• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Solved I keep getting those popup windows. Legit? Malware? How do I get rid of them?

Status
Not open for further replies.
I keep getting those popup windows (see attached screenshots). I suspect they are malware. I tried to get rid of them using a 3rd party app, but it did not work. How can I get rid of this malware?

As requested here, I ran FRST and am copying text from the 2 files produced after the scan. Any help is appreciated. Thank you.

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 25-03-2023
Exécuté par marti (administrateur) sur LAPTOP-OFLICC0A (Acer Swift SF314-43) (01-04-2023 14:01:28)
Exécuté depuis C:\Users\marti\Downloads
Profils chargés: marti
Plate-forme: Microsoft Windows 11 Home Version 22H2 22621.1485 (X64) Langue: Anglais (États-Unis) -> Français (Canada)
Navigateur par défaut: Edge
Mode d'amorçage: Normal
==================== Processus (Avec liste blanche) =================
(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)
(C:\Program Files\Acer\Quick Access Service\QASvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Quick Access Service\QAAdminAgent.exe
(C:\Program Files\Acer\Quick Access Service\QASvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Quick Access Service\QAAgent.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(C:\Program Files\WindowsApps\MicrosoftTeams_23047.400.1873.7204_x64__8wekyb3d8bbwe\msteams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\111.0.1661.62\msedgewebview2.exe <12>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <29>
(explorer.exe ->) (Opera Software AS -> Opera Software) C:\Users\marti\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe <2>
(services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\Care Center\ACCSvc.exe
(services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Quick Access Service\QASvc.exe
(services.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0364120.inf_amd64_636d39f1d2b33111\B364017\atiesrxx.exe
(services.exe ->) (DTS, Inc. -> DTS Inc.) C:\Windows\System32\DTS\PC\APO4x\DtsApo4Service.exe
(services.exe ->) (GoTrustID Inc -> GOTrustID Inc.) C:\Program Files\GoTrust ID Plugin\Bridge_Service.exe
(services.exe ->) (GOTrustID Inc.) [Fichier non signé] C:\Program Files\GoTrust ID Plugin\GoTrust ID Plugin\GTFidoService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\NisSrv.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\System32\Sgrm\SgrmBroker.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_4b6fe1c4e6f1d68a\RtkAudUService64.exe <3>
(svchost.exe ->) (Acer Incorporated -> ) C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
(svchost.exe ->) (Acer Incorporated -> Microsoft) C:\Program Files\Acer\StorPSCTL\StorPSCTL.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\marti\AppData\Local\Microsoft\OneDrive\23.054.0313.0001\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23022.140.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.3400.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
==================== Registre (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_4b6fe1c4e6f1d68a\RtkAudUService64.exe [1256520 2021-03-31] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\System32\OneDriveSetup.exe [50312608 2022-05-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\System32\OneDriveSetup.exe [50312608 2022-05-07] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [MicrosoftEdgeAutoLaunch_4A886EB596DDE810C696BFE47BAAC943] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4056016 2023-03-29] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [Opera GX Stable] => C:\Users\marti\AppData\Local\Programs\Opera GX\launcher.exe [2637208 2023-03-22] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [Opera GX Browser Assistant] => C:\Users\marti\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [] => [X]
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
==================== Tâches planifiées (Avec liste blanche) ============
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
Task: {01A8093B-0A95-4880-984D-C411107DE09F} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [58352 2023-03-05] (HP Inc. -> HP Inc.)
Task: {04B4685D-A1CE-4A24-9887-36C9219A64D7} - System32\Tasks\ModifyLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1710472 2020-12-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {0600DD45-FAF2-4131-A006-0B17509B9F78} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => %windir%\system32\sc.exe start InventorySvc
Task: {0D66473D-1527-4BD2-A201-B9CCDBD53425} - System32\Tasks\Oem\AcerJumpstartTask => C:\Program Files (x86)\Acer\Acer Jumpstart\hermes.exe [70792 2022-08-15] (Acer Incorporated -> )
Task: {0EF07161-0F04-4894-B176-ADF5B612AF5A} - System32\Tasks\StorPSCTL => C:\Program Files\Acer\StorPSCTL\StorPSCTL.exe [153640 2020-09-17] (Acer Incorporated -> Microsoft)
Task: {11F0DAC5-42F5-4069-9D2A-999A8D4E1FFA} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144264 2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {1570B4EE-D8A6-44BB-9A9D-07A76F81CC85} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => C:\WINDOWS\system32\MusNotification.exe /RunOnAC ReadyToReboot (Pas de fichier)
Task: {16D8AE9B-9AD9-47BB-BA8D-2F4A1588FD1D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MpCmdRun.exe [1645904 2023-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1CE73B3F-9B7B-4FD1-9B3D-E00FF6C0A23D} - System32\Tasks\ACCBackgroundApplication => C:\Program Files (x86)\Acer\Care Center\ACCStd.exe [4836512 2021-12-30] (Acer Incorporated -> )
Task: {210B3BCA-77BB-49E5-82D2-2FFCA33BAA07} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MpCmdRun.exe [1645904 2023-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {21BC3EB8-1CA5-4621-BA50-52EECCDAA850} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MpCmdRun.exe [1645904 2023-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {339B1510-DB11-42F9-95B2-D830C2E7E45D} - System32\Tasks\AMDInstallLauncher => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1710472 2020-12-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {3B2FFACE-794D-4FE9-8F1A-7642657EBE01} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [168880 2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {3EE12F8F-B4B7-424E-8830-E258BB446369} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [461472 2021-12-30] (Acer Incorporated -> Acer Incorporated)
Task: {43703415-4763-40F1-9806-96227EE283CC} - System32\Tasks\Opera GX scheduled Autoupdate 1678805962 => C:\Users\marti\AppData\Local\Programs\Opera GX\launcher.exe [2637208 2023-03-22] (Opera Norway AS -> Opera Software)
Task: {465EC0EA-3725-47A5-BE48-78509AEC1BCB} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26405352 2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {5C190CE2-5C3A-466B-A369-46B52669B619} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2971808 2021-12-30] (Acer Incorporated -> )
Task: {5E787C58-94BB-4A0C-BF16-4E887CEED25C} - System32\Tasks\AcerCMUpdateTask2.5.22250 => C:\Program Files (x86)\Acer\Amundsen\2.5.22250\awc.exe [96904 2022-09-25] (Acer Incorporated -> )
Task: {658EAAA1-1467-4A28-93EA-733976F463AE} - System32\Tasks\Quick Access => C:\Program Files\Acer\Quick Access Service\QALauncher.exe [446624 2022-01-03] (Acer Incorporated -> Acer Incorporated)
