start:: CreateRestorePoint: CloseProcesses: Hosts: RemoveProxy: HKLM\...\Run: [CL-25-270F398B-8755-4784-B9C2-9360C509547B] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\CL-25-270F398B-8755-4784-B9C2-9360C509547B\setuplauncher.exe" GroupPolicy: Restriction ? <==== ATTENTION HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION S1 amsdk; \??\C:\Windows\system32\drivers\amsdk.sys [X] U3 aswbdisk; no ImagePath 2020-11-04 18:41 - 2020-11-04 18:41 - 000195428 _____ C:\ProgramData\vpn.1604511663.bdinstall.v2.bin 2020-11-04 18:41 - 2020-11-04 18:41 - 000000000 ____D C:\ProgramData\Bitdefender VPN 2020-11-04 18:37 - 2020-11-04 22:07 - 000000000 ____D C:\Program Files\Bitdefender 2020-11-04 18:37 - 2020-11-04 18:37 - 000765404 _____ C:\ProgramData\cl.1604511385.bdinstall.v2.bin 2020-11-04 18:37 - 2020-11-04 18:37 - 000101428 _____ C:\ProgramData\cl.kit.1604511383.bdinstall.v2.bin 2020-11-04 18:37 - 2020-11-04 18:37 - 000000000 ____D C:\ProgramData\48C4687D-9760-4F5B-BAB3-60351B0841E4 2020-11-04 18:31 - 2020-11-04 18:31 - 000121648 _____ C:\ProgramData\agent.1604511064.bdinstall.v2.bin 2020-11-04 17:22 - 2020-11-04 17:22 - 000000000 ____D C:\ProgramData\Bitdefender Agent 2020-11-03 20:20 - 2020-11-04 17:30 - 000000000 ____D C:\ProgramData\Avast Software 2020-10-22 16:00 - 2020-10-22 16:02 - 000745835 _____ C:\Windows\ZAM.krnl.trace 2020-10-22 16:00 - 2020-10-22 16:00 - 000000000 ____D C:\Users\Ignace\AppData\Local\Zemana 2020-10-19 20:57 - 2020-10-19 20:57 - 000000000 ____D C:\Users\Ignace\AppData\Local\CDex 2020-10-19 20:56 - 2020-10-19 21:02 - 000000000 ____D C:\Program Files (x86)\CDex ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\07164304.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\07164304.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver" EmptyTemp: cmd: ipconfig /flushdns cmd: netsh winsock reset cmd: sfc /scannow end::