start::
CreateRestorePoint:
CloseProcesses:
Hosts:
RemoveProxy:
GroupPolicy: Restriction ? <==== ATTENTION
SearchScopes: HKU\S-1-5-21-3598648777-3919985599-1165234887-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3598648777-3919985599-1165234887-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3598648777-3919985599-1165234887-1001 -> {7ED3ED8E-6FA7-4816-9D29-8AC70AB439D6} URL =
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\Video Converter Ultimate\Transfer\DriverInstall.exe" [X]
2020-04-05 11:05 - 2020-04-05 11:08 - 000000000 ____D C:\Program Files (x86)\Wondershare
2020-04-05 11:05 - 2020-04-05 11:06 - 000000000 ____D C:\ProgramData\Wondershare
2020-04-05 11:05 - 2020-04-05 11:05 - 000000000 ____D C:\Users\Dominique-admin\AppData\Roaming\Wondershare
2020-04-05 11:05 - 2020-04-05 11:05 - 000000000 ____D C:\Users\Dominique-admin\AppData\Local\Wondershare
2020-04-05 11:05 - 2020-04-05 11:05 - 000000000 ____D C:\ProgramData\Wondershare MediaServer
2020-04-05 11:05 - 2020-04-05 11:05 - 000000000 ____D C:\Program Files (x86)\WondershareUpdate
2020-04-05 11:04 - 2020-04-05 11:05 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2020-04-05 11:04 - 2020-04-05 11:05 - 000000000 ____D C:\ProgramData\Documents\Wondershare
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> Pas de fichier
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Pas de fichier
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> Pas de fichier
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Pas de fichier
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Pas de fichier
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Pas de fichier
EmptyTemp:
cmd: ipconfig /flushdns
cmd: netsh advfirewall reset
cmd: md C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database
cmd: DISM /Online /Cleanup-image /Restorehealth
cmd: sfc /scannow
end::