Résultats de correction de Farbar Recovery Scan Tool (x64) Version: 20-09-2023 Exécuté par PC du camping car (20-09-2023 17:34:47) Run:2 Exécuté depuis C:\Users\PC du camping car\Desktop Profils chargés: defaultuser0 & PC du camping car Mode d'amorçage: Normal ============================================== fixlist contenu: ***************** CreateRestorePoint: CloseProcesses: C:\Windows\Prefetch\AVASTCLEAR.EXE-510FADD7.pf C:\Windows\Prefetch\AVASTNM.EXE-A097FF9E.pf C:\Windows\Prefetch\AVASTSVC.EXE-CBA6876B.pf C:\Windows\Prefetch\AVASTUI.EXE-19622E35.pf C:\Windows\Prefetch\AVASTUI.EXE-19622E36.pf C:\Windows\Prefetch\AVASTUI.EXE-19622E37.pf C:\Windows\Prefetch\AVASTUI.EXE-19622E3D.pf C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-16B44146.pf C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-68EC2C31.pf C:\FRST\Quarantine\C\ProgramData\Avast Software C:\FRST\Quarantine\C\Users\PC du camping car\AppData\Local\Avast Software C:\Program Files\Avast Software deletekey: HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software deletekey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\avast deletekey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage Deletevalue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|AvastUI.exe deletekey: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\AVAST Software deletekey: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\AvastAdSDK deletekey: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{0d0504ba-c43e-4d3d-90ed-38d4d3517e2b}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$avast antivirus deletekey: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{0d0504ba-c43e-4d3d-90ed-38d4d3517e2b}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$avast antivirus Deletevalue: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView|{6D809377-6AF0-444B-8957-A3773F02200E}\Avast Software\Avast\setup\instup.exe Deletevalue: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\PC du camping car\Downloadsavast_free_antivirus_setup_online.exe Deletevalue: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Avast Software\Avast\AvastUI.exe Deletevalue: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files\Avast Software\Avast\setup\instup.exe Deletevalue: HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\PC du camping car\Desktop\avastclear.exe CMD: net start WinDefend CMD: net start wscsvc reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Account Protection" /va /f StartRegedit: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender] "DisableAntiSpyware"=- "DisableBehaviorMonitoring"=- "DisableOnAccessProtection"=- "DisableScanOnRealtimeEnable"=- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet] "SubmitSamplesConsent"=- "SpyNetReporting"=- [-HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection] "DisableRealtimeMonitoring"=- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend] "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="@%ProgramFiles%\\Windows Defender\\MpAsDesc.dll,-240" "DisplayName"="@%ProgramFiles%\\Windows Defender\\MpAsDesc.dll,-310" "ErrorControl"=dword:00000001 "FailureActions"=hex:80,51,01,00,00,00,00,00,01,00,00,00,03,00,00,00,14,00,00,\ 00,01,00,00,00,e8,03,00,00,01,00,00,00,10,27,00,00,01,00,00,00,60,ea,00,00 "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\ 6d,00,44,00,61,00,74,00,61,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,\ 00,66,00,74,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,44,00,\ 65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,70,00,6c,00,61,00,74,00,66,\ 00,6f,00,72,00,6d,00,5c,00,34,00,2e,00,31,00,38,00,2e,00,32,00,33,00,30,00,\ 34,00,2e,00,38,00,2d,00,30,00,5c,00,4d,00,73,00,4d,00,70,00,45,00,6e,00,67,\ 00,2e,00,65,00,78,00,65,00,22,00,00,00 "LaunchProtected"=dword:00000003 "ObjectName"="LocalSystem" "RequiredPrivileges"=hex(7):53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,\ 00,6e,00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,\ 65,00,00,00,53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,00,72,00,69,\ 00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,\ 74,00,6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,\ 00,00,00,53,00,65,00,44,00,65,00,62,00,75,00,67,00,50,00,72,00,69,00,76,00,\ 