52 - 000002025 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2023-04-01 11:19 - 2023-04-01 11:51 - 000000000 ____D C:\ProgramData\Malwarebytes
    2023-04-01 11:19 - 2023-04-01 11:19 - 002649088 _____ (Malwarebytes) C:\Users\marti\Downloads\MBSetup.exe
    2023-04-01 11:19 - 2023-04-01 11:19 - 002086424 _____ (Malwarebytes) C:\Users\marti\Downloads\MBSetup-076886.076886-Consumer.exe
    2023-03-27 11:14 - 2023-03-27 11:15 - 000000000 ____D C:\WINDOWS\Minidump
    2023-03-22 18:27 - 2023-04-01 13:34 - 000003126 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
    2023-03-14 10:59 - 2023-03-28 08:49 - 000004218 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1678805962
    2023-03-14 10:59 - 2023-03-28 08:49 - 000001438 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Opera GX Browser.lnk
    2023-03-14 10:59 - 2023-03-14 10:59 - 000000000 ____D C:\Users\marti\AppData\Local\Opera Software
    2023-03-14 10:58 - 2023-03-14 10:58 - 003599088 _____ (Opera Software) C:\Users\marti\Downloads\OperaGXSetup.exe
    2023-03-14 10:58 - 2023-03-14 10:58 - 000000000 ____D C:\Users\marti\AppData\Roaming\Opera Software
    2023-03-10 16:33 - 2023-03-10 16:33 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_ 11_00.Wdf
    2023-03-09 14:26 - 2023-03-09 14:27 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2023-03-09 14:23 - 2023-03-09 14:26 - 000000000 ____D C:\WINDOWS\ServiceProfiles
    2023-03-09 14:23 - 2023-03-09 14:23 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
    2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
    2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
    2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
    2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\WINDOWS\addins
    2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\Program Files\Reference Assemblies
    2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\Program Files\MSBuild
    2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
    2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\Program Files (x86)\MSBuild
    2023-03-09 14:16 - 2023-03-09 14:16 - 000000000 ____D C:\WINDOWS\SysWOW64\fr
    2023-03-09 14:16 - 2023-03-09 14:16 - 000000000 ____D C:\WINDOWS\system32\fr
    2023-03-09 11:40 - 2023-04-01 13:40 - 001800634 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2023-03-09 11:39 - 2023-03-09 11:39 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
    2023-03-09 11:37 - 2023-03-09 11:37 - 000000020 ___SH C:\Users\marti\ntuser.ini
    2023-03-09 11:35 - 2023-04-01 13:34 - 000003110 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
    2023-03-09 11:35 - 2023-04-01 13:33 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2023-03-09 11:35 - 2023-03-29 22:40 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4235641016-2069265453-480244600-1001
    2023-03-09 11:35 - 2023-03-29 22:40 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4235641016-2069265453-480244600-1001
    2023-03-09 11:35 - 2023-03-24 14:42 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
    2023-03-09 11:35 - 2023-03-21 19:42 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskM achineUA
    2023-03-09 11:35 - 2023-03-21 19:42 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskM achineCore
    2023-03-09 11:35 - 2023-03-09 11:35 - 000004302 _____ C:\WINDOWS\system32\Tasks\Software Update Application
    2023-03-09 11:35 - 2023-03-09 11:35 - 000003852 _____ C:\WINDOWS\system32\Tasks\ACCAgent
    2023-03-09 11:35 - 2023-03-09 11:35 - 000003682 _____ C:\WINDOWS\system32\Tasks\AcerCMUpdateTask2.5.2225 0
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4235641016-2069265453-480244600-500
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002782 _____ C:\WINDOWS\system32\Tasks\UbtFrameworkService
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002730 _____ C:\WINDOWS\system32\Tasks\ACC
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002712 _____ C:\WINDOWS\system32\Tasks\UEIPInvitation
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002672 _____ C:\WINDOWS\system32\Tasks\ModifyLinkUpdate
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002478 _____ C:\WINDOWS\system32\Tasks\StorPSCTL
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002408 _____ C:\WINDOWS\system32\Tasks\GoTrust ID Driver
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002328 _____ C:\WINDOWS\system32\Tasks\ACCBackgroundApplication
    2023-03-09 11:35 - 2023-03-09 11:35 - 000002222 _____ C:\WINDOWS\system32\Tasks\Quick Access
    2023-03-09 11:35 - 2023-03-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
    2023-03-09 11:35 - 2023-03-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Oem
    2023-03-09 11:35 - 2023-03-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
    2023-03-09 11:35 - 2023-03-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
    2023-03-09 11:34 - 2023-03-09 11:35 - 000011433 _____ C:\WINDOWS\diagwrn.xml
    2023-03-09 11:34 - 2023-03-09 11:35 - 000011433 _____ C:\WINDOWS\diagerr.xml
    2023-03-09 11:29 - 2023-03-27 12:45 - 000000000 ____D C:\Users\marti
    2023-03-09 11:28 - 2023-04-01 13:33 - 000672592 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2023-03-09 11:28 - 2023-04-01 12:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2023-03-09 11:28 - 2023-03-09 11:28 - 000000000 ____D C:\WINDOWS\system32\config\BFS
    2023-03-04 21:43 - 2023-03-20 16:23 - 000000000 ___DC C:\WINDOWS\Panther
    2023-03-04 21:30 - 2023-03-04 21:30 - 000000000 ___HD C:\ProgramData\CyberLink
    2023-03-04 20:54 - 2023-03-27 11:14 - 000000000 ____D C:\Program Files\Mozilla Firefox
    ==================== Un mois (modifiés) ==================
    (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
    2023-04-01 14:03 - 2022-05-07 01:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2023-04-01 14:01 - 2022-05-07 01:22 - 000000000 ____D C:\WINDOWS\INF
    2023-04-01 13:54 - 2022-09-18 20:08 - 000000000 ____D C:\Users\marti\AppData\Local\CrashDumps
    2023-04-01 13:34 - 2022-09-19 03:11 - 000000000 ___RD C:\Users\marti\OneDrive
    2023-04-01 13:34 - 2022-05-07 01:24 - 000000000 ___HD C:\Program Files\WindowsApps
    2023-04-01 13:34 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SystemTemp
    2023-04-01 13:34 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2023-04-01 13:34 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\AppReadiness
    2023-04-01 13:33 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\ServiceState
    2023-04-01 13:33 - 2021-10-09 00:29 - 000012288 ___SH C:\DumpStack.log.tmp
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\UUS