Task: {73D722E6-DE9B-4611-8388-25CA83320EF5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26405352 2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {813B2C56-6F2D-484E-B86B-DF76C2F855FB} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [676256 2023-03-24] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {8170D08E-C704-4FCE-923C-D677D2E15478} - System32\Tasks\GoTrust ID Driver => C:\Program Files\GoTrust ID Plugin\Resource\GO-Trust_ID_Driver.exe [68192 2020-09-08] (GoTrustID Inc -> )
Task: {88621C38-F695-4912-AEF9-5BB0D49C126F} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program Service\Framework\TriggerFramework.exe [268328 2020-11-19] (Acer Incorporated -> Acer Incorporated)
Task: {909402D5-5385-48F4-9EF5-636CE46AB87E} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1710472 2020-12-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {9F1757B3-F7D3-4B8C-BE53-4CA17987853F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [718752 2023-03-24] (Mozilla Corporation -> Mozilla Foundation)
Task: {B33FBB97-F1FA-440A-8EDB-21D6BB7249DF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => C:\WINDOWS\system32\MusNotification.exe LogonUpdateResults (Pas de fichier)
Task: {BA2A96DE-5BCB-4FC3-B351-01323816CB02} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [41632 2021-12-30] (Acer Incorporated -> )
Task: {BBE20386-9427-4620-8998-B55C875A9187} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MpCmdRun.exe [1645904 2023-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C7847B8E-6F52-47B2-99CE-9B5D71B1C03E} - System32\Tasks\UEIPInvitation => C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UEIPOOBECheck.exe [2211368 2020-11-19] (Acer Incorporated -> Acer Incorporated)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (Pas de fichier)
Task: {DC916C0A-D8DB-4A09-BD85-D99C9770FFD8} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [58352 2023-03-05] (HP Inc. -> HP Inc.)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => C:\WINDOWS\system32\MusNotification.exe (Pas de fichier)
Task: {EAC219FB-53D0-4246-975D-E1412A5513E4} - \Opera GX scheduled assistant Autoupdate 1679494619 -> Pas de fichier <==== ATTENTION
Task: {F2B21506-C943-453E-9FD1-00F0C5B4CB59} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [144264 2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {F2C355BB-9AEB-4D05-AF3D-BF97AB07A50F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => C:\WINDOWS\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Pas de fichier)
(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)
==================== Internet (Avec liste blanche) ====================
(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)
ProxyServer: [S-1-5-21-4235641016-2069265453-480244600-1001] => 64.235.204.107:3128
Tcpip\Parameters: [DhcpNameServer] 24.200.243.189
Tcpip\..\Interfaces\{530e4e9f-72bd-4859-b913-715ad06691f7}: [DhcpNameServer] 150.200.3.1
Tcpip\..\Interfaces\{77aa0e95-1ed9-4d23-af4d-cb853f56a2e9}: [DhcpNameServer] 24.200.243.189
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\marti\AppData\Local\Microsoft\Edge\User Data\Default [2023-04-01]
Edge Notifications: Default -> hxxps://malwaretips.com; hxxps://reianter.com
Edge HomePage: Default -> hxxp://google.ca/
Edge StartupUrls: Default -> "hxxp://google.ca/"
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
FireFox:
========
FF DefaultProfile: m2ecii3o.default
FF ProfilePath: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\m2ecii3o.default [2022-09-19]
FF ProfilePath: C:\Users\marti\AppData\Roaming\Mozilla\Firefox\Profiles\5r4zelcq.default-release [2023-04-01]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-11-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-11-01] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
Opera:
=======
StartMenuInternet: (HKU\S-1-5-21-4235641016-2069265453-480244600-1001) Opera GXStable - "C:\Users\marti\AppData\Local\Programs\Opera GX\Launcher.exe"
==================== Services (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R2 ACCSvc; C:\Program Files (x86)\Acer\Care Center\ACCSvc.exe [259232 2021-12-30] (Acer Incorporated -> Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12634512 2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
R2 DtsApo4Service; C:\WINDOWS\System32\DTS\PC\APO4x\DtsApo4Service.exe [201376 2020-10-17] (DTS, Inc. -> DTS Inc.)
R2 GoTrust ID Plugin; C:\Program Files\GoTrust ID Plugin\GoTrust ID Plugin\GTFidoService.exe [15360 2020-09-08] (GOTrustID Inc.) [Fichier non signé]
R2 GoTrustID Service; C:\Program Files\GoTrust ID Plugin\Bridge_Service.exe [336992 2020-09-08] (GoTrustID Inc -> GOTrustID Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [229360 2023-03-05] (HP Inc. -> HP Inc.)
S3 InventorySvc; C:\WINDOWS\system32\inventorysvc.dll [304480 2023-03-09] (Microsoft Windows -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9094440 2023-04-01] (Malwarebytes Inc. -> Malwarebytes)
S3 QALSvc; C:\Program Files\Acer\Quick Access Service\QALSvc.exe [466080 2022-01-03] (Acer Incorporated -> Acer Incorporated)
R3 QASvc; C:\Program Files\Acer\Quick Access Service\QASvc.exe [504480 2022-01-03] (Acer Incorporated -> Acer Incorporated)
R2 SgrmBroker; C:\WINDOWS\system32\Sgrm\SgrmBroker.exe [414632 2022-05-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TextInputManagementService; C:\WINDOWS\System32\TabSvc.dll [266240 2023-03-16] (Microsoft Windows -> Microsoft Corporation)
S3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program Service\Framework\UBTService.exe [342568 2020-11-19] (Acer Incorporated -> Acer Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\NisSrv.exe [3224328 2023-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2302.7-0\MsMpEng.exe [133544 2023-03-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 SecurityService; "C:\Program Files (x86)\TotalAV\SecurityService.exe" [X] <==== ATTENTION
===================== Pilotes (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R3 AcerAirplaneModeController; C:\WINDOWS\System32\drivers\AcerAirplaneModeController.sys [36800 2022-06-02] (Acer Incorporated -> Acer Incorporated)
R3 AMDAfdAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\amdacpafd.inf_amd64_07e32c567a3649e1\amdacpafd.sys [266048 2021-01-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R2 bfs; C:\WINDOWS\system32\drivers\bfs.sys [91480 2023-03-09] (Microsoft Windows -> Microsoft Corporation)
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [106496 2022-05-07] (Microsoft Corporation) [Fichier non signé]
S0 GenPass; C:\WINDOWS\System32\DriverStore\FileRepository\genpass.inf_amd64_bef88a423225ecdc\genpass.sys [62800 2022-05-07] (Microsoft Windows -> Microsoft Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223176 2023-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2023-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239544 2023-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MTKBTFilterX64; C:\WINDOWS\system32\DRIVERS\mtkbtfilterx.sys [284496 2022-03-01] (Microsoft Windows Hardware Compatibility Publisher -> MediaTek Inc.)
R3 mtkwlex; C:\WINDOWS\System32\drivers\mtkwl6ex.sys [1408472 2022-02-25] (Microsoft Windows Hardware Compatibility Publisher -> MediaTek Inc.)
S0 ProtectedELAM; C:\WINDOWS\System32\drivers\protected_elam.sys [18912 2023-02-17] (Microsoft Windows Early Launch Anti-malware Publisher -> TODO: <Company name>)
S0 pvscsi; C:\WINDOWS\System32\drivers\pvscsii.sys [45408 2022-05-07] (Microsoft Windows -> VMware, Inc.)