69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,\ 00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,\ 6c,00,65,00,67,00,65,00,00,00,53,00,65,00,4c,00,6f,00,61,00,64,00,44,00,72,\ 00,69,00,76,00,65,00,72,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,\ 65,00,00,00,53,00,65,00,53,00,65,00,63,00,75,00,72,00,69,00,74,00,79,00,50,\ 00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,53,00,\ 68,00,75,00,74,00,64,00,6f,00,77,00,6e,00,50,00,72,00,69,00,76,00,69,00,6c,\ 00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,6e,00,63,00,72,00,65,00,61,00,\ 73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,00,72,00,69,00,76,00,69,00,6c,\ 00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,\ 50,00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,\ 00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,54,00,\ 63,00,62,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,\ 00,65,00,49,00,6e,00,63,00,72,00,65,00,61,00,73,00,65,00,42,00,61,00,73,00,\ 65,00,50,00,72,00,69,00,6f,00,72,00,69,00,74,00,79,00,50,00,72,00,69,00,76,\ 00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,53,00,79,00,73,00,74,00,\ 65,00,6d,00,45,00,6e,00,76,00,69,00,72,00,6f,00,6e,00,6d,00,65,00,6e,00,74,\ 00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,\ 54,00,61,00,6b,00,65,00,4f,00,77,00,6e,00,65,00,72,00,73,00,68,00,69,00,70,\ 00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00 "ServiceSidType"=dword:00000001 "Start"=dword:00000002 "Type"=dword:00000010 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\Security] "Security"=hex:01,00,14,80,cc,00,00,00,d8,00,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,9c,00,06,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,21,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 14,00,9d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,00,28,00,ff,01,0f,\ 00,01,06,00,00,00,00,00,05,50,00,00,00,bf,55,08,72,3b,e0,28,d0,89,79,4b,f8,\ 91,89,6e,7c,40,25,ec,f4,01,01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,\ 00,00,05,12,00,00,00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc] "DelayedAutoStart"=dword:00000001 "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00 "Description"="@%SystemRoot%\\System32\\wscsvc.dll,-201" "DisplayName"="@%SystemRoot%\\System32\\wscsvc.dll,-200" "ErrorControl"=dword:00000001 "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\ 00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00 "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\ 74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\ 00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\ 6b,00,20,00,4c,00,6f,00,63,00,61,00,6c,00,53,00,65,00,72,00,76,00,69,00,63,\ 00,65,00,4e,00,65,00,74,00,77,00,6f,00,72,00,6b,00,52,00,65,00,73,00,74,00,\ 72,00,69,00,63,00,74,00,65,00,64,00,20,00,2d,00,70,00,00,00 "LaunchProtected"=dword:00000002 "ObjectName"="NT AUTHORITY\\LocalService" "RequiredPrivileges"=hex(7):53,00,65,00,43,00,68,00,61,00,6e,00,67,00,65,00,4e,\ 00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\ 67,00,65,00,00,00,53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,\ 00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\ 00,00,00,00 "ServiceSidType"=dword:00000001 "Start"=dword:00000002 "Type"=dword:00000020 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Parameters] "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\ 00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\ 77,00,73,00,63,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00 "ServiceDllUnloadOnStop"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\wscsvc\Security] "Security"=hex:01,00,14,80,1c,01,00,00,28,01,00,00,14,00,00,00,30,00,00,00,02,\ 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ 00,00,02,00,ec,00,08,00,00,00,00,00,18,00,9d,00,02,00,01,02,00,00,00,00,00,\ 05,20,00,00,00,21,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,\ 12,00,00,00,00,00,18,00,9d,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\ 02,00,00,00,00,14,00,9d,00,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,00,\ 14,00,9d,00,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,00,28,00,fd,01,02,\ 00,01,06,00,00,00,00,00,05,50,00,00,00,e5,fe,79,5f,a0,ae,0d,3b,22,fa,0a,c9,\ 