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SystemResources
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\oobe
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\appraiser
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\ShellExperiences
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\ShellComponents
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\Provisioning
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
    2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\bcastdvr
    2023-04-01 13:32 - 2022-05-07 01:17 - 000524288 _____ C:\WINDOWS\system32\config\BBI
    2023-04-01 12:32 - 2022-05-07 01:17 - 000000000 ____D C:\WINDOWS\CbsTemp
    2023-04-01 11:52 - 2022-09-19 05:42 - 000000000 ____D C:\Users\marti\AppData\LocalLow\Mozilla
    2023-04-01 11:51 - 2022-11-01 13:31 - 000000000 ____D C:\Program Files\Malwarebytes
    2023-04-01 11:31 - 2022-05-07 01:24 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
    2023-04-01 11:21 - 2022-09-19 05:42 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
    2023-04-01 11:20 - 2022-09-19 03:09 - 000000000 ____D C:\Users\marti\AppData\Local\D3DSCache
    2023-04-01 11:10 - 2022-09-19 03:11 - 000000000 ____D C:\ProgramData\Packages
    2023-04-01 11:10 - 2022-09-19 03:09 - 000000000 ____D C:\Users\marti\AppData\Local\Packages
    2023-03-31 11:08 - 2021-10-09 01:06 - 000000000 ____D C:\Program Files\Microsoft Office
    2023-03-31 08:27 - 2021-10-09 00:30 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
    2023-03-29 22:40 - 2022-09-19 03:03 - 000002383 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\OneDrive.lnk
    2023-03-27 15:26 - 2021-10-09 00:29 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
    2023-03-27 11:15 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2023-03-27 11:14 - 2021-10-09 01:13 - 002451782 ____N C:\WINDOWS\Minidump\032723-10750-01.dmp
    2023-03-27 11:14 - 2021-10-09 01:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2023-03-24 14:42 - 2021-10-09 01:03 - 000001009 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
    2023-03-22 21:02 - 2022-09-19 03:09 - 000000000 ____D C:\Users\marti\AppData\Local\ConnectedDevicesPlatf orm
    2023-03-16 16:54 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
    2023-03-16 16:53 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\es-MX
    2023-03-16 16:53 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\Dism
    2023-03-16 11:21 - 2022-09-21 08:06 - 000000000 ____D C:\WINDOWS\system32\MRT
    2023-03-16 11:20 - 2022-09-21 08:06 - 153620824 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2023-03-16 00:21 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
    2023-03-11 15:18 - 2022-09-20 18:07 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
    2023-03-10 15:55 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
    2023-03-10 15:54 - 2022-09-19 03:11 - 000000000 ____D C:\Users\marti\AppData\Local\PlaceholderTileLogoFo lder
    2023-03-09 18:26 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\appcompat
    2023-03-09 17:40 - 2022-05-07 01:17 - 000000000 ____D C:\WINDOWS\servicing
    2023-03-09 14:28 - 2022-05-07 01:24 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2023-03-09 14:28 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
    2023-03-09 14:27 - 2022-09-19 04:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 7.4
    2023-03-09 14:27 - 2022-09-19 02:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Acer
    2023-03-09 14:27 - 2022-09-19 02:46 - 000000000 ____D C:\WINDOWS\oem
    2023-03-09 14:27 - 2022-05-07 01:28 - 000000000 ____D C:\WINDOWS\Setup
    2023-03-09 14:27 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\spool
    2023-03-09 14:27 - 2022-05-07 01:24 - 000000000 ____D C:\ProgramData\USOPrivate
    2023-03-09 14:27 - 2021-10-09 01:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
    2023-03-09 14:27 - 2021-10-09 01:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
    2023-03-09 14:27 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\MsDtc
    2023-03-09 14:26 - 2021-10-09 00:49 - 000000000 ____D C:\WINDOWS\system32\DTS
    2023-03-09 14:26 - 2021-10-09 00:46 - 000000000 ____D C:\WINDOWS\system32\AMD
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\system32\UNP
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SystemApps
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\Sgrm
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\setup
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\Globalization
    2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\Program Files\Common Files\System
    2023-03-09 14:21 - 2022-05-07 01:25 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
    2023-03-09 14:21 - 2022-05-07 01:24 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
    2023-03-09 14:17 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
    2023-03-09 14:17 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\MUI
    2023-03-09 14:17 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\OCR
    2023-03-09 14:16 - 2022-05-07 02:10 - 000000000 ____D C:\Program Files\Windows Photo Viewer
    2023-03-09 14:16 - 2022-05-07 02:10 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
    2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
    2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
    2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
    2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
    2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\system32\winrm
    2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\system32\WCN
    2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\system32\slmgr
    2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\system32\F12
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\system32\dsc
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\Sysprep
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\migwiz
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\Com
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\IME
    2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\Program Files (x86)\Windows Defender
    2023-03-09 11:54 - 2022-05-07 01:24 - 000000000 ___RD C:\WINDOWS\PrintDialog
    2023-03-09 11:37 - 2021-10-09 00:32 - 000000000 __RHD C:\Users\Public\AccountPictures
    2023-03-09 11:35 - 2022-05-07 01:24 - 000000000 ____D C:\Program Files\Windows Defender
    2023-03-09 11:35 - 2022-05-07 01:17 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
    2023-03-09 11:32 - 2022-05-07 01:24 - 000000000 __RHD C:\Users\Public\Libraries
