Borrowed game: Avast detects all my files as viruses

ZangDev Posted messages 9 Status Member -  
fabul Posted messages 42285 Registration date   Status Moderator Last intervention   -

Hello,

yesterday I borrowed a game (Call of Duty: Black Ops II) from a friend and when I ran it my antivirus (Avast) went crazy and started detecting all my executables as viruses, even when I added exceptions… right now I had to put it on hold to calm it down

NB: I didn't take the source of the game or where he got it from otherwise I would have mentioned it… in any case, from now on it’s better if I download or buy my games myself

I'm sorry, but regarding the order of the files I think this is it
Addition.txt : https://uploadnow.io/f/gQxFWrY

FRST.txt : https://uploadnow.io/f/SgtQDsW


6 answers

  1. fabul Posted messages 42285 Registration date   Status Moderator Last intervention   6 092
     

    Hello,

    Run this antivirus in Offline mode (Bootable USB key)

    https://free.drweb.fr/aid_admin/

    0
    1. ZangDev Posted messages 9 Status Member
       

      and how do I use it please

      0
      1. ZangDev Posted messages 9 Status Member > fabul Posted messages 42285 Registration date   Status Moderator Last intervention  
         

        so basically I boot the USB with the downloaded image, then I start the PC from it???

        sorry if I seem to be bothering you but I see your solution but I do NOT understand it AT ALL… could you be a little more detailed and precise in your statements?

        thank you

        0
      2. fabul Posted messages 42285 Registration date   Status Moderator Last intervention   6 092 > ZangDev Posted messages 9 Status Member
         

        That's right.

        Create a bootable key (that boots) and start with it to analyze the system from outside the system.

        0
  2. fabul Posted messages 42285 Registration date   Status Moderator Last intervention   6 092
     

    Download the file for USB drweb-livedisk-900-usb.exe

    Insert a blank USB drive of at least 2GB into the PC's USB port

    Run the program drweb-livedisk-900-usb.exe

    Select the correct USB drive to format

    Check the Format USB Drive... box

    And click Create Dr.Web Live Disk

    Then click YES to format (Erase everything on the USB drive)

    Wait a few minutes for the USB drive to be created.

    When the drive is created and ready to use, restart the PC while tapping the Boot Menu key as soon as it powers on.

    The key varies by PC, if you tell me the model, I might be able to help further, otherwise you can find a list of Boot Menu and BIOS keys here according to the manufacturer:

    https://www.malekal.com/liste-touches-acces-bios-boot-menu-constructeur/

    When Dr.Web Live CD starts from the Boot Menu, it’s simple, just click Continue > Start Scanning, and then delete what is detected.

    Is it an HP?

    Try the Escape or F9 key for the Boot Menu (to boot from the USB drive instead of Windows)

    -

    PS:

    If it doesn't work or help, create a Ventoy USB drive

    https://www.ventoy.net/en/download.html

    Extract everything from the Ventoy archive and use Ventoy2Disk.exe

    If the PC is old, create the drive in MBR mode

    If it is recent (Windows 8 or higher) in GPT mode for EFI

    And place the .ISO file of Kaspersky Rescue Disk on the Ventoy drive afterwards

    https://rescuedisk.s.kaspersky-labs.com/updatable/2018/krd.iso

    Boot from it the same way with the Boot Menu to scan the system with Kaspersky Rescue Disk

    0
  3. ZangDev Posted messages 9 Status Member
     

    otherwise do you have any idea about the exact problem with my machine

    I'm asking this question because of the files that the pinned description asked us to create (FRST and addition)

    it's also that the download takes quite a long time from where I am so ... I am once again sorry

    0
    1. fabul Posted messages 42285 Registration date   Status Moderator Last intervention   6 092
       

      "Otherwise, do you have an idea of the exact problem with my machine?"

      In another topic, you mentioned an infected external hard drive.

      USB viruses are often dealt with using USBFix, but is it now paid?"

      0
  4. fabul Posted messages 42285 Registration date   Status Moderator Last intervention   6 092
     

    I am not used to FRST otherwise I might have seen something?

    But I didn't see any obvious signs of infection.