01,5a,41,3a,e5,a6,4a,b7,00,00,28,00,ff,01,0f,00,01,06,00,00,00,00,00,05,50,\ 00,00,00,b5,89,fb,38,19,84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,00,00,\ 28,00,ff,01,0f,00,01,06,00,00,00,00,00,05,50,00,00,00,db,8c,74,0f,c2,72,73,\ f3,2b,26,b9,44,77,1e,4f,02,76,63,b5,21,01,01,00,00,00,00,00,05,12,00,00,00,\ 01,01,00,00,00,00,00,05,12,00,00,00 EndRegedit: EmptyTemp: ***************** Le Point de restauration a été créé avec succès. Processus fermé avec succès. C:\Windows\Prefetch\AVASTCLEAR.EXE-510FADD7.pf => déplacé(es) avec succès "C:\Windows\Prefetch\AVASTNM.EXE-A097FF9E.pf" => non trouvé(e) "C:\Windows\Prefetch\AVASTSVC.EXE-CBA6876B.pf" => non trouvé(e) "C:\Windows\Prefetch\AVASTUI.EXE-19622E35.pf" => non trouvé(e) "C:\Windows\Prefetch\AVASTUI.EXE-19622E36.pf" => non trouvé(e) "C:\Windows\Prefetch\AVASTUI.EXE-19622E37.pf" => non trouvé(e) "C:\Windows\Prefetch\AVASTUI.EXE-19622E3D.pf" => non trouvé(e) C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-16B44146.pf => déplacé(es) avec succès "C:\Windows\Prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-68EC2C31.pf" => non trouvé(e) "C:\FRST\Quarantine\C\ProgramData\Avast Software" dossier déplacer: C:\FRST\Quarantine\C\ProgramData\Avast Software => déplacé(es) avec succès "C:\FRST\Quarantine\C\Users\PC du camping car\AppData\Local\Avast Software" dossier déplacer: C:\FRST\Quarantine\C\Users\PC du camping car\AppData\Local\Avast Software => déplacé(es) avec succès "C:\Program Files\Avast Software" => non trouvé(e) HKEY_LOCAL_MACHINE\SOFTWARE\Avast Software => supprimé(es) avec succès HKEY_LOCAL_MACHINE\SOFTWARE\Classes\avast => supprimé(es) avec succès HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage => supprimé(es) avec succès "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\AvastUI.exe" => supprimé(es) avec succès HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\AVAST Software => supprimé(es) avec succès HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\AvastAdSDK => supprimé(es) avec succès HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{0d0504ba-c43e-4d3d-90ed-38d4d3517e2b}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$avast antivirus => supprimé(es) avec succès HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{0d0504ba-c43e-4d3d-90ed-38d4d3517e2b}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$avast antivirus => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\ShowJumpView\\{6D809377-6AF0-444B-8957-A3773F02200E}\Avast Software\Avast\setup\instup.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\PC du camping car\Downloadsavast_free_antivirus_setup_online.exe" => non trouvé(e) "HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files\Avast Software\Avast\AvastUI.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files\Avast Software\Avast\setup\instup.exe" => supprimé(es) avec succès "HKEY_USERS\S-1-5-21-2348191869-1658706661-1089226288-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\PC du camping car\Desktop\avastclear.exe" => supprimé(es) avec succès ========= net start WinDefend ========= L'erreur systŠme 2 s'est produite. Le fichier sp‚cifi‚ est introuvable. ========= Fin de CMD: ========= ========= net start wscsvc ========= Le service demand‚ a d‚j… ‚t‚ d‚marr‚. Vous obtiendrez une aide suppl‚mentaire en entrant NET HELPMSG 2182. ========= Fin de CMD: ========= ========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Account Protection" /va /f ========= Erreurÿ: Erreurÿ: le systŠme n'a pas trouv‚ la cl‚ ou la valeur de Registre sp‚cifi‚e. ========= Fin de Reg: ========= Registre ====> L'op�ration a r�ussi. =========== EmptyTemp: ========== FlushDNS => terminé(e) BITS transfer queue => 786432 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18985950 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B Windows/system/drivers => 594570 B Edge => 0 B Chrome => 0 B Firefox => 94426363 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 5116 B NetworkService => 5116 B defaultuser0 => 5116 B PC du camping car => 4770351 B RecycleBin => 525839 B EmptyTemp: => 114.5 MB données temporaires supprimées. ================================ Le système a dû redémarrer. ==== Fin de Fixlog 17:36:26 ====