start::
CreateRestorePoint:
CloseProcesses:
RemoveProxy:
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {2E0F0FBC-7918-477C-BBA1-E7E262C758EB} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(1): schtasks.exe -> /Change /TN "\{0F8099C9-BB16-444E-BB25-76EE17C4D51E}" /ENABLE
Task: {2E0F0FBC-7918-477C-BBA1-E7E262C758EB} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(2): schtasks.exe -> /Change /TN "\{1A19B538-ACFF-4723-BAD7-C740DDBCA68C}" /ENABLE
Task: {2E0F0FBC-7918-477C-BBA1-E7E262C758EB} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(3): schtasks.exe -> /Change /TN "\{50F4C717-90F8-4E48-8AE5-B0F5C2AED7D2}" /ENABLE
Task: {2E0F0FBC-7918-477C-BBA1-E7E262C758EB} - System32\Tasks\AVAST Software\Gaming mode Task Scheduler recovery => Command(4): schtasks.exe -> /Change /TN "\AVAST Software\Gaming mode Task Scheduler recovery" /DISABLE
Task: {E04A9610-EF89-4168-A8A5-64067D79A70F} - System32\Tasks\{1A19B538-ACFF-4723-BAD7-C740DDBCA68C} => C:\Windows\system32\pcalua.exe -a C:\ProgramData\Hauppauge\UNWISE32WINTV7.EXE -c /U C:\PROGRA~3\HAUPPA~1\WinTV8.LOG
Edge Extension: (IBM Security Rapport) - C:\Users\PB\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kajikgogckeajjplomldcempamhidmcc [2020-12-21]
Edge HKLM-x32\...\Edge\Extension: [kajikgogckeajjplomldcempamhidmcc]
FF Extension: (IBM Security Rapport) - C:\Users\PB\AppData\Roaming\Mozilla\Firefox\Profiles\3bw1477v.default-release\Extensions\rapportext@trusteer.com.xpi [2020-06-18] [UpdateUrl:hxxps://clients2.google.com/service/update2/crx]
FF Extension: (Privacy Possum) - C:\Users\PB\AppData\Roaming\Mozilla\Firefox\Profiles\3bw1477v.default-release\Extensions\woop-NoopscooPsnSXQ@jetpack.xpi [2019-12-30]
FF Extension: (Avast Online Security) - C:\Users\PB\AppData\Roaming\Mozilla\Firefox\Profiles\3bw1477v.default-release\Extensions\wrc@avast.com.xpi [2021-02-17]
CHR HKU\S-1-5-21-1337720634-1639997172-2869916048-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof]
OPR Extension: (Rich Hints Agent) - C:\Users\PB\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2020-12-19]
U1 aswbdisk; pas de ImagePath
S3 cmudaxp; system32\drivers\cmudaxp.sys [X]
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
R1 RapportAegle64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportAegle64.sys
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys
R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys
2021-02-04 11:48 - 2021-02-04 11:48 - 000000000 ____D C:\ProgramData\Ask
FCheck: C:\Windows\system32\vcruntime140.dll [2020-08-28] <==== ATTENTION (zéro octet Fichier/Dossier)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
FirewallRules: [{47302B64-B522-403A-A28F-8771866D53F3}] => (Allow) C:\Program Files (x86)\AOMEI Backupper\ABService.exe => Pas de fichier
FirewallRules: [{8CF7961B-B2E8-4479-9E15-A0AC4F8FDD93}] => (Allow) C:\Program Files (x86)\AOMEI Backupper\ABService.exe => Pas de fichier
FirewallRules: [TCP Query User{6FC66EE6-BEC3-4D8F-A04C-1738890E8583}C:3\apache2\bin\httpd.exe] => (Allow) C:3\apache2\bin\httpd.exe => Pas de fichier
FirewallRules: [UDP Query User{C993ADA1-2224-4E37-B2AC-06D8B28A1409}C:3\apache2\bin\httpd.exe] => (Allow) C:3\apache2\bin\httpd.exe => Pas de fichier
FirewallRules: [TCP Query User{5851C649-9F99-4AC2-B255-1B19167B282E}C:3\mysql\bin\mysqld-nt.exe] => (Allow) C:3\mysql\bin\mysqld-nt.exe => Pas de fichier
FirewallRules: [UDP Query User{23BC2702-200C-42D5-A51A-B0AB66E756E9}C:3\mysql\bin\mysqld-nt.exe] => (Allow) C:3\mysql\bin\mysqld-nt.exe => Pas de fichier
EmptyTemp:
cmd: ipconfig /flushdns
cmd: netsh winsock reset
cmd: sfc /scannow
end::