S3 RoutePolicy; C:\WINDOWS\System32\drivers\RoutePolicy.sys [98304 2022-05-07] (Microsoft Windows -> )
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49608 2023-03-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [495896 2023-03-27] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [99624 2023-03-27] (Microsoft Windows -> Microsoft Corporation)
R1 webshieldfilter; C:\WINDOWS\System32\drivers\webshieldfilter.sys [96264 2023-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) <==== ATTENTION
R2 wtd; C:\WINDOWS\System32\drivers\wtd.sys [118784 2023-03-16] (Microsoft Windows -> Microsoft Corporation)
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
==================== NetSvcs (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
==================== Un mois (créés) (Avec liste blanche) =========
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2023-04-01 14:01 - 2023-04-01 14:02 - 000022388 _____ C:\Users\marti\Downloads\FRST.txt
2023-04-01 14:01 - 2023-04-01 14:01 - 000000000 ____D C:\FRST
2023-04-01 14:00 - 2023-04-01 14:00 - 002379264 _____ (Farbar) C:\Users\marti\Downloads\Non confirmé 700523.crdownload
2023-04-01 14:00 - 2023-04-01 14:00 - 002379264 _____ (Farbar) C:\Users\marti\Downloads\Non confirmé 621581.crdownload
2023-04-01 13:58 - 2023-04-01 14:01 - 002379264 _____ (Farbar) C:\Users\marti\Downloads\FRST64.exe
2023-04-01 13:58 - 2023-04-01 13:58 - 002379264 _____ (Farbar) C:\Users\marti\Downloads\Non confirmé 443631.crdownload
2023-04-01 13:40 - 2023-04-01 13:40 - 000806226 _____ C:\WINDOWS\system32\perfh00C.dat
2023-04-01 13:40 - 2023-04-01 13:40 - 000154624 _____ C:\WINDOWS\system32\perfc00C.dat
2023-04-01 12:24 - 2023-04-01 12:24 - 000000000 ___HD C:\$WinREAgent
2023-04-01 12:07 - 2023-04-01 12:07 - 002649088 _____ (Malwarebytes) C:\Users\marti\Downloads\MBSetup-38EEE4E8 (1).exe
2023-04-01 11:51 - 2023-04-01 11:51 - 002649088 _____ (Malwarebytes) C:\Users\marti\Downloads\MBSetup-38EEE4E8.exe
2023-04-01 11:34 - 2023-04-01 11:34 - 000000000 ____D C:\Users\marti\OneDrive\Documents\TotalAV
2023-04-01 11:32 - 2023-04-01 11:32 - 000000000 ____D C:\ProgramData\SecuritySuite
2023-04-01 11:31 - 2023-04-01 12:02 - 000000000 ____D C:\Program Files (x86)\TotalAV
2023-04-01 11:31 - 2023-04-01 11:31 - 000000000 ____D C:\Users\marti\AppData\Local\GUI
2023-04-01 11:31 - 2023-04-01 11:31 - 000000000 ____D C:\ProgramData\TotalAV
2023-04-01 11:30 - 2023-04-01 11:31 - 057278304 _____ C:\Users\marti\Downloads\TotalAV_Setup.exe
2023-04-01 11:20 - 2023-04-01 11:52 - 000002037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2023-04-01 11:20 - 2023-04-01 11:52 - 000002025 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2023-04-01 11:19 - 2023-04-01 11:51 - 000000000 ____D C:\ProgramData\Malwarebytes
2023-04-01 11:19 - 2023-04-01 11:19 - 002649088 _____ (Malwarebytes) C:\Users\marti\Downloads\MBSetup.exe
2023-04-01 11:19 - 2023-04-01 11:19 - 002086424 _____ (Malwarebytes) C:\Users\marti\Downloads\MBSetup-076886.076886-Consumer.exe
2023-03-27 11:14 - 2023-03-27 11:15 - 000000000 ____D C:\WINDOWS\Minidump
2023-03-22 18:27 - 2023-04-01 13:34 - 000003126 _____ C:\WINDOWS\system32\Tasks\AMDInstallLauncher
2023-03-14 10:59 - 2023-03-28 08:49 - 000004218 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1678805962
2023-03-14 10:59 - 2023-03-28 08:49 - 000001438 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera GX Browser.lnk
2023-03-14 10:59 - 2023-03-14 10:59 - 000000000 ____D C:\Users\marti\AppData\Local\Opera Software
2023-03-14 10:58 - 2023-03-14 10:58 - 003599088 _____ (Opera Software) C:\Users\marti\Downloads\OperaGXSetup.exe
2023-03-14 10:58 - 2023-03-14 10:58 - 000000000 ____D C:\Users\marti\AppData\Roaming\Opera Software
2023-03-10 16:33 - 2023-03-10 16:33 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2023-03-09 14:26 - 2023-03-09 14:27 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2023-03-09 14:23 - 2023-03-09 14:26 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2023-03-09 14:23 - 2023-03-09 14:23 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\WINDOWS\addins
2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\Program Files\Reference Assemblies
2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\Program Files\MSBuild
2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2023-03-09 14:17 - 2023-03-09 14:17 - 000000000 ____D C:\Program Files (x86)\MSBuild
2023-03-09 14:16 - 2023-03-09 14:16 - 000000000 ____D C:\WINDOWS\SysWOW64\fr
2023-03-09 14:16 - 2023-03-09 14:16 - 000000000 ____D C:\WINDOWS\system32\fr
2023-03-09 11:40 - 2023-04-01 13:40 - 001800634 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2023-03-09 11:39 - 2023-03-09 11:39 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2023-03-09 11:37 - 2023-03-09 11:37 - 000000020 ___SH C:\Users\marti\ntuser.ini
2023-03-09 11:35 - 2023-04-01 13:34 - 000003110 _____ C:\WINDOWS\system32\Tasks\AMDLinkUpdate
2023-03-09 11:35 - 2023-04-01 13:33 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2023-03-09 11:35 - 2023-03-29 22:40 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4235641016-2069265453-480244600-1001
2023-03-09 11:35 - 2023-03-29 22:40 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4235641016-2069265453-480244600-1001
2023-03-09 11:35 - 2023-03-24 14:42 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2023-03-09 11:35 - 2023-03-21 19:42 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2023-03-09 11:35 - 2023-03-21 19:42 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2023-03-09 11:35 - 2023-03-09 11:35 - 000004302 _____ C:\WINDOWS\system32\Tasks\Software Update Application
2023-03-09 11:35 - 2023-03-09 11:35 - 000003852 _____ C:\WINDOWS\system32\Tasks\ACCAgent
2023-03-09 11:35 - 2023-03-09 11:35 - 000003682 _____ C:\WINDOWS\system32\Tasks\AcerCMUpdateTask2.5.22250
2023-03-09 11:35 - 2023-03-09 11:35 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4235641016-2069265453-480244600-500
2023-03-09 11:35 - 2023-03-09 11:35 - 000002782 _____ C:\WINDOWS\system32\Tasks\UbtFrameworkService
2023-03-09 11:35 - 2023-03-09 11:35 - 000002730 _____ C:\WINDOWS\system32\Tasks\ACC
2023-03-09 11:35 - 2023-03-09 11:35 - 000002712 _____ C:\WINDOWS\system32\Tasks\UEIPInvitation
2023-03-09 11:35 - 2023-03-09 11:35 - 000002672 _____ C:\WINDOWS\system32\Tasks\ModifyLinkUpdate
2023-03-09 11:35 - 2023-03-09 11:35 - 000002478 _____ C:\WINDOWS\system32\Tasks\StorPSCTL
2023-03-09 11:35 - 2023-03-09 11:35 - 000002408 _____ C:\WINDOWS\system32\Tasks\GoTrust ID Driver
2023-03-09 11:35 - 2023-03-09 11:35 - 000002328 _____ C:\WINDOWS\system32\Tasks\ACCBackgroundApplication
2023-03-09 11:35 - 2023-03-09 11:35 - 000002222 _____ C:\WINDOWS\system32\Tasks\Quick Access
2023-03-09 11:35 - 2023-03-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
2023-03-09 11:35 - 2023-03-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Oem
2023-03-09 11:35 - 2023-03-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP
2023-03-09 11:35 - 2023-03-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2023-03-09 11:34 - 2023-03-09 11:35 - 000011433 _____ C:\WINDOWS\diagwrn.xml
2023-03-09 11:34 - 2023-03-09 11:35 - 000011433 _____ C:\WINDOWS\diagerr.xml
2023-03-09 11:29 - 2023-03-27 12:45 - 000000000 ____D C:\Users\marti
2023-03-09 11:28 - 2023-04-01 13:33 - 000672592 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2023-03-09 11:28 - 2023-04-01 12:02 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2023-03-09 11:28 - 2023-03-09 11:28 - 000000000 ____D C:\WINDOWS\system32\config\BFS
2023-03-04 21:43 - 2023-03-20 16:23 - 000000000 ___DC C:\WINDOWS\Panther
2023-03-04 21:30 - 2023-03-04 21:30 - 000000000 ___HD C:\ProgramData\CyberLink
2023-03-04 20:54 - 2023-03-27 11:14 - 000000000 ____D C:\Program Files\Mozilla Firefox
==================== Un mois (modifiés) ==================
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2023-04-01 14:03 - 2022-05-07 01:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2023-04-01 14:01 - 2022-05-07 01:22 - 000000000 ____D C:\WINDOWS\INF
2023-04-01 13:54 - 2022-09-18 20:08 - 000000000 ____D C:\Users\marti\AppData\Local\CrashDumps
2023-04-01 13:34 - 2022-09-19 03:11 - 000000000 ___RD C:\Users\marti\OneDrive
2023-04-01 13:34 - 2022-05-07 01:24 - 000000000 ___HD C:\Program Files\WindowsApps
2023-04-01 13:34 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SystemTemp