    2023-03-09 11:30 - 2022-05-07 01:24 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
    2023-03-09 11:29 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2023-03-05 21:31 - 2023-01-13 12:35 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
    2023-03-04 21:35 - 2021-10-09 01:09 - 000000000 ____D C:\ProgramData\Norton
    2023-03-04 20:40 - 2022-09-18 19:24 - 000000000 ____D C:\Users\marti\AppData\LocalLow\Norton
    2023-03-04 20:38 - 2022-09-19 04:04 - 000000000 ____D C:\Program Files\Common Files\AV
    ==================== SigCheck ============================
    (Il n’y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)
    ==================== Fin de FRST.txt ========================
    [HEADING=1]Résultats de l’Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 25-03-2023
    Exécuté par marti (01-04-2023 14:06:07)
    Exécuté depuis C:\Users\marti\Downloads
    Microsoft Windows 11 Home Version 22H2 22621.1485 (X64) (2023-03-09 15:37:19)
    Mode d’amorçage: Normal[/HEADING]
    [HEADING=1]==================== Comptes: =============================
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.)
    Administrator (S-1-5-21-4235641016-2069265453-480244600-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-4235641016-2069265453-480244600-503 - Limited - Disabled)
    Guest (S-1-5-21-4235641016-2069265453-480244600-501 - Limited - Disabled)
    marti (S-1-5-21-4235641016-2069265453-480244600-1001 - Administrator - Enabled) => C:\Users\marti
    WDAGUtilityAccount (S-1-5-21-4235641016-2069265453-480244600-504 - Limited - Disabled)
    ==================== Centre de sécurité ========================
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.)
    AV: Total AV (Disabled - Up to date) {0567E33F-93C9-11B5-891D-90A37AEB2766}
    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: Norton Security Ultra (Enabled - Up to date) {9E3FD331-C4C2-7AC4-0537-131EEF1B1F8A}
    FW: Norton Security Ultra (Enabled) {A6045214-8EAD-7B9C-2E68-BA2B11C858F1}
    ==================== Programmes installés ======================
    (Seuls les logiciels publicitaires (‘adware’) avec la marque ‘caché’ (‘Hidden’) sont susceptibles d’être ajoutés au fichier fixlist.txt pour qu’ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.)
    Acer Configuration Manager (HKLM-x32...{8CB1A03C-9849-4744-AD56-341A18F9E3E2}) (Version: 2.5.22250 - Acer)
    Acer Jumpstart (HKLM-x32...{0C5ED25A-B8D1-4E71-BFCB-6B370A4EA19C}) (Version: 3.5.22220.20 - Acer)
    AMD Software (HKLM...\AMD Catalyst Install Manager) (Version: 20.40.32 - Advanced Micro Devices, Inc.)
    Care Center Service (HKLM...{AFB52E98-7597-4484-9202-58F0FD3512ED}) (Version: 4.00.3042 - Acer Incorporated)
    DriverSetupUtility (HKLM...{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}) (Version: 1.00.3026 - Acer Incorporated)
    GoTrust ID Plugin 2.0.12.36 (HKLM...\GoTrust ID Plugin) (Version: 2.0.12.36 - GoTrust ID Inc.)
    LibreOffice 7.4.1.2 (HKLM...{2382F0CD-B06A-49B7-912F-A8BB1C7FD511}) (Version: 7.4.1.2 - The Document Foundation)
    Malwarebytes version 4.5.25.256 (HKLM...{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.25.256 - Malwarebytes)
    Microsoft 365 - en-us (HKLM...\O365HomePremRetail - en-us) (Version: 16.0.16227.20212 - Microsoft Corporation)
    Microsoft Edge (HKLM-x32...\Microsoft Edge) (Version: 111.0.1661.62 - Microsoft Corporation)
    Microsoft Edge WebView2 Runtime (HKLM-x32...\Microsoft EdgeWebView) (Version: 111.0.1661.62 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-4235641016-2069265453-480244600-1001...\OneDriveSetup.exe) (Version: 23.054.0313.0001 - Microsoft Corporation)
    Microsoft Update Health Tools (HKLM...{EF9EBC42-6969-45CE-A8D2-B9249B00C838}) (Version: 5.69.0.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32...{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation)
    Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.29.30139 (HKLM-x32...{8d5fdf81-7022-423f-bd8b-b513a1050ae1}) (Version: 14.29.30139.0 - Microsoft Corporation)
    Microsoft Visual C++ 2019 X64 Additional Runtime - 14.24.28127 (HKLM...{8678BA04-D161-45BE-ACA4-CC5D13073F35}) (Version: 14.24.28127 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.24.28127 (HKLM...{7DC387B8-E6A2-480C-8EF9-A6E51AE81C19}) (Version: 14.24.28127 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2019 X86 Additional Runtime - 14.29.30139 (HKLM-x32...{1AEA8854-7597-4CD3-948F-8DE364D94E07}) (Version: 14.29.30139 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.29.30139 (HKLM-x32...{1679EF65-55F3-4248-B91E-6B3BE1A69CDF}) (Version: 14.29.30139 - Microsoft Corporation) Hidden
    Mozilla Firefox (x64 en-US) (HKLM...\Mozilla Firefox 111.0 (x64 en-US)) (Version: 111.0 - Mozilla)
    Mozilla Maintenance Service (HKLM...\MozillaMaintenanceService) (Version: 104.0.2 - Mozilla)
    Office 16 Click-to-Run Extensibility Component (HKLM...{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.16130.20218 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Licensing Component (HKLM...{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.16227.20204 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Localization Component (HKLM...{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13127.20616 - Microsoft Corporation) Hidden
    Opera GX Stable 96.0.4693.117 (HKU\S-1-5-21-4235641016-2069265453-480244600-1001...\Opera GX 96.0.4693.117) (Version: 96.0.4693.117 - Opera Software)
    Quick Access Service (HKLM...{AB25551C-74EF-4BAB-9989-891517FCF9FF}) (Version: 3.00.3038 - Acer Incorporated)
    Realtek Audio Driver (HKLM-x32...{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9088.1 - Realtek Semiconductor Corp.)
    TotalAV (HKLM-x32...\TotalAV) (Version: 5.22.37 - TotalAV) <==== ATTENTION
    Update for Windows 10 for x64-based Systems (KB5001716) (HKLM...{82BD0A1C-815F-487F-9AE7-CE73DA413CFF}) (Version: 4.91.0.0 - Microsoft Corporation)
    User Experience Improvement Program Service (HKLM...{323EA05D-046D-449D-9D7C-89243C957CCE}) (Version: 5.00.3010 - Acer Incorporated)
    Windows PC Health Check (HKLM...{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
    Packages:[/HEADING]
    [HEADING=1]Acer Product Registration → C:\Program Files\WindowsApps\AcerIncorporated.AcerRegistratio n_2.0.3040.0_x64__48frkmn4z8aw4 [2022-10-16] (Acer Incorporated)
    AMD Radeon Software → C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.20.40028.0_x64__0a9344xs7nr 4m [2022-09-22] (Advanced Micro Devices Inc.) [Startup Task]
    Aura Privacy → C:\Program Files\WindowsApps\Aura-YourDigitalHalo.FigLeaf_6.2.4.0_x64__ecvh8cc66bmhj [2022-09-22] (Aura - Your Digital Halo)
