start::
closeprocesses:
createrestorepoint:
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
FF Extension: (Avast Online Security) - C:\Users\ChamNat\AppData\Roaming\Mozilla\Firefox\Profiles\syb7c4m9.default\Extensions\wrc@avast.com.xpi [2019-12-07]
FF Extension: (Avast Online Security) - C:\Users\ChamNat\AppData\Roaming\Mozilla\Firefox\Profiles\5vzlpk25.default-release\Extensions\wrc@avast.com.xpi [2021-02-17]
R2 AvastWscReporter; \Avast\wsc_proxy.exe [56904 2021-02-25] (Avast Software s.r.o. -> AVAST Software)
C:\Program Files\AVAST Software
2021-04-01 18:53 - 2021-04-01 18:53 - 000339680 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2021-04-01 18:53 - 2021-04-01 18:53 - 000216376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswcd2ab1c31d2ffaf6.tmp
2021-03-31 18:46 - 2021-03-31 18:46 - 000000000 ____D C:\Users\ChamNat\AppData\Local\mbam
2021-03-31 18:46 - 2021-03-31 18:46 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-03-31 18:45 - 2021-03-31 18:45 - 002084016 _____ (Malwarebytes) C:\Users\ChamNat\Downloads\MBSetup.exe
2021-04-01 18:53 - 2020-10-18 17:41 - 000177872 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw84d2691e321ef28d.tmp
2021-04-01 18:53 - 2020-04-16 00:51 - 000524416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw95b6beb17f7ee502.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000850120 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswac0f9089c9580812.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000466696 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw754ef6f830680dbe.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000365520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswb26f9a4d2b2c9c7b.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000326976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw1d2a6e905233ba41.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000250328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw9c2ba69c15551e1e.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000208552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw15f594322893b7c3.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000107808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw8424c3c3c51c6fb1.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000099288 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw44337e86e6ba3f2d.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000083368 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswc70ed5f75b5ddeb6.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000041304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\asw8efe828c10c7901e.tmp
2021-04-01 18:53 - 2019-12-07 19:35 - 000035680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswcefd371acae02e61.tmp
2021-04-01 18:58 - 2019-12-07 19:34 - 000000000 ____D C:\ProgramData\AVAST Software
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
AlternateDataStreams: C:\Users\ChamNat\Documents\Sic Semper Tyrannis.mp4:AFP_AfpInfo [130]
AlternateDataStreams: C:\Users\ChamNat\Documents\Sic Semper Tyrannis.mp4:com.apple.lastuseddate#PS [34]
AlternateDataStreams: C:\Users\ChamNat\Documents\Sic Semper Tyrannis.mp4:com.apple.quarantine [21]
AlternateDataStreams: C:\Users\ChamNat\Documents\Sic Semper Tyrannis.mp4:Mac_Metadata [42]
HKU\S-1-5-21-2438185012-704424215-3564399428-1001\Software\Classes\regfile: regedit.exe "%1" <==== ATTENTION
cmd: sfc /scannow
emptytemp:
end::