2023-04-01 13:34 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2023-04-01 13:34 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\AppReadiness
2023-04-01 13:33 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\ServiceState
2023-04-01 13:33 - 2021-10-09 00:29 - 000012288 ___SH C:\DumpStack.log.tmp
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\UUS
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SystemResources
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\appraiser
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\ShellExperiences
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\ShellComponents
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\Provisioning
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2023-04-01 13:32 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\bcastdvr
2023-04-01 13:32 - 2022-05-07 01:17 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2023-04-01 12:32 - 2022-05-07 01:17 - 000000000 ____D C:\WINDOWS\CbsTemp
2023-04-01 11:52 - 2022-09-19 05:42 - 000000000 ____D C:\Users\marti\AppData\LocalLow\Mozilla
2023-04-01 11:51 - 2022-11-01 13:31 - 000000000 ____D C:\Program Files\Malwarebytes
2023-04-01 11:31 - 2022-05-07 01:24 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2023-04-01 11:21 - 2022-09-19 05:42 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2023-04-01 11:20 - 2022-09-19 03:09 - 000000000 ____D C:\Users\marti\AppData\Local\D3DSCache
2023-04-01 11:10 - 2022-09-19 03:11 - 000000000 ____D C:\ProgramData\Packages
2023-04-01 11:10 - 2022-09-19 03:09 - 000000000 ____D C:\Users\marti\AppData\Local\Packages
2023-03-31 11:08 - 2021-10-09 01:06 - 000000000 ____D C:\Program Files\Microsoft Office
2023-03-31 08:27 - 2021-10-09 00:30 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2023-03-29 22:40 - 2022-09-19 03:03 - 000002383 _____ C:\Users\marti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-03-27 15:26 - 2021-10-09 00:29 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2023-03-27 11:15 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2023-03-27 11:14 - 2021-10-09 01:13 - 002451782 ____N C:\WINDOWS\Minidump\032723-10750-01.dmp
2023-03-27 11:14 - 2021-10-09 01:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2023-03-24 14:42 - 2021-10-09 01:03 - 000001009 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2023-03-22 21:02 - 2022-09-19 03:09 - 000000000 ____D C:\Users\marti\AppData\Local\ConnectedDevicesPlatform
2023-03-16 16:54 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2023-03-16 16:53 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\es-MX
2023-03-16 16:53 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\Dism
2023-03-16 11:21 - 2022-09-21 08:06 - 000000000 ____D C:\WINDOWS\system32\MRT
2023-03-16 11:20 - 2022-09-21 08:06 - 153620824 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2023-03-16 00:21 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2023-03-11 15:18 - 2022-09-20 18:07 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-03-10 15:55 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2023-03-10 15:54 - 2022-09-19 03:11 - 000000000 ____D C:\Users\marti\AppData\Local\PlaceholderTileLogoFolder
2023-03-09 18:26 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\appcompat
2023-03-09 17:40 - 2022-05-07 01:17 - 000000000 ____D C:\WINDOWS\servicing
2023-03-09 14:28 - 2022-05-07 01:24 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2023-03-09 14:28 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2023-03-09 14:27 - 2022-09-19 04:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 7.4
2023-03-09 14:27 - 2022-09-19 02:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Acer
2023-03-09 14:27 - 2022-09-19 02:46 - 000000000 ____D C:\WINDOWS\oem
2023-03-09 14:27 - 2022-05-07 01:28 - 000000000 ____D C:\WINDOWS\Setup
2023-03-09 14:27 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\spool
2023-03-09 14:27 - 2022-05-07 01:24 - 000000000 ____D C:\ProgramData\USOPrivate
2023-03-09 14:27 - 2021-10-09 01:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2023-03-09 14:27 - 2021-10-09 01:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2023-03-09 14:27 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2023-03-09 14:26 - 2021-10-09 00:49 - 000000000 ____D C:\WINDOWS\system32\DTS
2023-03-09 14:26 - 2021-10-09 00:46 - 000000000 ____D C:\WINDOWS\system32\AMD
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\system32\UNP
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SystemApps
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\setup
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\Globalization
2023-03-09 14:22 - 2022-05-07 01:24 - 000000000 ____D C:\Program Files\Common Files\System
2023-03-09 14:21 - 2022-05-07 01:25 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2023-03-09 14:21 - 2022-05-07 01:24 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2023-03-09 14:17 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2023-03-09 14:17 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\MUI
2023-03-09 14:17 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\OCR
2023-03-09 14:16 - 2022-05-07 02:10 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2023-03-09 14:16 - 2022-05-07 02:10 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\system32\winrm
2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\system32\WCN
2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\system32\slmgr
2023-03-09 14:16 - 2022-05-07 02:01 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\system32\F12
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\system32\dsc
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\migwiz
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\Com
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\IME
2023-03-09 14:16 - 2022-05-07 01:24 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2023-03-09 11:54 - 2022-05-07 01:24 - 000000000 ___RD C:\WINDOWS\PrintDialog
2023-03-09 11:37 - 2021-10-09 00:32 - 000000000 __RHD C:\Users\Public\AccountPictures
2023-03-09 11:35 - 2022-05-07 01:24 - 000000000 ____D C:\Program Files\Windows Defender
2023-03-09 11:35 - 2022-05-07 01:17 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2023-03-09 11:32 - 2022-05-07 01:24 - 000000000 __RHD C:\Users\Public\Libraries
2023-03-09 11:30 - 2022-05-07 01:24 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2023-03-09 11:29 - 2022-05-07 01:24 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2023-03-05 21:31 - 2023-01-13 12:35 - 000000000 ____D C:\Program Files\HPPrintScanDoctor
2023-03-04 21:35 - 2021-10-09 01:09 - 000000000 ____D C:\ProgramData\Norton
2023-03-04 20:40 - 2022-09-18 19:24 - 000000000 ____D C:\Users\marti\AppData\LocalLow\Norton
2023-03-04 20:38 - 2022-09-19 04:04 - 000000000 ____D C:\Program Files\Common Files\AV
==================== SigCheck ============================
(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)
==================== Fin de FRST.txt ========================

Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version: 25-03-2023
Exécuté par marti (01-04-2023 14:06:07)
Exécuté depuis C:\Users\marti\Downloads
Microsoft Windows 11 Home Version 22H2 22621.1485 (X64) (2023-03-09 15:37:19)
Mode d'amorçage: Normal
==========================================================
==================== Comptes: =============================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.)
Administrator (S-1-5-21-4235641016-2069265453-480244600-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4235641016-2069265453-480244600-503 - Limited - Disabled)
Guest (S-1-5-21-4235641016-2069265453-480244600-501 - Limited - Disabled)
marti (S-1-5-21-4235641016-2069265453-480244600-1001 - Administrator - Enabled) => C:\Users\marti
WDAGUtilityAccount (S-1-5-21-4235641016-2069265453-480244600-504 - Limited - Disabled)
==================== Centre de sécurité ========================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.)
AV: Total AV (Disabled - Up to date) {0567E33F-93C9-11B5-891D-90A37AEB2766}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton Security Ultra (Enabled - Up to date) {9E3FD331-C4C2-7AC4-0537-131EEF1B1F8A}
FW: Norton Security Ultra (Enabled) {A6045214-8EAD-7B9C-2E68-BA2B11C858F1}
==================== Programmes installés ======================
(Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.)