    Care Center S → C:\Program Files\WindowsApps\AcerIncorporated.AcerCareCenterS _4.0.3042.0_x64__48frkmn4z8aw4 [2022-09-19] (Acer Incorporated)
    Clipchamp → C:\Program Files\WindowsApps\Clipchamp.Clipchamp_2.5.15.0_neu tral__yxz26nhyzhsrt [2023-03-10] (Microsoft Corp.)
    Disney+ → C:\Program Files\WindowsApps\Disney.37853FC22B2CE_1.49.3.0_x6 4__6rarf9sa4v8jt [2023-03-31] (Disney)
    DTS Audio Processing → C:\Program Files\WindowsApps\DTSInc.DTSAudioProcessing_1.10.9 .0_x64__t5j2fzbtdg37r [2023-03-09] (DTS, Inc.)
    GoTrust ID → C:\Program Files\WindowsApps\GOTrustTechnologyInc.GO-TrustAuthenticator_3.1.21.0_x64__0r04f53sqacg6 [2023-03-05] (GoTrustID Inc.)
    HP Smart → C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_143.1. 1136.0_x64__v10z8vjag6ke6 [2023-03-05] (HP Inc.)
    Messenger → C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_1820.9.73 .0_x64__8xx8rvfyw5nnt [2023-03-21] (Meta) [Startup Task]
    Microsoft Advertising SDK for XAML → C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.18 11.1.0_x64__8wekyb3d8bbwe [2022-09-20] (Microsoft Corporation) [MS Ad]
    Microsoft Advertising SDK for XAML → C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.18 11.1.0_x86__8wekyb3d8bbwe [2022-09-20] (Microsoft Corporation) [MS Ad]
    Microsoft Defender → C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2302 .13004.0_x64__8wekyb3d8bbwe [2023-03-10] (Microsoft Corporation) [Startup Task]
    Microsoft Family → C:\Program Files\WindowsApps\MicrosoftCorporationII.Microsoft Family_0.2.39.0_x64__8wekyb3d8bbwe [2023-03-10] (Microsoft Corp.)
    Microsoft Whiteboard → C:\Program Files\WindowsApps\Microsoft.Whiteboard_53.10126.51 7.0_x64__8wekyb3d8bbwe [2023-03-05] (Microsoft Corporation)
    ms-resource://MicrosoftCorporationII.QuickAssist/resources/APP_WINDOW_NAME → C:\Program Files\WindowsApps\MicrosoftCorporationII.QuickAssi st_2.0.19.0_x64__8wekyb3d8bbwe [2023-03-10] (Microsoft Corp.)
    ms-resource:AppStoreName → C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1. 52851.0_x64__8wekyb3d8bbwe [2023-03-09] (Microsoft Corporation)
    ms-resource:AppStoreName → C:\Program Files\WindowsApps\Microsoft.RawImageExtension_2.1. 60611.0_x64__8wekyb3d8bbwe [2023-03-28] (Microsoft Corporation)
    ms-resource:AppxManifest_DisplayName → C:\Windows\SystemApps\Microsoft.Windows.PrintQueue ActionCenter_cw5n1h2txyewy [2023-03-09] (Microsoft Corporation)
    ms-resource:OEMAppName → C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_23.4.11.0_x6 4__xbfy0k16fey96 [2023-03-25] (Dropbox Inc.)
    PhotoDirector for acer → C:\Program Files\WindowsApps\CyberLinkCorp.ac.PhotoDirectorfo racerDesktop_8.0.6428.0_x64__ypz87dpxkv292 [2022-09-19] (CYBERLINK COM CORP)
    PowerDirector for acer → C:\Program Files\WindowsApps\CyberLinkCorp.ac.PowerDirectorfo racerDesktop_14.0.4304.0_x64__ypz87dpxkv292 [2022-09-19] (CYBERLINK COM CORP)
    QuickAccess → C:\Program Files\WindowsApps\AcerIncorporated.QuickAccess_3.0 .3038.0_x64__48frkmn4z8aw4 [2022-09-19] (Acer Incorporated)
    Realtek Audio Control → C:\Program Files\WindowsApps\RealtekSemiconductorCorp.Realtek AudioControl_1.25.247.0_x64__dt26b99r8h8gj [2023-03-05] (Realtek Semiconductor Corp)
    Spotify Music → C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0 [2023-03-31] (Spotify AB) [Startup Task]
    User Experience Improvement Program V5 → C:\Program Files\WindowsApps\AcerIncorporated.UserExperienceI mprovementProgramV_5.0.3010.0_x64__48frkmn4z8aw4 [2022-09-19] (Acer Incorporated)
    Windows Feature Experience Pack → C:\Windows\SystemApps\MicrosoftWindows.Client.Core _cw5n1h2txyewy [2023-04-01] (Microsoft Windows)
    WindowsAppRuntime.1.2 → C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2_ 2000.777.2143.0_x64__8wekyb3d8bbwe [2023-03-05] (Microsoft Corporation)
    WindowsAppRuntime.1.2 → C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2_ 2000.802.31.0_x64__8wekyb3d8bbwe [2023-03-17] (Microsoft Corporation)
    WindowsAppRuntime.1.2 → C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2_ 2000.802.31.0_x86__8wekyb3d8bbwe [2023-03-17] (Microsoft Corporation)
    ==================== Personnalisé CLSID (Avec liste blanche): ==============
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s’il est inscrit séparément.)
    CustomCLSID: HKU\S-1-5-21-4235641016-2069265453-480244600-1001_Classes\CLSID{D3E34B21-9D75-101A-8C3D-00AA001A1652}\localserver32 → C:\Program Files\WindowsApps\Microsoft.Paint_11.2301.22.0_x64 __8wekyb3d8bbwe\PaintApp\mspaint.exe () [Fichier non signé]
    ContextMenuHandlers3: [MBAMShlExt] → {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-01] (Malwarebytes Inc. → Malwarebytes)
    ContextMenuHandlers5: [ACE] → {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll [2021-02-16] (Advanced Micro Devices, Inc. → Advanced Micro Devices, Inc.)
    ContextMenuHandlers6: [MBAMShlExt] → {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-01] (Malwarebytes Inc. → Malwarebytes)
    ==================== Codecs (Avec liste blanche) ====================
    ==================== Raccourcis & WMI ========================
    ==================== Modules chargés (Avec liste blanche) =============
    ==================== Alternate Data Streams (Avec liste blanche) ========
    ==================== Mode sans échec (Avec liste blanche) ==================
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le “AlternateShell” sera restauré.)
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\HidSpiCx.sys => “”=“Driver”
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\MBAMService => “”=“Service”
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\TextInputManagementService => “”=“Service”
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal{5099944A-F6B9-4057-A056-8C550228544C} => “”=“Memory”
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal{5099944A-F6B9-4057-A056-8C550228544C} => “SafeBootDrivers”=“1”
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\HidSpiCx.sys => “”=“Driver”
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\MBAMService => “”=“Service”
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\TextInputManagementService => “”=“Service”
    ==================== Association (Avec liste blanche) =================
    ==================== Internet Explorer (Avec liste blanche) ==========
    BHO-x32: Skype for Business Browser Helper → {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2023-03-03] (Microsoft Corporation → Microsoft Corporation)
    Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation → Microsoft Corporation)
