start::
closeprocesses:
createrestorepoint:
CustomCLSID: HKU\S-1-12-1-1206209816-1086181295-1248512403-1444017220_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\NicolasSAUNIER\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll => Pas de fichier
SearchScopes: HKU\S-1-12-1-1206209816-1086181295-1248512403-1444017220 -> DefaultScope {7D2B5E21-6874-4DF6-B157-C60D002DEEB4} URL =
SearchScopes: HKU\S-1-12-1-1206209816-1086181295-1248512403-1444017220 -> {7D2B5E21-6874-4DF6-B157-C60D002DEEB4} URL =
FirewallRules: [{B584C67E-5971-4F1F-A095-E53EB6DA1F78}] => (Allow) C:\Users\NicolasSAUNIER\AppData\Local\Temp\7zS2D9F\HP.EasyStart.exe => Pas de fichier
FirewallRules: [{73BEF5E5-0E17-458D-9C0D-C9853F1DAFD1}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_2.0.7811.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe => Pas de fichier
FirewallRules: [{6D363250-FD52-4996-B9C8-9993CBA480CD}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_2.0.7811.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe => Pas de fichier
Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)]
Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)]
Edge Extension: (McAfee® WebAdvisor) -> EdgeExtension_5A894077McAfeeWebAdvisor_wafk5atnkzcwy => C:\Program Files\WindowsApps\5A894077.McAfeeWebAdvisor_2.0.22033.0_x86__wafk5atnkzcwy [2020-06-05]
Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)]
Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)]
C:\Users\NicolasSAUNIER\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
cmd: sfc /scannow
emptytemp:
end::