Acer Configuration Manager (HKLM-x32\...\{8CB1A03C-9849-4744-AD56-341A18F9E3E2}) (Version: 2.5.22250 - Acer)
Acer Jumpstart (HKLM-x32\...\{0C5ED25A-B8D1-4E71-BFCB-6B370A4EA19C}) (Version: 3.5.22220.20 - Acer)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 20.40.32 - Advanced Micro Devices, Inc.)
Care Center Service (HKLM\...\{AFB52E98-7597-4484-9202-58F0FD3512ED}) (Version: 4.00.3042 - Acer Incorporated)
DriverSetupUtility (HKLM\...\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}) (Version: 1.00.3026 - Acer Incorporated)
GoTrust ID Plugin 2.0.12.36 (HKLM\...\GoTrust ID Plugin) (Version: 2.0.12.36 - GoTrust ID Inc.)
LibreOffice 7.4.1.2 (HKLM\...\{2382F0CD-B06A-49B7-912F-A8BB1C7FD511}) (Version: 7.4.1.2 - The Document Foundation)
Malwarebytes version 4.5.25.256 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.25.256 - Malwarebytes)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.16227.20212 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 111.0.1661.62 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 111.0.1661.62 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\OneDriveSetup.exe) (Version: 23.054.0313.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{EF9EBC42-6969-45CE-A8D2-B9249B00C838}) (Version: 5.69.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.29.30139 (HKLM-x32\...\{8d5fdf81-7022-423f-bd8b-b513a1050ae1}) (Version: 14.29.30139.0 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.24.28127 (HKLM\...\{8678BA04-D161-45BE-ACA4-CC5D13073F35}) (Version: 14.24.28127 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.24.28127 (HKLM\...\{7DC387B8-E6A2-480C-8EF9-A6E51AE81C19}) (Version: 14.24.28127 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.29.30139 (HKLM-x32\...\{1AEA8854-7597-4CD3-948F-8DE364D94E07}) (Version: 14.29.30139 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.29.30139 (HKLM-x32\...\{1679EF65-55F3-4248-B91E-6B3BE1A69CDF}) (Version: 14.29.30139 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 111.0 (x64 en-US)) (Version: 111.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 104.0.2 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.16130.20218 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.16227.20204 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13127.20616 - Microsoft Corporation) Hidden
Opera GX Stable 96.0.4693.117 (HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Opera GX 96.0.4693.117) (Version: 96.0.4693.117 - Opera Software)
Quick Access Service (HKLM\...\{AB25551C-74EF-4BAB-9989-891517FCF9FF}) (Version: 3.00.3038 - Acer Incorporated)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9088.1 - Realtek Semiconductor Corp.)
TotalAV (HKLM-x32\...\TotalAV) (Version: 5.22.37 - TotalAV) <==== ATTENTION
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{82BD0A1C-815F-487F-9AE7-CE73DA413CFF}) (Version: 4.91.0.0 - Microsoft Corporation)
User Experience Improvement Program Service (HKLM\...\{323EA05D-046D-449D-9D7C-89243C957CCE}) (Version: 5.00.3010 - Acer Incorporated)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Packages:
=========
Acer Product Registration -> C:\Program Files\WindowsApps\AcerIncorporated.AcerRegistration_2.0.3040.0_x64__48frkmn4z8aw4 [2022-10-16] (Acer Incorporated)
AMD Radeon Software -> C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.20.40028.0_x64__0a9344xs7nr4m [2022-09-22] (Advanced Micro Devices Inc.) [Startup Task]
Aura Privacy -> C:\Program Files\WindowsApps\Aura-YourDigitalHalo.FigLeaf_6.2.4.0_x64__ecvh8cc66bmhj [2022-09-22] (Aura - Your Digital Halo)
Care Center S -> C:\Program Files\WindowsApps\AcerIncorporated.AcerCareCenterS_4.0.3042.0_x64__48frkmn4z8aw4 [2022-09-19] (Acer Incorporated)
Clipchamp -> C:\Program Files\WindowsApps\Clipchamp.Clipchamp_2.5.15.0_neutral__yxz26nhyzhsrt [2023-03-10] (Microsoft Corp.)
Disney+ -> C:\Program Files\WindowsApps\Disney.37853FC22B2CE_1.49.3.0_x64__6rarf9sa4v8jt [2023-03-31] (Disney)
DTS Audio Processing -> C:\Program Files\WindowsApps\DTSInc.DTSAudioProcessing_1.10.9.0_x64__t5j2fzbtdg37r [2023-03-09] (DTS, Inc.)
GoTrust ID -> C:\Program Files\WindowsApps\GOTrustTechnologyInc.GO-TrustAuthenticator_3.1.21.0_x64__0r04f53sqacg6 [2023-03-05] (GoTrustID Inc.)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_143.1.1136.0_x64__v10z8vjag6ke6 [2023-03-05] (HP Inc.)
Messenger -> C:\Program Files\WindowsApps\FACEBOOK.317180B0BB486_1820.9.73.0_x64__8xx8rvfyw5nnt [2023-03-21] (Meta) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2022-09-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2022-09-20] (Microsoft Corporation) [MS Ad]
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2302.13004.0_x64__8wekyb3d8bbwe [2023-03-10] (Microsoft Corporation) [Startup Task]
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.39.0_x64__8wekyb3d8bbwe [2023-03-10] (Microsoft Corp.)
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_53.10126.517.0_x64__8wekyb3d8bbwe [2023-03-05] (Microsoft Corporation)
ms-resource://MicrosoftCorporationII.QuickAssist/resources/APP_WINDOW_NAME -> C:\Program Files\WindowsApps\MicrosoftCorporationII.QuickAssist_2.0.19.0_x64__8wekyb3d8bbwe [2023-03-10] (Microsoft Corp.)
ms-resource:AppStoreName -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.52851.0_x64__8wekyb3d8bbwe [2023-03-09] (Microsoft Corporation)
ms-resource:AppStoreName -> C:\Program Files\WindowsApps\Microsoft.RawImageExtension_2.1.60611.0_x64__8wekyb3d8bbwe [2023-03-28] (Microsoft Corporation)
ms-resource:AppxManifest_DisplayName -> C:\Windows\SystemApps\Microsoft.Windows.PrintQueueActionCenter_cw5n1h2txyewy [2023-03-09] (Microsoft Corporation)
ms-resource:OEMAppName -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_23.4.11.0_x64__xbfy0k16fey96 [2023-03-25] (Dropbox Inc.)
PhotoDirector for acer -> C:\Program Files\WindowsApps\CyberLinkCorp.ac.PhotoDirectorforacerDesktop_8.0.6428.0_x64__ypz87dpxkv292 [2022-09-19] (CYBERLINK COM CORP)
PowerDirector for acer -> C:\Program Files\WindowsApps\CyberLinkCorp.ac.PowerDirectorforacerDesktop_14.0.4304.0_x64__ypz87dpxkv292 [2022-09-19] (CYBERLINK COM CORP)
QuickAccess -> C:\Program Files\WindowsApps\AcerIncorporated.QuickAccess_3.0.3038.0_x64__48frkmn4z8aw4 [2022-09-19] (Acer Incorporated)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.25.247.0_x64__dt26b99r8h8gj [2023-03-05] (Realtek Semiconductor Corp)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0 [2023-03-31] (Spotify AB) [Startup Task]
User Experience Improvement Program V5 -> C:\Program Files\WindowsApps\AcerIncorporated.UserExperienceImprovementProgramV_5.0.3010.0_x64__48frkmn4z8aw4 [2022-09-19] (Acer Incorporated)
Windows Feature Experience Pack -> C:\Windows\SystemApps\MicrosoftWindows.Client.Core_cw5n1h2txyewy [2023-04-01] (Microsoft Windows)
WindowsAppRuntime.1.2 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2_2000.777.2143.0_x64__8wekyb3d8bbwe [2023-03-05] (Microsoft Corporation)
WindowsAppRuntime.1.2 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe [2023-03-17] (Microsoft Corporation)
WindowsAppRuntime.1.2 -> C:\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.2_2000.802.31.0_x86__8wekyb3d8bbwe [2023-03-17] (Microsoft Corporation)
==================== Personnalisé CLSID (Avec liste blanche): ==============
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
CustomCLSID: HKU\S-1-5-21-4235641016-2069265453-480244600-1001_Classes\CLSID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}\localserver32 -> C:\Program Files\WindowsApps\Microsoft.Paint_11.2301.22.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exe () [Fichier non signé]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-01] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\WINDOWS\System32\atiacm64.dll [2021-02-16] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-04-01] (Malwarebytes Inc. -> Malwarebytes)
==================== Codecs (Avec liste blanche) ====================
==================== Raccourcis & WMI ========================
==================== Modules chargés (Avec liste blanche) =============
==================== Alternate Data Streams (Avec liste blanche) ========
==================== Mode sans échec (Avec liste blanche) ==================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HidSpiCx.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TextInputManagementService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{5099944A-F6B9-4057-A056-8C550228544C} => ""="Memory"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{5099944A-F6B9-4057-A056-8C550228544C} => "SafeBootDrivers"="1"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HidSpiCx.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TextInputManagementService => ""="Service"
==================== Association (Avec liste blanche) =================
==================== Internet Explorer (Avec liste blanche) ==========
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2023-03-03] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-03-31] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts contenu: =========================
(Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.)