    ==================== Hosts contenu: =========================
    (Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.)
    2019-12-07 05:14 - 2019-12-07 05:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
    ==================== Autres zones ===========================
    (Actuellement, il n’y a pas de correction automatique pour cette section.)
    HKU\S-1-5-21-4235641016-2069265453-480244600-1001\Control Panel\Desktop\Wallpaper → C:\WINDOWS\web\wallpaper\Windows\img0.jpg
    DNS Servers: 24.200.243.189
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Le Pare-feu est activé.
    ==================== MSCONFIG/TASK MANAGER éléments désactivés ==
    ==================== RèglesPare-feu (Avec liste blanche) ================
    (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s’il est inscrit séparément.)
    FirewallRules: [{8F88F1AD-FDA0-4D45-83F8-BD458DF38945}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation → Microsoft Corporation)
    FirewallRules: [{B3823EA1-2FFF-4E17-A1FA-970E21016764}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation → Mozilla Corporation)
    FirewallRules: [{36E62C02-AD54-423B-9631-B0954E98B66A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation → Mozilla Corporation)
    FirewallRules: [TCP Query User{FFFECA14-45FC-4045-AFD0-4C1BA1FA263D}C:\users\marti\appdata\local\programs \opera gx\opera.exe] => (Allow) C:\users\marti\appdata\local\programs\opera gx\opera.exe (Opera Norway AS → Opera Software)
    FirewallRules: [UDP Query User{152AE52B-DEE8-4E86-AE15-34C3FFCF4C08}C:\users\marti\appdata\local\programs \opera gx\opera.exe] => (Allow) C:\users\marti\appdata\local\programs\opera gx\opera.exe (Opera Norway AS → Opera Software)
    FirewallRules: [{9EB0FC93-ACE2-4F7A-A493-633426D81079}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23047.400.1873.72 04_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation → Microsoft Corporation)
    FirewallRules: [{82A28CE1-3B4E-41CE-830E-4084DBE50B46}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23047.400.1873.72 04_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation → Microsoft Corporation)
    FirewallRules: [TCP Query User{329FEC60-1987-4A71-B97E-15E369368A6A}C:\users\marti\appdata\local\programs \opera gx\opera.exe] => (Block) C:\users\marti\appdata\local\programs\opera gx\opera.exe (Opera Norway AS → Opera Software)
    FirewallRules: [UDP Query User{F573C6AC-3695-4D9E-8620-A3A9508A7EBD}C:\users\marti\appdata\local\programs \opera gx\opera.exe] => (Block) C:\users\marti\appdata\local\programs\opera gx\opera.exe (Opera Norway AS → Opera Software)
    FirewallRules: [{3E050F9F-714C-4E03-996F-022405AD9EED}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3207.0_ x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl → Skype Technologies S.A.)
    FirewallRules: [{77B762E6-02FB-4551-9F4F-646708311078}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3207.0_ x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl → Skype Technologies S.A.)
    FirewallRules: [{DFCFA30B-9776-4D15-9324-69A74FC46900}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3207.0_ x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl → Skype Technologies S.A.)
    FirewallRules: [{044ED535-1933-4635-AC29-E6C430B578F5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3207.0_ x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl → Skype Technologies S.A.)
    FirewallRules: [{0DAF48AE-3C2A-4EA7-B046-DD0DBD3FE899}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{380FDBF7-2FA6-4F22-B4CC-D41F9B9C86CA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{46C73E68-5EB3-4A28-9730-16DCAAB9DFAE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{F3EEBA4E-0A2E-44BF-91DD-613B890E897A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{B97B893D-AED9-444B-9810-15BDA714B7B3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{B521E76A-FF5C-483B-9BE1-33E3B91B6FC3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{1FFA4153-5304-4F99-B27C-2540A225B1CA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{D4D6B18E-F5CC-4F51-B70D-66DC8283F258}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{A2B0671A-4865-486B-9B42-52ACD7DB66DC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{9E46010B-A333-4634-BA4F-6F2CC1D4850F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923 .0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB → Spotify Ltd)
    FirewallRules: [{02EE34C0-BFCB-405D-9084-A0C933099C9D}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\111.0.1661 .62\msedgewebview2.exe (Microsoft Corporation → Microsoft Corporation)
    ==================== Points de restauration =========================
    ATTENTION: La Restauration système est désactivée (Total:475.83 GB) (Free:419.44 GB) (88%)
    ==================== Éléments en erreur du Gestionnaire de périphériques ============
    ==================== Erreurs du Journal des événements: ========================
    Erreurs Application:[/HEADING]
    [HEADING=1]Error: (04/01/2023 01:54:14 PM) (Source: Application Error) (EventID: 1000) (User: LAPTOP-OFLICC0A)
    Description: Nom de l’application défaillante : AcerRegistrationBackGroundTask.exe, version : 1.0.0.0, horodatage : 0x63119a97
    Nom du module défaillant : KERNELBASE.dll, version : 10.0.22621.1485, horodatage : 0x0f433a40
    Code d’exception : 0xc000041d
    Décalage du défaut : 0x001479d2
    ID processus défaillant : 0x0x2e24
    Heure de démarrage de l’application défaillante : 0x0x1d964c2f5f27537
    Chemin de l’application défaillante : C:\Program Files\WindowsApps\AcerIncorporated.AcerRegistratio n_2.0.3040.0_x64__48frkmn4z8aw4\DesktopApp\AcerReg istrationBackGroundTask.exe
    Chemin du module défaillant : C:\WINDOWS\System32\KERNELBASE.dll
    Code de rapport : f1a9dbc6-151f-4981-ad1a-ae28da3d7dbe
    Nom complet de l’ensemble défaillant : AcerIncorporated.AcerRegistration_2.0.3040.0_x64__ 48frkmn4z8aw4
    ID de l’application relative à l’ensemble défaillant : Acer.AcerRegistration
    Error: (04/01/2023 01:54:11 PM) (Source: Application Error) (EventID: 1000) (User: LAPTOP-OFLICC0A)
    Description: Nom de l’application défaillante : AcerRegistrationBackGroundTask.exe, version : 1.0.0.0, horodatage : 0x63119a97
    Nom du module défaillant : KERNELBASE.dll, version : 10.0.22621.1485, horodatage : 0x0f433a40
    Code d’exception : 0xc0020001
    Décalage du défaut : 0x001479d2
    ID processus défaillant : 0x0x2e24
    Heure de démarrage de l’application défaillante : 0x0x1d964c2f5f27537
    Chemin de l’application défaillante : C:\Program Files\WindowsApps\AcerIncorporated.AcerRegistratio n_2.0.3040.0_x64__48frkmn4z8aw4\DesktopApp\AcerReg istrationBackGroundTask.exe
