je vais explorer d'autres pistes
ceci en attendant
En mode sans échec
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
C:\Sophos_Uninstall_strings.txt
C:\Windows\SysWOW64\SophosED\SophosED.dll
C:\Windows\SysWOW64\SophosAV\sophos_detoured.dll
C:\Windows\SysWOW64\SophosAV\sophos_detoured.dll.stf00
C:\Windows\System32\SophosBootTasks.exe
C:\Windows\System32\SophosNA.exe
C:\Windows\System32\SophosED\SophosED.dll
C:\Windows\System32\SophosAV\sophos_detoured_x64.dll
C:\Windows\System32\SophosAV\sophos_detoured_x64.dll.stf00
C:\Windows\System32\drivers\SophosBootDriver.sys
C:\Windows\System32\drivers\SophosED.man
C:\Windows\System32\drivers\SophosED.sys
C:\Windows\System32\drivers\SophosEL.sys
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\SophosBootDriver.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\SophosED-amd64-2.2.6.731.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\SophosED-amd64-3.0.0.1333.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\SophosED-amd64-3.0.1.842.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\SophosED-amd64-3.0.1.875.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\SophosEL-amd64-2.2.0.2736.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\SophosEL-amd64-3.0.0.909.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\SophosEL-amd64-3.0.1.309.cat
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\Sophos Anti-Virus Startup Log_241201_011352.txt
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\Sophos Anti-Virus Startup Log_241201_054606.txt
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\Sophos Anti-Virus Startup Log_241201_074956.txt
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\Sophos Anti-Virus Startup Log_241201_100237.txt
C:\Windows\Prefetch\SOPHOSCLEANUP.EXE-14AD4351.pf
C:\Windows\Prefetch\SOPHOSMTREXTENSION.EXE-C7247930.pf
C:\Windows\Prefetch\SOPHOSOSQUERY.EXE-86284D78.pf
C:\Windows\Prefetch\SOPHOSOSQUERYEXTENSION.EXE-8430AB11.pf
C:\Windows\Prefetch\SOPHOSSAFESTORE.EXE-380FD505.pf
C:\Windows\Prefetch\SOPHOSUPDATE.EXE-69593AE5.pf
C:\Windows\Installer\{4EFCDD15-24A2-4D89-84A4-857D1BF68FA8}\sophossupport.ico
C:\Windows\ELAMBKUP\SophosEL.sys
C:\Users\k8valyd\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_Diag
C:\Users\k8valyd\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_UI
C:\Users\k8valyd\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Sophos_Sophos Diagnostic Utility_sdugui_exe
C:\Users\k8emerj\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_Diag
C:\Users\k8emerj\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_UI
C:\Users\k8emerj\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Sophos_Sophos Diagnostic Utility_sdugui_exe
C:\Users\k8bourb\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_Diag
C:\Users\k8bourb\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_UI
C:\Users\k8bourb\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Sophos_Sophos Diagnostic Utility_sdugui_exe
C:\Users\k8aumop\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_Diag
C:\Users\k8aumop\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_UI
C:\Users\k8aumop\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Sophos_Sophos Diagnostic Utility_sdugui_exe
C:\Users\JPEmery\Pictures\freecad\desinstal sophos par revo.jpg
C:\Users\JPEmery\AppData\Roaming\Microsoft\Windows\Recent\desinstal sophos par revo.lnk
C:\Users\JPEmery\AppData\Local\Temp\Sophos Endpoint Agent Uninstall 2024_12_01_20_31_55Z.log
C:\Users\JPEmery\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_Diag
C:\Users\JPEmery\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Sophos_Sophos Diagnostic Utility_sdugui_exe
C:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_Diag
C:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_UI
C:\Users\Administrator\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Sophos_Sophos Diagnostic Utility_sdugui_exe
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_Diag
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\Sophos_UI
C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\150\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Sophos_Sophos Diagnostic Utility_sdugui_exe
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.0.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.1.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.2.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.3.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.4.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.5.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.6.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.7.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.8.log
C:\ProgramData\Sophos\Sophos UI\logs\SophosUI.Net.log
C:\ProgramData\Sophos\Sophos UI\logs\telemetry\SophosUITelemetryLog.sess1.20240127T06.json
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFileScanner.log
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFileScanner.log.lock
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1655529954-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1668693428-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1671442122-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1675599703-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1675618309-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1679221541-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1679481987-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1680808292-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1681415505-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1681678259-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1683089133-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1683278444-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1684148138-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1685270936-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1686057426-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1687293033-1
C:\ProgramData\Sophos\Sophos File Scanner\Logs\SophosFS.log-1687633971-1
Unlock: HKLM\System\CurrentControlSet\Services\SAVService
Delete: HKLM\System\CurrentControlSet\Services\SAVService
Unlock: HKLM\System\CurrentControlSet\Services\SntpService
Delete: HKLM\System\CurrentControlSet\Services\SntpService
Unlock: HKLM\System\CurrentControlSet\Services\Sophos AutoUpdate Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos AutoUpdate Service
Unlock: HKLM\System\CurrentControlSet\Services\Sophos Clean Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos Clean Service
Unlock: HKLM\System\CurrentControlSet\Services\Sophos Device Control Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos Device Control Service
Unlock: HKLM\System\CurrentControlSet\Services\Sophos Endpoint Defense Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos Endpoint Defense Service
Unlock: HKLM\System\CurrentControlSet\Services\Sophos File Scanner Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos File Scanner Service
Unlock: HKLM\System\CurrentControlSet\Services\Sophos Health Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos Health Service
Unlock: HKLM\System\CurrentControlSet\Services\Sophos Live Query
Delete: HKLM\System\CurrentControlSet\Services\Sophos Live Query
Unlock: HKLM\System\CurrentControlSet\Services\Sophos MCS Agent
Delete: HKLM\System\CurrentControlSet\Services\Sophos MCS Agent
Unlock: HKLM\System\CurrentControlSet\Services\Sophos MCS Client
Delete: HKLM\System\CurrentControlSet\Services\Sophos MCS Client
Unlock: HKLM\System\CurrentControlSet\Services\Sophos Safestore Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos Safestore Service
Unlock: HKLM\System\CurrentControlSet\Services\Sophos System Protection Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos System Protection Service
Unlock: HKLM\System\CurrentControlSet\Services\Sophos Web Control Service
Delete: HKLM\System\CurrentControlSet\Services\Sophos Web Control Service
Unlock: HKLM\System\CurrentControlSet\Services\swi_filter
Delete: HKLM\System\CurrentControlSet\Services\swi_filter
Unlock: HKLM\System\CurrentControlSet\Services\swi_service
Delete: HKLM\System\CurrentControlSet\Services\swi_service
Unlock: HKLM\System\CurrentControlSet\Services\SAVOnAccess
Delete: HKLM\System\CurrentControlSet\Services\SAVOnAccess
Unlock: HKLM\System\CurrentControlSet\Services\hmpalertsvc
Delete: HKLM\System\CurrentControlSet\Services\hmpalertsvc
Unlock: HKLM\System\CurrentControlSet\Services\SAVAdminService
Delete: HKLM\System\CurrentControlSet\Services\SAVAdminService
Reboot:
end::
Corrige et heberge le rapport fixlog
@+