2019-12-07 05:14 - 2019-12-07 05:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Autres zones ===========================
(Actuellement, il n'y a pas de correction automatique pour cette section.)
HKU\S-1-5-21-4235641016-2069265453-480244600-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 24.200.243.189
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Le Pare-feu est activé.
==================== MSCONFIG/TASK MANAGER éléments désactivés ==
==================== RèglesPare-feu (Avec liste blanche) ================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
FirewallRules: [{8F88F1AD-FDA0-4D45-83F8-BD458DF38945}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B3823EA1-2FFF-4E17-A1FA-970E21016764}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{36E62C02-AD54-423B-9631-B0954E98B66A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{FFFECA14-45FC-4045-AFD0-4C1BA1FA263D}C:\users\marti\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\marti\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{152AE52B-DEE8-4E86-AE15-34C3FFCF4C08}C:\users\marti\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\marti\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [{9EB0FC93-ACE2-4F7A-A493-633426D81079}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23047.400.1873.7204_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{82A28CE1-3B4E-41CE-830E-4084DBE50B46}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23047.400.1873.7204_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{329FEC60-1987-4A71-B97E-15E369368A6A}C:\users\marti\appdata\local\programs\opera gx\opera.exe] => (Block) C:\users\marti\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{F573C6AC-3695-4D9E-8620-A3A9508A7EBD}C:\users\marti\appdata\local\programs\opera gx\opera.exe] => (Block) C:\users\marti\appdata\local\programs\opera gx\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [{3E050F9F-714C-4E03-996F-022405AD9EED}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3207.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{77B762E6-02FB-4551-9F4F-646708311078}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3207.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{DFCFA30B-9776-4D15-9324-69A74FC46900}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3207.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{044ED535-1933-4635-AC29-E6C430B578F5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3207.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{0DAF48AE-3C2A-4EA7-B046-DD0DBD3FE899}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{380FDBF7-2FA6-4F22-B4CC-D41F9B9C86CA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{46C73E68-5EB3-4A28-9730-16DCAAB9DFAE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{F3EEBA4E-0A2E-44BF-91DD-613B890E897A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B97B893D-AED9-444B-9810-15BDA714B7B3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B521E76A-FF5C-483B-9BE1-33E3B91B6FC3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{1FFA4153-5304-4F99-B27C-2540A225B1CA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{D4D6B18E-F5CC-4F51-B70D-66DC8283F258}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A2B0671A-4865-486B-9B42-52ACD7DB66DC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{9E46010B-A333-4634-BA4F-6F2CC1D4850F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.208.923.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{02EE34C0-BFCB-405D-9084-A0C933099C9D}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\111.0.1661.62\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Points de restauration =========================
ATTENTION: La Restauration système est désactivée (Total:475.83 GB) (Free:419.44 GB) (88%)
==================== Éléments en erreur du Gestionnaire de périphériques ============
==================== Erreurs du Journal des événements: ========================
Erreurs Application:
==================
Error: (04/01/2023 01:54:14 PM) (Source: Application Error) (EventID: 1000) (User: LAPTOP-OFLICC0A)
Description: Nom de l’application défaillante : AcerRegistrationBackGroundTask.exe, version : 1.0.0.0, horodatage : 0x63119a97
Nom du module défaillant : KERNELBASE.dll, version : 10.0.22621.1485, horodatage : 0x0f433a40
Code d’exception : 0xc000041d
Décalage du défaut : 0x001479d2
ID processus défaillant : 0x0x2e24
Heure de démarrage de l’application défaillante : 0x0x1d964c2f5f27537
Chemin de l’application défaillante : C:\Program Files\WindowsApps\AcerIncorporated.AcerRegistration_2.0.3040.0_x64__48frkmn4z8aw4\DesktopApp\AcerRegistrationBackGroundTask.exe
Chemin du module défaillant : C:\WINDOWS\System32\KERNELBASE.dll
Code de rapport : f1a9dbc6-151f-4981-ad1a-ae28da3d7dbe
Nom complet de l’ensemble défaillant : AcerIncorporated.AcerRegistration_2.0.3040.0_x64__48frkmn4z8aw4
ID de l’application relative à l’ensemble défaillant : Acer.AcerRegistration
Error: (04/01/2023 01:54:11 PM) (Source: Application Error) (EventID: 1000) (User: LAPTOP-OFLICC0A)
Description: Nom de l’application défaillante : AcerRegistrationBackGroundTask.exe, version : 1.0.0.0, horodatage : 0x63119a97
Nom du module défaillant : KERNELBASE.dll, version : 10.0.22621.1485, horodatage : 0x0f433a40
Code d’exception : 0xc0020001
Décalage du défaut : 0x001479d2
ID processus défaillant : 0x0x2e24
Heure de démarrage de l’application défaillante : 0x0x1d964c2f5f27537
Chemin de l’application défaillante : C:\Program Files\WindowsApps\AcerIncorporated.AcerRegistration_2.0.3040.0_x64__48frkmn4z8aw4\DesktopApp\AcerRegistrationBackGroundTask.exe
Chemin du module défaillant : C:\WINDOWS\System32\KERNELBASE.dll
Code de rapport : e41e0c80-1cc8-40d7-9706-ff552ed75db5
Nom complet de l’ensemble défaillant : AcerIncorporated.AcerRegistration_2.0.3040.0_x64__48frkmn4z8aw4
ID de l’application relative à l’ensemble défaillant : Acer.AcerRegistration
Error: (04/01/2023 01:54:11 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application : AcerRegistrationBackGroundTask.exe
Version du Framework : v4.0.30319
Description : le processus a été arrêté en raison d'une exception non gérée.
