start::
CreateRestorePoint:
CloseProcesses:
RemoveProxy:
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction
HKU\S-1-5-21-2877674399-294292187-1114645722-1001\...\Run: [com.blitz.app] => C:\Users\arnau\AppData\Local\Programs\Blitz\Blitz.exe
CHR DefaultSearchURL: Default -> hxxps://fr.search.yahoo.com/search?fr=mcafee&type=E210FR885G0&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
CHR DefaultSuggestURL: Default -> hxxps://fr.search.yahoo.com/sugg/gossip/gossip-fr-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
CHR Extension: (McAfee® WebAdvisor) - C:\Users\arnau\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho
S1 WinSetupMon; system32\DRIVERS\WinSetupMon.sys [X]
2022-06-20 21:32 - 2022-06-20 21:32 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2022-06-20 21:27 - 2022-06-20 21:27 - 011158272 _____ (McAfee, LLC) C:\Users\arnau\Downloads\MCPR.exe
HKU\S-1-5-21-2877674399-294292187-1114645722-1001\...\StartupApproved\Run: => "EPLTarget\P0000000000000002"
EmptyTemp:
cmd: ipconfig /flushdns
cmd: sfc /scannow
end::