    Chemin du module défaillant : C:\WINDOWS\System32\KERNELBASE.dll
    Code de rapport : e41e0c80-1cc8-40d7-9706-ff552ed75db5
    Nom complet de l’ensemble défaillant : AcerIncorporated.AcerRegistration_2.0.3040.0_x64__ 48frkmn4z8aw4
    ID de l’application relative à l’ensemble défaillant : Acer.AcerRegistration
    Error: (04/01/2023 01:54:11 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
    Description: Application : AcerRegistrationBackGroundTask.exe
    Version du Framework : v4.0.30319
    Description : le processus a été arrêté en raison d’une exception non gérée.
    Informations sur l’exception : code d’exception c0020001, adresse d’exception 767479D2
    Pile :
    à MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr , IntPtr, Int32, IntPtr, IntPtr)
    à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
    à System.Environment._Exit(Int32)
    à System.Environment.Exit(Int32)
    à AcerRegistrationBackGroundTask.MainWindow+d__24.Mo veNext()
    à System.Runtime.CompilerServices.AsyncVoidMethodBui lder.Start[[AcerRegistrationBackGroundTask.MainWindow+d__24, AcerRegistrationBackGroundTask, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](d__24 ByRef)
    à AcerRegistrationBackGroundTask.MainWindow.closeBac kGroundTask()
    à AcerRegistrationBackGroundTask.MainWindow.Window_L oaded(System.Object, System.Windows.RoutedEventArgs)
    à System.Windows.RoutedEventHandlerInfo.InvokeHandle r(System.Object, System.Windows.RoutedEventArgs)
    à System.Windows.EventRoute.InvokeHandlersImpl(Syste m.Object, System.Windows.RoutedEventArgs, Boolean)
    à System.Windows.UIElement.RaiseEventImpl(System.Win dows.DependencyObject, System.Windows.RoutedEventArgs)
    à System.Windows.UIElement.RaiseEvent(System.Windows .RoutedEventArgs)
    à System.Windows.BroadcastEventHelper.BroadcastEvent (System.Windows.DependencyObject, System.Windows.RoutedEvent)
    à System.Windows.BroadcastEventHelper.BroadcastLoade dEvent(System.Object)
    à MS.Internal.LoadedOrUnloadedOperation.DoWork()
    à System.Windows.Media.MediaContext.FireLoadedPendin gCallbacks()
    à System.Windows.Media.MediaContext.FireInvokeOnRend erCallbacks()
    à System.Windows.Media.MediaContext.RenderMessageHan dlerCore(System.Object)
    à System.Windows.Media.MediaContext.RenderMessageHan dler(System.Object)
    à System.Windows.Media.MediaContext.Resize(System.Wi ndows.Media.ICompositionTarget)
    à System.Windows.Interop.HwndTarget.OnResize()
    à System.Windows.Interop.HwndTarget.HandleMessage(MS .Internal.Interop.WindowMessage, IntPtr, IntPtr)
    à System.Windows.Interop.HwndSource.HwndTargetFilter Message(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
    à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
    à MS.Win32.HwndSubclass.DispatcherCallbackOperation( System.Object)
    à System.Windows.Threading.ExceptionWrapper.Internal RealCall(System.Delegate, System.Object, Int32)
    à System.Windows.Threading.ExceptionWrapper.TryCatch When(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
    à System.Windows.Threading.Dispatcher.LegacyInvokeIm pl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
    à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
    à MS.Win32.UnsafeNativeMethods.ShowWindow(System.Run time.InteropServices.HandleRef, Int32)
    à System.Windows.Window.ShowHelper(System.Object)
    à System.Windows.Window.Show()
    à System.Windows.Application+<>c.b__105_0(System.Obj ect)
    à System.Windows.Threading.ExceptionWrapper.Internal RealCall(System.Delegate, System.Object, Int32)
    à System.Windows.Threading.ExceptionWrapper.TryCatch When(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
    à System.Windows.Threading.DispatcherOperation.Invok eImpl()
    à System.Windows.Threading.DispatcherOperation.Invok eInSecurityContext(System.Object)
    à MS.Internal.CulturePreservingExecutionContext.Call backWrapper(System.Object)
    à System.Threading.ExecutionContext.RunInternal(Syst em.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
    à System.Threading.ExecutionContext.Run(System.Threa ding.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
    à System.Threading.ExecutionContext.Run(System.Threa ding.ExecutionContext, System.Threading.ContextCallback, System.Object)
    à MS.Internal.CulturePreservingExecutionContext.Run( MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object)
    à System.Windows.Threading.DispatcherOperation.Invok e()
    à System.Windows.Threading.Dispatcher.ProcessQueue()
    à System.Windows.Threading.Dispatcher.WndProcHook(In tPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
    à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
    à MS.Win32.HwndSubclass.DispatcherCallbackOperation( System.Object)
    à System.Windows.Threading.ExceptionWrapper.Internal RealCall(System.Delegate, System.Object, Int32)
    à System.Windows.Threading.ExceptionWrapper.TryCatch When(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
    à System.Windows.Threading.Dispatcher.LegacyInvokeIm pl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
    à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
    à MS.Win32.UnsafeNativeMethods.DispatchMessage(Syste m.Windows.Interop.MSG ByRef)
    à System.Windows.Threading.Dispatcher.PushFrameImpl( System.Windows.Threading.DispatcherFrame)
    à System.Windows.Threading.Dispatcher.PushFrame(Syst em.Windows.Threading.DispatcherFrame)
    à System.Windows.Application.RunDispatcher(System.Ob ject)
    à System.Windows.Application.RunInternal(System.Wind ows.Window)
    à System.Windows.Application.Run(System.Windows.Wind ow)
    à AcerRegistrationBackGroundTask.Startup.Main(System .String)
    Error: (04/01/2023 01:33:20 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
    Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\LAPTOP-OFLICC0A$ via https://amd-keyid-52fb59e29aa83a962f...lates/Aik/scep :
    GetCACaps
    Méthode : GET(15ms)
    Étape : GetCACaps
    The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
    Error: (04/01/2023 01:33:19 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
    Description: Échec de l’initialisation de l’inscription du certificat SCEP pour Local system via https://amd-keyid-52fb59e29aa83a962f...lates/Aik/scep :
    GetCACaps
    Méthode : GET(47ms)
    Étape : GetCACaps
    The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
    Error: (04/01/2023 01:32:58 PM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
    Description: Nom de l’application défaillante : DtsApo4Service.exe, version : 1.6.4.0, horodatage : 0x5f7eb00c