Informations sur l'exception : code d'exception c0020001, adresse d'exception 767479D2
Pile :
à MS.Win32.UnsafeNativeMethods.CallWindowProc(IntPtr, IntPtr, Int32, IntPtr, IntPtr)
à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
à System.Environment._Exit(Int32)
à System.Environment.Exit(Int32)
à AcerRegistrationBackGroundTask.MainWindow+<closeBackGroundTask>d__24.MoveNext()
à System.Runtime.CompilerServices.AsyncVoidMethodBuilder.Start[[AcerRegistrationBackGroundTask.MainWindow+<closeBackGroundTask>d__24, AcerRegistrationBackGroundTask, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](<closeBackGroundTask>d__24 ByRef)
à AcerRegistrationBackGroundTask.MainWindow.closeBackGroundTask()
à AcerRegistrationBackGroundTask.MainWindow.Window_Loaded(System.Object, System.Windows.RoutedEventArgs)
à System.Windows.RoutedEventHandlerInfo.InvokeHandler(System.Object, System.Windows.RoutedEventArgs)
à System.Windows.EventRoute.InvokeHandlersImpl(System.Object, System.Windows.RoutedEventArgs, Boolean)
à System.Windows.UIElement.RaiseEventImpl(System.Windows.DependencyObject, System.Windows.RoutedEventArgs)
à System.Windows.UIElement.RaiseEvent(System.Windows.RoutedEventArgs)
à System.Windows.BroadcastEventHelper.BroadcastEvent(System.Windows.DependencyObject, System.Windows.RoutedEvent)
à System.Windows.BroadcastEventHelper.BroadcastLoadedEvent(System.Object)
à MS.Internal.LoadedOrUnloadedOperation.DoWork()
à System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
à System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks()
à System.Windows.Media.MediaContext.RenderMessageHandlerCore(System.Object)
à System.Windows.Media.MediaContext.RenderMessageHandler(System.Object)
à System.Windows.Media.MediaContext.Resize(System.Windows.Media.ICompositionTarget)
à System.Windows.Interop.HwndTarget.OnResize()
à System.Windows.Interop.HwndTarget.HandleMessage(MS.Internal.Interop.WindowMessage, IntPtr, IntPtr)
à System.Windows.Interop.HwndSource.HwndTargetFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
à MS.Win32.UnsafeNativeMethods.ShowWindow(System.Runtime.InteropServices.HandleRef, Int32)
à System.Windows.Window.ShowHelper(System.Object)
à System.Windows.Window.Show()
à System.Windows.Application+<>c.<RunInternal>b__105_0(System.Object)
à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
à System.Windows.Threading.DispatcherOperation.InvokeImpl()
à System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object)
à MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object)
à System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
à System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
à MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object)
à System.Windows.Threading.DispatcherOperation.Invoke()
à System.Windows.Threading.Dispatcher.ProcessQueue()
à System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
à MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
à MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
à System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
à System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
à System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
à MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
à MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
à System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
à System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
à System.Windows.Application.RunDispatcher(System.Object)
à System.Windows.Application.RunInternal(System.Windows.Window)
à System.Windows.Application.Run(System.Windows.Window)
à AcerRegistrationBackGroundTask.Startup.Main(System.String[])
Error: (04/01/2023 01:33:20 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Échec de l’initialisation de l’inscription du certificat SCEP pour WORKGROUP\LAPTOP-OFLICC0A$ via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep :
GetCACaps
Méthode : GET(15ms)
Étape : GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (04/01/2023 01:33:19 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Échec de l’initialisation de l’inscription du certificat SCEP pour Local system via https://AMD-KeyId-52fb59e29aa83a962fb9eef0fe5b4811de6b751e.microsoftaik.azure.net/templates/Aik/scep :
GetCACaps
Méthode : GET(47ms)
Étape : GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (04/01/2023 01:32:58 PM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Nom de l’application défaillante : DtsApo4Service.exe, version : 1.6.4.0, horodatage : 0x5f7eb00c
Nom du module défaillant : DtsApo4Service.exe, version : 1.6.4.0, horodatage : 0x5f7eb00c
Code d’exception : 0xc0000005
Décalage du défaut : 0x000000000000bed0
ID processus défaillant : 0x0x149c
Heure de démarrage de l’application défaillante : 0x0x1d964b34f0188f4
Chemin de l’application défaillante : C:\WINDOWS\System32\DTS\PC\APO4x\DtsApo4Service.exe
Chemin du module défaillant : C:\WINDOWS\System32\DTS\PC\APO4x\DtsApo4Service.exe
Code de rapport : 9d54bd47-fb22-4152-9710-bbe5a1ba10ac
Nom complet de l’ensemble défaillant :
ID de l’application relative à l’ensemble défaillant :
Error: (04/01/2023 01:32:58 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informations du service de cliché instantané de volumes : impossible de démarrer le serveur COM de CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} et de nom CEventSystem. [0x8007045b, A system shutdown is in progress.
]
Error: (04/01/2023 12:23:14 PM) (Source: Application Error) (EventID: 1000) (User: LAPTOP-OFLICC0A)
Description: Nom de l’application défaillante : AcerRegistrationBackGroundTask.exe, version : 1.0.0.0, horodatage : 0x63119a97
Nom du module défaillant : KERNELBASE.dll, version : 10.0.22621.1413, horodatage : 0xac6c9125
Code d’exception : 0xc000041d
Décalage du défaut : 0x00147922
ID processus défaillant : 0x0x3b38
Heure de démarrage de l’application défaillante : 0x0x1d964b63fdb1913
Chemin de l’application défaillante : C:\Program Files\WindowsApps\AcerIncorporated.AcerRegistration_2.0.3040.0_x64__48frkmn4z8aw4\DesktopApp\AcerRegistrationBackGroundTask.exe
Chemin du module défaillant : C:\WINDOWS\System32\KERNELBASE.dll
Code de rapport : 3a481592-7668-4cb4-9536-c3711cc8d611
Nom complet de l’ensemble défaillant : AcerIncorporated.AcerRegistration_2.0.3040.0_x64__48frkmn4z8aw4
ID de l’application relative à l’ensemble défaillant : Acer.AcerRegistration
Erreurs système:
=============
Error: (04/01/2023 01:35:59 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-OFLICC0A)
Description: Le serveur {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} ne s’est pas enregistré sur DCOM avant la fin du temps imparti.
Error: (04/01/2023 01:33:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service SecurityService n'a pas pu démarrer en raison de l'erreur :
Le fichier spécifié est introuvable.
Error: (04/01/2023 01:32:51 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM a reçu l’erreur « 1115 » lors de la tentative de démarrage du service UsoSvc avec les arguments « Unavailable » pour exécuter le serveur :
{B91D5831-B1BD-4608-8198-D72E155020F7}
Error: (04/01/2023 01:32:51 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM a reçu l’erreur « 1115 » lors de la tentative de démarrage du service UsoSvc avec les arguments « Unavailable » pour exécuter le serveur :
{B91D5831-B1BD-4608-8198-D72E155020F7}
Error: (04/01/2023 12:02:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service SecurityService n'a pas pu démarrer en raison de l'erreur :
Le fichier spécifié est introuvable.
Error: (04/01/2023 10:57:37 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-OFLICC0A)
Description: Le serveur {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} ne s’est pas enregistré sur DCOM avant la fin du temps imparti.
Error: (03/31/2023 10:48:02 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Échec de l’installation : l’installation de la mise à jour suivante a échoue avec l’erreur 0x8007000a : 9WZDNCRFJ3PR-MICROSOFT.WINDOWSALARMS.
Error: (03/31/2023 08:29:19 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-OFLICC0A)
Description: Le serveur {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} ne s’est pas enregistré sur DCOM avant la fin du temps imparti.
Windows Defender:
================
Date: 2023-03-31 16:42:12
Description:
L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
ID de l’analyse : {20ED401A-5B69-4F30-874B-2F45525563C8}
Type de l’analyse : Antimalware
Paramètres de l’analyse : Quick Scan
Utilisateur : NT AUTHORITY\SYSTEM
Date: 2023-03-31 00:30:21
Description:
L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
ID de l’analyse : {3E15ED26-DC14-41CA-B82D-FB66C0F6243A}
Type de l’analyse : Antimalware
Paramètres de l’analyse : Quick Scan
Utilisateur : NT AUTHORITY\SYSTEM
Date: 2023-03-28 17:51:25
Description:
L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
ID de l’analyse : {F4AD2CE9-87FF-46CF-B9EF-44C07F3A5FC2}
Type de l’analyse : Antimalware
Paramètres de l’analyse : Quick Scan
Utilisateur : NT AUTHORITY\SYSTEM
Date: 2023-03-26 14:40:14
Description:
L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
ID de l’analyse : {9DA129A8-76AC-4BE7-A5E2-237B9DE2F61D}
Type de l’analyse : Antimalware
Paramètres de l’analyse : Quick Scan
Utilisateur : NT AUTHORITY\SYSTEM
Date: 2023-03-25 19:18:49
Description:
L’analyse Microsoft Defender Antivirus a été arrêtée avant la fin.
