start::
CreateRestorePoint:
CloseProcesses:
RemoveProxy:
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== ATTENTION (Restriction - ProxySettings)
ProxyServer: [HKLM] => http=127.0.0.1:48080;https=127.0.0.1:48080
ProxyServer: [HKLM-x32] => http=127.0.0.1:48080;https=127.0.0.1:48080
AutoConfigURL: [HKLM] => http=127.0.0.1:48080;https=127.0.0.1:48080
ProxyServer: [S-1-5-21-3470697656-2204332084-3721796178-1001] => http=127.0.0.1:48080;https=127.0.0.1:48080
ProxyServer: [S-1-5-21-3470697656-2204332084-3721796178-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08152019104716295] => http=127.0.0.1:48080;https=127.0.0.1:48080
ProxyServer: [S-1-5-21-3470697656-2204332084-3721796178-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08152019104719151] => http=127.0.0.1:48080;https=127.0.0.1:48080
ProxyServer: [S-1-5-21-3470697656-2204332084-3721796178-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08152019104925454] => http=127.0.0.1:48080;https=127.0.0.1:48080
Tcpip\..\Interfaces\{b3136ba2-3755-4aad-9fb3-0ec38ad5daa3}: [NameServer] 8.8.8.8,8.8.4.4
ManualProxies: 1http=127.0.0.1:48080;https=127.0.0.1:48080
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {1E2C9A91-8CD4-40AB-AA5D-E5711BAD4FB9} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA}
Task: {1EA5E3D8-995F-48D2-A0F0-98041E739875} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Pas de fichier
Task: {44969C78-6B81-440C-B2A9-BE466F667B4F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Pas de fichier
Task: {494B28B6-F2CB-402A-9771-6228F2295793} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Pas de fichier
Task: {8C95E6E8-C43E-4CD3-9617-8FBCB2EA6B6E} - \WPD\SqmUpload_S-1-5-21-3470697656-2204332084-3721796178-1001 -> Pas de fichier
Task: {942CEEAA-84F4-441A-B6C0-9E55535D9AB8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Pas de fichier
Task: {F979983A-7F40-48CF-9E77-150A0DE4181E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Pas de fichier
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-3470697656-2204332084-3721796178-1001.job => C:\Users\Bruno\AppData\Local\GoToMeeting\13761\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-3470697656-2204332084-3721796178-1001.job => C:\Users\Bruno\AppData\Local\GoToMeeting\13761\g2mupload.exe
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-9c84122f&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-9c84122f&q=
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-9c84122f&q=
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-9c84122f&q=
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fidikogfgleiaefnjbmnjaplmgknppkg] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
2019-08-02 10:09 - 2019-08-04 18:58 - 000000000 ____D C:\Users\Bruno\Desktop\201908StellaD7200
2019-07-25 11:01 - 2019-07-25 19:08 - 000000000 ____D C:\Users\Bruno\Desktop\201908StellaZ6
2019-08-13 20:26 - 2017-04-09 22:28 - 000000000 ____D C:\Users\Bruno\AppData\Roaming\587f70fbb13dab12e9435dd9c38914c7
2019-08-13 09:38 - 2017-05-19 15:08 - 000015766 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2016-11-29 11:07 - 2017-02-06 10:07 - 000017231 _____ () C:\Users\Bruno\AppData\Roaming\Tenapehaf
2017-12-12 16:07 - 2017-12-12 16:07 - 000000052 _____ () C:\Users\Bruno\AppData\Local\QNKHEByByB
EmptyTemp:
cmd: ipconfig /flushdns
end::