start::
closeprocesses:
createrestorepoint:
SafeZone Stable 1.51.2220.62 (HKLM-x32\...\SafeZone 1.51.2220.62) (Version: 1.51.2220.62 - Avast Software) Hidden
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
SearchScopes: HKU\S-1-5-21-838140020-3380330352-3532157349-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NS&chn=1000&geo=FR&ver=22.9.1.12&locale=fr_FR&guid=A4BEFD3C-8FA9-4C6E-88A6-18EB6B0248E2&doi=2016-09-01&gct=sb&qsrc=2869
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton AntiVirus\Engine\21.7.0.11\IPS\IPSBHO.DLL => Pas de fichier
FirewallRules: [{BE02BEA3-AD99-4E22-B30F-26CCC3E6DBD6}] => (Allow) C:\Users\user\AppData\Roaming\Zoom\bin\airhost.exe => Pas de fichier
FirewallRules: [{C40400CC-39F5-4148-8439-FF49E7CB31D4}] => (Allow) C:\Users\user\AppData\Roaming\Zoom\bin\airhost.exe => Pas de fichier
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
C:\Program Files (x86)\Adobe\Reader 9.0
HKLM-x32\...\Run: [WinZip UN] => C:\Program Files (x86)\WinZip\WZUpdateNotifier.exe [2231184 2020-08-19] (Corel Corporation -> Corel Corporation)
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {41866919-92F9-4291-8E82-F13380CB731D} - System32\Tasks\{09C49F6A-172A-4B6C-9AAB-6DA371C20084} => C:\Program Files\Mozilla Firefox\firefox.exe 0
Task: {5F8B4619-323E-4EE8-93F5-F85301A993A8} - System32\Tasks\{94D2F998-5948-4EF2-B066-BAA0FEE5B333} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe [2866736 2020-09-11] (Adobe Inc. -> Adobe Systems Incorporated)
Task: {67AE336D-4D1A-4D4B-9B4C-106275EFCA9E} - System32\Tasks\{E1B1FD1C-ABBE-456E-AFCE-7E511555E7C7} => C:\Program Files\Mozilla Firefox\firefox.exe 0
Task: {7A156267-D552-4E66-B213-3BAB9E552C55} - System32\Tasks\{4B9697C1-AC03-4CA9-80BC-F9AD2A8D0FAE} => C:\Program Files\Mozilla Firefox\firefox.exe 0
Task: {8A16266C-71D9-4015-AFBA-A24BBDDB210C} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files (x86)\WinZip\WZUpdateNotifier.exe [2231184 2020-08-19] (Corel Corporation -> Corel Corporation)
Task: {8EA88872-33BA-45F3-8DF1-2C30F8A29C55} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files (x86)\WinZip\WZUpdateNotifier.exe [2231184 2020-08-19] (Corel Corporation -> Corel Corporation)
Task: {9209220F-81C6-4438-8378-BB44436D8A92} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\user\Downloads\esetonlinescanner.exe
Task: {996C3EE1-6C84-47B9-A45F-16ADDB6E0990} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files (x86)\WinZip\WZUpdateNotifier.exe [2231184 2020-08-19] (Corel Corporation -> Corel Corporation)
Task: {EBECE54D-598F-49AA-BF9C-4356EDE4D21D} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\user\Downloads\esetonlinescanner.exe
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
FF Extension: (Avast SafePrice | Comparaison, offres, coupons) - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\np56vq73.Utilisateur par défaut-1552947619706\Extensions\sp@avast.com.xpi [2019-10-18]
FF Extension: (Avast Online Security) - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\np56vq73.Utilisateur par défaut-1552947619706\Extensions\wrc@avast.com.xpi [2018-10-12]
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Pas de fichier]
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Pas de fichier]
FF Plugin-x32: @videolan.org/vlc,version=3.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Pas de fichier]
FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Pas de fichier]
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [Pas de fichier]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-03-27]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn]
S2 McAfee WebAdvisor; "C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe" [X]
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [531280 2020-10-06] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klfltsdk; C:\Windows\System32\DRIVERS\klfltsdk.sys [252544 2020-10-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klgse; C:\Windows\System32\DRIVERS\klgse.sys [521336 2020-10-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [1107064 2020-10-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klifsdk; C:\Windows\System32\DRIVERS\klifsdk.sys [1105536 2020-10-06] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [212304 2020-10-06] (Kaspersky Lab -> AO Kaspersky Lab)
2020-10-25 22:32 - 2020-10-06 13:06 - 001107064 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys
2020-10-25 22:32 - 2020-10-06 13:06 - 000531280 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\kl1.sys
2020-10-25 22:32 - 2020-10-06 13:06 - 000521336 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klgse.sys
2020-10-25 22:32 - 2020-10-06 13:06 - 000147680 _____ (AO Kaspersky Lab) C:\Windows\system32\klhkum.dll
2020-10-06 13:06 - 2020-10-06 13:06 - 001105536 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klifsdk.sys
2020-10-06 13:06 - 2020-10-06 13:06 - 000252544 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klfltsdk.sys
2020-10-06 13:06 - 2020-10-06 13:06 - 000212304 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwtp.sys
cmd: net stop winmgmt
cmd: DEL C:\Windows\System32\wbem\Repository\*.* Del c: \ Windows \ System32 \ WBEM \ Repository \ *.*
emptytemp:
end::