    Nom du module défaillant : DtsApo4Service.exe, version : 1.6.4.0, horodatage : 0x5f7eb00c
    Code d’exception : 0xc0000005
    Décalage du défaut : 0x000000000000bed0
    ID processus défaillant : 0x0x149c
    Heure de démarrage de l’application défaillante : 0x0x1d964b34f0188f4
    Chemin de l’application défaillante : C:\WINDOWS\System32\DTS\PC\APO4x\DtsApo4Service.ex e
    Chemin du module défaillant : C:\WINDOWS\System32\DTS\PC\APO4x\DtsApo4Service.ex e
    Code de rapport : 9d54bd47-fb22-4152-9710-bbe5a1ba10ac
    Nom complet de l’ensemble défaillant :
    ID de l’application relative à l’ensemble défaillant :
    Error: (04/01/2023 01:32:58 PM) (Source: VSS) (EventID: 13) (User: )
    Description: Informations du service de cliché instantané de volumes : impossible de démarrer le serveur COM de CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} et de nom CEventSystem. [0x8007045b, A system shutdown is in progress.
    ]
    Error: (04/01/2023 12:23:14 PM) (Source: Application Error) (EventID: 1000) (User: LAPTOP-OFLICC0A)
    Description: Nom de l’application défaillante : AcerRegistrationBackGroundTask.exe, version : 1.0.0.0, horodatage : 0x63119a97
    Nom du module défaillant : KERNELBASE.dll, version : 10.0.22621.1413, horodatage : 0xac6c9125
    Code d’exception : 0xc000041d
    Décalage du défaut : 0x00147922
    ID processus défaillant : 0x0x3b38
    Heure de démarrage de l’application défaillante : 0x0x1d964b63fdb1913
    Chemin de l’application défaillante : C:\Program Files\WindowsApps\AcerIncorporated.AcerRegistratio n_2.0.3040.0_x64__48frkmn4z8aw4\DesktopApp\AcerReg istrationBackGroundTask.exe
    Chemin du module défaillant : C:\WINDOWS\System32\KERNELBASE.dll
    Code de rapport : 3a481592-7668-4cb4-9536-c3711cc8d611
    Nom complet de l’ensemble défaillant : AcerIncorporated.AcerRegistration_2.0.3040.0_x64__ 48frkmn4z8aw4
    ID de l’application relative à l’ensemble défaillant : Acer.AcerRegistration
    Erreurs système:[/HEADING]
    [HEADING=1]Error: (04/01/2023 01:35:59 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-OFLICC0A)
    Description: Le serveur {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} ne s’est pas enregistré sur DCOM avant la fin du temps imparti.
    Error: (04/01/2023 01:33:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: Le service SecurityService n’a pas pu démarrer en raison de l’erreur :
    Le fichier spécifié est introuvable.
    Error: (04/01/2023 01:32:51 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: DCOM a reçu l’erreur « 1115 » lors de la tentative de démarrage du service UsoSvc avec les arguments « Unavailable » pour exécuter le serveur :
    {B91D5831-B1BD-4608-8198-D72E155020F7}
    Error: (04/01/2023 01:32:51 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: DCOM a reçu l’erreur « 1115 » lors de la tentative de démarrage du service UsoSvc avec les arguments « Unavailable » pour exécuter le serveur :
    {B91D5831-B1BD-4608-8198-D72E155020F7}
    Error: (04/01/2023 12:02:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: Le service SecurityService n’a pas pu démarrer en raison de l’erreur :
    Le fichier spécifié est introuvable.
    Error: (04/01/2023 10:57:37 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-OFLICC0A)
    Description: Le serveur {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} ne s’est pas enregistré sur DCOM avant la fin du temps imparti.
    Error: (03/31/2023 10:48:02 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
    Description: Échec de l’installation : l’installation de la mise à jour suivante a échoue avec l’erreur 0x8007000a : 9WZDNCRFJ3PR-MICROSOFT.WINDOWSALARMS.
    Error: (03/31/2023 08:29:19 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-OFLICC0A)
    Description: Le serveur {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} ne s’est pas enregistré sur DCOM avant la fin du temps imparti.
    Windows Defender:[/HEADING]
    Date: 2023-03-31 16:42:12
    Description:
    L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
    ID de l’analyse : {20ED401A-5B69-4F30-874B-2F45525563C8}
    Type de l’analyse : Antimalware
    Paramètres de l’analyse : Quick Scan
    Utilisateur : NT AUTHORITY\SYSTEM
    Date: 2023-03-31 00:30:21
    Description:
    L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
    ID de l’analyse : {3E15ED26-DC14-41CA-B82D-FB66C0F6243A}
    Type de l’analyse : Antimalware
    Paramètres de l’analyse : Quick Scan
    Utilisateur : NT AUTHORITY\SYSTEM
    Date: 2023-03-28 17:51:25
    Description:
    L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
    ID de l’analyse : {F4AD2CE9-87FF-46CF-B9EF-44C07F3A5FC2}
    Type de l’analyse : Antimalware
    Paramètres de l’analyse : Quick Scan
    Utilisateur : NT AUTHORITY\SYSTEM
    Date: 2023-03-26 14:40:14
    Description:
    L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
    ID de l’analyse : {9DA129A8-76AC-4BE7-A5E2-237B9DE2F61D}
    Type de l’analyse : Antimalware
    Paramètres de l’analyse : Quick Scan
    Utilisateur : NT AUTHORITY\SYSTEM
    Date: 2023-03-25 19:18:49
    Description:
    L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
    ID de l’analyse : {A3EBD069-B501-4B31-BBCE-BE367E4CA67D}
    Type de l’analyse : Antimalware
    Paramètres de l’analyse : Quick Scan
    Utilisateur : NT AUTHORITY\SYSTEM
    [HEADING=1]CodeIntegrity:[/HEADING]
    Date: 2023-04-01 11:34:05
    Description:
    Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\TotalAV\wscf.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
    ==================== Infos Mémoire ===========================
    BIOS: Insyde Corp. V1.04 07/28/2021
    Carte mère: LN Sake_CA
    Processeur: AMD Ryzen 7 5700U with Radeon Graphics
    Pourcentage de mémoire utilisée: 69%
    Mémoire physique - RAM - totale: 7530.81 MB
    Mémoire physique - RAM - disponible: 2332.57 MB
    Mémoire virtuelle totale: 11626.81 MB
    Mémoire virtuelle disponible: 5385.27 MB
    ==================== Lecteurs ================================
    Drive c: (Acer) (Fixed) (Total:475.83 GB) (Free:419.44 GB) (Model: KINGSTON OM8PDP3512B-AA1) NTFS
    \?\Volume{c670f240-7b27-40aa-9fab-a8d9ec3c6d4d}\ (Recovery) (Fixed) (Total:1 GB) (Free:0.47 GB) NTFS
    \?\Volume{d0504640-819f-4fcf-a900-78bb5595bcb2}\ (ESP) (Fixed) (Total:0.09 GB) (Free:0.04 GB) FAT32
    ==================== MBR & Table des partitions ====================
    ==================== Fin de Addition.txt =======================
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #2
    @MartinC79 Sorry for the delay, looking over the logs now.

