start::
CreateRestorePoint:
CloseProcesses:
Hosts:
RemoveProxy:
GroupPolicy: Restriction ? <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
Task: {70F647C1-9B12-4498-B5CE-333D6597D648} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2760512 2020-08-18]
CHR Extension: (New Tab Redirect) - C:\Users\bques\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna
R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [78936 2019-06-07]
R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [45472 2019-03-20]
R3 phantomtap; C:\WINDOWS\System32\drivers\phantomtap.sys [45056 2020-03-18]
2020-08-20 19:28 - 2020-08-20 19:28 - 000000000 ____D C:\Users\bques\AppData\Local\Amazon
2020-08-20 14:16 - 2020-08-20 14:16 - 000000000 ____D C:\Program Files (x86)\Amazon
2020-08-18 18:32 - 2020-08-18 18:32 - 000002566 _____ C:\WINDOWS\system32\Tasks\Avira_Antivirus_Systray
2020-08-18 18:32 - 2020-08-18 18:32 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avira
2020-08-22 17:32 - 2018-11-20 16:35 - 000000000 ____D C:\Program Files (x86)\Avira
2020-08-22 17:32 - 2018-11-20 16:34 - 000000000 ____D C:\ProgramData\Avira
2019-11-12 18:14 - 2019-11-12 18:51 - 000000716 ____H () C:\Users\bques\AppData\Roaming\{9410B859-E353-7DE2-8242-906C15EC71D6}
ContextMenuHandlers3: [STKContextMenu] -> {90DD7445-E924-4c6e-92AC-01F8C3A7E0C7} => C:\Program Files (x86)\Amazon\SendToKindle\stkContextMenu_250.dll
EmptyTemp:
cmd: ipconfig /flushdns
cmd: netsh advfirewall reset
cmd: netsh winsock reset
cmd: sfc /scannow
end::