start::
closeprocesses:
createrestorepoint:
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare software CO., LIMITED -> Wondershare)
BHO: Pas de nom -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> Pas de fichier
BHO-x32: Pas de nom -> {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} -> Pas de fichier
FF ProfilePath: Profiles/zu0kh7hs.default [non trouvé(e)] <==== ATTENTION
S2 ElevationService; C:\Program Files (x86)\Wondershare\drfone\Addins\Backup\ElevationService.exe [X]
S3 HnGEpicService; D:\Games\Epic Games\Games\HeroesGeneralsWWII\hngservice.exe [X]
S4 Wondershare InstallAssist; C:\ProgramData\Wondershare\Service\InstallAssistService.exe [X]
AlternateDataStreams: C:\Users\Cédric\AppData\Local\Temp:zIhuTmTj0DgBizIZUgGd [2602]
FirewallRules: [{4F8F43A0-D6A8-439C-AB1F-D50312311672}] => (Allow) C:\Users\Cédric\AppData\Roaming\Zoom\bin\airhost.exe Pas de fichier
FirewallRules: [{63A77B56-170E-40C2-A0C6-3F4323B71231}] => (Allow) C:\Users\Cédric\AppData\Roaming\Zoom\bin\airhost.exe Pas de fichier
cmd: md C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database
end::