    However, the end of Addition.txt is missing that you may have posted before the scan finished.

    I use RegRun Reanimator more often.

    https://forums.commentcamarche.net/forum/affich-38206831-alors-vous-voulez-supprimer-les-virus-vous-meme-comment

    0
    1. ZangDev Posted messages 9 Status Member
       

      Please, is it normal that it detects system files... and what exactly does it do to the files found (deletion... repair... quarantine... I don't know... please I just want to know)

      Thank you for your patience regarding my case

      0
      1. fabul Posted messages 42285 Registration date   Status Moderator Last intervention   6 092 > ZangDev Posted messages 9 Status Member
         

        If it's system files that have been infected, the system needs to be repaired with
        sfc /scannow

        Reanimator deletes when requested to delete.

        0
  5. ZangDev Posted messages 9 Status Member
     

    Hello,

    I no longer want to take any risks, but I also don't want to lose my data... could you help me disinfect my device and my external drive?

    I have seen the different conversations and apparently each problem has its solution (its analysis), so here are mine:



    FRST.txt: https://uploadnow.io/files/W6v4jzH

    Addition.txt: https://uploadnow.io/files/bpYSkh2

    Best regards, thank you


    0
    1. fabul Posted messages 42285 Registration date   Status Moderator Last intervention   6 092
       

      The site uploadnow.io is asking me to log in...

      0
      1. ZangDev Posted messages 9 Status Member > fabul Posted messages 42285 Registration date   Status Moderator Last intervention  
         

        I copy the content here

        Addiction.txt

        Additional Analysis Results from Farbar Recovery Scan Tool (x64) Version: 11-10-2025
        Executed by Ange (15-10-2025 13:03:33)
        Executed from C:\Users\Ange\Desktop
        Microsoft Windows 10 Professional Version 22H2 19045.6332 (X64) (2023-01-21 14:01:04)
        Boot Mode: Normal
        ==========================================================


        ==================== Accounts: =============================

        (If an item is included in the fixlist.txt file, it will be removed.)

        Administrator (S-1-5-21-2580522982-2987149798-2802210835-500 - Administrator - Disabled)
        Ange (S-1-5-21-2580522982-2987149798-2802210835-1004 - Administrator - Enabled) => C:\Users\Ange
        DefaultAccount (S-1-5-21-2580522982-2987149798-2802210835-503 - Limited - Disabled)
        HPG4 (S-1-5-21-2580522982-2987149798-2802210835-1001 - Administrator - Enabled) => C:\Users\HPG4
        Guest (S-1-5-21-2580522982-2987149798-2802210835-501 - Limited - Disabled)
        WDAGUtilityAccount (S-1-5-21-2580522982-2987149798-2802210835-504 - Limited - Disabled)

        ==================== Security Center ========================

        (If an item is included in the fixlist.txt file, it will be removed.)

        AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
        AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}

        ==================== Installed Programs ======================

        (Only 'adware' software marked as 'Hidden' may be added to the fixlist.txt file to avoid being hidden. Adware programs must be uninstalled manually.)

        Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1036-1033-7760-BC15014EA700}) (Version: 25.001.20756 - Adobe)
        Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601120}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
        Audio Controls Application (HKLM\...\HP-NB-AIO) (Version: 4.0.130.0 - Conexant Systems)
        Free Avast Antivirus (HKLM\...\Avast Antivirus) (Version: 25.9.10453.3120 - Gen Digital Inc.)
        CCleaner (HKLM\...\CCleaner) (Version: 6.39 - Piriform)
        COLMIS_3 (HKLM-x32\...\COLMIS WINDOWS APP Windows 32 bits Executable) (Version: 3.2.2.0 - NECC)
        Demon Slayer: Kimetsu no Yaiba (HKLM-x32\...\Demon Slayer: Kimetsu no Yaiba_is1) (Version:  - )
        Dev-C++ 5 beta 9 release (4.9.9.2) (HKLM-x32\...\Dev-C++) (Version:  - )
        Git (HKLM\...\Git_is1) (Version: 2.46.0 - The Git Development Community)
        Google Chrome (HKLM-x32\...\Google Chrome) (Version: 141.0.7390.108 - Google LLC)
        Intel(R) Chipset Device Software (HKLM\...\{4A121459-D3F8-4908-A474-96D45641E357}) (Version: 10.1.18243.8188 - Intel Corporation) Hidden
        Intel(R) Chipset Device Software (HKLM-x32\...\{f3b1c211-1159-4262-bb97-84150cda9096}) (Version: 10.1.18243.8188 - Intel(R) Corporation)
        Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2313.4.16.0 - Intel Corporation)
        Intel(R) Management Engine Components (HKLM\...\{6A16D17C-1F3D-4BB8-ACFE-ACB373C96D11}) (Version: 1.0.0.0 - Intel Corporation) Hidden
        Intel(R) Management Engine Components (HKLM\...\{C2492DBC-1733-4CF9-AF8C-63EC77DA7942}) (Version: 1.0.0.0 - Intel Corporation) Hidden
        Intel(R) Management Engine Driver (HKLM\...\{1B837123-92FE-4BBC-8BE1-1CE69EC78936}) (Version: 1.0.0.0 - Intel Corporation) Hidden
        Intel(R) Trusted Connect Service Client x64 (HKLM\...\{C9552825-7BF2-4344-BA91-D3CD46F4C442}) (Version: 1.66.712.0 - Intel Corporation) Hidden
        Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.66.712.0 - Intel Corporation) Hidden
        Intel(R) Trusted Connect Services Client (HKLM-x32\...\{b6e20498-6533-4bb9-8102-77ace49ffe78}) (Version: 1.66.712.0 - Intel Corporation) Hidden
        Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 141.0.3537.71 - Microsoft Corporation)
        Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 141.0.3537.71 - Microsoft Corporation) Hidden
        Microsoft Office Professional Plus 2021 - fr-fr (HKLM\...\ProPlus2021Retail - fr-fr) (Version: 16.0.19231.20156 - Microsoft Corporation)
        Microsoft OneDrive (HKU\S-1-5-21-2580522982-2987149798-2802210835-1001\...\OneDriveSetup.exe) (Version: 25.137.0715.0001 - Microsoft Corporation)
        Microsoft OneDrive (HKU\S-1-5-21-2580522982-2987149798-2802210835-1004\...\OneDriveSetup.exe) (Version: 25.179.0914.0003 - Microsoft Corporation)
        Microsoft Project - fr-fr (HKLM\...\ProjectProRetail - fr-fr) (Version: 16.0.19231.20156 - Microsoft Corporation)
        Microsoft Update Health Tools (HKLM\...\{1FC1A6C2-576E-489A-9B4A-92D21F542136}) (Version: 3.74.0.0 - Microsoft Corporation)
        Microsoft VC++ redistributables repacked. (HKLM\...\{8F69E094-110C-41C1-8017-A1643C6A68A9}) (Version: 12.0.0.0 - Intel Corporation) Hidden
        Microsoft VC++ redistributables repacked. (HKLM-x32\...\{0117C91D-E81E-4C19-BD1C-22CFCBD2A332}) (Version: 12.0.0.0 - Intel Corporation) Hidden
        Microsoft Visio - fr-fr (HKLM\...\VisioProRetail - fr-fr) (Version: 16.0.19231.20156 - Microsoft Corporation)
        Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
        Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
        Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
        Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
        Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
        Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
        Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
        Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
        Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
        Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810 (HKLM-x32\...\{5af95fd8-a22e-458f-acee-c61bd787178e}) (Version: 14.40.33810.0 - Microsoft Corporation)
        Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810 (HKLM-x32\...\{47109d57-d746-4f8b-9618-ed6a17cc922b}) (Version: 14.40.33810.0 - Microsoft Corporation)
        Microsoft Visual C++ 2022 x64 Additional Runtime - 14.40.33810 (HKLM\...\{59CED48F-EBFE-480C-8A38-FC079C2BEC0F}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2022 x64 Minimum Runtime - 14.40.33810 (HKLM\...\{B8B3BB4A-A10D-4F51-91B7-A64FFAC31EA7}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2022 x86 Additional Runtime - 14.40.33810 (HKLM-x32\...\{5EA6C998-D5AC-4ED9-89C3-9F25B17CCD3D}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
        Microsoft Visual C++ 2022 x86 Minimum Runtime - 14.40.33810 (HKLM-x32\...\{0C3457A0-3DCE-4A33-BEF0-9B528C557771}) (Version: 14.40.33810 - Microsoft Corporation) Hidden
        Microsoft Visual Studio Code (User) (HKU\S-1-5-21-2580522982-2987149798-2802210835-1004\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.105.0 - Microsoft Corporation)
        Node.js (HKLM\...\{0463EF6C-7AE0-4657-970D-FD4634A98A35}) (Version: 22.20.0 - Node.js Foundation)
        Notepad++ (HKLM-x32\...\Notepad++) (Version: 7 - Notepad++ Team)
        Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.19231.20072 - Microsoft Corporation) Hidden
        Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.16327.20264 - Microsoft Corporation) Hidden
        Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-040C-1000-0000000FF1CE}) (Version: 16.0.19231.20072 - Microsoft Corporation) Hidden
        Opera Stable 120.0.5543.161 (HKU\S-1-5-21-2580522982-2987149798-2802210835-1001\...\Opera 120.0.5543.161) (Version: 120.0.5543.161 - Opera Software)
        OptaneDowngradeGuard (HKLM\...\{86B0E6C1-32E0-42CC-BC4F-BF3C0730CECB}) (Version: 18.0.0.0 - Intel Corporation) Hidden
        Python 3.13.7 (64-bit) (HKU\S-1-5-21-2580522982-2987149798-2802210835-1004\...\{9a46f6d0-8f11-4f8f-a23d-d617db01bbb6}) (Version: 3.13.7150.0 - Python Software Foundation)
        Python 3.13.7 Add to Path (64-bit) (HKLM\...\{235C9435-3313-4658-881D-5A7E559A5A41}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python 3.13.7 Core Interpreter (64-bit) (HKLM\...\{BE75E968-78F4-411D-92E4-73EC3043F7E4}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python 3.13.7 Development Libraries (64-bit) (HKLM\...\{96A23710-E014-4A5B-96A1-DE64AC37251B}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python 3.13.7 Documentation (64-bit) (HKLM\...\{CFAAA24B-16EF-4D9D-80A5-F67798771571}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python 3.13.7 Executables (64-bit) (HKLM\...\{E4047598-558F-4468-8B53-9FCEF7F86E0D}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python 3.13.7 pip Bootstrap (64-bit) (HKLM\...\{CD31E178-F872-466B-A231-9C8AA53A89FD}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python 3.13.7 Standard Library (64-bit) (HKLM\...\{A139F43E-8105-465D-AC80-28F349CBE08D}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python 3.13.7 Tcl/Tk Support (64-bit) (HKLM\...\{A65B1339-6492-4CA4-AEB5-2B25A83A20B9}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python 3.13.7 Test Suite (64-bit) (HKLM\...\{6BD2B618-9A2B-47D9-B24B-2F05BD2768E4}) (Version: 3.13.7150.0 - Python Software Foundation) Hidden
        Python Launcher (HKLM-x32\...\{8B8DEA15-D815-4CB1-AC10-4E7713F3DFA0}) (Version: 3.13.7150.0 - Python Software Foundation)
        RstDowngradeGuard (HKLM\...\{13C2A26E-7AD4-4D82-BB4F-DEA6E871B958}) (Version: 18.0.0.0 - Intel Corporation) Hidden
        Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.3.8.27 - Synaptics Incorporated)
        Update for x64-based Windows Systems (KB5001716) (HKLM\...\{B8D93870-98D1-4980-AFCA-E26563CDFB79}) (Version: 8.94.0.0 - Microsoft Corporation)
        VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.16 - VideoLAN)
        Wampserver64 3.3.5 (HKLM\...\{wampserver64}_is1) (Version: 3.3.5 - Dominique Ottello alias Otomatic)
        WinRAR 5.60 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)
        Zoom Workplace (HKU\S-1-5-21-2580522982-2987149798-2802210835-1001\...\ZoomUMX) (Version: 6.4.12 (64384) - Zoom Communications, Inc.)

