start::
closeprocesses:
createrestorepoint:
HKLM-x32\...\Run: [Orange_MEA MIFI40 ModemListener] => C:\Program Files (x86)\Orange_MEA\MW40\BackgroundService\ModemListener.exe [172840 2016-07-01] (JRD COMMUNICATION (SHENZHEN) LTD -> )
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKU\S-1-5-21-164975066-2011734899-3013885378-1001\...\Policies\Explorer: []
HKU\S-1-5-21-164975066-2011734899-3013885378-1001\...\MountPoints2: {d95e4ee2-96b1-11eb-90db-34689541ce9f} - "D:\autorun.exe"
Task: {DA24B599-1212-4728-B47B-4EAD87F0BDF4} - System32\Tasks\IMF_SkipUAC_Igor => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
C:\Program Files (x86)\IObit
2021-05-12 00:41 - 2021-05-12 00:41 - 000000000 ____D C:\ProgramData\Outbyte
2021-05-12 00:41 - 2021-05-12 00:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outbyte
2021-05-12 00:41 - 2021-05-12 00:41 - 000000000 ____D C:\Program Files (x86)\Outbyte
2021-05-12 00:39 - 2021-05-12 00:40 - 020906976 _____ (Outbyte) C:\Users\hp\Downloads\0x800c0006_repair-setup.exe
2021-05-12 11:35 - 2021-03-27 01:39 - 000000000 ____D C:\Users\hp\AppData\LocalLow\IObit
2021-05-12 11:27 - 2021-03-27 15:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 8
2021-05-04 13:00 - 2021-03-27 02:01 - 000002091 _____ C:\Users\Public\Desktop\Adobe Reader 9.lnk
cmd: DISM /Online /Cleanup-image /Restorehealth
cmd: sfc /scannow
emptytemp:
end::