start::
closeprocesses:
createrestorepoint:
HKU\S-1-5-21-3761955104-2453934275-1756335967-1001\...\StartupApproved\Run: => "Web Companion"
IE trusted site: HKU\S-1-5-21-3761955104-2453934275-1756335967-1001\...\hola.org -> hxxp://hola.org
AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8 [168]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
Task: {AECF7891-5EB7-4460-9778-209C1C16B026} - System32\Tasks\Firefox Default Browser Agent 708C99EBD244EB47 => C:\Users\Thomas\AppData\Roaming\irbacue.exe <==== ATTENTION
C:\Users\Thomas\AppData\Roaming\irbacue.exe
Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)]
Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)]
Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)]
Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)]
S3 EuGdiDrv; \SystemRoot\system32\EuGdiDrv.sys [X]
S3 ssudmdm; \SystemRoot\system32\DRIVERS\ssudmdm.sys [X]
S3 ss_conn_usb_driver2; \SystemRoot\System32\Drivers\ss_conn_usb_driver2.sys [X]
cmd: netsh advfirewall reset
cmd: sfc /scannow
cmd: DISM /Online /Cleanup-image /Restorehealth
emptytemp:
end::