        Chrome apps:
        ============
        Sheets (HKU\S-1-5-21-2580522982-2987149798-2802210835-1001\...\6703c6bf267d853aaa1657b6ba85e104) (Version: 1.0 - Google\Chrome)

        Packages:
        =========
        Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2025-10-07] ()
        Intel® Graphics Configuration Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-10-05] (INTEL CORP) [Startup Task]
        HP Support Assistant -> C:\Program Files\WindowsApps\AD2F1837.HPSupportAssistant_9.47.41.0_x64__v10z8vjag6ke6 [2025-10-12] (HP Inc.)
        HP System Information -> C:\Program Files\WindowsApps\AD2F1837.HPSystemInformation_8.10.45.0_x64__v10z8vjag6ke6 [2025-10-05] (HP Inc.)
        Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1042.0_x64__8j3eq9eme6ctt [2025-10-05] (INTEL CORP)
        Local Artificial Intelligence Manager -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\AI [2025-10-12] ()
        Microsoft.Office.ActionsServer -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\ActionsServer [2025-10-12] ()
        OfficePushNotificationsUtility -> C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16 [2025-10-12] ()

        ==================== Custom CLSID (With whitelist): ==============

        (If an item is included in the fixlist.txt file, it will be removed from the Registry. The file will not be moved unless it is listed separately.)

        CustomCLSID: HKU\S-1-5-21-2580522982-2987149798-2802210835-1004_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => No file
        CustomCLSID: HKU\S-1-5-21-2580522982-2987149798-2802210835-1004_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => No file
        CustomCLSID: HKU\S-1-5-21-2580522982-2987149798-2802210835-1004_Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\localserver32 -> C:\Users\Ange\AppData\Local\Microsoft\OneDrive\25.179.0914.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
        CustomCLSID: HKU\S-1-5-21-2580522982-2987149798-2802210835-1004_Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\localserver32 -> C:\Users\Ange\AppData\Local\Microsoft\OneDrive\25.179.0914.0003\OneDrive.Sync.Service.exe (Microsoft Corporation -> Microsoft Corporation)
        ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-03] (Gen Digital Inc. -> Gen Digital Inc.)
        ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-03] (Gen Digital Inc. -> Gen Digital Inc.)
        ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2025-09-29] (Adobe Inc. -> Adobe Systems Inc.)
        ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2016-09-21] (Notepad++ -> )
        ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-03] (Gen Digital Inc. -> Gen Digital Inc.)
        ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
        ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
        ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-03] (Gen Digital Inc. -> Gen Digital Inc.)
        ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2025-10-03] (Gen Digital Inc. -> Gen Digital Inc.)
        ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
        ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)