ID de l’analyse : {A3EBD069-B501-4B31-BBCE-BE367E4CA67D}
Type de l’analyse : Antimalware
Paramètres de l’analyse : Quick Scan
Utilisateur : NT AUTHORITY\SYSTEM

CodeIntegrity:
===============
Date: 2023-04-01 11:34:05
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\TotalAV\wscf.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Infos Mémoire ===========================
BIOS: Insyde Corp. V1.04 07/28/2021
Carte mère: LN Sake_CA
Processeur: AMD Ryzen 7 5700U with Radeon Graphics
Pourcentage de mémoire utilisée: 69%
Mémoire physique - RAM - totale: 7530.81 MB
Mémoire physique - RAM - disponible: 2332.57 MB
Mémoire virtuelle totale: 11626.81 MB
Mémoire virtuelle disponible: 5385.27 MB
==================== Lecteurs ================================
Drive c: (Acer) (Fixed) (Total:475.83 GB) (Free:419.44 GB) (Model: KINGSTON OM8PDP3512B-AA1) NTFS
\\?\Volume{c670f240-7b27-40aa-9fab-a8d9ec3c6d4d}\ (Recovery) (Fixed) (Total:1 GB) (Free:0.47 GB) NTFS
\\?\Volume{d0504640-819f-4fcf-a900-78bb5595bcb2}\ (ESP) (Fixed) (Total:0.09 GB) (Free:0.04 GB) FAT32
==================== MBR & Table des partitions ====================
==================== Fin de Addition.txt =======================
 

Attachments

  • screenshot.jpg
    screenshot.jpg
    57.8 KB · Views: 10
  • screenshot2.jpg
    screenshot2.jpg
    66.2 KB · Views: 9
Uninstall with Geek Uninstaller.

TotalAV (HKLM-x32\...\TotalAV) (Version: 5.22.37 - TotalAV) <==== ATTENTION

Copy the content of the code box below.
Do not copy the word code!!!
Right Click FRST and run as Administrator.
Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
Attach it to your next message.


Code:
Start::
CloseProcesses:
SystemRestore: On
CreateRestorePoint:
RemoveProxy:
C:\WINDOWS\system32\drivers\etc\hosts
Hosts:
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [] => [X]
S2 SecurityService; "C:\Program Files (x86)\TotalAV\SecurityService.exe" [X] <==== ATTENTION
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
R1 webshieldfilter; C:\WINDOWS\System32\drivers\webshieldfilter.sys [96264 2023-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) <==== ATTENTION
R1 webshieldfilter; C:\WINDOWS\System32\drivers\webshieldfilter.sys [96264 2023-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) <==== ATTENTION
C:\WINDOWS\System32\drivers\webshieldfilter.sys
C:\Program Files (x86)\TotalAV
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [] => [X]
Task: {1570B4EE-D8A6-44BB-9A9D-07A76F81CC85} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => C:\WINDOWS\system32\MusNotification.exe /RunOnAC ReadyToReboot (Pas de fichier)
Task: {B33FBB97-F1FA-440A-8EDB-21D6BB7249DF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => C:\WINDOWS\system32\MusNotification.exe LogonUpdateResults (Pas de fichier)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (Pas de fichier)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => C:\WINDOWS\system32\MusNotification.exe (Pas de fichier)
Task: {EAC219FB-53D0-4246-975D-E1412A5513E4} - \Opera GX scheduled assistant Autoupdate 1679494619 -> Pas de fichier <==== ATTENTION
Task: {F2C355BB-9AEB-4D05-AF3D-BF97AB07A50F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => C:\WINDOWS\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Pas de fichier)
S2 SecurityService; "C:\Program Files (x86)\TotalAV\SecurityService.exe" [X] <==== ATTENTION
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4235641016-2069265453-480244600-1001\...\Run: [] => [X]
Task: {1570B4EE-D8A6-44BB-9A9D-07A76F81CC85} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => C:\WINDOWS\system32\MusNotification.exe /RunOnAC ReadyToReboot (Pas de fichier)
Task: {B33FBB97-F1FA-440A-8EDB-21D6BB7249DF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults => C:\WINDOWS\system32\MusNotification.exe LogonUpdateResults (Pas de fichier)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\WINDOWS\System32\MbaeParserTask.exe (Pas de fichier)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => C:\WINDOWS\system32\MusNotification.exe (Pas de fichier)
Task: {EAC219FB-53D0-4246-975D-E1412A5513E4} - \Opera GX scheduled assistant Autoupdate 1679494619 -> Pas de fichier <==== ATTENTION
Task: {F2C355BB-9AEB-4D05-AF3D-BF97AB07A50F} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => C:\WINDOWS\system32\MusNotification.exe /RunOnBattery ReadyToReboot (Pas de fichier)
S2 SecurityService; "C:\Program Files (x86)\TotalAV\SecurityService.exe" [X] <==== ATTENTION
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
ProxyServer: [S-1-5-21-4235641016-2069265453-480244600-1001] => 64.235.204.107:3128
Tcpip\Parameters: [DhcpNameServer] 24.200.243.189
Tcpip\..\Interfaces\{530e4e9f-72bd-4859-b913-715ad06691f7}: [DhcpNameServer] 150.200.3.1
Tcpip\..\Interfaces\{77aa0e95-1ed9-4d23-af4d-cb853f56a2e9}: [DhcpNameServer] 24.200.243.189
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge Notifications: Default -> hxxps://malwaretips.com; hxxps://reianter.com
2023-04-01 13:40 - 2023-04-01 13:40 - 000806226 _____ C:\WINDOWS\system32\perfh00C.dat
2023-04-01 13:40 - 2023-04-01 13:40 - 000154624 _____ C:\WINDOWS\system32\perfc00C.dat
2023-04-01 11:34 - 2023-04-01 11:34 - 000000000 ____D C:\Users\marti\OneDrive\Documents\TotalAV
2023-04-01 11:32 - 2023-04-01 11:32 - 000000000 ____D C:\ProgramData\SecuritySuite
2023-04-01 11:31 - 2023-04-01 12:02 - 000000000 ____D C:\Program Files (x86)\TotalAV
2023-04-01 11:31 - 2023-04-01 11:31 - 000000000 ____D C:\Users\marti\AppData\Local\GUI
2023-04-01 11:31 - 2023-04-01 11:31 - 000000000 ____D C:\ProgramData\TotalAV
2023-04-01 11:30 - 2023-04-01 11:31 - 057278304 _____ C:\Users\marti\Downloads\TotalAV_Setup.exe
2023-03-04 21:35 - 2021-10-09 01:09 - 000000000 ____D C:\ProgramData\Norton
2023-03-04 20:40 - 2022-09-18 19:24 - 000000000 ____D C:\Users\marti\AppData\LocalLow\Norton
2023-03-04 20:38 - 2022-09-19 04:04 - 000000000 ____D C:\Program Files\Common Files\AV
CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
CMD: del /f /s /q %windir%\prefetch\*.*
CMD: del /s /q C:\Windows\SoftwareDistribution\download\*.*
CMD: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
cmd: del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*"
CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
CMD: ipconfig /flushdns
C:\Windows\Temp\*.*
C:\WINDOWS\system32\*.tmp
C:\WINDOWS\syswow64\*.tmp
emptytemp:
Reboot:
End::
 
Status
Not open for further replies.