    Comment

    • MartinC79
      PCHF Member
      • Apr 2023
      • 2

      #3
      Originally posted by Malnutrition
      @MartinC79 Sorry for the delay, looking over the logs now.
      No worries! Problem solved since I posted this. Thanks anyway

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #4
        Uninstall with Geek Uninstaller.

        TotalAV (HKLM-x32...\TotalAV) (Version: 5.22.37 - TotalAV) <==== ATTENTION

        Copy the content of the code box below.
        Do not copy the word code!!!
        Right Click FRST and run as Administrator.
        Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
        Attach it to your next message.
        Code:
        Start::
        CloseProcesses:
        SystemRestore: On
        CreateRestorePoint:
        RemoveProxy:
        C:\WINDOWS\system32\drivers\etc\hosts
        Hosts:
        HKLM\...\Run: [] => [X]
        HKLM-x32\...\Run: [] => [X]
        HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [] => [X]
        S2 SecurityService; "C:\Program Files (x86)\TotalAV\SecurityService.exe" [X] <==== ATTENTION
        S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
        R1 webshieldfilter; C:\WINDOWS\System32\drivers\webshieldfilter.sys [96264 2023-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) <==== ATTENTION
        R1 webshieldfilter; C:\WINDOWS\System32\drivers\webshieldfilter.sys [96264 2023-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) <==== ATTENTION
        C:\WINDOWS\System32\drivers\webshieldfilter.sys
        C:\Program Files (x86)\TotalAV
        HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
        HKLM\...\Run: [] => [X]
        HKLM-x32\...\Run: [] => [X]
        HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [] => [X]
        Task: {1570B4EE-D8A6-44BB-9A9D-07A76F81CC85} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => C:\WINDOWS\system32\MusNotification.exe /RunOnAC ReadyToReboot (Pas de fichier)
        Task: {B33FBB97-F1FA-440A-8EDB-21D6BB7249DF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => C:\WINDOWS\system32\MusNotification.exe LogonUpdateResults (Pas de fichier)
        Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (Pas de fichier)
        Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => C:\WINDOWS\system32\MusNotification.exe (Pas de fichier)
        Task: {EAC219FB-53D0-4246-975D-E1412A5513E4} - \Opera GX scheduled assistant Autoupdate 1679494619 -> Pas de fichier <==== ATTENTION
        Task: {F2C355BB-9AEB-4D05-AF3D-BF97AB07A50F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => C:\WINDOWS\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Pas de fichier)
        S2 SecurityService; "C:\Program Files (x86)\TotalAV\SecurityService.exe" [X] <==== ATTENTION
        S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
        HKLM\...\Run: [] => [X]
        HKLM-x32\...\Run: [] => [X]
        HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [] => [X]
        Task: {1570B4EE-D8A6-44BB-9A9D-07A76F81CC85} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => C:\WINDOWS\system32\MusNotification.exe /RunOnAC ReadyToReboot (Pas de fichier)
        Task: {B33FBB97-F1FA-440A-8EDB-21D6BB7249DF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => C:\WINDOWS\system32\MusNotification.exe LogonUpdateResults (Pas de fichier)
        Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (Pas de fichier)
        Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => C:\WINDOWS\system32\MusNotification.exe (Pas de fichier)
        Task: {EAC219FB-53D0-4246-975D-E1412A5513E4} - \Opera GX scheduled assistant Autoupdate 1679494619 -> Pas de fichier <==== ATTENTION
        Task: {F2C355BB-9AEB-4D05-AF3D-BF97AB07A50F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => C:\WINDOWS\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Pas de fichier)
        S2 SecurityService; "C:\Program Files (x86)\TotalAV\SecurityService.exe" [X] <==== ATTENTION
        S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
        ProxyServer: [S-1-5-21-4235641016-2069265453-480244600-1001] => 64.235.204.107:3128
        Tcpip\Parameters: [DhcpNameServer] 24.200.243.189
        Tcpip\..\Interfaces\{530e4e9f-72bd-4859-b913-715ad06691f7}: [DhcpNameServer] 150.200.3.1
        Tcpip\..\Interfaces\{77aa0e95-1ed9-4d23-af4d-cb853f56a2e9}: [DhcpNameServer] 24.200.243.189
        Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
        Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
        Edge Notifications: Default -> hxxps://malwaretips.com; hxxps://reianter.com
        2023-04-01 13:40 - 2023-04-01 13:40 - 000806226 _____ C:\WINDOWS\system32\perfh00C.dat
        2023-04-01 13:40 - 2023-04-01 13:40 - 000154624 _____ C:\WINDOWS\system32\perfc00C.dat
        2023-04-01 11:34 - 2023-04-01 11:34 - 000000000 ____D C:\Users\marti\OneDrive\Documents\TotalAV
        2023-04-01 11:32 - 2023-04-01 11:32 - 000000000 ____D C:\ProgramData\SecuritySuite
        2023-04-01 11:31 - 2023-04-01 12:02 - 000000000 ____D C:\Program Files (x86)\TotalAV
        2023-04-01 11:31 - 2023-04-01 11:31 - 000000000 ____D C:\Users\marti\AppData\Local\GUI
        2023-04-01 11:31 - 2023-04-01 11:31 - 000000000 ____D C:\ProgramData\TotalAV
        2023-04-01 11:30 - 2023-04-01 11:31 - 057278304 _____ C:\Users\marti\Downloads\TotalAV_Setup.exe
        2023-03-04 21:35 - 2021-10-09 01:09 - 000000000 ____D C:\ProgramData\Norton
        2023-03-04 20:40 - 2022-09-18 19:24 - 000000000 ____D C:\Users\marti\AppData\LocalLow\Norton
        2023-03-04 20:38 - 2022-09-19 04:04 - 000000000 ____D C:\Program Files\Common Files\AV
        CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
        CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
        CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
        CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
        CMD: del /f /s /q %windir%\prefetch\*.*
        CMD: del /s /q C:\Windows\SoftwareDistribution\download\*.*
        CMD: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
        cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
        cmd: del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*"
        CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
        CMD: ipconfig /flushdns
        C:\Windows\Temp\*.*
        C:\WINDOWS\system32\*.tmp
        C:\WINDOWS\syswow64\*.tmp
        emptytemp:
        Reboot:
        End::

        Comment

        • Malnutrition
          PCHF Moderator
          • Jul 2016
          • 7041

          #5
          Originally posted by MartinC79
          No worries! Problem solved since I posted this. Thanks anyway
          Well, I did find a few things to remove, if you want follow up, or I can mark this as solved.

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7041

            #6
            You also need run the Norton Removal Tool.

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7041

              #7
              Marked solved. My apologies for the delay, it was not solved here. But it was…

              Comment

              Working...