        ==================== Codecs (With whitelist) ====================

        ==================== Shortcuts & WMI ========================

        ==================== Loaded Modules (With whitelist) =============

        2025-10-15 12:51 - 2017-07-16 13:24 - 000114688 _____ () [Unsigned file] C:\Users\Ange\AppData\Local\Temp\is-7MBS2.tmp\HIF2RAW_DLL.DLL
        2025-10-15 12:51 - 2017-07-16 13:24 - 000126464 _____ () [Unsigned file] C:\Users\Ange\AppData\Local\Temp\is-7MBS2.tmp\RAW2HIF_DLL.DLL
        2025-10-15 12:51 - 2017-08-06 17:09 - 000089088 _____ () [Unsigned file] C:\Users\Ange\AppData\Local\Temp\is-7MBS2.tmp\zlibwapi.dll
        2025-10-15 10:59 - 2024-04-04 14:50 - 000560128 _____ () [Unsigned file] c:\wamp64\bin\apache\apache2.4.59\bin\pcre2-8.dll
        2025-10-15 10:59 - 2024-02-15 12:48 - 019686912 _____ () [Unsigned file] c:\wamp64\bin\mariadb\mariadb11.3.2\bin\server.dll
        2025-10-15 11:01 - 2025-10-15 11:02 - 000000000 ___JL () [symlink -> c:\wamp64\bin\php\php8.2.18\libsasl.dll] c:\wamp64\bin\apache\apache2.4.59\bin\libsasl.dll
        2025-10-15 11:01 - 2025-10-15 11:02 - 000000000 ___JL () [symlink -> c:\wamp64\bin\php\php8.2.18\libsqlite3.dll] c:\wamp64\bin\apache\apache2.4.59\bin\libsqlite3.dll
        2025-09-29 23:10 - 2025-09-29 23:10 - 000030720 _____ (Adobe Systems Inc.) [Unsigned file] C:\Program Files\Adobe\Acrobat DC\Acrobat\locale\fr_fr\Acrobat Elements\ContextMenuShim64.fra
        2025-10-15 10:59 - 2024-04-04 15:03 - 000216064 _____ (Apache Software Foundation) [Unsigned file] c:\wamp64\bin\apache\apache2.4.59\bin\libapr-1.dll
        2025-10-15 10:59 - 2024-04-04 15:03 - 000036864 _____ (Apache Software Foundation) [Unsigned file] c:\wamp64\bin\apache\apache2.4.59\bin\libapriconv-1.dll
        2025-10-15 10:59 - 2024-04-04 15:03 - 000300032 _____ (Apache Software Foundation) [Unsigned file] c:\wamp64\bin\apache\apache2.4.59\bin\libaprutil-1.dll
        2025-10-15 10:59 - 2024-04-04 15:03 - 000462848 _____ (Apache Software Foundation) [Unsigned file] c:\wamp64\bin\apache\apache2.4.59\bin\libhttpd.dll
        2025-10-15 10:59 - 2024-04-04 15:04 - 000015360 _____ (Apache Software Foundation) [Unsigned file] C:\wamp64\bin\apache\apache2.4.59\modules\mod_actions.so
        2025-10-15 10:59 - 2024-04-04 15:04 - 000021504 _____ (Apache Software Foundation) [Unsigned file] C:\wamp64\bin\apache\apache2.4.59\modules\mod_alias.so
        2025-10-15 10:59 - 2024-04-04 15:04 - 000013312 _____ (Apache Software Foundation) [Unsigned file] C:\wamp64\bin\apache\apache2.4.59\modules\mod_allowmethods.so
        2025-10-15 10:59 - 2024-04-04 15:04 - 000013824 _____ (Apache Software Foundation) [Unsigned file] C:\wamp64\bin\apache\apache2.4.59\modules\mod_asis.so
        2025-10-15 10:59 - 2024-04-04 15:04 - 000017920 _____ (Apache Software Foundation) [Unsigned file] C:\wamp64\bin\apache\apache2.4.59\modules\mod_auth_basic.so
        2025-10-15 10:59 - 2024-04-04 15:04 - 000034304 _____ (Apache Software Foundation) [Unsigned file] C:\wamp64\bin\apache\apache2.4.59\modules\mod_auth_digest.so
        2025-10-15 10:59 - 2024-04-04 15:04 - 000016896 _____ (Apache Software Foundation) [Unsigned file] C:\wamp64\bin\apache\apache2.4.59\modules\mod_authn_core.so
        2025-10-15 10:59 - 2024-04-04 15:04 - 000015360 _____ (Apache Software Foundation) [Fichier non signé] C:\wamp64\bin\apache\apache2.4.59\modules\mod_cache.so

        0
  6. fabul Posted messages 42285 Registration date   Status Moderator Last intervention   6 092
     

    Hi again,

    Please run a sfc /scannow with Windows PowerShell (Admin)
    (FRST indicates that the system file dllhost.exe is missing)

    Are the viruses detected only on the external media?

    If it's a shortcut type virus on a USB key or drive, I still say USBFix

    Otherwise, it may be due to formatting or deleting the USB drive.

    Have you tried Kaspersky Live on a bootable USB key?

    I don't know if it can scan all the drives?

    Avast may not be better than Defender in your case, so uninstall Avast as well.

    Then if you want me to check if I see anything obvious with Reanimator, please make a RegRun Reanimator report:

    https://greatis.com/security/reanimator.html

    After installation, click on the Send Report tab > Send Report > Reboot

    After rebooting, close the program window and send the report on your desktop regrunlog.txt preferably via Cijoint.org for 60 days (the maximum).

    https://cijoint.org

    Then communicate the cijoint link here.

    0